Privacy notice
Summary
BuyersIQ handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This page is a pre-review draft: the operational detail on our Security & data handling page describes architecture today; this notice will be consolidated after legal review.
Personal information we collect
Depending on how you use the product, categories may include:
- Identity and account: name, email address, phone number (including for one-time passcodes), organisation or firm name where supplied, authentication identifiers held by Supabase Auth.
- Review content:files you upload (typically PDF contract and disclosure packs), extracted text and structured fields derived from those files, findings, questions you submit to Q&A, and technical metadata (page counts, file size, hashes) for integrity and billing evidence.
- Billing: billing contact details, Stripe customer and payment references, invoices, transaction timestamps — we do not store full card numbers on our infrastructure when Checkout handles card data.
- Communications: messages you send through support or partnership forms, email headers, and optional phone/SMS delivery metadata when OTP is enabled for your account.
- Technical and security: IP-derived security signals, device/browser type, coarse location from network data where needed for fraud prevention, audit logs of administrative actions, application error reports where you consent to telemetry.
- Marketing preferences: subscription to product updates where you opt in, recorded through the preference centre or campaign tooling once live.
Why we use it
Primary purposes include:
- providing AI-assisted review, evidence mapping, and reporting you requested;
- billing, accounting, and fraud prevention;
- security monitoring, abuse prevention, and fulfilling legal obligations;
- improving reliability and safety of models and rules (including aggregate or de-identified analytics where permitted).
Service providers
We use subprocessors that process personal information on our behalf, including (as at the draft date):
- Supabase — authentication, Postgres database, storage for uploaded PDFs, realtime channels;
- Anthropic — AI inference over the documents you submit for review (see Security page for retention details);
- Stripe — payments, billing portal, and tax invoices;
- Resend — transactional email (receipts, security notices, product mail where enabled);
- Mapbox — maps when a feature surfaces property location;
- Market-data providers — as enabled per phase (for example census, schools, environmental overlays); each integration is listed on the Security page when it processes personal or property-linked data.
Contracts and data-processing terms follow our vendor risk process; this list is not exhaustive and will move to a published subprocessor table.
Retention and controls
Default retention targets and your export or deletion rights are described under Account & data in the product and on the Security page (AI provider processing, storage, and local extracts). Where you request deletion subject to any statutory hold, we will delete or de-identify within the periods stated after review — this paragraph will cite exact day counts once counsel approves.
Notifiable data breaches
Where we become aware of unauthorised access or loss that is likely to result in serious harm, we will assess under the Notifiable Data Breaches scheme, notify the OAIC and affected individuals when required, and document remedial steps.
Access, correction, complaints
You may request access to personal information we hold and seek correction under APP 12 and APP 13. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner. The OAIC publishes guidance on the APPs ( Australian Privacy Principles guidelines) and how to lodge a complaint (Lodge a privacy complaint).
Privacy contact
Privacy requests and breach reports: privacy@buyersiq.com.au. For other matters, use Contact and pick the appropriate path.