Legal

Privacy Policy

Effective April 12, 2026

1. Introduction

PlanInsight is operated by Martin Picha (ABN 66 448 014 707), trading as PlanInsight (“we”, “our”, or “us”). We are an APP entity under the Privacy Act 1988 (Cth) and this policy describes how we handle personal information in accordance with the Australian Privacy Principles (APPs).

This policy explains what we collect, why, who we share it with, and the rights you have. By using PlanInsight you acknowledge the practices described here. If you do not agree, please do not use the service.

2. Information We Collect

Account information

Name, email address, organisation name (if applicable), and a hashed password. Collected when you register.

Billing information

Stripe processes all payments. We do not store card numbers. We receive and retain a tokenised customer reference, subscription status, invoice history, and billing address.

Usage and product analytics

Pages visited, features used, searches performed, DXF downloads, and approximate session timing. Collected via Mixpanel (in the logged-in app) and Beampipe (on the marketing site). See Section 8 for cookie details.

Technical and error data

IP address, browser user agent, device type, request paths, and error stack traces. Collected via server logs, Cloudflare Turnstile (bot protection on public forms), and Sentry (error monitoring). We configure Sentry to scrub common PII fields (emails, tokens, authorisation headers) from error reports before they leave our server.

Property search data

When you look up a property, we query Australian state and territory government systems (QLD, NSW, VIC, NT, TAS, and others) for titles, land valuations, development applications, spatial boundaries, and related records. Results are cached on our servers to improve performance and reduce load on source systems. Cache retention varies by dataset (typically 30 days; some datasets such as Tasmanian spatial layers are retained indefinitely because the source data rarely changes). A full list of Upstream Sources and their licences is maintained on our Data Sources & Attributions page.

Important: Title and council records are public register data and may include personal information about third parties (for example, the name of a registered property owner). You are responsible for using this information lawfully and only for the purpose for which the relevant register makes it available.

BYDA enquiries

When you request underground asset information for a property through PlanInsight, we lodge a “Before You Dig Australia” enquiry against that property using accounts operated by PlanInsight. The property details you provide (address, lot/plan, purpose) are transmitted to BYDA / SmarterWX and, through them, to the relevant asset owners. Asset owner responses (including utility plans and response documents) are returned to PlanInsight, stored on our servers, and made available to you inside the app. The BYDA information displayed in the app is for research and early-stage planning; it is not a valid BYDA certificate for excavation (see our Terms of Service).

Communications

If you email us or use our contact form, we retain your message, email address, and any context you provide so we can respond and maintain a support history.

3. How We Use Your Information

We use information we collect to:

  • Provide, operate, and improve the PlanInsight platform
  • Process subscription payments and send billing communications
  • Respond to support enquiries
  • Send transactional and service emails (and, with your consent, product updates)
  • Monitor performance, detect errors, and prevent fraud or abuse
  • Comply with legal and tax obligations

We do not sell personal information. We do not use your data to train third-party AI models.

4. Who We Share It With

We share information with two small groups of service providers: those who handle your personal information as part of running the platform, and those who receive only technical signals or act on requests you make through the Service.

Processors who handle your personal information

ProviderPurposeLocation
VultrServer and database hosting (where your account data and cached searches live)Sydney, Australia
StripePayment processing and subscription managementUnited States / global
SentryError and exception monitoring (may include authenticated user ID and email in captured error reports, subject to our scrubbing rules)United States
MixpanelProduct analytics for the logged-in app (user ID and event stream)United States

Services that receive technical signals or act on your requests

ProviderWhat they receiveLocation
Cloudflare (Turnstile)Browser signals (IP address, user agent, behavioural signals) used to verify you are not a bot. Does not receive form field values.Global edge network
BYDA / SmarterWXProperty details (address, lot/plan, purpose) when you request underground asset information. Enquiries are lodged under PlanInsight’s own BYDA accounts rather than under your identity.Australia

Each provider is bound by a contract or data processing agreement limiting use of any data they receive to the services they provide to us.

