Legal

Privacy Policy

RR Sols Pty Ltd t/a WattleAddr · ABN 56 672 722 486 · Last updated 5 September 2026

RR Sols Pty Ltd (ABN 56 672 722 486) t/a WattleAddr handles personal information in line with the Australian Privacy Principles (APPs). We host and process all data in Australia and do not send address or account data offshore; the one narrow exception, on the card-payment page, is described under "Data residency and cross-border disclosure".

1. Introduction

This Privacy Policy explains how RR Sols Pty Ltd (ABN 56 672 722 486), trading as WattleAddr ("we", "us", "our"), handles personal information. It applies to our website, the WattleAddr developer console, the WattleAddr API and the WattleAddr Shopify app.

This policy is a notice of how we handle personal information, not a contract. Where we rely on your consent we will ask for it separately.

We are a small Australian business. Whether or not the Privacy Act 1988 (Cth) requires it of us, we handle personal information as if we were bound by the Australian Privacy Principles and the Notifiable Data Breaches scheme, and this policy describes what we actually do. We have not opted in to the Privacy Act under section 6EA; if we do, we will say so here.

2. Whose information this covers

  • Website visitors and enquirers.
  • Account holders and customers (the people who sign up to and administer a WattleAddr account), and Shopify merchants who install our app.
  • End Users: individuals whose address input is submitted to the API by our customers' applications. For this data we act on the customer's instructions, as set out in our Data Processing Agreement. Australian law does not distinguish "controllers" from "processors"; each of us holds the data and is directly responsible for its own obligations.

3. What personal information we collect

We collect only what we need to provide and support the Service. This may include:

  • Account and contact information: name, work email, company name, ABN, billing contact and address. For Shopify merchants, the store domain and subscription status Shopify sends us.
  • Authentication data: hashed passwords and session records (IP address and browser type, which expire after 30 days). We never store passwords in plain text.
  • Address queries: the address text that customers' End Users type into forms and submit to the API, and the matched address returned. This "search log" may contain personal information (for example, a person's residential address). Retention is configured by the customer, who can also choose to store queries as a salted keyed hash (pseudonymisation, since we hold the key, not anonymisation) or to store no query or matched-address text at all.
  • Usage and technical data: API request metadata, IP addresses, timestamps, usage counts, device and browser information, and log data used for security, billing and diagnostics.
  • Payment information: your billing contact and address, and a record of each invoice and payment. If you pay an invoice by card in the console, you enter the card details on our page but they are encrypted and sent directly to our Australian payment processor (Pinch Payments) by their in-browser script; the card number, expiry date and security code never reach our servers and we never store them. The name on the card passes through our servers in order to be sent to the processor; we do not retain it. The processor keeps a payment record against our merchant account, holding your name, billing email and a tokenised reference to the card. There is no saved card, no direct debit mandate and no automatic payment. If we owe you a refund, we ask for your Australian bank account name, BSB and account number so we can send it; we hold the BSB and account number only until the refund is sent or declined, then delete them, keeping the account name and the last three digits so the payment can be matched against our bank statement.
  • Communications: support requests, contact-form messages and correspondence with us. Contact-form messages include the IP address they were sent from.

We do not intentionally collect sensitive information (as defined in the Privacy Act) and ask that you do not submit it through the Service.

4. How we collect it

We collect personal information directly from you when you visit our site, create an account, use the console, or contact us; from Shopify when you install our app; and through your use of the API (including address queries your application submits). Customers submit End User data to us on their own behalf and are responsible for having a lawful basis to do so and for any notice they owe their End Users. At sign-up we point you to this policy and ask you to accept our Terms of Service.

5. Why we collect and use it

We collect, hold and use personal information to:

  • provide, operate, secure and improve the Service, including matching and returning address results;
  • authenticate accounts and API keys, and prevent fraud, abuse and security incidents;
  • meter usage, bill you, and manage your account;
  • provide support and respond to enquiries;
  • comply with our legal obligations and enforce our terms.

We only use personal information for the purposes for which it was collected, for a directly related secondary purpose you would reasonably expect, or as otherwise permitted by the APPs or with your consent (APP 6). We do not sell personal information, and we do not use End User data for advertising, profiling or model training.

6. Disclosure of personal information

We disclose personal information only:

  • to the service providers listed under "Our service providers" below, each under confidentiality and data-protection obligations;
  • to a customer, where the information relates to that customer's account or its End Users;
  • to Shopify, for merchants who use our Shopify app: we send Shopify your plan selection so it can bill you, and Shopify sends us your store domain, subscription status and uninstall or data-erasure requests;
  • where required or authorised by law, or to a court, regulator or law-enforcement body acting lawfully;
  • to protect the rights, property or safety of any person, or to investigate suspected unlawful activity;
  • in connection with a sale or restructure of our business, subject to this policy and on notice to you.

7. Our service providers

We use a small number of Australian providers to run the Service: Binary Lane Pty Ltd (cloud hosting, Sydney and Melbourne), VentraIP Australia Pty Ltd (outbound email: invoices, account notices and contact-form messages), and Pinch Payments (card payments of our invoices). Our database runs on WattleDB, a managed PostgreSQL platform that is another product of RR Sols Pty Ltd, on Binary Lane infrastructure in Australia; it is the same legal entity, not a third party. The full list, with what each provider sees, is in Annex C of our Data Processing Agreement and in our Data Residency Attestation.

Shopify Inc. is not our service provider: it is the platform through which merchants buy our app, and its handling of merchant data is governed by Shopify's own privacy policy. We do not send End User address data to Shopify.

