This explains how [Legal Entity] ("Reguler", "we") handles personal information, consistent with the Australian Privacy Principles under the Privacy Act 1988 (Cth). In short: we only handle your data to run the service for you — we never sell it or use it for our own purposes.
You (the business) decide what customer information you collect and how it's used — you are the controller of your customers' personal information. We act as your processor, handling it only on your instructions to provide the service.
Solely to provide the service to you: syncing customers from Square, segmenting them, sending the SMS you initiate, showing you your analytics, and providing support.
We do not own your data — you do. We will not sell, rent, share or disclose it, and will not use it for our own advertising, marketing, product development, or to train machine-learning models. We access it only (a) to operate and support the service, (b) when you instruct us, or (c) where the law requires.
We use trusted providers strictly to deliver the service, sharing only what's needed:
Passwords are hashed (bcrypt), data is encrypted in transit (HTTPS), sessions use httpOnly cookies, and access is restricted to what's needed to run and support the service.
We keep your data while your account is active. You can export it at any time, and we delete it within 30 days of account closure, except where the law requires us to keep it.
Because you control your customers' information, requests from them for access, correction or deletion are handled by you; we'll help you as your processor.
If a breach affecting your data occurs, we will notify you without undue delay, consistent with the Notifiable Data Breaches scheme.
Privacy questions or deletion requests: admin@reguler.io.