Privacy policy
Version 0.1 (alpha launch text, prior to counsel review)
Last updated: 29 May 2026
This Privacy Policy explains how Pump House collects, uses, and protects personal information. It is written to comply with the Australian Privacy Act 1988 and the 13 Australian Privacy Principles (APPs). We treat your data the way we would want ours treated. Where we have made trade-offs, we explain them. If something is unclear, ask us at [email protected].
1. Who we are (APP 1)
Pump House is operated by STANDING CLEAR PTY LTD (ABN 19669522847), Sydney, NSW, Australia.
For any privacy question, contact us at [email protected].
We have a designated privacy contact. For alpha and early customer phases, that contact is Michael Khedoori as the founder. As we grow we will appoint a formal Privacy Officer and update this section.
2. What information we collect
We collect three categories of personal information:
About you, our customer (the contractor or inspector using Pump House):
- Name, email, phone number.
- Business name and ABN.
- Password (stored hashed, never readable).
- One-time sign-in codes and remembered-device tokens, both stored only as hashes.
- IP address and browser fingerprint on each sign-in (used to detect suspicious activity).
- Any photos, signature, or profile data you choose to upload.
About the building owners and managers you enter into Pump House (your customers):
- Name, contact details, building address.
- Building characteristics relevant to fire safety inspection.
You enter this data on behalf of those people. Under privacy law, we treat them as having consented through their commercial relationship with you. You are responsible for telling them that their information is stored in Pump House.
About the buildings and inspections themselves:
- Building characteristics, layout, fire safety assets.
- Defects logged during inspections (text, photos, classifications).
- Reports generated, recipients, send timestamps.
- Audit trail of every action taken inside an organisation.
3. How we collect it (APP 3, 4, 5)
We collect personal information directly from you when you:
- Sign up for an account.
- Add information to your organisation (buildings, defects, reports).
- Email or contact us.
- Use the service in any normal way.
We do not collect personal information about people who are not Pump House users without their knowledge. The exception is building owner information that you enter; that is your responsibility to handle lawfully.
We do not buy personal information from third parties. We do not run advertising, so we do not collect tracking data for ad purposes.
4. How we use it (APP 6)
We use your personal information to:
- Provide the Pump House service to you.
- Process payments and send invoices.
- Send you transactional emails (account verification, password reset, report delivery, billing).
- Respond to your support requests.
- Investigate and resolve security incidents.
- Improve the service (in aggregate, never tied to individual users in a way that identifies them).
- Comply with Australian law (tax records, court orders).
Pump House uses artificial intelligence to help you produce reports faster. Two features use AI: report drafting, which sends the relevant building, measure, and defect data for a report to our AI provider so it can generate draft wording that you then review and edit; and legacy report ingest, which sends an uploaded prior report (PDF) to the AI provider so it can extract that report's structured contents. Our AI provider is Anthropic (United States). Under our commercial agreement with Anthropic, they process this data only to return the result to us and do not use it to train their models. You always review AI-generated drafts before they become part of a report, and the AI never sends anything on your behalf.
We do not use your personal information to train our own artificial intelligence models. If we add further AI features in the future we will update this policy and tell you what changes before the features go live.
We do not sell personal information.
5. When we share it (APP 6, 8)
We share personal information with these categories of third parties, only as needed to operate the service:
- Hosting provider: DigitalOcean (Sydney, syd1 region) hosts the Pump House application. Your data is processed and stored on their Sydney infrastructure.
- Database provider: DigitalOcean Managed PostgreSQL (Sydney, syd1 region) hosts the Pump House database. Same Sydney processing and storage.
- Object storage: DigitalOcean Spaces (Sydney, syd1 region) holds your PDFs, defect photos, and uploads. Sydney processing and storage.
- Email delivery: Resend (United States) delivers transactional emails on our behalf. Email content (recipient address, subject, body) crosses to US servers for delivery.
- Error monitoring: Sentry (European Union region after our 2026 migration; previously United States) receives error reports. We scrub these reports to remove personal identifiers before they leave Pump House.
- AI provider: Anthropic (United States) processes report data and uploaded legacy reports to generate draft report wording and to extract the contents of prior reports. This content crosses to US servers for processing. Under our commercial terms Anthropic does not use it to train their models.
- Backups: DigitalOcean (Sydney, syd1 region). Database backups are created and stored automatically by DigitalOcean within the Sydney region, encrypted at rest with provider-managed keys. We do not replicate backups outside Australia.
We do not share your data with marketing companies, data brokers, or anyone whose business model depends on personal information.
We may disclose information if required by a valid Australian court order or government request, in which case we will tell you unless we are legally prevented from doing so.
