Privacy Policy
Effective date: 1 August 2025
NextClick Technologies ABN [insert ABN] ("we", "us", "our") operates the Sitelens platform available at audit.nextclicktechnologies.online (the "Platform").
This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. What personal information we collect
1.1 Account information
When you create an account we collect:
- Email address
- Name (optional, if provided)
- Business name and industry (optional)
- Country
- Password (hashed — we never store your password in plain text)
If you sign in via a third-party provider (Google, GitHub, Discord, LinkedIn) we receive your name and email from that provider. We do not receive your password or payment details from those providers.
1.2 Audit inputs
When you run an audit, we collect and store the website URL you submit, along with any optional context you provide (company name, industry, country, contact email). This information is used to generate your audit report and is retained as part of your account history.
1.3 Usage data
We automatically collect:
- Audit activity (timestamps, scores, completion status)
- Feature usage (report views, PDF exports, share link creation)
- Error logs (anonymous, no personally identifying payload)
We do not use advertising tracking, behavioural profiling, or third-party analytics pixels.
1.4 Email settings
If you configure email delivery, we store your Resend API key (encrypted at rest), sender address, and email delivery history (recipient addresses, delivery timestamps, open/click events from your Resend webhooks). This data belongs to you and is only used to operate the email delivery feature on your behalf.
1.5 Payment information
We do not store payment card details. Billing is processed by our payment partner. We receive and store subscription tier, status, and renewal dates only.
2. How we collect personal information
We collect personal information:
- Directly from you when you register, configure settings, or run an audit
- From third-party OAuth providers when you use social sign-in
- Automatically through server logs when you interact with the Platform
Anonymous audits (run without an account) are stored with no associated user identity until you claim them.
3. Why we collect and use personal information
We collect and use your personal information to:
- Provide, operate, and improve the Platform
- Create and manage your account
- Generate and store audit reports on your behalf
- Send reports by email where you have configured and initiated delivery
- Enforce subscription plan limits and feature access
- Communicate with you about your account (transactional emails only)
- Maintain security and detect fraud or abuse
- Comply with legal obligations
We do not sell your personal information to third parties. We do not use your audit data to train AI models or share it with advertising networks.
4. Disclosure of personal information
We disclose personal information to the following service providers, strictly for the purpose of operating the Platform:
- Supabase Inc. — database, authentication, and storage infrastructure. Your data is stored in Supabase-managed PostgreSQL databases. Supabase is SOC 2 Type 2 certified.
- Resend Inc. — transactional email delivery. Your Resend API key and recipient email addresses are transmitted to Resend only when you initiate email delivery from the Platform.
- Google LLC — the Gemini AI API is used to generate executive narrative sections of audit reports. The audit findings and your optional business context (company name, industry, country) are included in the prompt. No personally identifying information beyond business context is transmitted. Google's API data usage policies apply.
- OAuth providers (Google, GitHub, Discord, LinkedIn) — used only for authentication. We receive name and email; we do not share your data back to these providers.
We may also disclose personal information where required by Australian law, a court order, or regulatory authority, or to protect the rights and safety of users or the public.
5. Security
We implement reasonable technical and organisational safeguards including:
- All data transmitted over HTTPS (TLS 1.2+)
- Row-level security enforced in the database — your data is inaccessible to other users
- API keys and secrets encrypted at rest using AES-256
- Multi-factor authentication required for platform administrators
- Immutable admin activity log with cryptographic hash chain for tamper detection
No security measure is perfect. In the event of a data breach that is likely to cause serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required under the Notifiable Data Breaches scheme.
6. Data retention
Audit reports are retained for as long as your account is active, subject to your subscription plan's history limits. You may delete individual reports at any time from your dashboard.
Email delivery history is retained for 30, 90, or 180 days based on the retention setting in your email configuration. You may purge it on demand from Settings.
If you close your account, we will delete your personal information within 30 days, subject to legal obligations that require longer retention (e.g., tax records).
7. Cookies and local storage
We use browser localStorage to store your authentication session token. We do not use third-party advertising or tracking cookies. The Platform does not use cookie consent banners because we do not set non-essential cookies.
8. Your rights
Under the Australian Privacy Principles you have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — ask us to correct information that is inaccurate, incomplete, or misleading
- Deletion — request deletion of your account and associated data
- Complaint — lodge a complaint with us, and if unresolved, with the OAIC at oaic.gov.au
To exercise any of these rights, contact us at privacy@nextclicktechnologies.online. We will respond within 30 days.
9. Cross-border disclosures
Some of our service providers are located outside Australia (United States). Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it in a manner consistent with the APPs, including through contractual data processing agreements.
10. Children
The Platform is intended for business users and is not directed at children under 16. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users by email for material changes. Continued use of the Platform after the effective date constitutes acceptance of the revised policy.
12. Contact us
Privacy enquiries and requests: privacy@nextclicktechnologies.online
NextClick Technologies
Australia