Skip to main content
Tradie Texts
Terms of ServicePrivacy PolicySMS Consent & Opt-OutAI DisclosureRefund & CancellationData Retention & DeletionBlogAbout
TT
Tradie Texts

Missed-call recovery for Aussie tradies — every ring gets an answer, even when your hands are full.

LegalTerms of ServicePrivacy PolicySMS Consent & Opt-OutAI DisclosureRefund & CancellationData Retention & Deletion
SupportHelp & FAQBlogAbout
Contacthello@tradietexts.com.au
© 2026 Tradie Texts·ABN 64 896 703 064

Legal & policies

Privacy Policy

Effective date: 9 June 2026

This Privacy Policy explains how Tradie Texts (ABN 64 896 703 064) ("we", "us", "our") handles personal information in connection with the Tradie Texts service ("Service").

We are based in New South Wales, Australia. We handle personal information in accordance with the *Privacy Act 1988* (Cth) and the Australian Privacy Principles (APPs) where they apply. Even if a small-business exemption applies at a particular time, this policy states the privacy standard we intend to follow for the Service.

1. Who this policy covers

This policy covers:

  • Account holders and trade businesses that use the Service ("Customers");
  • People who call or SMS a Customer and whose enquiry is handled through the Service ("Callers");

and

  • Website visitors and people who contact us for support.

For Customer account information, we decide how that information is handled. For Caller information, the Customer is the business dealing directly with the Caller and decides how the lead is used. As between us and the Customer, we process Caller information to provide the Service on the Customer's behalf and instructions. We may still have direct obligations under privacy law for information we hold.

2. Information we collect

From Customers, we may collect:

  • Name, business name, email address, phone numbers, trade type, timezone and business settings;
  • Forwarding numbers, notification numbers, Twilio number configuration and AI greeting/persona

settings;

  • Authentication information managed through Supabase Auth;
  • Billing information handled through Stripe, including customer IDs, subscription details,

invoice status and plan usage; and

  • Support requests, feedback and technical information.

From Callers, through the Customer's configured phone and SMS workflow, we may collect:

  • Phone number, missed-call status, time of call and related Twilio metadata;
  • SMS message bodies and conversation history;
  • Information the Caller volunteers, such as name, address, job description, urgency, preferred

call-back time and safety or emergency details; and

  • AI-generated or AI-extracted lead information, such as summaries, urgency indicators and

qualification scores.

Automatically, we may collect operational logs, webhook payloads, request metadata, security events, usage events and error information. Application logs are designed to redact phone numbers and message bodies, but webhook and database records may contain personal information.

We do not intentionally seek sensitive information. If a Caller volunteers health, safety or other sensitive information, we process it only as necessary to provide the Service, help the Customer respond, or comply with law.

3. How we collect information

We collect Customer information when a Customer signs up, completes onboarding, configures the Service, uses the dashboard, pays for a subscription, or contacts support.

We collect Caller information when a Caller calls or messages a Customer number connected to the Service, when Twilio sends us webhook events, when the Customer views or updates leads, and when AI tools process message content for reply generation or lead extraction.

Because Callers may not have a direct account with Tradie Texts, Customers must ensure they give any privacy notices required for their own business. The first automated SMS should also disclose that the Caller is texting an AI assistant. Where practicable, the Customer should make a privacy notice available on their website, quote form, voicemail flow, or other customer-facing channel.

4. Why we use information

We use personal information to:

  • Provide missed-call detection, SMS recovery, AI-assisted replies, lead qualification, dashboard

display and emergency escalation;

  • Configure phone routing, business settings and customer notifications;
  • Provide support, troubleshoot issues, enforce usage limits and prevent misuse;
  • Bill Customers, administer trials and subscriptions, and report metered usage;
  • Maintain security, verify webhook signatures, preserve idempotency and investigate incidents;
  • Improve reliability and product performance; and
  • Comply with legal, tax, accounting and regulatory obligations.

