Privacy Policy
Effective date: 14 July 2026 Last updated: 15 July 2026
WPC Consulting Pty Ltd (ABN 66 644 159 053) ("we", "us", "our", or "Sitepack") operates the Sitepack platform at sitepack.com.au, app.sitepack.com.au, and related mobile and messaging interfaces.
We take privacy seriously. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
Read this together with our Terms and Conditions. Capitalised terms not defined here have the meaning given in the Terms.
1. Scope
1.1 This Policy applies to personal information we collect when you:
(a) create or use a Sitepack account;
(b) submit Take 5, SWMS, toolbox talk, incident, or near-miss records through the platform;
(c) receive or send messages via SMS, WhatsApp, or email as part of the service;
(d) contact us for support or sales enquiries; or
(e) visit our public websites.
1.2 It does not apply to third-party sites, services, or products that Sitepack links to or integrates with. Those are governed by their own privacy policies.
2. What information we collect
We collect only what we need to run the service. Broadly, this falls into six categories.
2.1 Account information
Name, email address, phone number, business name (where applicable), ABN, and password (stored as a salted hash — never in plain text).
2.2 Payment information
Payment card details are handled directly by Stripe and are not stored on our systems. We receive from Stripe a customer identifier, the last four digits of the card, the card brand, and the transaction history for your subscription.
2.3 Site and safety records
Information you and your crew submit through the platform, including:
(a) SWMS content, hazard descriptions, and control measures;
(b) Take 5 records (including voice recordings and their transcripts, where you use the voice capture feature);
(c) toolbox talk records and attendance;
(d) incident and near-miss reports, including photos, notes, and location details you attach;
(e) worker names, contact details, and sign-on records; and
(f) site names, addresses, and job identifiers.
2.4 Communications data
The content and metadata of messages sent through Sitepack (for example, WhatsApp confirmations, SMS toolbox talk broadcasts, and email notifications), including delivery status and phone numbers of recipients you provide.
2.5 Technical data
IP address, device and browser identifiers, operating system, timestamps, and log data generated when you use the platform. This is used to run and secure the service.
2.6 Support and enquiry data
If you contact us for support, sales, or feedback, we collect what you send us (name, email, message content, and any attachments).
We do not knowingly collect information from children under 18. You must be at least 18 to create an account.
3. Sensitive information
3.1 Some incident and near-miss records may include information about a person's health (for example, a description of an injury). This is "sensitive information" under the Privacy Act.
3.2 We collect this information only where it is reasonably necessary to help you meet your safety and record-keeping obligations, and only where the individual concerned has consented — or where collection is otherwise permitted or required by law.
3.3 You are responsible, as the person conducting a business or undertaking, for obtaining any consents required from workers before submitting their sensitive information through Sitepack.
4. How we collect personal information
4.1 We collect information directly from you when you create an account, use the platform, or contact us.
4.2 We may collect information about your workers, subcontractors, or crew members from you (or from other users on your account) when they are added to a site, sign on to a SWMS, complete a Take 5, or receive a toolbox talk.
4.3 We collect technical data automatically when you use the platform.
4.4 We may collect information from Stripe about your subscription and payment activity.
5. Why we collect it — and the lawful basis
We collect and use personal information for the following purposes:
(a) to create and administer your account;
(b) to provide the Sitepack service, including generating, storing, and delivering safety documentation;
(c) to process payments and manage your subscription;
(d) to send you service communications (payment receipts, security alerts, account notices, and safety document delivery confirmations);
(e) to provide customer support;
(f) to improve Sitepack, subject to the de-identification rules in clause 8.3 of the Terms;
(g) to detect, investigate, and prevent fraud, abuse, or breaches of the Terms;
(h) to comply with legal obligations (for example, tax, record-keeping, or lawful requests from regulators); and
(i) with your opt-in consent, to send you marketing or product-update communications (see section 8 below).
We do not use personal information for any other purpose without your consent, unless permitted or required by law.
6. Who we share information with
We share personal information only with the following categories of recipient, and only to the extent necessary.
6.1 Service providers
We use a small number of trusted providers to run Sitepack:
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase | Database, storage, and authentication | Australia (Sydney — ap-southeast-2) |
| Vercel | Web hosting and application delivery | Australia (Sydney — syd1) |
| Stripe | Payment processing | Australia and United States |
| Twilio | SMS and WhatsApp messaging | Australia and United States |
| OpenAI, Anthropic | AI-assisted drafting and voice transcription for SWMS, Take 5, and toolbox talks | United States |
Each provider is contractually obliged to use personal information only to provide their service to us, to protect it with appropriate security, and to comply with applicable data-protection law.
