Legal
Privacy Policy
How we handle personal information — yours, your staff's, and your customers'.
Version 1.0 · Effective 20 August 2026
The short version
Your shop's data is yours. We hold it so the software can do its job — nothing else. We never sell it,
and we never market to your customers.
Everything lives on servers in Sydney. Text messages, emails and card payments are carried by
specialist providers (Twilio, SendGrid, Stripe) whose systems are overseas, so those messages leave
Australia in transit.
Questions, corrections or complaints: lukas@donedocket.com.
We answer them ourselves.
1. Who we are
DoneDocket is operated by Alter Ego Alterations Pty Ltd (ABN 56 683 203 438,
ACN 683 203 438) trading as DoneDocket, of Melbourne, Victoria, Australia. In this policy "we", "us" and
"DoneDocket" mean that company.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This
policy explains what personal information we collect, why, who we disclose it to and how you can access,
correct or complain about it.
2. Two different roles — this matters
DoneDocket is used by alterations and tailoring businesses. There are two distinct groups of people
whose information passes through it, and our responsibilities differ for each.
- The shop, its owner and its staff. They are our customer. We collect their
information directly and we are responsible for it.
- The shop's own customers — the people who bring garments in. That information is
collected by the shop, for the shop's purposes, and we hold and process it on the shop's
behalf so their software works. The shop decides what is collected, what it is used for and how
long it is kept. We do not use it for our own purposes, we never market to those people, and we never
sell or rent it to anyone.
If you are a customer of a shop that uses DoneDocket and you want your information changed or removed,
contact the shop directly — they can do it themselves inside the software. If they need our help, we help
them. See section 12.
3. What we collect about a shop and its staff
- Business details: trading and legal name, ABN, addresses, phone numbers, email
addresses and opening hours for each shop.
- Owner and manager accounts: email address and a password (stored by our
authentication provider, never in readable form).
- Staff records: name, phone number, role, which shops they work at, their four-digit
PIN, and their working roster where you enter one.
- Timesheets: check-in and check-out times, breaks, and — where an owner edits a
shift — who edited it, when and why.
- Activity records: which staff member took an order, marked it ready, took a payment,
issued a refund or cancelled a job, and when. This is the point of the software, and it is kept as an
audit trail.
- Devices: where a shop turns on device enrolment, a label you choose ("front counter
iPad") and a stored one-way hash of the device's secret.
- Support and fault reports: messages you send us through the app, and automatic
reports when a screen crashes — the error, the page you were on, your browser version, and the identity
of whoever was signed in.
4. What we hold on a shop's behalf about their customers
Collected by the shop at the counter, on their kiosk, or through their own customer page:
- Name, mobile number and email address, and whether they prefer texts, email, both or neither.
- Order records: garments, alterations, notes and measurements, prices, dates, deposits, payments,
refunds, and whether the job was collected.
- The history of the relationship: visit count, total spent, first and last visit, any tags, credits or
account arrangements the shop has set up, and how they heard about the shop.
- Messages: the full text of every text message and email the shop sends them through DoneDocket, and
every reply that comes back.
- Feedback survey responses, including any comments they write.
- Check-ins at the shop's kiosk, and any requests they make through their order-tracking page.
We do not hold street addresses for a shop's individual customers. Business accounts
that are invoiced monthly do carry a billing address, entered by the shop.
5. Payment information
We never see or store a full card number.
- Card payments at the counter go directly from the payment terminal to the shop's
payment provider. What comes back to us is a receipt: the card type, a masked number showing only the
last four digits, an authorisation code and a reference number.
- Online invoice payments are taken on Stripe's own hosted payment page. Card details
are entered there and never pass through our systems. We store only Stripe's references and whether the
invoice was paid.
- Cash, bank transfer and account payments are recorded as amounts and dates.
6. Visitors to donedocket.com
- No cookies, no advertising pixels and no session tracking. We do not run Google
Analytics, Meta pixels, or any advertising tag.
- We use Cloudflare Web Analytics, which counts page views without cookies and without
building a profile of you.
- Our pages load typefaces from Google Fonts, which means your IP address and browser
version are visible to Google when a page loads. This applies to the shop software as well as this site.
- If you book a walkthrough, we collect what you type into that form — your name, shop, email, phone,
shop size, current system and what you'd like to fix — plus, if you arrived from an advertisement or a
link, which campaign or site sent you. It is emailed to us so we can reply. We use it to contact you
about DoneDocket and for nothing else.
7. What we use it for
- Running the software: taking orders, tracking jobs, sending the shop's messages to their customers,
printing receipts, processing payments, keeping timesheets and audit trails.
- Supporting the shop when something goes wrong, and fixing faults.
- Billing for the subscription, and metering text-message usage against the shop's allowance.
- Keeping the service secure — rate limiting, lockouts after wrong PINs, and audit logs.
- Meeting our legal and tax obligations.
We do not use a shop's customer data to train models, to build a marketing list, or to contact those
customers ourselves for any reason.
