Skip to main content
Scriptshift

Privacy

Privacy policy

What this company holds today, what a released tool would and would not collect, how long anything is kept, and how to make us delete it.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)

1Who we are and what this policy covers

SCRIPTSHIFT TECHNOLOGIES PTY LTD (ACN 698 500 542, ABN 21 698 500 542) is an Australian proprietary company in Western Australia. It builds release and deployment tooling for small software teams. In this document "we", "us" and "our" mean that company, and "you" means whoever is reading it or writing to us.

What this policy covers

  • This website at scriptshift.cc.
  • Email sent to our published address, and our reply to it.
  • Any release tooling this company publishes in future. It is described here before publication so the description exists in advance of the collection rather than being written around it afterwards.

What it does not cover

  • Any website you reach by following a link from ours.
  • The code hosting, cloud and secret management services you already use. Those are your own suppliers under your own agreements, and nothing we do changes them.
  • Anything our tooling reads inside infrastructure you control when you run it. That never reaches us, for reasons set out in the section on roles below.

Where things stand. Nothing has been published. The only personal information this company currently holds is correspondence sent to it, and the request logs kept by the company that hosts this website. That is the honest total. The rights described later are not aspirational for that information: access, correction, deletion and complaint all work today.

2The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

Australian Privacy Principle 1 is the one this document exists to satisfy. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices that ensure it complies with the rest of the principles, and to keep a clearly expressed and up to date privacy policy that says what it collects, how it holds it, how you get access to it and correct it, and how you complain. This page is that policy. The complaints route APP 1 also requires is at section 23, and how a change to this document is published is at section 25.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. SCRIPTSHIFT TECHNOLOGIES PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

3Who decides, and where a handling role would arise

Most business privacy policies split into two roles, one where the organisation decides what happens to personal information and one where it merely acts on somebody else's instructions. Australian law does not use the controller and processor labels the way European law does, but the underlying distinction still matters and it is the clearest way to explain what we do.

Where we decide, and are answerable

For correspondence, for the request logs this website generates, and for any future product telemetry, we decide what is collected and for what purpose. Every obligation in this policy is written for that position, and every right described later is exercisable against us directly.

Where a handling role would arise, and why it does not yet

We would be handling information on your instructions if we hosted your releases, stored your logs, or ran a service your data passed through on its way somewhere else. We do none of those things. The tooling runs on infrastructure you control, reads what you point it at, and sends nothing back to us.

The consequence is worth stating precisely, because it is stronger than a promise. If a release script of yours touches personal information, that information never becomes ours. We cannot access it, we cannot disclose it, we cannot lose it, and we cannot be compelled to produce it, because we never receive it. That is a property of the architecture rather than a commitment in a document, and a property is harder to quietly abandon than a commitment.

If that changes

If a hosted component ever means personal information reaches us on a customer's instructions, this section is rewritten before that component exists, and a written data handling agreement is in place before the first byte arrives. We would also then name every sub-processor in the recipients table below, and commit to notifying customers before adding one.

4What we collect

These tables are the complete list. A category that does not appear in one of them is not collected. Where a table describes something that has not been built, it says so in the table rather than in a caveat somewhere else.

From this website

Personal information generated by scriptshift.cc
CategoryFieldsPurposeKept
Request logsIP address, timestamp, path requested, user agent string, referring page, response codeServing the page and blocking automated abuse. Held by the hosting provider on its own systems rather than exported to usThe provider's own cycle, currently under 30 days
Security cookieA strictly necessary cookie the hosting provider may set, and a clearance cookie if you are shown a challengeTelling automated traffic apart from human traffic30 minutes and up to 30 days respectively

There is no analytics on this website, no advertising, no tracking pixel, no session recording, no heat mapping and no attempt to recognise a returning visitor. There is therefore no consent banner, because there is nothing here that consent would be for. The full reasoning, including why the Australian position differs from the European one, is in the cookie notice.

From correspondence

Personal information you send us by email
CategoryFieldsPurposeKept
Your messageEmail address, the display name your mail client sends, subject line, message body, any attachmentAnswering you, and fixing whatever you told us aboutSupport 24 months, complaints 7 years
Mail metadataDelivery headers your provider attaches, including originating server, routing hops and timestampsDelivering, threading and filtering mail. We do not read these except when diagnosing a delivery failureThe same as the message it belongs to
Privacy request recordThat a request was made, what was asked for, what we did, and the datesBeing able to show that a request was handled within time, which is what APP 12 and APP 13 require of us in practice7 years

What a published product would collect

Nothing is published. The table below is the design intent recorded in advance, so that if a tool does ship, this page is a constraint rather than a later justification.

