Privacy Act 1988 (Cth)
Privacy Policy
Effective date: 18 August 2026 · Version 1.1 · Last updated: 21 August 2026
Operator legal name, ABN, postal address and Privacy Officer email are not published yet. This policy describes what the product actually does. Do not treat the missing identity block as an incorporated entity. Complete it before a public paying launch.
1. Who we are
This Privacy Policy applies to the Harbour Payday Super calculator and practice workspace (“Harbour”, “we”, “us”, “our”). The operating company has not been named on this page.
Privacy Officer contact will be published here once the operating entity is registered.
We are committed to complying with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
2. Scope
This policy covers personal information we collect via the website, the public calculator, sign-in, the practice workspace, and any related services.
The public calculator runs entirely in your browser. Pay figures you enter on the public calculator are not transmitted to or stored by us unless you choose to sign in and save a draft or client record. The public calculator does not need an account. Analytics may still run on /.
Live sign-in is Clerk email magic link only. The account identifier is the email you type into Clerk. Organizations auto-create. No social providers (Google, Microsoft, or X) are offered.
Live processors: Clerk (authentication), Supabase Sydney ap-southeast-2 (signed-in book), PostHog US (product analytics: pageview and button clicks with path and button_id only; replay off), and this host (Grok Build / Vercel). Sentry is not a live processor on this build.
3. What we collect
- Clerk email — the address you type for magic-link sign-in. That email is the account identifier.
- Optional client label — a name you type for a saved draft. It is a label, not a Tax File Number. Harbour does not store TFNs.
- Calculation envelope — Qualifying Earnings day, amount typed, first-contribution flag, statutory due, latest safe, this payday SG, skipped days, rule pack version — when you save a draft (session tab or signed-in Sydney book).
- Optional rejection / resubmit notes — attempted pay date, reject reason, who recorded, when recorded, resubmit date, resubmit note — only if you type them.
- Product analytics — PostHog US: page path and button id only. Session replay is off. We do not send Qualifying Earnings amounts, payday dates, SG dollars, TFNs, client labels, or emails as event properties.
We do not collect Australian Business Numbers (ABNs), pay frequency, or headcount on this product. Contact and Privacy Officer email are not yet published.
Full legal text
4. How we collect personal information
- Directly from you when you enter data or save drafts.
- From Clerk when you complete an email magic-link sign-in (the email you typed; no Google, Microsoft, or X sign-in).
- Automatically via essential Clerk session cookies for magic-link sign-in, and via PostHog for anonymous pageviews and named button clicks (see Cookies).
We collect only what is reasonably necessary for the functions of the Service.
5. Why we collect and how we use personal information
Primary purposes under the APPs:
- To provide the calculator and multi-client practice workspace.
- To authenticate your account and maintain signed-in sessions.
- To save, retrieve, purge and export your drafts and working papers.
- To improve the accuracy, security and usability of the tool.
- To respond to your enquiries and exercise or defend legal rights.
- To comply with our legal obligations.
We do not sell personal information.
AI use: Super Guarantee numbers are produced by a local deterministic engine. Public calculator inputs stay in your browser and are not sent to an AI model. We do not currently send signed-in workspace data to an AI processor (none). We do not use your data to train models.
6. Disclosure of personal information
We may disclose personal information to:
- Service providers who assist in operating the platform (hosting, authentication, analytics, signed-in storage) under contracts that require them to protect the information and use it only for the contracted purpose. Live processors: Clerk (authentication, email magic link); Supabase Sydney ap-southeast-2 (signed-in book); PostHog US (product analytics); this host (Grok Build / Vercel).
- Clerk, for email magic-link authentication. We do not use Google, Microsoft, or X as sign-in processors.
- Error monitoring: none published. Sentry is not a live processor on this build.
- Professional advisers, or as required by law (for example a court order or regulator).
We do not disclose to third parties for their own marketing.
7. Overseas disclosure
Live processors include Clerk (authentication), PostHog US (analytics), and this host (Grok Build / Vercel), which may be outside Australia. Signed-in book data is stored in Supabase Sydney (ap-southeast-2). Where we disclose personal information to an overseas recipient we take reasonable steps to ensure the recipient does not breach the APPs in relation to the information (APP 8), or we otherwise comply with the Privacy Act. We do not invent Microsoft or Google as processors.
8. Security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps include:
- Encryption in transit (TLS) for the hosted service.
- Access controls and authentication for signed-in workspace data.
- Fail-closed tenant isolation on stored practice records.
- Stored practice calculations are kept 90 days. This host does not run a scheduled purge yet. Session tab saves are lost on refresh.
No method of transmission or storage is 100% secure. You remain responsible for the security of your own devices and credentials.
9. Retention
- Signed-in calculation payloads and drafts are kept 90 days. This host does not run a scheduled purge yet. Do not treat the 90-day line as a completed automatic job.
- Session tab saves (Save to this tab) are lost on refresh, another browser, or another device.
- Account information is retained while your account is active and for a reasonable period thereafter for security, dispute resolution and legal compliance.
- You may delete individual clients or request account deletion at any time.
10. Your rights under the APPs
Under the Australian Privacy Principles you have the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading personal information.
- Make a complaint about our handling of your personal information.
Contact the Privacy Officer once published below. We will respond within a reasonable period (generally 30 days). We may need to verify your identity.
If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (OAIC):
- Website: https://www.oaic.gov.au
- Phone: 1300 363 992
- Online complaint form on the OAIC website
11. Cookies and analytics
Essential. Clerk session cookies so email magic-link sign-in works.
Product analytics. PostHog (US cloud, project Harbour public calculator). Pageview and button clicks with path and optional button_id only. Replay is off. No Qualifying Earnings, payday, SG dollars, TFN, client label, or email as event properties. Identify, if used, is the Clerk user id only — never an email. The public calculator does not need an account. Analytics may still run on /.
You can control cookies through your browser settings. The public calculator does not require an account for core calculation, CSV, or PDF.
12. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published at this URL with the effective date and version number. Material changes will be notified via the Service or email where appropriate.
13. Contact
Privacy Officer
Operating entity not yet published
Postal address not yet published
Email: not yet published