Privacy Policy
Last updated: February 2026
Signplanr is operated by Milo Enterprises (Aust) Pty. Ltd. (ABN 66 668 291 469) ("we", "us", "our", "Milo Enterprises"). This Privacy Policy explains how we collect, use, store, disclose, and protect personal information in connection with the Signplanr platform ("the Service"), in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using the Service, you consent to the practices described in this policy. If you do not agree, you should not use the Service.
1. Information we collect
1.1 Account information
When you create an account, we collect your name, email address, and password. Passwords are cryptographically hashed and never stored in plain text.
1.2 Organisation data
Information you provide about your organisation, including organisation name, logo, billing contact details, tax identifiers (such as ABN), and member details.
1.3 Billing and payment information
If you subscribe to a paid plan, payment information (such as credit or debit card details) is collected and processed directly by our payment processor, Stripe. We do not store your full card number, CVV, or other sensitive payment credentials on our servers. We receive from Stripe a limited set of billing details, including card type, last four digits, expiry date, billing address, and transaction history, for the purpose of displaying billing information and managing your subscription.
1.4 Event and sign data
Event details, sign types, sign placements, custom field values, status updates, assignment information, comments, and announcements you enter into the platform.
1.5 Photos and files
Installation photos uploaded by contractors, map images, PDF site plans, artwork files, and reference documents uploaded by organisers. Photos may be compressed client-side before upload.
1.6 Map and location data
Site plan images and PDF files you upload, as well as geographic coordinates (latitude and longitude) for sign placements on geo-maps.
1.7 Device and usage data
When you use the Service, we may automatically collect:
- Device type and operating system
- Browser type and version
- IP address (anonymised for analytics purposes)
- Pages visited and features used (in aggregate, not individually identifiable)
We use Plausible Analytics, a privacy-focused analytics service that does not use cookies and does not collect personal data. Plausible provides aggregate usage statistics only and is compliant with GDPR, PECR, and other privacy regulations without requiring a cookie consent banner.
1.8 Transactional email data
When we send you emails (such as account verification, password resets, invitations, or billing notifications), our email delivery provider processes your email address and message content for the purpose of delivering those emails.
1.9 Information from third parties
If you are invited to the platform by another user (via an organisation invitation, event invitation, or access code), we receive your email address from the inviting user for the sole purpose of facilitating the invitation.
2. How we use your information
We use personal information for the following purposes:
- Providing the Service: Creating and managing your account, processing your data, enabling collaboration between organisers and contractors, and delivering the core functionality of the platform.
- Billing and subscriptions: Processing payments, managing your subscription plan, sending invoices and billing notifications, and enforcing plan limits.
- Communications: Sending transactional emails (account verification, password resets, invitations, billing notifications, and service announcements). We do not send unsolicited marketing emails. Any promotional or lifecycle emails can be unsubscribed from at any time.
- Service improvement: Understanding aggregate usage patterns to improve features and performance. We do not use individually identifiable data for this purpose.
- Security and integrity: Detecting and preventing fraud, abuse, and unauthorised access. Maintaining audit logs of significant actions for platform security and accountability.
- Legal compliance: Complying with applicable laws, regulations, and legal processes.
3. How we store your data
3.1 Infrastructure
All structured data (accounts, events, signs, status history) is stored in a PostgreSQL database managed by Supabase. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Photos, maps, and uploaded files are stored in Supabase Storage with access controls ensuring only authorised users can view or download files belonging to their organisation.
Application hosting and delivery is provided by Vercel.
Our infrastructure providers maintain SOC 2 Type II compliance and implement industry-standard security practices.
3.2 Multi-tenant data isolation
Signplanr is a multi-tenant application. All organisations share the same infrastructure, but data is strictly isolated at the database level using row-level security (RLS) policies. Every database query is scoped to the authenticated user's organisation. There is no mechanism for one tenant to query, view, or modify another tenant's data through the application.
3.3 Cross-border data transfers
Our infrastructure providers (Supabase, Vercel, Stripe, and Resend) operate servers primarily in the United States and other countries outside Australia. By using the Service, you acknowledge and consent to your personal information being transferred to and processed in countries outside Australia. We take reasonable steps to ensure that overseas recipients of personal information comply with the APPs, and our agreements with these providers include data protection obligations consistent with Australian privacy standards.
