Skip to content

Standards Mate Pty Ltd

Privacy Policy

How we collect, use, store and protect your information. Encrypted at rest and in transit, hosted in Sydney, compliant with the Australian Privacy Principles. Questions: [email protected].

1. Introduction

Standards Mate Pty Ltd (ABN 91 674 794 640), which runs StandardsMate™ ("we", "our" or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services. By using StandardsMate, you agree to the collection and use of information in accordance with this Privacy Policy.

2. Information We Collect

2.1 Information You Provide

  • We collect information that you provide directly to us, including:
  • Account Information: name, email address, password, and company details.
  • Profile Information: job title, industry, location, and professional qualifications.
  • Payment Information: billing details and payment card information (processed securely by Stripe, our PCI-DSS compliant payment processor).
  • Procurement Data: delivery addresses, purchase order details, and order history when using procurement features.
  • Referral Information: referral codes shared, referred users, and referral credit balances.
  • Communications: messages, questions, and feedback you send to us.
  • Feedback Calls: if you choose to give us your mobile number and tick the box saying the StandardsMate team can call you, we keep that number, when and where you agreed and the wording you saw, and use it only to call you about how StandardsMate is working for you and what to build next; we never sell it, never use it for marketing calls or texts, never show it on your quotes, invoices or job pages, and delete it when you remove it in Settings or delete your account.
  • Marketing Preferences: whether you have unsubscribed from our marketing email, when you unsubscribed or turned it back on, and how you did it, for example through the link in one of our emails or in your account settings. Since August 2026 each change has been logged with the email address, IP address and browser it came from, so we have a record that we acted on it. For an unsubscribe from before then, we hold only the fact that you unsubscribed.
  • Payment data security: All payment information is processed through Stripe, a PCI-DSS Level 1 certified payment processor. We do NOT store complete credit card numbers on our servers. Payment data is encrypted in transit using TLS/SSL encryption. We adhere to GDPR and Australian Privacy Principles for all payment data handling. All financial information is held to the highest levels of security protection.

2.2 Information Automatically Collected

  • When you use our service, we automatically collect:
  • Usage Data: pages viewed, features used, time spent, and interaction patterns.
  • Device Information: browser type, operating system, and device identifiers.
  • Location Data: approximate geographic location based on IP address.
  • Cookies and Tracking: data collected through cookies and similar technologies.
  • A first-party identifier: a randomly generated identifier stored in a cookie on your device the first time you visit, including when you arrive through one of our short links. We record the pages you view and the buttons you press against it, and the campaign or link that brought you here, whether or not you accept the banner. If you create an account, that history is joined to your account.
  • Short links: when you follow a standardsmate.com.au/go link we record the link code, the time, the referring site and your browser type. We do not record your IP address against the link.

2.3 Geolocation Data Collection

  • Marketing-page geolocation: when you visit our public pages we resolve an approximate geographic region (country, region, city, timezone, languages) from your IP address through a third-party service. This is used solely to localise content. We do not store this data on our servers. It is held in your browser's localStorage for up to 30 days and you can clear it at any time by clearing your browser cache.
  • Site diary: the site diary does not collect your device location. Each entry records when it was saved, who saved it and, where the job has an address, the weather at the job address. Diary entries saved before 30 September 2026 may hold the location your browser reported when the entry was saved, if you had allowed location access. That location stays with the entry for the life of the job; it is not shown in the app and is not used for anything.
  • Safety document sign-on: location is required at sign-on while the business asks for it on its safety document (SWMS) sign-ons. Before anything is collected, the signing page tells the worker that their location is recorded when they sign on, to show they were on site, and that the business sees it; their browser then asks for their location. Their precise location (latitude, longitude and its accuracy) is recorded with the signature, together with the date and time, their IP address and browser, and the state or territory whose notice they were shown, and appears on the business's own copy of the signed document. If the phone cannot find a location (no signal, or it takes too long), the sign-on still goes through and is marked "Location not confirmed" with the reason. If the worker blocks location, the sign-on cannot go through until they turn it back on, and they can ask their supervisor instead. The location is kept only with the sign-on record. It is shown only to the business and its job admins, is not printed on the copy emailed to the worker or on a shared link, and is not used in AI prompts, statistics, marketing or advertising audiences. A business can switch the requirement off, and then no location is asked for or saved. Locations saved before 30 September 2026, before the signing page said what it records, stay with the sign-on but are not shown or printed from now on; copies of the document already filed or emailed before this change may still carry them.

