Superseded version — archived for reference. This is Privacy Policy version 2.0, which applied from 1 August 2026 until it was superseded by version 2.1 on 8 August 2026. It is published here unchanged, so anyone can read the text that applied to them during that period. This is not the current policy — see the current Privacy Policy and the version history.
Privacy Policy
Version: 2.0 Effective from: 1 August 2026
1. About this policy
Urban Pulse Strategies Pty Ltd (ABN 82 650 700 226; ACN 650 700 226), trading as Urban Pulse ("Urban Pulse", "we", "us" or "our"), provides a software-as-a-service platform for the Australian construction industry. The platform provides document transmittal and electronic signing, site and planning intelligence, project management, a services marketplace, payments, referrals and related business tools.
This policy explains how we handle personal information in connection with the platform, our websites and our related services (together, the "Service"). It applies to everyone whose personal information we handle, including account holders, the people they invite, and people who contact us.
We are the entity responsible for the personal information described in this policy. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Contact us. For any privacy question, or to exercise your rights, contact our Privacy Officer:
- Email: privacy@urbanpulse.com.au
- Post: Privacy Officer, Urban Pulse Strategies Pty Ltd, PO Box 81, Aspley QLD 4034.
2. Information we collect
We collect the categories of personal information described below. Where you upload a document, any personal information within it is handled as document content rather than as a separate profile record.
2.1 Account and identity information
Your name, email address, username and hashed password; authentication factors where you use multi-factor authentication; and session and sign-in records. Where relevant to your use of the Service, we also collect your role, business name, ABN, ACN, licence numbers, business address and contact details.
We store a one-way hash of your password and never store it in plain text. We record successful and unsuccessful sign-in events, including the time, the outcome and a one-way hash of the identifier used.
2.2 Documents, envelopes and signing records
The documents you upload or generate — contracts, quotes, variations, dilapidation and inspection reports, photographs, drawings, project files and attachments — together with their metadata (filename, type, size, integrity hash, upload time, uploader, malware-scan result and storage location), and any personal information contained within them, such as counterparty names, addresses, signatures, contract values and project details.
When you prepare an envelope for signature, we collect each participant's name and email address, and their phone number where you provide it. For signers, we record the signature and initials fields assigned to them and the page and placement of each field, which we use to route, evidence and audit that envelope. When a document is signed, we record the signer's name and email address, the time of signing, signing-context metadata, a truncated network prefix and a one-way hash of the browser, bound to the signature and consent record.
2.3 Payments, subscriptions and referrals
Billing name and address, payment references and receipts, subscription plan and status, Stripe customer and subscription identifiers, and the records we need to reconcile invoices, refunds, disputes and tax obligations. Card details are tokenised in your browser by Stripe before they reach us; we do not receive or store full card numbers.
If you take part in our referral program, we collect your referral code and its link to your account, and — for referred sign-ups — a one-way hash of the referred email address and the identifiers needed to attribute the referral. Where you choose a cash payout, we collect the account name, BSB and account number, and either your ABN or a "Statement by a supplier" declaration, which we use to make and evidence the payment.
2.4 Project, planning, marketplace and collaboration content
The information you create in our project-management, town-planning, marketplace and property-intelligence tools, including project names and addresses, tasks, milestones, requests for information, variations, defects, claims, daily logs, comments and attachments; planning-site records, zoning and overlay context and due-diligence material; marketplace profiles, jobs, bids, messages, ratings and dispute records, including the names and email addresses of parties to a marketplace contract; and the messages, channel membership and attachments you exchange with your team, trades and clients in a project's messaging channels.
Where you invite a client to a project channel, we collect the email address you provide, which we use only to send the invitation and to grant that person access to that channel after they sign in and their email is matched to their verified account. Where you send a listing enquiry, we collect the listing, subject, message and a one-way hash of the network address for rate-limiting and abuse prevention. Free-text fields may contain personal information you choose to include.
2.5 Communications and support
The content of emails, messages, in-app chats, support tickets, feature requests and other communications you send to us or through the Service. If you send a listing enquiry, your message and account email address are provided to the person handling that listing so they can respond.
