Skip to main content

Privacy Policy

Last updated: February 2026

Signplanr is operated by Milo Enterprises (Aust) Pty. Ltd. (ABN 66 668 291 469) ("we", "us", "our", "Milo Enterprises"). This Privacy Policy explains how we collect, use, store, disclose, and protect personal information in connection with the Signplanr platform ("the Service"), in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using the Service, you consent to the practices described in this policy. If you do not agree, you should not use the Service.

1. Information we collect

1.1 Account information

When you create an account, we collect your name, email address, and password. Passwords are cryptographically hashed and never stored in plain text.

1.2 Organisation data

Information you provide about your organisation, including organisation name, logo, billing contact details, tax identifiers (such as ABN), and member details.

1.3 Billing and payment information

If you subscribe to a paid plan, payment information (such as credit or debit card details) is collected and processed directly by our payment processor, Stripe. We do not store your full card number, CVV, or other sensitive payment credentials on our servers. We receive from Stripe a limited set of billing details, including card type, last four digits, expiry date, billing address, and transaction history, for the purpose of displaying billing information and managing your subscription.

1.4 Event and sign data

Event details, sign types, sign placements, custom field values, status updates, assignment information, comments, and announcements you enter into the platform.

1.5 Photos and files

Installation photos uploaded by contractors, map images, PDF site plans, artwork files, and reference documents uploaded by organisers. Photos may be compressed client-side before upload.

1.6 Map and location data

Site plan images and PDF files you upload, as well as geographic coordinates (latitude and longitude) for sign placements on geo-maps.

1.7 Device and usage data

When you use the Service, we may automatically collect:

  • Device type and operating system
  • Browser type and version
  • IP address (anonymised for analytics purposes)
  • Pages visited and features used (in aggregate, not individually identifiable)

We use Plausible Analytics, a privacy-focused analytics service that does not use cookies and does not collect personal data. Plausible provides aggregate usage statistics only and is compliant with GDPR, PECR, and other privacy regulations without requiring a cookie consent banner.

1.8 Transactional email data

When we send you emails (such as account verification, password resets, invitations, or billing notifications), our email delivery provider processes your email address and message content for the purpose of delivering those emails.

1.9 Information from third parties

If you are invited to the platform by another user (via an organisation invitation, event invitation, or access code), we receive your email address from the inviting user for the sole purpose of facilitating the invitation.

2. How we use your information

We use personal information for the following purposes:

  • Providing the Service: Creating and managing your account, processing your data, enabling collaboration between organisers and contractors, and delivering the core functionality of the platform.
  • Billing and subscriptions: Processing payments, managing your subscription plan, sending invoices and billing notifications, and enforcing plan limits.
  • Communications: Sending transactional emails (account verification, password resets, invitations, billing notifications, and service announcements). We do not send unsolicited marketing emails. Any promotional or lifecycle emails can be unsubscribed from at any time.
  • Service improvement: Understanding aggregate usage patterns to improve features and performance. We do not use individually identifiable data for this purpose.
  • Security and integrity: Detecting and preventing fraud, abuse, and unauthorised access. Maintaining audit logs of significant actions for platform security and accountability.
  • Legal compliance: Complying with applicable laws, regulations, and legal processes.

3. How we store your data

3.1 Infrastructure

All structured data (accounts, events, signs, status history) is stored in a PostgreSQL database managed by Supabase. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Photos, maps, and uploaded files are stored in Supabase Storage with access controls ensuring only authorised users can view or download files belonging to their organisation.

Application hosting and delivery is provided by Vercel.

Our infrastructure providers maintain SOC 2 Type II compliance and implement industry-standard security practices.

3.2 Multi-tenant data isolation

Signplanr is a multi-tenant application. All organisations share the same infrastructure, but data is strictly isolated at the database level using row-level security (RLS) policies. Every database query is scoped to the authenticated user's organisation. There is no mechanism for one tenant to query, view, or modify another tenant's data through the application.

3.3 Cross-border data transfers

Our infrastructure providers (Supabase, Vercel, Stripe, and Resend) operate servers primarily in the United States and other countries outside Australia. By using the Service, you acknowledge and consent to your personal information being transferred to and processed in countries outside Australia. We take reasonable steps to ensure that overseas recipients of personal information comply with the APPs, and our agreements with these providers include data protection obligations consistent with Australian privacy standards.

