Privacy Policy

Last updated: 21 July 2026

1. About this policy and who we are

Construct-it is a software-as-a-service platform for construction and trade sub-contractors, operated by Construct-it Technologies Pty Ltd (ABN 44 699 411 080), based in Brisbane, Queensland, Australia (“Construct-it”, “we”, “us”, “our”). This policy explains how we collect, hold, use and disclose personal information, and how you can access, correct or complain about it. It applies to our website (construct-it.au), our web and mobile apps, and our dealings with customers, prospects and visitors.

Two roles. For personal information about our own account holders, billing contacts and website visitors, we are the entity that decides how the information is handled. For the project data our customers enter about their employees, clients, suppliers and sub-contractors, we act on the customer's behalf — the customer is responsible for its own privacy obligations to those individuals, and requests from those individuals should be directed to the relevant customer.

Contact us at info@construct-it.au for any privacy question.

2. Anonymity and pseudonymity

Where lawful and practicable you may deal with us anonymously or by a pseudonym — for example when making a general enquiry. This is not practicable where we need to identify you, such as to create and bill an account or to respond to an access or correction request.

3. What information we collect

  • Account information — name, work email, company name, role, and a hashed password.
  • Billing information — billing contact, business name, ABN, and billing address. Card details are collected and stored by Stripe, not by us — we do not see or store full card numbers.
  • Project data you enter — projects, progress claims, variations, retention data, schedules, timesheets, documents and photos, and details of your clients, suppliers, sub-contractors and employees. This may include personal information about third parties that you provide to us (see the “two roles” note above).
  • Connected-system data — when you connect Xero, we receive invoice, contact, payroll and bank-transaction data via OAuth, to the extent needed for the integration.
  • Usage and device data — log files, IP address, browser/user-agent, pages viewed and actions taken, for security, troubleshooting and product improvement.
  • Support and communications — records of your enquiries and our correspondence.

We generally collect personal information directly from you or your Authorised Users. Where you provide personal information about other individuals, you must ensure you are entitled to do so and that those individuals are aware of this policy. We do not intentionally collect sensitive information (as defined in the Privacy Act — e.g. health, racial or biometric data); please do not upload it unless necessary.

4. Why we collect it and how we use it

  • to create, operate and secure your account and the Service;
  • to perform the Service's functions (e.g. compute retention, generate progress claims, parse uploaded documents, and — on your explicit instruction — post invoices to your connected Xero organisation);
  • to process payments, manage subscriptions, and issue tax invoices and receipts;
  • to provide support and send service communications (trial reminders, billing receipts, security and password notices, and material changes to our terms or this policy);
  • to detect, prevent and investigate fraud, abuse and security incidents;
  • to improve and develop the Service (including using aggregated, de-identified usage data); and
  • to comply with our legal obligations (including record-keeping and tax law).

We use personal information only for the purpose for which it was collected, a directly related purpose you would reasonably expect, or another purpose you have consented to or that is permitted or required by law. We do not sell your personal information, and we do not use your Customer Data or uploaded documents to train AI models.

5. Direct marketing

We may send you marketing about our own products where the law allows (for example, to existing customers about similar services, or where you have consented). Every marketing message identifies us and includes an easy unsubscribe option, consistent with the Spam Act 2003 (Cth). Opting out of marketing does not stop essential service communications. We do not provide your personal information to third parties for their own marketing.

6. Who we share data with (sub-processors)

We disclose personal information to trusted service providers (“sub-processors”) who help us run the Service, each only to the extent needed for its function and under contractual obligations to protect the information:

  • Supabase — database, storage and authentication — data stored in Sydney, Australia
  • Vercel — application hosting / compute — United States (data in transit / edge)
  • Stripe — payment processing and card data — we never see your card numbers
  • Xero — accounting integration, only if you connect it
  • Resend — transactional email (receipts, reminders, resets) — United States
  • Anthropic (Claude) — AI parsing of documents you upload — not used to train AI models — United States
  • Google (Places API) — address autocomplete — United States
  • Sentry — error monitoring and diagnostics — United States

We keep the current list, function and location of our providers on our sub-processors page. We may also disclose personal information to our professional advisers; where required or authorised by law, a court or a regulator; to prevent a serious threat to safety; or to a buyer in connection with a sale or reorganisation of our business (under confidentiality).

7. Overseas disclosure

Your project data is stored in Sydney, Australia (via Supabase). Some processing and data in transit occurs through the overseas sub-processors listed above — primarily in the United States. This is a cross-border disclosure under Australian Privacy Principle 8. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, principally through contractual data-protection terms. By using the Service you acknowledge these overseas disclosures.

8. Data quality

We take reasonable steps to keep personal information accurate, up to date and complete. Please keep your account details current and let us know of any changes. You are responsible for the accuracy of the project data you enter.

9. Storage and security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, including:

  • tenant isolation using database row-level security so one customer cannot access another's data;
  • encryption in transit (TLS) for connections, and encryption at rest of connected-system tokens (e.g. Xero OAuth tokens) using AES-256;
  • access controls and least-privilege administration; and
  • encrypted, retained backups per our providers' standard schedules.

No system is completely secure and we cannot guarantee absolute security. We will notify you and act as required under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act if an eligible data breach likely to result in serious harm occurs.

10. Cookies and tracking

We use first-party cookies for authentication (session) and site function. We do not use third-party advertising or cross-site tracking cookies.

11. How long we keep it (retention)

Active accounts. We keep personal information for as long as you have an account and as needed for the purposes above.

Cancelled accounts. When you cancel, you can export your data yourself for 30 days after cancellation. After that export window, your account and project data are permanently deleted 60 days after cancellation — except that accounting and audit records (for example progress claims and invoice references) are kept for 7 years as required by Australian tax law, and data may persist in encrypted backups until it is purged in the ordinary backup cycle.

12. Accessing and correcting your information

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Email info@construct-it.au. We will respond within a reasonable time (we aim for 30 days) and will verify your identity first. We may charge a reasonable cost for access in limited cases and will explain if we must refuse a request. Where the personal information is project data our customer controls, we may direct your request to that customer.

13. Complaints

If you have a privacy concern or believe we have breached the APPs, contact our Privacy Officer at info@construct-it.au. We will acknowledge and investigate and aim to respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au, phone 1300 363 992, or GPO Box 5288, Sydney NSW 2001.

14. Changes to this policy

We may update this policy from time to time. We will publish the updated version with a new effective date and, for material changes, give you at least 14 days' notice by email and/or an in-app banner before it takes effect.

15. Contact us

Construct-it Technologies Pty Ltd (ABN 44 699 411 080) — Privacy Officer. Email info@construct-it.au · construct-it.au · Brisbane, Queensland, Australia.