Privacy Policy
Draft notice: this privacy policy is prepared for product testing. Replace the placeholders and review your Privacy Act obligations before launch.
Who this policy covers
This policy explains how Payoff collects, uses, stores, and shares personal information when you create an account, use focus sessions, or make payments.
Information Payoff may collect
- Account details such as email address, user ID, login provider, and account status.
- Goal and productivity data such as plan choice, commitment level, target hours, goals, tasks, session times, check-ins, and progress history.
- Payment references from Stripe, including customer IDs, checkout session IDs, payment method references, payment intent IDs, and charge status. Payoff does not store raw card numbers.
- Technical data such as browser, device, error logs, and approximate usage events needed to run and secure the service.
How Payoff uses information
Payoff uses information to authenticate users, run focus sessions, calculate unfinished commitment, show progress, manage payments, prevent fake sessions, provide support, improve reliability, and meet legal or tax obligations.
Payments
Card details are handled by Stripe. Payoff stores Stripe references so payments can be connected to the correct account and cycle.
Sharing information
Payoff may share necessary information with service providers such as Supabase for authentication/database hosting and Stripe for payments. Payoff should not sell personal information.
Overseas storage and processors
Supabase, Stripe, hosting providers, analytics tools, and email providers may process or store information outside Australia. Before launch, confirm each provider and list any required details here.
Security
Payoff uses Supabase authentication, row-level security, Stripe-hosted payment collection, and server-side payment functions. No online service can guarantee perfect security, so Payoff also needs monitoring, backups, and breach-response processes before launch.
Access, correction, and deletion
Users should be able to request access to, correction of, or deletion of their personal information. Deletion requests may not remove records Payoff must keep for payment, fraud prevention, legal, tax, or dispute reasons.
Data retention
Payoff should keep personal information only as long as needed for the service, legal obligations, dispute handling, accounting, security, and legitimate business purposes. Before launch, set a real retention schedule.
Children
Payoff is intended for users aged 18 or over. Do not create an account if you are under 18.
Contact and complaints
Before launch, replace this with your support email, legal business name, ABN if applicable, and a process for privacy questions or complaints.