6.2 Overseas disclosure and APP 8
Sitepack's primary database and file storage are hosted in Sydney, Australia.
Some processing does cross borders:
(a) Payment processing and messaging (Stripe, Twilio) may involve routing through the United States. We have taken reasonable steps to ensure these providers handle personal information in a manner consistent with the APPs, including relying on their published privacy commitments and standard contractual protections.
(b) AI-assisted features (SWMS drafting, Take 5 voice transcription, hazard suggestions) send the relevant content to OpenAI (United States) or Anthropic (United States) for processing and return. These providers do not train their public models on Sitepack API traffic (this is a contractual commitment under their API terms). Content is processed transiently and is not retained for training. If you do not want your content processed by these providers, do not use the AI features — the platform's manual entry paths remain fully available.
By using the AI features, you consent to your input being sent to these providers for the sole purpose of returning the requested output.
6.3 Other sharing
We may share personal information:
(a) with your consent;
(b) to comply with a lawful request from a court, regulator, or law-enforcement agency;
(c) to protect our rights, property, or safety, or that of our users or the public; or
(d) in connection with a sale or restructure of our business, where the recipient agrees to be bound by this Policy (or a policy at least as protective).
We do not sell personal information. We do not disclose personal information to advertisers or data brokers.
7. Storage and security
7.1 Personal information is stored on servers hosted in Australia (Sydney), except where a specific processing purpose requires a specific provider (see section 6).
7.2 We use industry-standard security measures, including encryption in transit (TLS 1.2+), encryption at rest for the primary database and file storage, role-based access controls, audit logging, and least-privilege access for our own staff.
7.3 No system is completely secure. In the unlikely event of a data breach that is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches scheme and notify affected individuals and the Office of the Australian Information Commissioner as required by law.
8. Marketing communications
8.1 We send service communications (payment receipts, security alerts, safety document delivery confirmations, and account notices) by default. These are necessary to provide the service and are not marketing.
8.2 We do not send marketing or product-update emails, SMS, or WhatsApp messages unless you have opted in — for example, by ticking a box during sign-up or in your account settings.
8.3 Marketing communications are sent only to the account holder, not to workers, subcontractors, or crew members whose contact details you have added.
8.4 You can withdraw marketing consent at any time by clicking the unsubscribe link in any marketing email, replying STOP to a marketing SMS, or emailing us at the address in section 12.
8.5 Withdrawing marketing consent does not affect service communications.
9. How long we keep information
9.1 We keep personal information for as long as your account is active, plus the retention periods set out in the Terms:
(a) Customer Data (including SWMS, Take 5, toolbox talk, and incident records) is retained for 30 days after subscription termination to allow export or reinstatement, and then deleted from active systems;
(b) backups are overwritten in the ordinary course of our backup rotation, typically within a further 90 days;
(c) payment records and tax-related records are kept for the period required by Australian tax law (currently 5 years); and
(d) de-identified data derived from Customer Data may be retained as described in clause 8.3 of the Terms.
9.2 We may retain limited information for longer where required by law or to defend legal claims.
10. Your rights under the Australian Privacy Principles
Under the APPs, you have the right to:
(a) Access your personal information. Send us a request at the address in section 12 and we will respond within 30 days.
(b) Correct your personal information if you believe it is inaccurate, out of date, incomplete, irrelevant, or misleading. Most account details can be updated directly in the app; for anything else, contact us.
(c) Withdraw consent for anything we do that relies on consent (including marketing communications and, where applicable, use of de-identified data for hazard-library improvement — see clause 8.3 of the Terms).
(d) Request deletion of your personal information, subject to our lawful retention obligations (section 9).
(e) Complain about how we have handled your personal information. Send your complaint to the address in section 12. We will acknowledge it within 5 business days and respond substantively within 30 days.
(f) Escalate your complaint. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
You do not have to identify yourself when you make a general enquiry, but we may be unable to action a request that involves your personal information without verifying your identity.
11. Cookies and analytics
11.1 The Sitepack platform uses only the cookies necessary to keep you logged in, remember your preferences, and secure your session. We do not use third-party advertising, tracking, or profiling cookies.
11.2 We may, in future, add basic web analytics (such as aggregate page-view counts) to understand how the platform is used. If we do, we will update this Policy and, where required by law, seek your consent before enabling any tracking that identifies you.
12. Contact us
Privacy questions, requests, and complaints:
WPC Consulting Pty Ltd Attn: Privacy Officer wpcconsultingpty@gmail.com 6 Cumbalum Street, Hemmant QLD 4174, Australia
Please put "Sitepack — Privacy request" in the subject line so we can route your request quickly.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email or in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this Policy shows the most recent revision.