We do not sell personal information. We do not use Caller information for our own marketing.

5. AI processing

The Service uses AI to draft SMS replies and extract lead information. Message content and related conversation context may be sent to OpenAI or another AI provider we appoint for these purposes.

We take a data-minimisation approach and do not intentionally send unnecessary sensitive information to AI systems. AI-generated information can be inaccurate or incomplete, so Customers must verify information before relying on it.

If AI processing uses personal information for automated decision-making that has the potential to affect an individual's rights or interests, we will update this policy to include the additional information required by any applicable automated decision-making transparency obligation.

6. Disclosure to service providers

We use service providers to operate the Service:

ProviderPurposeLikely location
SupabaseDatabase, authentication and storageAustralia (Sydney region) and/or provider infrastructure locations
TwilioVoice, SMS, webhook delivery and message recordsUnited States and global carrier networks
OpenAIAI reply generation, moderation and lead extractionUnited States
StripePayments, subscriptions, invoices and billing recordsUnited States and other Stripe processing locations
VercelApplication hosting, serverless functions and deployment logsUnited States and global edge locations
UpstashRate limiting and idempotency cacheUnited States and/or selected provider region
Resend or email provider, if enabledService and billing emailsUnited States and/or provider locations

We may also disclose information to professional advisers, regulators, law enforcement, courts, acquirers in a business sale or restructure, or others where required or authorised by law.

7. Overseas disclosure (APP 8)

Some providers are located overseas, especially in the United States. Before disclosing personal information overseas, we take reasonable steps appropriate to the circumstances, such as reviewing provider security and privacy terms, using reputable providers, limiting the data disclosed, maintaining contractual protections where available, and documenting the disclosure in this policy.

Customers authorise these overseas disclosures for the purpose of operating the Service. Customers must ensure their own privacy notices and consents are sufficient for their Caller relationships and industry context.

8. Security

We use reasonable technical and organisational safeguards, including access controls, encryption in transit, Supabase row-level security, signed webhook verification, secret management, least privilege credentials, rate limiting, idempotency controls and redacted application logging.

No method of transmission or storage is completely secure. If we become aware of an eligible data breach under the Notifiable Data Breaches scheme, we will assess it and notify affected individuals and the OAIC where required.

9. Retention

We keep personal information only for as long as needed for the purposes described in this policy, unless we are required or permitted by law to keep it longer.

Our current retention settings and operational process are described in the Data Retention and Deletion Policy. In summary, Caller leads and SMS message bodies are intended to be retained for up to 24 months after last activity, webhook payloads should be minimised or deleted sooner where operationally practicable, and billing/tax records may be retained for 7 years.

10. Access, correction and deletion

Customers can access and update most account and business information in the dashboard. Customers can also contact hello@tradietexts.com.au to request access, correction or deletion.

Callers should first contact the trade business they called, because that business controls the customer relationship and decides how the lead is used. We will reasonably assist the relevant Customer to locate, correct, export, delete or de-identify Caller records. A Caller may also contact us directly at hello@tradietexts.com.au, and we will route the request where appropriate.

We may need to verify identity before acting. We may refuse or limit a request where permitted by law, for example where we must retain billing, security, legal or dispute records.

11. Complaints

If you have a privacy complaint, contact hello@tradietexts.com.au with details. We will investigate and respond within a reasonable time. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

12. Anonymity and pseudonymity

Callers can choose how much information to include in an SMS, but the Service cannot operate without processing the caller's phone number and message content. Customers cannot use the Service anonymously because account, billing and business configuration details are needed.

13. Changes

We may update this policy from time to time. Material changes will be notified to Customers by email, in-app notice, or another reasonable method. The effective date shows when this version started.

14. Contact

Tradie Texts Privacy enquiries: hello@tradietexts.com.au Support: hello@tradietexts.com.au

Back to top ↑