Australian Privacy Act 1988 compliant

Privacy Policy

Effective: 26 August 2026 Last updated: 28 August 2026 ABN 44 770 175 476

Plain English summary: ClearTrace AU collects only the personal information needed to find and remove your data from broker websites. We don't sell your data. We don't share it with advertisers. You can access, correct, or delete your information at any time.

01

About this policy

ClearTrace AU is a data removal and privacy monitoring service operated by ClearTrace AU as a sole trader (ABN 44 770 175 476), based in New South Wales, Australia.

This Privacy Policy explains how we collect, use, hold, and disclose personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using our website or subscribing to our service, you agree to the collection and use of information as described in this policy.

02

What personal information we collect

We collect the following categories of personal information:

Account information

  • Full name
  • Email address
  • State or territory of residence
  • Subscription tier and payment status

Service delivery information

  • Information you provide to help us locate your records on data broker websites (e.g. aliases, previous addresses, phone numbers)
  • Records of removal requests made on your behalf, including broker name, outcome, and timestamp
  • Monitoring data — where your information was found and its status

Technical information

  • Browser type and device type (collected anonymously via server logs)
  • Pages visited on our website
  • Referring URL

We do not collect sensitive information such as health, financial account, or biometric data.

03

How we collect your information

We collect personal information:

  • Directly from you — when you sign up, use our free exposure scanner, or contact us
  • Automatically — through server logs and basic analytics when you visit our website
  • From data broker websites — as part of our service, we search for and retrieve records about you from third-party data aggregator sites in order to request their removal. This information is used solely to perform that removal and is not retained beyond what is needed for reporting and audit purposes.

We will only collect personal information by lawful and fair means, and only information that is reasonably necessary to provide our service.

04

How we use your information

We use your personal information to:

  • Deliver the ClearTrace AU data removal and monitoring service
  • Generate your personalised exposure reports
  • Communicate with you about your account, removals, and service updates
  • Process subscription payments (via our payment processor)
  • Maintain an audit log of removal actions taken on your behalf
  • Improve our service and identify new data brokers to cover
  • Comply with legal obligations

We will not use your information for direct marketing to third parties, profiling for advertising, or any purpose that is inconsistent with why it was collected.

05

Disclosure of your information

We do not sell, rent, or trade your personal information. We may share it only in the following circumstances:

  • Payment processors — to process subscription payments. We use a third-party payment provider (e.g. Stripe) who is bound by their own privacy policy and PCI-DSS obligations. We do not store your card details.
  • Data broker websites — we submit opt-out requests on your behalf. This necessarily involves sharing your name and contact details with those websites for the purpose of removal.
  • Operational notifications — when you sign up, an automated notification containing your name, email address, plan and payment amount is delivered to our operator chat on Telegram so that a new signup is never missed. These messages go to a private chat that only we can read. Telegram is bound by its own privacy policy.
  • Search providers — to find where your information is published, we use a third-party search API (Searlo) that queries publicly accessible sources on our behalf. Your name is sent to that provider, along with your phone number where a search uses it, and your email address where a search uses it. This happens each time we run a scan for you, not only when you first sign up. We send the search terms only — we do not send your address, date of birth, payment details or report history — and the provider returns publicly available search results. It is bound by its own privacy policy. Without this we cannot tell you where you appear, so it is not optional for an active subscription.
  • Breach-checking service — your email address is sent to Have I Been Pwned, a third-party breach notification service, so we can tell you which known data breaches it has appeared in. This runs both when you supply an email address with a free scan and each time we scan for you as a subscriber. We send the address only; we receive back a list of breaches and show it to you in your browser. Have I Been Pwned is bound by its own privacy policy. On a free scan this check is optional — leave the email field blank and it does not run. For a subscription it runs on the address on your account. The separate password check on the same page never transmits your password: it is hashed in your browser and only the first five characters of that hash are sent, which cannot identify the password or you.
  • Legal requirements — if required by law, court order, or a regulatory authority (such as the Office of the Australian Information Commissioner).
  • Business succession — if the business is sold or transferred, your information may be transferred to the successor, who will be bound by this policy.
06

Overseas disclosure

Some data broker websites we interact with on your behalf are operated by companies based overseas, including in the United States. Submitting opt-out requests to these sites involves disclosing your information to those overseas operators.

By using our service, you consent to this disclosure for the specific and limited purpose of requesting removal of your information from those sites.

Our payment processor (Stripe) stores payment data on servers located in the United States. Stripe is certified under applicable data protection frameworks.

Our database is hosted in the Tokyo region, so your client record — including your name, contact details, scan history and findings — is stored on servers located in Japan. There is currently no Australian region available from our database provider. Access remains restricted to us, and the data is not disclosed to anyone in Japan beyond the hosting provider storing it.

Our operator notification service (Telegram) processes and stores messages on servers outside Australia. These messages contain limited personal information — your name, email address and plan — as described in section 5.