2.4 Information from Third Parties

  • We may receive information from:
  • Authentication Providers: Google (when you sign in using OAuth).
  • Analytics Services: usage statistics and performance data.
  • Payment Processors: transaction confirmation and billing information.

2.5 Customer Approvals and Electronic Signatures

  • When a customer approves a quote, variation, or scope of works through a unique approval link we send them, we capture the following as evidence of consent: the typed full name of the signer, a PNG image of the handwritten signature drawn on the canvas, the IP address the approval was submitted from, and the timestamp.
  • These artefacts are retained as part of the project record for the lifetime of the project and may be produced as evidence in the event of a dispute. We retain them in line with standard Australian e-signature evidence practice (cf. DocuSign / Adobe Sign). Customers can request access to or correction of their signature record by contacting us.

2.6 Uploaded Files and Photos

  • Documents you upload to a project (contracts, SWMS, certificates, drawings, insurance, permits), photos you attach to diary entries or material records, and files you attach to chat conversations are stored in encrypted cloud object storage (Amazon S3 in the Sydney region, AES-256 server-side encryption). Access is gated by short-lived signed URLs that rotate every five minutes.
  • Document contents are also parsed into searchable text fragments so the in-app AI assistant can quote them when answering questions inside that project. These fragments are stored alongside the document on our servers and are only retrievable within the scope of the project that uploaded them.

2.7 Time Tracking and Hours Logs

  • When you use the time-tracking feature, we record the start time, end time, computed duration, optional notes, optional hourly rate, billable flag, and member attribution for each entry. This data is used to calculate billable hours on the project, populate invoice line items, and provide weekly rollup summaries. Hourly rates are snapshotted at write time so retroactive rate changes do not alter previously logged history.

2.8 Push Notification Subscriptions

  • If you enable push notifications, your browser generates a unique endpoint URL and a pair of encryption keys (p256dh + auth). We store these alongside your user account so we can send you push messages when a task deadline is approaching, a project deadline is approaching, or you are mentioned. You can disable push notifications at any time from the Settings page or your browser's site settings; disabling soft-deletes the subscription on our side so we will stop sending pushes within seconds.

3. How We Use Your Information

  • We use your information to:
  • Provide, maintain, and improve our service.
  • Process your transactions and send related information.
  • Send you technical notices, updates, and support messages.
  • Respond to your comments, questions, and customer service requests.
  • Send you emails about StandardsMate, such as product updates, tips and offers, if you have an account. You can unsubscribe at any time, as described in section 4.
  • Monitor and analyse trends, usage, and activities.
  • Detect, prevent, and address technical issues and fraud.
  • Personalise and improve your experience.
  • Comply with legal obligations.
  • Improve the compliance answers our AI assistant gives, using feedback and questions as described in clause 3.1.
  • Enhance platform features based on user behaviour and feedback.

3.1 How we use what you type to improve StandardsMate

  • We do not train any AI model on your data. There is no model of our own to train: answers come from Anthropic’s Claude models reading the standards text we retrieve for your question (and, for the job features, the job details listed in clause 5.1), and under Anthropic’s commercial terms what we send is not used to train their models either.
  • What we do use: the thumbs up or down you give an answer, the reason you add, and the general feedback form, read by a person on our team to find and fix wrong answers.
  • Calculator inputs: your calculator inputs and results are saved to your account so you can see your last calculations again. A person on our team can also look at stored calculator inputs and results, for one calculation or added up across many, to check a calculator is giving a correct answer and to see what people are actually calculating.
  • Support: our admin console lists a short preview of each conversation, built from the first part of your message, so our team can find the right one to look into. A person on our team opens the full conversation to investigate a problem you have reported or an answer flagged as wrong, and every time a full conversation is opened it is logged. We do not open full conversations for any other reason.
  • Usage: which features and pages you use, counted as described in clause 9, decides what we build and fix next.
  • Website examples: we may show anonymised, edited versions of questions asked in the chat on our public website to illustrate how StandardsMate is used. These are reviewed by a person before they appear and never include your name, contact details, company, licence number or job address. Contact us if you would like a question removed or would prefer none of your questions be used this way.
  • If you would prefer that nobody on our team reads your questions for improvement, contact us and we will exclude your account; investigations you ask for yourself are the exception.

