Photo Mar 08 12 25 34 PM

Privacy Policy

1. Introduction

This Privacy Policy explains how Optimo Awnings Northern Pty Ltd (ABN 51 612 947 261) ("Optimo Go", "we", "us", "our") handles personal information in connection with the Optimo Go platform, websites, and related services (the "Platform").

We are bound by the Privacy Act 1988 (Cth) (the "Privacy Act") and the 13 Australian Privacy Principles ("APPs"). This policy describes how we collect, use, disclose, store, and secure personal information, and how you can access, correct, or complain about our handling of it.

By using the Platform, you agree to the practices described in this policy. If you do not agree, please do not use the Platform.

2. Our two roles: customer data vs. account data

Optimo Go is a business-to-business platform. Our role under the Privacy Act differs depending on the information involved:

  • Where we act on behalf of our customers ("Customer Data"). Our customers are the organisations ("Tenants") that subscribe to the Platform. When a Tenant uploads or enters information into their workspace, including information about their own staff, contractors, customers, vehicles, incidents, and jobs, the Tenant determines how that information is handled. We process that Customer Data only to provide the Platform under our agreement with the Tenant and on the Tenant's instructions. The relevant Tenant's own privacy policy governs that data, and you should contact that Tenant to exercise your privacy rights in respect of it. This policy describes how we protect Customer Data, but the Tenant is responsible for collecting it lawfully and for responding to access and correction requests about it.
  • Where we act on our own behalf ("Account Data"). We collect and handle some information for our own purposes, for example, the contact and billing details of the people who administer a Tenant account, and technical data about how the Platform is used. For that information, we are the entity responsible under the Privacy Act, and this policy applies directly.

If you are an individual whose data appears in a Tenant's workspace and you are unsure who to contact, you may reach out to us using the details in Section 16 and we will direct you to the relevant Tenant.

3. The personal information we collect

Depending on how you interact with the Platform, we may collect the following categories of personal information:

Account and identity information

  • Name, job title, business email address, and business phone number.
  • Username and the organisation you belong to.
  • Profile details you choose to provide.

Authentication and security information

  • Passwords (stored only as salted, hashed values, we never store them in plain text).
  • Passkey / WebAuthn credentials and two-factor authentication (TOTP) configuration.
  • OAuth identifiers where you sign in via a connected identity provider.
  • Session tokens and audit-log records of security-relevant actions.

Billing and payment information

  • Billing contact details, subscription plan, and invoice history.
  • Payment card details are collected and processed directly by our payment provider, Stripe, and are not stored on our own servers. We retain only limited information such as the card brand, last four digits, and transaction references.

Content you create or upload in the Platform

  • Records relating to jobs, work orders, quotes, customers, scheduling, incidents, risk assessments, inventory, purchasing, and uploaded documents and files. This may include personal information about you or third parties that a Tenant chooses to record. As noted in Section 2, this is usually Customer Data.

Location and telematics information

  • Where the telematics features are used, we collect GPS location, route, trip history, and vehicle/device identifiers from connected tracking hardware. Location data is sensitive and can reveal the movements of identifiable individuals (such as drivers). It is collected and used only to provide the tracking, reporting, and scheduling features to the relevant Tenant, and is treated as Customer Data under the control of that Tenant. Tenants are responsible for notifying and, where required, obtaining consent from the individuals being tracked.

Communications information

  • Messages, notifications, SMS, and emails sent through or in connection with the Platform, and records of your support requests and our correspondence with you.

Technical and usage information (collected automatically)

  • IP address, device and browser type, operating system, and approximate location derived from IP.
  • Log data, feature usage, timestamps, and diagnostic/error reports.
  • Cookies and similar technologies (see Section 6).

We generally do not seek to collect sensitive information (as defined in the Privacy Act) about you for our own purposes. Where a Tenant records sensitive information in their workspace, they are responsible for having a lawful basis to do so.

4. How we collect personal information

We collect personal information:

  • Directly from you — when you register, configure an account, communicate with us, or use the Platform.
  • From the Tenant — when an organisation invites you, provisions your account, or records information about you.
  • Automatically — through your use of the Platform, including via cookies, log files, and connected telematics devices.
  • From third parties — such as identity providers (OAuth sign-in), our payment provider, and integrations you or your Tenant connect (for example, accounting integrations).

Where it is reasonable and practicable, we collect personal information directly from the individual concerned. Where we receive personal information we did not solicit, we handle it in accordance with APP 4.

5. Why we collect and how we use personal information

We use personal information for the following purposes:

  • To create, authenticate, and secure user accounts.
  • To provide, operate, maintain, and improve the Platform and its features.
  • To process subscriptions, billing, and payments.
  • To provide customer support and respond to enquiries.
  • To send service and transactional communications (for example, security alerts, account notices, and document or workflow notifications).
  • To monitor, diagnose, and resolve technical issues, and to detect and prevent fraud, abuse, and security incidents.
  • To produce reports and analytics for Tenants within their own workspace.
  • To comply with our legal obligations and enforce our terms.

