Legal
Privacy policy
Last updated: 19 August 2026
NextDataLinq ("we", "us", "our") respects your privacy. This policy explains what personal information we collect, why we collect it, who we share it with and how you can access or correct it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Information we collect
We only collect what we need to quote, deliver, bill and support our services:
- Contact details — your name, business name, email address and, if you give it to us, your phone number and business address.
- Enquiry content — what you tell us in emails about your business and what you need built.
- Billing information — the billing name, email and address associated with your payment, plus invoice and payment records. See section 3 regarding card numbers.
- Account information — usernames and securely hashed passwords for staff logins in systems we host for you.
- Technical logs — server logs recording IP address, date and time, requested page and error details, kept for security and fault diagnosis.
We do not collect sensitive information (such as health, biometric or political information), and we do not knowingly collect information from children.
2. Why we collect it
To prepare quotes, provide and support our services, set up and maintain your systems, issue invoices and process payments, respond to your enquiries, meet our record-keeping and tax obligations, and secure our systems against misuse. We do not sell personal information, and we do not use it for advertising or profiling.
3. Payment information
Card payments are processed by Stripe Payments Australia Pty Ltd. Card details are entered directly into Stripe's secure payment forms — we never see, handle or store your full card number, expiry date or security code. We receive only what Stripe returns to us: whether the payment succeeded, the amount, the card brand, the last four digits and the billing contact details. Stripe's handling of your information is governed by its own privacy policy at stripe.com/au/privacy.
4. This website
This website is deliberately simple. It sets no advertising or tracking cookies, runs no analytics or advertising scripts, embeds no social media widgets, and loads no fonts, images or code from third-party servers. There is no contact form — enquiries reach us by email, which means nothing you type is stored on this site.
Our web server keeps standard access logs (see section 1) for security and troubleshooting. Our DNS and network provider, Cloudflare, may process request metadata in the course of routing traffic to our server.
5. Data inside systems we host
If you are our business customer, the systems we host for you hold your own operational data — menu items, orders, order times, amounts, staff accounts and, where your customers provide it, their name, phone number and order details. For that information, you are the entity responsible to your customers and we act as your service provider. We access it only to operate, support, back up and fix your system, or where you ask us to, or where the law requires it. We do not use your operational data or your customers' details for our own purposes, and we never sell it.
If you are a member of the public who ordered through a system we host, the business you ordered from is your first point of contact for questions about that data. You may also email us and we will pass your request to them or action it on their instruction.
6. Who we share information with
We disclose personal information only to the extent needed to run the service:
- Stripe — payment processing.
- Our hosting provider (DigitalOcean) — servers on which the services run.
- Cloudflare — DNS and network routing for our domain.
- Email providers — to send and receive correspondence, invoices and automated reports.
- Apple and Google — where we publish a mobile app on your behalf, using the account and developer details required for the listing.
- Our accountant, and government agencies — where required for tax, audit or legal compliance.
We may also disclose information where required or authorised by law, or to protect our rights or someone's safety.
7. Overseas disclosure
Some of the providers listed above are located outside Australia or store data on servers outside Australia, including in the United States and Singapore. Where we disclose personal information to them, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. Servers hosting customer systems are provisioned in the Asia-Pacific region wherever practical.
8. How we protect it
- All traffic to our sites and applications is encrypted with HTTPS.
- Servers are firewalled, key-only for administrative access, and kept patched.
- Passwords are stored hashed, never in plain text, and staff sessions are signed and time-limited.
- Access to production systems is restricted to the people who need it.
- Databases and uploaded files are backed up nightly, and backups are access-controlled.
No system is perfectly secure. If a data breach occurs that is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
9. How long we keep it
We keep enquiry correspondence for up to 2 years, and billing and invoice records for at least 5 years as required by Australian tax law. Server access logs are kept for up to 90 days. Data inside a system we host for you is kept for as long as your plan is active; after cancellation it is retained for 30 days so it can be exported or restored, then deleted from live systems, with backups ageing out within a further 30 days.
10. Access, correction and deletion
You may ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email tashilhamoln@gmail.com and we will respond within 30 days. There is no charge for making a request. We may need to verify your identity first, and we may decline a request where the law requires us to keep the information — if we decline, we will tell you why.
11. Complaints
If you think we have mishandled your personal information, email us and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or by calling 1300 363 992.
12. Changes to this policy
We may update this policy from time to time. The current version is always at this address, with the "last updated" date at the top. If a change materially affects how we handle your information, we will notify you by email.
13. Contact
Privacy enquiries:
NextDataLinq
Perth, Western Australia, Australia
Email: tashilhamoln@gmail.com