The Hidden Legal Risks Sitting on Most Business Websites

Most business websites look polished on the surface, but the legal basics underneath are often patchy. A site might collect customer details without a proper privacy policy, make broad claims that could breach fair trading rules, or use copied images and content without clear permission. Many founders also launch with thin website terms, no clear refund position, and forms that quietly create obligations they did not mean to take on.

The hidden risks sitting on most business websites usually do not feel urgent until something goes wrong. That might be a customer complaint, a privacy request, a payment dispute, a competitor challenge, or a developer handover that leaves you without control of your own site. This guide explains where New Zealand businesses commonly get caught, when these issues tend to show up, and what to fix before you spend more money on setup, advertising, or selling online.

Overview

A business website is not just a marketing asset. It is often a sales channel, a data collection tool, and a source of legal promises to customers. Small gaps in the wording, setup, or ownership position can create outsized problems later.

The main legal risks usually sit in your content, your customer journey, your privacy practices, and your supplier arrangements.

  • Privacy disclosures, cookie tracking, and how you collect and store personal information
  • Fair Trading Act risk from testimonials, pricing, discounts, product claims, and comparative advertising
  • Website terms, sale terms, booking terms, refund wording, and online contract formation
  • Ownership of domain names, website code, imagery, logos, and written content
  • Email marketing consent, contact forms, and lead capture practices
  • Trade mark risk in your brand name, slogans, and campaign language
  • Consumer law obligations when selling goods or services online in New Zealand
  • Developer, agency, and software provider contracts that control access, updates, and liability

What The Hidden Risks Sitting on Most Business Websites Means For New Zealand Businesses

The hidden risks sitting on most business websites means legal exposure often sits in ordinary website features that founders treat as admin. The issue is rarely one dramatic mistake. It is usually a series of small gaps that add up.

In New Zealand, your website can trigger obligations under consumer law, privacy law, intellectual property rules, and contract law. If you are selling online, collecting enquiries, taking bookings, offering digital services, or using remarketing tools, your site is doing more legal work than many businesses realise.

Privacy is not just a policy page

If your website collects names, email addresses, phone numbers, addresses, payment information, or behavioural data, privacy obligations are already in play. That applies whether you run an ecommerce store, a SaaS platform, a consultancy, or a simple lead generation site.

A privacy policy should match what your business actually does. If your forms feed into a CRM, if you use third party scheduling tools, if analytics platforms track user behaviour, or if overseas service providers store your data, the wording needs to reflect that reality.

This is where founders often get caught:

  • using a generic privacy template that does not match actual systems or data flows
  • collecting more information than needed through forms and checkout pages
  • failing to explain marketing opt-ins clearly
  • not having an internal process for access or correction requests
  • assuming a cookie banner alone solves privacy compliance

The legal problem is not only the missing document. It is the mismatch between what the site says and what the business actually does with personal information.

Website copy is often written by marketers, founders, or designers who are focused on conversion. That is understandable, but statements on your site can become representations under the Fair Trading Act 1986.

Claims such as “best in New Zealand”, “guaranteed results”, “fully compliant”, “risk free”, or “limited time only” can cause trouble if they are exaggerated, unsubstantiated, or misleading in context. The same applies to crossed out pricing, headline discounts, scarcity claims, and testimonials that do not reflect typical customer outcomes.

Common pressure points include:

  • before and after statements for fitness, beauty, or software performance services
  • pricing pages that hide compulsory fees until late checkout
  • subscription offers where renewal terms are buried
  • claims that a product is made in New Zealand, eco-friendly, or endorsed, without a proper basis
  • reviews or star ratings presented without explaining incentives or moderation practices

If a reasonable customer could be misled, the wording needs work, even if the business did not mean to deceive anyone.

Online sales need proper terms, not scattered disclaimers

A website often forms part of the contract with your customer. Product descriptions, refund statements, booking conditions, delivery timeframes, and account signup flows can all shape what the customer is entitled to expect.

For New Zealand businesses, online selling also needs to be consistent with consumer protections, including obligations that cannot always be contracted out of when dealing with consumers. If your site says “no refunds in any circumstances” or “we accept no responsibility whatsoever”, that wording may not do what you think it does.

