Legal
Privacy Policy
CRM Pilot Project Manager · Last updated 19 June 2026
This Privacy Policy explains how Tech To Cloud Pty Ltd (ABN 80 612 353 698) (“we”, “us”, “CRM Pilot”) handles personal information in connection with CRM Pilot Project Manager(the “Service”, at tasks.crmpilot.com.au). We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
1. Information we collect
We collect only what we need to run the Service:
- Account information — your name, email address and password (stored hashed, never in plain text).
- Content you create — workspaces, projects, tasks, sub-tasks, comments, labels, mind maps, and the data you enter in the Command Center (e.g. weekly reports, team tasks).
- Team & invite data — email addresses you invite, and workspace membership.
- Billing information — your plan and subscription status. Card payments are processed by Stripe; we do not see or store full card numbers.
- Technical & usage data — IP address, browser/device type, and security/audit logs needed to operate and protect the Service.
2. How we use your information
- To provide, maintain and secure the Service and your account.
- To authenticate you and isolate your workspace from others.
- To process subscriptions and payments.
- To provide support and troubleshoot issues you report.
- To send service and account communications (e.g. invites, security notices).
- To improve reliability and develop new features.
- To meet legal obligations and enforce our terms.
We do not sell your personal information, and we do not use your content to train AI models.
3. Who can access your data — including our team
Your workspace data is private to you and the people you invite. Access between accounts is technically enforced by row-level security, so one customer cannot see another customer’s data.
Authorised CRM Pilot staff may access your account data only when necessary to: provide support you have requested, investigate a security or fraud issue, keep the Service running, or meet a legal obligation. This access is limited to staff who need it, is used strictly for those purposes, and is never used to browse your content for any other reason. Our support tools surface account data in a read-only view for troubleshooting. If you’d prefer we not access a specific workspace for a support request, tell us and we’ll work with you another way where possible.
4. Service providers & overseas disclosure
We use a small number of trusted providers to deliver the Service. Some store data outside Australia:
- Supabase — database, authentication & file hosting (data hosted in Sydney, Australia).
- Vercel — application hosting & content delivery (United States / global edge).
- Stripe — payment processing (United States & global).
- Resend — transactional email delivery, e.g. invites (United States).
Where personal information is disclosed overseas, we take reasonable steps to ensure these providers handle it consistently with the APPs. We do not otherwise disclose your personal information except as described here or where required by law.
5. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects about you. Features such as the Marketing Health Score are informational aids you and your team interpret — they are not used to make decisions about individuals.
6. Data security
We protect your information with encryption in transit (HTTPS/TLS), row-level security that isolates each workspace, the principle of least-privilege for staff access, and a secret service key that is never exposed to your browser. No system is perfectly secure, but we take reasonable steps to protect your data.
7. Data retention & deletion
We keep your information while your account is active. You can export your data at any time, and you can ask us to delete your account — when you do, your personal information and content are removed (subject to any records we must keep by law). Deleting your account cascades to your workspaces, projects and tasks.
8. Your rights
Under the APPs you can request access to, or correction of, the personal information we hold about you, and ask us to delete it. To make a request, email us at the address below. If you’re not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Data breaches
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme.
10. Cookies
We use essential cookies to keep you signed in and to keep the Service secure. We do not use them for advertising.
11. Children
The Service is intended for business use and is not directed at children under 16.
12. Changes to this policy
We may update this policy from time to time. We’ll change the “last updated” date above and, for material changes, take reasonable steps to let you know.
13. Contact us
Privacy questions or requests: info@crmpilot.com.au. Tech To Cloud Pty Ltd, Melbourne, Australia.