Opsivia Privacy Policy

Last updated: 21 July 2026

We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. What we collect

  • Account information: name, email, password (encrypted), organization details.
  • Business data you input: inventory records, staff details (name, contact info, pay rates, rostered hours), sales records, invoicing/client data, and content of any documents you upload (e.g. sales statements, supplier invoices) for AI processing.
  • Billing information: handled directly by Stripe; we store a reference to your Stripe customer ID but not full payment card details.
  • Usage data: log data, device/browser information, and analytics to help us improve the Service.

2. How we use it

  • To provide and operate the Service, including the features you've configured for your Organization.
  • To process AI-assisted features (e.g. extracting line items from uploaded photos/PDFs of sales statements or supplier invoices) — these are processed via our AI infrastructure and not used to train external models.
  • To send transactional emails (account verification, password resets, billing notices, roster notifications) and, where relevant, product updates.
  • To bill you for your subscription via Stripe.

3. Who we share it with

We share data with the following service providers as necessary to operate the platform:

  • Supabase (database and authentication hosting)
  • Stripe (payment processing)
  • Resend (transactional email delivery)
  • Lovable (application hosting and AI processing infrastructure)

These providers may store or process data outside Australia (including the United States). By using the Service, you acknowledge this overseas disclosure. We take reasonable steps to ensure these providers handle data securely.

We do not sell your data or your staff's/customers' personal information to third parties.

4. Data of your staff and customers

If you input personal information about your staff (for rostering) or your customers (for invoicing/sales records), you are responsible for ensuring you have the right to do so and, where required, that affected individuals are aware of how their information is being used. We process this data solely to provide the Service to you.

5. Data security

We use industry-standard measures including encryption in transit and at rest, role-based access controls, and tenant data isolation (each Organization's data is logically separated). No system is perfectly secure, and we encourage strong, unique passwords.

6. Data retention

We retain your data for as long as your account is active. On cancellation, data is retained for 30 days before deletion, unless you request earlier deletion or we are required by law to retain it longer.

7. Your rights

Under the Privacy Act, you may request access to, correction of, or deletion of personal information we hold about you, subject to legal exceptions. Contact us at info@opsivia.com.au to make a request.

8. Cookies

We use essential cookies/local storage to keep you logged in and remember your preferences. We do not use third-party advertising cookies.

9. Changes to this policy

We may update this policy from time to time. Material changes will be notified via email or in-app notice.

10. Contact

For privacy questions or complaints: info@opsivia.com.au. If unresolved, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).