Privacy Policy
Last updated 3 September 2026
This is all of it. We collect the least we can, publish only what a directory listing needs, and count page views as daily totals with no cookie and no record of who visited. Where our practice is untidy, this policy says so instead of describing something tidier.
1.Who we are, and what this policy covers
Bizroots (bizroots.com.au) is a Western Australian business directory, operated from Perth by Xaio Tech Pty Ltd (ABN 27 697 386 084). That company is responsible for the personal information described here.
We handle personal information in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), and we treat this policy as binding on us. APP 1 asks an organisation to set out plainly what it does with personal information, and that is the whole job of this document: the sections below work through what we collect and why, what we publish, who else handles it, how we protect it, how long we keep it, and how you see and fix what we hold. It covers the website, the signup wizard, your member dashboard, the public listing pages and the email we send you.
It does not cover what a listed business does with an enquiry you send it. Once you contact a business through its listing, that business is responsible for your information, not us.
One rule sits above the rest: we do not sell personal information, we do not rent it, and we do not hand it to anyone for their own marketing. There is no version of this business funded by your data — every dollar comes from a subscription.
If you trade as a sole trader, your business details are also personal information about you. This policy is written on that basis.
2.What you give us when you join
Everything in this section you type in yourself. Almost all of it is here because publishing a listing and taking a payment need it; where an item is optional, it says so.
- Your name — kept with your account so we know who we are writing to. It is never published.
- Your email address — it creates your sign-in and receives your receipt, renewal reminders and any billing problem. Read this part twice: the address you give at signup is also written to your listing as its public contact email, and the mobile number you give is written as its public phone number. A listing needs a way to be contacted, and by default that is what you typed. You can change either address, or clear them, under Profile in your dashboard.
- Your mobile number — as above: it becomes the phone number on your public listing until you change it.
- Your password, if you set one. Our authentication provider stores a hash of it. We never store the password itself and cannot read it. If you use Continue with Google, there is no password at all.
- Your ABN and trading name. The trading name is always yours to set: the Register's own trading-name data has not been updated since 2012, so we do not use it.
- Your listing content — description, categories, suburb and postcode, street address, your service-area answer, and any profile fields you fill in: website, socials, opening hours, licence and insurance details, memberships, years in business, team size, languages spoken, callout fee, and a second contact email and phone.
- Photos and a logo. Uploaded files are served from public URLs. Treat anything you upload as public from the moment it finishes uploading, including before your listing goes live.
- A half-finished signup. If you stop partway we keep the session — your name, email, mobile, ABN, trading name and the time you reached each step — so a resume link can pick it up. That link is a long random string and anyone holding it can see those details, so treat it like a password. It keeps working until we delete the unfinished signup, 12 months after you last touched it, whether or not you ever paid — see section 10.
- Your state, if you are outside WA. When the Register says the ABN's main location is not in Western Australia, we offer to take your email so we can tell you when we open there. We store it with the signup, and nothing in the product reads it yet — the mailing list it is for does not exist.
3.What the Australian Business Register gives us
We send ABN Lookup exactly two things: the eleven digits you typed, and the identifier the Register issued to us. Not your name, not your email, not your IP address. An ABN that fails its checksum never leaves our server.
We store the Register's reply word for word, with the date and the source, and we keep it. It does two jobs: it is a 30-day cache, so we are not hammering a government service, and it is an honest record of what the Register actually said on the day. That includes ABNs typed into the site that never became a listing.
From that reply we publish your legal or entity name, your entity type, whether the ABN is active, and the date we last checked. For many sole traders the legal name is your own name. We also keep, without publishing, the GST registration flag and the state and postcode the Register holds for the ABN.
Be clear about what a lookup proves: that the ABN exists and is active on the Register. It does not prove the ABN is yours — anyone can type anyone's ABN. That is why the badge on a listing reads "ABN verified as at" a date, and nothing stronger. If a listing is not yours, use the report link on it.
