eFile Vault — Privacy Policy
Version: 2026-09-15.1-review Status: revised draft for owner and Australian legal review; not yet activated for customer acceptance.
VENTURESTACK PTY LTD (ABN 55 699 711 272) operates eFile Vault. Contact us at info@venture-stack.com.au for privacy enquiries, access or correction requests and complaints. This policy covers the website, account and download service, desktop application and related hosted features.
1. Purpose and application
This policy describes our handling of personal information. It is not an unlimited consent request, a guarantee of security, a service-level agreement, or a waiver of your statutory rights. We comply with privacy obligations to the extent they apply to us. References to Australian Privacy Principles describe relevant handling requirements and do not represent that every law or exemption applies identically to every activity.
When you use eFile Vault for an organisation, that organisation may control account membership, workspaces, access and information it supplies. Its handling is also governed by its own arrangements. Describing it as responsible for Customer Data does not remove any obligations that apply independently to us.
2. Information handled
Depending on the features you use, we may handle:
- Account and identity information: email address, verification/account identifiers, name and organisation details you provide, authentication/session information and membership or entitlement records. Password authentication is provided through our authentication service; do not include passwords in enquiries.
- Website enquiries and support: name, organisation, email, topic, message, correspondence and diagnostic material you choose to provide. Avoid sending confidential matter content or sensitive personal information unless it is needed and you are authorised.
- Acceptance and download evidence: verified account identifier and email, name and organisation declared by the user, exact terms/privacy/consent wording and document versions, hashes of those documents, server timestamps, record/request identifiers, and technical request context such as IP address and browser information where captured. User-supplied information is not necessarily independently verified.
- Workspace and filing information: matter names, folders, file names, senders, recipients, dates, tags, tasks, notes, comments, membership and permission information, and search data. Search processing may include extracted document/email text and derived searchable terms. Do not assume searchable data is anonymised or that hosted processing excludes document content.
- Connected service information: account/provider identifiers, access grants and tokens used for the mail or storage integrations you enable; and messages, attachments and metadata handled through the requested filing functions.
- Commercial information: plan, seat count, billing contact, payment references and status when billing is enabled. A payment processor handles card information through its payment flow; the filing app is not intended to collect card details directly.
- Technical information: device/browser/app version, network/request information, authentication/security events and error or operational logs generated by the services used to provide the product. We do not represent that all logs exclude personal information.
Customer files may contain information about clients, staff or third parties, including sensitive information. You must assess your authority to supply and process that material. Where consent or another legal condition is required, it must be met for the relevant handling; your general acceptance of this policy is not consent on behalf of every person in your documents.
3. Collection and choices
Information can come directly from you, your organisation or authorised users, integrations you connect, and technical operation of the Service. Mail access follows the provider permissions you authorise. The account-and-download flow requires an account and recorded acceptance before an installer is authorised. If you decline information reasonably necessary for those functions, we may be unable to provide them.
We distinguish acknowledgement that this policy has been provided from any specific consent. For website registration and download access we request consent to handling the account information you supply and acceptance/download records for those stated purposes, as described here. That consent does not cover advertising, sale of data, unrelated analytics, general AI training or unspecified future purposes. Processing may also be authorised or required independently by law; consent is not asserted as the only basis for every activity.
You may contact us about withdrawing a consent. Withdrawal affects consent-based future handling to the extent applicable, may prevent dependent functions being supplied, and does not invalidate earlier lawful handling or require deletion of records lawfully retained for another reason. Additional consent, when needed for a particular optional feature or sensitive information, must be sought at that point rather than assumed from this policy.
4. Purposes
We handle information to register and authenticate accounts; verify and administer access; organise, index, search, display and share information according to requested features and permissions; process enquiries and payments; operate, maintain, troubleshoot and secure the Service; investigate abuse; administer acceptance and downloads; establish, exercise or defend legal rights; and meet legal obligations.
Any additional use or disclosure must have an applicable legal basis and, where required, appropriate notice or consent. This policy does not grant us a licence to sell personal information or use private customer files for unrelated marketing or AI training. No marketing consent is bundled into the download acceptance step.
5. Storage, integrations and recipients
You select a local or supported cloud-drive folder for the document library. The desktop application and integrations process file content to carry out requested functions. Choosing your own folder does not mean that no personal information reaches hosted systems: account information, metadata, notes, search data and acceptance records may be hosted separately. File bytes may also be supplied to us if you deliberately send them for support. Your storage provider operates under your separate arrangements.
