DRAFT. This document is a draft awaiting approval. It will be marked final here once it is approved. Questions: admin@supplysafe.com.au.
SupplySafe
Privacy policy
Draft of 11 October 2026. Plain English; where this document and the law differ, the law applies.
SupplySafe keeps Safety Data Sheets (SDS) current and on record for Australian businesses. To do that we hold some personal information about the people who use it. This policy says what we collect, why, where it lives, who sees it, and what you can do about it. It follows the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Who we are
SupplySafe is operated by the business trading as SupplySafe (ABN to be inserted on approval), based in Victoria, Australia. We are the “APP entity” responsible for your personal information under the Privacy Act. Contact for anything in this policy: admin@supplysafe.com.au.
What we collect
We collect only what the service needs. Most of it is information you type in yourself.
- Your account: your name, work email address, password (stored only as a one-way hash we cannot read), and, if you turn it on, the details needed for two-step verification (an authenticator secret; never your codes).
- Your company: business name, ABN, what the company does, state, phone, address, and the people in its team, their roles and the invitations sent to them.
- Safety Data Sheets and products: the SDS files your company uploads and the product, manufacturer and revision details read from them. SDS are safety documents about chemicals, not about people, but Section 1 of an SDS can name a contact person and phone number at the manufacturer.
- What you do in SupplySafe: an audit trail of actions taken in your company (who uploaded, published, invited, changed settings, and when), support requests you send us and our replies, and the notification emails we send.
- Technical information: the usual server logs (time, path, outcome; not the content of what you typed), the IP address of each request for rate limiting and security, and, if the bot check is on, the result of Cloudflare Turnstile.
We do not collect government identifiers (other than your company’s public ABN), health information, or payment card details. We use no advertising or tracking cookies: the only cookies are the ones that keep you signed in and remember your theme.
Why we use it
- To run your account and your company’s SDS library, register and public QR pages.
- To send you the emails the service needs: confirming your address, resetting your password, invitations, support replies, and a daily notice when SupplySafe has checked and published your SDS.
- To keep the service secure: proving who you are at sign-in, rate limiting, and the audit trail your company’s owners and admins can see.
- To answer support requests and tell you about problems with your SDS.
- To meet our legal obligations.
We do not sell personal information, use it for advertising, or use it to train artificial-intelligence models.
Where it is stored
Your data stays in Australia unless the table below says otherwise. These are the providers that process it for us:
- Database and files
- Supabase, hosted in Sydney (AWS ap-southeast-2). Accounts, companies, SDS files, audit trail, support requests.
- Application
- Vercel, serving from Sydney (syd1). Runs the website; its server logs are held by Vercel.
- Resend. Sends our emails (confirmations, invitations, notices, support replies). Resend keeps delivery logs; its servers are in the United States.
- Code and backups
- GitHub. Our source code, and an encrypted nightly backup of the database and SDS files in a private repository (United States).
- Bot check (when on)
- Cloudflare Turnstile, at sign-up and sign-in only. Cloudflare sees the request it checks; it does not see your account.
Because Resend and GitHub operate outside Australia, some personal information (email addresses in sent mail; the encrypted backup) is disclosed overseas. We take the steps APP 8 requires: contracts with those providers, encryption of the backup with a key only we hold, and sending no more than each task needs.
Who sees it
- Your company’s team. Owners and admins see the company’s members, invitations, settings and audit trail. Every member sees the company’s SDS library or register.
- Other companies. Nothing about you. A company that publishes an SDS makes that SDS and its product details public (that is the point of an SDS). Who holds a product in their register is never shown to the company that publishes it.
- The public. A workshop can switch on a public QR page listing the SDS it holds. It shows the SDS, product names and the heading the workshop chose; no names of people, no addresses.
- SupplySafe staff. A small number of operators check and publish SDS and answer support. They sign in with two-step verification, every action they take is recorded, and they cannot see which workshops hold which products.
- Authorities. Only where the law requires it.
How long we keep it
- Safety Data Sheets: for as long as your company has an account, and for as long as the law may require afterwards. SDS are compliance records: workplaces must be able to show which SDS applied to a product at a given time, so a superseded SDS is kept and marked superseded rather than deleted.
- Your account: until you delete it. Deleting it (Settings → Account) signs you out everywhere and removes the account 30 days later; you can cancel in that time. Your company and its SDS are not deleted with your account.
- Audit trail: kept with the company. After your account is deleted, entries show the action without a way to identify you.
- Support requests: deleted with your account.
- Backups: nightly, kept for 7 days (daily) and 4 weeks (weekly). A deleted record leaves the backups on that schedule.
- Server logs: held by our providers for their standard periods (days to a few weeks).
Your choices and rights
- See and correct: your name and email are under Settings → Account; your company’s details under Settings → Business profile. Download my data gives you a file of what we hold about you.
- Delete: Settings → Account → Delete my account. If you are the only owner of a company, make someone else the owner first.
- Ask us: for access to or correction of anything else, or to complain, email admin@supplysafe.com.au. We reply within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
How we protect it
Every table is protected by row-level security in the database, so a company’s data is reachable only by its members. Owners, admins and SupplySafe staff must use two-step verification. SDS files live in a private bucket and are served through short-lived signed links. Passwords are hashed, not stored. Our code is checked automatically before every release for anything that would leak server secrets or one company’s data into another’s pages. We keep an encrypted off-site backup.
If a data breach is likely to cause serious harm, we will tell the people affected and the Information Commissioner as the Notifiable Data Breaches scheme requires.
Not an emergency service
SupplySafe is a records service. It is not a source of emergency advice and SupplySafe support is not an emergency contact. In a chemical emergency call 000, or the Poisons Information Centre on 13 11 26, and follow the SDS.
Changes to this policy
When we change this policy we update the date at the top and, for changes that matter, tell account holders by email. The current version is always at this address. See also our Terms of service.