LocalCraft (ABN 35 637 498 840) ("we", "us", "our") respects your privacy. This policy explains how we handle personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Effective date: 20 August 2026. Contact: info@localcrft.com.au.
We follow the APPs as our standard even where a small-business exemption might currently apply, because it is the right baseline and our clients expect it.
We do not intentionally collect sensitive information and ask that you do not submit it through enquiry forms.
Directly from you (forms, email, account sign-up); automatically, where you are signed in to the portal (essential session cookies and server logs, clause 13); and, for End Customer Data, through our customers' websites that we operate.
To provide and operate the Services; to capture and route enquiries to the relevant business; to send service and notification messages; to provide support and billing; to secure the Platform and prevent abuse; to improve the Services; and to meet legal obligations. Any marketing or promotional messages sent on a customer's behalf are governed by our Messaging Consent & Unsubscribe practices and the customer's consent.
We use trusted service providers to run the Platform. They handle data on our behalf under their own security and privacy commitments. We describe them here by role, with the countries where data is processed, and we will identify the specific provider to you on legitimate request (for example, where your contract or the law requires it):
| Who | Purpose | Where data is processed |
|---|---|---|
| Our hosting provider | Website hosting, serverless functions, CDN | United States (with global edge/CDN locations) |
| Our database & authentication provider (cloud tier) | Database and sign-in | Sydney, Australia |
| Our email delivery provider | Sending notification / enquiry emails | United States |
| Our SMS / telephony provider (when SMS/call features are enabled for a customer) | SMS sending/receiving and call-event records (missed-call text-back, STOP handling) | United States (with global network infrastructure) |
| The advertising platform's reporting API (when a customer connects their own advertising account) | Read-only retrieval of the customer's own advertising spend for reporting; access tokens are stored encrypted (AES-256-GCM) | United States (with global infrastructure) |
| Your browser's push notification service (when an owner enables notifications) | Delivering portal push notifications; payload limited to at most a first name | United States (with global infrastructure) |
| A payment processor (when online payments are added, not yet active) | Payment processing | United States (with global infrastructure) |
| An AI provider (when AI features are enabled, not yet active; this table names the provider when the feature goes live) | AI-assisted drafting; configured for no-training / zero-retention where personal information is involved | United States |
| Our object-storage backup provider | Holds encrypted nightly backups of Platform data | Oceania region of a global provider; may include locations outside Australia |
| Our CI/build provider | Runs scheduled builds and the nightly backup job | United States |
Where we manage advertising on a customer's behalf, campaign measurement uses hashed identifiers only, uploaded through the advertising platform's own conversion API, never their End Customers' raw personal details.
We do not sell personal information. We disclose it only to these providers, to the customer whose End Customer it is, or where required by law.
Privacy switch. If your Order uses the private or local deployment option, your data is hosted in your own environment and some providers above may not apply. Your Order records the option you use.
Some providers process data outside Australia (for example, the United States). Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the APPs, including choosing reputable providers and, where available, hosting the database in an Australian region. By using the Services you acknowledge that information may be processed overseas as described above.
Where AI features are enabled, content you submit may be processed by an AI provider to generate drafts or suggestions. Where personal information is involved, we use business arrangements that do not train on your data and minimise retention. AI output is a draft for human review and is not professional advice. (AI drafting currently runs in an internal test mode only; no information is sent to any AI provider. This clause takes effect when AI features go live, which additionally requires a passed quality evaluation and the feature being switched on for the customer.)
We use measures appropriate to the risk, including encryption in transit (HTTPS), access controls, tenant isolation (each business's data is separated, including database row-level security in the cloud tier), encryption at rest for stored third-party credentials (AES-256-GCM), append-only audit records for consent, opt-outs and messaging, and optional whole-database encryption for self-hosted deployments. No system is perfectly secure, but we work to protect information and to detect and respond to incidents.
If an eligible data breach occurs, we respond in line with the Notifiable Data Breaches scheme, including notifying the OAIC and affected individuals where required, and we support our customers in meeting their own obligations.
We keep personal information only as long as needed for the purposes above or as required by law. End Customer Data is kept while we provide the Service to the relevant customer; after a customer leaves, data is available for export for 30 days and is then deleted or de-identified unless we must keep it.
Our object-storage backup provider holds encrypted nightly backups on a rolling 7-daily plus 4-weekly cycle (approximately 35 days), pruned automatically. Backups age out on this cycle regardless of when the live data is deleted, so a deletion is reflected in backups within roughly that window, without a separate backup-deletion step.
Any marketing or promotional messages include a way to opt out, and we honour opt-outs promptly (see §2's consent and opt-out records above). You can also contact us to opt out at any time.
You can ask us to access or correct your personal information by contacting info@localcrft.com.au. We will respond within a reasonable time and may need to verify your identity. If we hold End Customer Data on a customer's behalf, we may direct the request to that customer.
Our public website (localcrft.com.au) sets no cookies and runs no analytics or advertising trackers. The pages themselves are static. Its one form, the health-check enquiry, submits by a server-side POST, which our hosting provider receives and stores, together with technical data such as your IP address, for delivery and spam prevention.
Where you sign in to a client portal we operate, we set essential cookies only, to keep you signed in and to protect the session against misuse. We do not use analytics, advertising, or cross-site tracking cookies anywhere in the Platform.
You can control cookies through your browser. The portal will not work without its essential cookies.
If we ever introduce analytics, this policy is updated in the same change that introduces it, never in advance of it.
If you have a privacy concern, contact us first at info@localcrft.com.au and we will try to resolve it. If you are not satisfied, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
We may update this policy. The current version is published at https://localcrft.com.au/legal/services-privacy/ with the effective date shown, and we will tell customers about material changes before they take effect.
Published at https://localcrft.com.au/legal/services-privacy/ · Effective 20 August 2026.