PropellorSoft — Privacy Policy
- Effective date: 2026-09-21
- Version: 0.2 (draft)
- Last updated: 2026-09-21
- Privacy contact: hello@propellorsoft.com
This Privacy Policy explains how PropellorSoft ("we", "us", "our") collects, uses, discloses, and protects personal information when you use the PropellorSoft platform (the "Service") described in our Terms of Service, and how we handle information in connection with our Acceptable Use Policy. The public self-serve AI website builder at /start is not currently offered; the usual public intake is the contact form and prospect chat on propellorsoft.com, plus contact forms on sites we host.
We handle personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs"). This policy is written against that framework.
1. What we collect
1.1 Account information. Your email address, used for magic-link sign-in (no passwords are stored). Authentication is provided by Supabase, hosted in Sydney, Australia.
1.2 Site content. The content and structure of sites we host for you, including business details you provide in a brief, material you upload, edits you or we make, and instructions you give a site assistant if that feature is enabled. Some of this may be personal information (for example your name, business contact details, or details about other people you choose to publish).
1.3 Usage events. Server-side records of your use of metered features — the kind of event (for example, an AI site generation or an AI chat message), the quantity, and timestamps. We use these records to calculate plan quotas and overage billing, which is reported to Stripe, if and when those features are offered.
1.4 Billing information. Subscription status, plan, invoices, payment events, and (where we invoice hourly extra work through Stripe) those charges are processed by Stripe. Your card or bank details never touch PropellorSoft servers — they are collected and held by Stripe under its own terms and privacy policy.
1.5 Support, briefs, and request content. Messages you send us, including support enquiries, custom-work requests, and the original brief you give us for a site (which may contain business and technical details).
1.6 Abuse reports. If you report a site under the Acceptable Use Policy, we collect the report content and, if you provide it, your contact details.
1.7 Technical logs. Standard server and application logs (such as IP address, timestamps, and request metadata) used to operate, secure, and rate-limit the Service — for example, enquiry throttling and, if self-serve generation is offered, the free-generation rate limit of 5 per IP address per hour.
1.8 Marketing contact form. If you use the contact form on propellorsoft.com (or a hosted contact form on a site we operate), we collect your name, email address, and message. We store the message against the relevant site and email it to our enquiry inbox. We may send you a short confirmation email.
1.9 Prospect chat. If you use the chat on the marketing site, we collect the messages you send, plus your name, email address, and optional phone number if you provide them. We use an AI assistant to reply. When we have a name, a valid email, and a clear need, we email a brief and the conversation to our team so we can follow up. This chat gathers a brief only; it does not build or publish a site.
1.10 Site enquiries. Contact forms on customer sites we host may collect a visitor's name, email, and message. We store those enquiries for the site operator (and may store the source IP address to enforce a short rate limit). Marketing-site and prospect-chat briefs are treated as enquiries for the same purpose: so we can reply and scope work.
1.11 Bot checks. The marketing contact form, prospect chat, and (where enabled) customer-site contact forms use Cloudflare Turnstile. A verification token is sent to Cloudflare to help us tell that a submission is from a person rather than an automated script.
2. How we collect it
2.1 Directly from you when you sign up, send a contact form, use the prospect chat, give us a brief, build or edit a site, use a site assistant or other AI features, attach a domain, contact support, or request custom work.
2.2 Automatically from your use of the Service (usage events, technical logs, and bot-check results), and from Stripe (billing and payment status events).
2.3 From third parties only in limited cases — for example, registrar and registry systems when we register or manage a domain on your behalf.
3. Why we use it (purposes)
3.1 We use personal information to:
- (a) create and authenticate your account (magic-link sign-in);
- (b) generate, host, publish, and serve your websites;
- (c) provide hosting, custom-domain features, and (on paid plans that include it) the site assistant;
- (d) measure usage against plan quotas and calculate metered overage or hourly extra work for billing;
- (e) process subscriptions and payments via Stripe, including failed-payment retries and reminders;
- (f) register, renew, and manage domains on your behalf;
- (g) moderate published sites (automated AI checks and human review) and enforce the Acceptable Use Policy, including handling reports;
- (h) respond to support, marketing, and site-form enquiries, and scope or quote extra work and custom work;
- (i) maintain the security and integrity of the Service (rate limiting, bot checks, abuse prevention); and
- (j) comply with legal obligations, including tax records and the Notifiable Data Breaches scheme (clause 8).
3.2 We do not sell personal information. We do not rent, trade, or sell personal information to third parties, and we do not use your content to advertise to third parties.
