Legal
Privacy policy
What we collect, why we have it, who gets to see it, and what we will not do with it.
- Version
- 2
- Effective
- 11 August 2026
1. Who this covers, and who is responsible
MyFloorPro is run by J&NB Enterprises Pty Ltd (ABN 11 700 887 609), trading as My Floor Pro. In this policy, “we”, “us” and “our” mean that entity, and “you” means the person reading it.
Privacy enquiries, requests for access or correction, and privacy complaints go to privacy@myfloorpro.com.au. One address, monitored by us, and there is no other step you have to find first.
It covers people who use MyFloorPro as a flooring business or as a flooring installer, and the people who work for them. It covers the MyFloorPro application and this website. Any other service we introduce later gets its own privacy notice rather than being folded quietly into this one.
This policy says “flooring business” for the side that has flooring to be laid, and “installer” for the side that lays it. “Flooring business” is deliberately broad: it covers shops and retailers, flooring contractors, builders, property managers, insurance restorers and commercial flooring companies. If our screens call you something narrower than that, this policy still covers you.
Whether or not the Privacy Act 1988 presently applies to us as a matter of law, we commit to handling personal information consistently with the Australian Privacy Principles. Where the Office of the Australian Information Commissioner has jurisdiction, you may complain to it after first giving us a reasonable chance to respond. Somebody handing us their business records should not have to work out which side of a turnover threshold we sit on, so we are not asking you to.
Our terms of use cover the rest of the relationship, and trust and safety explains what we check and what we do not.
2. What is switched on today, and what is not
Today you can register, create an account, build a profile, and answer our Founding Network questions. That is all that works.
None of this exists yet: posting a job, matching, expressing interest in work, releasing anyone’s contact details, messaging another member, inviting your colleagues into your organisation, fees, payments, reviews, and the MyFloorPro Score. Each sits behind a switch on our own servers, and every one of those switches is off.
The rest of this policy describes both states, and it keeps them apart. Every section that describes something switched off says so in the section itself.
3. What we collect
Three lists, kept separate on purpose. The first two are what we hold today. The third is what would be collected once a feature is switched on, and none of it exists yet.
Collected from you, now
- Your account. Email address, full name, phone number if you give us one, and your timezone.
- Your organisation. Legal name, trading name, ABN, business type, website, description, main suburb, state and postcode, phone number, billing email address, and any branches you add with their own suburb, state, postcode and phone number.
- Your installer profile. Business structure, trading name, main region, how far you will travel, whether you work domestic or commercial, years of experience, crew size, a summary of when you have room for more work, whether you are looking for subcontract work, the job types and project sizes you prefer, a portfolio link, your skills and how experienced you are in each, the regions you service, your equipment, the credentials you hold and when they expire, and whether you are registered for GST.
- Your flooring business profile. Business structure, whether you work domestic or commercial, whether you use subcontractors, how often you need extra installers, the role of your main contact, who you would prefer us to deal with during the pilot, the regions you operate in, the flooring categories you handle, and the kind of installer help you are looking for.
- Founding Network answers. Your answers to our pilot questions, how you heard about MyFloorPro, and a referral code if you type one in. These are research answers. They are never shown to anybody as though they were a job.
Generated by the platform, now
- Policy consent records. Which version of our terms and of this policy you accepted, when, and the IP address it was accepted from.
- Records of attempts to sign in. One row per attempt at signing in, registering, resetting a password or asking for another confirmation email, recorded against an email address or an IP address with the time it happened. No password and no code is ever written there. They exist so we can slow down an attack on somebody’s account, and section 15 says how long they are kept.
- Audit records. A log of what was done: the action, the record it was done to, who did it, when, the IP address and the browser user agent, and which fields changed. It records the names of the fields rather than their contents. A value that identifies somebody or that a person typed freely, such as a trading name, a link or a written summary, is recorded as having changed rather than being copied into the log.
- Account state. Whether an account is active, the time it last signed in, and how far through setting up a profile it has got.
Collected only once a named feature is switched on
None of the following is collected today, because none of these features runs. They are listed so you can see the whole shape of it before any of it starts.
