This Privacy Policy explains how Brave Labs Pty Ltd (ABN 20 700 483 816) (“Chlor”, “we”, “us”) handles personal information when you use our pool service management software (the “Service”) and the chlor.app website. We handle information under this policy and applicable Australian privacy law. The Australian Privacy Principles (APPs) inform our privacy practices; statutory rights and the Notifiable Data Breaches scheme apply where the Privacy Act 1988 (Cth) covers the relevant entity and activity.
1. Information we collect
We collect the following categories of personal information:
- Account information: your name, email address, phone number, business name, ABN, password hash, and the role you hold inside your business (owner, technician).
- Customer records you upload: names, email addresses, phone numbers, property addresses, gate codes, access notes and notification preferences for your pool service customers.
- Pool service data: water chemistry test results, chemical dosing records, equipment details, service history, photos taken during a service visit, and free-text technician notes.
- Billing and payment information: subscription plan, billing interval, customer invoice and transaction history. Paddle processes Chlor subscription payments. Stripe processes payments your customers make through Stripe Connect. Payment card numbers and bank account details are collected and stored by the relevant payment provider and are never stored on Chlor servers.
- Connected accounting data: if you choose to connect Xero or QuickBooks, we read organisation details, account and tax settings, and customer contacts needed to configure and operate the integration. We send the customer details, invoices and payment records you direct Chlor to synchronise. We also store provider identifiers, mappings, sync status and encrypted OAuth credentials needed to maintain the connection.
- Communications: emails and SMS we send on your behalf to your customers, support tickets, and onboarding survey responses.
- Technical data: browser and device information, requests, error diagnostics and performance traces used for hosting, debugging and security. These records can contain personal information; they are not all anonymous analytics. We filter diagnostic data to reduce personal information and secrets. Separate aggregate page-use analytics are provided by Vercel Analytics. When you allow measurement, we also use PostHog for product analytics after you sign in, and Google Ads to measure whether an advertisement led to a Chlor beta request. Google Ads sets advertising cookies on chlor.app for that conversion measurement. We do not use those tools to build remarketing audiences, and we do not send hashed emails to Google as Enhanced Conversions.
- Location data: when you use route optimisation or map features we process the property addresses you have entered. If you request a route from your current location and grant your browser permission, we also use that foreground location for the route. We do not collect background location.
2. How we collect it
We collect personal information directly from you when you sign up, configure your account, import customer data, take a water test, send a message through the platform, or contact support. We also collect technical data automatically when you use the Service. Where you upload your customers’ personal information, you must be entitled to collect, use and share it for the requested service and provide any notices or obtain any consents required by applicable law.
3. Why we collect it
- To provide, operate and maintain the Service.
- To manage Chlor subscriptions through Paddle and customer invoicing and payments through Stripe Connect.
- To connect an accounting provider you select and synchronise supported customer, invoice and payment records with that provider.
- To send transactional communications on your behalf (appointment reminders, on-the-way SMS, service-complete reports, invoice delivery and payment reminders).
- To provide customer support and respond to enquiries.
- To improve the Service through product analytics, debugging and security monitoring.
- To comply with Australian legal and regulatory obligations (including tax, anti-fraud and law-enforcement requests).
4. Disclosure to third parties
We disclose personal information to the following third-party service providers as needed for the features you use. Optional integrations and features only receive the relevant data when enabled:
- Supabase Pte. Ltd — database, authentication and file storage. During Chlor’s private beta, the Production project is hosted in the AWS ap-northeast-1 region (Tokyo, Japan). We plan to migrate Production to AWS ap-southeast-2 (Sydney, Australia) before public launch.
- Paddle.com Market Ltd — Chlor subscription payment processing, subscription management and tax compliance as Merchant of Record.
- Stripe Payments Australia Pty Ltd — used by your customers when paying invoices issued through Chlor (Stripe Connect). Stripe handles payment data under its own privacy terms and also processes data to provide the integration.
- Xero Limited — optional accounting integration for organisation and account setup, customer contacts, invoices and payments.
