Privacy Policy
Last Updated: February 1, 2026
🔒 Our Privacy Promise
We don't store your data. All ABN information you upload is processed in real-time and deleted immediately after your report is generated. Your data never touches our permanent storage.
1. Overview
GST-Verify ("we", "our", or "us") is operated by Aotol Pty Ltd (ABN 40 126 182 107). We are committed to protecting your privacy and handling your data with care and respect. This Privacy Policy explains how we collect, use, and protect information when you use our ABN verification service.
2. Information We Collect
2.1 ABN Data (Not Stored)
When you use our service, you upload:
- Australian Business Numbers (ABNs)
- Associated business names (if included in your file)
Important: This data is processed in memory only and is permanently deleted immediately after your verification report is generated. We do not store, log, or retain any ABN information you submit.
2.2 Payment Information
Payment processing is handled entirely by Stripe, our secure payment provider. We do not store:
- Credit card numbers
- CVV codes
- Banking details
We only receive confirmation of successful payment via Stripe session IDs, which are used solely to authorize report generation.
2.3 Analytics Data
We use Firebase Analytics to understand how our service is used. This includes:
- Page views (home page, sample report, pricing)
- File upload events (file type, number of ABNs)
- Process completion events
- Anonymous usage patterns
This data is anonymized and used only to improve our service. No personally identifiable information is collected.
2.4 Technical Information
Like most websites, we automatically collect certain technical information:
- IP addresses (for security and fraud prevention)
- Browser type and version
- Device type
- Access times
3. How We Use Information
3.1 ABN Verification
ABN data you provide is used exclusively to:
- Query the Australian Business Register (ABR) via ABN Lookup web services
- Generate your verification report
- Process is completed in real-time and data is immediately deleted
3.2 Service Improvement
Anonymous analytics help us:
- Understand user behavior and preferences
- Identify and fix technical issues
- Improve user experience
- Optimize service performance
3.3 Security
Technical information is used to:
- Prevent fraudulent transactions
- Protect against abuse and attacks
- Maintain service security
4. Data Retention
4.1 ABN Data: Immediately Deleted
Zero retention policy. ABN information exists in our system only during active processing (typically seconds) and is permanently deleted immediately after your report is generated.
4.2 Payment Information
Stripe session IDs are retained for 30 days for reconciliation and dispute resolution, then automatically deleted. No payment card details are ever stored by us.
4.3 Analytics Data
Anonymous usage analytics are retained in Firebase Analytics according to Google's data retention policies (typically 14 months). This data cannot be linked back to individual users or specific ABN information.
5. Data Sharing and Disclosure
5.1 Third-Party Services
We use the following third-party services:
- Australian Business Register (ABR): ABNs are queried via ABN Lookup web services to retrieve GST registration information
- Stripe: Payment processing (see Stripe's Privacy Policy)
- Firebase Analytics: Anonymous usage analytics (see Google's Privacy Policy)
- Cloudflare: Hosting and security services
5.2 Legal Requirements
We may disclose information if required by law, court order, or governmental authority. However, since we don't store ABN data, there is no ABN information to disclose.
5.3 No Sale of Data
We do not sell, rent, or trade any user information to third parties. Ever.
6. Your Rights
Under Australian privacy law, you have rights regarding your personal information:
- Access: Request information about data we hold (note: ABN data is not stored)
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your information (ABN data is already auto-deleted)
- Objection: Object to certain processing activities
To exercise these rights, contact us at the details below.
7. Security Measures
We implement industry-standard security measures:
- HTTPS encryption for all data transmission
- Cloudflare security and DDoS protection
- Cloudflare Turnstile for bot prevention
- Secure payment processing via Stripe (PCI DSS compliant)
- No permanent storage of sensitive data
- Regular security updates and monitoring
8. Cookies and Tracking
We use minimal cookies and tracking:
- Firebase Analytics cookies (anonymous usage tracking)
- Session storage for temporary data during verification process
- Stripe payment session cookies
No third-party advertising or tracking cookies are used.
9. Children's Privacy
Our service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children.
10. International Data Transfers
Your data may be processed in Australia and other countries where our service providers operate (including USA for Stripe and Firebase). All transfers comply with applicable privacy laws and use appropriate safeguards.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top indicates when the policy was last revised. Continued use of our service after changes constitutes acceptance of the updated policy.
12. Australian Privacy Principles
We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Our practices align with APP requirements for collection, use, disclosure, and security of personal information.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
Aotol Pty Ltd
ABN 40 126 182 107
Website: https://company.aotol.com
14. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us using the contact details above. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
Summary: Your Privacy in Simple Terms
- ✅ ABN data is never stored - deleted immediately after use
- ✅ No credit card details stored - Stripe handles all payments
- ✅ Anonymous analytics only - no personally identifiable tracking
- ✅ HTTPS encryption for all data transmission
- ✅ Australian owned and operated - complies with AU privacy laws