For users in the European Economic Area (EEA) or United Kingdom: transfers are made under Standard Contractual Clauses or other lawful transfer mechanisms as maintained by our infrastructure providers.
4. Data retention
4.1 Active accounts
Your data is retained for as long as your account is active. Archived events and their associated data (signs, photos, maps) remain accessible to you until you choose to delete them.
4.2 Event deletion
When you delete an event, all associated signs, photos, maps, reference documents, and status history are permanently removed after a 30-day retention window. This action cannot be undone after the retention period.
4.3 Organisation deletion
When an organisation is deleted, all associated data (events, signs, photos, maps, sign types, member records) is retained for 30 days before permanent deletion. Audit log records are retained permanently for security and accountability purposes.
4.4 Account termination
Upon account termination (whether by you or by us), we retain your data for 30 days to allow for data export, after which it is permanently deleted. Audit log entries referencing your account are retained for security purposes but personal identifiers are anonymised.
4.5 Invitation records
Contractor and organisation invitation records are retained for audit purposes even after an invitation expires or is revoked.
4.6 Billing records
Transaction and invoice records are retained for the period required by applicable Australian tax law (currently 5 years from the date of the transaction) and by our payment processor's data retention policies.
5. Cookies and tracking
Signplanr does not use tracking cookies, advertising cookies, or third-party marketing pixels. We use Plausible Analytics, which operates without cookies and does not track individual users.
The Service uses essential browser storage (such as local storage and service worker caches) solely for the purpose of providing offline functionality in the contractor mobile app and maintaining your authenticated session. These are strictly necessary for the operation of the Service and do not track you across websites.
6. Third-party services
We use the following third-party services to operate the platform. Each service processes data only as necessary to perform its function:
| Service | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Authentication, database, and file storage | Account data, all application data, uploaded files | United States |
| Vercel | Application hosting and content delivery | HTTP requests, IP addresses (in server logs, auto-deleted) | United States / Global edge |
| Stripe | Payment processing | Billing details, payment card information, transaction data | United States |
| Resend | Transactional email delivery | Email addresses, email content | United States |
| Mapbox | Map tile rendering for geo-maps | Geographic coordinates, map viewport data | United States |
| Plausible | Privacy-focused website analytics | Aggregate page views, referrers, device types (no personal data) | European Union |
We do not sell, rent, or share your personal data with advertisers, data brokers, or any third party for their own marketing purposes.
7. Data security
We implement reasonable technical and organisational measures to protect your personal information, including:
- Encryption at rest and in transit
- Row-level security for multi-tenant data isolation
- Cryptographic password hashing
- Role-based access controls
- Audit logging of significant administrative actions
- Regular security reviews
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
8. Your rights under Australian Privacy Principles
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate, incomplete, or out-of-date personal information
- Request deletion of your account and associated data
- Complain about a breach of the APPs
To exercise any of these rights, contact us at contact@signplanr.com. We will respond to access and correction requests within 30 days.
If you are not satisfied with our response to a privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
8.1 Additional rights for EEA/UK residents
If you are located in the European Economic Area or United Kingdom, you may also have the right to:
- Request restriction of processing
- Object to processing
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent at any time where processing is based on consent
9. Account deletion
You can request full deletion of your account and all associated personal data at any time by contacting us at contact@signplanr.com, or by using the account deletion feature in the Service (available at /account). We will process deletion requests within 30 days.
If you are an organisation owner, you must transfer ownership to another member before your account can be deleted, to prevent unintended data loss for other members.
When your account is deleted:
- Personal data is anonymised (name replaced with "Deleted User", email cleared)
- Your authentication account is disabled
- Organisation membership is removed
- Contractor event memberships are preserved as anonymised historical records for audit purposes
- Photos and comments are attributed to "Deleted User"
10. Children's privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at contact@signplanr.com.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other operational reasons. When we make material changes:
- We will update the "Last updated" date at the top of this page
- For significant changes that affect how we process your personal information, we will provide notice through the Service (such as an in-app banner or email notification) at least 14 days before the changes take effect
- Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy
We encourage you to review this policy periodically.
12. Contact
If you have questions about this Privacy Policy or how we handle your personal information, contact us at:
Milo Enterprises (Aust) Pty. Ltd.
ABN 66 668 291 469
Email: contact@signplanr.com
For privacy complaints, you may also contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
See also our Terms of Service.