If you contact us through our website enquiry form, we collect the email address and message you provide, your name if you choose to give it, and a short label recording which page you started from. Submitting the form requires you to give consent, which is the basis on which we reply. We use these details to respond to and keep a record of your enquiry, and we do not add you to marketing on the basis of an enquiry unless you separately opt in.
If an email bounces, is reported as spam or is unsubscribed, we record the address and event so we can honour suppression and opt-out obligations.
2.6 Technical, usage and analytics information
We collect technical and usage information to operate, secure, measure and improve the Service, including your IP address, browser type, device type, operating system, the pages and features you use, the actions you take and related timing. For recipients viewing a document through a secure link, we collect a truncated network identifier and a one-way browser fingerprint. We collect error and diagnostic logs, which are scrubbed to remove credential-shaped values and known personal-information fields before they leave our infrastructure.
We measure how the Service is used through two channels. Our first-party analytics record which pages and features are used and basic engagement signals such as time on a page and scroll depth. This information is stored on our Australian infrastructure and is associated with your account and organisation. We also use PostHog, a third-party product-analytics provider, in a privacy-protective configuration: it runs without analytics cookies and without cross-session tracking, sends only a fixed set of allowlisted events, and carries no directly identifying information in the event payload. We do not use analytics information for advertising or to build advertising profiles. See Section 5 for who we share information with, and Section 10 for cookies.
Where a map is shown on a property or site-intelligence surface, the address or map area you are viewing is used to draw the map, and the map provider receives standard technical information from your browser (see Section 5).
2.7 AI-assisted features
When you use an AI-assisted feature, we process the prompts, documents, extracted text, and project or planning records needed to produce the requested draft or answer. AI output is draft assistance only; a person remains responsible for reviewing it before it is sent, lodged, signed or relied on.
Our cross-project assistant is powered by Anthropic's Claude API. It answers status questions across your projects, summarises what needs your attention, suggests questions drawn from your own records, and drafts client updates for you to review and send. When you use it, we send the relevant project and status records and your question to Anthropic to generate the response (see Section 5.6).
3. How we collect personal information
We collect personal information:
- Directly from you — when you create an account, complete onboarding, upload a document, send an envelope, use our planning, project or marketplace tools, make or receive a payment, submit an enquiry, or contact support.
- From the people you deal with — when another user nominates you as a recipient, collaborator, payer, contractor, consultant or project participant.
- From your device — through cookies, logs and browser interactions.
- From our service providers — such as Stripe, Google and our authentication provider, where they return information needed to deliver the Service.
Where we collect your personal information from someone other than you, we take reasonable steps to make you aware of this policy, including by linking to it from account and recipient surfaces.
4. How we use personal information
We use personal information where it is reasonably necessary for our functions and activities, where you have consented, where you would reasonably expect the use, or where the use is required or authorised by Australian law. Specifically, we use it to:
- Provide the Service — create and secure accounts, operate workspaces, send envelopes and capture signatures, store documents, run our planning, project and marketplace tools, provide support, and maintain transaction records.
- Process payments and referrals — verify payment methods, settle funds through Stripe, reconcile payments and refunds, and administer referral rewards.
- Secure the Service and prevent fraud — authenticate users, detect and investigate suspicious activity, enforce our terms, and protect users and the platform.
- Measure and improve the Service — analyse how features are used, diagnose and fix faults, and develop improvements.
- Communicate with you — send service notifications, security alerts, document-status updates, receipts, support replies and, where you have opted in, marketing.
- Comply with the law — meet our tax, consumer-protection, privacy and data-breach obligations, and respond to lawful requests from courts, regulators and law-enforcement agencies.
5. Who we share personal information with
We share personal information only with the recipients described below, and only to the extent necessary to provide the Service. Each overseas recipient is identified by country. For overseas recipients, we take reasonable steps to ensure they handle personal information consistently with the Australian Privacy Principles, through data-processing agreements, contractual safeguards and vendor security commitments, and we maintain an internal cross-border disclosure register.
5.1 Stripe, Inc. (United States) — payments
We use Stripe to process card payments, subscription billing and disputes. Stripe receives payment and billing information, including cardholder name, billing address, email address, a payment-method token, amount, invoice references and subscription identifiers. Your full card number is tokenised by Stripe in your browser and does not reach us.