4. AI processing and overseas disclosure
4.1 Where we use AI to reply to the prospect chat, to operate a site assistant, or (if offered) to generate or edit sites, your inputs — such as a brief, chat messages, business details, and instructions — are sent to AI models via Vercel AI Gateway. This processing may occur in the United States. We use zero-data-retention providers where available, meaning the AI provider does not retain your inputs after processing where that arrangement is in place.
4.2 By using AI features, you acknowledge that your inputs will be disclosed overseas as described in this clause. We take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs, but overseas recipients may not be subject to the Privacy Act; by using the Service you acknowledge APP 8.1 may not apply to those disclosures. [Flagged for lawyer — confirm APP 8 / cross-border disclosure wording and consent framing.]
4.3 Do not include sensitive personal information (for example health information) or other people's personal information in AI prompts or site content unless you have the authority and a lawful basis to do so. You are responsible for personal information you choose to publish on your site (see clause 9).
5. Other disclosures
5.1 We disclose personal information to service providers who help us operate the Service, limited to what they need:
- Supabase — authentication and database hosting (Sydney, Australia);
- Stripe — subscription billing, metered overage, hourly extra-work invoices where processed through Stripe, and payment processing (card details are held by Stripe, not us);
- Vercel AI Gateway and underlying AI model providers — prospect chat, site assistant, and any AI generation or edit features (see clause 4);
- Cloudflare — Turnstile bot checks on the marketing contact form, prospect chat, and (where enabled) customer-site contact forms;
- Resend — sending enquiry notifications and contact confirmation emails;
- Wholesale domain registrar and registries — to register, renew, and transfer domains on your behalf; domain registration data may be published in WHOIS-type directories as required by registry policy;
- Hosting and infrastructure providers — to store and serve sites and logs.
5.2 We may also disclose personal information: where required or authorised by law (including to courts, regulators, or law enforcement); to authorities in connection with serious criminal content under the Acceptable Use Policy; and to a prospective buyer in connection with a merger, acquisition, or sale of assets, subject to confidentiality.
6. Security and retention
6.1 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure — including passwordless authentication, server-side access controls, and hosting account data in Australia (Sydney) with Supabase.
6.2 Retention while active. Account data, site content, and usage records are kept while your account is active. Usage events are retained as needed for billing accuracy, dispute resolution, and tax/audit obligations.
6.3 Retention after lapse or cancellation. If your paid plan lapses past the grace period, or you cancel, your site is unpublished but not deleted; we retain account and site data so the site can be restored if you resubscribe, and as required for billing and legal purposes. You may request deletion under clause 7.
6.4 When personal information is no longer needed, we take reasonable steps to destroy or de-identify it, subject to legal retention obligations.
7. Access, correction, and deletion
7.1 You may request access to, or correction of, the personal information we hold about you (APPs 12 and 13) by emailing hello@propellorsoft.com. We will respond within a reasonable time and generally within 30 days.
7.2 You may request deletion of your account and personal information by emailing hello@propellorsoft.com. Deletion removes your sites and account data; we may retain records we are required or permitted by law to keep (for example billing and tax records) and de-identified data.
7.3 AI-generated content. Deleting your account deletes our copy of your site content. Note that under the Terms, AI-generated site content is licensed to you only for the life of your subscription — see clause 6 of the Terms of Service for what you may and may not retain after cancellation.
8. Data breaches
8.1 We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of an eligible data breach — one likely to result in serious harm — we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required, and will otherwise assess and respond to suspected breaches under our incident process.
9. Your responsibilities for personal information you publish
9.1 Sites you publish are public. If you include personal information about other people (staff, customers, testimonials, images) on your site, you are responsible for having the right to publish it and for your own compliance with privacy law. We act as your hosting provider for that content and are not responsible for it under clause 7 of the Terms.
10. Cookies and analytics
10.1 The portal uses cookies or equivalent storage needed to keep you signed in and operate the Service. Cloudflare Turnstile may set cookies or similar storage as part of the bot check on contact forms and prospect chat. We do not currently use third-party advertising trackers. [Flagged for lawyer/product — confirm final analytics stack before go-live and update this clause to match; if product analytics are added, disclose them here.]
11. Complaints
11.1 If you believe we have breached the Privacy Act or the APPs, contact us at hello@propellorsoft.com with details. We will investigate and respond within a reasonable time.
11.2 If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au, 1300 363 992.
12. Changes to this policy
12.1 We may update this Privacy Policy from time to time under clause 11.3 of the Terms. Material changes will be notified by email or in-product notice at least 30 days before taking effect, and the "Last updated" date above will be revised.
13. Contact
13.1 Privacy enquiries, access/correction/deletion requests, and complaints: hello@propellorsoft.com.