Privacy Policy
Last updated: 31 July 2026
This Privacy Policy explains how ProfitIQ collects, holds, uses and discloses personal information, and how you can access or correct your information or make a complaint. It applies to our website at profitiq.com.au (the Website) and, once generally available, to the ProfitIQ software platform at profitiq.app (the Services).
1. Who we are
References in this Privacy Policy to “ProfitIQ”, “we”, “us” and “our” are to Profit IQ Operating Pty Ltd (ACN 695 508 153, ABN 51 695 508 153) of Unit 2, 31 Bay Vista Lane, Ewingsdale NSW 2481, trading as ProfitIQ. We are the entity responsible for handling personal information collected through the Website and the Services.
As an early-stage business, ProfitIQ may currently fall within the “small business operator” exemption in the Privacy Act 1988 (Cth). We have chosen to comply with the Australian Privacy Principles (APPs) as a matter of best practice regardless of whether the exemption applies to us at any given time.
2. Personal information we collect
The personal information we collect depends on how you interact with us — as a visitor to the Website, a person who joins our early access waitlist, or (once the Services launch) a registered customer or a member of a customer’s team.
| Category | Examples |
|---|---|
| Identity & contact information | Name, email address, phone number, business name, job title. |
| Business information | ABN, business address, team size, trade type, and other information you provide when registering interest or creating an account. |
| Account credentials | Login details and authentication tokens for your ProfitIQ account. |
| Billing information | Subscription plan, billing address and transaction history. Card and payment details are collected and stored directly by our third-party payment processor (see clause 7) — we do not store full card numbers. |
| Integration data | When you connect a third-party accounting tool such as Xero or MYOB, we access the job, invoice, cost, supplier and client data made available through that tool’s API, to the extent needed to calculate margins, budgets and profitability. |
| Content you upload | Plans, drawings, quotes, estimates, site diary entries, photos, notes and other documents you upload to the Services. This content may include personal information about third parties, such as your clients, subcontractors or site visitors (see clause 3). |
| Usage & device data | Pages viewed, features used, log files, IP address, device and browser type, and approximate location inferred from IP address. |
| Cookies & similar technology | Information collected via cookies and similar technologies on the Website (see clause 11). |
3. Personal information about other people you provide to us
The Services are designed to hold job and project information that may include personal information about people other than you — for example, the names and addresses of your clients on a quote, or subcontractors named in a site diary entry (Third-Party Personal Information). If you upload or input Third-Party Personal Information into the Services, you confirm that you are authorised to provide it to us and that you have taken reasonable steps to make the individuals concerned aware of, and where required obtain their consent to, this Privacy Policy and the fact that their information may be held and processed by ProfitIQ on your behalf. You are responsible for ensuring your own collection and use of Third-Party Personal Information complies with applicable privacy law.
4. How we collect personal information
- Directly from you — when you join our early access waitlist, register an account, contact us, or otherwise provide information through the Website or Services.
- Automatically — through cookies, analytics tools and server logs when you use the Website or Services.
- From connected third-party services — such as Xero, MYOB or other accounting, payment or productivity tools you choose to connect, in accordance with the permissions you grant at the time of connection.
- From other sources — such as publicly available business registers, or from a business partner who refers you to us, where you have consented to that referral.
Where reasonable and practicable, we collect personal information directly from the individual concerned. Where we collect personal information from a third party (including from a customer administrator about members of their team), we rely on that third party to have provided any required notices.
5. Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose personal information to:
- provide, operate, maintain and improve the Website and Services;
- create and administer your account, verify your identity and provide customer support;
- calculate job costings, margins, budgets and profitability insights within the Services;
- process payments and manage billing and subscriptions;
- communicate with you about your account, respond to enquiries, and manage the early access waitlist;
- send you service updates, product news and marketing communications, where you have consented or as otherwise permitted by the Spam Act 2003 (Cth), and always with an option to opt out;
- monitor, analyse and improve the performance, security and usability of the Website and Services;
- detect, investigate and prevent fraud, abuse, and security incidents;
- comply with our legal and regulatory obligations; and
- for any other purpose disclosed to you at the time of collection and to which you have consented.
6. Automated decision-making and AI-assisted features
Certain features of the Services — including Plan Intelligence (which uses AI to read uploaded plans and documents) and profitability and budget insights — use automated tools, including artificial intelligence and machine learning models, to process information you upload and generate insights, summaries or flags for your review.
These automated tools are decision-support tools: they surface information and suggestions to help you make your own business decisions (such as which jobs to quote, reprice or take on). They do not make decisions about, and are not used to make decisions about, any individual’s legal rights or otherwise significantly affect any individual, without a human of your business reviewing the output.
In line with APP 1.7, where we use a computer program to make a decision, or a decision that could reasonably be expected to significantly affect the rights or interests of an individual is substantially assisted by a computer program, we will disclose in this Privacy Policy: the kinds of personal information used in that process, and the kinds of decisions made solely or substantially by the program. As at the date of this Policy, ProfitIQ’s AI features — including document classification, profitability analysis, and project summaries — support your own business decisions and do not make decisions about, or that significantly affect, any individual’s rights or interests without your review. This threshold is accordingly not currently met by any feature of the Services. If that changes — for example, a future feature that automatically declines a supplier or flags a worker without a person reviewing it first — we will update this clause to describe the personal information used and the kinds of decisions made.
