PropellorSoft — Privacy Policy
- Effective date: [TBD — to be set on go-live]
- Version: 0.1 (draft)
- Last updated: 2026-08-06
- Privacy contact: hello@propellorsoft.com
This Privacy Policy explains how PropellorSoft ("we", "us", "our") collects, uses, discloses, and protects personal information when you use the PropellorSoft platform (the "Service") described in our Terms of Service, and how we handle information in connection with our Acceptable Use Policy.
We handle personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs"). This policy is written against that framework.
1. What we collect
1.1 Account information. Your email address, used for magic-link sign-in (no passwords are stored). Authentication is provided by Supabase, hosted in Sydney, Australia.
1.2 Site content. The content and block structure of the sites you build, including business details you provide in onboarding answers, edits you make in the editor, images and other material you upload, and instructions you give the AI. Some of this may be personal information (for example your name, business contact details, or details about other people you choose to publish).
1.3 Usage events. Server-side records of your use of metered features — the kind of event (for example, an AI site generation or an AI chat message), the quantity, and timestamps. We use these records to calculate plan quotas and overage billing, which is reported to Stripe.
1.4 Billing information. Subscription status, plan, invoices, and payment events are processed by Stripe. Your card or bank details never touch PropellorSoft servers — they are collected and held by Stripe under its own terms and privacy policy.
1.5 Support and request content. Messages you send us, including support enquiries and "request custom work" concierge requests (which may contain business and technical details of the engagement you want).
1.6 Abuse reports. If you report a site under the Acceptable Use Policy, we collect the report content and, if you provide it, your contact details.
1.7 Technical logs. Standard server and application logs (such as IP address, timestamps, and request metadata) used to operate, secure, and rate-limit the Service — for example, enforcing the free-generation rate limit of 5 per IP address per hour.
2. How we collect it
2.1 Directly from you when you sign up, answer onboarding questions, build or edit a site, use AI features, attach a domain, contact support, or request custom work.
2.2 Automatically from your use of the Service (usage events and technical logs), and from Stripe (billing and payment status events).
2.3 From third parties only in limited cases — for example, registrar and registry systems when we register or manage a domain on your behalf.
3. Why we use it (purposes)
3.1 We use personal information to:
- (a) create and authenticate your account (magic-link sign-in);
- (b) generate, host, publish, and serve your websites;
- (c) provide the editor, AI chat assistant, and custom-domain features;
- (d) measure usage against plan quotas and calculate metered overage for billing;
- (e) process subscriptions and payments via Stripe, including failed-payment retries and reminders;
- (f) register, renew, and manage domains on your behalf;
- (g) moderate published sites (automated AI checks and human review) and enforce the Acceptable Use Policy, including handling reports;
- (h) respond to support enquiries and scope/quote custom work requests;
- (i) maintain the security and integrity of the Service (rate limiting, abuse prevention); and
- (j) comply with legal obligations, including tax records and the Notifiable Data Breaches scheme (clause 8).
3.2 We do not sell personal information. We do not rent, trade, or sell personal information to third parties, and we do not use your content to advertise to third parties.
4. AI processing and overseas disclosure
4.1 To generate and edit sites, your inputs — business details, onboarding answers, and instructions to the AI — are sent to AI models via Vercel AI Gateway. This processing may occur in the United States. We use zero-data-retention providers where available, meaning the AI provider does not retain your inputs after processing where that arrangement is in place.
4.2 By using AI features, you acknowledge that your inputs will be disclosed overseas as described in this clause. We take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs, but overseas recipients may not be subject to the Privacy Act; by using the Service you acknowledge APP 8.1 may not apply to those disclosures. [Flagged for lawyer — confirm APP 8 / cross-border disclosure wording and consent framing.]
4.3 Do not include sensitive personal information (for example health information) or other people's personal information in AI prompts or site content unless you have the authority and a lawful basis to do so. You are responsible for personal information you choose to publish on your site (see clause 9).
5. Other disclosures
5.1 We disclose personal information to service providers who help us operate the Service, limited to what they need:
- Supabase — authentication and database hosting (Sydney, Australia);
- Stripe — subscription billing, metered overage, and payment processing (card details are held by Stripe, not us);
- Vercel AI Gateway and underlying AI model providers — AI generation and chat (see clause 4);
- Wholesale domain registrar and registries — to register, renew, and transfer domains on your behalf; domain registration data may be published in WHOIS-type directories as required by registry policy;
- Hosting and infrastructure providers — to store and serve sites and logs.
5.2 We may also disclose personal information: where required or authorised by law (including to courts, regulators, or law enforcement); to authorities in connection with serious criminal content under the Acceptable Use Policy; and to a prospective buyer in connection with a merger, acquisition, or sale of assets, subject to confidentiality.
6. Security and retention
6.1 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure — including passwordless authentication, server-side access controls, and hosting account data in Australia (Sydney) with Supabase.
6.2 Retention while active. Account data, site content, and usage records are kept while your account is active. Usage events are retained as needed for billing accuracy, dispute resolution, and tax/audit obligations.
6.3 Retention after lapse or cancellation. If your paid plan lapses past the grace period, or you cancel, your site is unpublished but not deleted; we retain account and site data so the site can be restored if you resubscribe, and as required for billing and legal purposes. You may request deletion under clause 7.
6.4 When personal information is no longer needed, we take reasonable steps to destroy or de-identify it, subject to legal retention obligations.
7. Access, correction, and deletion
7.1 You may request access to, or correction of, the personal information we hold about you (APPs 12 and 13) by emailing hello@propellorsoft.com. We will respond within a reasonable time and generally within 30 days.
7.2 You may request deletion of your account and personal information by emailing hello@propellorsoft.com. Deletion removes your sites and account data; we may retain records we are required or permitted by law to keep (for example billing and tax records) and de-identified data.
7.3 AI-generated content. Deleting your account deletes our copy of your site content. Note that under the Terms, AI-generated site content is licensed to you only for the life of your subscription — see clause 6 of the Terms of Service for what you may and may not retain after cancellation.
8. Data breaches
8.1 We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of an eligible data breach — one likely to result in serious harm — we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required, and will otherwise assess and respond to suspected breaches under our incident process.
9. Your responsibilities for personal information you publish
9.1 Sites you publish are public. If you include personal information about other people (staff, customers, testimonials, images) on your site, you are responsible for having the right to publish it and for your own compliance with privacy law. We act as your hosting provider for that content and are not responsible for it under clause 7 of the Terms.
10. Cookies and analytics
10.1 The portal uses cookies or equivalent storage needed to keep you signed in and operate the Service. We do not currently use third-party advertising trackers. [Flagged for lawyer/product — confirm final analytics stack before go-live and update this clause to match; if product analytics are added, disclose them here.]
11. Complaints
11.1 If you believe we have breached the Privacy Act or the APPs, contact us at hello@propellorsoft.com with details. We will investigate and respond within a reasonable time.
11.2 If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au, 1300 363 992.
12. Changes to this policy
12.1 We may update this Privacy Policy from time to time under clause 11.3 of the Terms. Material changes will be notified by email or in-product notice at least 30 days before taking effect, and the "Last updated" date above will be revised.
13. Contact
13.1 Privacy enquiries, access/correction/deletion requests, and complaints: hello@propellorsoft.com.