Signplanr Privacy Policy
Last updated: 25 August 2026
Signplanr is operated by Milo Enterprises (Aust) Pty. Ltd. (ABN 66 668 291 469) ("we", "us", "our", "Milo Enterprises"). This Privacy Policy explains how we collect, use, store, disclose, and protect personal information in connection with the Signplanr platform ("the Service"), in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy covers everyone whose personal information we handle through the Service: organisers and team members, contractors, customer users (an organisation's own clients who are given a login), people who are invited to the Service, and visitors to our website.
By using the Service, you consent to the practices described in this policy. If you do not agree, you should not use the Service.
1. Information we collect
1.1 Account information
When you create an account, we collect your name, email address, and password. Passwords are cryptographically hashed and never stored in plain text. If you sign in through your organisation's single sign-on provider, we receive your name and email address from that provider.
1.2 Organisation data
Information you provide about your organisation, including organisation name, logo, billing contact details, tax identifiers (such as ABN), and member details.
1.3 Billing and payment information
If you subscribe to a paid plan, payment information (such as credit or debit card details) is collected and processed directly by our payment processor, Stripe. We do not store your full card number, CVV, or other sensitive payment credentials on our servers. We receive from Stripe a limited set of billing details, including card type, last four digits, expiry date, billing address, and transaction history, for the purpose of displaying billing information and managing your subscription.
For paid plans with storage overage billing enabled, we periodically calculate your organisation's storage usage and report aggregated overage quantities (in gigabytes) to Stripe for metered billing purposes. No file contents or filenames are shared with Stripe — only the total overage amount.
1.4 Event, sign, survey, and job data
Event details, sign types, sign placements, custom field values, status updates, assignment information, comments, announcements, survey questions and answers, annotated survey photos, job records, and the notification recipients you choose for an event.
1.5 Photos and files
Installation photos uploaded by contractors, map images, PDF site plans, artwork files, and reference documents uploaded by organisers. Photos are uploaded as captured by the device. Photo files may contain embedded metadata (EXIF) such as capture time, device model and — if location tagging is enabled on the camera — the GPS coordinates where the photo was taken. We do not currently remove this metadata, and it is retained with the photo and included when photos are exported.
1.6 Map and location data
Site plan images and PDF files you upload, as well as geographic coordinates (latitude and longitude) for sign placements on geo-maps.
Device location: when you choose to locate yourself on a geo-map, record a survey location, or create a geo-map, the app asks your browser for your device's current position and uses it to centre the map or place a pin. Survey locations are stored with the survey. We do not track your location in the background.
1.7 Device and usage data
When you use the Service, we may automatically collect:
- Device type and operating system
- Browser type and version
- IP address (used for security and rate limiting; anonymised before use in analytics)
- Pages visited, features used, and user interactions
We use PostHog for product analytics to understand how features are used and to improve the Service. PostHog collects usage events (such as page views and feature interactions), and for authenticated users, we associate analytics data with your account role and subscription plan tier to understand usage patterns across different user segments. PostHog may record anonymised session replays (with all text inputs automatically masked) to help us identify usability issues. PostHog does not serve advertisements and is configured to use browser local storage rather than cookies.
We also use Vercel Analytics and Vercel Speed Insights to measure website performance (such as page load times and Core Web Vitals). These tools collect anonymous, aggregated performance metrics and do not track individual users across sessions.
Advertising measurement. Our website and application load a Google Ads tag that sets advertising cookies and reports page views and a sign-up conversion event to Google so we can measure the effectiveness of our advertising. No sign, photo, or organisation data is sent to Google. You can block these cookies in your browser without affecting the Service.
1.8 Transactional email data
When we send you emails (such as account verification, password resets, invitations, or billing notifications), our email delivery provider processes your email address and message content for the purpose of delivering those emails.
1.9 Information from third parties
If you are invited to the platform by another user (via an organisation invitation, event invitation, or access code), we receive your email address from the inviting user for the sole purpose of facilitating the invitation.
1.10 Security and sign-in data
To keep accounts secure, we also hold:
- Trusted devices: if you choose to trust a device after two-factor authentication, we store a hashed token, a device and browser label, and the IP address at the time the device was trusted. Trusted devices expire after 30 days.
- Two-factor authentication: your authenticator secret is held by our authentication provider, and your backup codes are stored hashed.
- Single sign-on connections: for organisations using SSO, the organisation's email domain(s) and identity-provider metadata.
- Failed sign-in counters: short-lived, IP-based counters used for rate limiting and lockout.
- Email suppression records: addresses that have bounced or lodged a complaint, so we stop sending to them.
1.11 Customer users
An organisation may invite its own clients to the Service as customer users. If you are a customer user, we collect your name and email address, and the photos, comments, sign requests, approvals, and rejections you submit. This activity becomes part of the inviting organisation's records and is visible to that organisation. Customer users see only the signs they have been linked to, and customer users on the same event can see each other's names.
2. How we use your information
We use personal information for the following purposes:
- Providing the Service: Creating and managing your account, processing your data, enabling collaboration between organisers and contractors, and delivering the core functionality of the platform.
