Privacy Policy
Template draft — last updated August 2026
This is a drafted template, not a finalised legal document.It has not yet had a legal review. Per this project's own build plan, a real legal review is required before this policy is relied on for a broader customer base (Phase 2) — do not treat this page as compliant advice until that review has happened and every [placeholder] below has been completed with real business details.
Who this policy covers
This policy applies to [FreightFix legal business name and ABN](“FreightFix”, “we”, “us”), operator of the FreightFix freight invoice audit service, and describes how we handle personal and business information you provide when you use it.
What we collect
- Account details: business name, and the email address you sign up and log in with.
- A forwarding email address we generate for your account, and any invoices sent to it or uploaded directly through the app.
- The content of your uploaded Australia Post invoices: line-item billing data (weights, dimensions, zones, surcharges, charges, and amounts), which we parse and store to run the audit.
- Records our system generates from that data: flagged billing discrepancies, drafted dispute letters, and any recovery outcomes you record.
- Billing information for our own gain-share fee (processed by Stripe — see “Third parties” below; we do not store your card details ourselves).
We deliberately do not ask for or store your Australia Post account credentials, and V1 of this service never logs into a carrier portal on your behalf.
Why we collect it
- To parse and audit your invoices for billing errors.
- To draft dispute correspondence and a structured export for you to review and submit yourself.
- To calculate our gain-share fee against confirmed recoveries, and to invoice you for it.
- To send you alerts about new findings, dispute updates, and a weekly activity summary.
Third parties we share data with
We use a small number of specialist providers to run the service — we don't sell your data, and we don't share it with anyone else:
- Supabase — our database, file storage, and login provider, hosted in the Sydney (ap-southeast-2) region.
- Postmark — sends transactional email (confirmations, alerts, your weekly digest) and receives invoices you forward to your FreightFix address.
- Google (Gemini API)— used only to extract line-item data from PDF invoices that don't come as a structured file. We use a separate, paid-tier API key for any real customer invoice specifically so it is not used to train Google's models — never a free-tier key for real customer data.
- Stripe — processes our gain-share billing once that feature is live for your account; Stripe, not FreightFix, holds your payment details.
None of these providers are permitted to use your data for anything other than providing their service to us.
How long we keep your data
We keep your data for as long as your account is active. If you cancel, we retain it for 90 days (in case you want to reactivate, or in case a support or carrier dispute needs it), then permanently delete it. If you'd like your data deleted sooner, contact us and we'll action it within 30 days.
Security
Your data is encrypted at rest and in transit. Access is enforced at the database level, not just in application code — each customer's data is isolated so that even a bug in our own code can't leak one customer's invoices to another.
Your rights
You can ask us what data we hold about you, ask us to correct it, or ask us to delete it (see “How long we keep your data” above). You can cancel your account at any time from your account settings.
Privacy Act 1988 and the Australian Privacy Principles
The Australian Privacy Principles (APPs) apply in full to businesses with turnover over A$3 million, or those handling health or credit information. As an early-stage business, we likely fall under the small-business exemption today — but we handle your data in line with the APPs regardless, because that exemption is expected to be repealed in the near future, and because you're trusting us with real financial records either way.
Changes to this policy
If we make a material change to how we handle your data, we'll email the address on your account before it takes effect.
Contact
Questions about this policy: [contact email].