Skip to main content

Legal

Privacy Policy

How WorkClear handles account, billing, API, and website data.

Last updated: 16 July 2026

Overview

WorkClear (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our website, dashboard, bulk verification tools, and licence verification API.

Information We Collect

API Usage

  • We log API endpoint, response status, response time, and related usage data for quotas, debugging, and abuse prevention
  • API request query values and IP addresses are stored as non-reversible HMAC hashes in our API request logs
  • API keys are stored as hashes and are only shown once when created

Dashboard and Bulk Usage

  • Dashboard search history stores the query and a result summary so you can review recent searches
  • Search audit events may store query, state, sector, a non-reversible IP hash, user agent, and outcome details for abuse detection, coverage-gap review, support, and product reliability
  • Bulk CSV uploads are processed to return verification results; uploaded files are not used to build customer profiles or sold to third parties

Account Information

  • Email address (for account and billing communications)
  • Company name (optional, for enterprise customers)
  • Payment information (processed securely by Stripe)
  • Plan, API key metadata, quota usage, and billing state needed to operate your account

Contact, Waitlist, and Website Use

  • Contact and waitlist details you submit, including name, email, company, requested workflow, volume, timing, and message
  • Aggregate page and product-event analytics collected through Plausible to understand acquisition and workflow use
  • Error and performance diagnostics processed through Sentry; WorkClear disables default PII collection and applies additional header, cookie, email, API-key, and request-body scrubbing
  • Short-lived browser session storage used to avoid counting selected analytics events more than once per session

How We Use and Share Information

We use personal information to provide and secure accounts, process billing, enforce quotas, return verification results, respond to inquiries, improve source coverage and product reliability, investigate abuse, and meet legal, tax, and accounting obligations. We do not sell customer search, API, contact, or billing data.

We use managed providers for database and authentication, application hosting, payments, transactional email, error monitoring, and aggregate analytics. Current core providers include Supabase, Vercel, Stripe, Resend, Sentry, and Plausible. We disclose only the information needed for those providers to perform their service or where disclosure is required by law.

Core production database infrastructure is hosted in Australia. Some providers, support personnel, edge systems, or subprocessors may process or make information accessible outside Australia. Provider locations can change, so contact us for the current information relevant to your account before relying on a specific data- residency requirement.

Data Sources

The licence data provided through WorkClear is sourced from publicly available government and regulatory registers across current live WorkClear coverage. Examples include:

  • Queensland Building and Construction Commission (QBCC)
  • NSW Fair Trading
  • Victorian Building Authority (VBA)
  • Consumer and Business Services South Australia
  • Western Australia, ACT, Northern Territory, Tasmania, real-estate, and security licensing registers where live coverage is shown on our Status and Sources pages

Source data may include names, licence numbers, licence classes, status, expiry details, business identifiers, and addresses where those fields are published by the relevant register.

Data Security

  • Traffic to WorkClear is encrypted over HTTPS/TLS
  • Core database infrastructure is hosted in Australia, while the public application uses managed hosting and edge infrastructure
  • We use authentication, row-level access controls, API quotas, rate limits, and audit logs to protect account and usage data
  • We do not sell customer search, API, or billing data

Data Retention

Dashboard search audit events are retained for up to 30 days; source lookup telemetry for up to 90 days; API request logs and aggregate bulk-job outcomes for up to 180 days; and contact, waitlist, and Stripe webhook records for up to two years unless a longer period is required for a legal, tax, billing, dispute, fraud-prevention, or security purpose. Expired rate-limit records are removed by the same recurring retention job. Dashboard search history remains available until you clear it or delete your account. Operational backups may retain deleted data until the applicable backup expires.

Deleting your account immediately cancels active WorkClear subscriptions before account and authentication records are removed. Privacy-safe aggregate source/bulk events may remain without your user or API-key identifier until their retention period expires. Stripe and other providers may retain billing, tax, fraud, or transaction records under their own legal obligations.

Your Rights

Subject to applicable law, you may:

  • Access your personal information
  • Request correction of inaccurate information
  • Request deletion of your account and associated data
  • Opt out of marketing communications

We may need to verify your identity before acting on an access, correction, or deletion request. We aim to respond within a reasonable period. If we cannot resolve a privacy complaint, you may be able to contact the Office of the Australian Information Commissioner through its privacy complaint process.

Contact Us

For privacy requests or complaints, email support@workclear.com.au or use our contact page.