← Back to home

Privacy Policy

Last updated: September 26, 2026

1. Overview

This Privacy Policy explains how Bings Intuitive Tech ("we", "us", "our") collects, uses, discloses and protects personal information in connection with the BINGS software suite — Run Book, Drill Calc, Stock, People, Safety and Assets (together, the "Service").

This Policy covers personal information handled through the Service, including information about Authorised Users that a Customer's Company Admin adds, and information we collect directly (such as account sign-up and support details). It should be read alongside the BINGS Terms of Service, which governs use of the Service more broadly — where the two overlap (for example, on Customer Data), the Terms of Service sets out the contractual position and this Policy sets out the privacy-law position.

Capitalised terms not defined in this Policy — such as Customer, Authorised User, Customer Data, Service and Subscription — have the meanings given to them in the Terms of Service.

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. What Personal Information We Collect

CategoryExamples
Account & contact detailsName, email, phone, job role, employer, login credentials
Business & billing detailsCompany name, ABN, billing email, business address and phone — entered at sign-up or in the Company section of the Service
Personnel data (People module)Employee/contractor names, contact details, roster and shift patterns, payroll exception data — entered by a Customer's Company Admin or Supervisor
Operational dataRun sheets, hole records, survey data, stock levels, safety records — which may include the names of personnel who performed or logged an activity
Payment detailsBilling name, address and payment method — card details are entered directly on Stripe's secure checkout page; we never see or store card numbers
Technical & device dataIP address, device/browser type, log-in timestamps, app version, crash and diagnostic logs
Support communicationsAnything you tell us when contacting support or providing feedback

Most of this information is provided by Customer's Company Admins and Supervisors on behalf of their organisation, rather than directly by the individuals it describes — see Section 3.

3. How We Collect Personal Information

We collect personal information: (a) directly, when an individual creates an account, signs in, or contacts support; (b) from a Customer's Company Admin or Supervisor, who enters or uploads information about their organisation's personnel and operations (most personnel data reaches us this way, not from the individual directly); and (c) automatically through the Service, such as log-in timestamps and device information generated as the Service is used.

Where a Customer provides us with personal information about its own personnel, Customer is responsible for telling those individuals that their information will be handled through the Service and for having any consents in place that it needs under its own obligations as an employer. We are not in a position to collect that notice directly from people we have no relationship with.

4. How We Use Personal Information

We use personal information to: provide, maintain and support the Service (including the Run Book, Drill Calc, Stock, People, Safety and Assets modules); authenticate logins and enforce the session and licensing rules described in the Terms of Service; process payments through Stripe and manage billing; respond to support requests; maintain the security and integrity of the Service; and meet our legal obligations.

As set out in the Terms of Service, we do not use Customer Data to train externally-facing AI models, and we do not sell or rent personal information to third parties for their own marketing. We do not use personal information — including in de-identified or aggregated form — for analytics or benchmarking across customers.

5. Automated Decision-Making

Some modules use automated logic to help with day-to-day operations — for example, the Roster Board's rotation generator, which produces draft rosters from patterns a Supervisor sets, and the Payroll Exception Report, which flags roster/timesheet mismatches for a human to review. These tools produce drafts and flags for a person to check; they do not make final decisions about an individual's pay or roster without human review.

Where this kind of processing could materially affect an individual (such as a decision about hours or pay), Customer's Company Admin or Supervisor remains responsible for reviewing the output before acting on it. From December 2026, Australian Privacy Principle 1 requires clearer disclosure of how automated decision-making systems work; we will update this section with more detail on the specific inputs and logic used as that obligation takes effect and as these features develop.

6. Storage & Security

Personal information handled through the Service is stored using Firebase/Firestore (Google Cloud infrastructure), with role-based access controls matching the Company Admin / Supervisor / Rig Operator model described in the Terms of Service — an Authorised User can generally only see data relevant to their role and site.

Some modules support offline use, in which case data is held temporarily on the local device (via IndexedDB) until connectivity resumes and it syncs to Firestore. We use encryption in transit and rely on Firebase's access-control and authentication tools to restrict access to authorised systems and personnel. No method of storage or transmission is completely secure, and we cannot guarantee absolute security, but we take reasonable technical and organisational steps to protect personal information against misuse, loss and unauthorised access.

7. Disclosure to Third Parties

We disclose personal information to the following categories of third party, only as needed to run the Service: Stripe, to process payments and manage billing; Google (Firebase/Google Cloud), which hosts and stores Service data and sends sign-in and password-reset emails as our infrastructure provider; Resend, which sends our other emails (such as contact and sign-up confirmations) and receives the recipient's name and email address to do so; and a professional adviser, regulator or law enforcement body, where we are required to by law.

We do not sell personal information, and we do not disclose it to third parties for their own independent marketing purposes. Any other disclosure would only happen with Customer's consent or as otherwise permitted by the Privacy Act.

8. Overseas Storage & Disclosure

Firebase/Google Cloud stores and processes Service data in Google's asia-southeast1 region (Singapore), and requests may pass through Google's global network on the way. This means personal information is stored and processed overseas, not onshore in Australia. Stripe processes payment data internationally as part of its global payments infrastructure, and Resend may process email addresses outside Australia.

Under Australian Privacy Principle 8, we take reasonable steps to ensure any overseas recipient of personal information handles it consistently with the APPs — including relying on the data protection terms Google, Stripe and Resend offer their business customers. If you'd like data kept only in Australian data centres, let us know and we'll confirm whether that's supported for your account.

9. Direct Marketing

We may send account holders service-related communications (such as billing notices, security alerts, or updates about the modules they use) — these aren't marketing and can't be opted out of while the Subscription is active, since they're necessary to run the Service.

We will only send direct marketing (such as news about new modules or features) with consent, and every marketing message will include a clear way to opt out. We do not use personal information collected for operating the Service (such as personnel data entered into the People module) for marketing purposes.

10. Data Breach Notification

We maintain a data breach response plan and comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act. If a breach involving personal information is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals or Customer, as required, as soon as practicable after becoming aware of it — including what happened, what information was involved, and what steps we and they can take in response.

11. Retention & Deletion

We retain personal information for as long as Customer's Subscription is active, and as needed to comply with legal obligations (including payroll and financial record-keeping requirements, which can run to several years). After a Subscription ends, Customer Data — including any personal information within it — is deleted from our production systems in line with our standard retention schedule; residual copies may persist briefly in backups before being purged.

Where an individual's information is no longer needed and we are not required to keep it, we take reasonable steps to destroy or de-identify it.

12. Access, Correction & Complaints

An individual can ask to access or correct personal information we hold about them by contacting us at contact@bingstech.com.au. Where the information was entered by a Customer's Company Admin (for example, personnel data in the People module), we will generally direct the request to that Customer, since they control that data day-to-day — Customer's own Company Admin can usually update or correct it directly in the Service.

If someone believes we have mishandled their personal information, they can lodge a complaint with us at the contact above. We will investigate and respond within a reasonable time. If they are not satisfied with our response, they can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

13. Changes to This Policy & Contact

We may update this Policy from time to time, particularly as new privacy obligations take effect (including the automated decision-making disclosure requirements commencing December 2026 referenced in Section 5). We will post the updated Policy and, for a material change, give Customer at least 30 days' notice in the same way as under the Terms of Service.

Questions, requests or complaints about this Policy can be sent to Bings Intuitive Tech at contact@bingstech.com.au.