1. Scope
This policy covers personal information handled by [legal entity name], ABN [ABN], in operating LocateAU and this website. It is written to align with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
2. Account information
When you create an account we hold your email address, an authentication record, and any organisation details you supply. Authentication is handled by Supabase; we do not store your password, only the credential material Supabase holds on our behalf.
3. Addresses you send to the API
The addresses you submit are the queries you ask us to answer. They may be personal information about your customers, so we treat them accordingly.
- Queries are processed to produce a response and are not used to build a marketing profile, sold, or shared with other customers.
- We do not use your query content to train models.
- Query content is retained only as long as needed for debugging and abuse investigation, and is subject to the retention limits in section 5.
You remain responsible for having a lawful basis to send us your customers' addresses, and for telling those people how their information is handled in your own privacy policy.
4. Request logs
Every API request is logged with a request ID, the endpoint called, the response status, latency, the account and key used, and a timestamp. These logs make the dashboard's usage figures possible and let us investigate errors you report.
We never log full API keys, Supabase access tokens, or payment credentials.
5. Retention
Request metadata is retained for [retention period] and then deleted or aggregated into usage counters. Aggregate counters that contain no query content are kept for billing and capacity planning. Account records are kept while the account is open and for [retention period] afterwards to meet tax and record-keeping obligations.
6. Billing information
Payments are processed by Stripe. Card numbers never reach our servers. We store the Stripe customer and subscription identifiers, your plan, and the status Stripe reports to us through webhooks.
7. Third parties we rely on
- Supabase for authentication and session management.
- Stripe for payments, invoices and subscription state.
- [Hosting provider] for the servers running the API and this site.
Some of these providers process data outside Australia. Where that happens, we take reasonable steps to ensure the handling remains consistent with the Australian Privacy Principles.
8. Security
API keys are stored as verifiable representations rather than recoverable secrets, and the full key is shown only once when it is created. Access to production systems is limited to people who need it. No system is perfectly secure, and we will notify affected individuals and the OAIC where an eligible data breach occurs.
9. Cookies
This site sets what is needed to keep you signed in. There is no advertising network, no cross-site tracking pixel, and no third-party analytics profile built from your visit.
10. Your rights
You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account and its data. Deleting your account revokes its API keys and removes its request logs, subject to records we must retain by law.
11. Complaints and contact
Privacy questions and access requests go to [privacy contact email]. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.