Our search provider (Searlo) processes searches outside Australia. Its published privacy policy states that service data is stored in the European Union, on servers hosted in France, and that its operational support is provided from Bangladesh. The provider does not publish where it is incorporated. Your name, and your phone number or email address where a search uses them, are sent to it each time we scan for you. See section 5.

Our breach-checking provider (Have I Been Pwned) serves its API from infrastructure outside Australia, so your email address may be processed on overseas servers when that check runs — both on a free scan and on the scans we run for you as a subscriber. The address is sent for the single purpose of the breach lookup and is not retained by us. See section 5.

Aside from the disclosures and storage arrangements described above, we do not transfer your personal information outside Australia.

07

How long we keep your information

  • Active subscribers — we retain your personal information for as long as your subscription is active, and for as long as we are providing monitoring or removal services to you.
  • After cancellation — we keep your information for 90 days after your subscription ends, then delete it permanently. The 90-day window runs from the date your subscription ends, not from any later administrative step, so it does not depend on how quickly we process the closure. It exists so we can answer questions about work already completed, and so you can reactivate without starting again. During that window your record is closed and withdrawn from active service — we stop scanning, stop sending removal requests, and stop producing reports for you. Deletion is carried out by a person rather than automatically, so it happens promptly after the 90 days rather than at the exact moment they elapse. You can ask us to delete your information sooner, and we will.
  • What deletion covers — permanent deletion removes your name and contact details, any information you gave us to help locate your records, your scan history and findings, the reports we generated for you, and our records of the removal requests we sent on your behalf. Where copies exist in our email or notification systems, those are removed as part of the same process. Deletion is not reversible.
  • Financial records — Australian tax law requires records of business transactions to be kept for five years. Invoices and payment records are retained for that period regardless of the above, limited to what taxation and accounting obligations require. Our payment processor retains its own records under its own policy.
  • Free scan users — when you run a free scan, the name you enter is sent to a third-party search API which queries publicly accessible sources on our behalf. If you also supply a phone number, that number is sent to the same search API to check the sources indexed by number rather than by name. If you also supply an email address, it is sent to Have I Been Pwned for the breach check described in section 5. Results — both the broker scan and the breach check — are returned to your browser in real time and are not stored in our database. We record anonymous counts only: how many sources were checked, how many returned a result, whether an email or phone number was supplied, and which site referred you. Those counts contain no name, email address, search query or result content, and nothing in them can be linked back to you or to any individual scan. If you ask us to email your results, that email — containing your name and email address — is delivered to our business inbox and retained for up to 90 days so we can respond to you. The results email we send back to you also lists the names and dates of any breaches your address appeared in, so that message carries part of your breach history as well as your contact details — worth knowing before you forward it or leave it sitting in an inbox. We do not keep a copy of those breach results. We do not use it to send you marketing, and we do not add you to any list. You can ask us to delete it sooner at any time.
  • Deletion on request — you can ask us to delete your information at any time, including during the 90-day window, and we will do so within 30 days, subject only to the financial records described above.
08

Security

We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include:

  • Client data stored in a hosted libSQL database (Turso), with access restricted to the operator
  • Database credentials held in environment variables, never committed to the code repository
  • Logs and reports excluded from version control and public repositories
  • HTTPS enforced on all web pages
  • Payment processing handled entirely by PCI-DSS compliant provider — we do not handle card data directly

No method of data transmission or storage is 100% secure. If you believe your information has been compromised, please contact us immediately at hello@cleartrace.au.

09

Your rights

Under the Australian Privacy Principles, you have the right to:

  • Access — request a copy of the personal information we hold about you
  • Correction — ask us to correct information that is inaccurate, out of date, or incomplete
  • Deletion — request deletion of your account and personal information (subject to retention obligations above)
  • Complaint — lodge a complaint if you believe we have mishandled your information

To exercise any of these rights, contact us at hello@cleartrace.au. We will respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10

Cookies and analytics

Our website uses no third-party analytics platforms (such as Google Analytics) at this time. Basic server logs may record your IP address and browser type for security and diagnostic purposes. These logs are not used to track individual users across sessions.

We do not use advertising cookies or tracking pixels.

If we introduce analytics or cookies in the future, this policy will be updated and you will be notified.

11

Children

Our service is intended for individuals aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a minor, please contact us and we will delete it promptly.

12

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify active subscribers by email

Continued use of the service after changes are notified constitutes acceptance of the updated policy.

13

Contact us

For any privacy-related queries, access requests, or complaints, please contact:

ClearTrace AU

Operated by ClearTrace AU (Sole Trader)

ABN 44 770 175 476

New South Wales, Australia

Email: hello@cleartrace.au

We aim to respond to all privacy enquiries within 30 days. For complaints that cannot be resolved directly, you may contact the OAIC at oaic.gov.au or on 1300 363 992.