Privacy policy.
What data we collect, why we collect it, who helps us process it, and how long we keep it. Plain English first, aligned to the Australian Privacy Principles.
This policy explains the information HoistAI Pty Ltd handles to run Hoist, process currently available free checks, support customers, keep records verifiable, and administer any legacy billing relationship. Normal customer checkout and per-call charging are unavailable. Stripe-related language below covers retained legacy records and any future billing reactivation.
Only what the service needs
Account, search, technical, and any retained legacy billing data are handled for service delivery, support, and legal recordkeeping.
No advertising resale
We do not sell personal information or share search history for advertising.
Export, correct, delete
Records are exportable, and deletion requests are honoured unless law requires retention.
Plain-English summary
- We collect the information needed to run your account, process currently available free checks, support you, and keep records verifiable. No current workflow charges you.
- We don't sell, share, or use your search history for marketing.
- We don't search individual grantors. Ever.
- Your records are exportable. We delete on request unless a law requires us to keep something, or the request touches our security/fraud-prevention audit trail (see "How long we keep it" below).
- Records and certificates stay in Australia where we control storage. Some subprocessors operate globally (see /trust/residency).
Who we are
HoistAI Pty Ltd, ABN 11 695 718 659, 81–83 Campbell Street Surry Hills NSW 2010. "We", "us", or "Hoist" in this policy means HoistAI Pty Ltd trading as Hoist.
What we collect
Account information
- Email address (for sign-in and notifications)
- Display name and organisation (optional; for Due Diligence Record branding)
- Role (broker, IP, dealer, etc. - optional, helps us prioritise features)
Legacy and future billing information
Currently available workflows are free and unmetered, and normal customer checkout is unavailable. If you have a legacy billing relationship, or if paid checkout is reactivated in the future, the following categories may be handled:
- Any card or BPay payment-instrument details are held by Stripe; Hoist does not see or store the payment instrument details.
- Billing address, when needed for a legacy or future tax invoice.
- ABN, when needed for legacy or future GST treatment.
Search activity
- Available checks you run, including the ABN, timestamp, reference, and result status. Future PPSR contract inputs such as an ACN or serial number currently fail closed without register dispatch or a result.
- Records and certificates you generate.
- Connection and account usage statistics
- Verification log hashes that let historic records be checked without storing personal details in those hashes.
Technical
- IP address (request-time only; a full IP address is not stored in a Hoist-owned database. A truncated network-prefix (not a full IP) is retained in our security audit trail for session-fingerprinting and abuse detection, for the audit trail's retention period described below. Standard connection-level request logs beyond that are handled at the Cloudflare platform level.)
- Browser, SDK, or connected-tool user agent
- Errors (sent to Sentry AU, with PII scrubbed pre-send)
Connected tool context
When you access Hoist through an AI tool or connected client, we may receive only the details needed to complete that request:
- The client identifier for the tool or app making the request.
- The fields submitted by the AI agent for an available check. A future PPSR contract may receive an ACN or serial number, but Hoist currently rejects the request without a price, register dispatch, result, or certificate.
- We do not receive or store your surrounding AI conversation, prompt history, or model reasoning. We only receive the fields needed for the tool call.
- If your AI tool sends extra request metadata, such as a session identifier, any of it captured in our product-analytics events follows the same 30-day observability-log retention described below.
Why we collect it
- To provide the service. Run currently available free checks, generate records, support your account, and contact you when something breaks.
- To keep required billing records. Retain legacy billing and tax records, and process a payment only if normal checkout is reactivated in the future with terms disclosed before purchase.
- To meet legal obligations. Keep tax records and support applicable legal obligations. Hoist has no current PPSR dispatch and makes no current AFSA reseller-reporting claim.
- To improve the product. Aggregated usage statistics inform what we build next. We do not share per-customer breakdowns externally.
Who we share with
Subprocessors only. Full list at /trust#subprocessors. Notably:
- AFSA - Hoist does not currently send PPSR preview or paid-search inputs to AFSA; PPSR requests fail closed. AFSA would be a source operator only after separately proved production launch.
- Stripe - to retain or process records for legacy billing relationships and, if normal checkout is reactivated in the future, to process authorised payments. Stripe is not used to charge currently available workflows.
- Cloudflare - for compute/storage.
We do not sell or share personal information for advertising. We do not share with data brokers.
How long we keep it
- Records and certificates: 30 days after account closure, except billing and tax records tied to a legacy or future billing relationship, which we keep for 7 years after that relationship ends to meet AU tax requirements (see below).
- Verification log entries (hashes only): retained indefinitely so historic verification works.
- Account and billing metadata kept for tax purposes: 7 years after closure (AU tax requirements).
- Product-analytics logs (per-event records keyed to a pseudonymous identifier, reported publicly only in aggregate): 30 days, enforced by a database constraint with no incident-investigation hold. Standard connection-level request logs are handled at the Cloudflare platform level on Cloudflare's own retention schedule, not a Hoist-owned 30-day database.
- Security/audit trail (auth, webhook, and account-security events, including a truncated IP network-prefix used for abuse detection): kept for a 90-day minimum operator proof horizon. No deletion path exists in our application code today, so this is excluded from user-initiated deletion requests, consistent with how most privacy policies treat fraud- and abuse-prevention logs, on the basis of our legitimate security interest.
Your rights
Under the Australian Privacy Principles (APPs):
- Access - request a copy of your personal information. Self-serve in dashboard or use the current contact route at /contact/.
- Correction - fix inaccurate information.
- Deletion - request deletion (subject to legal retention obligations and our security/audit-trail carve-out described in "How long we keep it" above).
- Complaint - to us first; then the OAIC at oaic.gov.au if unresolved.
Cookies
We use first-party cookies for authentication (Clerk session) and a Cloudflare WAF cookie. No third-party advertising cookies. No tracking pixels. Detail at /privacy/cookies.
International transfers
Most data stays in AU. Some subprocessors process in the US (Stripe, Postmark, Clerk). See /trust/residency for the per-category breakdown.
Updates
Material changes to this policy go to all account holders by email and appear in /changelog tagged privacy. The "Last updated" date at the top of this page moves whenever any change ships.
Need a privacy or account answer?
Use the contact route for privacy rights, account access, billing, and setup questions.
Contact
Privacy officer: /contact/. Postal: HoistAI Pty Ltd, Attn: Privacy, 81–83 Campbell Street Surry Hills NSW 2010.
