Legal
Privacy Policy
Last updated 27 September 2026
This Privacy Policy describes how Retention Track Pty Ltd (ABN 28 682 975 373) (we, us, our) collects, uses, stores and discloses personal information in connection with the paymentclaims.ai platform (the Platform). It applies to information collected through the Platform, our websites, our emails, and any related services. By accessing or using the Platform you consent to the practices described below.
1. Who we are
The Platform is owned and operated by Retention Track Pty Ltd, a company registered in Australia. Our registered office is at Unit 15, 5 Murphy Street, O'Connor, Western Australia 6163. The Platform serves customers in Australia and New Zealand. You can contact us about this Policy at privacy@retentiontrack.com.
2. Information we collect
The categories of personal information we collect depend on how you interact with the Platform. They may include:
- Account information: name, work email address, password (hashed), profile image, and the organisation and company you belong to.
- Workspace content: information you enter about your business, counterparties, contracts (including contract items and variations), payment claims, payment schedules, retention and retention releases, documents you upload, and related correspondence.
- Business identifiers: ABN, ACN or NZBN details you enter for your companies and counterparties, together with the registry records we retrieve when verifying them (see section 6). For sole traders, these records can include an individual's name.
- Communications: emails you send to us, support requests, invitations you send to other users, and notification preferences.
- Customer contact information: where your organisation is our customer, the name, email address and phone number of the people we deal with there, which we keep in our customer relationship records (see section 6).
- Technical data: IP address, browser type and version, device identifiers, time-zone setting, operating system, and pages or features accessed.
- Accounting connection data: where a company in your organisation connects Xero, the access credentials for that connection, and the accounting records we read from and write to that Xero organisation — its organisation profile, chart of accounts, tax rates and contacts, together with the status, outstanding balance and payment dates of the invoices we have raised in it. A Xero contact can carry an individual's name and email address.
- Connected application information: where you connect an application to the Platform — your own AI tool, in the ordinary case — we hold the record of that connection: which application it is, the name and address it supplied when it registered, that you authorised it, and when. We do not verify what an application says about itself. We also record which application began a draft it started for you, so that you can see where it came from when you review it. The connection is yours: it acts as you (see sections 4 and 6), and you can end it from your account page at any time.
- Payment method information: where an owner of your organisation adds a card, the card is entered directly into Stripe and we never receive the card number or security code. What we hold is a reference to the card in Stripe together with the details needed to show you which card is on file — its brand, last four digits, expiry month and year, and any name you give it — and, where your organisation holds more than one card, which of your companies is charged to which.
- Billing contact information: an email address for your organisation's billing, which Stripe uses to send you a receipt for each payment and to send you any invoice that remains outstanding. An owner of your organisation can nominate this address, change it, or clear it. Where none is nominated we use the email address of the owner of your organisation, and the Platform shows you which of the two is in effect.
- Usage and analytics data: product analytics and session replay events captured by PostHog to help us understand how the Platform is used, and — on our public website only, not on the Platform — the advertising measurement data described in section 10.
- Demo booking information: if you book a demonstration through our website, the name, email address and any other details you enter on the booking page, and the time you choose. The booking is taken for us by Calendly (see section 6), which passes those details to us and to the person who will meet you. You do not need an account to book one, and booking does not create one.
- Demonstration enquiry information: if you ask us about a demonstration rather than booking one yourself, the name, work email address and company name that you enter, and — if you choose to give them — a phone number and a time that you say would suit you. This form is on our own website and the details are emailed to us; no scheduling service is involved and nothing is booked. We use them to reply to you. You do not need an account, and asking does not create one.
- Support and security records: where a member of our staff accesses your account for support, or is given access to help set your account up, we record who accessed it, the organisation concerned, the time, and the IP address and browser user agent of the request — and, for the kinds of access that call for them, whose account was accessed, the reason given, and an entry for each change attempted. The reason is written by the member of staff about their own access and is not collected from you. See section 4 for when each kind of access happens, and section 9 for which entries hold which of those and how long they are kept.
