Privacy
Privacy notice
This notice explains the information Service Sheet handles, why it is needed, how different record types are retained, and how to contact us about privacy.
Last updated:
Information we handle
Service Sheet handles account and user details; organisation, role and Location-access records; asset identifiers; kilometres and engine hours; customer-defined maintenance schedules; completed service records; factual issue reports; issue photographs a customer chooses to upload; billing and account records; and security and audit evidence.
We receive this information from account users, invited team members, operators or drivers using the QR workflow, and companies that help operate the service. Secure sign-in and browser cookies are used to keep people signed in, remember their active organisation and recognise a browser that has been verified for 30 days.
How information is used
Information is used to keep each organisation’s records separate, provide maintenance tracking and reminders, operate QR workflows, maintain service and issue history, sign users in, apply roles and permissions, protect the service, provide support, administer accounts and billing, send transactional communications, investigate faults and meet legal or accounting obligations.
Service Sheet does not use operator submissions to independently diagnose faults or decide maintenance requirements. Your organisation remains responsible for checking submitted information and making maintenance and safety decisions.
QR and operator submissions
Public QR submissions may include a reading, issue description, optional photograph, the relevant asset and limited information used to protect the public reporting workflow. Service Sheet does not independently verify that a reading, description or photograph is complete or accurate. The organisation that controls the asset is responsible for telling operators what to submit and for reviewing that information.
Issue photographs
Uploaded images are validated, converted to one normalised WebP file and stripped of unnecessary embedded data before private storage. Service Sheet does not keep the original upload or a separate thumbnail. When retention completes, the private image file is removed, but the historical issue record remains, including the report and resolution details and evidence that a photo was removed under the retention rule.
Record retention
Different record types serve different purposes and are not all deleted at the same time.
| Record type | What happens |
|---|---|
| Organisation and account records | Retained while the account is active or deactivated. Deactivation stops operational use but is not deletion. |
| Asset records and meter-reading history | Retained as operational history while the account exists, including for archived assets. |
| Maintenance schedules and completed service history | Retained as customer operational history while the account exists. |
| Issue records | Resolving an issue does not delete its historical record. The report, resolution and available audit evidence remain while the account exists. |
| Issue photographs | Available while the issue is open, then for 30 full days from resolution. The private image file is removed automatically after that period. |
| Billing and accounting records | Retained as needed to administer subscriptions, reconcile payments, resolve disputes and meet legal, tax or accounting obligations. Payment-provider retention also applies. |
| Security and audit records | Retained as reasonably needed to protect accounts, investigate activity and evidence important actions. Minimal deletion evidence may remain after operational account data is removed. |
Permanent account deletion is separate from deactivation, requires any active paid subscription to have ended, and removes customer operational content through a protected process. Protected database backups may retain database records until normal rotation. Standard database backups do not contain issue-photo files; Service Sheet does not operate a scheduled permanent photo archive. Records may be retained for longer where reasonably required by law, a court or tribunal order, accounting obligations, dispute handling, fraud prevention or security.
Service providers
Companies that host and operate Service Sheet, manage sign-in, store information, deliver transactional email and process payments handle the information needed for those functions. Service Sheet currently uses Vercel, Supabase, Resend and Stripe. Stripe processes payment details; Service Sheet does not store card numbers or CVC. These companies process and retain information under their applicable terms, privacy arrangements and service regions, which may involve processing outside Australia.
Analytics and location
Service Sheet uses a first-party browser identifier to distinguish a returning browser from a new browser during public submissions, without invasive fingerprinting. Public website analytics use a first-party anonymous identifier, page and device category, referral category and approximate network-derived country, region and city. Raw visitor IP addresses are not retained in Service Sheet website analytics records, and QR/operator workflow activity is excluded from website analytics.
Service Sheet does not collect optional one-time submission location and does not continuously track or independently verify an asset’s location.
Access, correction and complaints
You may ask for access to or correction of personal information, raise a privacy concern, or enquire about account deactivation or deletion. We may need to verify your identity and authority within the organisation before disclosing or changing account information. We will review privacy complaints and explain the outcome or available next steps.
Questions or support
Questions about privacy, access, correction, data retention or your Service Sheet account? Contact Service Sheet at support@servicesheet.com.au.