- Intuit Inc. — optional QuickBooks Online accounting integration for company and tax setup, customers, invoices and payments.
- Resend — transactional email delivery (signup confirmations, invoices, reports, password resets).
- Twilio — SMS delivery for appointment reminders and on-the-way notifications.
- Google Maps Platform — address autocomplete, geocoding and route optimisation.
- Vercel Inc. — application hosting and aggregate web analytics, and AI Gateway for the operational alert observer described below.
- PostHog, Inc. — product analytics for signed-in Chlor use (page and named product events). Hosted on PostHog Cloud EU in Germany. Session replay and click autocapture are off.
- Google LLC — Google Ads conversion measurement on public marketing pages only. Used to attribute a beta request to an ad click. Not loaded in the dashboard, customer portal, or mobile app.
- Sentry — application error diagnostics, performance monitoring and operational alerts. Session replay is disabled.
- PowerSync — synchronisation of authorised workspace data for offline mobile use when mobile sync is enabled. The Sydney Staging service is connected; Production sync is not yet connected.
- Slack and incident.io — operational alert delivery, incident coordination and operator notification. Alerts are designed to minimise customer information.
- OpenAI, through Vercel AI Gateway — analysis of filtered operational alert summaries to assist human diagnosis. The observer handles alerts from both Production and Staging; it is not a general-purpose customer-record assistant and does not make autonomous changes to customer records or payments.
We may also disclose personal information where required by Australian law, in response to a lawful request from a regulator or law-enforcement agency, or where necessary to prevent serious harm.
5. Overseas data transfers
During Chlor’s private beta, operational data may be stored in Japan through our current Supabase Production project. We plan to migrate that project to Sydney, Australia before public launch. Sydney hosting does not mean all information stays in Australia. Payment, communications, monitoring and hosting providers may process information overseas through their infrastructure, support teams and subprocessors, including in the United States and Europe. A provider’s headquarters is not necessarily its processing location. Contact us for information about the providers relevant to your use of Chlor. We must meet applicable cross-border privacy obligations, including APP 8 where it applies; this policy is not a statement that every provider processes data only in Australia or has been certified as APP-compliant.
Resend sends our email from Tokyo, Japan, but stores email content and delivery logs in the United States. Our Sentry organisation stores diagnostic events in the United States, and our Slack workspace uses default United States storage. These are verified service locations, not an exhaustive list of every support or subprocessor location.
Supabase also identifies the United States and Singapore as possible transfer destinations beyond project hosting. Our Twilio SMS service uses its United States region; this does not restrict every carrier, account or support activity to that country. When you connect Xero, Xero hosts its online accounting services in the United States.
Our PowerSync Staging sync infrastructure is in Australia. PowerSync lists United States providers for account management, authentication and system operations, and states that those supporting providers do not process customer database sync payloads. This does not mean all PowerSync account information stays in Australia.
Google Maps may process information on servers outside your country. Under its terms and privacy policy, Google may use and retain service data, including search terms, IP addresses and coordinates, to provide and improve Google products and services. We do not have a service-specific country list for our Maps APIs and do not promise Australian-only processing.
Paddle lists the United States for cloud hosting and payment services, Ireland for analytics, and the United Kingdom, Germany, Belgium and the Netherlands for other supporting services. Vercel identifies the United States as its primary processing location and permits global processing. Its provider register also lists Spain for analytics and the United Kingdom for support. These are provider-published locations, not confirmation that every listed service receives your information.
PostHog Cloud EU stores product-analytics events in Germany (AWS eu-central-1). Google Ads conversion tags send click and conversion data to Google, which processes advertising data in the United States and other countries where Google operates. We do not have an Australian-only processing commitment for Google Ads.
Intuit may store and process personal information in the United States and other countries where its group or service providers operate. We do not have an Australian-only hosting commitment for QuickBooks Online. The information shared depends on the accounting connection and services you choose.
6. Data retention
We retain personal information only while it is reasonably needed to provide the Service, meet a legal obligation, resolve a payment or dispute, or protect the Service from fraud and misuse. A workspace deletion request has a minimum 30-day cancellable grace period. We do not report a request as completed until outstanding obligations are resolved and the approved process has destroyed, de-identified or put the affected information beyond ordinary use.