- Billing and subscriptions: Processing payments, managing your subscription plan, sending invoices and billing notifications, and enforcing plan limits.
- Communications: Sending transactional emails (account verification, password resets, invitations, billing notifications, and service announcements). We also send operational notifications to the people an organisation nominates (for example when a sign request or survey is submitted). If you subscribe to our newsletter, or your organisation is on the Free plan, we may send a small number of product and onboarding emails — including a short series in your first 30 days that may reference your organisation's own activity. Every such email includes an unsubscribe link, and the preference is recorded for your organisation. Transactional emails (security, billing, invitations) cannot be unsubscribed from while you have an account.
- Service improvement: Understanding aggregate usage patterns to improve features and performance. We do not use individually identifiable data for this purpose.
- Security and integrity: Detecting and preventing fraud, abuse, and unauthorised access. Maintaining audit logs of significant actions for platform security and accountability.
- Legal compliance: Complying with applicable laws, regulations, and legal processes.
3. How we store your data
3.1 Infrastructure
All structured data (accounts, events, signs, surveys, status history) is stored in a PostgreSQL database managed by Supabase in its Sydney, Australia region (AWS ap-southeast-2). Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Photos, maps, and uploaded files are stored in Supabase Storage in the same region, with access controls ensuring only authorised users can view or download files belonging to their organisation.
Application servers run in Vercel's Sydney region; Vercel's global edge network serves static assets and routes requests.
Our infrastructure providers maintain SOC 2 Type II compliance and implement industry-standard security practices.
3.2 Multi-tenant data isolation
Signplanr is a multi-tenant application. All organisations share the same infrastructure, but data is strictly isolated at the database level using row-level security (RLS) policies. Every database query is scoped to the authenticated user's organisation. There is no mechanism for one tenant to query, view, or modify another tenant's data through the application. Milo Enterprises personnel and automated system processes (for example scheduled maintenance jobs and billing webhooks) may access data across organisations where needed to operate, support, or secure the Service. Such access is limited to what the task requires and administrative actions are logged.
3.3 Cross-border data transfers
Your core application data is stored and processed in Australia. Some of the supporting services we rely on — Anthropic, Stripe, Resend, PostHog, Mapbox, Cloudflare, Upstash, and Google — operate in the United States or on global networks, and receive the limited data described in section 6. By using the Service you acknowledge that this information may be transferred to and processed outside Australia. We take reasonable steps to ensure that overseas recipients of personal information comply with the APPs, and our agreements with these providers include data protection obligations consistent with Australian privacy standards.
For users in the European Economic Area (EEA) or United Kingdom: transfers are made under Standard Contractual Clauses or other lawful transfer mechanisms as maintained by our infrastructure providers.
4. Data retention
4.1 Active accounts
Your data is retained for as long as your account is active. Archived events and their associated data (signs, photos, maps) remain accessible to you until you choose to delete them.
4.2 Event deletion
When you delete an event, all associated signs, photos, maps, reference documents, and status history are permanently removed after a 30-day retention window. This action cannot be undone after the retention period.
4.3 Organisation deletion
When an organisation is deleted, all associated data (events, signs, photos, maps, sign types, member records) is retained for 30 days before permanent deletion. Audit log records are retained for as long as needed for security and accountability; personal identifiers in them are anonymised when the related account is deleted.
4.4 Account termination
Upon account termination (whether by you or by us), we retain your data for 30 days to allow for data export, after which it is permanently deleted. Audit log records are retained for as long as needed for security and accountability; personal identifiers in them are anonymised when the related account is deleted.
4.5 Invitation records
Contractor and organisation invitation records are retained for audit purposes even after an invitation expires or is revoked.
4.6 Billing records
Transaction and invoice records are retained for the period required by applicable Australian tax law (currently 5 years from the date of the transaction) and by our payment processor's data retention policies.
4.7 Offline device storage
If you download an event for offline use in the mobile app, event data, sign records, map images, artwork, and any photos, comments, status changes, or survey answers you capture while offline are stored in your browser's storage on your device until they sync. This data is removed when you sign out or use Clear offline data, and you are responsible for the security of the device.
4.8 Exports
Exports (CSV, PDF, and photo ZIP files) are generated on request and downloaded to your device. Once downloaded, they are outside our control, and you are responsible for storing and sharing them appropriately.
5. Cookies and tracking
Signplanr does not use third-party tracking cookies for the purpose of building advertising profiles across websites. We do use a Google Ads conversion tag (see section 1.7), which sets advertising cookies to measure sign-ups from our advertising.
The Service uses essential browser storage (such as local storage and service worker caches) for the purpose of providing offline functionality in the contractor mobile app (see section 4.7), maintaining your authenticated session, and storing anonymous analytics identifiers for PostHog (so that usage events can be attributed to a single session). These do not track you across websites.