4.What is published on your listing
A listing is a public page. Search engines read it, and so can anything else that can open a web page.
Published: your trading name; the legal name the Register holds; your ABN, its status and the date we checked it; your description; your categories; your suburb and postcode; your service area; the contact email and phone in your listing's contact fields; every profile field you fill in; and your photos and logo.
Your founding member number sits in the public data behind your listing as well. The page itself does not print it — you see it on your dashboard — but anyone reading the listing data directly can read it, so we count it as public rather than let you assume otherwise.
Your street address is published only if you switch that on, and it is off by default. The map point on your listing is the centre of your suburb, not your street.
Not published: your password, your billing details, your sign-in history, your contact name, your daily view counts (only you see those), the outside-WA email, and the GST flag and registered state and postcode we take from the Register.
Your listing also publishes its phone number and email in a machine-readable block so search engines understand the page. Our Terms ban bulk scraping, but that is a rule, not a wall — nothing technical stops a determined bot reading what is on a public page. If you would rather a number stayed private, do not put it on the listing.
5.What a visitor to the site gives us, or generates
You do not need an account, and you do not need to tell us who you are, to read any public page on this site. Browsing generates the first three things below, and none of them identifies you. Reporting a listing is the one place a visitor can choose to hand us a name.
- Listing views. We store one row per listing per day, holding the listing, the date and a number. There is no per-visitor record anywhere, no IP address, no user agent, no analytics cookie, and no third-party analytics or advertising script on the site at all. We cannot tell a member who looked at their listing, because we never kept it.
- One cookie, and only sometimes. If you arrive on a link carrying a campaign or referral tag (utm, ref or invite), or you follow a link from another website, we set a cookie named br_attr so we know later which link brought a signup. An ordinary visit — typing the address, or a normal search result — sets nothing at all. The cookie lasts 90 days, cannot be read by scripts in the page, and holds only the campaign tags, the hostname you came from, the page you landed on, an invite code if there was one, and the time. It holds no name, no email and no identifier for you. If you go on to sign up, we keep a copy of it with your signup so we know which campaign worked.
- Server logs. Our host and our database provider keep the usual request logs, including IP addresses, for security and reliability. We use IP addresses in memory to rate limit forms so they cannot be flooded, and we do not write an IP address into our own database.
- A report about a listing. Anyone can tell us a listing is not what it claims. The form takes a free-text reason and, if you want to give them, a name and an email so we can come back to you — both are optional and the form works without them. We email the whole report, including whatever you typed, to our own admin address, and we keep it after it is resolved. Do not put anything in the reason field you would not want us to hold.
6.Why we collect each of these
- To publish the listing you asked us to publish.
- To check the ABN against the Register and show the date we did it.
- To let you sign in, and to get you back into a half-finished signup.
- To take the payment, store your locked renewal price and run the subscription.
- To email you about your own subscription: the receipt, a renewal reminder, a card about to expire, a failed payment, a cancellation.
- To show you how many times your listing was viewed each day.
- To know which campaign or referral brought a member in.
- To act on a report that a listing is not what it claims.
- To keep an accurate record of billing events and admin decisions.
We do not build advertising profiles, we do not use your information to train any model, and we do not make automated decisions about you.
7.Who else handles it, and where they are
APP 6 says we may use your information for the reason we collected it, and not quietly turn it to something else. Everything below is us doing the job you paid for: five companies and one government service, each getting only what its part of that job needs, each handling it on our instructions.
- Supabase — our database, sign-in and file storage, so effectively everything described in this policy lives there. Our project runs in Supabase's Sydney region, so the data sits in Australia. Supabase itself is a United States company and its staff can reach that infrastructure from overseas.
- Stripe — payment and the billing portal. Stripe receives your email address, and your card details straight from your browser. We also pass it the listing's identifier and, if you arrived on a campaign link, the campaign source and name and any invite code. United States.
