CoreDocket Privacy Policy

Effective date: 27 August 2026

1. Who we are

CoreDocket is operated by Peak Productive Consulting Pty Ltd trading as CoreDocket (“we”, “us”). We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what personal information we collect through our website and our software, why we collect it, and who it is shared with.

2. Two different roles

It matters which hat we are wearing when your information reaches us.

As a business: when you visit our website or make an enquiry, we decide what is collected and why. Sections 3 to 6 apply.

As a service provider: when our customers use CoreDocket to run their field service business, they enter information about their own staff, customers and job sites. That information belongs to them. We hold and process it on their instructions, we do not use it for our own purposes, and their own privacy policy governs it. Section 7 applies.

3. Information you give us

When you submit an enquiry, request access, or book a demo, we collect the name, email address, phone number and any message you provide, along with the page you submitted from and the site that referred you. We use this only to respond to you, to arrange a demo, and to follow up about CoreDocket. We do not sell it, and we do not share it with anyone outside the processors listed in section 8.

If you create an account, we also collect your name, email address, the organisation you belong to, and your role within it, so that we can authenticate you and apply the correct permissions.

4. Information collected automatically

First-party analytics. Our own analytics records each page view on this site: a randomly generated session identifier, the page path, the referring site, your IP address, an approximate location derived from that IP address (country, state, city), and your device and browser type. We use it to understand how people find and move through the site. It is stored in our own database, is visible only to our platform administrators, is never sold or shared for advertising, and is automatically deleted after 90 days.

Session analytics. We use Microsoft Clarity to record heatmaps and session replays of our marketing pages only, so we can see which parts of a page people read and where they get stuck. Clarity is deliberately blocked on every signed-in product screen, so it never records job, customer or pricing data. Clarity sets its own cookies; Microsoft’s handling of that data is covered by the Microsoft Privacy Statement.

Buttons and forms. When you click a call-to-action we record which button, on which page, and the referring site, together with a one-way hash of your IP address that changes daily. The hash lets us ignore repeat clicks from the same person without storing an identifier we can trace back to you.

Cookies. We use cookies that are strictly necessary to keep you signed in and to keep the service secure. Beyond those, the only cookies are the Clarity analytics cookies described above. We do not run advertising or retargeting pixels.

5. Why we collect it

To answer enquiries and arrange demonstrations; to create and secure accounts; to provide, support and improve the service; to understand how the website performs; to send service-related messages; and to meet our legal and record-keeping obligations. We do not use your personal information for automated decision-making.

6. Direct marketing

If you enquire, we may contact you about CoreDocket. Every marketing message includes an unsubscribe option, and you can opt out at any time by emailing us. Opting out of marketing does not stop essential service messages such as security and billing notices.

7. Customer data inside the product

Our customers use CoreDocket to record jobs, dockets, pricing, site photographs and customer signatures. We access that data only to operate the service, to provide support at the customer’s request, to keep backups, or where the law requires it. We do not use it to market to their customers, and we do not sell it.

If you are a customer of one of our customers and want your information accessed, corrected or deleted, please contact the business you dealt with. They control that record; we will assist them in responding.

8. Who we share information with

We disclose personal information only to the providers required to operate CoreDocket, and only for that purpose. Each is listed below with the information it receives and the location in which it is processed. Providers marked optional receive no information unless the relevant feature is enabled on your account.

  • Supabase

    Database, authentication and file storage.

    Receives: All information held in your account, including jobs, dockets, customers, photographs, signatures and safety records. Processed in Sydney, Australia.

  • Vercel

    Application hosting.

    Receives: Information in transit while pages and requests are served. Processed in Sydney, Australia. Logs and the edge network operate globally.

  • Twiliooptional

    Job SMS, including arrival notifications and replies.

    Receives: Mobile numbers and the content of messages sent and received. Processed in The United States, using Australian numbers.

    Twilio retains its own copy of message content.

  • Resend

    Sending docket reports, quotes, invoices and account email.

    Receives: Recipient name and email address, and the attached document. Processed in The United States.

  • Geoapify

    Address autocomplete, maps and travel times.

    Receives: Site addresses entered into the application. Processed in The European Union.

    Addresses are sent to Geoapify as they are entered into an address field, not only when a record is saved.

  • Xerooptional

    Transferring invoices to your accounting system.

    Receives: Customer name, address, contact details and invoice lines. Processed in Your Xero account's own region.

  • MYOBoptional

    Pushing invoices into your accounting system.

