Privacy Policy

Last updated: 23 March 2026

Blumetec Hub ("we", "us", "our") operates a lead and variation management platform for Australian service professionals. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using Blumetec Hub — whether as a service professional (account holder) or as a client submitting an enquiry — you agree to the practices described in this policy.

1. What information we collect

We collect the following personal information:

From service professionals (account holders)

  • Full name and email address (via Google sign-in)
  • Business name and unique account slug
  • Subscription and billing status
  • IP address and usage logs for security and rate limiting

From clients (via the service professional's enquiry form)

  • Full name
  • Email address
  • Phone number
  • Property address
  • Job description and preferred contact time
  • Photos uploaded in relation to a job
  • IP address (for spam and abuse prevention)

We do not collect sensitive information (such as health, financial, or government identifier data) beyond what is voluntarily provided in job descriptions.

2. Why we collect it

We collect personal information to:

  • Provide the Blumetec Hub lead and variation management service to service professionals
  • Allow service professionals to receive and manage client enquiries
  • Send automated email reminders and job status notifications to service professionals
  • Enable clients to view and approve quotes via a secure portal link
  • Help clients understand the contents of a quote using AI analysis, when the client chooses to use the AI explainer feature in the client portal
  • Prevent spam and abuse on public-facing forms
  • Maintain and improve the platform

We will not use your personal information for marketing or share it with third parties for their own marketing purposes.

3. Who can see your information

Service Professionals

A service professional's personal information is accessible only to that professional. Other professionals cannot see your account, leads, or client data.

Clients

When a client submits an enquiry, that information is visible only to the service professional who owns the enquiry form. Clients can access their own quote and variation information via a secure, private link. Clients cannot see other clients' information.

Blumetec Hub

Our team may access personal information where necessary to provide support, investigate abuse, or comply with legal obligations. We do not routinely access professional or client data.

4. Third-party services

We use the following third-party services to operate the platform. All are based in the United States. By using Blumetec Hub, you acknowledge that your personal information may be transferred to and stored in the US. See section 7 for more detail.

ProviderPurposeData shared
SupabaseDatabase and file storage (hosted on AWS ap-southeast-2, Sydney)All personal data
GoogleAuthentication (Google Sign-In) and AI processing (Gemini) — including job note summarisation, action item extraction, and AI-assisted quote explanation for clientsAccount holder name and email (Sign-In); job notes and descriptions (AI summarisation); quote PDF files (when a client uses the AI quote explainer feature)
ResendTransactional email delivery to service professionalsAccount holder name, email; client name and job summary
VercelWeb hosting and serverless functionsIP addresses, request logs
SentryError monitoringError details, masked page data
UpstashRate limiting on public formsIP addresses only

Each provider has their own privacy policy and data processing terms. We select providers that maintain appropriate security standards.

5. Data retention

  • Active accounts: Personal information is retained for as long as your account is active.
  • After deletion: When an account is deleted, we will delete or de-identify all associated personal information within 30 days.
  • Client data: Client enquiry data is retained as long as the service professional's account exists. When a professional deletes their account, all associated client data is also deleted.
  • Backups: Data may persist in encrypted backups for up to 30 days after deletion before being permanently removed.

6. How to request access or deletion

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information

To make a request, email us at support@blumetechub.com.au. We will respond within 30 days. We may need to verify your identity before processing the request.

Service professionals can request full account deletion, which will remove all leads, client data, quotes, photos, and variations associated with their account.

Clients who wish to have their enquiry data removed should contact the service professional directly, or email us at the address above if they are unable to reach them.

7. Overseas disclosure

Blumetec Hub is an Australian business. However, some of the third-party services we use store and process data in the United States (see section 4). We take reasonable steps to ensure these providers maintain appropriate protections, but we cannot guarantee that overseas recipients will comply with the Australian Privacy Principles.

Supabase stores database data in the AWS ap-southeast-2 (Sydney) region, meaning most personal data remains in Australia. Other services (Vercel, Resend, Google, Sentry) process data in the US.

AI processing by Google: Job descriptions, notes, and — when a client chooses to use the AI quote explainer — quote PDF files are sent to Google's Gemini AI service for processing. This data is transmitted to Google's servers, which may be located outside Australia. We recommend reviewing Google's Gemini API Terms of Service for details on how they handle submitted data. Clients can choose not to use the AI explainer feature, in which case their quote PDF is not sent to Google.

By using Blumetec Hub, you consent to this overseas transfer under APP 8.

8. Security

We take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification, or disclosure. These include:

  • Encrypted data storage and transmission (HTTPS/TLS)
  • Authentication required to access professional accounts (Google OAuth)
  • Row-level security policies to isolate each professional's data
  • Rate limiting on public-facing forms to prevent abuse
  • Error monitoring and logging to detect anomalies

No internet transmission is completely secure. If you believe your data has been compromised, contact us immediately.

9. Complaints

If you believe we have breached the Australian Privacy Principles or the Privacy Act 1988, you may:

  1. Contact us first at support@blumetechub.com.au. We will investigate and respond within 30 days.
  2. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au/privacy/privacy-complaints

10. Changes to this policy

We may update this Privacy Policy from time to time. The current version will always be available at blumetechub.com.au/privacy. We will notify account holders of material changes via email.

Contact us

For any privacy-related questions, contact us at support@blumetechub.com.au.