Privacy
PlantRego — Privacy Policy
Version 1.0 · 31 July 2026 · entity/ABN pending registration
PlantRego is operated by an entity currently being registered in Perth, Western Australia (ABN to be added once registration completes). This policy explains what information we collect, why, where it is stored, who can access it, and your rights.
Although PlantRego may currently fall within the small business exemption under the Privacy Act 1988 (Cth), we voluntarily comply with the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme.
1. What we collect
Account and business information
Business name, ABN, trading address, billing contact. Owner and user details: name, email address, role (Owner or Technician), and optionally phone number.
Plant and compliance records (entered by you and your users)
Plant/asset details: descriptions, makes, models, serial numbers, plant registration numbers, locations. Inspection and checklist records, including the name of the user who completed each entry and the date/time. Photographs uploaded by users — typically of plant, data plates, and inspection/registration certificates. Certificates may contain the names and licence numbers of third-party inspectors.
Payment information
Payments are processed by Stripe. We receive confirmation of payment status and the last 4 digits/card type for reference. We never see or store full card numbers.
Technical information
Sign-in events (timestamps, IP address). Your password — stored only as a salted cryptographic hash (via Supabase Auth); we cannot see or retrieve your actual password. QR scan and page-access events (which asset, which user, when) — used for the audit trail that is the core of the product. Basic device/browser information and error logs needed to run and secure the service.
What we don't collect
We do not request GPS/location permissions, we do not use advertising trackers, and we do not sell or share data for marketing.
2. Why we collect it
- To provide the service: compliance registers, inspection history, due-date alerts, Evidence Pack exports
- To maintain the audit trail (who inspected what, when) that gives records their evidentiary value
- To bill you, provide support, and secure the service (e.g. investigating suspicious sign-ins)
- To send service emails (password resets, due-date alerts, billing and service notices). We do not send third-party marketing.
3. Where your data is stored
- All application data is hosted on Supabase (database, file storage, and authentication) in the Sydney, Australia region (AWS ap-southeast-2). Your plant records, photos, and compliance data are stored in Australia and do not leave Australia in the ordinary course of the service.
- Uploaded photos and certificates are stored in private storage buckets scoped to your organisation.
- Encrypted backups are taken at least daily and stored within the same region.
4. Who can access your data
- Your own users only. Every database record is isolated per organisation and enforced at the database layer (row-level security) — not just in the app interface. Another workshop cannot access your data, and Technicians only see what their role allows.
- Us, only as needed to provide support, fix faults, or meet legal obligations. We access customer records for support with your knowledge wherever practicable.
- Service providers (sub-processors) who help us run PlantRego, each bound by their own security and privacy obligations: Supabase (hosting, database, storage, authentication — Sydney, AU); Stripe (payment processing); Resend (transactional email delivery — password resets, alerts; email addresses may be processed outside Australia in transit); Vercel (delivery of the web application itself — no plant or compliance data is stored on Vercel).
- No one else. We do not sell, rent, or trade your information. We disclose data to third parties only with your direction (e.g. you export an Evidence Pack and give it to a builder) or where required by law.
5. Security
- Encryption in transit (TLS) and at rest
- Per-organisation isolation enforced by database row-level security
- Passwords stored only as salted cryptographic hashes — never in plain text, never visible to us
- Least-privilege access keys; administrative access limited to the operator
- Daily encrypted backups and tested restore procedures
No system is perfectly secure, but if a data breach occurs that is likely to result in serious harm, we will notify affected customers and the OAIC in line with the Notifiable Data Breaches scheme.
6. Retention and deletion
- While your subscription is active, records are retained so your compliance history remains complete — that history is the product.
- After cancellation: data is held in export-only form for 90 days, then permanently deleted from live systems and cycled out of backups.
- You can request earlier deletion, or deletion of specific records, at any time. Note that statutory record-keeping obligations for plant rest with you, so export before you delete.
7. Your rights
You (and your users) can:
- Access and correct personal information we hold — most of it is directly visible and editable in the app
- Export all organisation data at any time (Evidence Pack PDF, CSV + file export)
- Ask questions or complain about privacy handling by emailing hello@plantrego.com. We'll respond within 30 days. If unresolved, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
8. Your workers' information
Inspection records are attributed to the individual worker who completed them, with timestamps. This is a work record created in the ordinary course of employment. As the employer, you are responsible for making your workers aware that this activity is recorded in PlantRego.
9. Changes
We'll notify Owners by email of material changes to this policy at least 30 days before they take effect.
Contact
Entity name and ABN pending registration. Perth, WA. Email: hello@plantrego.com