5.2 Resend (United States) and Amazon SES, Tokyo (Japan) — email delivery
We use Resend to deliver transactional email, including sign-in confirmations, invoices, document notifications, support updates and recipient notifications. Resend receives the recipient's email address, the message and delivery metadata. Resend's control plane operates in the United States, and outbound delivery and bounce processing are routed through Amazon SES in Tokyo, Japan.
5.3 Amazon Web Services (Australia) and Neon — hosting, storage and database
We host the Service on Amazon Web Services in the Sydney region (ap-southeast-2) for compute, file storage and secrets management, and we use Neon as our managed PostgreSQL database, configured in the Sydney region. Account data, documents, audit records and analytics reside on this Australian infrastructure. Your electronically signed documents are prepared and completed within Urban Pulse's own signing ceremony and stored on this infrastructure; we do not send them to a third-party e-signature provider.
5.4 Better Auth (via Neon Auth) and Google LLC (United States) — authentication
We use Better Auth, hosted via Neon Auth, to manage account credentials and sessions. When you choose "Continue with Google", your browser is directed to Google to approve the sign-in and returned to us with a signed token containing your email address, whether it is verified, and basic profile information such as your name, which we use to authenticate you and create or match your account.
5.5 Google LLC (United States) — maps
Where we display a map on a property or site-intelligence surface, it is loaded directly from Google in your browser. Google receives the map location and standard technical information, including IP address, browser type and device type, and may set or read its own cookies within the embedded map.
5.6 Anthropic, PBC (United States) — AI assistance
We use Anthropic's Claude API to power our cross-project assistant. When you use it, Anthropic receives your project and status records and the text of your question and the draft it produces — including project names (often a property address), task, milestone, request-for-information and variation names, statuses and dates, and, where relevant, document status and party names from your records. It does not receive your uploaded document contents, passwords or one-time codes. Anthropic processes this information under a Zero Data Retention agreement with us and does not retain it after the response is generated.
5.7 PostHog, Inc. (United States) — product analytics
We use PostHog to measure how the Service is used. PostHog receives the allowlisted analytics events described in Section 2.6 — page and feature usage, campaign and source parameters, and coarse technical information. Your IP address is received at the point of collection and discarded after coarse location is derived; we do not enable analytics cookies, cross-session tracking, session recording or advertising features.
5.8 Intercom, Inc. (United States) — support chat
We use Intercom to provide in-product support chat for signed-in customers. We verify your identity to Intercom with a short-lived signed token created on our servers. Intercom receives your email address, display name, account and organisation identifiers and role, the messages you send, and standard technical information such as IP address and timestamps. When you open support, we also send a coarse, allowlisted page label for the surface you opened it from; we do not send project or property identifiers.
5.9 Other recipients
- The people you deal with. When you send a document, enquiry, project item, marketplace job or message through the Service, the recipient you nominate receives the information needed to view, respond, sign, quote, pay or collaborate.
- Professional advisers. Our lawyers, accountants, auditors and insurers may receive information where reasonably necessary and under duties of confidentiality.
- Regulators and law enforcement. We may disclose information where required or authorised by Australian law.
- A successor. If our business is sold or restructured, personal information may transfer to the acquirer under equivalent privacy commitments.
We do not sell personal information, and we do not disclose it for third-party advertising.
6. Storage and security
We store customer personal information in Australia: our database (Neon), file storage (Amazon S3), compute (Amazon ECS) and secrets (AWS Secrets Manager) are all in the Sydney region (ap-southeast-2). Personal information leaves Australia only through the overseas recipients identified in Section 5.
We take reasonable steps to protect personal information from loss, misuse and unauthorised access, modification or disclosure, including:
- Encryption — TLS 1.2 or higher in transit, and encryption at rest for file storage and the managed database.
- Access control — role-based access, least-privilege cloud roles, and multi-factor authentication on our staff cloud and code accounts.
- Auditing — durable, append-only logging of state-changing actions on envelopes, documents, payments and key records.
- Secret management — credentials and keys held in AWS Secrets Manager under least-privilege controls.
- Engineering controls — runtime scrubbing of credential-shaped values, automated checks against committing secrets, tenant-isolation controls and bounded payloads.
- Assurance — a defined incident-response process, independent security reviews and tracked remediation.