Design intent for a future release of the tooling
CategoryFieldsPurposeOptional
Crash reportStack trace, tool version, operating system name and versionFixing a defect in the tool itselfYes. Off until switched on, and the prompt says what is sent
Version pingTool version and a coarse platform string, with no identifier of any kind attachedKnowing which versions are still in use before removing support for oneYes. Off until switched on
Licence validationA licence key and the fact that it was checkedEstablishing entitlement, if any part of the tooling is ever licensed rather than freeOnly applicable if you hold a licence

What is deliberately absent from that table. Nothing about your deployment. Not the names of your hosts, not your environment variable names or values, not your commit messages, not the contents of your release file, not the identity of whoever approved it, and not the timing of your releases. A tool that runs on your own machines has no need to send any of that anywhere, and a design that never collects it is worth considerably more than a promise to look after it.

Sensitive information

We do not collect sensitive information as the Privacy Act defines it. That means no health information, no racial or ethnic origin, no political opinions or associations, no religious or philosophical beliefs, no trade union membership, no sexual orientation or practices, no criminal record, and no biometric information or biometric templates. There is no field anywhere in anything we run that is intended to hold any of it.

5Notification at the point of collection

Australian Privacy Principle 5 requires that we tell you certain things at or before the point at which we collect personal information about you, or as soon as practicable afterwards. The list includes our identity and how to contact us, the fact and circumstances of collection, whether collection is required by law, the purposes, the consequences if the information is not provided, who we usually disclose it to, and whether it is likely to go overseas and to which countries.

We satisfy that in three places rather than only in this one, because a notice nobody reads at a moment nobody is paying attention is a formality.

  • Before you write. The contact page states what each subject line is for, what is useful to include, how long we take to answer, and how long the resulting thread is kept. That is APP 5 information delivered at the point of collection rather than filed here.
  • In this document. The collection tables above name the purpose and the retention of every category. The recipients table names everyone who receives anything and where they are.
  • In any future release. If a tool ships with optional reporting, the prompt states what is sent and what happens if you decline, before the first transmission rather than in a settings screen you have to go looking for.

The consequence of not providing information

Generally that we cannot answer you, because we have no other way to reach you. There is no service that can be withheld, because we do not operate one. Nothing on this website requires you to identify yourself in order to read it.

Collection from someone other than you

APP 3.6 requires that personal information be collected from the individual concerned unless it is unreasonable or impracticable to do so. We collect from you and from nobody else. We do not buy lists, we do not use enrichment services, and we do not scrape professional networks. If your details reach us because a colleague copied you into a thread, that is dealt with under the section on information we did not ask for.

6Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

Reading this website is anonymous in the ordinary sense of the word. There is no account, no sign in, no analytics, no fingerprinting and nothing that attempts to recognise you on a second visit. What the hosting provider logs is set out in the collection tables and it is not attached to a name.

Writing to us can be pseudonymous. A question about the tooling does not need your real name and we will not ask for one. A pseudonymous address is a perfectly good address to reply to, and a report of a defect or a security problem is judged on whether it is right rather than on who sent it.

The one place the option genuinely narrows is a request to access or correct information. To answer that we have to be satisfied you are the person the information is about, otherwise the access right becomes a disclosure risk for somebody else. Even there, verification is against the address the information is held under rather than against an identity document, and we will not ask you to send one.

7Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

This happens most often when somebody sends us a bug report and includes a full screen recording, a diagnostic export, or a message thread containing other people's details. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Practically: unsolicited attachments containing third party personal information are deleted from the inbox and from any backup rotation on its ordinary cycle, and the substance of the bug is recorded without them.

8Use and disclosure

Australian Privacy Principle 6 governs what we may do with personal information once we hold it. Information collected for one purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the two purposes are related, or where you have consented, or where one of the specific exceptions in the Act applies.

What we use it for

  • Answering your message. That is the primary purpose of almost everything we hold.
  • Reproducing and fixing a defect you reported, and telling you when it is fixed.
  • Serving this website and defending it against automated abuse.
  • Meeting a legal obligation, which for a company of this size means tax, accounting and company records.
  • Establishing, exercising or defending a legal claim, if one ever arises.

What we do not do

  • We do not sell personal information. Not to a data broker, not to an advertiser, not bundled into anything described as an audience.
  • We do not run a marketing list, and no marketing email has ever been sent under this company name.
  • We do not profile you, score you, or enrich what you sent us with data bought from anybody.
  • We do not use correspondence as training data for a machine learning model, ours or anyone else's, and we do not paste it into a third party assistant in order to draft a reply.
  • We do not quote or publish your message without asking you first. That includes this website, a public defect tracker and a conference talk.