We do not knowingly collect special-category personal information (such as health, biometric or political data) and we ask that you do not upload such information to the Platform.
3. How we collect information
- Directly from you when you create an account, complete forms, upload documents, configure your workspace, book a demonstration, or contact us.
- From other users in your organisation when they invite you or record information about counterparties or contracts you work on.
- From public business registries (the Australian Business Register and the New Zealand Business Number register) when you or another user in your organisation looks up a business identifier.
- Automatically from your device and browser when you use the Platform or visit our public website, including through cookies and similar technologies (see section 10).
- From a connected Xero organisation — where a user in your organisation connects one to a company in your workspace and authorises the connection — both when we read it directly and when Xero notifies us that an invoice we raised in it has changed.
- From an application you have connected — where you authorise one to act as you, both when it records information in the Platform and when it supplies a document for the Platform to read (see sections 2, 4 and 6).
- From Stripe, when an owner of your organisation adds a card — Stripe collects the card itself and tells us only what section 2 describes — and when Stripe tells us whether a charge or an invoice for the Claim Fee has been paid, so the Platform can show you what is outstanding.
- From our service providers (such as our authentication, hosting, email, AI and analytics providers) acting on our behalf.
4. Why we collect information
We use personal information to provide, secure and improve the Platform, including to:
- create and administer your account, authenticate you, and manage organisation and company memberships;
- notify our own team when a new account is created — your name, your email address and the time you signed up — so that we can contact you about getting set up;
- arrange and hold a product demonstration where you book one through our website, and follow up with you about it (see sections 2 and 6);
- reply to you with demonstration times where you ask for them through our website, or confirm a time where you propose one yourself, including by telephone if you give us a number (see section 2);
- measure the effectiveness of our advertising on our public website — how many people who saw an advertisement for the Platform went on to visit the site, and what they read — so that we can decide what to keep paying for (see section 10). We do not do this inside the Platform;
- decide who sees our advertisements on Meta's services — chiefly so that our existing customers and people who have already booked a demonstration are not shown them (see section 6);
- deliver the core features of the Platform (preparing and tracking payment claims, recording payment schedules, recording payment claims served on you and preparing, issuing and serving payment schedules in reply, managing retention, and related records);
- process documents you upload so that the Platform can extract and pre-fill contract and claim details for your review (see section 5);
- where you connect an application to the Platform, let it read and record information in your workspace as you, and process the documents it supplies (see below, and sections 2 and 6);
- where a company connects an accounting system, raise tax invoices and related accounting entries in it on your instruction, correct or remove entries we have raised where you instruct us to, and keep the Platform in step with what that system reports about them (see section 6);
- process payment of the per-claim fees described in our Access Terms, and keep records of your purchases;
- send transactional emails such as account confirmations, password resets, invitations and claim submissions;
- send you the deadline reminders and the weekly digest described immediately below, unless you have turned them off;
- respond to your enquiries and provide customer support, including by accessing your account where that is necessary to investigate a request or a fault (see below);
- monitor performance, diagnose issues, detect and prevent fraud or abuse, and otherwise keep the Platform secure;
- understand how the Platform is used and improve it; and
- comply with our legal, regulatory and contractual obligations.
Notifications we send you about your own records
Security of payment legislation runs to fixed statutory deadlines, so the Platform emails the members of a company about that company's own claims and contracts. These messages are sent to the work email address on your account, and they cover:
- a payment schedule that is approaching or has passed its statutory deadline, and a claim email that failed to reach the respondent;
- a claim period that has opened on a contract, and retention that has become available to release; and
- a weekly summary of the above, sent on Monday morning in your organisation's local time zone and only when there is something to report.
