Privacy policy
How we collect, use, share, and protect personal information
Effective date: 3 August 2026
1. Who we are and what this policy covers
Tradie Forms Australia (ABN 97 663 623 050) operates Tradie Forms. We provide tools that help Australian tradies fill, manage, share, sign, lodge, and export trade paperwork. We are not affiliated with any government, regulator, or statutory authority.
This policy explains how we handle personal information when you visit our website, create an account, use the service, contact support, or interact with a form or link shared through Tradie Forms.
2. Information we collect
Account, workspace, and billing information
We collect information such as your name, email address, account and sign-in details, workspace membership and role, preferences, plan, billing status, and transaction records. Stripe processes payment card details. We do not store complete card details on our servers.
Forms, jobs, and saved details
We collect the information you enter, upload, import, or generate while using the service. Depending on the form, this may include business and licence details, customer and worker contact details, site addresses, job notes, test results, signatures, photos, attachments, form drafts, completed forms, PDFs, and lodgement records.
Some of this information may relate to customers, workers, property owners, signers, or other people who do not have a Tradie Forms account. If you provide information about another person, you are responsible for having authority or another lawful basis to do so.
Sharing, signing, and lodgement information
If you create a share or signature link, we collect the information needed to operate and secure it, including the form or PDF made available, link status and expiry, access events, and any signer name or signature provided. If you lodge a supported form, we keep the submission status, references, licence details used, and related audit information.
Connected service information
If you connect ServiceM8, Fergus, or Xero, we collect connection and workspace identifiers, encrypted credentials or tokens, permissions, provider account details, and any import mappings you save. We access job, customer, contact, project, business, or staff information when you search, import, or request an available action. We do not bulk-copy your connected service database into Tradie Forms.
AI assistant information
The AI assistant processes what you choose to send to it. This can include chat messages, current form fields and answers, saved details, connected service information, images, documents, voice recordings and transcripts, assistant responses, and actions you ask it to perform. We store the active assistant conversation so you can continue it.
Usage, device, and support information
We collect technical and usage information such as IP address, browser and device details, approximate country or region, pages visited, features used, download activity, performance data, and errors. Our product analytics do not include form answers, attachments, customer details, assistant prompts, or assistant responses. We also collect information you send when you contact support or provide feedback.
3. How we collect and use information
We collect information directly from you and when you:
- create an account, join a workspace, or manage a subscription
- fill, save, upload, share, sign, lodge, or export paperwork
- connect and use a third-party service
- use the AI assistant, address search, licence lookup, or another tool
- visit the website or use the app
- contact support or respond to a survey
We use this information to:
- provide, personalise, and maintain the service
- authenticate accounts and manage workspace access
- save drafts and completed forms, generate PDFs, and keep audit records
- run features you choose, including connections, sharing, signing, lodgement, and AI assistance
- process subscriptions and keep accounting records
- send authentication, billing, security, support, and service messages
- measure product usage, fix errors, improve performance, and develop features
- prevent misuse, protect the service, comply with law, and resolve disputes
If we cannot collect information needed for an account or feature, we may not be able to provide that account or feature. You can still browse public pages and, where available, fill forms locally without signing in.
4. When we share information
We share personal information only as needed for the following purposes:
- Service providers: with providers that support hosting and data storage, authentication, payments, analytics and error reporting, email, address features, AI processing, and other service operations. These include Convex, Clerk, Stripe, PostHog, Google Maps, Vercel AI Gateway, and the AI providers selected through it.
- Your workspace: with people who can access the same team workspace, according to their role and the features you use.
- People you choose: with recipients of share or signature links. Anyone with a valid link, and a password if you set one, may be able to access the information made available through it.
- Connected services: with ServiceM8, Fergus, or Xero when you connect an account, request an import, or choose to attach a completed PDF back to that service.
- Authorities: with a regulator or its service provider when you choose to lodge a supported form, and where required or authorised by law.
- Business changes: with advisers and a prospective buyer, investor, or successor where reasonably necessary for a sale, financing, restructure, or transfer of the business, subject to appropriate confidentiality protections.
We do not sell personal information or use form content for targeted advertising.
5. Connected services
Connections are optional. The provider shows you the permissions requested before you connect. Imported values become part of the form, job, or saved record you place them into and are then handled like other information in that record.
