Product
Overview
The commercial operating system for construction. Capture a commercial event once, every downstream workflow stays connected.
See the whole product →
Contract models
Fixed, cost plus & open book
Claim a fixed sum, reimburse at actual cost, or bill fully open book. ClaimStack handles each, the right way.
See how →
Solutions
Overview
Built for every side of the contract. One commercial record the whole project team can trust, head contract to supplier.
See how it fits your role →
For subcontractors
Free to collaborate
Invited to a project? Submit claims and variations in a format that holds up, free forever.
See the plan →
Resources
Overview
Practical guides on claims, variations and contracts, plus how ClaimStack connects, who's behind it, and how we keep your commercial data safe.
Read the blog →
Get started
See it on your project
A 30-minute walkthrough on your numbers, where the margin usually leaks.
Book a demo →
Pricing
Your Privacy Matters

Privacy Policy

How we collect, use, and protect your information

Version: 2026-08-04Effective Date: 4 August 2026Last Updated: 4 August 2026

1. Introduction

ClaimStack Pty Ltd (ACN 688 993 535) ("ClaimStack", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our construction project financial management platform.

By using ClaimStack, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide when using our platform:

  • Account Information: Name, email address, phone number, company name, ABN, business address
  • Project Data: Project details, contract information, payment claims, variations, invoices, purchase orders, budgets, cashflow forecasts, and related documentation
  • Financial Information: Payment details, banking information, subscription billing (processed securely through Stripe)
  • Communications: Correspondence (RFIs, notices, site instructions), support requests, feedback, and communications with our team
  • Documents: Files, photos, PDFs, receipts, and other documents you upload to the platform
  • Voice Recordings: Audio recordings captured via site notes for AI-powered transcription and task extraction
  • Timesheets: Time entries, resource assignments, and labour records submitted by your team

2.2 Automatically Collected Information

  • Usage Data: Pages visited, features used, time spent on platform, click patterns
  • Device Information: IP address, browser type, operating system, device identifiers
  • Log Data: Access times, error logs, system activity
  • Cookies: Session cookies, preference cookies, analytics cookies (see Section 8)

3. How We Use Your Information

We use the collected information for:

  • Service Delivery: Providing, maintaining, and improving our construction financial management platform
  • AI-Powered Features: Processing documents, receipts, voice recordings, and project data using artificial intelligence to extract information, generate summaries, and automate workflows (see Section 3.1)
  • Communication: Sending notifications, updates, security alerts, correspondence, and support messages
  • Collaboration: Enabling sharing and collaboration between authorised users (builders, subcontractors, consultants, clients)
  • Analytics: Understanding usage patterns and improving user experience
  • Security: Detecting and preventing fraud, unauthorised access, and security threats
  • Legal Compliance: Meeting regulatory requirements and responding to legal requests
  • Business Operations: Processing subscription payments, managing accounts, providing customer support

3.1 AI and Automated Processing

ClaimStack uses artificial intelligence to enhance platform functionality. Your data may be processed by AI systems for:

  • Document Extraction: Automatically extracting invoice details, line items, and supplier information from uploaded PDFs
  • Receipt Scanning: Extracting supplier, date, and amount information from receipt photos
  • Voice Transcription: Converting site note audio recordings into text and extracting actionable tasks
  • Project Summaries: Generating AI-powered dashboard summaries and risk assessments
  • Program Matching: Matching construction program activities to budget items for cashflow forecasting

AI processing is performed by Google Cloud Vertex AI (see Section 4.2). All AI-generated outputs are presented for human review before any action is taken.

3.2 AI Training and Retention

We do not train AI models on your data, and we do not permit our AI provider to do so. Google's Service Specific Terms (clause 18, "Training Restriction") commit that Google will not use customer data to train or fine-tune any AI/ML model without our prior permission or instruction, which we do not give. We do not fine-tune, and we do not operate any model trained on customer content.

Retention during processing. We do not enable request/response logging, and we do not use grounding features that retain query data. Two limited retention mechanisms nonetheless apply at our AI provider, and we disclose them rather than claim zero retention:

  • Latency caching: inputs and outputs may be held in memory for up to 24 hours, isolated to our project, to speed up responses. This data is never written to disk and is never used for training.
  • Abuse monitoring: if Google's automated safety classifiers flag a request as suspicious, Google may retain that prompt for up to 90 days solely to investigate misuse of its acceptable use policy. This is triggered by a classifier, not applied to all traffic, and this data is never used for training.