These are on by default, because the Platform exists to keep you ahead of those deadlines. They are not marketing, and we do not use your email address to send you marketing. You can turn each of the three groups above off independently — from the notification settings on your account page, or from the unsubscribe link in the footer of any of these emails, which needs no sign-in. Turning one group off does not affect the others, and none of it affects the operational emails listed above (account confirmations, password resets, invitations and the record of a claim you serve), which are part of providing the Platform and cannot be switched off while your account is open.
Each notification is sent only to members who have been granted access to the company the claim or contract belongs to, and its contents are limited to that company's own records.
When an application you connect acts in your account
You can connect an application of your own choosing to the Platform — in the ordinary case an AI tool you already use — so that it can work with your records without anyone re-keying them. An application you connect acts as you: it sees what you see and can do what you can do, in each organisation and company you can reach, and nothing more. In practice that is narrower than it sounds: today an application can read your records and start a contract draft from a document it supplies, and that is the whole of what it writes. It cannot serve or submit a payment claim, cannot incur a fee, cannot confirm anything the Platform has extracted from a document, and cannot reach billing, members, a connected accounting system, or the creation or deletion of a company. The Platform tells you what an application is asking for before you connect it, and Access Terms clause 3.11 sets out what you are authorising.
The connection is yours rather than your organisation's, so you can end it at any time from your own account page and nobody else can end it for you — though removing your access to an organisation also ends your application's access to that organisation's records. Disconnecting takes effect on the application's next request: we stop serving it from that point, and we do not control any credential it has already been given. We keep a record of which of the Platform's features an application asked for and whether we served it — not of what it sent us — so that we can see how this is used and detect misuse. What we record about a connection, and what we disclose to an application while it is connected, are described in sections 2 and 6.
When our staff access your account
Personnel we authorise may access your account where that is reasonably necessary to investigate a request for support, to diagnose or correct a fault, to prevent or investigate misuse of the Platform, or to comply with a legal obligation. That access can take two forms: viewing your organisation's administrative details — its companies, its members and their email addresses, and its billing status — or using the Platform as one of your users. In the second case they see what that user sees, which can include any of the categories described in section 2 — your workspace content, and for a company that has connected an accounting system, the accounting records described there. This is access by our own personnel, and is not a disclosure of your information to anyone else; section 6 sets out who we do share it with.
Such access is read-only. It does not alter any of your information, and while it is in progress the Platform refuses every change the person performing it could otherwise make to your account. Those refusals are enforced by the Platform for the duration of the access, rather than being left to the discretion of the person performing it. Access of the kind described under “When our staff help set your account up” below is a different thing, and is not read-only.
Access as one of your users requires a reason to be recorded before it begins, and it ends automatically after a short period. Every such access, and every occasion on which a member of staff opens your organisation's details, is written to the security audit log described in section 9 — which cannot be edited or deleted by anyone, and which we keep permanently.
We do not email you each time this happens. If you would like to know what has been recorded about access to your account, ask us at privacy@retentiontrack.com and we will tell you.
When our staff help set your account up
Separately from the above, we may give one of our own staff a temporary membership of your organisation so that they can help set your account up — loading your contracts and the claim history that predates your use of the Platform, and the counterparties and contacts they involve. This is not read-only. While it is in force that person can create, change and delete records in your account: counterparties and contacts, contracts and the items and variations in them, your pre-existing claim history, and a company's own settings. They can also upload documents into your account, including the documents those records are prepared from. They cannot raise, submit or serve a payment claim, record a payment schedule, create or delete a company, connect or change a connected accounting system, see or change billing, or add, remove or change anyone in your organisation. The Platform enforces those limits itself.
A reason has to be recorded before it begins, and it ends by itself on a stated day, no more than 14 days after the day it is given. We email the owner of your organisation when it begins, and whenever it is extended to a later day. While it is in force you can see it in your own list of members — who holds it, the reason recorded for it, and the day it ends — and an owner or administrator can end it there at any time, without telling us first. Ending it takes effect immediately, though it does not undo anything already done.
