This Privacy Policy explains how SpendShift Enterprises Pty Ltd ACN 689 089 610 (“SpendShift”, “we”, “us” or “our”) collects, holds, uses, discloses and protects personal information in connection with www.spendshift.com.au, the SpendShift audit, personalised savings reports, payment processing, report delivery and related services.
We are committed to handling personal information responsibly and transparently. Where the Privacy Act 1988 (Cth) (“Privacy Act”) and the Australian Privacy Principles apply to us, we will handle personal information in accordance with those requirements. We may also choose to follow comparable privacy practices where the Privacy Act does not strictly apply.
By using the website or providing personal information to us, you acknowledge that your information will be handled as described in this Privacy Policy. Where consent is required by law, we will seek it separately.
We may update this Privacy Policy from time to time by publishing a revised version on the website. The date at the end of the policy shows when it was last updated.
This Privacy Policy applies to visitors to the website, users who complete the free audit, customers who purchase a report, and anyone who contacts us.
SpendShift is intended for people aged 18 years or older. If you believe a person under 18 has provided personal information to us, contact us so we can assess and, where appropriate, delete it.
Depending on how you use SpendShift, we may collect:
SpendShift does not receive or store your any payment card number or security code. Those details are handled by Stripe and, where used, Apple Pay and other relevant financial institutions.
We may collect personal information:
We may collect, use and disclose personal information to:
We do not currently use customer email addresses for promotional marketing unless the person separately opts in or we otherwise have a lawful basis to do so. Transactional emails, such as payment confirmations, report links, service notices and responses to requests, are not promotional marketing.
SpendShift uses Anthropic’s Claude Application Programming Interface (“API”) to assist with generating personalised reports. The audit answers and related instructions necessary to generate the report are transmitted to Anthropic for processing.
The report is generated using automated technology and may contain errors, omissions, generalisations or estimates. The use of AI does not preclude you from being required to review the report critically and verify information before acting on it. You must do your own due diligence before seeking to rely on SpendShift reports or products.
We do not intentionally use customer audit answers to train our own machine-learning model. Anthropic may process and temporarily retain API inputs and outputs in accordance with its commercial terms, privacy documentation and security practices.
We may disclose or make personal information available to service providers that help us operate SpendShift, including:
These providers may collect information directly from you or receive it from us. Their handling of information is also governed by their own terms and privacy policies.
We may also be required to disclose information to regulators, courts, law-enforcement agencies and government bodies where compelled to do so by law.
Some of our service providers operate or use infrastructure outside Australia. As a result, personal information may be processed, accessed or stored in countries other than Australia, including the United States as well as other locations in which Anthropic, Stripe, Vercel, Supabase, Resend, Google or their subprocessors operate.
The exact locations may change over time and may depend on provider infrastructure and the selected hosting region. Where required by law, we will take reasonable steps in the circumstances to protect sensitive information before making disclosures to an overseas recipient.
Generated reports, audit answers, associated email addresses and relevant transaction identifiers are stored in Supabase. Each report is generated once and may be accessed again through its saved report URL.
Our current retention practice is to retain these records indefinitely unless they are manually deleted, deletion is requested and accepted, or deletion is otherwise required by law. We may also retain records for legal, security, fraud-prevention, accounting, taxation, insurance, dispute-resolution and business-continuity purposes.
Because indefinite retention creates additional privacy and security risk, this retention policy should be reviewed periodically. Where the Privacy Act requires us to destroy or de-identify personal information that is no longer needed for a permitted purpose, we will take reasonable steps to do so.
A saved report URL may allow access to the report without a user account or password. You are responsible for keeping that URL confidential and for not sharing it with anyone you do not want to access the report.
If you believe a report link has been disclosed, accessed without permission or otherwise compromised, contact us promptly. We may disable, replace or delete a report link where reasonably necessary, but we cannot guarantee that a report accessed or copied by another person can be retrieved or erased.
We take reasonable administrative, technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, service-provider security features, encryption in transit, environment separation, logging, monitoring and restricted administrative access.
No website, database, transmission or storage system is completely secure. We cannot guarantee absolute security. You should use a secure device and network and protect any email account or report URL used to access your report.
We and our service providers may use cookies, pixels, local storage, server logs and similar technologies. Google Analytics may use first-party analytics cookies. Stripe may use cookies and similar technologies when you visit Stripe Checkout for checkout functionality, security and fraud prevention. Vercel and other infrastructure providers may use essential technologies for security and operation.
More information is available in our Cookie Policy.
You may contact us to request access to personal information we hold about you, correction of inaccurate information, or deletion of a report and associated personal information.
We may need to verify your identity before acting on a request. We may refuse or limit a request where permitted or required by law, including where information must be retained for legal, accounting, security, fraud-prevention or dispute-resolution purposes. If we refuse a request, we will explain the reason where required.
Because reports may be linked to an email address and saved report URL, please provide the purchasing email address and report URL when making a request. Do not send us payment-card details.
If you have a complaint about how we handle personal information, contact us using the details below. Please include enough information for us to understand and investigate the issue. We will acknowledge receipt of your complaint within 5 business days and provide a response within a reasonable period thereafter.
If you are not satisfied with our response and the Privacy Act applies, you may escalate your complaint to the Office of the Australian Information Commissioner.
The website and reports may contain links to third-party websites or services. We are not responsible for the privacy, security, content or practices of those third parties. You should review their privacy policies before providing information or using their services.
SpendShift Enterprises Pty Ltd
ACN 689 089 610
Address: 2 Blackwoods Road, Nobbys Creek NSW, Australia
Email: info@spendshift.com.au
Website: www.spendshift.com.au
Last updated: 9 August 2026