During Chlor’s private beta, irreversible workspace deletion is disabled while the Australian retention and anonymisation policy is independently approved and implemented. A blocked request remains visible and cancellable; Chlor does not tell you that the workspace has been deleted. You may export your workspace data while you still have access.
Disconnecting stops future synchronisation and clears Chlor’s stored OAuth credentials for that connection. It does not delete records already created in Xero or QuickBooks. Those records remain under your control in the connected provider and are subject to that provider’s retention rules.
Brave Labs may retain the minimum financial and transaction evidence it is legally required to keep, generally for seven years after the relevant transactions are completed. We do not treat an entire operational workspace as a financial record. Data remaining in encrypted backups is kept beyond ordinary use until the provider’s normal backup cycle expires; the final retention schedule will be published before general availability.
7. Security
We implement reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, modification and disclosure. Measures include TLS for connections to Chlor and its service-provider APIs, encryption at rest, role-based access controls, least-privilege service accounts, audit logging and regular dependency security reviews. No internet-facing system is completely secure; we cannot guarantee absolute security.
Email and SMS are not end-to-end encrypted. Our email provider attempts a TLS connection to the receiving mail server, but email delivery may proceed without TLS if that secure connection cannot be established. Avoid sending sensitive information through these channels.
8. Notifiable data breaches
We promptly assess suspected data breaches and take steps to contain harm. Where the Notifiable Data Breaches scheme applies and there are reasonable grounds to believe an eligible data breach has occurred, we notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. Our internal targets are initial assessment within 24 hours and notification within 72 hours where required; these are response targets, not statutory waiting periods. The scheme requires reasonable steps to complete a suspected-breach assessment within 30 days, and we aim to do so sooner.
9. Cookies and analytics
We use a small number of strictly-necessary cookies for authentication, session management and CSRF protection. Vercel Analytics measures aggregate page views without setting personal-data cookies and without tracking you across other websites.
If you continue with measurement, we also use Google Ads conversion cookies (including first-party _gcl_* cookies on chlor.app) to record whether an ad click later became a beta request, and PostHog first-party analytics cookies to recognise a signed-in user for product analytics. These are optional and nothing runs until you choose. On your first visit we ask, wherever you are, with advertising measurement and product analytics as separate choices you can accept or refuse independently. You can change either at any time via Measurement settings in the footer. Conversion cookies are not used to build remarketing audiences, and Google Ads tags are not loaded on authenticated product pages.
10. Children
Chlor is a business-to-business product and is not directed at persons under 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us so we can delete it.
11. Your requests and rights
You can contact us to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate or out-of-date information.
- Request deletion of your personal information, subject to legal retention requirements.
- Withdraw consent to non-essential processing (such as marketing emails) at any time.
- Request a copy of the data you have entered, in a common machine-readable format (we will provide it on request — see section 12).
Where applicable, APPs 12 and 13 provide statutory access and correction rights, subject to their exceptions. Deletion and export requests are also handled under our product processes and section 6; they are not a claim of an unconditional statutory right to erasure or data portability.
If a pool service business entered your information, contacting that business is usually the quickest way to correct its service records. You can also contact us about information we hold. We will coordinate with the business where appropriate and remain responsible for our own handling of your information. Each business must determine its own privacy obligations; not every small business is an APP entity.
12. How to contact us or make a complaint
For any privacy enquiry, access request or complaint, please email privacy@chlor.app or write to us at:
Privacy Officer
Brave Labs Pty Ltd
21 Crombie Avenue, Bundall QLD 4217, Australia
We will acknowledge your complaint within 7 days and respond substantively within 30 days. If you are not satisfied with our response, you may ask the Office of the Australian Information Commissioner about complaints within its jurisdiction at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5288, Sydney NSW 2001.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “last updated” date. Material changes will also be notified to account holders by email at least 14 days before they take effect.
This policy is governed by the laws of Queensland, Australia. See also our Terms of Service, Refund Policy and Acceptable Use Policy.