Someone holding that access is our staff member and not one of your people. They do not receive the deadline reminders, claim-window notices, bounce alerts or weekly digests we send the members of your companies about your own records, and nothing they do in your account is counted in the product analytics described in section 10. What they do is recorded instead, in the security audit log described in section 9.
5. AI document processing
The Platform includes AI-assisted features that read documents you upload (such as contracts, payment claims and payment schedules, including a payment claim served on you by a subcontractor) to transcribe, classify and extract information from them, so that the Platform can pre-fill drafts for your review. To provide these features we send the relevant documents and data to Anthropic, whose Claude models perform the processing via API.
- Under Anthropic's commercial API terms, inputs and outputs are not used to train Anthropic's models. We do not use your documents or data to train or fine-tune AI models, whether our own or a third party's.
- Extraction results are staged in the Platform for your review — nothing extracted by AI takes effect until a user in your organisation confirms it.
- If you do not want a document processed by these features, do not upload it to an AI-assisted flow; the underlying records can always be entered manually.
Information from a connected accounting system is excluded from all of these features.
What we read from a connected Xero organisation — its organisation profile, chart of accounts, tax rates and contacts, and the status of the invoices we have raised in it and the payments, credit notes, prepayments and overpayments applied to them — is never sent to Anthropic or to any other AI provider, in raw or processed form. It is not used to train, fine-tune, adapt or enhance any AI model, and it is not used to improve the output an AI-assisted feature produces for you or for anyone else. This applies to every AI-assisted feature the Platform offers, including any added in future.
6. Who we share information with
We share personal information only where necessary to operate the Platform or as permitted by law. Our key sub-processors are:
- Supabase — managed PostgreSQL database, file storage and authentication infrastructure.
- Vercel — application hosting and edge delivery.
- Inngest — durable background-job orchestration (for example email dispatch and document-processing pipelines).
- Resend — transactional email delivery (account confirmations, password resets, invitations, served payment claims and their spreadsheet copies, served payment schedules, and the deadline reminders and weekly digest described in section 4).
- Anthropic — AI processing of documents and data for the extraction features described in section 5.
- Google — address autocomplete (Google Maps Platform / Places API): as you type an address into the Platform, the partial text is sent to Google to return matching address suggestions.
- Xero — accounting integration, for companies that choose to connect one. The connection is made by a user in your organisation, one company at a time; we disclose nothing to Xero for a company that has not been connected. Where a company is connected, we read that Xero organisation's profile, chart of accounts, tax rates and contacts, and we write tax invoices, invoice attachments and manual journals into it on your instruction. Where you instruct us to correct a tax invoice we raised, we also alter or void that invoice and, where a payment has been applied to it or a credit note, prepayment or overpayment has been allocated to it, remove that payment or allocation and make it again unchanged — Xero does not permit an invoice to be altered while money is applied to it. To do so we read the credit note, prepayment or overpayment concerned, and change nothing in it other than that allocation. We do not sell, aggregate or supply what we read from your Xero organisation to any other party. It is disclosed only to the infrastructure providers listed in this section that host and operate the Platform — principally Supabase, which stores it, and Vercel and Inngest, which process it in order to run the Platform — and, as set out in section 5, never to an AI provider.
- Stripe — payment processing for the Claim Fee. When your organisation is created we send Stripe your organisation name, an internal identifier and your billing email address (see section 2) so that a billing customer record can be created for it. We send that address to Stripe again whenever it changes, and each charge carries it so that Stripe can email you the receipt. If an owner of your organisation adds a payment method, the card is collected by Stripe directly — we never receive or store the card number or security code. Stripe returns a reference to the saved card and its brand, last four digits and expiry, which we keep so the Platform can show you which card is on file and charge the right one (see section 2). Each charge names the payment claim it is for — its reference, and the name and reference of the contract it belongs to — so that the receipt Stripe sends you says what you paid for. In the uncommon case where a claim is served but the charge could not be taken at the time, Stripe raises an invoice for it carrying the same description, and Stripe (not us) emails you about that invoice and hosts the page where it can be paid.