4. Marketing Communications

  • Our Terms of Service say, in clause 8.5, that creating an account includes agreeing to receive marketing email from StandardsMate. We may send you:
  • Platform updates and new feature announcements.
  • Educational content about Australian Standards and compliance.
  • Tips and best practices for using StandardsMate.
  • Special offers and promotions.
  • How to unsubscribe: every marketing email has an unsubscribe link at the bottom. You can also turn marketing email off, or back on, in Settings, on the Account tab, under Email preferences.
  • When it takes effect: the unsubscribe link and the setting both stop marketing email straight away. The only exception is an email that was already on its way when you unsubscribed.
  • What still arrives: unsubscribing stops marketing email only. You will still get the emails that come with using your account, such as email address verification, sign-in emails and password resets, receipts and emails about your paid plan and payments, and job emails such as invitations and reminders. Quotes, invoices and other documents you send to your own customers through StandardsMate still go out as normal.
  • If you do not have an account: if a business that uses StandardsMate sent you a form, a quote, an invoice or a document to sign, you are their customer and not ours. Clause 15.4 explains what we do and do not send you.

5. How We Share Your Information

5.1 Service Providers

  • Third-party vendors who perform services on our behalf, including:
  • Payment processing (Stripe).
  • Cloud hosting (AWS Sydney, ap-southeast-2).
  • Email delivery services.
  • Analytics providers.
  • Customer support tools.
  • Artificial intelligence: we use Anthropic’s Claude models, through Anthropic’s API, to answer compliance questions, draft job plans, scopes, quotes and safety documents, sort inbound email and label photos. Anthropic processes this data in the United States.
  • What is sent: the question or brief, the standards text we retrieve for it, your trade and region, and, when the assistant is used on a job, that job’s details, which can include a customer’s name, contact details and site address. Your password, payment details and files you have not attached to the request are never sent. Under Anthropic’s commercial terms, what we send is not used to train Anthropic’s models.
  • Speech to text: if you use the microphone button to dictate instead of typing, the audio is transcribed on our own server and is never sent to a third party.

5.2 Trade Suppliers and Business Partners

  • When you use our material ordering and procurement features, we share necessary information with: trade suppliers (building materials suppliers, electrical wholesalers and other trade vendors) to fulfill your orders and provide pricing information; delivery partners (logistics and delivery companies) to ship your orders; payment processors for processing transactions with suppliers; procurement partners that facilitate material sourcing and price comparison.
  • We only share information necessary to fulfill your orders (such as delivery address, contact details, and order specifications). We do not sell your personal information to suppliers or partners.
  • Anonymised data sharing: we may share anonymised and aggregated data with trade suppliers to improve service quality, pricing, and inventory availability. Anonymised purchase trends, market insights, inventory optimisation, pricing analysis. All personal identifying information is removed before data is shared with suppliers. Data is aggregated and anonymised so individual users cannot be identified. Suppliers receive statistical trends only, never individual user data. No financial information, payment details, or contact information is shared in this process.

5.3 Standards and Compliance Data Providers

  • To provide accurate standards information, we may work with:
  • Standards Australia: for access to Australian Standards content and updates.
  • Regulatory Bodies: for current compliance requirements and regulatory information.
  • Industry Associations: for best practices and industry-specific guidance.
  • Content Providers: for educational materials and compliance resources.

5.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5.5 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities.

5.6 With Your Consent

We may share your information for any other purpose with your explicit consent.

6. Data Security

  • We implement appropriate technical and organisational security measures to protect your personal information, including:
  • Encryption of data in transit (TLS/SSL) and at rest.
  • Production data hosted on AWS infrastructure in Sydney (ap-southeast-2).
  • Secure password hashing (bcrypt/Argon2).
  • Regular security assessments and updates.
  • Access controls and authentication.
  • Monitoring for unauthorised access.
  • No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

6.1 Data Breach Notification

  • In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will:
  • Notify affected users without undue delay (within 72 hours where feasible).
  • Notify relevant supervisory authorities as required by law.
  • Provide information about the nature of the breach, data affected, and mitigation steps.
  • Take immediate action to contain and remediate the breach.
  • Offer guidance on steps you can take to protect yourself.

7. Data Retention

  • We retain your personal information for as long as necessary to: provide our services to you; comply with legal obligations; resolve disputes; enforce our agreements.

7.1 Retention Periods

  • Active Account Data: retained while your account is active.
  • Deleted Account Data: deleted immediately upon account deletion, except where a line below says a record is kept for longer, such as the log of your marketing email choices.
  • Transaction Records: retained for 7 years for tax and accounting purposes.
  • Referral and Credit Data: retained for 7 years for tax and financial record purposes.
  • Marketing Preferences: whether you have unsubscribed is kept while your account exists. The log of each time you unsubscribe or turn it back on (email address, IP address and browser) is kept after you unsubscribe and after your account is deleted, so we can show we acted on your request.
  • Professional Verification Documents: retained while account is active plus 2 years.
  • Legal Hold Data: retained until legal matters are resolved.
  • Website visit history not linked to an account: deleted after 90 days.
  • Website visit history linked to an account: kept while the account exists and deleted with it.
  • Short link click records: the identifier is removed after 90 days and the record is deleted after 13 months.
  • Records of your cookie and advertising choice: kept while the account exists.
  • When your information is no longer needed, we will securely delete or anonymise it.

