1. About this policy
This policy describes how the operator of Locksmithy Business (Locksmithy, we, us) manages personal information when providing the Locksmithy Business software service, operating the public website, processing subscriptions, delivering platform communications and providing support. A subscribing business remains responsible for its own handling of customer and staff information entered into its workspace.
2. Information we may collect and hold
Depending on how you use the service, this can include account and identity details; business contact and subscription details; staff profile and access information; support communications; audit and security records; device/browser/IP information; billing provider identifiers and limited card metadata such as brand and last four digits; and operational information entered by a subscribing business about its customers, jobs, vehicles, products, suppliers, invoices and communications.
Locksmithy does not intentionally store raw payment card numbers or CVV for platform subscriptions; Square handles payment card tokenisation and card-on-file processing.
3. Why we use information
- to create, authenticate and administer accounts and business workspaces;
- to provide jobs, scheduling, stock, purchasing, billing, reporting and integration features;
- to process and administer Locksmithy subscriptions;
- to send service, security, trial, payment and support notifications;
- to prevent abuse, investigate incidents and maintain audit trails;
- to provide support and exercise explicit, audited support access when authorised; and
- to comply with legal obligations and protect the platform, users and third parties.
4. Service providers and overseas disclosures
Locksmithy uses third-party infrastructure and integration providers, which can include Supabase for database/authentication infrastructure, Square for platform subscription payments, email/SMS providers, and integrations selected by a subscribing business such as Xero or ServiceM8. Those providers may process information in Australia or overseas according to their infrastructure and contractual arrangements. We take reasonable steps to use providers appropriate for the service and restrict access to what is needed for the relevant function.
5. Security
We use measures including authenticated access, tenant-scoped permissions, role controls, audit logging, Site Owner MFA, time-limited support access, server-side SMS limits, secret storage outside public website files, and provider webhook validation. No online system can promise absolute security.
6. Retention, archive and deletion
We retain information while required to provide the service, administer subscriptions, resolve disputes, meet legal/accounting requirements or protect legitimate interests. Archive, export and scheduled-deletion controls are designed to support review before permanent deletion. Where information is no longer required and there is no legal reason to retain it, it should be destroyed or de-identified as appropriate.
7. Access and correction
Account Owners and authorised business staff can access and correct much of their business information inside Locksmithy. For platform-level personal information or requests that cannot be completed in the application, contact us through the Contact page.
8. Privacy questions and complaints
Send privacy questions or complaints using the Contact page and select Privacy, or use the privacy contact shown above. We will assess the request and respond within a reasonable period. If a privacy complaint cannot be resolved directly and Australian privacy law applies, you may also have a right to contact the Office of the Australian Information Commissioner.
9. Changes to this policy
We may update this policy when the service, providers or legal requirements change. The current version is published on this page.
