Legal
Privacy policy
Effective 3 September 2026 · replaces the version dated 12 July 2022
iPACT holds licences, work rights evidence, signatures and payment details for real people. This policy sets out what we collect, why, who sees it and what you can do about it. It is written to the Australian Privacy Principles in the Privacy Act 1988 (Cth).
1Who this policy covers
This policy applies to everyone whose personal information reaches iPACT. In practice that is three groups:
- Principal contractors and their office staff, who hold an iPACT account.
- Drivers and subcontractors whose records are held in a principal contractor's iPACT account.
- Visitors to our website.
Where a principal contractor uploads or enters information about a driver, that contractor decides what goes in and what it is used for. We hold and process it on their instructions, and this policy describes what we do with it. If you are a driver and you want a record changed or removed, ask your principal contractor first; you can also contact us and we will help.
2What we collect
We collect only what the service needs. Because iPACT exists to keep compliance records, some of that is documentation you would not hand to an ordinary software provider, so we set it out specifically rather than in general terms.
Account and contact information
Name, business name, email address, phone number, postal address, role and login credentials.
Driver licences
The licence holder's name, licence number, class, state of issue and expiry date, and an image of the card where one is uploaded. iPACT reads these details from the uploaded card.
Work rights evidence
Where a driver's right to work is conditional: visa subclass, conditions including any cap on hours, expiry dates, and the VEVO result confirming them. Where a bridging visa applies we also record the dates that determine how often the check is repeated.
Business and payment details
ABN, GST registration status, rates, and the bank account details used to pay a driver. Subscription payments are handled by a third-party payment processor; we do not store your card number.
Records created as work is done
- Time reports: start and finish times submitted by drivers.
- Vehicle inspections: photographs of the vehicle and a walk-around video.
- Incident reports: what happened, photographs taken at the scene, and the address where it happened.
- Toolbox talks, agreements and other documents, with the electronic signature applied to them.
- Customer commitments: the details of a delivery complaint and how it was resolved.
- Invoices, deductions and transactions.
Technical information
IP address, device and browser type, operating system, app version, pages viewed, and the date and time of each action. Every significant action in iPACT is recorded with who performed it, when, and the IP address it came from. That audit trail is the product: it is what makes a record defensible.
Location
Where a feature needs it, and only with the permission you give your device, we record the location attached to an inspection, incident or delivery record.
Sensitive information
We do not seek health information, racial or ethnic origin, political or religious beliefs, or criminal records. If a document you upload happens to contain something of that kind, we treat it with the same protections as everything else and use it only for the purpose you uploaded it.
4Why we collect it
To provide iPACT: to onboard drivers, verify licences and work rights, run vehicle inspections, record incidents and hazards, distribute toolbox talks, produce invoices and pay runs, and give a principal contractor the records they need when someone asks for them. Also to support and secure the service, to bill for it, and to meet our own legal obligations.
We do not use your information to advertise to you, and we do not sell it.
5Who we disclose it to
- Within your operation. A principal contractor sees the records of the drivers in their account. A team leader sees what their role allows. A driver sees only their own records. Records are separated at the row level, so no other operation using iPACT can see yours.
- Service providers who help us run iPACT. The cloud application platform the product is built and hosted on, a payment processor, an email and SMS messaging provider, error and analytics tooling, and a mapping provider. They act on our instructions, under contract, and may use the information only to provide their service to us.
- Where the law requires it, or where it is necessary to prevent a serious threat to someone's life, health or safety.
- A buyer, if the business is sold, on the same terms as this policy.
We do not give your information to anyone to use for their own purposes, and we never sell it.
6Information sent overseas
Your information is held in Australia and in the United States. Some of the service providers described above, or their support teams, are located in the United States. Where we disclose personal information to them we take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles, and we remain accountable for it.
If you would like to know the countries relevant to a particular part of the service, ask us at support@ipact.com.au and we will tell you.
7How we protect it
- Encryption. Information is encrypted in transit and encrypted at rest.
- Certification. APPSXDESIGN PTY LTD holds ISO/IEC 27001:2022 certification for information security management, covering the development, deployment, maintenance and support of iPACT. Certificate QCC/D821/0425, issued 3 April 2025.
- Separation. Row-level isolation keeps each operation's records apart from every other operation's.
- Access control. Permissions follow the org chart and are enforced per contract and row by row, not just hidden in the interface.
- Audit trail. Significant actions are recorded with the person, the time and the originating IP address.
No system can be guaranteed against every attack. What we can say is what we do, and the above is auditable rather than aspirational.
8If something goes wrong
We are covered by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If a data breach occurs that is likely to result in serious harm, we will assess it promptly and, where the scheme requires, notify both the affected individuals and the Office of the Australian Information Commissioner. Where the breach concerns records held in a principal contractor's account, we will notify that contractor so they can meet their own obligations.
9Artificial intelligence
iPACT includes an assistant, POSTRA, which answers questions from your own knowledge hub and cites the document each answer came from. It is grounded in your documents, not the open internet.
Your information is not used to train models for other customers or for anyone outside your own operation, and it is not sold or supplied to third parties for the training of their models.
10How long we keep it
Compliance records exist to be produced later, sometimes years later, so we keep them while your account is open and for as long as the relevant record-keeping obligations require. When an account is closed we delete or de-identify personal information that we no longer need, except where we must keep it to meet a legal obligation or to resolve a dispute. Backups are cycled out on a schedule.
11Getting your records out
You can export from iPACT at any time as PDF, CSV or Excel. The record is yours; we hold it, we do not own it.
12Access and correction
You may ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Email support@ipact.com.au. We will respond within a reasonable period, normally 30 days, and we do not charge for making a request. If we refuse access or a correction we will tell you why in writing and how to complain.
If your records sit inside a principal contractor's account, we will usually direct the request to them, because it is their account and their decision what it contains. We will help either way.
13Cookies
Our website uses cookies that are necessary for it to work, and analytics cookies that tell us how the site is used. You can block or delete cookies in your browser; the site will still work. The logged-in application uses cookies to keep you signed in.
14Complaints
Email support@ipact.com.au with the detail of your complaint. We will acknowledge it and give you a written response, normally within 30 days.
If you are not satisfied with our response, you can take it to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, GPO Box 5218, Sydney NSW 2001.
15Changes to this policy
We will update this page when the service or the law changes, and the effective date at the top will change with it. If a change materially affects how we handle your information we will tell account holders directly rather than rely on you noticing.
APPSXDESIGN PTY LTD (ABN 81 625 849 961), trading as iPACT.
PO Box 307, Wandong, Victoria 3758, Australia
support@ipact.com.au