Privacy Policy
Effective 27 July 2026
XGrafter (“XGrafter”, “we”) is committed to protecting the privacy of individuals whose personal information we handle. This Policy explains how we collect, use, disclose, and store personal information, in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
1. What information we collect
- Account information — name, email, phone, company name, ABN.
- Customer Data — jobs, quotes, invoices, contacts, employees, and other records you upload to run your business through XGrafter.
- Usage data — anonymised logs of feature use, browser, device, and IP address to operate and improve the Service.
- Communications — records of support requests and correspondence.
2. How we use it
We use personal information to:
- Provide, maintain, and improve the Service.
- Bill and communicate with you.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not sell your personal information or use Customer Data to train machine-learning models that leave your account.
3. Where your data lives
Customer Data is stored in Australia. We use the following sub-processors:
- Supabase / AWS Sydney (ap-southeast-2) — primary database, file storage, authentication. All Customer Data resides in Sydney.
- Resend — transactional email (welcome emails, invoice notifications). Email content in transit is stored briefly by Resend for delivery diagnostics.
- Vercel — application hosting. Requests routed via edge locations globally but no Customer Data is stored at the edge.
4. Disclosure
We disclose personal information only to our sub-processors as listed above, and where required by law. We do not share Customer Data with third parties for marketing purposes.
5. Security
We employ industry-standard safeguards including TLS encryption in transit, encrypted storage at rest, principle-of-least-privilege access controls, and regular security review of our infrastructure. No system is perfectly secure — we recommend enabling multi-factor authentication on your account.
6. Retention
We retain Customer Data for the duration of your subscription and for 30 days after termination to allow for reactivation and data export. After 30 days, Customer Data is permanently deleted from active systems. Backups are retained for up to 90 days.
7. Your rights
You may request to:
- Access the personal information we hold about you.
- Correct any information that is inaccurate.
- Delete personal information (subject to legal retention obligations).
- Export your Customer Data in a machine-readable format.
Send requests to ops@xgrafter.com. We will respond within 30 days.
8. Cookies and tracking
We use strictly necessary cookies to keep you signed in and remember preferences. We do not use third-party marketing or advertising cookies.
9. Mobile app (XGrafter Field for iOS)
The XGrafter Field iOS app is a companion to the web platform for on-site crew. It signs in with the same credentials as the web dashboard and does not collect any additional personal information beyond what's covered above.
Device permissions the app may ask for:
- Camera — used only when you tap "Add photo" on a site task or job note. Photos are uploaded directly to your tenant's storage in AWS Sydney and are never transmitted to any third party.
- Photo library — used only when you tap "Attach from library". Only the photos you explicitly select are read; the app has no background access to your library.
- Face ID / Touch ID — optional. If you opt in, iOS grants the app a local device gate that unlocks the app faster than typing your password. The biometric check happens entirely on-device — no facial data, fingerprints, or biometric templates ever leave your phone or reach XGrafter. You can turn this off any time from the profile screen or by revoking permission in iOS Settings.
What the app does NOT do:
- No third-party analytics or tracking SDKs.
- No advertising identifiers collected.
- No cross-app or cross-website tracking.
- No location data collected.
- No push notifications sent in the current build.
If the app is uninstalled, any biometric opt-in preference and cached session data stored on-device are deleted by iOS as part of the standard uninstall process.
10. Children
The Service and the XGrafter Field app are business tools intended for use by employees of a subscribing business. We do not knowingly collect personal information from anyone under 16 years of age. If you believe we have inadvertently collected information from a minor, contact us at ops@xgrafter.com and we will delete it.
11. Complaints
If you believe we have breached the APPs, contact us at ops@xgrafter.com. If unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).
12. Changes to this Policy
We may update this Policy from time to time. The effective date at the top reflects the most recent revision. Material changes will be notified by email.