- Jobs and the detail in them, matches and their scores and explanations, expressions of interest, and the record of an introduction and the contact details released with it.
- Blocking or blacklist preferences.
- Messages between two members, once there is messaging.
- Feedback answers and the MyFloorPro Score built from them.
- Complaints, the findings we make on them, and appeals.
- Billing and fee records for our own fees, and the tax records that go with them.
- Documents or photos you upload. There is nowhere to upload one today, anywhere in the product.
- Agreement to receive marketing, and the suppression record that keeps it stopped once you ask us to stop. Section 13 explains where that stands.
- Invitations you send. The email address of a colleague you invite, the role you are giving them, and the branch you are putting them in.
Licence numbers. We do not ask for one. The credential screen says so, no field asks for one, and nothing the platform writes stores one. We record the type of credential, who issues it, when it expires and whether we have checked it, and we stop there.
What people type anyway. Several boxes take free text, and an email to us takes anything at all. So a licence number, somebody’s home address, a customer’s name or a phone number can reach us even though we never asked for it, whether in a profile summary, a portfolio link, a support email or, later, a message or an uploaded document. We would rather say what happens then than pretend it cannot happen. It is held under this policy like anything else, it is not used for anything other than the reason it arrived, we do not copy it into an audit record, and you can ask us to remove it under section 16. Please do not put somebody else’s personal information into a free text box when the work does not need it.
4. Types of information
The Privacy Act 1988 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether the information or opinion is recorded in a material form or not.
Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
We generally do not collect Sensitive Information.
We will not use Sensitive Information for direct marketing.
5. Children and age requirements
MyFloorPro is intended for use by individuals aged 18 years or over. We do not knowingly collect Personal Information from individuals under 18.
6. How we collect it
Three ways, and no others.
- From you. We may collect Personal Information from you whenever you input such information into the website or the application, or otherwise provide it to us: when you register, when you fill in your profile, when you answer our pilot questions, and when you email us.
- From other people in your organisation. Colleagues can edit shared organisation details, so some of what your organisation shows may have been typed by one of them rather than by you.
- Generated by the platform. Audit records, records of attempts to sign in, and the record of which policy version you accepted are created by the system as you use it.
Where reasonable and practicable, we collect your Personal Information from you only. However, sometimes we may be given information from a third party. In those cases, we will take reasonable steps to make you aware of the information that was provided by the third party.
We do not buy personal information from anybody, and we do not gather it by scraping other websites.
7. Why we use it
Working today:
- To create your account and let you sign in.
- To build the profile you fill in, and to show it to the people section 9 says can see it.
- To let the people in your organisation work on the same records, with the right ones able to edit and remove.
- To answer you when you contact us.
- To keep accounts secure, to slow down attacks, and to look into misuse.
- To keep a record of who changed what, so a disagreement about what happened can be settled by looking rather than by arguing.
- To work out what to build next, using what founding members tell us.
- To meet our own legal, tax and record keeping obligations.
Once the marketplace is switched on, and not before, we will also use it to match jobs with installers and produce a shortlist, to release contact details between two parties after the required step is completed, to charge and receipt our own fees, to record feedback and produce the MyFloorPro Score, and to look into complaints.
Two different kinds of money, and only one of them involves us. A flooring business may pay us our own introduction, marketplace or software fees, once those features are switched on, and we show you the amount before you commit to it. An installer is not charged to find flooring work, to rank for it, to win it, or to be introduced to a flooring business, so we have no reason to use an installer’s information to sell them access to work.
Payment for the flooring work itself is a separate thing entirely, and it stays between the flooring business and the installer. We do not currently collect, hold, transfer or distribute payment for the flooring work, so we hold no bank details, no invoices and no payment records for it at all. Our own fees are not being charged yet either. Stripe is planned for collecting our own fees when that starts, and it is not in use today.
8. Automated matching, shortlists and ranking
Not switched on yetThis section describes something switched off. It is written now because matching is the part of the platform where something about a person is worked out partly by a machine, and that deserves saying out loud before it runs.
