Privacy Policy

Effective 27 July 2026

Draft — pending legal review. This document is provided as-is while our legal team finalises the definitive version. Contact ops@xgrafter.com with questions.

XGrafter Pty Ltd (“XGrafter”, “we”) is committed to protecting the privacy of individuals whose personal information we handle. This Policy explains how we collect, use, disclose, and store personal information, in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

1. What information we collect

  • Account information — name, email, phone, company name, ABN.
  • Customer Data — jobs, quotes, invoices, contacts, employees, and other records you upload to run your business through XGrafter.
  • Usage data — anonymised logs of feature use, browser, device, and IP address to operate and improve the Service.
  • Communications — records of support requests and correspondence.

2. How we use it

We use personal information to:

  • Provide, maintain, and improve the Service.
  • Bill and communicate with you.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.

We do not sell your personal information or use Customer Data to train machine-learning models that leave your account.

3. Where your data lives

Customer Data is stored in Australia. We use the following sub-processors:

  • Supabase / AWS Sydney (ap-southeast-2) — primary database, file storage, authentication. All Customer Data resides in Sydney.
  • Resend — transactional email (welcome emails, invoice notifications). Email content in transit is stored briefly by Resend for delivery diagnostics.
  • Vercel — application hosting. Requests routed via edge locations globally but no Customer Data is stored at the edge.

4. Disclosure

We disclose personal information only to our sub-processors as listed above, and where required by law. We do not share Customer Data with third parties for marketing purposes.

5. Security

We employ industry-standard safeguards including TLS encryption in transit, encrypted storage at rest, principle-of-least-privilege access controls, and regular security review of our infrastructure. No system is perfectly secure — we recommend enabling multi-factor authentication on your account.

6. Retention

We retain Customer Data for the duration of your subscription and for 30 days after termination to allow for reactivation and data export. After 30 days, Customer Data is permanently deleted from active systems. Backups are retained for up to 90 days.

7. Your rights

You may request to:

  • Access the personal information we hold about you.
  • Correct any information that is inaccurate.
  • Delete personal information (subject to legal retention obligations).
  • Export your Customer Data in a machine-readable format.

Send requests to ops@xgrafter.com. We will respond within 30 days.

8. Cookies and tracking

We use strictly necessary cookies to keep you signed in and remember preferences. We do not use third-party marketing or advertising cookies.

9. Complaints

If you believe we have breached the APPs, contact us at ops@xgrafter.com. If unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).

10. Changes to this Policy

We may update this Policy from time to time. The effective date at the top reflects the most recent revision. Material changes will be notified by email.