6. Cross-border data flow (APP 8)
Most of your personal information is processed and stored in Australia (DigitalOcean Sydney, including hosting, database, and object storage). Some information crosses borders for these specific services:
- Email delivery: Resend (US) processes email contents to deliver transactional emails.
- Error monitoring: Sentry (EU) receives error events.
- AI features: Anthropic (US) processes report data and uploaded legacy reports to generate report drafts and extract prior-report contents.
By using Pump House you consent to these cross-border transfers. We take reasonable steps to ensure the recipients of your information protect it consistently with the Australian Privacy Principles.
7. Direct marketing (APP 7)
We send transactional emails (account, billing, system notices) regardless of marketing preference. These are not marketing.
We may send marketing emails about new Pump House features, tips, or updates. You can unsubscribe from these emails at any time using the link at the bottom of every marketing email, or by emailing [email protected]. Unsubscribing from marketing does not unsubscribe you from transactional emails.
We do not send marketing on behalf of third parties. We do not sell or rent our mailing list.
8. Security (APP 11)
We protect your personal information with measures that are reasonable for the kind of information we hold and the size of our business. Specifically:
- Sign-in requires your email and password, plus a one-time code we email you whenever you sign in from a new device or browser.
- Passwords are hashed with bcrypt before storage. We never see your plaintext password.
- One-time sign-in codes and remembered-device tokens are stored only as hashes, never in readable form.
- All connections to Pump House use HTTPS (TLS 1.2 or higher).
- Each customer's data is isolated by Postgres Row Level Security policies at the database level. Cross-customer leakage is not possible through normal application use.
- Photo uploads are stored with their original metadata. Where a photo carries EXIF data, we read its capture time and GPS coordinates and store them with the photo, so an inspection photo can be tied to when and where it was taken. We do not strip this metadata, so treat defect photos as carrying location information.
- Every administrative action is logged in an audit trail with timestamp, user, and a description of what changed.
- We run regular automated security tests covering authentication, tenancy isolation, and known attack patterns. As of June 2026 we run 70+ such tests on every code change.
- We have written threat models for the Pump House application, the hosting infrastructure, and the AI features. We review them at least once per major release.
No system is perfectly secure. If you become aware of a security issue with Pump House, please report it to [email protected]. We do not punish responsible disclosure.
9. Retention and deletion (APP 11.2)
We keep your personal information only as long as we need it to provide the service or to comply with legal obligations.
Active account data: kept while your account is active.
After account deletion: when you delete your account, we soft-delete your data immediately and hard-delete after a 30-day grace period. During the grace period, you can restore the account by signing in and confirming. After the grace period, your data is removed from active systems.
Backups: backup copies of your data are created and retained automatically by DigitalOcean in the Sydney region on a rolling short-term basis. After you delete your active account, any backup copies that still contain your data cycle out of retention within that rolling window; we do not keep long-term archival backups.
Audit logs: we keep audit logs for at least 7 years where required by Australian tax or commercial record-keeping law. Audit log entries are stripped of personally identifying details except where needed for the log's purpose.
Marketing emails: if you unsubscribe from marketing, we keep a record of the unsubscribe so we do not accidentally send you marketing again. We do not keep any other marketing data about you after you unsubscribe.
10. Your rights (APP 12, 13)
You have these rights under Australian privacy law:
- Access: ask us what personal information we hold about you. We respond within 30 days. From inside the app, you can also use Account, Export to download a copy of all your data instantly.
- Correction: ask us to correct any inaccurate personal information. From inside the app, most fields are directly editable.
- Deletion: ask us to delete your account and all associated personal information. From inside the app, use Account, Delete. The 30-day grace period applies as described above.
- Withdrawal of consent: for processing that depends on your consent (most cross-border transfers fall here), you can withdraw consent at any time. Doing so may mean we can no longer provide some or all of the service.
- Complaint: if you think we have mishandled your personal information, contact us first at [email protected]. If we cannot resolve it, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
We do not charge for any of these requests.
11. Children
Pump House is a business service. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it.
12. Notifiable Data Breaches
We comply with the Notifiable Data Breaches scheme under the Australian Privacy Act. If a breach of personal information happens that is likely to result in serious harm to affected individuals, we will:
- Contain the breach.
- Investigate the cause and scope.
- Notify affected individuals as soon as practicable.
- Notify the Office of the Australian Information Commissioner.
- Take steps to prevent recurrence.
We document every security incident, whether it triggers the Notifiable Data Breaches scheme or not.
13. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. If a change materially affects how we handle your information, we will email the account owner at least 14 days before the change takes effect.
Contact
For any privacy question, email [email protected].