Document: WG-PRV-001 · Updated 5 September 2026
The short version
- We collect what we need to build your site, run it, and invoice you.
- We never sell your information, and we never use it for marketing you did not ask for.
- Some of the services we use hold data overseas, mostly in the United States. They are all named below.
- We also hold information about your customers. We use it to run your service and for nothing else.
- Ask us what we hold and we will send it, or fix it, within 30 days.
- If information is lost or exposed and it could seriously harm you, we tell you and the OAIC.
This summary is here to be readable. It is not the policy, the sections below are.
This policy explains how Web Gecko handles personal information. It follows the Privacy Act 1988 (Cth) and the Australian Privacy Principles, which we call the APPs below.
1. Who we are
Web Gecko (ABN 32 300 992 377) builds and runs websites for small businesses in Queensland and across Australia.
Contact us at [email protected], on 0494 737 600, or in writing to PO 4034, Forest Lake QLD 4078. Our address is Suite 4034, Unit 9/235 Forest Lake Blvd, Forest Lake QLD 4078.
The same person handles privacy questions and complaints. Use any of those details and it reaches us.
2. Two kinds of information, and why the difference matters
Yours. Information about you as our client, or as someone who has asked us for a quote. We decide what happens to it, and this policy governs it.
Your customers'. Information your website and your phone line collect from the people who contact you: names, numbers, enquiries, bookings, job photos. We hold that on your behalf and on your instruction. It is your business's information, not ours. We do not use it for our own marketing and we never sell it. Your own privacy policy governs what your business does with it.
3. What we collect about you
- Who you are: business name, contact name, ABN and trading details
- How to reach you: email, phone and business address
- Your trade licence number, where your trade needs one shown on advertising
- Billing: what you were invoiced and what you paid. Card and bank details are entered on Stripe's own page. We never see them and we never store them
- Your signature record: if you sign an agreement online we keep the name you typed, your IP address, your browser, and the times it was sent, opened and accepted
- Technical information: website analytics, IP address, browser type and which pages were viewed
- Content: the text, images and material you give us for your site or your socials
- Our conversations: emails, messages and notes about your job
4. What we hold about your customers, for you
- Name, email and phone, from a form on your site or a booking
- Their enquiry, in their own words
- Booking details: date, time and the job they want done
- Missed-call rescue: the text thread that follows a missed call, and any voicemail. The recording itself stays with the phone provider
- Job photos. Photos uploaded through your portal are stored in a public bucket, which means anyone who has the link can open the file. Do not upload anything you would not put on your website
5. How we collect it
Most of it comes straight from you, when you ask for a quote, sign up, use your portal, or send us content.
Some arrives through the systems we run for you: a form on your site, a booking, a missed call.
Some we collect from public sources when we are looking for businesses to approach. That means Google Business Profile listings, the Australian Business Register, and business websites. It is business contact information, and for a sole trader it is still personal information, so we tell you here rather than leave it unsaid.
If we contact you off a public listing and you ask us not to contact you again, we stop and we record it so it does not happen twice.
6. Why we use it
- To deliver the work you engaged us for
- To quote, invoice and take payment
- To talk to you about your job, including drafts and approvals
- To send service notices, such as an invoice or a renewal
- To meet our legal and tax obligations
- To fix problems and improve how the service runs
We do not use your personal information for marketing you did not ask for, and we do not sell it to anyone.
7. Who we share it with, and where they hold it
We use other companies to run the service. Each one only gets what it needs to do its job, and each is engaged to handle it on our behalf.
| Provider | What they do | Where the data can be held |
|---|---|---|
| Cloudflare | Website hosting, form capture, spam filtering, photo storage | United States, and any country where Cloudflare runs servers, including Australia |
| Stripe | Payments and subscriptions | Australia and the United States |
| Twilio | Text messages and voicemail | United States |
| Resend | Sending email | United States |
| Your Google Business Profile, and your business details when we build your site with Google Stitch | United States, and other countries where Google runs data centres | |
| Buffer | Scheduling social posts | United States |
| Anthropic and OpenAI | Writing and editing your website from your brief, and drafting social posts from your job notes and photos | United States |
| Backblaze | Off-site backup. It is encrypted on our machine before it is uploaded, so Backblaze cannot read it | United States |
We may also share information with our accountant or lawyer where it is needed, and with a regulator or a court where the law requires it.