8. Who else handles it
We use specialist providers to run parts of the service. Each receives only what it needs.
| Provider | What it handles | Where |
| Supabase | The database and account sign-in — all of the information described above | Sydney, Australia |
| Fly.io | Runs the application itself | Sydney, Australia |
| Twilio | Sends and receives text messages — the recipient's mobile number and the full message | United States |
| SendGrid (Twilio) | Sends and receives email — the address, subject, message and any attached invoice | United States |
| Stripe | Card payment of invoices, and the shop's own payout account | United States / Ireland |
| Linkly | Connects the shop's payment terminal to their bank | Australia |
| Cloudflare | Domain routing, and the cookieless page counter on this website | United States |
| Google Fonts | Typefaces — sees the IP address of anyone loading a page | United States |
We may also disclose information where the law requires it, to our professional advisers under
confidentiality, or to a buyer if the business is ever sold — in which case this policy continues to apply
until you are told otherwise.
We never sell personal information.
9. Where it is stored, and what leaves Australia
The database and the application both run in Sydney, Australia. Backups are held in the
same region.
Some information necessarily crosses the border in the course of doing its job, and by using DoneDocket
you consent to these overseas disclosures (APP 8): text messages and mobile numbers go to Twilio, emails and
email addresses to SendGrid, invoice payment details to Stripe, and page requests to Cloudflare and Google
Fonts. These providers are bound by their own contractual and legal obligations, but they are not subject to
the Australian Privacy Act, and we cannot guarantee they will handle information the way an Australian
entity must.
10. Texts and emails to a shop's customers
When DoneDocket sends a message, it is sent for the shop and on their instruction — the
shop's name leads every message. The shop is responsible for having the customer's consent to contact them,
and for keeping their contact details accurate.
- Every text ends with "Reply STOP to opt out." A customer who replies STOP is
unsubscribed at the carrier level and stops receiving messages.
- A shop can also set any customer to email only, text only, or no contact at all — which we honour
everywhere in the software.
- Replies come back into the shop's message thread, where their staff can read and answer them.
11. How we protect it
- Separation between shops is enforced by the database itself, not just by application
code — a signed-in user of one shop cannot read another shop's rows even if the software has a bug.
- All traffic is encrypted in transit (HTTPS), and the database is encrypted at rest by our hosting
provider.
- Staff sessions expire after four hours and are never written to browser storage.
- Order-tracking and invoice links use unguessable random tokens tied to the issuing shop.
- Public forms are rate limited; repeated wrong PINs trigger an escalating lockout.
- Incoming messages from our text provider are signature-verified before we accept them.
- Device secrets are stored only as one-way hashes.
About staff PINs. A four-digit PIN identifies who did what at the counter; it is a
convenience credential, not a strong secret. PINs are never displayed through the software or returned by
our interfaces, but staff should not reuse a PIN that protects anything else, and owners should remove
staff who leave.
Support access. To investigate a fault we may need to sign into a shop's account and see
what their staff see, including customer records. Every such access is recorded permanently with who did it,
when, and from where. We do it to fix problems, and for no other reason.
No system is perfectly secure. If a data breach occurs that is likely to cause serious harm, we will
notify the affected shop without undue delay and within 72 hours of becoming aware of it,
and will notify the Office of the Australian Information Commissioner where the Notifiable Data Breaches
scheme requires it.
12. How long we keep it
- While a shop's subscription is active, their data is kept so the software works — job
history and customer records are the product.
- After a subscription ends, the shop has 30 days to export their
data. We then delete it within 90 days of the subscription ending.
- Records we must keep longer: invoices and payment records for seven years, as
Australian tax law requires; and security and support-access logs, which are kept separately for up to
two years.
- Walkthrough enquiries — if you ask us for a walkthrough, we keep what you told us
(your name, your shop, your contact details, what you want to fix, and how you found the site) in our
own records as well as in our email, so an enquiry can't be lost. We use it only to answer you and to
set your shop up if you go ahead; we never sell it or use it for unrelated marketing. We keep it for
24 months after we last hear from you, and we'll delete it sooner if you ask.
13. Access, correction and complaints
If you are a shop using DoneDocket: most of your information is visible and editable
inside the software. For anything else, email us and we will provide or correct it, normally within 30 days.
If you are a customer of a shop that uses DoneDocket: the shop holds your information
and controls it. Ask them for access, correction or deletion — they can do all three themselves. If you
cannot reach them, or they need our help, contact us and we will assist them in responding to you.
Complaints: email lukas@donedocket.com with
the details. We will acknowledge within five business days and respond within 30 days. If you are not
satisfied with our response, you can complain to the Office of the Australian Information Commissioner at
oaic.gov.au or 1300 363 992.
14. Children
DoneDocket is business software and is not directed at children. We do not knowingly collect information
from anyone under 16 except incidentally, where a shop's customer happens to be young — in which case it is
the shop's record, held on their behalf.
15. Changes to this policy
We will update this page when the way we handle information changes, and change the version and date at
the top. If a change materially affects the shops using DoneDocket, we will tell them by email before it
takes effect.