Legal

Privacy Policy

Last updated: 6 September 2026

We collect the minimum personal information needed to run a paid, multi-user analytics product: who you are, which workspace you belong to, what you are subscribed to, and how the product is used. This page sets out the details and your rights.

1. Scope

This policy explains how Child Care Demand handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It covers the public website, the subscription product, and support interactions.

Report content is about places, services, and public planning records. It is not about individuals. The personal information we handle is mostly account and billing information about our users.

2. What we collect

  • Account information: name, work email, and authentication identifiers managed by our identity provider, Clerk, plus the Australian mobile number you add to Child Care Demand.
  • Workspace information: workspace name, membership, roles, and invitations.
  • Visibility portfolio information: the centres a workspace privately identifies as operated, owned as landlord, or both. These claims are self-reported and do not alter the public ACECQA provider record.
  • Local visibility check information: the selected centre, requested email address and mobile number for report-related contact, verification and report-access records, fixed search locations and queries, observed search positions, dated AI responses and citations, public website checks, comparison centres, provider costs, and data-quality states.
  • Billing information: subscription plan, seat count, and payment status. Card details are collected and stored by Stripe; we never see full card numbers.
  • Usage information: pages visited, signups, workspace creation, checkout, trial and subscription lifecycle, report starts/completions/failures/views/refreshes/shares, share-link opens, comparisons, and product events collected in our application database, via Google Tag Manager / Google Analytics, and via PostHog when configured, plus standard server logs.
  • Report activity context: report address, report name, report URL, report slug, report type, catchment, state, LGA, suburb or SA2 where available, workspace name, and the user account connected with the activity.
  • Communication preferences: the channel, status, source, consent wording and version, change time, and an audit history of later changes or withdrawals.
  • Support correspondence you send us.
  • When you report a data issue, we save the report ID and address, workspace and user identifiers, affected section, source links, your description and application version. A notification is sent to our support inbox through Resend and Crisp so we can investigate and follow up.

3. Why we collect it

  • To operate the product: authentication, workspace access, report generation, and share links.
  • To bill subscriptions and manage seats.
  • To secure the platform, prevent abuse, and debug issues.
  • To understand product usage, identify activation and churn risk, and improve features.
  • To respond to support requests and send service notices.
  • To deliver a requested Local SEO & AI Visibility Check, compare the selected centre with nearby operating services, and monitor centres only when a subscriber enables monitoring.
  • To send lifecycle marketing only when the recorded email or SMS preference permits it.

4. Who we disclose it to

We disclose personal information only to the service providers that run the platform, each under their own security and privacy commitments:

  • Clerk (authentication and user management)
  • Stripe (payments and subscription management)
  • Vercel (application hosting)
  • Neon (database hosting)
  • Google (Tag Manager and Analytics)
  • PostHog (product analytics, when enabled)
  • Resend (transactional and consented lifecycle email delivery)
  • Crisp (support inbox and website live chat, including the messages you send us and, when you are signed in, your name, email address, workspace, account role, plan, billing interval, signup date and whether your workspace has generated its first report)
  • Sentry (sanitised error and security-event diagnostics, including redacted page addresses and the workspace and user identifiers needed to match an error to a support request)
  • Upstash Redis (rate limiting and abuse prevention using user, workspace, or request identifiers)
  • Mapbox (address suggestions, geocoding, drive-time calculations, and map rendering for reports)
  • MapTiler (map tiles for reports)
  • DataForSEO (location-controlled Google and AI visibility observations for requested reports, when enabled)
  • Google PageSpeed Insights (public website performance and SEO-readiness checks)

5. Overseas disclosure

Some of these providers store data outside Australia, primarily in the United States. Where that happens, the disclosure is to deliver the service you signed up for, and we take reasonable steps to ensure providers handle personal information consistently with the Australian Privacy Principles. Our primary application database is hosted in the AWS Sydney region.

6. Security

Access to production systems is restricted and credential-based. Traffic is encrypted in transit, payment details never touch our servers, and webhook integrations are signature-verified. No internet service can promise perfect security, but we design so that a single compromised component exposes as little as possible.

7. Retention

We keep account, workspace, report activity, first-party analytics, and lifecycle alert records while your subscription is active and for a reasonable period afterwards for billing, dispute, support, product analytics, and audit purposes, then delete or de-identify them. Third-party analytics data is retained per the configured retention windows of the analytics providers.

Unconverted Local SEO & AI Visibility Check lead records expire after 90 days. Email verification links expire after 30 minutes and public report links expire after seven days. You can ask us to delete a private portfolio claim or visibility report subject to legal and audit requirements.

8. Cookies and analytics

The product uses strictly necessary cookies for sign-in sessions. The public site uses Google Tag Manager / Google Analytics to measure traffic; these set analytics cookies. We also use first-party local storage and session storage identifiers to understand visitor sessions, registration drop-off, activation, and retention. Product analytics may use PostHog cookies or local storage when configured. Blocking analytics cookies does not affect product sign-in.

Market history pages store the last research market you viewed and its timestamp in a first-party cookie for up to 30 days. This connects research visits with signup, trial and report activity on the same browser. It contains no street address and does not subscribe you to marketing.

We do not collect passwords, authentication/session tokens, raw share-link tokens, full card details, API keys, webhook signatures, or credentials in analytics events.

9. Communication choices

Email and SMS use one combined opt-in choice. You can later unsubscribe from email, SMS, or both in Settings. An email unsubscribe link also works without signing in and is recorded immediately.

SMS permission covers urgent changes to deals you are analysing. SMS delivery is not active yet. Withdrawing marketing permission does not stop account, billing, security or essential service messages needed to provide Child Care Demand.

A requested visibility report and enabled rank alerts are service messages. Marketing consent is separate and unchecked in the free report form. Subscribers can disable alerts for an individual centre and use the service-message unsubscribe control without changing general marketing consent.

10. Access, correction, and complaints

You can access and update most account details directly in the product. For access requests, corrections, deletion requests, or privacy complaints, email support@childcaredemand.com. We will respond within 30 days. If you are unsatisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

11. Changes to this policy

We will update this policy as the product and our providers change, and will note the date of the latest revision at the top of this page. Material changes will be notified in-product or by email.