We will only use or disclose personal information for the purpose for which it was collected, a directly related secondary purpose you would reasonably expect, or as otherwise permitted under the Privacy Act or with your consent.

6. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Platform, and understand usage. Some cookies are strictly necessary for the Platform to function (for example, authentication and session cookies). You can control non-essential cookies through your browser settings, but disabling necessary cookies may prevent the Platform from working correctly.

7. Disclosure of personal information

We do not sell personal information. We disclose personal information only as needed to operate the Platform, and to the following categories of recipients:

  • The relevant Tenant and its authorised users, in respect of data within that Tenant's workspace.
  • Service providers and sub-processors who help us run the Platform (see the table below), under contractual obligations to protect the information and use it only for the services they provide to us.
  • Professional advisers, auditors, and insurers, where reasonably necessary.
  • Regulators, law enforcement, or other parties where required or authorised by law, or to protect our rights, safety, or property.
  • A successor entity in connection with a sale, merger, or restructure of our business, subject to this policy.

Sub-processors

ProviderPurposeNotes on data location
Amazon Web Services (AWS)Cloud hosting and storageHosted in Australia (Sydney, ap-southeast-2)
Amazon SESOutbound email deliveryAWS infrastructure
StripePayment processing and subscription billingMay process data overseas, including the United States
XeroAccounting / ERP integration [only where a Tenant connects it]Australia / New Zealand
TwilioSMS notificationsMay process data overseas, including the United States
SentryError monitoring and diagnosticsMay process data overseas, including the United States
MapboxMaps and geocodingMay process data overseas, including the United States
Google FontsWeb font deliveryMay log IP addresses when fonts are served


8. Overseas disclosure (APP 8)

We store primary Customer Data and Account Data in Australia (AWS Sydney, ap-southeast-2). However, some of our sub-processors (see Section 7) may store or process limited personal information outside Australia, including in the United States.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the APPs, generally through contractual protections. Where you consent to an overseas disclosure, or it is otherwise permitted under APP 8.2, those steps may not apply.

9. Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including:

  • Encryption of data in transit (TLS) and at.
  • Hashed and salted password storage, support for passkeys (WebAuthn) and two-factor authentication.
  • Logical separation of each Tenant's data through per-tenant database schemas.
  • Role- and permission-based access controls, audit logging, and least-privilege access for our personnel.
  • Network, application, and infrastructure security controls provided through AWS.

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential.

10. Data retention

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, to provide the Platform, and to meet our legal, accounting, and reporting obligations.

  • Account Data is retained for the life of the account and for a reasonable period afterwards.
  • Customer Data is retained on behalf of the Tenant and is dealt with according to our agreement with that Tenant. On termination, Customer Data is deleted or returned in accordance with that agreement, subject to any legal retention requirements.

When personal information is no longer needed, we take reasonable steps to destroy it or de-identify it.

11. Direct marketing (APP 7)

We may send you information about the Platform, including new features and service updates. Where the law requires consent, we will obtain it. You can opt out of marketing communications at any time using the unsubscribe link in the message or by contacting us (Section 16). We will still send you non-promotional service and transactional messages necessary to operate your account.

12. Accessing and correcting your information (APPs 12 & 13)

You may request access to, or correction of, the personal information we hold about you for our own purposes (Account Data). To do so, contact us using the details in Section 16. We will respond within a reasonable period and may need to verify your identity. There is generally no charge for an access request, though we may charge a reasonable cost for retrieval in some cases. If we refuse access or correction, we will tell you why in writing and explain how to complain.

For personal information held within a Tenant's workspace (Customer Data), please direct your request to the relevant Tenant, who controls that information. We will assist the Tenant to fulfil your request where appropriate.

13. Data breaches

We have processes to detect, assess, and respond to data breaches. If a breach involving personal information is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme. Where a breach concerns Customer Data, we will also notify the relevant Tenant promptly so they can meet their own obligations.

14. Third-party links and services

The Platform may link to or integrate with third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with personal information.

15. Children's privacy

The Platform is intended for use by businesses and their personnel, and is not directed to children. We do not knowingly collect personal information from children for our own purposes.

16. Changes to this policy

We may update this policy from time to time. We will post the updated version on the Platform and change the "Last updated" date above. Where changes are significant, we will take reasonable steps to notify you. Your continued use of the Platform after a change takes effect constitutes acceptance of the updated policy.

17. Contact us and complaints

If you have questions, requests, or a complaint about how we handle personal information, please contact our Privacy Officer:

Optimo Awnings Northern — Privacy Officer Email: privacy@optimogo.app Post: 6 Union Street, Longford, TAS, 7301

We will acknowledge your complaint and aim to respond within [e.g. 30 days]. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001