Matching will work in two stages. First, blockers. If an installer cannot do the work, they are excluded outright: the flooring category is not one they offer, the site is outside every area they travel to, they have told us they are not available for those dates, a credential the job requires is missing or out of date, or the job needs a bigger crew than they have. A blocker is a yes or no test, and it is recorded with its reason.
Second, scoring. Everybody left is scored on weighted factors: how well the flooring categories and skills line up, specialist skills the job asks for, when they have room for the work, distance from the site, experience in that kind of building, credentials we have checked and that are current, floor preparation, equipment, track record on the platform, how reliably they respond and finish, any previous work with that business, and whether the size and payment terms of the job fit what the installer has told us they want. Those are the factors, and there is no other one hiding behind them. The weights are ours, they are held as configuration with a version stamped on it, and an old score always shows the weights it was actually worked out with.
What comes out is a shortlist with a plain explanation attached: the score, what matched, what was missing, and any blocker that applied. Both sides see that explanation. A new installer is not buried for having no history with us, because track record and behaviour score neutrally until there is enough to go on.
Nothing about a subscription can reach the scoring. Paying us cannot improve a score, a place in a list, or how often work is put in front of an installer.
The MyFloorPro Score, when it exists, is a reputation figure built from recorded events, so every part of it can be traced back to something that happened and explained to the person it is about. Some events are left out on purpose. Paying for a subscription must never affect it. Neither does how complete a profile is: a finished profile is not a good score, and a score cannot exist at all before there have been introductions and feedback about them.
No decision with a legal or otherwise significant effect on you is made only by a machine. Matching produces a shortlist and the reasons for it. A person at the flooring business then decides who to speak to, who to engage, and on what terms. We do not make that decision, and neither does the software.
The same rule holds on our side of it. Nothing fully automated engages a person, refuses anyone work, makes a finding about somebody’s conduct, restricts a feature, or suspends or closes an account. A person makes those decisions, and our terms of use set out how to ask us to look at one again.
Where MyFloorPro uses a computer program to make, or substantially and directly contribute to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, we will provide information in this Privacy Policy about the kinds of Personal Information used by that system and the kinds of decisions made or substantially contributed to by it, as required by applicable privacy law.
If a shortlist result matters to you, ask us and we will tell you what applied to you and why. If a record behind it is wrong, correct it in your profile or ask us to fix it, and the result changes with it.
We will review this section as our matching, ranking, security and marketplace management systems develop to ensure that it accurately reflects how automated systems are used by MyFloorPro.
9. Who can see your profile
Today, nobody outside your own business and ours. There is no public directory, no profile page anyone can browse, and no button that publishes anything, because none of that is built. What you write is visible to you, to the colleagues in your organisation whose role lets them see it, and to our own people where they need it to answer you or look into a problem. It is not shown to any other member, and it is not indexed by a search engine.
That is the whole picture during the Founding Network stage. If you are wondering whether filling in a profile puts you in front of flooring businesses yet, it does not.
When jobs and matching are switched on, that changes in two steps, and both are described here before either happens.
- Before an introduction. The other side sees a profile with the identifying parts removed: the flooring you lay, the areas you cover, crew size, equipment, the credentials we have checked and exactly what we checked, and a suburb, state and postcode. It does not include your name, your business or trading name, your phone number, your email address, your website, your ABN, or the street address of a site.
- After an introduction. Contact details are released to both sides at once, and only when all of this is true: both sides have shown real interest or one has been selected, the feature is switched on, any fee has been disclosed to and paid by the flooring business, and the introduction has been written to our audit log. An installer never pays for that release. Every release is written to the audit log.
10. Who we share it with
- The other side of an introduction. Nobody is shown to anybody yet. Section 9 says what will be shown, and when.
- Other people in your organisation. Your colleagues can see your organisation’s records, according to the role they hold.
