A.C.N. 696 624 987 Pty Ltd (ABN 85 696 624 987), trading as Stagex ("Stagex", "we", "us") is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform.
1. Information We Collect
1.1 Information You Provide
Account information: name, email, phone number, company name, ABN, and role within your organisation.
Business data: job details, client records, quotes, invoices, milestones, and escrow transaction data.
Payment information: billing name and address. Card numbers are processed by Stripe under PCI-DSS Level 1 — we do not store raw payment credentials.
Verify ABNs, licences, and insurance for Trust Badge eligibility.
Detect and prevent fraud, abuse, and security breaches.
Comply with Australian legal obligations including tax, AML/CTF, and financial reporting.
Send marketing communications — you may opt out at any time via account settings.
3. Data Storage and Security
Stagex’s primary application database is currently hosted by Supabase in Singapore. Stagex uses third-party service providers that may process or store information in Australia and other countries. Section 4 below lists the providers Stagex uses today. This section is an interim factual correction and has not yet been reviewed by privacy counsel.
This section was corrected on 2026-08-16. It previously stated that data was stored in Australia in Supabase’s Sydney (ap-southeast-2) region. That statement was first published on 2026-03-20 and was incorrect throughout: the production database has been in Singapore (ap-southeast-1) since it was created on 2025-11-11. This is an interim factual correction made by engineering; it has not yet been reviewed by legal counsel, and the cross-border disclosure position under Australian Privacy Principle 8 is being assessed.
We implement the following security measures:
TLS 1.2+ encryption for all data in transit.
AES-256 encryption for all data at rest.
Role-based access controls on a need-to-know basis.
Multi-factor authentication for all internal systems.
Automated dependency and vulnerability scanning on every build.
SOC 2 Type II audit readiness in progress for core infrastructure (target 2027).
Eligible data breaches are assessed within 30 days and notified to you and the OAIC as soon as practicable, under the Notifiable Data Breaches scheme (Privacy Act 1988 (Cth), Part IIIC).
4. Sharing Your Information
We do not sell or trade your personal information. We share data only:
With service providers: Supabase (database and file storage), Stripe (payments), Twilio (SMS), Resend (email), Sentry (error monitoring), PostHog (product analytics), Anthropic (AI features), and the accounting and rostering services you choose to connect (Xero, MYOB, Deputy, Google). Several of these process or store information outside Australia.
Within your organisation: team members can view data according to their role permissions.
With counterparties: escrow and Marketplace transactions share business name and job communications with the other party.
With legal authorities: where required by law, court order, or to protect safety.
5. Your Privacy Rights
Under the Privacy Act 1988 (Cth), you have the right to:
Access (APP 12): request a copy of your personal information. We respond within 30 days.
Correction (APP 13): request correction of inaccurate or outdated information.
Deletion: request deletion of your data, subject to legal retention requirements.
Portability: export your data in JSON or CSV format via account settings.
Opt-out: unsubscribe from marketing communications at any time.
6. Cookies and Tracking
Category
Purpose
Opt-out
Essential
Authentication, CSRF protection, security tokens.
Required
Functional
Theme, language, table layout preferences.
Account Settings
Analytics
PostHog session recordings and event analytics (anonymised).
Cookie banner
Marketing
Conversion tracking for marketing campaigns.
Cookie banner
7. Data Retention
Account data: retained while active plus 90 days after closure.
Financial records: 7 years per the Corporations Act 2001.
Compliance documents: 5-7 years per WHS legislation.
AML/CTF records: 7 years per the AML/CTF Act 2006.
8. Contact
For privacy enquiries, access requests, or complaints:
A.C.N. 696 624 987 Pty Ltd — Privacy Officer
ACN 696 624 987 · ABN 85 696 624 987
Email:
Response time: within 30 days.
If unsatisfied, you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.