Privacy Policy
Last updated 10 October 2026
TradieBridge is a backup of the records a trade business keeps in the systems it connects, such as Simpro, Xero, Verizon Connect, Deputy, The Fleet Office, Dialpad and Moveware, and a way for that business to connect its own AI assistant to the copy. It is made by Oli Nelson in Australia. In this policy, “we”, “us” and “our” mean Oli Nelson, and “the service” means TradieBridge, including the app at app.tradiebridge.com and this website.
We handle personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles. This policy explains what we collect, why, where it goes, and how you can reach us.
Who the information is about
- Account holders and staff of a trade business that uses the service.
- Clients, contacts, staff and suppliers of that business, whose details sit in the documents the business copies.
- Visitors to this website.
What we collect
- Account details: your name, email address and role in the business.
- Source documents: the records the business’s connections can read, such as jobs, quotes, invoices, timesheets, customers and sites; payroll records, which can include tax file numbers, bank accounts and birth dates; vehicle locations, trips and drivers; phone calls, with who called whom, call recording and voicemail links, call transcripts, contacts and phone numbers; and removal jobs, with the customer’s addresses, an inventory of their goods and the goods they keep in storage. We store those documents as each system sent them.
- Connection details: the Simpro host and API key, the Xero, Deputy and Moveware consents, the Verizon Connect and The Fleet Office API credentials, and the Dialpad API key the business gives us. These are encrypted at rest.
- Feedback: an idea or a problem your assistant sends us with your approval. We store it against the business and the person who sent it.
- Technical data: IP address, browser and device details, sign-in times, and error reports.
We do not collect payment card numbers. Stripe handles cards. We do not use cookies or trackers for advertising. The app uses a session cookie so you stay signed in. This website sets two DataFast analytics cookies, and the app reads them. The visitor cookie, datafast_visitor_id, holds a random ID for 365 days. The session cookie, datafast_session_id, lasts 30 minutes.
Why we collect it
- To copy the business’s documents from the systems it connects into a backup the business owns.
- To keep that copy current, let the business browse it, and export it.
- To let the business connect its own AI assistant to that copy.
- To read the feedback a business sends us, and use it to improve the service.
- To run accounts, billing, and sign-in.
- To keep the service secure, fix faults and send service notices.
- To meet legal duties, such as tax and record-keeping rules.
We do not sell personal information. We do not use it for advertising.
Assistants
A business can mint a token and connect its own AI assistant to the copy. When it does, that assistant reads the documents the business already holds. We do not send those documents to an AI provider of our own. The business is responsible for the assistant it connects.
An assistant can also send us an idea or a problem. It shows the text to the person using it, and sends it only when that person agrees. We store it and email it to our staff. Do not put a password, API key or token in it.
Logins for systems without an official integration
Some systems a business uses offer no official integration. If a business asks us to, and we switch it on, TradieBridge signs in to such a system with a login the business gives us and reads the business’s records there. The business accepts the risks of that access when it connects. For that login, we:
- Encrypt it in transit, and at rest in our database with a key we keep outside that database.
- Use it only to sign in and read the records the business connected. TradieBridge changes nothing in that system.
- Never sell it or show it. No page, export, API or assistant tool shows it, to the business or to our staff. Our staff reach it only where strictly necessary to resolve a support request the business raised.
- Share it with nobody except the trusted infrastructure providers that help us connect to your systems (see below).
- Delete it when the business removes the connection or closes its account: from our database within 30 days, and from our backups as they expire, within 90 days.
Use a unique password for that login. Where the system offers it, give TradieBridge a login of its own with read-only access rather than a person’s login. A login that asks for a second step, such as a code or an app, cannot be connected. If you believe the login is compromised, remove the connection, change the password, and email privacy@tradiebridge.com.
Who we share it with
We share personal information only with providers that help us run the service:
- Hosting and storage: DigitalOcean, for the app, the database and file storage. Cloudflare, for this website, tradiebridge.com.
- Email delivery: MailPace, for sign-in codes, export links, and the feedback emails to our staff.
- Error monitoring: Sentry, for crash and error reports.
- Payments: Stripe, for subscriptions.
- Analytics: DataFast, for visits to tradiebridge.com, and for sign-up and subscription steps. It links these to a random visitor ID, never a name or email address. It also reads subscription amounts from Stripe, to show which visits led to a paid subscription.
- Simpro: we call the Simpro API with the key the business gives us, to read the documents the business asked us to copy.
- Xero: we call the Xero API under the read-only consent the business gives, to read the documents the business asked us to copy.
- Verizon Connect: we call the Verizon Connect API with the credentials the business gives us, to read the documents the business asked us to copy.
- Deputy: we call the Deputy API under the consent the business gives, to read the documents the business asked us to copy.
- The Fleet Office: we call The Fleet Office API with the API keys the business gives us, to read the documents the business asked us to copy.
- Dialpad: we call the Dialpad API with the API key the business gives us, to read the documents the business asked us to copy.
- Moveware (MoveConnect): we call the Moveware API under the consent the business gives through MoveConnect’s sign-in, to read the documents the business asked us to copy.
- Connection infrastructure: trusted infrastructure providers that help us connect to your systems. Where they handle a login the business gives us, they use it only to make that connection.
Some of these providers store data outside Australia, including in the United States. We choose providers that commit to protecting personal information to a standard comparable to Australian law.
We also disclose information when the law requires it, or to protect the rights, property or safety of people.
How long we keep it
We keep the copy for as long as the business keeps its account. When a business closes its account, or removes a connection, we delete that connection’s copy. Backups of our own database expire on their own cycle. See our data deletion page for how to request deletion.
Security
Data is encrypted in transit. API keys are encrypted at rest. Access to production systems is limited to the people who operate the service. No system is perfectly secure, and we will tell affected people and the regulator about a data breach where the law requires it.
Your rights
You can ask us for a copy of the personal information we hold about you, and ask us to correct it. If you are a client or contact of a business that uses the service, you can also ask that business directly, since it controls those records. We respond within 30 days.
Contact
Email privacy@tradiebridge.com. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
We update this policy when the service changes. The date at the top shows the latest version.