8. Your Rights and Choices

  • You have the right to:
  • Access: request a copy of your personal information.
  • Correction: update or correct inaccurate information.
  • Deletion: request deletion of your personal information.
  • Portability: receive your data in a structured, commonly used format.
  • Objection: object to processing of your information.
  • Restriction: request restriction of processing.
  • Withdrawal: withdraw consent at any time.
  • To exercise these rights, please contact us using the information provided below.

8.1 Self-Service Data Management

  • As an authenticated user, you can manage your data directly through your account settings:
  • Download Your Data: visit your Settings page to export all your personal data in JSON format.
  • Delete Your Account: use the "Delete Account" feature in Settings to permanently remove your account and all associated data.
  • Update Your Information: modify your profile information, email preferences, and account settings at any time.
  • Quick access: logged-in users can access these features by going to Dashboard → Settings.

9. Cookies and Tracking Technologies

  • Our own analytics: the first-party identifier described in section 2.2 runs regardless of the cookie banner. We use it to operate and improve StandardsMate and to measure which of our own advertising brought people to this site.
  • Only if you press Accept on the banner, we also use: Google Analytics 4 and Google Ads (Google LLC), Microsoft Clarity (Microsoft Corporation), Meta Pixel and the Meta Conversions API (Meta Platforms, Inc.), and Reddit Pixel (Reddit, Inc.).
  • What is sent to them: page URLs with tokens removed, device and browser information, advertising click identifiers, and, for the Conversions API, a hashed form of your email address, your IP address and your browser identifier.
  • Purposes: to measure our advertising and to show StandardsMate advertising to people who have visited this site.
  • These providers store data in the United States.
  • How to withdraw: press Decline on the banner, use the "Cookie and advertising choices" link on this page to choose again, or use Google’s and Meta’s own advertising settings.
  • Platform retention: Google keeps advertising lists for up to 540 days and Meta for up to 180 days.
  • Types of cookies we use:
  • Essential Cookies: required for the service to function.
  • Analytics Cookies: help us understand how you use the service.
  • Preference Cookies: remember your settings and preferences.
  • Advertising Cookies: set only if you press Accept on the banner, used by Google, Meta and Reddit to measure our advertising and to show StandardsMate advertising to people who have visited this site.

9.1 Third-Party Links

Our service may contain links to third-party websites, services, or resources that are not owned or controlled by StandardsMate. We are not responsible for the privacy practices or content of these third-party sites. We encourage you to review the privacy policies of any third-party sites you visit. This Privacy Policy applies only to information collected by our service.

10. Children's Privacy

Our service is intended for users who are 16 years of age or older. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child under 16 has provided us with personal information, please contact us and we will delete such information.

11. International Data Transfers

  • Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.
  • We take steps to ensure that your data is treated securely and in accordance with this Privacy Policy, including:
  • Using Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to countries outside the EEA.
  • Ensuring our service providers comply with applicable data protection frameworks.
  • Implementing appropriate technical and organisational safeguards.
  • Conducting due diligence on all international data processors.

11.1 Automated Decision Making

  • We may use automated decision making in certain contexts, including:
  • Credit Limit Assessment: automated evaluation of credit applications for procurement (subject to manual review).
  • Content Recommendations: AI-powered suggestions for relevant standards and compliance information.
  • Fraud Detection: automated analysis to identify suspicious transactions or activities.
  • Your rights: you have the right to request human review of any automated decision that significantly affects you, to express your point of view, and to contest the decision.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.

13. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us: StandardsMate. Privacy Team, Brisbane, Queensland, Australia. Email: [email protected].

14. Australian Privacy Act Compliance

StandardsMate is committed to compliance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We handle personal information in accordance with these principles and applicable Australian privacy laws.

14.1 Privacy Complaints Process

  • If you believe we have breached the Australian Privacy Principles or you wish to make a privacy complaint:
  • Contact our Privacy Team at [email protected] with details of your complaint.
  • We will acknowledge your complaint within 7 business days.
  • We will investigate your complaint and respond within 30 days.
  • If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
  • For more information about your privacy rights in Australia, visit the OAIC website at www.oaic.gov.au.