    Receives: Customer name, address, contact details and invoice lines. Processed in Australia.

  • Stripe

    Processing payment for your CoreDocket subscription.

    Receives: Your billing name, email address, business address and payment details. No customer records are disclosed to Stripe. Processed in The United States and Australia.

    Card details are entered on Stripe's hosted checkout page and are not received or stored by CoreDocket.

  • Anthropicoptional

    Producing a draft price list from a rate card you upload.

    Receives: Price list content only. Job, customer and safety records are not disclosed. Processed in The United States.

    This limit is set by CoreDocket rather than by the provider. Any change to it will be published here and notified to account holders.

  • Microsoft Clarity

    Usage analytics on our public marketing pages.

    Receives: Visitor activity on coredocket.com.au only. Disabled on all signed-in screens. Processed in Global.

Some of these providers operate outside Australia, which means personal information may be stored or processed overseas: Twilio, Resend, Stripe and Anthropic in the United States, and Geoapify in the European Union. Before disclosing personal information to any of them, we take reasonable steps to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles, as APP 8 requires. All other components of the platform, including the information held in your account, remain in Australia. See section 9.

We do not sell personal information, and we do not disclose it for advertising purposes. This list is reviewed when the platform changes and was last verified on 27 August 2026. The current version is published at coredocket.com.au/sub-processors.

9. Where your information is stored

Information held in your account is stored in Australia. Each component is set out below.

  • Your database, files and sign-inSydney, Australia

    Supabase, region ap-southeast-2.

  • The application that serves your screensSydney, Australia

    Vercel functions are pinned to the syd1 region, confirmed from production response headers.

  • BackupsSydney, Australia

    Retained with the database, in the same region.

The exceptions are the providers identified in section 8 that perform a specific function outside Australia: sending email and SMS, processing card payments, and address lookup. No other information is transferred outside Australia.

10. How we protect it

Personal information is encrypted in transit using TLS and encrypted at rest by our database and storage provider. In addition, the following controls apply:

  • Each organisation’s records are isolated at the database level rather than by application code. Isolation therefore holds independently of any fault in the application.
  • Photographs, signatures and attachments are stored privately. They are not accessible by URL. Access is granted individually and expires.
  • Access follows the permissions you set. What each person may see and do is determined by you and enforced on the server at the point the action is performed.
  • Our personnel do not browse customer data. We access it only to operate the service, to provide support at your request, or where required by law.

No system is entirely secure. In the event of a data breach likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and will inform you of what is known at the time rather than on completion of the assessment.

11. How long we keep it

Two retention regimes apply, depending on whose information it is. Information we collect for our own purposes — website analytics, enquiries and billing — is retained for a period we set and enforce. Information you enter into the platform remains yours: it is retained while your account is open, made available on request, and deleted on your instruction. CoreDocket does not delete your business records on a schedule of its own, as the obligation to retain them rests with you.

  • Your jobs, dockets, customers, photographs and signatures

    While your account is open, then 90 days after it closes.

    These are your business records. No retention limit is applied while your account is open. The 90-day period allows a closed account to be exported.

  • Safety documents and the signatures on them

    While your account is open, without alteration.

    A signature is recorded against the specific version of the document that was signed, and is not affected by later edits to that document.

  • Timesheets and leave

    While your account is open.

    These are employee records. Responsibility for retaining them rests with the employer, for seven years under the Fair Work Act 2009 (Cth). CoreDocket does not delete them on a schedule of its own.

  • Job SMS, both directions

    While your account is open.

    No automatic deletion period currently applies. Twilio also retains its own copy of message content.

  • Website analytics on coredocket.com.au

    90 days, then automatically deleted.

    Deletion is applied automatically in the database.

  • Billing records

    7 years.

    Required for taxation and corporate record-keeping.

Where an account is closed, data is retained for 90 days so that it may still be exported, and is then deleted or de-identified. Backups are held in the same region and expire on a rolling window. CoreDocket does not withhold your records in order to secure payment of an account.

12. Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it where we are not required to keep it, or opt out of marketing. Email us and we will respond within 30 days. There is no charge to make a request.

13. Complaints

If you believe we have mishandled your personal information, email us first and we will investigate and respond in writing. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

14. Children

CoreDocket is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16.

15. Changes to this policy

We may update this policy as the service changes. The effective date at the top of this page shows when it was last revised, and material changes will be notified to account holders by email or in the app.

16. Contact

Peak Productive Consulting Pty Ltd trading as CoreDocket
Privacy enquiries: enquiries@coredocket.com.au