Lockspect Privacy Policy
Last updated 30 September 2026.
1. About this policy and who we are
This policy explains how Lockspect Pty Ltd (ACN 702 724 061, “Lockspect”, “we”) handles personal information when you use the Lockspect platform.
Lockspect is a business-to-business (B2B) tool. There are two layers of data involved, and it matters which one applies:
- Account Data — information about you as a Lockspect user (your name, email, role, which Company you belong to). We collect this directly from you, and we are responsible for it under this policy.
- Company Data — the customer and site information a Company's own staff enter into Lockspect about that Company's own customers (e.g. a homeowner's name, address and site details for a solar quote). Here, your Company is the data controller, not Lockspect — the Company decides what customer data to collect and why. Lockspect hosts and processes that data on the Company's behalf, as its service provider. If you are a customer of one of our Company users and have a query about your own data, you should contact that Company directly, not Lockspect.
2. Information we collect
Account Data (collected directly from you):
- Name, email address, password (stored securely, never in plain text)
- Role and Company membership
- Support or contact correspondence with us
Company Data (entered by a Company's staff about their own customers and sites):
- Customer name, address and contact details
- Site and property details (e.g. switchboard, battery and roof information, energy retailer, NMI)
- Photos taken during a site visit
- Quotes and pricing generated from a site visit
Technical data (collected automatically):
- Device, browser and IP address information
- Session information, used to enforce our one-active-session-per-user security control
- CAPTCHA/bot-verification results (via Cloudflare Turnstile), to protect the platform from automated abuse
3. How we use information
We use information to:
- create and secure your account (authentication, enforcing one active session per user, isolating each Company's data from every other Company's);
- provide the core service — locking and versioning site-visit checklists, generating quotes;
- send transactional emails (e.g. invitations, sign-up confirmations) via our email provider;
- protect the platform from bots and abuse (CAPTCHA);
- respond to support requests;
- meet legal obligations.
4. Who we share information with
We do not sell personal information. We share information only with:
- Sub-processors who help us run Lockspect:
- Supabase — database, authentication and file storage
- Vercel — application hosting
- Resend — transactional email delivery
- Cloudflare — bot protection, DNS and email routing
- (in future) a payment processor, once billing is introduced — Lockspect itself will not hold your card details
- Other members of your own Company, where your role gives you visibility of that data within the Company's workspace.
- Authorities, where required by law.
Each Company's data is isolated from every other Company at the database level and is never shared across Companies.
5. Where your information is stored
Our primary database is hosted in Australia (Sydney region). Some of our sub-processors (listed in section 4) may store or process data outside Australia as part of how their services operate — Vercel (US-based hosting infrastructure), Resend (US-based email delivery), and Cloudflare (global network, security and DNS services) — exact data-residency terms are being confirmed with each vendor. Where personal information is disclosed overseas, we take reasonable steps consistent with Australian Privacy Principle 8 to ensure it is handled consistently with the APPs.
6. Data retention, locked records and security
- Locked site-visit records. Once a Company locks a site-visit checklist, it becomes a permanent, append-only record by design — this is core to what Lockspect does. It cannot be edited or deleted afterwards, including by us through ordinary means; a later change creates a new version rather than altering the original.
- Account Data. We retain Account Data while your account and Company remain active, and for a further period afterwards where needed for legal, accounting or dispute-resolution purposes.
- Security. We protect information with database-level access controls (each Company's data isolated from every other Company's), enforced single active sessions per user, CAPTCHA-based bot protection, and encryption in transit and at rest.
7. Your rights and how to contact us
- If you are a Lockspect user, you can ask us to access or correct your Account Data by contacting admin@lockspect.com.
- If you are a customer of one of our Company users and want to access, correct or ask about your own data, please contact that Company directly — they control that data, not us.
- You can make a complaint about how we handle personal information by contacting admin@lockspect.com. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
8. Cookies, children's privacy and changes to this policy
- Cookies. We use minimal, session-based cookies needed to keep you signed in securely. We do not use advertising or cross-site tracking cookies.
- Children. Lockspect is a business tool for trade companies and their staff. It is not directed at children, and we do not knowingly collect personal information from children.
- Changes. We may update this policy from time to time. We will give reasonable notice of material changes (e.g. by email or in-app notice).