If we become aware of an eligible data breach under Part IIIC of the Privacy Act, we will notify affected individuals and the Office of the Australian Information Commissioner as required.
We take reasonable steps to keep personal information accurate, up to date and complete for the purpose for which it is held. Please tell us if your details change.
7. How long we keep information
We keep personal information only for as long as we need it for the purposes in this policy, or for longer where the law requires. The periods below apply.
| Category | Retention period |
|---|---|
| Transactional and financial records — envelopes, signatures, payments, referral payouts and invoices | 7 years after the transaction completes, in line with Australian tax and consumer-protection record-keeping requirements. |
| Uploaded documents | For the life of the associated project or envelope, plus 7 years where the document forms part of a regulated transaction record. |
| Audit log of state-changing actions | 7 years from the date of the action. |
| Account profile and contact details | Purged within approximately 90 days of account closure, allowing for recovery and reconciliation; details embedded in transactional records follow the 7-year period above. |
| Web session and request logs | 90 days, rolling. |
| Sign-in and sign-up events | Held in the security audit log and retained for 7 years. |
| Recipient view links | 14 days by default; the sender may set this between 1 hour and 30 days per envelope. |
| Analytics information | 24 months, de-identified where practicable. |
| AI assistant questions and drafts | Up to 12 months, and deleted sooner when the related project is deleted. |
| Enquiries, referral records, and marketing consent/opt-out records | For as long as needed to handle the matter and administer the program, plus a reasonable period to keep a record and evidence opt-outs, then deleted or de-identified. |
| Conveyancer matters and drafted summaries | For the life of the matter; deleted on request to the extent we are not required by law to retain them. |
Where you ask us to delete your personal information (Section 8), we do so except where we are required by law to keep it.
8. Your rights
You have the right to:
- Access the personal information we hold about you.
- Correct information you believe is inaccurate, out of date, incomplete or misleading.
- Delete your personal information, which we will do except where we are required by law to retain it.
- Port the personal information you have provided, in a structured, commonly used, machine-readable format where technically practicable.
- Object to direct marketing (see Section 9).
- Complain about how we have handled your personal information (see Section 12).
To exercise any of these rights, email privacy@urbanpulse.com.au. We will respond within a reasonable period and, for access and correction requests, no later than 30 days. We may need to verify your identity before we act.
9. Marketing
We send marketing only where you have expressly opted in through a clearly labelled consent. Every marketing email identifies Urban Pulse Strategies Pty Ltd as the sender, includes our ABN and Australian postal address, and includes a working unsubscribe link; every marketing SMS identifies us as the sender and includes an opt-out instruction (such as "Reply STOP to opt out"). We action unsubscribe and opt-out requests within five business days, and we keep consent and opt-out records to evidence our compliance with the Spam Act 2003 (Cth).
You can manage your preferences at any time by emailing privacy@urbanpulse.com.au. Service messages — such as sign-in alerts, document notifications, receipts and security notices — are not marketing and continue while your account is active.
10. Cookies and similar technologies
We use cookies and similar technologies for:
- Strictly necessary functions — keeping you signed in, remembering security preferences and protecting against attacks.
- Analytics — our analytics run without analytics cookies, using in-memory state rather than cookies or local storage.
- Embedded maps — where a Google map is displayed, Google may set or read its own cookies within the map frame; those cookies are controlled by Google.
Your browser lets you inspect and clear cookies. Clearing strictly necessary cookies will sign you out.
11. Children
The Service is intended for people aged 18 and over and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe we have, email privacy@urbanpulse.com.au and we will delete it.
12. Complaints
If you believe we have mishandled your personal information, please contact us first at privacy@urbanpulse.com.au. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days; if it will take longer, we will explain why and give you a revised timeframe.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au · 1300 363 992 · GPO Box 5288, Sydney NSW 2001.
13. Changes to this policy
We update this policy from time to time. When we make a change, we update the version and effective date below. For material changes that affect what we collect, who we share it with, or your rights, we will give you at least 14 days' notice by email or in-app notice before the change takes effect. The current policy applies from its effective date.
Version: 2.0 · Effective from: 1 August 2026 Issued by Urban Pulse Strategies Pty Ltd (ABN 82 650 700 226). Questions: privacy@urbanpulse.com.au.