Legal

Privacy policy

ServiceFast (“ServiceFast”, “we”, “us”) provides a workspace that Australian construction and service businesses use to manage enquiries, estimates, jobs, invoices and aftercare. This policy explains what personal information we handle, why, and the choices you have. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Who is responsible for which information

Each business that uses ServiceFast has its own workspace. The business decides what records it keeps there, such as its clients, contacts, leads, estimates, jobs, documents and photos, and it is responsible for that information. We store and process it on the business’s behalf to provide the service. We are responsible for the account information we need to run ServiceFast itself.

Information we collect

Information from Google

ServiceFast requests only your basic Google profile (name, email address and profile picture) so you can sign in and so your account can be identified. We do not use Google user data for advertising, we do not sell it, and we do not share it except with the service providers listed below where needed to run ServiceFast. ServiceFast’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

We do not sell personal information, and we do not use advertising cookies or third-party analytics trackers.

Cookies

ServiceFast uses essential cookies only: a secure sign-in session cookie and a preference that remembers which workspace you last opened. Sign-in sessions end after seven days without use.

Where information is stored and who processes it

Workspace records are stored in a database hosted in Sydney, Australia. Uploaded files, email delivery and the ServiceFast application run on Cloudflare’s network, which may process information in other countries. We use these service providers to run ServiceFast:

Some of these providers are based in, or process information in, countries outside Australia, including the United States. We take reasonable steps to ensure they protect personal information consistently with the Australian Privacy Principles.

Security

Information is encrypted in transit. Each workspace is isolated from every other workspace, access is limited by team role, connection tokens for third-party services are encrypted at rest, and invitation and sign-in links are stored only as one-way hashes and expire.

Keeping and deleting information

We keep workspace records while the business’s workspace is active. Workspace owners and admins can export their records at any time; export files are deleted after seven days. When a workspace is closed we delete or de-identify its records within a reasonable period unless we are required by law to keep them.

Access, correction and complaints

You can ask to access or correct your personal information, or ask a question about this policy, by emailing support@servicefast.dev. If your information is held in a business’s workspace, we may refer your request to that business. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

We will update this page when our practices change and revise the date above.