Early access policy

Privacy Policy

How PayProof AU handles reports, person/contact details, evidence files, and responses.

Last updated 2 September 2026

1. Scope

This privacy policy explains how PayProof AU handles personal information during the early-access pilot. It is written to follow privacy-by-design principles and should be reviewed by an Australian privacy lawyer before public launch.

Even if a small business exemption applies at a particular stage, PayProof AU intends to handle personal information carefully because the service deals with payment disputes and reputational risk.

2. Information we collect

  • Waitlist details, such as name, email, industry, role, and the payment-risk problem you want solved.
  • Report details, such as ABN, business or project name, person or job-contact name, private contact hint, work type, invoice amount, invoice dates, payment status, follow-up notes, and evidence summaries.
  • Reporter details, such as name and email, so we can verify reports and contact the reporter during review.
  • Evidence files, such as job photos, invoices, quotes, contracts, correspondence, delivery records, payment receipts, and redacted bank transaction evidence.
  • Business response material, correction requests, takedown requests, and records of moderation decisions.
  • Technical information needed to run and protect the service, such as request logs, security events, device/browser data, and approximate usage information.

3. Information not to upload

  • Tax file numbers, Medicare numbers, passport details, driver licence numbers, passwords, full bank account numbers, card numbers, or full identity documents.
  • Private home addresses, personal phone numbers, health information, family information, employee details, number plates, faces, or unrelated third-party information unless truly necessary and lawful to provide.
  • Material covered by a suppression order, confidentiality obligation, settlement restriction, legal professional privilege, or another restriction you are not authorised to disclose.

4. How we use information

  • To operate the early-access pilot and respond to invite requests.
  • To receive, store, review, verify, moderate, and manage payment evidence.
  • To check whether report details match ABN, company, person/contact, invoice, public-record, or payment-context information.
  • To contact reporters, reported businesses, and people requesting corrections or takedowns.
  • To prevent abuse, fake reports, duplicate reports, spam, scraping, security incidents, and unlawful use.
  • To improve the product, moderation process, and user experience.
  • To send service messages and, where lawful and consented to, launch or product updates with an unsubscribe option.

5. What may become public

Evidence files are not intended to be public. Reporter identity is not intended to be public unless the reporter consents or disclosure is required by law.

After review, PayProof AU may publish a neutral summary that includes ABN, business name, trading name, person or job-contact name where necessary for identification, invoice amount or range, payment status, relevant dates, delay period, report count, verification status, dispute status, public-record context, and response material.

Private contact hints, private phone numbers, private emails, private addresses, bank details, identity documents, and raw evidence files are not intended to be public.

PayProof AU may refuse to publish, remove, or de-identify information where publication creates legal, privacy, safety, or fairness concerns.

6. Sharing information

  • With service providers who host, store, secure, process, or help operate PayProof AU.
  • With reviewers, advisers, lawyers, insurers, accountants, or professional support where needed to operate or protect the service.
  • With a reported business or affected person where needed to verify a report, invite a response, handle a correction request, or resolve a dispute. Reporter identity should not be shared unless necessary, consented to, or legally required.
  • With regulators, courts, law enforcement, or other third parties where required or authorised by law.
  • With a buyer or successor if the business is sold, merged, restructured, or transferred, subject to appropriate confidentiality and privacy protections.

7. Storage, security, and overseas processing

PayProof AU uses technical, administrative, and operational safeguards designed to protect information from misuse, interference, loss, unauthorised access, modification, and disclosure.

Hosting and service providers may store or process information in Australia or overseas. PayProof AU should keep an up-to-date provider list before public launch.

No online service can guarantee perfect security. If a serious eligible data breach occurs and PayProof AU is required to notify affected people or a regulator, PayProof AU will follow the applicable notification process.

8. Retention

PayProof AU keeps information only while it is needed for the pilot, verification, moderation, dispute handling, legal risk management, security, accounting, or other legitimate business purposes.

Information may be deleted, de-identified, restricted, or retained where required to handle legal claims, fraud prevention, safety issues, complaints, or audit records.

9. Access, correction, and complaints

You may ask PayProof AU to access or correct personal information it holds about you. You may also ask for inaccurate, out-of-date, incomplete, irrelevant, or misleading information to be corrected.

Privacy requests should be sent to ben.b.halligan@gmail.com.

If you are not satisfied with the response and Australian privacy law applies, you may be able to contact the Office of the Australian Information Commissioner.

10. Marketing messages

PayProof AU should only send commercial electronic messages where it has consent or another lawful basis. Marketing messages should identify PayProof AU, include contact details, and include an unsubscribe option.