We use third-party AI service providers to process documents and data on our behalf, subject to contractual terms that restrict their use of your information to providing the relevant service to us and prohibit its use to train their own general-purpose models without our authorisation. AI features are currently provided via Amazon Bedrock, which gives us access to Anthropic’s Claude models without your information being shared directly with Anthropic as a separate party — Amazon Web Services, Inc. is the sub-processor.
7. Who we disclose personal information to
We may disclose personal information to:
- our staff and contractors, on a need-to-know basis, to operate the Website and Services;
- cloud hosting, storage and AI infrastructure providers — currently Firebase Hosting (Google) for the Website, and Amazon Web Services (Amazon ECS, RDS, S3, CloudFront and Bedrock) for the Services;
- analytics providers — currently Mixpanel and PostHog, used within the Services to understand product usage;
- our payment processor, Stripe, Inc., to process subscription payments. Card details are entered and stored directly with Stripe — we only ever hold a Stripe customer reference, never full card numbers;
- our transactional email provider, Resend (for account, password-reset and notification emails), and Cloudflare (Turnstile bot-protection on sign-up);
- AI and data-processing service providers referred to in clause 6, to provide the relevant features of the Services;
- our professional advisers, including our accountants, auditors and lawyers;
- a purchaser or prospective purchaser, and their advisers, in connection with an actual or proposed sale, merger, financing or restructure of our business;
- regulators, law enforcement and other third parties where we are required or authorised to do so by law; and
- any other third party where you have consented to the disclosure.
We do not sell personal information, and we do not disclose personal information collected via the Services to other ProfitIQ customers.
8. Overseas disclosure
Our core infrastructure — the application, database and file storage for the Services — runs on Amazon Web Services in the ap-southeast-2 (Sydney, Australia) region, so most of your personal information stays in Australia. There are three exceptions worth knowing about:
- our AI features run on Amazon Bedrock using a “global” cross-region inference profile, which means the AI request (including relevant content from your account) may be processed in an AWS region outside Australia — potentially in the United States, elsewhere in Asia-Pacific, or in Europe — depending on capacity and routing at the time;
- our payment processor, Stripe, Inc., is a US company that processes payment data as part of its global infrastructure; and
- our analytics provider PostHog is, by default, hosted on its United States cloud instance.
Before we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles that information consistently with the APPs — including, where appropriate, by entering into contractual arrangements requiring the recipient to protect the information to a standard comparable to the APPs.
9. Direct marketing
We will only send you direct marketing communications by electronic means (such as email) in accordance with the Spam Act 2003 (Cth) — that is, with your consent (which may be inferred from our existing relationship with you) and always with a clear and functioning unsubscribe mechanism. You can opt out of marketing communications at any time by using the unsubscribe link in any marketing email or by contacting us using the details in clause 15. We may still send you non-marketing communications relating to your account or the Services, such as service updates and billing notices.
10. Data quality and security
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, complete and up to date, and to protect it from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include encryption of data at rest and in transit (TLS); storing credentials in a dedicated secrets manager rather than in application code or environment variables; isolating our database in a private network with least-privilege access controls; verifying that every request for project or job data belongs to the authenticated user making it; time-limited, single-purpose links for file uploads and downloads; and running our application with the minimum operating-system privileges needed. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we experience a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will comply with our obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.
11. Cookies and similar technologies
The Website and Services may use cookies and similar technologies (such as local storage and pixels) to keep you signed in, remember your preferences, understand how the Website and Services are used, and, where applicable, measure the performance of our marketing. The Website does not currently use analytics or marketing cookies. Within the Services, we use Mixpanel and PostHog to understand how the product is used, and Cloudflare Turnstile to detect automated sign-ups; if the Website adopts similar tools, this Policy will be updated accordingly. Most browsers let you control or disable cookies through their settings; disabling cookies may affect the functionality of the Website and Services.
12. Access, correction and complaints
You may request access to, or correction of, the personal information we hold about you by contacting us using the details in clause 15. We will respond within a reasonable period (and in any event within 30 days). We may need to verify your identity before actioning a request, and in limited circumstances permitted by the Privacy Act we may decline a request for access or correction, in which case we will provide our reasons.
If you believe we have breached the APPs or this Privacy Policy, please contact us first using the details in clause 15 so we can try to resolve your complaint. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
13. Retention
We retain personal information for as long as needed to provide the Website and Services, comply with our legal obligations (including tax and accounting record-keeping requirements), resolve disputes, and enforce our agreements. When personal information is no longer needed for these purposes, we take reasonable steps to destroy or de-identify it, unless we are required by law to retain it for longer. You can permanently delete your account, or all of your project, chat, document and financial data while keeping your account, at any time from within the Services. Deletion removes your files and database records immediately and cannot be undone; a copy may briefly persist in our routine, encrypted infrastructure backups (kept on a rolling basis, currently up to 30 days) before it is fully removed from those backups too.
14. Children
The Website and Services are intended for business use by adults and are not directed at, or intended to be used by, children. We do not knowingly collect personal information from children.
15. Contact us
For any question, access or correction request, or complaint about this Privacy Policy or our handling of your personal information, contact our Privacy Officer:
- Email:
- Post: Unit 2, 31 Bay Vista Lane, Ewingsdale NSW 2481
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our practices or legal requirements. The “Last updated” date at the top of this page shows when it was last revised. Where changes are material, we will take reasonable steps to notify you, such as by email or a notice on the Website or within the Services.