This is a disclosure outside Australia under APP 8. We take reasonable steps to make sure these providers handle information consistently with the APPs, and each is bound by its own data processing terms. You should know the limit of that. Once information is held overseas, Australian privacy law may not protect it the same way. It may also be reachable by that country's courts and agencies.
If you would rather we did not use a particular provider, tell us. Some of them are the service, so the honest answer may be that we cannot deliver that part of it.
8. Where it is held
- Cloudflare, for your website, form enquiries, portal data and photos
- On our own computers in Australia, for your client, job and invoice records
- In an encrypted off-site backup
9. How long we keep it
- Client, job and contact records: for as long as you are a client, then 7 years, because tax law requires business records to be kept that long
- Invoices and payment records: 7 years, same reason
- Missed-call text threads and voicemail: 12 months, then deleted
- Your final backup after you leave: 90 days, then deleted
- Agreement and portal links: they expire by themselves, and a link is dead once revoked
10. Keeping it safe
Everything travels over an encrypted connection. Access is limited to the people who need it. Backups are encrypted before they leave the machine. We hold no card numbers and no bank account numbers.
No system on the internet is perfectly secure, and we do not pretend otherwise.
11. If there is a data breach
The Notifiable Data Breaches scheme in Part IIIC of the Privacy Act says what happens next, and we follow it.
We contain the breach first. We then assess it, and the law gives us a maximum of 30 days from becoming aware of it to finish that assessment.
If the breach is likely to cause serious harm, we notify you and the Office of the Australian Information Commissioner (OAIC) as soon as we can. We tell you what happened and what to do about it.
12. Getting a copy, or fixing it
You can ask for a copy of the personal information we hold about you, or ask us to correct it, at any time. Email [email protected] or call 0494 737 600.
There is no self-service login for this. We put it together by hand and respond within 30 days.
In some cases the Privacy Act lets us refuse access. If that happens we tell you why, in writing, and how to challenge it.
13. Deleting it
Ask us to delete your information and we remove your name and contact details from our client, job, follow-up and missed-call records.
We cannot delete everything, and here is the honest limit. Invoices and other tax records must be kept for 7 years, so those stay, with your contact details stripped out of them. Anything already sent to one of the providers in section 7, a text message or a payment receipt, is held under that provider's own rules.
14. Marketing, unsubscribing and calls
Marketing emails and texts follow the Spam Act 2003. Every marketing email carries who sent it, how to reach them, and an unsubscribe link, and every marketing text offers a STOP reply. Unsubscribe and we action it within 5 business days.
Messages your system sends your own customers are sent by you, not by us. You need their consent. See section 12 of our Terms and Conditions (WG-TNC-001).
We call clients about their service, and about what else we offer, with your consent given in the service agreement. Tell us to stop, by any means, and we stop permanently. If your number is on the Do Not Call Register, that consent is what makes the call lawful, and withdrawing it takes effect straight away.
15. Cookies and analytics on this site
These legal pages run no scripts at all. webgecko.au sets no advertising or tracking cookies, and we sell nothing to advertisers.
Our host and Cloudflare keep standard server logs, which include IP addresses, and Cloudflare may set a cookie that tells a person from a bot. Both exist to keep the site up and secure.
16. Making a complaint
Contact us first, using any of the details in section 1. We investigate and respond within 30 days.
If our answer does not satisfy you, complain to the Office of the Australian Information Commissioner. Their website is oaic.gov.au and their line is 1300 363 992. Complaining to them costs nothing and you do not need our permission.
17. Changes to this policy
The current version is always the one on this page, with the date at the top. If we change something that affects how we handle your information, we tell you.
WebGecko