Privacy Policy
1. Who this policy covers
This policy explains how RapidHQ (ABN 25 862 736 953), operator of RapidQA, collects, uses, and stores personal information through the RapidQA platform. It applies to admin users, worker users, and anyone whose details appear in a project's distribution list for report emails.
2. What we collect
| Category | Examples |
|---|---|
| Account details | Name, email address, company, role (admin or worker) |
| Work records | Checklist responses, comments, photos taken on site, digital signatures, timestamps |
| Project data | Project names, addresses, builder/engineer contacts your company enters |
| Billing details | Handled directly by our payment processor, Stripe — RapidQA does not store full card details |
| Usage data | Basic technical logs (e.g. login activity) used for account security and support |
3. How we collect it
Directly from you — when your company sets up an account, when an admin invites a worker, and when forms are completed on site through the worker app.
4. How we use it
- To provide the core service — storing, generating, and delivering quality records and reports;
- To send account-related emails — invites, password resets, and report notifications;
- To provide support when you contact us;
- To maintain the security and integrity of the platform.
We don't use your data for advertising, and we don't sell it to anyone.
5. Who it's shared with
Personal information is shared only:
- Within your own company's account — admins can see the work records of workers at their company, as needed to review and manage projects;
- With recipients you configure — report emails go to whichever addresses your company adds to a project's distribution list (e.g. a builder or engineer);
- With service providers who help us run RapidQA — currently Supabase (hosting and database), Resend (sending emails), and Stripe (payment processing). Each only receives what's necessary to perform their specific function, and none of them are permitted to use your data for their own purposes.
6. Where data is stored
RapidQA's infrastructure may store and process data on servers located outside Australia, including in the United States, depending on the service providers listed above. We select providers with appropriate security practices, but if this matters for your company's own compliance requirements, please get in touch before signing up so we can talk through the specifics.
7. Data security
We take reasonable technical and organisational measures to protect the information stored in RapidQA, including encrypted connections and access controls limiting who can see a given company's data. No system is completely immune to risk, and we can't guarantee absolute security, but we take this seriously and will notify affected users promptly if we become aware of a data breach affecting their information.
8. How long we keep it
We retain work records for as long as your company's account is active, and for a reasonable period afterward in case you need to reactivate or export historical records. If you'd like data deleted sooner, contact us and we'll action it, subject to any records we're legally required to retain.
9. Access and correction
You can ask us at any time for a copy of the personal information we hold about you, or to have it corrected. Admin users can update most of this directly within RapidQA; for anything else, contact us at the address below.
10. Cookies
RapidQA uses only the minimum technical cookies needed to keep you logged in and remember your session. We don't use tracking or advertising cookies.
11. Changes to this policy
We may update this policy from time to time, most often to reflect new features. We'll note the date at the top of this page, and let you know directly if a change is significant.
12. Contact
Questions about this policy, or requests relating to your personal information, can be sent to hello@rapidqa.com.au.