- Our own people. Our staff can see what they need in order to answer you or to look into a complaint, and once there is messaging that can include messages between two members. What a member of staff does on somebody’s behalf inside the application is written to the audit log. Access is not controlled in one place only: our people can also reach information through the database, through server logs and through the mailboxes below, and those routes are controlled by who holds an account and a key rather than by a screen in the application. The platform administration console is closed in every environment while we finish additional protection for signing in to staff accounts, so nobody is using it today.
- Suppliers who help us run the platform. Four of them, and what each one does is below.
- Supabase. The database and the accounts system. Your account, your organisation and your profile live here.
- Vercel. Hosting for this website and for the application, and the page view and page speed measurements described in section 19.
- Resend. Sends the automated emails: confirming your address, resetting a password, and inviting a colleague. Those come from no-reply@myfloorpro.com.au, which is an automated sender rather than a mailbox anybody reads.
- Google Workspace. Our own business email and documents. The support@myfloorpro.com.au, privacy@myfloorpro.com.au and accounts@myfloorpro.com.au mailboxes are here, so anything you send to support, to privacy or about your account or billing is handled in Google Workspace, along with our internal business communications.
Planned and not in use: Stripe, for collecting our own fees when fees are switched on, and PostHog, for more detailed product analytics. Neither has any of your information today.
Each supplier may handle your information only to do the job we engaged them for, and none of them may use it for their own purposes.
- Where the law requires it. A court, a regulator, the police or another body, where we are required or authorised by law to hand something over.
We do not sell personal information, and we do not pass it to another company so they can market to you.
11. Information handled outside Australia
Some of our suppliers are companies outside Australia, and some of them handle information outside Australia. Before we disclose your personal information to one of them, we take the step the Australian Privacy Principles require of us: a written contract that binds the supplier to handle it only for us and to protect it in a way consistent with those principles.
Here is what we can actually stand behind, rather than a list of countries we have guessed at.
- The database is in Sydney. The database and accounts system, which is where your account, your organisation and your profile actually live, runs in Supabase’s Sydney region, in Australia.
- The companies themselves are overseas. Supabase, Vercel and Resend are United States companies, and Google Workspace is run by Google. Being hosted in Sydney does not change where a company and its staff are, and a supplier’s own people may reach information from outside Australia in the course of running or supporting the service.
- What each supplier publishes. Supabase’s privacy policy says personal information may be transferred to, stored and processed in a country other than the one it was collected in. Vercel says it may store, process and transmit information outside your country of residence. Resend publishes a list of the other companies it relies on, and every one of them is in the United States. Google publishes a list of the companies it relies on and where each of them works, and it covers many countries.
- Email and analytics. Email we send you is handled by Resend and reaches you through their sending infrastructure. Anything you send to one of our mailboxes is handled in Google Workspace. Page view and page speed measurements go to Vercel. None of those three is limited to Australia.
What we will not do is invent the rest. The exact countries a supplier stores or processes in vary by service and change over time, and we are not going to publish a list we cannot stand behind. Each of those four companies publishes its own current list of the suppliers it uses and where they are, and we will point you to the right page if you ask. If this matters to you before you register, write to privacy@myfloorpro.com.au and we will tell you what we know and what we do not.
12. Messages, and when a person reads one
Not switched on yetThere is no messaging on MyFloorPro today, so nothing in this section is happening. It is written now because reading somebody’s messages is the kind of thing that should be described before it can occur, not afterwards.
Once there is messaging, we do not read it as a matter of course. Two things can put a message in front of a person. The first is a complaint: if somebody complains about what happened on MyFloorPro, our staff can look at the records that complaint needs, and messages between the two members can be part of that. The second is contact details: before an introduction is made, contact details are not meant to be exchanged, and a message that looks like it carries a phone number, an email address or a business name is flagged for a person to look at.
A pattern match is not a finding, and it never acts on its own. It does not block the message, it does not charge anybody, and it does not restrict, suspend or close an account. A person decides, after looking at both accounts and our own records. Our terms of use say what happens next and how to ask us to look at it again.
Every time one of our people opens a message on this basis it is written to the audit log, with who did it and when.
13. Marketing and other messages
There are two kinds of email, and only one of them is optional.