- PostHog — product analytics (see section 10).
- Calendly — scheduling for demonstrations booked through our website. When you open the booking page Calendly receives your IP address and browser information; if you book, it receives the details described in section 2 and passes them to us. Calendly is not used anywhere in the Platform, and we do not send it anything you enter into the Platform.
- Google Analytics — advertising and traffic measurement on our public website (see section 10). Google's tag tells Google that a browser visited a page of our website, and — where you book a demonstration through the website — that a booking was completed. It is not told your name, your email address, the time you chose, or any other detail of the booking. Where that browser is signed in to a Google account, Google can associate the visit with that account. It is not used on the Platform, and we do not send Google anything you enter into the Platform, any document you upload, or anything about your claims, contracts or counterparties. This is separate from the address autocomplete described above, which is a Platform feature and reports nothing about your browsing.
- Attio — our customer relationship records. We keep there the name, email address and phone number of the people we deal with at our customers. If you book a demonstration, your name, email address, booking time and the advertisement you arrived from are recorded there.
- Meta Platforms — advertising measurement on our public website (see section 10), and matching for the audiences of our advertisements. Meta's pixel tells Meta that a browser visited a page of our website, and — where you book a demonstration through the website — that a booking was completed. For a booking, we also send Meta, from our own server, a one-way hashed form of your name and email address so Meta can match the booking to its own records; we never send the time you chose or anything else you entered. We also send Meta a one-way hashed form of the name, email address and phone number of our customers and of people who have booked a demonstration, so that Meta can leave them out of, or include them in, the audiences for our advertisements. Meta uses the hashed data only to match it to its own users and deletes it once the match is done. You can ask us to leave you out by emailing privacy@retentiontrack.com. Where that browser is signed in to a Meta service, Meta can associate the visit with that account. It is not used on the Platform, and apart from the hashed customer details described above, we do not send Meta anything you enter into the Platform, any document you upload, or anything about your claims, contracts or counterparties.
Where you connect an application to the Platform (see sections 2 and 4), we disclose to that application what the user who connected it can see in the Platform, for as long as the connection is live. In practice that is your contracts in full — their parties, dates, scope items, variations and value — your payment claims with their line items, amounts and service dates, your retention position, what is due and the statutory deadlines that attach to it, your projects by name and reference, and your counterparties, including the names and email addresses of the contacts you have recorded for them. It can also see which organisations and companies the user who connected it can reach, that user's role in each, and what that role permits. Two parts of that are worth naming rather than leaving to your records in general: those contacts are other people's staff, who have no relationship with us and have agreed to nothing with us, and the claim figures carry the dates your statutory rights run from. If you do not want an application able to read them, do not connect one — everything in the Platform works without a connected application.
The company that makes an application you connect is your service provider, not ours. We do not choose it, engage it or add it to the list above, and we do not control what it does with what it reads — if it is an AI tool, that is governed by your own arrangement with its vendor rather than by this policy or by section 5. We disclose to an application only what the user who connected it authorised, and we stop on its next request once that user disconnects it. An application you connect can also supply documents to the Platform, which we handle exactly as we handle a document you upload yourself, including as described in section 5.
When you serve a payment claim, we send it by email to the contract contacts you have recorded — the claim PDF we generate, a spreadsheet copy of the claim if you choose to attach one, and any supporting documents you have attached to that claim (for example a statutory declaration, site photos or supplier invoices). We do not inspect or alter what you attach; you choose the files and the recipients, and the documents are listed by filename on the claim itself. The same applies to a re-send. After a claim is served, you can also have us email its spreadsheet copy on its own: to the people the claim was emailed to, or, for a claim you served another way, to the contract contacts you have recorded, whom we show you before it is sent.
