01
Privacy Policy
This Privacy Policy explains how Powder OS collects, uses, holds and discloses personal information through powderos.app and in providing design, website, hosting, maintenance and related services. Powder OS means the operator of powderos.app and, for a client project, the service provider identified in the relevant proposal or service agreement.
We aim to handle personal information transparently and in a manner consistent with applicable Australian privacy law. The exact obligations that apply can depend on the organisation, activity and information involved.
1. Scope
This policy applies to personal information handled by Powder OS about website visitors, prospective customers, clients, suppliers and business contacts.
When we operate a website or workflow on behalf of a client, the client may control the personal information collected from its customers. The client's privacy notice and the relevant service agreement apply to that collection, while Powder OS handles the information only for the agreed service and lawful operational purposes.
2. Personal information we may collect
Depending on how you interact with us, we may collect:
- your name, role, organisation and contact details
- enquiry, proposal, project, support and communication records
- billing, transaction and account-administration information, but not full payment-card details processed by a payment provider
- content, photographs, documents, credentials and other materials supplied for a project
- approvals, preferences and records of your instructions
- website usage and technical information, such as pages viewed, referral source, device type, browser, operating system, approximate location and performance measurements
- information reasonably required to provide an agreed client workflow, which may include customer, vehicle, booking, job or uploaded-photo information.
We do not ask website visitors to provide sensitive information. A client project may involve sensitive information only where it is necessary for an approved workflow and appropriate collection, access, security and retention controls have been agreed.
3. How we collect information
We usually collect information directly from you when you contact us, request a proposal, enter an Agreement, provide project material, approve work, ask for support or otherwise communicate with us.
We may also receive information from:
- your authorised staff, advisers or service providers
- publicly available business sources
- analytics, hosting, security and performance services used to operate our website
- a client-controlled website or connected service where the relevant Agreement authorises us to provide technical support or processing.
4. Why we use personal information
We may use personal information to:
- respond to enquiries and prepare proposals
- verify instructions and administer our relationship with you
- design, build, host, secure, maintain and support agreed services
- process billing and maintain business records
- communicate about projects, service changes, security, support and renewals
- operate, protect, measure and improve our website and services
- prevent misuse, investigate incidents and enforce agreements
- meet legal, regulatory, insurance and professional obligations
- send marketing communications where permitted, with a clear way to opt out.
We will not use personal information for an unrelated purpose unless you consent or the use is otherwise authorised or required by law.
5. Website analytics, local storage and cookies
The website uses Vercel Web Analytics to understand aggregate traffic and Vercel Speed Insights to measure real-world performance. Vercel Web Analytics is designed not to use cookies or retain information that identifies a visitor across different websites or days. Analytics and performance data may include page paths, referral information, device and browser details, approximate location and web-performance measurements.
The website also records first-party page views for a private visit log operated by this site. The browser beacon does not write a cookie or other identifier to your device. Requests that send a Do Not Track or Global Privacy Control signal are not recorded. The log stores the page path and coarse technical details such as referral host, device class, browser, operating system, approximate location, language, viewport width and campaign tags when present. Raw IP addresses, raw user agents and full referrer URLs are not stored. A salted value that changes each UTC day is used to estimate daily visitors. Deletion of these records is not automatic.
The website uses local browser storage to remember studio lighting and sound preferences, and whether the sound prompt has already been shown. Local storage is not a cookie. This preference data stays in your browser unless you clear it.
The current website does not use advertising or marketing cookies.
You can clear local storage and cookies through your browser settings. Clearing the stored preferences will reset those choices. Blocking site storage may affect those preferences but should not prevent access to these policy pages.
6. Website assistant
The homepage includes an interactive studio assistant. Text you submit there is sent to a third-party model provider so that a reply can be produced. Do not submit passwords, confidential client information or material you lack authority to provide.
This application does not persist visitor assistant conversations. The provider's handling of prompts and replies is governed by their terms. The assistant's own wording is general information, not a quote, a commitment or advice about your situation.
Where the assistant offers an enquiry form and you send it, that enquiry is handled under this policy as an enquiry record, separately from the chat.
7. Disclosure and service providers
We may disclose personal information where reasonably necessary to:
- hosting, infrastructure, analytics, security, communication, payment and project-delivery providers
- professional advisers, insurers, contractors and auditors who need the information for their work
- a buyer or successor in connection with a proposed or completed business restructure, subject to appropriate confidentiality
- government, regulatory, law-enforcement or court authorities where authorised or required by law
- another person where you authorise the disclosure.
We do not sell personal information.
8. Overseas processing
Some technology and service providers operate globally and may process or store information outside Australia. The countries involved depend on the provider and the service used for a particular project. We do not make a blanket promise that data remains in Australia.
Where a project involves material personal-information handling, the service configuration, provider roles and any relevant data-location requirements should be addressed in the Agreement or project documentation.
9. Security
We use technical and organisational measures appropriate to the service and information involved. These may include encrypted connections, access controls, supported technology, managed infrastructure, backups, monitoring and restricted access.
No internet or storage system is completely secure. You are responsible for protecting credentials issued to you, controlling staff access and notifying us promptly of suspected unauthorised access.
10. Retention and deletion
We retain personal information only for as long as reasonably needed for the purpose for which it was collected, to provide or support the service, to maintain necessary business records, to resolve a dispute, or to meet legal, insurance and contractual obligations.
When information is no longer required, we take reasonable steps to delete or de-identify it, subject to lawful retention requirements and the normal operation of secure backups. Client-project retention, export and deletion arrangements may be specified in the Agreement.
11. Access and correction
You may ask to access personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify your identity before responding.
We will respond within a reasonable time. If we cannot provide access or make a requested correction, we will explain why where required by law and tell you about available complaint options.
12. Marketing communications
We send commercial email or messages only where we have the required consent or another lawful basis. Marketing communications identify the sender and include a functional way to unsubscribe. You can opt out at any time, and we will action the request within the period required by law.
Service, security, billing and project communications are not marketing messages and may still be sent where needed to administer an active relationship.
13. Privacy enquiries and complaints
Send an access request, correction request or privacy complaint to Powder OS using the contact details in your proposal, service agreement or latest correspondence. Please mark the message for the attention of the Privacy Officer and include enough detail for us to understand and investigate the request.
If you do not have an existing business contact, address the request to "Privacy Officer, Powder OS" through any enquiry channel Powder OS makes available. A dedicated public privacy or legal contact address has not been published on this website. We will acknowledge and investigate a complaint within a reasonable time.
If the Privacy Act 1988 applies to the matter and you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner at oaic.gov.au.
14. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The current version is published on powderos.app. Material changes apply prospectively from the date of publication unless law requires otherwise.