We may also disclose information if required by law, in response to a valid legal request, or to protect our rights, users, or the public. If PlanInsight is acquired or merges with another entity, personal information may transfer as part of that transaction; we will notify you beforehand.

5. Cross-Border Disclosure (APP 8)

Several providers listed above are located outside Australia, primarily in the United States and United Kingdom. When we disclose personal information to them, we take reasonable steps to ensure they handle it consistently with the APPs, including signing data processing agreements and selecting providers with recognised security and privacy practices.

You acknowledge that by using PlanInsight, your information may be processed outside Australia for the purposes described in this policy.

6. Data Security

We use reasonable technical and organisational measures to protect personal information, including:

  • HTTPS / TLS for all data in transit
  • Hashed passwords and encrypted backups
  • Access controls limiting data access to authorised personnel
  • Bot protection (Cloudflare Turnstile) on public forms
  • Error monitoring with PII scrubbing before data leaves our environment
  • Regular dependency and security updates

No system is perfectly secure. We cannot guarantee absolute security, but we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) of any eligible data breach as required under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988).

7. Data Retention

  • Account data — kept while your account is active. On closure, deleted within 90 days except where retention is required by law (for example, tax and financial records are kept for 7 years under ATO rules).
  • Billing records — 7 years, in line with Australian tax law.
  • Mixpanel events — retained according to our Mixpanel plan (typically 12 months).
  • Sentry errors — 30 to 90 days.
  • Server logs — up to 30 days.
  • Cached property search data — typically 30 days; some datasets (e.g. Tasmanian spatial layers) are retained indefinitely because the underlying source data rarely changes. Cached data is not tied to your identity after the initial request.
  • Support emails — retained for as long as needed to maintain a support history, typically 2 years.

8. Cookies and Tracking

We use cookies and similar technologies for three purposes:

  • Strictly necessary — session, authentication, CSRF, and bot protection (Cloudflare Turnstile). These are required for the service to work and cannot be disabled.
  • Analytics — Mixpanel (logged-in app) and Beampipe (marketing site) help us understand which features are used and where users encounter friction. Beampipe is cookieless and privacy-friendly. Mixpanel uses cookies and is only activated where applicable consent has been obtained.
  • No advertising cookies — we do not use third-party advertising or retargeting cookies.

You can control cookies through your browser settings. Disabling strictly necessary cookies will prevent the platform from functioning.

9. Your Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may:

  • Access — request a copy of the personal information we hold about you (APP 12)
  • Correction — ask us to correct information that is inaccurate, out-of-date, or incomplete (APP 13)
  • Withdraw consent — opt out of product and marketing emails at any time (transactional emails will continue while your account is active)
  • Close your account — request account closure and deletion of personal information, subject to legal retention obligations

To exercise any of these rights, email hello@planinsight.com.au. We will respond within a reasonable period, typically within 30 days.

If you are unhappy with how we have handled your personal information, you can make a complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

10. Public Register Data and Third-Party Information

Some data you retrieve through PlanInsight originates from public registers maintained by Australian state and territory governments (land titles, valuations, development applications, spatial cadastre). This data may include personal information about third parties, such as registered owners.

You are responsible for using this information only for purposes permitted by the source register and applicable law. PlanInsight does not control the accuracy or currency of source data and is not a substitute for a legal title search, survey, or professional advice.

11. Children’s Privacy

PlanInsight is a professional tool not intended for use by individuals under 18. We do not knowingly collect personal information from children. If you believe we have inadvertently done so, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email to active account holders and highlighted on the site. The “Effective date” above indicates when the current version took effect.

13. Contact Us

Martin Picha (ABN 66 448 014 707) Trading as PlanInsight

Email: hello@planinsight.com.au Privacy enquiries: hello@planinsight.com.au

For complaints you believe are unresolved, contact the OAIC at www.oaic.gov.au.