Privacy Policy
DigiShift provides organisation-controlled software products. We collect only the information reasonably needed to authenticate users, provide authorised product features, capture information that users or their organisations choose to submit, keep services secure and support customers. The DigiShift mobile app currently contains no advertising SDK and no cross-app tracking implementation.
1. Who this policy applies to
This policy describes how DigiShift Pty Ltd handles personal information across DigiShift websites, DigiShift Core, the DigiShift mobile and web applications, DataStream and other connected DigiShift products where this policy is linked.
2. Information we may collect and hold
- Account and identity information: name, email address, organisation membership, role, product access, plan and account status.
- Organisation information: organisation name, billing/support contact information and product configuration.
- Product and workflow information: form responses, comments, approvals, review history and operational records submitted through an authorised DigiShift product.
- Field evidence you choose or are required to capture: foreground GPS coordinates, photographs, barcodes, signatures, files and documents.
- Device and service information: technical information reasonably required to operate, secure and troubleshoot the service, such as app/browser type, timestamps, request metadata and error information.
- Local offline data: assigned forms, drafts, queued submissions and related media may be stored on the user's device so field work can continue when connectivity is unavailable.
- Support information: messages, enquiries and information supplied when requesting technical or account support.
3. How information is collected
Information may be collected directly from you, from an authorised administrator of your organisation, through your use of DigiShift products, from device permissions you choose to grant, and from service providers that help us operate and secure the platform.
Location, camera, photo-library and file access are requested only when a feature needs them. Foreground location is captured when a user activates a location-enabled field; the current DigiShift mobile app does not request background location.
4. Why we use information
- to authenticate users and enforce organisation, product, role and plan permissions;
- to provide forms, workflows, submissions, reviews, reports, files and other requested product functions;
- to sync offline work and prevent duplicate submissions;
- to maintain security, auditability, reliability and service integrity;
- to provide support, investigate faults and communicate about the service;
- to meet legal, regulatory, contractual, accounting and record-keeping obligations; and
- to improve DigiShift products using appropriately controlled operational feedback and service information.
5. Organisation-controlled information
Most DigiShift accounts are provided through an organisation. Your organisation may determine which products, forms and workflows you can access and may control retention, assignment and business-use rules for information submitted through its workspace. DigiShift does not permit a user to gain access to another organisation merely by changing an organisation identifier in the client.
6. Service providers and disclosures
We may use trusted technology providers for cloud hosting, database services, application delivery, app build/distribution, email/support and other infrastructure required to provide DigiShift. We disclose information to those providers only as reasonably necessary for the service they perform, subject to their applicable contractual and security arrangements.
We may also disclose information where required or authorised by law, to protect users or the security of the service, during a corporate transaction subject to appropriate safeguards, or with the relevant user's or organisation's authority.
We do not sell personal information to advertisers. The current DigiShift mobile app does not contain a third-party advertising SDK or cross-app advertising tracker.
7. Overseas processing
Our primary DigiShift Core and Shared Platform database projects are configured in Australia. Some technology providers used for hosting, app distribution, support or related infrastructure may process information outside Australia, including in the United States and other countries where those providers operate. The countries involved can change as service-provider infrastructure changes.
8. Storage and security
We use technical and organisational controls designed to protect information from unauthorised access, loss, misuse and alteration. Controls include authenticated access, organisation and role checks, row-level security where applicable, private file storage, temporary signed file access and encrypted network transport. No internet or storage system can be guaranteed completely secure.
Authentication/session tokens and offline work may be stored on the user's device using the operating system and application storage mechanisms. Users should secure their device and sign out when access should end.
9. Retention
We retain personal and operational information for as long as reasonably required to provide the service, meet customer/organisation retention settings, resolve disputes, maintain audit integrity and satisfy legal or contractual obligations. When information is no longer required, we may delete or de-identify it where reasonably practicable.
10. Access and correction
You may request access to personal information DigiShift holds about you, or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. In an organisation-managed workspace, we may need to coordinate the request with the relevant organisation administrator.
Email mark@smarkz.com or use our support page.
11. Account and data deletion
You can request deletion of your DigiShift account and associated personal information through our Account & Data Deletion page. Some records may need to be retained where required by law, contract, security/audit obligations or the legitimate record-keeping requirements of the organisation that controls the workspace. Where full deletion is not appropriate, information may be restricted or de-identified where applicable.
12. Complaints
If you believe DigiShift has not handled your personal information appropriately, contact mark@smarkz.com with enough detail for us to investigate. We will review the issue and respond within a reasonable period. You may also have the right to contact the Office of the Australian Information Commissioner.
13. Automated decisions
DigiShift includes automation and AI-oriented product capabilities, but the current DigiShift mobile/DataStream release is designed around organisation-defined access rules and human-created workflow actions. If DigiShift arranges for personal information to be used by a computer program for decisions that could reasonably be expected to significantly affect an individual's rights or interests, this policy will be updated to describe the relevant information and decisions as required.
14. Children
DigiShift business products are not directed to children and are intended for authorised organisational users.
15. Changes to this policy
We may update this policy when DigiShift products, service providers, legal requirements or information-handling practices change. The current version and update date will remain published on this page.
Email mark@smarkz.com or visit DigiShift Support.