When you issue a payment schedule, we send it by email to the claimant: the contacts you have recorded for them on that contract, with any of their project-management and accounts contacts copied. We send the payment schedule PDF we generate from the figures and reasons you entered. It carries your company's name and the claim and contract it answers, and the email says the figures in it exclude GST. The people it goes to are the claimant's staff, not users of the Platform, and receiving it gives them no access to your workspace. We record when we sent it, and whether delivery failed.
On a payment claim, a spreadsheet copy of one, or a payment schedule we send for you, a reply goes to the reply-to address set for your company or, if none is set, to the email address of the person who sent it, so that address is visible to the people it is sent to. We also copy it to any addresses you have set for your company to be copied on claims and schedules.
When you use a registry lookup, we send the business identifier you entered to the relevant government registry — the Australian Business Register (operated by the Australian Taxation Office) or the New Zealand Business Number register (operated by the Ministry of Business, Innovation and Employment) — and store the record returned.
When you enter an address (for a company, counterparty or contract site), we send the text you type to Google's Places API to offer address suggestions. We store only the address you keep; the suggestions themselves are provided by Google.
If a company in your organisation connects Xero, we disclose to that company's own Xero organisation the information needed to raise and maintain the resulting accounting records. When you link a counterparty to a Xero contact — or ask us to create one — that is the counterparty's legal name, the ABN or NZBN recorded for it, and the email address of the person you have marked as its accounts contact. For each tax invoice raised from a payment claim, it is the contract and claim references, the description and invoiced value of each claim line, the retention withheld or released, the GST, the totals, and the payment due date. A retention write-off is posted as a manual journal carrying the contract's identifier and name and any reason you typed.
We also upload one document to that invoice as an attachment. For a claim served through the Platform, that is the claim PDF we generated. For a claim you lodged through the head contractor's own platform, we generated nothing, so it is the first supporting document you uploaded for that claim. Where you uploaded none, or where the first one is not a PDF or is too large for the accounting system to accept, we attach nothing and the invoice is raised without it. We upload only that first document and never look past it, so the rest of what you attached to a claim is not sent, and we upload it so that it appears on Xero's online invoice — the customer-facing page for the invoice. This means that document, and the details it contains, can be read by anyone holding that page's link, including the payer. That is deliberate: it is the document that supports the invoice, and the online invoice is where a payer goes to see it. If you do not want a claim disclosed in that way, do not push it to Xero — the claim and its records work in the Platform without a connected accounting system.
Where you choose it on a particular invoice, we also ask Xero to email that invoice to the recipient. The message is sent by Xero, from your Xero organisation, to the email address held on the Xero contact; we do not set the recipient, subject or content, and the email does not pass through our systems. We store the fact that it was sent and any failure Xero reported.
We then read back from that Xero organisation what has happened to the invoices we raised — their status, the amount outstanding, and when they were paid — so the Platform can show it against the claim. Apart from the reference data described above (organisation profile, chart of accounts, tax rates and contacts), we do not read your other accounting records.
We may also disclose personal information to our professional advisers, to related entities, in connection with a corporate transaction (such as a sale of the business), or to law enforcement or other authorities where required by law.
We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.
7. Overseas disclosure
Several of our sub-processors are based outside Australia and New Zealand. In particular, Vercel, Resend, Anthropic, Google, Inngest, Stripe, PostHog, Calendly, Meta and Attio process data in the United States or the European Union. Xero is headquartered in New Zealand and runs its platform on infrastructure in Australia and other countries, so information disclosed to a connected Xero organisation may be processed in New Zealand, Australia or overseas. Where you connect an application to the Platform, what we disclose to it is processed wherever that application runs, which we neither choose nor control. If you are in New Zealand, your information will also be processed in Australia. Where we transfer personal information overseas, we take reasonable steps to ensure that the recipient handles your information in accordance with applicable privacy laws, including (where relevant) by relying on Standard Contractual Clauses or equivalent safeguards.