Well-drafted website terms and customer terms should cover issues such as:

  • how orders are accepted and when a contract is formed
  • pricing errors and stock availability
  • delivery timeframes and risk in transit
  • returns, cancellations, credits, and faulty goods
  • service limitations for digital platforms or subscription products
  • account suspension, misuse, and acceptable use rules

These terms matter most when a customer disputes a charge, alleges non-delivery, or says your site promised something more than you intended.

Ownership problems can sit quietly until a handover or dispute

Many businesses pay a freelancer or agency to build their site and assume that means they own everything. Sometimes they do not. The developer may still control the domain account, hosting access, source files, plugins, or copyright in custom materials, depending on the contract and how the project was set up.

The same risk applies to logos, stock images, blog content, graphics, videos, and code snippets. If your website includes content copied from another site, lifted from a search result, or generated by a contractor without a clear assignment, you may not have the rights you think you have.

Before you sign a development or branding contract, check:

  • who owns the website code, design files, and written content
  • who controls the domain registration and hosting account
  • whether paid plugins, fonts, or stock assets are properly licensed
  • what happens at the end of the engagement
  • whether your business can move the site to another provider without penalty or technical lock-in

This is especially important before a capital raise, sale of the business, or rebrand. Buyers and investors often ask for proof that the business owns its key digital assets.

When This Issue Comes Up

These risks usually come up at practical business moments, not in abstract legal reviews. The trigger is often growth, conflict, or change.

When you launch or redesign your site

A new website build is the best time to sort the legal basics. It is far easier to set up your forms, checkout flow, policies, and ownership structure properly at the start than to retrofit them after launch.

This matters whether you are starting a business in New Zealand, shifting from social-only selling to a standalone store, or moving from brochure site to online bookings. A redesign can also create fresh risk if old legal wording is copied across without checking whether it still matches your operations.

When you start collecting leads or customer data

The moment you add a contact form, newsletter signup, chat widget, booking system, or customer account area, privacy and marketing rules become more relevant. Many SMEs add tools one by one and end up with data flowing across multiple platforms without a clear record of what is happening.

That creates risk when a customer asks what information you hold, where it came from, or how to unsubscribe from marketing communications.

When you start selling online

Before you launch online, your website should reflect how you actually sell. That includes pricing, delivery, cancellations, digital access rules, and what happens if the item is unavailable.

For service businesses, the same issue appears when customers can book and pay through the site. If your website accepts deposits, subscriptions, recurring plans, or prepaid packages, your terms need to be clear before the first transaction goes through.

When you work with agencies, developers, or software suppliers

Third party providers can create hidden legal risk if contracts are loose or responsibilities are unclear. A web developer might install analytics tools without explaining the privacy impact. A marketing agency might publish comparative claims or use customer reviews in ways that create fair trading issues. A software provider might host customer data offshore under terms you have not read closely.

The issue is not that outsourcing is a problem. The issue is assuming technical suppliers have covered the legal side when they usually have not.

When your business starts scaling

Growth tends to expose problems that were easy to ignore when traffic was low. More website visitors mean more data. More orders mean more refund and delivery disputes. More ad spend means more scrutiny of your claims. More staff and contractors mean more people publishing content in your name.

If you are preparing for investment, franchising, expansion, or a sale, website issues often surface during due diligence. That is where a missing trade mark, weak contractor agreement, or copied content can become expensive.

Practical Steps And Common Mistakes

The best way to reduce website legal risk is to match your documents, systems, and customer journey to how the business actually operates. Good legal hygiene on a website is practical, not decorative.

Audit what your website is really doing

Start with a plain-English review of the site. Ignore what you intended the website to do and focus on what it actually does today.

Check items such as:

  • what personal information is collected on each form
  • whether cookies or tracking tools are active
  • what claims appear on product, pricing, and landing pages
  • what terms the customer sees before payment, booking, or account creation
  • which third party tools process data, payments, chat, or marketing
  • who in your business can edit content or access customer information

Many hidden risks sit in old landing pages, legacy popups, and disconnected apps that no one has reviewed since launch.

Make your privacy position accurate and usable

Your privacy wording should explain what information you collect, why you collect it, how it is stored, who you share it with, and how people can access or correct it. It also needs to line up with actual internal practice.