- Resend — sends our email. It receives the recipient address, subject and content of every message we send, including the report notice that carries a reporter's name, email and reason. United States.
- Vercel — hosts the site. Every request to bizroots.com.au passes through Vercel, which holds the standard server logs described above. United States.
- Google — only if you choose Continue with Google. Google handles that sign-in and tells our authentication provider who you are. United States.
- ABN Lookup, run by the Australian Business Register — receives the ABN and our registered identifier, and nothing else. An Australian government service, in Australia.
Overseas, in plain terms: Stripe, Resend, Vercel and Google are overseas recipients, mostly in the United States, and our Australian-hosted database is run by an American company. Under APP 8 we rely on their standard data-protection terms and send each one the minimum its job requires. We cannot run the platform without them, and we would rather name all six than write "and our service providers".
There is nothing else: no advertising network, no analytics vendor, no font CDN, no error-reporting service, no CAPTCHA provider.
We will disclose information if a law, a court or a regulator requires it, and we will tell you when we are permitted to.
8.Payment and card details
Your card number is typed into Stripe's own checkout page. It never touches our servers. We never see and never store a card number, an expiry date or a security code.
What we do keep: Stripe's customer and subscription references, whether the subscription is active, past due or cancelled, the amount you paid, your locked renewal price, and the date your current year ends.
One exception, stated because it is true: when Stripe warns us that a saved card will expire before your renewal, we record the last four digits alongside that notice in our internal log so we can tell you which card we mean. Those four digits are the only card data in our database.
9.How we protect it, and what happens if there is a breach
APP 11 asks us to take reasonable steps to protect what we hold, and it is fair for you to want those steps named rather than summarised as "industry standard".
What we do. Everything runs over HTTPS. Every table has row-level security, so one member's session cannot read another member's rows. The key that bypasses those rules exists only in server code and is never sent to a browser. Public listing pages read from a read-only projection that cannot be written through. Passwords are stored as hashes by our authentication provider. Admin actions re-check who you are on every action, not once at the door.
What we do not do, so you are not misled: we do not add our own layer of encryption on top of the database. Assume that we can read anything you put on your listing, and that our providers hold it under their own security.
If there is a breach. We contain it, work out who is affected, and fix what let it happen. If it is likely to cause serious harm and we cannot act fast enough to prevent that harm, we notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act requires. You will be told what happened, what was exposed and what to do about it, in plain words.
No system is completely secure, and we are a small operation. That is exactly why this policy lists what we hold: so you can decide what to give us.
10.How long we keep things
The honest position is that most of this we keep for as long as the listing exists. Where something has a clock on it, the clock is written below and we hold ourselves to it. Where we keep something indefinitely, we say so and say why, rather than publish a retention schedule we do not follow.
- Your listing and everything attached to it — locations, service area, profile fields, photos, view counts, the subscription record — is kept for as long as the listing exists. Cancelling does not remove it: the page stays up, quietly marked as lapsed. A suspended listing disappears from the site, but its rows stay in the database.
- Unfinished signups are kept for 12 months from the last time you touched one, then deleted along with the resume link that opens them. If a signup becomes a live listing we delete it at that point, because the listing is what we keep from then on. Email privacy@bizroots.com.au and we will delete one sooner. At our size that clear-out is done by hand, not by a scheduled job.
- The Register's replies are kept indefinitely, including for ABNs that never became a listing.
- Our billing and admin log is kept indefinitely and never edited. It records payments, failures, cancellations, admin decisions and the four card digits described above, and it is deliberately kept even if an account goes.
- Reports about listings are kept after they are resolved, including the reporter's name and email if they gave one.
- Daily view counts are kept. They contain no personal information.
- Photos. Deleting a work photo deletes the file, though if that delete fails the file can be left behind. Replacing your logo does not delete the old file, and its URL keeps working. If you need an old image gone for certain, email us and we will remove it by hand.
- The attribution cookie is the one thing with an enforced life: 90 days in your browser. The copy kept with your signup has none.