8. Your rights and choices
Depending on your location, you may have the following rights in respect of the personal information we hold about you:
- access a copy of your personal information;
- request that we correct inaccurate or incomplete information;
- request that we delete your personal information (subject to legal or contractual retention requirements, and to the security audit log described in section 9);
- object to or restrict certain types of processing, including analytics;
- turn off the deadline reminders and the weekly digest described in section 4, from your account settings or the unsubscribe link in any of those emails;
- request a portable copy of personal information you have provided to us; and
- withdraw any consent you have given.
How to make a data access or deletion request
To exercise any of these rights, email us at privacy@retentiontrack.com with the subject line “Privacy request” and a description of what you would like us to do. We may need to verify your identity before we can act on your request. We aim to respond within 30 days. Requests are currently handled manually; we will let you know if we need additional information or time.
If your account belongs to an organisation, please note that your organisation administrator may also be able to action access, correction or deletion requests directly within the Platform.
9. How long we keep your information
We retain personal information for as long as your account remains active and for a reasonable period afterwards to meet our legal, accounting and reporting obligations, resolve disputes, and enforce our agreements. When personal information is no longer required, we take reasonable steps to delete or de-identify it. Workspace content you create is retained for as long as your organisation's workspace remains active; once your organisation deletes the workspace, we will delete or de-identify the associated data within a reasonable period.
The security audit log is an exception
We keep a separate, permanent security audit log of a small number of sensitive administrative actions — principally where a member of our support staff accesses or acts within a customer workspace (see section 4), where we grant or withdraw a billing exemption, where we add free claims to an organisation's account or take back the unused ones, and where we switch an organisation's head contractor features on or off. Every entry records who acted, what they did, which organisation was concerned, the time, and the IP address and browser user agent of the request.
What else an entry holds depends on the action. Where the action was taken inside a particular user's account, the entry also records whose account it was. Where the action requires a stated reason — accessing the Platform as one of your users, granting one of our staff access to help set your account up, granting a billing exemption, adding free claims to an organisation's account, and switching on an organisation's head contractor features — it records the reason given; where a reason is optional, as it is when a billing exemption is withdrawn, when free claims are taken back, when head contractor features are switched off, and when access to help set your account up is ended, it records whatever reason was given. For access to help set your account up it also records the day that access runs to and which of your companies it reached. Opening an organisation's administrative details records no reason, because none is asked for: requiring one in front of every routine support lookup would produce a box that is always filled in the same way, which is worse than an honest blank.
Where a member of our staff holds access to help set your account up (see section 4), the log also holds an entry for each change they attempt through it. That entry records who they are, which part of the Platform they used to make the change, your organisation, whichever of your companies they were viewing at the time, and the time — and it does not hold the contents of the change itself. Deliberately so: these entries are kept permanently and cannot be edited or deleted, so recording what was typed would mean holding your information in a place we could never remove it from. An entry means the change was attempted rather than that it took effect, because it is written before the change is applied and some changes fail. These entries cover the changes staff make through the Platform's own interfaces; reading your account is not recorded this way.
Almost every entry in this log records something we did. There is one exception: where an owner or administrator of your organisation ends a staff member's access from your own members page, that is recorded here too — it is the record of you ending our access, and it is kept on the same terms as the rest.
These entries cannot be edited or deleted, by us or by anyone else — the database itself refuses the change. They are deliberately kept after the account or the workspace they refer to has been deleted, and they retain the organisation name and the email addresses of the people involved so that the record still means something once those records are gone. If we deleted them along with the workspace, deleting a workspace would erase the evidence of what was done inside it, which is the opposite of what an audit log is for.
This is the one category of personal information we will not delete or de-identify on request. It is limited to the actions listed above: it is not a log of what you do in the Platform, and we do not record your ordinary use of the product in it.
10. Cookies and analytics
We use a small number of cookies and similar technologies:
- Strictly necessary cookies that keep you signed in and remember your preferences. These are always set and cannot be disabled.