6. Third-party services
We use the following third-party services to operate the platform. Each service processes data only as necessary to perform its function:
| Service | Purpose | Data processed | Location |
|---|---|---|---|
Supabase | Authentication, database, and file storage | Account data, all application data, uploaded files | Australia (Sydney) |
Vercel | Application hosting and content delivery | HTTP requests, IP addresses (in server logs, auto-deleted) | Australia (Sydney) / Global edge |
Vercel Analytics | Web performance monitoring | Anonymous page load metrics, Core Web Vitals | United States |
Stripe | Payment processing | Billing details, payment card information, transaction data, metered storage usage quantities, subscription lifecycle events | United States |
Resend | Transactional and product email delivery; newsletter list | Email addresses, email content | United States |
PostHog | Product analytics and session replay | Usage events, page views, user role and plan tier, anonymised session recordings (inputs masked) | United States / EU |
Mapbox | Map tile rendering for geo-maps | Geographic coordinates, map viewport data | United States |
Cloudflare Turnstile | Bot prevention (CAPTCHA) | Browser signals, IP address, challenge interaction data | Global (Cloudflare network) |
Upstash | Rate limiting | IP addresses, request metadata (counters only, no content) | United States |
Anthropic | AI plan analysis (detecting sign locations on uploaded plans) | Plan and map images submitted for AI plan import | United States |
Google Ads | Advertising conversion measurement | Advertising cookie identifiers, page views on our site, sign-up conversion event | United States |
6.1 Stripe data processing
Stripe acts as a data sub-processor for payment-related personal information. When you subscribe to a paid plan, we share the following with Stripe: your organisation's billing contact name, billing address, tax identifier (e.g. ABN), and email address. Stripe processes payment card details directly — we never receive or store your full card number. Stripe's processing of your data is governed by the Stripe Privacy Policy. We maintain a data processing agreement with Stripe that includes obligations consistent with the Australian Privacy Principles.
6.2 Anthropic data processing (AI plan import)
Anthropic acts as a data sub-processor for our AI plan import feature (available on Business and Enterprise plans). When a member of your organisation runs a plan analysis, the uploaded plan or map image is sent to Anthropic's Claude AI service to detect the sign locations marked on the drawing. Only the map image is shared — no account details or other personal information accompany the request — and Anthropic processes it solely to perform the analysis and return the results to us. Images are sent to Anthropic only when a user explicitly requests an analysis; uploaded maps are never sent automatically. Under Anthropic's commercial terms, content submitted through the service is not used to train Anthropic's models. Anthropic's processing of this data is governed by the Anthropic Privacy Policy.
We do not sell or rent your personal data. Apart from the advertising measurement described above, we do not share personal data with advertisers or data brokers.
7. Data security
We implement reasonable technical and organisational measures to protect your personal information, including:
- Encryption at rest and in transit
- Row-level security for multi-tenant data isolation
- Cryptographic password hashing
- Role-based access controls
- Optional two-factor authentication and single sign-on
- CAPTCHA-based bot prevention on authentication forms
- Rate limiting on API and authentication endpoints
- Audit logging of significant administrative actions
- Regular security reviews
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials. For more details on our security practices, see our Security page.
7.1 Data breaches
If we become aware of a data breach that is likely to result in serious harm to individuals, we will assess it promptly and, where required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), notify affected individuals and the Office of the Australian Information Commissioner. Organisation Owners will be told of any breach affecting their organisation's data.
8. Your rights under Australian Privacy Principles
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate, incomplete, or out-of-date personal information
- Request deletion of your account and associated data
- Complain about a breach of the APPs
To exercise any of these rights, contact us at contact@signplanr.com. We will respond to access and correction requests within 30 days.
If you are not satisfied with our response to a privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
8.1 Additional rights for EEA/UK residents
If you are located in the European Economic Area or United Kingdom, you may also have the right to:
- Request restriction of processing
- Object to processing
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent at any time where processing is based on consent
9. Account deletion
You can request full deletion of your account and all associated personal data at any time by contacting us at contact@signplanr.com, or by using the account deletion feature in the Service (available at /account). We will process deletion requests within 30 days.
If you are an organisation owner, you must transfer ownership to another member before your account can be deleted, to prevent unintended data loss for other members.
When your account is deleted:
- Personal data is anonymised (name replaced with "Deleted User", email cleared)
- Your authentication account is disabled
- Organisation membership is removed
- Contractor event memberships are preserved as anonymised historical records for audit purposes
- Photos and comments are attributed to "Deleted User"
- Audit log records that reference your account are retained for security and accountability, with personal identifiers anonymised (see section 4.4)
10. Children's privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at contact@signplanr.com.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other operational reasons. When we make material changes:
- We will update the "Last updated" date at the top of this page
- For significant changes that affect how we process your personal information, we will provide notice through the Service (such as an in-app banner or email notification) at least 14 days before the changes take effect
- Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy
We encourage you to review this policy periodically.
12. Contact
If you have questions about this Privacy Policy or how we handle your personal information, contact us at:
Milo Enterprises (Aust) Pty. Ltd.
ABN 66 668 291 469
Email: contact@signplanr.com
For privacy complaints, you may also contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
See also our Terms of Service.