- The unsubscribe list is kept permanently, on purpose. If you tell us not to email you, the record of that request is the only thing that stops us doing it again — deleting it would mean mailing someone who asked us not to. It holds an email address and the reason, and nothing else.
If you want something removed sooner, ask us. The next section says what we can and cannot take out.
11.Getting a copy of your information, and correcting it
Some of it you can fix yourself in a minute. Sign in and open Profile, and you can edit every field in the profile builder — the contact email and phone your listing shows, your website and socials, opening hours, licence and insurance details, and the rest — clear any of them, and add or remove your photos and logo.
The rest of your listing has no edit screen yet: your trading name, your description, your categories, the suburb and street address we hold, the service area you set at signup, and whether that street address is published. Email privacy@bizroots.com.au, tell us what it should say, and we will make the change.
Your legal name, entity type and ABN status come from the Register: correct them with the Register and we will pick the change up on the next check — we never overwrite them by hand.
For anything else — a copy of what we hold, a correction, or a request to take something down — email privacy@bizroots.com.au. APP 12 gives you the right to ask for a copy and APP 13 the right to have it corrected; you do not have to give a reason for either. We will ask enough to be satisfied you are who you say you are, and we will respond within 30 days. There is no charge.
Know how this works today: there is no export button and no delete-my-account button in the product. One person does these by hand. At our size that is fine, and we would rather say so than imply a self-service tool that does not exist.
What we can do: unpublish your listing, strip the contact details from it, correct anything that is wrong, and remove uploaded files. What we will keep: the unsubscribe list and the billing and admin log — one exists to protect you from us, and the other is the record of money that changed hands. Both are covered in section 10.
If we refuse a request we will tell you why in writing, and you can take it further — see section 13.
12.Email, marketing and the Spam Act
There are two kinds of email and the difference matters. Transactional email is part of the service you bought: your receipt, a renewal reminder, a card about to expire, a failed payment, a cancellation confirmation, a resume link, a sign-in email. It carries no unsubscribe link, because it is not marketing and the Spam Act 2003 (Cth) does not require one. If you do not want it, cancel the subscription; while you hold one, we have to be able to tell you about it.
Everything else is commercial email — marketing, in the language of APP 7 — and today we send none at all. If we ever do, it goes through a separate path that checks the unsubscribe list first and refuses to send if it cannot check, and it carries an unsubscribe link that works, the one-click unsubscribe headers your mail client uses, and our postal address, as the Act requires.
Unsubscribing from marketing never stops email about your own subscription. You can ask us to add your address to the unsubscribe list at any time by emailing privacy@bizroots.com.au, and we will keep that record permanently — see section 10.
13.Complaints
APP 1.3 says a privacy policy has to tell you how to complain and where to take it if our answer is not good enough. Here it is. If you think we have mishandled your information, email privacy@bizroots.com.au and tell us what happened. It reaches the person who can fix it. We will investigate and respond within 30 days.
If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner. The OAIC regulates the Privacy Act, its complaints process is free, and you do not need our permission to use it: oaic.gov.au.
14.Children and young people
Bizroots is a directory of businesses. An account exists to run a business listing and requires an active ABN, so the service is not designed for children and we do not knowingly collect information about them. If you believe a child has given us personal information, email privacy@bizroots.com.au and we will remove it.
15.Changes to this policy
The date at the top is the version. If we change something that affects how we use information you have already given us, we bump that date and email members before the change takes effect. Smaller corrections — clearer wording, a newly named provider — just change the date. Ask and we will send you the previous version.
16.Contact us
Privacy questions, access requests and complaints: privacy@bizroots.com.au. Anything else: hello@bizroots.com.au. Both reach Xaio Tech Pty Ltd (ABN 27 697 386 084), which operates Bizroots from Perth, Western Australia. You can also write to us at Xaio Tech Pty Ltd, 3/25 Walters Drive, Osborne Park, WA 6017. See also our Terms of Service.