- Analytics and session replay cookies set by PostHog, which we use to measure page views, understand how product features are used, and replay sessions to diagnose issues and improve the Platform. Analytics profiles are only created for signed-in users.
- Advertising and measurement cookies set by Meta and by Google on our public website at paymentclaims.ai. We advertise the Platform on Meta's and Google's services, and their pixel and tag tell us how many people who saw an advertisement went on to visit the site, which pages they read, and how many went on to book a demonstration, so that we can stop paying for advertisements that do not work. We report the fact that a booking was completed. To Meta we also send, from our own server, a one-way hashed form of your name and email address so Meta can match the booking to its own records; Google is told no detail of the booking, and neither is ever sent the time you chose or anything else you entered. Where your browser is signed in to a Meta or Google service, that company can associate the visit with your account there and use it to decide which of our advertisements to show you.
Advertising cookies are set on our public website only, and never inside the Platform. Signing in, the work you do in the Platform, the documents you upload and the claims you serve are not reported to any advertising network. If you are one of our customers, a hashed form of your contact details is sent to Meta as described in section 6, and nothing else about your use of the Platform.
When session replay is enabled, text and form inputs are masked by default — we do not record what you type into the Platform.
You can block advertising cookies in your browser, and you can control how Meta and Google use information they hold about you through the ad preferences in your Meta or Google account. We also honour the Global Privacy Control: where your browser sends that signal, no Meta or Google tag is loaded at all on any page of our website, so no advertising cookie is set and nothing about your visit is reported to either company. If you would like to opt out of analytics or session replay, contact us at privacy@retentiontrack.com or configure your browser to block the relevant cookies.
11. Storage and security
We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration and disclosure. These include encryption in transit and at rest, access controls, audit logging, and contractual obligations on our sub-processors. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
12. Children
The Platform is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
13. Additional information for New Zealand residents
If you are in New Zealand, the Privacy Act 2020 (NZ) and its Information Privacy Principles apply to our handling of your personal information. You have rights to access and correct the personal information we hold about you, which you can exercise as described in section 8. Your information may be held and processed in Australia and in the other locations described in section 7; we take reasonable steps to ensure comparable safeguards apply. If you have a privacy concern we cannot resolve, you may complain to the Office of the Privacy Commissioner at privacy.org.nz (opens in new tab).
14. Additional information for EU and UK residents
If you are located in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) and UK GDPR apply to our processing of your personal information. We act as a “controller” in respect of account information and analytics data, and as a “processor” in respect of workspace content you enter on behalf of your organisation. We rely on the following legal bases: performance of our contract with you, our legitimate interests in operating and improving the Platform, compliance with legal obligations, and (where required) your consent.
You have the right to lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office (ICO); in the EU it is the data protection authority of the member state in which you live or work.
15. Additional information for California residents
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with rights to know what personal information we collect about you, to request deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. The categories of information we collect are described in section 2. We do not sell personal information. The advertising cookies described in section 10 may amount to “sharing” personal information for cross-context behavioural advertising under the CCPA. You can opt out by blocking those cookies as described in that section, by sending a Global Privacy Control signal from your browser, or by contacting us at privacy@retentiontrack.com.
16. Links to other websites
The Platform may contain links to third-party websites that we do not operate. We are not responsible for the privacy practices of those websites and recommend that you review their privacy policies before providing them with personal information.
17. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If the changes are material, we will provide more prominent notice (for example, by email or via a notice in the Platform).
18. Complaints
If you have a complaint about how we have handled your personal information, please email us at privacy@retentiontrack.com. We will investigate and respond as soon as reasonably practicable. If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au (opens in new tab), to the Office of the Privacy Commissioner in New Zealand at privacy.org.nz (opens in new tab), or to the data protection authority in your jurisdiction.
19. Contact us
For any questions about this Privacy Policy or how we handle your personal information, please contact us at:
Retention Track Pty LtdUnit 15, 5 Murphy Street
O'Connor, Western Australia 6163
Australia
privacy@retentiontrack.com