15. If a business sent you a link

Tradespeople and businesses use StandardsMate to run their jobs. If one of them sent you an enquiry form, a job link, a quote, an invoice or a document to sign, then you are their customer and not ours. You have no account with us and you have not agreed to anything with us. Everything above this section is written for account holders. This section is written for you, because your information is handled by our software and you are entitled to know how.

15.1 What is collected about you

  • What you type into a form the business sends you: your name, email address, phone number, the address of the job, your answers to their questions, and anything you write in a notes or description field.
  • Photos and files you upload.
  • Your signature, where you sign a scope of work or a safety document, captured as an image.
  • Technical information about the visit: your IP address, your browser and device type, which pages you open, how long you stay, and which buttons and links you press, including the text on them. A randomly generated identifier is stored in your browser so repeat visits can be recognised. This is recorded whether or not you submit the form.
  • When you sign a safety document, your location is required at sign-on while the business asks for it. Before anything is collected, the page tells you that your location is recorded when you sign on, to show you were on site, and that the business sees it; your browser then asks for it. Your precise location at that moment is saved with the signature, together with the state or territory whose notice you were shown. If your phone cannot find a location, you still sign on and the sign-on is marked "Location not confirmed" with the reason. If you block location, you cannot sign on through the page until you turn it back on, or you can ask your supervisor. Your location is printed on the business's own copy of the signed document and shown in StandardsMate to the business and its job admins. It is kept only with the sign-on record, it is not on the copy emailed to you or on a shared link, and StandardsMate does not use it for anything else, including AI prompts, statistics, marketing or advertising audiences. Your IP address and browser are recorded with every signature.

15.2 Who holds it

  • The business that sent you the link. They chose to collect it, they decide what it is used for, and they are the right people to contact about it first.
  • StandardsMate, because we operate the software that business uses. Our staff can access the information in order to run the service, investigate faults and provide support.

15.3 Where it goes

  • Storage: on our servers in Sydney, Australia, encrypted at rest and in transit.
  • Files: photos, uploads and signature images are held in encrypted cloud storage in Sydney, and are reachable only through short-lived links issued to people entitled to the job, as described in clause 2.6.
  • Mapping: when the business turns on site maps, on their jobs list or on a job page, the job’s site address is sent from their browser to mapping services outside Australia to place a pin: Komoot Photon (Germany) and, as a fallback, Open-Meteo (Switzerland). The pin’s coordinates then go to OpenStreetMap Overpass (Germany) for the building outline, to Esri (United States) for the satellite imagery, and to Open-Meteo for the weather at the site. Where a job already holds coordinates, the address itself is not sent; only the coordinates are. Address suggestions offered while the business types an address come from OpenStreetMap Nominatim. The business is shown this and asked to agree the first time they turn site maps on, and can turn them off at any time.
  • Artificial intelligence: when the business uses the assistant on your job, details of that job are sent to our AI provider, Anthropic (United States), so it can answer their question or draft their paperwork. Those details can include your name, your contact details and the site address.
  • Email: mail we send you for the business goes through our email provider. It contains a tracking image and rewritten links, which tell the business when the message was opened and which links were followed. Your replies may be copied to an address that files them against the job.
  • Network and anti-spam: Cloudflare provides our network and the check that stops automated form submissions, and receives your IP address and browser information.
  • Product analytics: we record how the pages and forms are used, as described in 15.1, to operate and improve the product.
  • Only if you accept cookies on the banner: Microsoft Clarity records a replay of your session on the page, Google Ads and the Meta Conversions API measure our advertising, and advertising pixels from Meta and Reddit are loaded. Declining leaves these switched off.

15.4 What we do not do with it

  • We do not sell it.
  • We do not send you marketing because a business used StandardsMate with you, and giving your details to a business does not create an account or a mailing list entry for you. Emails a business sends you through StandardsMate can end with our name, a short description of StandardsMate and links to our website.
  • We do not use your details to contact you ourselves. Contact about the job comes from the business.

15.5 How long it is kept, and how to have it removed

  • The business keeps the job record for as long as they need it, the same as any other record of work they have done for you. It is their record, so ask them first.
  • If you cannot reach them, or you would rather ask us, email [email protected] with the name of the business and the link they sent you, and we will help you reach them or deal with the request ourselves where we are able to.
  • You can ask what is held about you, ask for it to be corrected, or complain, using the process in section 14. That process is open to you even though you are not an account holder.

Last updated: 30 September 2026.