Privacy Policy

Last updated 23 August 2026 · Version 2026-08-23

This policy explains how Tidal Shift handles personal information across our website, forms and platform. The entity responsible for the personal information described here is Tidal Circular Pty Ltd (ABN 15 691 289 522), trading as Tidal Shift Coordination; in this policy “Tidal Shift”, “we” and “us” mean Tidal Circular Pty Ltd. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

We generally do not collect sensitive information. If we ever need to, we will do so only with your consent.

A. Information we collect

  • Account & user information. Your name, email, role and organisation; a hashed password; multi-factor authentication and trusted-device records.
  • Enquiry information. Details you submit through our contact or request-access forms.
  • Operational data. Load, movement and coordination records that may include the names and contact details of site contacts and drivers.
  • Photos & evidence. Custody photos and their metadata. Where a device provides it, we retain the capture location and time as part of the chain-of-custody record.
  • Technical & usage data. IP address, device and browser information, session and security logs, and cookies used to keep you signed in.

B. How we collect it

  • Directly from you. Through forms, account setup and your use of the platform.
  • From an inviting organisation. Where a customer or partner organisation invites you to join.
  • Automatically. Technical and usage data generated as you use the platform.

C. Why we collect and use it

To provide the service (accounts, coordination, matching, tracking, verification and chain-of-custody records); to keep the platform secure (authentication, MFA, abuse prevention and audit); to communicate with you (service notifications, support, and — with your consent or an opt-out — updates); for aggregated, de-identified analysis and product improvement; and to meet legal and regulatory obligations, including cooperating with waste-tracking or reporting where required.

D. Disclosure of personal information

  • To other participants. Your organisation’s identity, and the sites it collects from and delivers to, are visible to counterparties who can act on the work — including carriers viewing available loads and carriers invited to quote. Personal contact details are not published in these views; participants exchange them through the platform’s messaging where a movement requires it. Commercial terms are not shared between competing participants.
  • To service providers. Hosting, storage, email delivery and similar providers engaged to operate the platform, under confidentiality obligations.
  • To scheme owners. Where a scheme applies, limited (often read-only) scheme-owner visibility.
  • For legal reasons. Where required by law or to regulators.
  • No sale. We do not sell personal information.

E. Where your information is stored

We host platform data with reputable cloud providers. Our platform database and file storage are currently hosted in Singapore; some service providers who support the platform (for example email delivery) may also process data in the United States. Where a suitable Australian hosting region is available for a service we use it, and we will update this policy if our hosting locations change. In all cases we apply access controls, encryption and contractual safeguards so your information is protected to a comparable standard, and we take reasonable steps to ensure overseas recipients handle it consistently with the Australian Privacy Principles.

F. Data security

  • Safeguards. Encryption in transit and at rest, access controls and row-level security, multi-factor authentication, and restricted staff access.
  • Data breaches. We operate under the Notifiable Data Breaches scheme and will assess and notify eligible breaches to affected individuals and the OAIC.

G. Access, correction & retention

  • Access & correction. You can ask us to access or correct your personal information (APP 12 and 13). We take reasonable steps to keep it accurate and up to date.
  • Export. While your account is active you can view your organisation’s records in the platform, and export the reporting data available to your account type. If you need a copy of your personal information in another form, ask us and we will provide it.
  • Retention. We keep records while your account is active and for as long as they are needed for the service, its chain-of-custody purpose, or our legal and regulatory obligations. We do not keep personal information longer than we need it, and you can ask us to delete personal information that is no longer required. Some records must be retained for longer where the law requires it.

H. Cookies & choices

  • Cookies. We use authentication and session cookies. We do not use third-party advertising trackers.
  • Direct marketing. You can opt out of updates at any time. Electronic messages comply with the Spam Act 2003 (Cth).

I. Complaints & contact

To reach our privacy contact, or to make a privacy complaint, email hello@tidalshift.com.au. If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

J. Changes

We may update this policy from time to time. The current version and its effective date are shown at the top of this page.

Questions? Get in touch. See all our legal documents, including the Terms of Use, Privacy Policy, Subscription Terms and Standard Services Framework.