Disclosure to law enforcement and courts

We may disclose personal information where the Act permits it. That includes where the disclosure is required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists, including a serious threat to the life, health or safety of any individual, and to an enforcement body where reasonably necessary for an enforcement related activity.

Where we make such a disclosure to an enforcement body we make a written note of it, which APP 6.5 requires. Where the law allows us to tell you that a request was made, we will tell you. We will not read a request more broadly than it is written, and we will ask for it in writing before acting on it.

No such request has been received. If that changes and we are permitted to say so, this paragraph is where it will be said.

9Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use or disclosure of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS, instant message or similar, and it is stricter than most people expect.

What the Spam Act actually requires

  • Consent. Express consent, or consent that can reasonably be inferred from an existing business relationship and from conspicuous publication of an address. Inferred consent is narrower than it sounds and it is not created by somebody handing over a business card.
  • Accurate sender identification. The message must clearly identify who sent it and how to contact them, and that information must stay accurate for at least 30 days after sending.
  • A functional unsubscribe facility. It must be presented clearly, it must work for at least 30 days after the message was sent, it must not cost more than an ordinary message to use, and a request must be actioned within 5 working days.

Penalties attach per message, and the Australian Communications and Media Authority enforces the Act.

Our position

We do not run a mailing list. There is no newsletter, no product announcement list, no drip sequence and no address on this website that subscribes you to anything.

Writing to our address does not sign you up. That is the single most common way a small company quietly builds a list, and it is the reason this sentence is here rather than left to be assumed.

If we ever start one

It will be opt in only. Consent will be recorded with a timestamp and with the exact wording that was agreed to, so that we can produce it if the question is ever asked. The first message will say where the address came from. An address collected from a support thread will not be moved onto it, because consenting to be answered is not consenting to be marketed to, and treating the two as the same thing is how most small companies end up in breach.

Messages that are not marketing

A reply to your own email, an answer to a privacy request, a security notice, and a notification under Part IIIC of the Privacy Act are not commercial electronic messages. They are sent regardless of any unsubscribe, because they exist to tell you something you need to know rather than to sell you something. The Spam Act treats messages of that kind differently and so do we.

Telephone

We do not telemarket and we publish no telephone number. The Do Not Call Register Act 2006 (Cth) is therefore not engaged by anything we do.

10Recipients, and where they are

The complete list of everyone who receives personal information from us. It is short because we hold very little, and a short list is the most useful security control a company of this size has available to it.

Recipients, what they receive and where they are
RecipientPurposeWhat it receivesWhere
Cloudflare, Inc.Serving this website and protecting it from automated abuseRequest logs, including IP address and user agentGlobal edge network, including Australia. Company incorporated in the United States
Our email providerReceiving, storing and sending correspondenceWhatever is in an email, including the address it came from and any attachmentAustralia and the United States
Our accountantStatutory accounts, business activity statements and tax lodgementsTransaction records, and a name where a specific query requires oneAustralia
Professional advisersLegal advice, where a matter genuinely requires itOnly what that matter requires, and no moreAustralia

Who is not on this list

No analytics provider. No advertising network. No customer relationship management system. No customer data platform. No enrichment or lead scoring service. No data broker. No marketing automation tool. No support desk product. No third party assistant that would receive the contents of your message in order to summarise it.

Adding any one of them means editing this table first and recording the change under the section on changes below. That ordering is the point of publishing the table.

Business transfer

On a sale of the company or of a substantial part of it, personal information may transfer to the buyer. Where we are lawfully able to do so we will give notice on this website before the transfer completes. The buyer is bound by this policy until it publishes its own, and its own cannot reduce your rights over information collected before the transfer without your consent.

11Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

12Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. We have no reason to, our products have no age verification or identity verification step that would need one, and no field in any system we operate is intended to hold one.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

13Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Most of what we hold is machine generated and therefore accurate in the narrow sense that it faithfully records what a device reported. The category most likely to go stale is anything you told us yourself, such as an email address in a support thread. We do not periodically re-verify those, because doing so would mean contacting people who have finished dealing with us.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

14Security, and what we do not hold

Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.

What "reasonable steps" means for a company this size

  • Transport encryption on every connection. The website and every app endpoint are served over HTTPS only.
  • Encryption at rest for stored data, provided by the underlying platform.
  • Multi-factor authentication on every administrative account that can reach production data or a store console.
  • Access on a need to know basis. The number of people who can reach production data is small and is reviewed when anyone joins or leaves.
  • Separate credentials for development and production, so a compromised development credential does not reach live data.
  • Collecting less. The most reliable security control available to a company of this size is not holding the data, which is why the collection tables on this page are as short as they are.