Our current architecture uses Supabase for account authentication, hosted database and related backend functions; the configured primary database region is Sydney, Australia. This is not a representation that every provider's support, telemetry, backup or other processing is exclusively Australian. Website hosting, enquiries and download functions are being prepared for Netlify. Stripe is used where payment functionality is enabled. Enquiry notifications are delivered to our nominated email account. Gmail, Microsoft and cloud-drive providers participate where you choose their integrations.
Information may be disclosed to personnel and contractors who need it for the relevant work; hosting, authentication, storage, communications, payment and security providers; your authorised organisation members; professional advisers and insurers; and authorities or other recipients where law requires or permits it. In a genuine business transaction, relevant information may be disclosed to advisers or prospective successors under appropriate arrangements and applicable law. This is not permission for unrestricted disclosure.
Some providers and recipients operate in the United States and other countries. The deployment review must confirm the likely overseas countries and relevant providers before this policy is activated, including Netlify and the business email service. Where overseas disclosure occurs, applicable Australian privacy requirements continue to apply. Acceptance of this policy is not a waiver of overseas-disclosure protections or blanket consent to an exception to them.
6. Security and customer controls
Security arrangements depend on the component and deployment and include access controls, authentication and protected connections where configured. We take the steps required by applicable law. No system is immune from error, unauthorised access or loss, and no absolute protection, end-to-end encryption or guaranteed restoration is represented. Some hosted search data can contain readable content or sensitive terms; do not assume all stored data is encrypted in a manner inaccessible to the operator.
You are responsible for your devices, account security, user permissions, connected services and independent backups. Notify us of suspected unauthorised access. These responsibilities do not excuse our own legal duties. Where a breach triggers a legal assessment or notification requirement, we will respond as required by that law; no fixed contractual notification deadline is created by this policy.
7. Retention and legal records
Retention depends on the purpose, account and feature, applicable law, dispute risk and operational circumstances. We do not promise that every category is deleted immediately on account closure, retained for the same fixed period, or recoverable for a fixed post-closure window.
We may retain acceptance/consent records and the associated versions of documents, commercial records, security evidence and information needed for actual or reasonably anticipated disputes after account closure where law permits. Retention must remain justified by the relevant purpose or legal requirement; it is not indefinite retention merely because a dispute is imaginable. Corrections to evidence may be appended with an explanation rather than silently replacing the original, subject to applicable access, correction and destruction obligations.
Where applicable law requires destruction or de-identification when information is no longer needed, we will act accordingly, subject to lawful exceptions. Backups, logs and third-party systems may have different deletion cycles. A legal hold can defer ordinary deletion to the extent justified. Removing a website/app account does not automatically delete files from a customer-controlled drive or another person's independently retained records.
8. Access, correction and complaints
Email info@venture-stack.com.au with your request or complaint and sufficient information to locate the relevant records. We may seek reasonable identity/authority verification and clarification, and may redact third-party information or rely on a lawful exception. We will handle requests, explain refusals and any available complaint mechanisms, and charge any permitted access fee only in accordance with applicable law. We do not charge merely to make a privacy complaint.
If information relates to an organisation's workspace, we may coordinate with its authorised contact where appropriate without overriding rights you have against us. To complain, identify the concern, relevant account and desired resolution. If unresolved, you may contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au or another competent regulator. Applicable statutory timeframes and remedies are unaffected by the absence of a promised service-response time.
9. Website technologies and changes
The website uses browser/session mechanisms needed for sign-in and operation, and hosting providers may process technical request information. The present website does not intentionally include advertising trackers; this is a description of the current implementation, not an irrevocable product commitment. Any future technology must be assessed for applicable notice/consent requirements before introduction.
We may revise this policy to reflect changed practices or legal requirements. A revised notice does not itself authorise a new use or override a consent requirement. Material changes requiring notice or consent will be handled accordingly. Historical versions relevant to recorded acceptances may be retained as evidence.
10. Business contact
VENTURESTACK PTY LTD — ABN 55 699 711 272. Enquiries, support, privacy and electronic notices: info@venture-stack.com.au. No street address is published in this draft. This does not displace statutory service arrangements or any applicable obligation to provide an address in another context.
SHA-256: 935c233c562da1e60443135a481cb399466861cd89067b78fbf42b0f92d4b677