Legal

Privacy Policy

Effective date: 8 March 2025 · Complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles

We collect minimal data, never sell it, and give you full control. This policy explains what we collect, why, and how to request deletion.

Contents

1. Who We Are2. What Information We Collect3. Why We Collect It4. Third-Party Services5. Data Storage and Security6. Data Retention7. Disclosure of Personal Information8. Your Rights Under Australian Privacy Law9. Cookies and Analytics10. Children's Privacy11. Overseas Disclosure12. Complaints and Contact

1. Who We Are

Locatalyze ("we", "us", "our") operates the location feasibility analysis platform at locatalyze.com. We are an Australian-based software company.

We are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) contained therein.

2. What Information We Collect

Information you provide

DataWhen collected
Email addressWhen you create an account
Password (hashed — never stored in plain text)Account creation
Business type, address, rent, setup budget, ticket sizeWhen you run an analysis
Name (optional)Profile settings
Payment detailsProcessed by Stripe — we never see your card number

Information collected automatically

  • IP address and approximate location (city/region level)
  • Browser type, device type, and operating system
  • Pages visited and features used (via anonymised analytics)
  • Error logs for debugging purposes

What we do NOT collect

  • Government identifiers (TFN, ABN, driver's licence)
  • Health or sensitive information
  • Information about children under 18
  • Biometric data

3. Why We Collect It

We collect personal information only for the following purposes:

PurposeLawful basis
To create and manage your accountContract performance
To generate your location analysis reportsContract performance
To process paymentsContract performance
To send transactional emails (report ready, account alerts)Contract performance
To respond to support queriesLegitimate interest
To improve the Platform and fix bugsLegitimate interest
To send product updates (opt-out available)Consent
To comply with legal obligationsLegal obligation

We will never sell your personal information to third parties. Ever.

4. Third-Party Services

We use the following third-party services. Each has its own privacy policy:

ServicePurposeData shared
SupabaseDatabase and authenticationEmail, hashed password, report data
VercelHosting and server infrastructureIP address, server logs
StripePayment processingPayment details (we never see card numbers)
OpenAIAI-generated analysis textBusiness type, address, financial inputs for the report
GeoapifyCompetitor proximity dataLatitude/longitude of the analysed address
Nominatim/OpenStreetMapAddress geocodingThe address you submit for analysis

OpenAI data note: When you run an analysis, your submitted address, business type, and financial inputs are sent to OpenAI's API to generate the analysis text. OpenAI may retain this data for up to 30 days for abuse monitoring purposes per their API data usage policy. We do not send your name, email, or account details to OpenAI.

5. Data Storage and Security

Your data is stored in Supabase's managed database infrastructure. Supabase uses industry-standard encryption at rest and in transit (TLS 1.2+). Our application is hosted on Vercel's cloud infrastructure.

We implement reasonable technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, or destruction. However, no internet transmission is completely secure and we cannot guarantee the absolute security of your data.

If we become aware of a data breach that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988.

6. Data Retention

  • Account data — retained while your account is active and for 90 days after deletion
  • Report data — retained while your account is active; deleted when you delete a report or close your account
  • Payment records — retained for 7 years as required by Australian taxation law
  • Server logs — retained for 30 days for security and debugging purposes

7. Disclosure of Personal Information

We will only disclose your personal information to third parties:

  • To the third-party service providers listed in Section 4, as required to operate the Platform
  • Where required or authorised by Australian law (e.g. in response to a court order or request from the Australian Taxation Office)
  • To protect the rights, property, or safety of Locatalyze, our users, or the public
  • In connection with a sale or merger of the business, where the acquirer agrees to be bound by this Privacy Policy

We will never sell, rent, or trade your personal information to any third party for marketing purposes.

8. Your Rights Under Australian Privacy Law

Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:

  • Access — request a copy of the personal information we hold about you
  • Correction — request that we correct inaccurate, incomplete, or outdated personal information
  • Deletion — request deletion of your account and associated personal information (subject to our legal retention obligations)
  • Opt-out — unsubscribe from marketing communications at any time
  • Complaint — lodge a complaint with us or directly with the OAIC if you believe we have breached your privacy rights

To exercise any of these rights, contact us at privacy@locatalyze.com.au. We will respond within 30 days.

9. Cookies and Analytics

We use strictly necessary cookies to maintain your login session. We do not use advertising cookies or third-party tracking cookies.

We may use privacy-respecting analytics tools to understand how the Platform is used in aggregate (e.g. page views, feature usage). These tools are configured to anonymise IP addresses and not to collect personally identifiable information.

10. Children's Privacy

The Platform is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a person under 18, we will take steps to delete it promptly.

11. Overseas Disclosure

Some of our third-party service providers (including Vercel, OpenAI, and Stripe) are based in the United States. By using the Platform, you consent to the transfer of your personal information to these providers for the purposes described in this policy.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information, as required by APP 8.

12. Complaints and Contact

If you have a complaint about how we handle your personal information, please contact our Privacy Officer first. We aim to resolve all privacy complaints within 30 days.

Privacy Officer — Locatalyze

Email: privacy@locatalyze.com.au
Australia

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
oaic.gov.au/privacy/privacy-complaints
Phone: 1300 363 992

This Privacy Policy was last updated on 8 March 2025. We will notify you of material changes by email or via a notice on the Platform. Previous versions are available on request.