Privacy Notice
Last updated 7 August 2026
This notice explains how Sitrep ("we", "us") handles personal information. For the accounts, users and business data you manage in the platform, Sitrep is the data controller for its own customer relationship, and a processor acting on your instructions for the staff, supplier and customer data you bring into your workspace.
What we collect and why
- Account details (name, email, business name, contact phone, ABN, address) — to create and administer your account and provide support. Legal basis: performance of our contract.
- Login credentials and session data — to authenticate you and keep your account secure. Legal basis: contract and legitimate interests in security.
- Workspace data you connect or enter (staff records and pay rates, rosters and hours, supplier invoices, sales and inventory data, mailbox content matched to invoices, review content) — to deliver the features you've enabled. Legal basis: contract, and your instructions as controller of that data.
- Support messages — to answer your questions. Legal basis: contract and legitimate interests.
- Usage, device and log data (pages used, feature events, IP address, browser type, error logs) — to keep the service reliable, prevent fraud and improve the product. Legal basis: legitimate interests.
- Marketing contact details — only where you've opted in. Legal basis: consent, withdrawable at any time.
Who we share it with
- Service providers and subprocessors — hosting and database infrastructure, email and SMS delivery, AI model providers used for summaries and drafts, and error monitoring.
- Stripe, our payment processor, for subscription billing, payment processing, tax calculation and invoicing.
- Integrations you connect — such as your point of sale, mailbox, accounting or Google Business Profile — only to the extent needed to sync the data you've authorised.
- Professional advisers (legal, accounting) and authorities where required by law.
We do not sell personal information.
Retention
We keep account and workspace data for as long as your account is active, and for up to 30 days after cancellation so you can export or restore it. Billing and tax records are kept for the period required by law (generally seven years). After that, data is deleted or anonymised. You can ask us to delete your workspace sooner.
Your rights
Under Australian privacy law — and the GDPR/UK GDPR where it applies to you — you may request access to your personal information, correct it, ask for erasure or restriction, object to processing, request a portable copy, or withdraw consent. Email privacy@sitrep.com and we'll respond within 30 days. You may also complain to the Office of the Australian Information Commissioner, or to your local supervisory authority.
International transfers
Our infrastructure and some subprocessors operate outside Australia, including in the United States and the EU. Where data leaves your region we rely on appropriate safeguards such as standard contractual clauses or adequacy decisions.
Security
We use appropriate technical and organisational measures: encryption in transit and at rest, encrypted storage of integration tokens, row-level access controls so each business only sees its own data, and role-based permissions inside your workspace. No system is perfectly secure, but we review these measures regularly.
Cookies
We use essential cookies and local storage to keep you signed in and remember your active store and preferences. We use a small amount of product analytics to understand feature usage. We do not run advertising cookies. You can clear or block cookies in your browser, though the app will not stay signed in without the essential ones.
Contact
Sitrep — privacy@sitrep.com. If we change this notice we'll update this page and, for material changes, notify account owners.