Privacy Policy
This policy explains how Australiair Heating and Cooling Pty Ltd (ABN 56 636 072 341), operator of ARC Ready, collects, uses, stores and discloses personal information. It is drafted to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
We are based in Victoria, Australia.
1. What we collect
We only collect information that is reasonably necessary to run ARC Ready. This includes:
- Account information — email address and hashed password (we never store your password in clear text).
- Business details — business name, trading name, RTA number, RHL number, RHL holder names, business segment, contact name, phone and postal address.
- Record-keeping data — the quarterly refrigerant activity you enter (purchases, sales, recovered refrigerant, cylinder leak tests, equipment, etc.).
- Support interactions — messages and attachments you send through the in-app support system.
- Payment metadata — plan, subscription status, and a Stripe customer reference. Full card details are handled by Stripe and never reach our servers.
- Basic technical data — IP address and user agent in server logs, used for security and rate-limiting.
2. How we use it
- To provide the Service: run your account, save your records, produce your PDFs, and make backups available to you.
- To process subscriptions and invoicing through Stripe.
- To respond to your support requests.
- To keep the Service secure: detecting abuse, enforcing rate limits, and investigating incidents.
- To comply with legal obligations, including tax and consumer law.
We do not sell your personal information, and we do not use your data to train external AI models. Internal support-response improvement, where used, operates only on sanitised content with personal identifiers removed.
3. Who we share it with
We share personal information with a small number of service providers, strictly to run the Service:
| Provider | Purpose | Where |
|---|---|---|
| Stripe | Subscription billing and payment processing | Global (Stripe's infrastructure) |
| Resend | Transactional email (e.g. password resets) | United States / EU |
| Binary Lane | Hosting of the application server and database | Australia |
We may also disclose information if required by law, in response to a valid legal request, or to protect our legal rights.
4. Where your data is stored
Your records and account data are stored on our server hosted in Australia. Some information (such as emails sent via Resend or metadata held by Stripe) is handled by providers that operate internationally. We only use providers that apply appropriate safeguards to personal information.
5. How long we keep it
- Account and record data: kept while your account is active. If you request deletion, the account is soft-deleted immediately and hard-deleted after 30 days (a grace period so you can change your mind).
- Billing records: retained for 5 years after the relevant transaction, as required by Australian tax law.
- Server logs: rotated and deleted on a rolling basis, typically within 30 days.
- Backups: retained per our backup schedule and overwritten on rotation.
6. Your rights
Under the Privacy Act and the APPs, you can:
- Access the personal information we hold about you.
- Ask us to correct information that is inaccurate or out of date.
- Request deletion of your account and associated data (see Section 5).
- Withdraw consent or opt out of non-essential communications.
- Make a complaint if you believe we have mishandled your information.
To exercise any of these, email privacy@arcready.com.au. We will respond within 30 days.
7. Security
We apply reasonable steps to protect your information, including TLS/HTTPS for all traffic, password hashing, time-limited session tokens, rate-limited authentication endpoints, and access controls on the server. No system is perfectly secure; if you become aware of a vulnerability, please report it to privacy@arcready.com.au.
8. Cookies and tracking
ARC Ready uses a small number of first-party storage items (such as your authentication token and theme preference) to keep you signed in and to remember display settings.
The public-facing pages of arcready.com.au use Google Ads conversion tracking (gtag.js) to measure the effectiveness of our advertising. This sets cookies that allow Google to attribute visits and subscriptions back to ad campaigns. The data we collect through this is limited to ad-click identifiers, page visits, and whether a visitor completed a subscription.
We have enhanced conversions enabled, which means that when you complete a subscription, your email address is hashed (one-way encrypted using SHA-256) in your browser and sent to Google. Google uses the hash to match the conversion to a signed-in Google account, improving attribution accuracy. Your email is never sent in plain text and we do not store the hash ourselves.
Google's handling of this data is governed by Google's Privacy Policy. You can opt out of personalised advertising at adssettings.google.com or block third-party cookies in your browser.
The in-app experience at /app/ is not used for advertising and does not currently include third-party tracking.
9. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the current version. Where changes are material, we will notify you in the Service or by email.
10. Contact and complaints
For privacy questions or requests: privacy@arcready.com.au.
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.