8. Data residency and cross-border disclosure (APP 8)

We store and process all personal information within Australia. Our primary infrastructure is in Sydney, with a standby in Melbourne and backups held in Australia, on Australian cloud infrastructure (Binary Lane). Address queries are not routed or processed outside Australia, and no End User address data is disclosed to any overseas recipient. This describes how the service operates now; if that changes we will update this policy and the Data Residency Attestation and notify customers before it takes effect.

One narrow exception applies, and only in the developer console. When you open the card-payment form on an invoice, your browser loads our payment processor's card-capture script from their content delivery network, which is operated globally by Microsoft. That request discloses your IP address, browser type and our site's address to that network; it carries no address data, no account data and no card data. The processor's own systems, which receive the card details, are hosted in Sydney. If you would rather not make that request, pay your invoices by bank transfer or PayID instead.

Two things run outside Australia and carry no personal information: our uptime probes run from GitHub-hosted servers and fetch only our public pages and API health endpoint; and outage alerts to us are sent through Telegram and contain only status text. No personal information is sent to any non-Australian endpoint other than the card-script request described above. Shopify, which merchants deal with directly, is a Canadian company with its own privacy policy.

9. Address search log and End User data

Because address queries can contain personal information, we give customers control over the search log:

  • configurable retention, up to the maximum for the plan (7, 30, 90 or 365 days), after which query and matched-address text is automatically purged by a daily job;
  • a keyed-hash mode that stores each query as a salted HMAC and does not keep the matched address text; this is pseudonymisation (we hold the key), not anonymisation;
  • a no-store mode that keeps no query or matched-address text at all, only counts, timing and billing;
  • the ability to apply either mode to log data already stored; and
  • access limited to the customer's authorised workspace members and to our staff strictly as needed to operate and support the Service.

When a customer deletes a workspace, its search-log text is deleted at that moment. Usage counts and billing fields remain as part of our tax records.

10. Security (APP 11)

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, including: encryption in transit (TLS); Australian-hosted, access-controlled infrastructure; hashing of passwords and API keys; least-privilege access; logging and monitoring; and regular review of our controls. No system is completely secure, but we work to protect your information and to respond quickly to any incident.

11. Direct marketing (APP 7 and the Spam Act)

We send service and account messages (invoices, usage and quota notices, key changes, security and maintenance notices, and notices under our Terms) that you cannot opt out of while you hold an account. We also send occasional news and offers about WattleAddr to account owners. We send these only where the Spam Act 2003 (Cth) allows, we never send them for anyone else's products, and every one carries a working unsubscribe link and identifies RR Sols Pty Ltd as the sender. You can stop them at any time with that link, in Account settings, or by leaving the news box unticked at sign-up. The link and the Account setting take effect immediately; a request by email is acted on within five business days. Stopping them does not affect service and account messages. We do not use tracking pixels or open tracking in any email.

12. Cookies and analytics

The console sets two first-party cookies: waddr_session, which signs you in (30 days), and waddr-theme, which remembers light or dark mode for one year, only if you choose one. The marketing website sets no cookies. Our website records the page viewed, referring site, time on page, country and city, browser type and IP address in our own Australian database, using a first-party beacon with no third-party analytics service. IP addresses and browser strings are cleared from those records after 90 days. You can control cookies through your browser settings.

13. Access and correction (APP 12 and 13)

You may request access to, or correction of, the personal information we hold about you by contacting privacy@wattleaddr.com.au. We respond within 30 days and may need to verify your identity. If we refuse access or correction, we will tell you why and how to complain. Where we hold End User data on behalf of a customer, please direct requests to that customer; we assist them as the Data Processing Agreement describes.

14. Retention and destruction

InformationHow long we keep it
Account and login detailsWhile the account exists, then deleted on your request or within 30 days of account closure
Session records (IP address, browser type)Expire 30 days after sign-in; expired records are deleted daily, and all your sessions are deleted when you sign out everywhere or change your password
Search-log text (query and matched address)The window the customer configures, up to the plan maximum; deleted immediately when the workspace is deleted
Search-log counts and billing fieldsFive years, as part of our tax records
Invoices, adjustment notes, refund recordsFive years, as the tax law requires; refund BSB and account number only until the refund is sent or declined
Website analyticsIP address and browser string cleared after 90 days; page, referrer and country kept
Contact-form messages and support correspondenceHeld in our email system for as long as needed to deal with the enquiry and any follow-up, and deleted on request
BackupsDatabase backups are taken daily and kept for 7 days, so a deleted record can remain in a backup for up to 7 days. Backups are restored only to recover the Service.

To close your account and have your personal information erased, email privacy@wattleaddr.com.au from the account owner's address. There is no self-service account deletion; workspaces can be deleted in the console.

15. Data breaches

We have a written procedure for assessing and responding to suspected data breaches. If a breach occurs that is likely to result in serious harm to an individual, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act) requires, and assist affected customers to meet their own obligations. Customers are told about breaches affecting their End User data within the time set out in our Data Processing Agreement.

16. Automated decisions

The Service makes automated decisions about API requests (for example, refusing requests once a plan's quota is reached, or rate-limiting a key). These affect your application's access to the Service, not any individual's rights or interests. We do not use automated decision-making that significantly affects individuals.

17. Children

The Service is intended for businesses and developers and is not directed at children. We do not knowingly collect personal information from children.

18. Complaints

If you have a privacy concern or complaint, contact our Privacy Officer at privacy@wattleaddr.com.au. We acknowledge complaints within 5 business days, investigate them, and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

19. Changes to this policy

We may update this policy from time to time. The current version, with its "last updated" date, is always available on our website. We notify account owners by email of material changes before they take effect.

20. Contact us

Privacy Officer, RR Sols Pty Ltd t/a WattleAddr, privacy@wattleaddr.com.au.

This document is part of the agreement between you and RR Sols Pty Ltd. It is not advice about your own legal position; get your own advice if you need it. Questions: legal@wattleaddr.com.au.