Privacy Policy

Last updated 1 July 2026

This policy explains how Tidal Shift handles personal information across our website, forms and platform. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

We generally do not collect sensitive information. If we ever need to, we will do so only with your consent.

A. Information we collect

  • Account & user information. Your name, email, role and organisation; a hashed password; multi-factor authentication and trusted-device records.
  • Enquiry information. Details you submit through our contact or request-access forms.
  • Operational data. Load, movement and coordination records that may include the names and contact details of site contacts and drivers.
  • Photos & evidence. Custody photos and their metadata. Where a device provides it, we retain the capture location and time as part of the chain-of-custody record.
  • Technical & usage data. IP address, device and browser information, session and security logs, and cookies used to keep you signed in.

B. How we collect it

  • Directly from you. Through forms, account setup and your use of the platform.
  • From an inviting organisation. Where a customer or partner organisation invites you to join.
  • Automatically. Technical and usage data generated as you use the platform.

C. Why we collect and use it

To provide the service (accounts, coordination, matching, tracking, verification and chain-of-custody records); to keep the platform secure (authentication, MFA, abuse prevention and audit); to communicate with you (service notifications, support, and — with your consent or an opt-out — updates); for aggregated, de-identified analysis and product improvement; and to meet legal and regulatory obligations, including cooperating with waste-tracking or reporting where required.

D. Disclosure of personal information

  • To other participants. Under our neutral model, identifying details are de-identified in cross-organisation views by default and revealed only where our identity-reveal rules apply (for example, once a booking is confirmed between you and a counterparty).
  • To service providers. Hosting, storage, email delivery and similar providers engaged to operate the platform, under confidentiality obligations.
  • To scheme owners. Where a scheme applies, limited (often read-only) scheme-owner visibility.
  • For legal reasons. Where required by law or to regulators.
  • No sale. We do not sell personal information.

E. Where your information is stored

We host platform data with reputable cloud providers. Where a suitable Australian hosting region is available we use it; where it is not, we store and process data in the nearest appropriate jurisdiction. In all cases we apply access controls, encryption and contractual safeguards so your information is protected to a comparable standard, and we take reasonable steps to ensure overseas recipients handle it consistently with the Australian Privacy Principles.

F. Data security

  • Safeguards. Encryption in transit and at rest, access controls and row-level security, multi-factor authentication, and restricted staff access.
  • Data breaches. We operate under the Notifiable Data Breaches scheme and will assess and notify eligible breaches to affected individuals and the OAIC.

G. Access, correction & retention

  • Access & correction. You can ask us to access or correct your personal information (APP 12 and 13). We take reasonable steps to keep it accurate and up to date.
  • Export. Your data is available to you as a PDF export alongside your other records while your account is active.
  • Retention. We retain records for up to one year after they are no longer required for the service or its chain-of-custody purpose, after which they are expunged (deleted or de-identified). Legal obligations may occasionally require a longer period.

H. Cookies & choices

  • Cookies. We use authentication and session cookies. We do not use third-party advertising trackers.
  • Direct marketing. You can opt out of updates at any time. Electronic messages comply with the Spam Act 2003 (Cth).

I. Complaints & contact

To reach our privacy contact, or to make a privacy complaint, email hello@tidalshift.com.au. If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

J. Changes

We may update this policy from time to time. The current version and its effective date are shown at the top of this page.

Questions? Get in touch. See also our Terms of Use, Privacy Policy and Subscription Terms.