Only the specific document, image, or audio file needed for a requested task is sent for AI processing. We do not transmit bulk project data.

4. Information Sharing and Disclosure

4.1 Within Your Organisation

Information is shared with authorised users within your company and with project stakeholders (subcontractors, consultants, clients) as configured by project administrators.

4.2 Service Providers

We share information with trusted third-party service providers who assist us in operating the platform:

  • Cloud Infrastructure: Google Cloud Platform — file storage, database hosting and application compute, in the Melbourne region (australia-southeast2)
  • AI Processing: Google Cloud Vertex AI (document extraction, voice transcription, summaries — see Sections 3.1 and 3.2)
  • Payment Processing: Stripe (subscription billing and payment processing) — United States
  • Email Delivery: Postmark (transactional emails, correspondence notifications, inbound invoice processing) — United States
  • Accounting Integration: Xero (optional accounting integration for syncing invoices and financial data) — New Zealand
  • Error Monitoring: Sentry (application performance, error tracking, and masked session replay, see Section 8.2) — United States
  • Product Analytics: PostHog (usage analytics and product improvement, see Section 8) — United States
  • Bot Protection: Google reCAPTCHA (login and registration security) — United States

All service providers are bound by data processing agreements and are required to protect your information in accordance with this policy and applicable laws.

4.3 Legal Requirements

We may disclose information if required by law, court order, or government request, or to:

  • Comply with legal obligations
  • Protect and defend our rights or property
  • Prevent or investigate fraud or security issues
  • Protect the safety of users or the public

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred. We will notify you before your information is transferred and becomes subject to a different privacy policy.

5. Data Storage and Security

Australian Data Hosting: Your documents, files, and database records are stored at rest in Australia, in Google Cloud's Melbourne region (australia-southeast2). Backups are held in the same region.

AI processing is a partial exception, and we would rather say so than overstate it. Requests to our AI provider are routed to Google's global endpoint for most features, which means the inference itself may be processed by Google outside Australia. Contract intelligence and document embeddings are pinned to Australian regions. In every case the data remains within Google Cloud under the contractual terms described in Section 3.2, is not used for training, and is not retained beyond the limited windows disclosed there. We are working to widen Australian-region processing as our provider makes more models available in those regions.

A note on jurisdiction. Google is a United States company. Storing data in Australia does not place it beyond the reach of US law, which can compel a US-headquartered provider to produce data it controls regardless of where that data is stored. No provider of this kind can honestly promise otherwise, and we do not.

Security Measures: We implement industry-standard security measures including:

  • TLS/SSL encryption for data in transit (HTTPS only)
  • AES-256 encryption at rest for all database records and stored files, managed by Google Cloud
  • bcrypt password hashing with salt
  • JWT-based authentication with secure session management
  • CSRF token protection on all state-changing operations
  • Rate limiting and account lockout protection
  • Row-level security (RLS) policies at database level
  • Role-based access controls (RBAC)
  • Automated backup and disaster recovery

For detailed security information, please refer to our Data Security Policy.

6. Your Rights and Choices

Under Australian Privacy Principles (APPs) and applicable laws, you have the right to:

  • Access: Request access to your personal information
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal information (subject to legal retention requirements)
  • Export: Download your data in a portable format
  • Opt-Out: Unsubscribe from marketing communications
  • Object: Object to processing of your personal information
  • Restrict: Request restriction of processing under certain circumstances

To exercise these rights, please contact us at privacy@claimstack.com.au

6.1 Limits on Deletion

Some records cannot be deleted on request. Once a payment claim, payment schedule, assessment, or invoice is submitted it becomes a permanent read-only record, and a copy sits in the account of the other party to that contract as their own business record. We also retain what we are required to retain by law. Where we cannot delete, we will tell you why.

6.2 Dealing With Us Anonymously

Australian Privacy Principle 2 gives you the option of dealing with an organisation anonymously or under a pseudonym where that is lawful and practicable. ClaimStack is a multi-party contract administration platform: payment claims, assessments, and notices only have legal and commercial meaning if the parties to them are identified. It is therefore not practicable to use the platform anonymously or pseudonymously. You can, of course, browse our public website without giving us any personal information.

