DRAFTDraft — have a lawyer review before relying on it.
Privacy Policy
Last updated 2026-10-06 · English is the governing text.
隐私政策(摘要)
- 数据保存在新加坡的服务器上(DigitalOcean 新加坡机房),即存放在澳大利亚境外。
- 店铺客户的资料由我们代表店铺处理:店铺是资料的控制者,我们是处理者。
- 校样核对程序运行在我们自己的服务器上,不会把你的文件发给第三方,也不会用任何文件训练 AI。
- 付款由 Paddle 处理,我们看不到也不保存你的银行卡信息。邮件通过 Resend 发送。
- 你可以随时要求查看、更正、导出或删除你的资料:support@plomb.app。
1. Who we are
Plomb is operated by [Owner's legal name], sole trader, trading as Plomb (ABN [ABN — pending]), [Business postal address], New South Wales, Australia ("we", "us").
This policy explains what personal information Plomb collects, why, where it is stored and the choices you have. We handle personal information in line with the Australian Privacy Principles and, for people in the EU and UK, the GDPR.
2. What we collect
Shop users: name, email address, password (stored only as a salted hash) or the Google / Microsoft account you sign in with (we receive your name and email address only), shop name, phone and logo, and your language preference.
Customers of shops: the details a shop or customer enters for an order (for example business name, phone, address, website), files uploaded (proofs, logos, site and install photos, production files), messages, change requests and approval records (name typed, email address used for the approval code, time, IP address and browser).
Technical data: server logs (IP address, time, page requested) kept for security for up to 30 days. We use a small number of strictly necessary cookies (sign-in session, language). We do not use advertising or third-party analytics cookies.
Billing: Paddle handles payment details. We receive from Paddle the subscription status, plan, country and a customer reference, never card numbers.
3. Shops' customers: we process on the shop's behalf
Information about a shop's customers is collected by the shop, which decides what to collect and why. For that information the shop is the controller and we are its processor: we only use it to run the Service for that shop and its customers. Customers who want to access, correct or delete their information should contact the shop first; we will help the shop respond.
4. How we use it
To provide the Service (check proofs, show orders, send approval codes and notifications, record approvals), to keep it secure (rate limits, abuse prevention, backups), to bill subscriptions through Paddle, and to answer support requests.
We do not sell personal information, use it for advertising, or use any uploaded file or detail to train artificial-intelligence models. The proof checker runs on our own server and does not send files to third parties.
5. Where it is stored
The app, its database and uploaded files are stored on our server in Singapore (DigitalOcean, SGP1), so your data is held outside Australia. Some service providers below also process limited data in other countries; where they do, we rely on their contractual commitments (including standard contractual clauses for EU / UK data).
6. Service providers (sub-processors)
DigitalOcean (hosting, Singapore) · Paddle.com (reseller and merchant of record: checkout, payments, tax, invoices) · Resend (delivery of emails such as approval codes and notifications) · Cloudflare (DNS and forwarding of email sent to our support address) · Google and Microsoft (only if you choose to sign in with them).
7. How long we keep it
Order data and files are kept while the shop's account is open, so approvals stay verifiable. When a shop is closed we delete its data within 30 days; backups expire within a further 30 days. Approval records may be kept longer only if the shop asks us to, or the law requires it. Billing records are kept by Paddle under its own policy.
8. Your rights
You can ask to access, correct, export or delete your personal information, or object to or restrict how we use it, by emailing support@plomb.app. We reply within 30 days. If you are unhappy with our answer you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in the EU / UK, your local data protection authority.
Legal bases (GDPR): performing our contract with shops; our legitimate interest in keeping the Service secure; legal obligations; and, for a shop's customers, the shop's own basis for collecting their information.
9. Security
Connections use HTTPS; passwords are hashed; customer links are stored only as hashes; files are served only to signed-in shop users and the holders of a valid customer link; access is logged. If a breach affects your information we will tell you and, where required, the regulator.
10. Changes and contact
We will post changes here and email shop owners about material ones. Contact: support@plomb.app.