Policy / Privacy
Privacy Policy
Effective 27 May 2026
Draft · Under legal review
This document is provided in good faith as the platform's best statement of current practice, but has not yet been finalised by Australian legal counsel. The version that becomes binding will be linked here and dated accordingly.
Who we are
DroneAssess (ABN 57 698 846 212) operates a drone-based roof inspection platform. We connect insurers and builders who need property roof assessments with independent drone pilots who can capture them, then deliver an assessment report.
This policy explains what personal information we collect from users of our website, mobile app, and connected services; how we use and disclose it; and the rights you have under Australian privacy law (the Privacy Act 1988and the Australian Privacy Principles, “APPs”).
Who this policy applies to
We collect information from three groups, and the specifics differ:
- Drone pilots — independent contractors in our network who self-select and complete jobs.
- Builders & claims handlers— customers who request roof inspections on properties they're working on.
- Insurers — customers who request roof inspections to support a claim, and whose claim references may appear on jobs.
We also process information about property owners and occupantsindirectly — for example, the address of an inspection, photos of their roof, and the resulting damage report. Property owners aren't our direct customers, but the protections in this policy still apply to information we hold about them.
What we collect, and when
Drone pilots
- Account: name, email, phone, password (hashed).
- Onboarding: Australian Business Number (ABN), bank account details for payouts, drone equipment + thermal capability, tier.
- Location: your device location while you're using the app to find nearby jobs and to GPS-stamp uploaded photos.
- Activity: jobs you've claimed, accepted, declined, started, completed, or unclaimed; status timestamps; admin approval state.
Builders, claims handlers, and insurers
- Account: name, email, phone, role within your organisation.
- Organisation: business name, the team members you've invited, your notification preferences.
- Jobs you submit: property address, scheduled date, internal reference numbers, claim numbers, the insurer name (where you tell us), and any free-text notes.
Photos and reports
- Photos uploaded by pilots from the inspection site. These include full views of the property roof and surroundings, not just close-ups of damage. We retain the EXIF metadata (latitude / longitude / capture time) embedded in the image file because we use it for fraud-detection and to verify on-site presence.
- Captions / notes the pilot writes about each photo, and any internal QA notes from our review team.
- AI-generated component inventories, damage findings, and the human reviewer's edits to those.
- The final assessment report (PDF) and its delivery history.
Technical information we collect automatically
- Device + browser identifiers, IP address, app version, OS version, and crash diagnostics when something fails.
- Cookies and similar tokens necessary to keep you signed in. We don't use third-party advertising or tracking cookies.
Why we collect it (APP 3 + APP 6)
We use your information to:
- Run the platform — match jobs to pilots, deliver reports.
- Verify that pilots are registered businesses with valid bank details before paying them.
- Detect fraud — for example, we may compare a photo's GPS EXIF against the job address to confirm the pilot was actually on site.
- Notify you about job status changes you've opted into (you can turn email alerts off in your account settings).
- Improve our automated assessment models. Inspection photos and the corrections our reviewers make to AI-generated findings form part of our training data. Photos are linked to the job they came from (which carries the property address); we don't share or sell training data outside the platform, and we don't train on your account or contact details.
- Comply with our legal and tax obligations.
We don't use your information for purposes other than these without telling you and (where the law requires) getting your consent.
Marketing communications
The emails we currently send are transactional — invitations, job-status updates, password resets. We don't send marketing or newsletter emails today. If we ever do, every such message will identify the sender and include a working unsubscribe mechanism in line with the Spam Act 2003 (Cth).
Who we share information with
We use the following service providers to run the platform. Each receives only the information needed to do their job, and all are bound by a contractual obligation to protect it:
- Supabase — database, authentication, file storage. Hosted in AWS (region: Sydney for AU data sovereignty).
- Vercel — web application hosting + edge network.
- Anthropic— AI processing of inspection photos (to detect roof components and damage) and uploaded work-order documents (to extract the job details). These are transmitted to Anthropic via API and are not used to train Anthropic's models. Anthropic's own privacy policy applies to that processing.
- Replicate — runs additional AI models that help us identify and outline roof components in photos. Photos are transmitted to Replicate via API.
- Resend — sending transactional emails (job status updates, invites, account confirmations).
- Google Maps Platform — primary address autocomplete and geocoding when you type an address.
- Mapbox and OpenStreetMap / Nominatim — geocoding fallbacks when the primary geocoder fails or returns no result. Only the address text is sent.
- Expo / EAS — diagnostics, over-the-air updates, and (in future) push-notification token relay for our mobile app.
- Apple App Store / Google Play — distribution of our pilot mobile app.
We share information between platform users only as the workflow requires:
- Pilots see the job address, contact details for the on-site contact, and any notes from the customer.
- Builders and insurers see job status and the final report. They do notsee the pilot's identity.
- Our internal review team sees photos and the AI's output so they can verify findings before a report is delivered.
We don't sell your personal information to anyone, ever.
Where your data is stored (APP 8)
Your information is stored on servers located in Australia where we've been able to choose a region (Supabase / AWS Sydney). Some service providers — notably Anthropic, Vercel, and the email infrastructure — process data outside Australia, predominantly in the United States. By using the platform you consent to this cross-border transfer for the limited purposes described above.
How long we keep it (APP 11)
We keep job-related information (jobs, photos, reports) for as long as you have an active account, plus seven years afterwards to meet Australian record-keeping obligations relevant to insurance work. Account information is kept while your account is active and deleted within 30 days of account closure unless we're required to retain it for legal or accounting reasons. You can ask us to delete information sooner — see section 9.
How we protect it (APP 11)
We take reasonable steps to protect your information from loss, unauthorised access, modification, or disclosure. These include:
- Encryption in transit (TLS) on every API and storage call.
- Encryption at rest for the database, file storage, and on-device authentication tokens (iOS Keychain / Android KeyStore).
- Row-level security in the database, so users only see data they're authorised to see.
- Access controls and audit logging for our internal review team.
No system is perfect. If we ever experience a data breach likely to result in serious harm to you, we'll notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
Your rights (APP 12 + APP 13)
You can ask us, at any time, to:
- Tell you what personal information we hold about you.
- Correct information that's wrong or out of date.
- Delete your account and the personal information attached to it (subject to the retention requirements in section 7).
- Stop sending you notification emails — also doable in your account settings.
- Provide a portable copy of the information you've given us, in a common machine-readable format.
Email privacy@droneassess.com.au to make any of these requests. We'll respond within 30 days.
Children
The platform isn't intended for use by anyone under 18. We don't knowingly collect personal information from children. If you believe we have, contact us and we'll delete it.
Changes to this policy
We may update this policy as the platform evolves. The effective date at the top changes when we do. For material changes — new categories of data, new third-party processors, or any narrowing of the rights described here — we'll notify active users by email or in-app notice at least 14 days before the new version takes effect.
Contact us / make a complaint
For privacy questions, requests under section 9, or to make a complaint, contact:
DroneAssess
12/2 Classic Way, Burleigh Waters QLD 4220
privacy@droneassess.com.au
If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.
