Legal

Privacy Policy

Effective 23 September 2026

1. About this policy

J.M Bausch & F.M Mina trading as InHaus Digital (ABN 87 260 336 796) is an Australian digital marketing agency. This policy explains how we handle personal information on the InHaus Digital platform (the dashboard, tracking and tools we provide to our clients) and in running our services. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

2. Whose information, and our role

Our clients. The people who log in (name, email address, a hashed password and their role) and the business and billing details we need to provide our services. We are responsible for this information.

Our clients’ customers and website visitors. When a client connects their store and marketing accounts, the platform processes information about that client’s customers on the client’s behalf. The client decides what is collected and why. If you shopped with or contacted one of our clients, please contact that business first; we will help them respond.

3. What the platform collects

  • From a client’s store (Shopify or WooCommerce): orders, the customer on each order (name, email address, phone number and address), products and refunds.
  • From the tracking on a client’s website: pages viewed, the referring site, campaign tags and ad click IDs, a first-party visitor ID stored in the browser, IP address, device and browser details, and details a visitor types into a checkout or enquiry form.
  • From connected ad accounts (Meta, Google, Pinterest): campaigns, spend, clicks, impressions and conversions.
  • From other services a client connects: Klaviyo (email marketing), Xero (profit and loss figures), Microsoft Clarity (visit heatmaps), Slack (notifications), and their help desk and courier accounts where the platform’s support and fulfilment tools are used.

4. How it is used

  • To attribute a client’s sales and enquiries to their marketing channels and report on performance.
  • To send conversions back to the client’s own ad accounts (Meta Conversions API, Google enhanced conversions, Pinterest) when the client has this switched on, so their ads learn from real sales. Email addresses and phone numbers are hashed (SHA-256) before they are sent, as those platforms require.
  • To pass checkout email addresses to the client’s Klaviyo account for abandoned-checkout emails, where set up.
  • To run AI analysis and reports (the Brain) and, where a client uses it, a support assistant that drafts replies to that client’s customers.
  • To operate, secure and improve the platform, and to bill our clients.

We do not sell personal information, and we do not use our clients’ customer data for our own marketing.

5. Who we share it with

Service providers that run parts of the platform for us, each receiving only what it needs:

  • Railway: hosting for the application and its database.
  • Cloudflare: storage for uploaded images and files.
  • Resend: sending the platform’s emails (reports, alerts, invitations and password resets).
  • Stripe: payments for platform subscriptions.
  • Anthropic: the AI model behind the Brain, reports and the support assistant. It receives what each feature needs, such as campaign and order figures, or the customer message being answered.
  • Google (Gemini): image generation in design tools, for the clients who use them.

And a client’s own accounts, when connected (Meta, Google, Pinterest, Klaviyo, Xero, Slack, Microsoft Clarity, their help desk and couriers), under the client’s own agreements with those providers.

6. Where it is stored

Several of these providers are based overseas, mostly in the United States, so personal information may be stored or processed outside Australia. We choose providers with strong security practices and send each only what it needs.

7. How long we keep it

For as long as a client’s workspace exists. When an engagement ends and the workspace is deleted, its data is removed from the platform, and backups expire on their normal cycle. Billing records are kept for as long as Australian tax law requires.

8. Security

All traffic to and from the platform is encrypted (HTTPS). Passwords are stored as one-way hashes, and the keys and tokens for connected accounts are encrypted before they are stored. Access is by invitation, and each login sees only the workspaces it belongs to.

9. Access, correction and complaints

You can ask to see or correct the personal information we hold about you by emailing hello@inhausdigital.com.au. If you are a customer of one of our clients, please contact that business first; we will help them respond. If you are not satisfied with how we handle a request or complaint, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

10. Children

The platform is a business service and is not directed at children.

11. Changes to this policy

We will update the date above when this policy changes and tell our clients about material changes.

12. Contact

Questions or requests about personal information: hello@inhausdigital.com.au.