7. Data Retention

We retain your information for as long as necessary to:

  • Provide our services and maintain your account
  • Comply with legal obligations (e.g., tax records, financial records)
  • Resolve disputes and enforce agreements
  • Meet industry-specific retention requirements for construction records

Construction Records: Given the nature of construction claims and legal requirements, we typically retain project data for a minimum of 7 years after project completion, in accordance with Australian business record-keeping requirements.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Essential Cookies: Required for platform functionality (JWT tokens for authentication, CSRF protection)
  • Preference Cookies: Remember your settings and preferences
  • Security Cookies: Detect and prevent fraudulent activity, rate limiting
  • Analytics Cookies: Understand how you use the platform so we can improve it (PostHog)

8.1 Product Analytics

We use PostHog to collect product analytics data to improve the Service. This includes:

  • Usage analytics: pages visited, which features are used, and navigation patterns
  • Interaction events: clicks on links and buttons we have specifically tagged for measurement
  • Performance metrics: page load times, Core Web Vitals, and error rates

Our analytics provider does not record your screen and does not receive keystrokes, form inputs, or page content. Analytics events carry only the type of action taken and non-identifying attributes such as your role and company type — never claim amounts, document contents, or company details.

PostHog data is processed in accordance with their privacy policy and our data processing agreement. Analytics data is used solely to improve the Service and is never sold to third parties or used for advertising.

8.2 Session Replay for Error Diagnosis

We use Sentry to diagnose faults. Sentry records a reconstruction of the page — layout, clicks, scrolling, and navigation — so we can see the sequence of events that led to an error. We capture every session in which an error occurs, plus a small random sample of ordinary sessions for reliability monitoring. All captured sessions have every piece of text masked and all images and media blocked before the recording leaves your browser.

This means your data is not visible to us in a replay. Claim and invoice amounts, document contents, contract details, names, and anything you type appear only as blanked-out placeholder blocks. We can see the shape of the page and what you interacted with, never the information on it.

8.3 Opting Out

You can opt out of product analytics at any time under Account → Preferences → Privacy. This setting is stored in the browser you set it in, so please repeat it on each browser or device you use. You can also control cookies through your browser settings. Note that disabling essential cookies will prevent you from using the platform.

Error monitoring and the masked session replay described in Section 8.2 continue regardless of this setting, as they are necessary to keep the platform working and to meet our security obligations. We do not use third-party advertising or marketing analytics cookies.

9. Third-Party Links and Services

Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.

10. Children's Privacy

ClaimStack is a business-to-business (B2B) platform intended for use by professionals in the construction industry. We do not knowingly collect information from individuals under 18 years of age. If you believe we have inadvertently collected such information, please contact us immediately.

11. International Data Transfers

Your project data is stored at rest in Australia. Some service providers process limited data outside Australia. Under Australian Privacy Principle 8 we are required to tell you where, so far as we are able:

  • United States: Stripe (billing), Postmark (email delivery), Sentry (error monitoring), PostHog (product analytics), Google reCAPTCHA (bot protection)
  • New Zealand: Xero, where you choose to enable the accounting integration
  • Not region-guaranteed: AI inference through Google Cloud Vertex AI's global endpoint, as described in Section 5. Google does not publish which region serves an individual request to that endpoint, so we cannot name a specific country for it.

When we transfer data outside Australia we rely on data processing agreements with each provider, contractual commitments restricting use of the data to providing the service to us, and the accountability requirements of APP 8. As noted in Section 5, contractual safeguards do not displace the operation of foreign law on a foreign provider.

12. Data Breach Notification

We are covered by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). If we suspect a data breach has occurred, we will:

  • contain it and begin an assessment immediately;
  • complete that assessment within 30 days, and usually far sooner;
  • where we conclude the breach is likely to result in serious harm, notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, telling you what happened, what information was involved, and what you should do about it; and
  • notify the affected company's nominated security contact directly where the breach involves that company's project data.

We do not wait for the end of the assessment period to tell you if we already know a breach is serious. Where we have agreed a shorter contractual notification period with a customer, that period applies to them.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending email notification to registered users
  • Displaying an in-app notice

Your continued use of ClaimStack after changes become effective constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

ClaimStack Pty Ltd, Privacy Officer

Email: privacy@claimstack.com.au

Support: support@claimstack.com.au

Website: www.claimstack.com.au

15. Privacy Complaints

If you believe we have breached the Australian Privacy Principles, you may file a complaint with us. We will:

  • Acknowledge your complaint within 7 days
  • Investigate and respond within 30 days
  • Provide reasons for our decision

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au

This Privacy Policy is governed by Australian law and the Australian Privacy Principles under the Privacy Act 1988 (Cth).