The first is the email the platform has to send in order to run your account: confirming your email address, resetting your password, inviting you or telling you about something that has happened on your account, and anything we have to send you for a legal, security or safety reason or because of something you have bought. Those are not marketing and you cannot switch them off while you hold an account, but they are limited to what running the account actually needs. We do not use that channel to sell you something.
The second is marketing, and it is different in every way. We send it only if you have agreed to receive it, we say who it is from, and every message carries a way to stop it. Ask us to stop and we will, and we intend to keep a suppression record so that a later import cannot quietly start it again. The Spam Act 2003 applies to us and we intend to stay on the right side of it.
Where this stands today, because it matters. We are not sending marketing. The place to record that you agreed, and the suppression list that keeps a withdrawal working after an account closes, are both built in the database, but nothing in the running application writes to either of them yet, and the application’s own database login has no access to them at all. So treat this section as what we will do rather than what is running: no marketing goes out until the consent record and the suppression list are wired up and working. Until then, ask us at privacy@myfloorpro.com.au and a person will action it.
14. How we keep it safe
What is actually in place, without dressing it up:
- Traffic is encrypted in transit. A session is a cookie that scripts in the browser cannot read, and that is only sent over an encrypted connection.
- The application reaches the database as a role holding only the permissions it needs, table by table. It owns nothing, and it cannot create tables, empty them, or alter the audit log.
- Row level security is on for every table, and the direct web route into the database is switched off, so the ordinary way in is through our own server code.
- The application can add to the audit log and read it. It cannot change or delete an entry.
- Signing in, registering, resetting a password and resending a confirmation are all rate limited, both per account and per address.
- Every action that matters is authorised on the server. What the browser chooses to show or hide is treated as decoration.
- There is nowhere to upload a document today. When there is, files will go to private storage with no public link, and reading one back will need a permission check and a link that expires.
Two limits worth stating plainly, because a security section that only lists strengths is not worth reading. Keeping one organisation’s records apart from another’s is enforced by authorisation checks in our server code, and strengthening that inside the database itself is work we have not finished. And our platform administration console is closed in every environment until we have finished additional protection for signing in to staff accounts.
Everything above reduces risk. None of it removes risk, and we are not going to tell you otherwise. If we get it wrong, section 20 says what we will do about it.
15. How long we keep it
This section says what actually happens today, which is not the same as what we would like the timetable to be. Section 18 of our terms of use says the same thing in the same words.
Three periods we can state, because each one is real:
- Records of attempts to sign in are ordinarily kept for about 24 hours. The code that writes them clears the older ones, so this happens without anybody doing anything.
- Financial, billing and tax records are kept for at least seven years, or longer where the law requires it.
- Records of the policy versions you accepted, of the introductions we made, and of complaints, disputes and marketplace transactions are kept for as long as we reasonably need them to establish what occurred and to comply with our legal obligations. Our audit log sits in this group.
Everything else about ordinary personal information works like this:
- When an account closes, its profile stops being displayed.
- Personal information we no longer reasonably require is deleted or de-identified.
- Deletion or de-identification may be delayed where the information is reasonably required for legal, tax, security, fraud prevention, consent, transaction, complaint, dispute or record preservation purposes.
- You can ask us to delete or de-identify your personal information at privacy@myfloorpro.com.au.
- We will explain what we retain and why.
- Our providers keep backups. Information we have deleted may remain in a backup until that backup ages out under the provider's applicable retention cycle.
Where Personal Information is no longer required for a purpose permitted by law, we will take reasonable steps to destroy or de-identify it, subject to any legal, accounting, security, fraud prevention, dispute resolution or other legitimate retention requirements.
What we are deliberately not promising, and why. We are not going to publish a number of days for deleting a closed account, clearing an expired invitation, ageing out a backup or dropping a security log. No scheduled process does any of those things today, and a deadline nobody can meet is worse than no deadline: it is a claim about software, made to somebody deciding whether to hand that software their business records. There is no automated deletion. A person carries this out when you ask, and tells you in writing what went, what stayed and why. Section 16 says how to ask. If that changes, this section changes with it under section 21, and not before.