ServiceM8
We may read your business profile and the job, customer, contact, address, schedule, note, category, and assigned staff details available under the permissions you approve. If you enable PDF upload, we can attach a completed PDF to the selected ServiceM8 job when you ask us to.
Fergus
We may read company, job, site, customer, and contact details available under the permissions you approve. If PDF upload is available and enabled, we can attach a completed PDF to the selected Fergus job when you ask us to.
Xero
We may read organisation settings, contacts, addresses, and projects where Xero Projects is enabled and the approved permissions allow it. If you enable PDF upload, we can attach a completed PDF to the selected Xero contact when you ask us to.
Disconnecting
Disconnecting from Connections removes the stored credentials and disables future access. We may retain non-secret connection metadata and saved import mappings to support your records or a later reconnection until they are no longer needed. Information you already imported into a form, job, or saved record remains there until that record is deleted under the controls and retention rules that apply to it. You may also need to revoke access in the provider's own account settings.
6. AI assistant
AI requests are sent through Vercel AI Gateway or our configured transcription service to the language, vision, or transcription provider needed for the request. Providers and processing locations may change as we maintain the feature.
We do not use assistant prompts, attachments, voice recordings, transcripts, or responses to train public AI models. We require our AI providers to process that information to provide services to us, subject to their applicable provider agreements. Voice recordings are sent for transcription and are not stored in your assistant chat history.
Select New chat to delete the active conversation from our live account data. This does not undo processing already completed by a provider or remove information that must remain temporarily in security logs, backups, or records kept to meet legal obligations.
7. Storage, overseas handling, and security
Our providers may store or process personal information in Australia, the United States, and other countries where they or their subprocessors operate. This is most likely for cloud hosting, authentication, analytics, payments, support, and AI processing. Contact us if you need the current provider list or likely countries for a particular feature.
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Measures include encryption in transit and at rest where supported, access controls, authentication, monitoring, secure credential storage, and backup and recovery processes. No online service can guarantee absolute security.
8. Retention and deletion
We keep personal information only for as long as reasonably needed for the purposes described in this policy, including providing the service, meeting legal and accounting obligations, preventing fraud, maintaining security, and resolving disputes.
- Account, workspace, and subscription records are generally kept while the account or workspace is active and for a reasonable period after closure where required for the purposes above.
- Completed forms, jobs, saved details, presets, and related files remain until you delete them, close the relevant account or workspace, or we no longer need them.
- Cloud drafts are deleted according to the draft retention period set for the account or workspace. The default is 30 days after the draft was last updated.
- Share and signature links expire after the period selected when they are created and can be revoked earlier. Sensitive link content is removed after expiry or revocation under our cleanup process.
- Connection credentials remain until you disconnect, revoke access, or the connection is otherwise removed. Short-lived search and import caches expire automatically.
- De-identified analytics may be kept for product measurement and improvement.
Deleted information may remain for a limited time in protected backups or logs before it is overwritten or de-identified. We may also retain information where law requires or permits it.
9. Your choices and privacy rights
- Update account, workspace, and saved details in the service.
- Delete forms, jobs, saved details, share links, and assistant chats where controls are available.
- Turn cloud autosave or the AI assistant off in Settings where available for your plan.
- Disconnect ServiceM8, Fergus, or Xero from Connections.
- Control cookies and local storage through your browser. Blocking all cookies may prevent sign-in or other account features.
- Ask us for access to or correction of personal information we hold about you.
- Ask us to delete information. We will assess the request against any legal, security, backup, accounting, or other legitimate retention need.
To make a request, contact support@tradieforms.com.au. We may need to verify your identity and authority before acting. If the information belongs to a team workspace, the workspace administrator may also control access to it.
10. Privacy questions and complaints
Send privacy questions or complaints to support@tradieforms.com.au. Include enough detail for us to understand the issue. We will acknowledge the complaint, investigate it, and aim to respond within a reasonable time.
If you are not satisfied with our response, you may contact the Australian Information Commissioner through the OAIC privacy complaints process.
11. Changes to this policy
We may update this policy when our service, providers, or legal obligations change. We will publish the updated policy and change the effective date. If a change materially affects how we handle personal information, we will take reasonable steps to notify affected account holders through the service or by email before it takes effect where practicable.