Legal

Privacy Policy

Effective 26 August 2026. This policy explains how Springtrack Software, operating under the brand Springtrack(“we”, “us”), collects, uses, discloses, and protects personal information when you use the Springtrack website and application (the “Service”). It is written with reference to the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and, where applicable, the UK/EU General Data Protection Regulation (GDPR).

By using the Service you agree to the collection and use of information as described here. If you don’t agree, please don’t use the Service.

1. Who we are

Springtrack is a time-tracking and invoicing service for teams and freelancers, provided by Springtrack Software, based in New South Wales, Australia. This policy covers personal information we collect through the Springtrack website, application, and client portal.

If you use Springtrack as an employee or member of an organisation (an “org”), your organisation is generally the controller of the data it enters into Springtrack (its clients, projects, invoices), and we process that data on the organisation’s behalf — see Data we process on behalf of your organisation. For your own account information (login, profile, billing), we act as the controller.

2. Information we collect

Account & profile data — name, email address, password (stored as a salted hash, never in plain text), organisation name, and role.

Billing data— your subscription plan, seat count, billing history, and billing address. Card and payment details are collected and stored by our payment processor, Stripe — Springtrack never sees or stores full card numbers. Your billing address is also used to determine the tax (for example, GST) applicable to your subscription — see Subscriptions & billing in our Terms of Service.

Usage data you create — time entries, projects, tasks, clients, invoices, estimates, expenses, notes, comments, attachments, and files you upload (receipts, avatars, documents) in the course of using the Service.

Device & log data — IP address, browser and device type, timestamps, and pages accessed, collected automatically for security, fraud prevention, and diagnosing problems.

Support communications — anything you send us via the in-app support form or email, including attachments you choose to include.

We do not knowingly collect more personal information than is needed to provide the Service, consistent with the APP 3 collection limitation principle.

3. How we use your information

  • To provide, operate, and maintain the Service, including the timer, kanban board, invoicing, and reporting features.
  • To process subscription payments and send billing communications via Stripe.
  • To send transactional email — invoice/estimate delivery, approval requests, timesheet reminders, account and security notices — via Resend.
  • To respond to support requests.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To maintain and improve the reliability and performance of the Service.
  • To comply with legal obligations, including tax and accounting record-keeping.

We do not sell personal information, and we do not use your data to train third-party AI models. Any marketing email is separate from transactional email and requires your consent, in line with the Spam Act 2003 (Cth) — you can unsubscribe at any time.

4. Data we process on behalf of your organisation

If you use Springtrack on behalf of an organisation, that organisation may enter personal information about its own clients and contacts into the Service — for example, client contact names and email addresses, so that invoices and estimates can be shared for approval through the Springtrack client portal. In this relationship, your organisation is the data controller and Springtrack is the data processor: we process this information only on the organisation’s instructions, to provide the Service.

The client portal is accessed via scoped, expiring, revocable links or an optional email magic-link — it never exposes an organisation’s full data set, only the specific client’s invoices and estimates. We record when a document is viewed through the portal (first/last viewed, a views log) so the organisation can see delivery status; we exclude the organisation’s own internal views from this tracking.

If you are a client contact who has received a portal link from an organisation using Springtrack, and you have questions about how your information is handled, please contact that organisation directly, or contact us at hello@springtrack.app and we will direct your request appropriately.

We offer a Data Processing Agreement (DPA) to organisation customers covering these obligations, including sub-processor disclosure, breach notification, and data return/deletion on termination. Contact us to request one.

5. Third-party service providers

We use a small number of specialist providers (“sub-processors”) to run Springtrack. Each is bound by its own data processing terms, which we have accepted:

  • Supabase — database, authentication, file storage, and realtime infrastructure.
  • Stripe — subscription billing and payment processing (PCI DSS compliant; we never handle raw card data).
  • Resend — transactional email delivery.
  • Vercel — application hosting and content delivery.

We maintain this list as our current sub-processors and will update it here if that changes. We don’t disclose personal information to other third parties except as described in this policy, with your consent, or where required by law (for example, a valid request from a law enforcement or regulatory body).

6. International data transfers

Springtrack is operated from Australia. Depending on the hosting region configured for your organisation, your data may be stored in Australia or another region supported by our infrastructure providers. Where personal information is transferred outside Australia — including to the United States or the EU, where some of our providers operate — we take reasonable steps to ensure it receives a comparable standard of protection, consistent with APP 8, including relying on Standard Contractual Clauses (SCCs) for transfers involving the EU/UK where applicable.

7. Data storage & security

Every table in our database enforces row-level security, so an organisation’s data is isolated from every other organisation’s at the database layer, not just in application code. Data is encrypted in transit (HTTPS/TLS) and at rest. Access to production data is restricted to what’s needed to operate the Service, and sensitive actions (like payments) go through PCI-compliant, tokenised flows via Stripe so we never see full card numbers.

No method of transmission or storage is 100% secure, and we can’t guarantee absolute security. If you believe your account has been compromised, contact us immediately at hello@springtrack.app.

8. Data retention & deletion

We retain your data for as long as your account or organisation is active, and as needed to provide the Service. If an organisation closes its account, we retain its data for a limited period (up to five years, to satisfy financial and tax record-keeping obligations) before permanent deletion, unless you request earlier deletion and we have no legal obligation to retain it. Choosing permanent deletion removes the organisation’s data, including linked authentication records, from our systems.

You can request a copy of your data, or request deletion, at any time by contacting us — see Your rights & choices.

9. Your rights & choices

Under the Australian Privacy Principles, you have the right to access the personal information we hold about you and to request correction if it’s inaccurate, out of date, or incomplete. If you are located in the UK or EU, GDPR gives you additional rights, including data portability, the right to object to certain processing, and the right to lodge a complaint with your local supervisory authority.

To exercise any of these rights, email hello@springtrack.app. We’ll respond within a reasonable time and at no cost, unless a request is manifestly unfounded or excessive. If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Cookies & similar technologies

We use strictly necessary cookies to keep you signed in and to keep the Service secure (for example, session and CSRF-protection cookies). We do not currently use non-essential tracking or advertising cookies. If that changes — for example, if we add analytics to the marketing site — we will update this policy and, where required for visitors in the UK/EU, present a cookie consent notice first.

11. Age & eligibility

Springtrack is a business tool and is not directed at children. You must be at least 18 years old, and using the Service on behalf of a business or organisation, to create an account.

12. Data breach notification

We maintain a process to detect, assess, and respond to data breaches. If a breach is likely to result in serious harm to affected individuals, we will notify the OAIC and affected individuals in line with the Notifiable Data Breaches (NDB) scheme, and will notify affected organisation customers so they can meet their own notification obligations to their clients.

13. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We’ll update the effective date above, and for material changes, we’ll notify you by email or an in-app notice before they take effect.

14. Contact us

Questions about this policy or how your data is handled? Contact us at hello@springtrack.app, or write to Springtrack Software.