One thing we will not claim. Our audit log is written so that the application can add to it and never change it, and that is worth having. It is not the same as saying a record can never be removed: where the law requires something to be deleted, or a retention period above has run out, it goes, and being in an append only log does not put it beyond reach.
Closing an account is not the same as erasing everything about it, and we would rather say that than imply otherwise. What stays, and why, is the list above.
16. Closing your account, and asking us to delete
You can close your account at any time by emailing accounts@myfloorpro.com.au, and you do not have to give a reason. Section 15 of our terms of use says the same thing about what closure does.
On closure your profile stops being displayed. Ask us to delete the ordinary profile information behind it, or to hold it in a form that no longer identifies you, and we will do that for everything we no longer reasonably require, on the basis set out in section 15. We do not run a timetable that does it for you, and section 15 says why we are not going to claim otherwise.
Some records stay. Consents to a policy, the audit log, records of introductions and fees, complaints and findings, and financial and tax records are kept on the basis set out in section 15, because they are what we would need in order to answer a question or a complaint about something that already happened, and because some of them we are required to keep.
You can ask us to delete your information at privacy@myfloorpro.com.au. There is no button in the product that does it, so a person does it, and we will tell you in writing what was deleted, what has to stay, and why.
17. Getting a copy, and correcting it
You can ask for a copy of the personal information we hold about you, and you can ask us to correct it. Most of it you can correct yourself by editing your profile. For the rest, ask privacy@myfloorpro.com.au.
The Australian Privacy Principles:
- permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12); and
- allow you to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13).
We may need to check you are who you say you are before we hand anything over. Then:
- we acknowledge your request within five business days;
- we aim to give you access, make the correction, or give you a written decision within 30 calendar days;
- if we refuse, we explain why in writing;
- and we tell you what you can do about that, including complaining to us under section 18 and, where it has jurisdiction, to the Office of the Australian Information Commissioner.
We take longer than 30 calendar days only where the request is complex enough to reasonably need it. If that happens we tell you before the 30 days is up, say why, and give you a date to expect an answer.
There is no fee for making a request. Where the law allows us to charge for giving you access, any charge will be reasonable, never excessive, and told to you before we do the work so you can decide. We do not charge for making a correction.
Two things we may not be able to hand over or change. One is another person’s information caught up in the same record. The other is the audit log, which is a history of what was done and is not rewritten, because a history that can be edited afterwards is not a history. We will not pretend otherwise by promising to change one. What we will do is correct the record the entry was about, and attach your correction or a note of your view to the historical entry where that is appropriate, so anyone reading it later sees both.
18. Making a complaint
Tell us first, at privacy@myfloorpro.com.au. Say what happened and what you would like done about it. Then:
- we acknowledge it within five business days;
- we investigate it fairly, and we look at our own records;
- we aim to give you a written response, with our reasons, within 30 calendar days;
- where we reasonably need longer, we explain why and give you a date to expect a response;
- and where somebody other than the person who handled the original matter can look at it, they will.
We may seek further information from you to clarify or investigate your complaint. If we agree that your complaint is well founded, we will take appropriate steps to address the issue.
We ask that you complain to us first and allow us a reasonable chance to respond. If you do not receive a response within 30 days, or you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner, the OAIC, at oaic.gov.au, where it has jurisdiction. We cannot promise what the OAIC will do with a complaint, because that is their decision and not ours.
None of this stops you getting your own legal advice, or using any other right the law gives you, at any time.
19. Cookies and analytics
We may use cookies and similar technologies when you access or use the MyFloorPro website, application or related services. Cookies are small data files stored on your device that can help us recognise your browser or device, remember information about your visit and understand how our services are being used.
Essential cookies. These are necessary for the operation, security and functionality of the platform. They may be used for purposes such as account authentication, maintaining login sessions, security, fraud prevention and remembering important platform settings. That is the kind the application sets: the cookies it needs to keep you signed in and to stop a form being submitted from somewhere it should not be. There are no advertising cookies and no tracking pixels belonging to another company. No custom analytics events are sent from either the website or the application, so there is no place for an email address, a user or business reference, or a token to be attached to one.