A common mistake is publishing a privacy policy that sounds polished but does not mention key tools, overseas providers, or marketing activity. Another is collecting optional information with no clear business reason.

Before you spend money on setup for a new CRM, booking platform, or ecommerce app, check whether the change affects your privacy messaging and your internal process for handling requests or incidents.

Review every customer-facing claim

Marketing language should be specific and supportable. If your site says something measurable, objective, or comparative, you should have a basis for it.

Pay special attention to:

  • headline pricing and automatic renewals
  • performance claims about software, health-adjacent services, or productivity gains
  • scarcity language such as countdowns or limited stock notices
  • comparisons with competitors
  • testimonials, endorsements, and influencer content
  • country of origin and sustainability statements

Founders often focus on whether a sentence is technically true. The better question is whether the overall impression could mislead an ordinary customer.

Fix your terms where customers actually see them

Terms are only useful if they are properly presented and tailored to the transaction. A generic footer document may not help much if the customer can buy, book, or subscribe without seeing the key conditions.

Think carefully about where the contract forms. For example, if a customer clicks “buy now”, “book now”, or “start trial”, the site should make it clear what terms apply at that point.

Businesses commonly need one or more of the following:

The wording should also fit your business structure and brand setup. If you are trading through a company registered with the Companies Office but marketing under a different business name, your legal identity should still be clear on the site.

Confirm ownership of digital assets

Ask one simple question: can the business access and control every important part of the website without asking permission from a former contractor? If the answer is no, sort that out early.

Record who owns or controls:

  • the domain name
  • hosting and DNS access
  • CMS and ecommerce platform logins
  • source code and design files
  • logos, brand assets, and image libraries
  • analytics, tag manager, ad accounts, and email marketing accounts

This is also the right time to assess trade mark risk. If your website brand is growing, a trade mark review can help you avoid building traffic and goodwill around a name that another business may challenge.

This is one of the most common mistakes. Founders copy policies, terms, disclaimers, and even FAQ wording from a competitor or overseas template because it feels faster and cheaper.

The problem is that copied text may not fit New Zealand law, your business model, or your systems. It can also create copyright issues and obvious inconsistencies that weaken your position in a dispute.

Templates can be useful starting points, but they still need contract review and tailoring. What works for a UK subscription platform or an Australian retailer may not fit your New Zealand operations, your registration details, or your customer process.

FAQs

Does every New Zealand business website need a privacy policy?

Not every site needs the same level of privacy wording, but if you collect personal information through forms, accounts, bookings, payments, or analytics tools, you should have a privacy policy that accurately explains what happens to that information.

Can I say no refunds on my website?

Not as a blanket rule. If you deal with consumers, New Zealand consumer law may give customers rights that cannot simply be removed by a website statement. Your refund wording should reflect your actual legal position and the type of goods or services you sell.

Who owns my website if I paid a developer to build it?

Payment alone does not always answer that question. Ownership and control depend on the contract, the assets involved, and how accounts were set up. Check the agreement, domain registration, hosting access, and any assignment of intellectual property.

Do I need website terms if I only use my site for enquiries?

Often yes. Even a lead generation site can benefit from website terms that cover permitted use, intellectual property, disclaimers, and limits around reliance on site content. If the site collects information, privacy wording is also important.

When should I review my website legally?

Review it when you launch, redesign, add new tools, change your pricing model, start selling online, run major ad campaigns, or engage a new agency or developer. A legal review is also sensible before investment, sale, or expansion.

Key Takeaways

  • The hidden risks sitting on most business websites usually relate to privacy, marketing claims, customer terms, and ownership of digital assets.
  • Your website can create legal obligations under New Zealand privacy, consumer, fair trading, contract, and intellectual property rules.
  • Generic templates and copied wording often cause more trouble because they do not match how your business actually operates.
  • Founders should review what the site collects, promises, sells, and connects to behind the scenes, especially before launch online or before signing with a developer or agency.
  • Clear website terms, accurate privacy disclosures, supportable marketing claims, and documented ownership of website assets can prevent costly disputes later.

If your business is dealing with the hidden risks sitting on most business websites and wants help with privacy policies, website terms, ecommerce sale terms, trade mark and IP ownership issues, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.