For users in the European Economic Area (EEA) or United Kingdom: transfers are made under Standard Contractual Clauses or other lawful transfer mechanisms as maintained by our infrastructure providers.

4. Data retention

4.1 Active accounts

Your data is retained for as long as your account is active. Archived events and their associated data (signs, photos, maps) remain accessible to you until you choose to delete them.

4.2 Event deletion

When you delete an event, all associated signs, photos, maps, reference documents, and status history are permanently removed after a 30-day retention window. This action cannot be undone after the retention period.

4.3 Organisation deletion

When an organisation is deleted, all associated data (events, signs, photos, maps, sign types, member records) is retained for 30 days before permanent deletion. Audit log records are retained permanently for security and accountability purposes.

4.4 Account termination

Upon account termination (whether by you or by us), we retain your data for 30 days to allow for data export, after which it is permanently deleted. Audit log entries referencing your account are retained for security purposes but personal identifiers are anonymised.

4.5 Invitation records

Contractor and organisation invitation records are retained for audit purposes even after an invitation expires or is revoked.

4.6 Billing records

Transaction and invoice records are retained for the period required by applicable Australian tax law (currently 5 years from the date of the transaction) and by our payment processor's data retention policies.

5. Cookies and tracking

Signplanr does not use tracking cookies, advertising cookies, or third-party marketing pixels. We use Plausible Analytics, which operates without cookies and does not track individual users.

The Service uses essential browser storage (such as local storage and service worker caches) solely for the purpose of providing offline functionality in the contractor mobile app and maintaining your authenticated session. These are strictly necessary for the operation of the Service and do not track you across websites.

6. Third-party services

We use the following third-party services to operate the platform. Each service processes data only as necessary to perform its function:

ServicePurposeData processedLocation
SupabaseAuthentication, database, and file storageAccount data, all application data, uploaded filesUnited States
VercelApplication hosting and content deliveryHTTP requests, IP addresses (in server logs, auto-deleted)United States / Global edge
StripePayment processingBilling details, payment card information, transaction dataUnited States
ResendTransactional email deliveryEmail addresses, email contentUnited States
MapboxMap tile rendering for geo-mapsGeographic coordinates, map viewport dataUnited States
PlausiblePrivacy-focused website analyticsAggregate page views, referrers, device types (no personal data)European Union

We do not sell, rent, or share your personal data with advertisers, data brokers, or any third party for their own marketing purposes.

7. Data security

We implement reasonable technical and organisational measures to protect your personal information, including:

  • Encryption at rest and in transit
  • Row-level security for multi-tenant data isolation
  • Cryptographic password hashing
  • Role-based access controls
  • Audit logging of significant administrative actions
  • Regular security reviews

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

8. Your rights under Australian Privacy Principles

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate, incomplete, or out-of-date personal information
  • Request deletion of your account and associated data
  • Complain about a breach of the APPs

To exercise any of these rights, contact us at contact@signplanr.com. We will respond to access and correction requests within 30 days.

If you are not satisfied with our response to a privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

8.1 Additional rights for EEA/UK residents

If you are located in the European Economic Area or United Kingdom, you may also have the right to:

  • Request restriction of processing
  • Object to processing
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent at any time where processing is based on consent

9. Account deletion

You can request full deletion of your account and all associated personal data at any time by contacting us at contact@signplanr.com, or by using the account deletion feature in the Service (available at /account). We will process deletion requests within 30 days.

If you are an organisation owner, you must transfer ownership to another member before your account can be deleted, to prevent unintended data loss for other members.

When your account is deleted:

  • Personal data is anonymised (name replaced with "Deleted User", email cleared)
  • Your authentication account is disabled
  • Organisation membership is removed
  • Contractor event memberships are preserved as anonymised historical records for audit purposes
  • Photos and comments are attributed to "Deleted User"

10. Children's privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at contact@signplanr.com.

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other operational reasons. When we make material changes:

  • We will update the "Last updated" date at the top of this page
  • For significant changes that affect how we process your personal information, we will provide notice through the Service (such as an in-app banner or email notification) at least 14 days before the changes take effect
  • Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy

We encourage you to review this policy periodically.

12. Contact

If you have questions about this Privacy Policy or how we handle your personal information, contact us at:

Milo Enterprises (Aust) Pty. Ltd.
ABN 66 668 291 469
Email: contact@signplanr.com

For privacy complaints, you may also contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

See also our Terms of Service.