You may be able to manage or disable cookies using your browser settings. Disabling certain cookies may affect the availability or functionality of parts of the platform. Where consent is required by applicable law for the use of particular cookies or tracking technologies, we will obtain that consent before using those technologies.
Now the part that is easy to overstate, so here it is in three separate pieces: what is in the code, what is switched on, and what the measurement itself receives.
- This website. The code for Vercel Web Analytics, which counts page views, and for Speed Insights, which measures how quickly pages load for real visitors, is in place.
- The application. The equivalent page view code is in place there too, with the extra narrowing described below. Speed Insights is deliberately not being added there.
- Whether anything is being counted. Measurement also has to be turned on in our Vercel account, and until it is, no page view is counted and nothing is sent. When we turn it on, what happens is what this section describes, and this section will say so before the measuring starts.
What we send, once it is on. The address of the page, and nothing after the question mark in it. Everything after the question mark is thrown away before anything is sent, campaign tags on a link included, so a page view cannot be tied back to the particular email or advert that brought you here.
The application narrows it further, because the addresses of its own pages are not harmless. Identifiers that sit in the address itself, the code in an invitation link, and the reference for a business or one of its profiles, are replaced with a label naming the kind of page instead of the thing. Three steps are not counted at all: confirming an email address, recovering an account, and setting a new password. The addresses behind those carry one time codes, and whether you have lost access to your account is not ours to measure.
What Vercel adds, which is the part we do not control. Their own documentation says that a data point may also carry the referring page, an approximate location worked out from the network address, the device type, the operating system and the browser, and that a visitor is told apart by a value worked out from the request itself, which is discarded after 24 hours. No cookie is set for it. So this is more than a bare count of pages, and less than a profile of a person, and we would rather describe it that way than claim it can identify nobody.
What it never carries is anything we chose to put there, because we put nothing there: no email address, no name, no user, organisation or business reference, and no token. Anything more detailed than the above is planned and not in use. When that changes, this section changes with it.
20. If there is a data breach
The Notifiable Data Breaches scheme sits inside the Privacy Act 1988, and whether it applies to us as a matter of law is the same open question as in section 1. Our position does not depend on the answer.
- Where the scheme applies to us, we comply with it.
- Where it does not, we intend to follow an equivalent process anyway: assess it the same way, and notify where serious harm is likely.
Either way, if personal information we hold is lost, or is seen or disclosed by somebody who should not have it, this is what we do. We investigate it, contain it and fix what let it happen. We work out what information is caught up in it and whose it is. Where it is appropriate, and certainly where serious harm is likely, we tell the people affected, in plain words, what happened and what to do about it. And we notify the OAIC where we are legally required to, or where it has jurisdiction and would accept the notification. We will not sit on it while we decide how it looks.
What we will not promise is a notification to a regulator that has no jurisdiction over us, because that would be a promise we could not keep. Nor is our internal step by step response plan finished yet. The commitments above hold from the day this policy takes effect; writing the runbook that makes them fast is work to be done before the pilot opens.
21. Changes, and the version you agreed to
This is version 2. Every version has a number, and both the number and the date it took effect are recorded in the platform. When you accept a policy at registration we record which version you accepted, when, and the IP address it came from. That record is what makes the acceptance mean something later.
If we change something that matters, we will not rely on you noticing. We will give you at least 30 calendar days’ notice wherever that is reasonably practicable, explain the change in plain language, and ask you to accept the new version before you carry on using the part it materially affects. Until you accept it, the version you accepted is the one that applies to you. A change we need to make straight away for a legal obligation, for safety, to prevent fraud or for cybersecurity may apply sooner, and we will tell you as soon as we reasonably can and say why.
A small correction that changes nothing of substance, such as a typo, a broken link or clearer wording, does not need a fresh acceptance and does not get a new version. We record it in the version history either way, so you can ask us for the version you accepted and we can produce it. We cannot make a material change to what you have already agreed to simply by editing this page, and a material change does not reach back and change something that already happened.