What we do not have, stated plainly

SCRIPTSHIFT TECHNOLOGIES PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.

We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

15Retention

Australian Privacy Principle 11.2 requires us to destroy personal information or de-identify it once it is no longer needed for any purpose for which it may be used or disclosed under the Australian Privacy Principles, unless a law or a court order requires us to keep it. Retention is therefore not a matter of preference, and a schedule is the only honest way to describe it.

Retention schedule, with the reason for each period
CategoryPeriodReason
Website request logsUnder 30 daysThe hosting provider's own cycle. We do not export them and we do not extend it
Security cookies30 minutes, and up to 30 days for a clearance cookieSet by the provider and expiring on their own
Support correspondence24 monthsLong enough to notice that the same question keeps arriving, which is usually a defect in the documentation
Complaint correspondence7 yearsEvidence of how a complaint was handled. It also matches the general limitation period for a contract action in Western Australia
Privacy request records7 yearsBeing able to demonstrate that requests were answered, and answered in time
Tax, accounting and invoice records7 yearsRequired by Australian tax law, and the period runs from the transaction rather than from the relationship ending
Company and contract records7 years after the contract endsLimitation period, and the Corporations Act record keeping obligation
Job application material, if any is ever received6 months after the outcome, unless you ask us to keep itThere is no reason to hold it longer, and we will not build a talent pool nobody asked to be in

Destruction means removal from live systems and expiry from backups on the ordinary rotation, complete within 35 days of the deletion. De-identification means removing every identifier and every field that could be used to reconstruct one, not simply removing the name column.

We do not mark a record as deleted and keep the record. That practice is common, it is invisible from outside, and it means the answer you were given was untrue.

16Access and correction

Australian Privacy Principle 12 gives you a right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you a right to ask us to correct it. Both are exercisable now, against the correspondence and log records described above, and neither depends on us having a product.

How to ask

Email [email protected] with "Privacy request" in the subject line. Say what you want. If you want everything, say that. Writing from the address the information is held against is by far the fastest route, because it is what lets us find the records and satisfy ourselves that they are yours in a single step.

Verifying who you are

We have to be satisfied you are the person the information is about, or an authorised representative acting for them. In practice this means we reply to the address the information is held under. We will not ask you to send an identity document, a photograph of a licence or a utility bill, because collecting a government identifier in order to answer a privacy request would create a worse problem than the one it solves.

Where somebody writes on your behalf, we will ask for something showing you authorised it. Where a request arrives from an address we hold nothing against, we will say so rather than fish for enough detail to find a match.

Timing, and what it costs

We respond within 30 days. Access is free. There is no charge for making a request, no charge for a correction, and no charge for a copy in an ordinary format. If you ask for something in a form that imposes a genuine cost we will tell you the charge before doing the work, and it will not be excessive, which is the standard the Act sets.

How the information is given

By email, as plain text or as an attachment in a format you can open without buying software. Where a record contains another person's personal information we will redact that part rather than refuse the whole request, and we will say what was redacted and why.

When access can be refused

The grounds in the Act are narrower than most people expect. They include where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings between us and would not be accessible by the discovery process, where giving access would reveal our intentions in negotiations with you and prejudice them, where it would be unlawful, and where it would be likely to prejudice an enforcement related activity.

If we refuse, in whole or in part, you get written reasons, the specific ground relied on, and a clear statement of how to complain. Where we can give you part of the information, or give it in a different way that meets the need behind the request, we will offer that instead of a flat refusal. Refusing everything because one paragraph is protected is not something we will do.

Correction

If information is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. The obligation applies whether or not you asked, once we become aware of it. There is no charge and no time limit on asking.

If we have disclosed the information to somebody else and you ask us to notify them of the correction, we will take reasonable steps to do so, unless that is impracticable or unlawful.

If we refuse to correct something, you can require us to associate a statement with the record saying that you consider it inaccurate, out of date, incomplete, irrelevant or misleading. We will then take reasonable steps to make that statement apparent to anybody who later looks at the record. That right is frequently overlooked and it is worth knowing that it exists, because it means a disputed record cannot be presented later as though it were undisputed.

17Deleting what we hold

There is no account to close, because there is no account. What there is, is correspondence, and you can have it deleted.

How to ask

Email [email protected] with "Delete my data" in the subject line, from the address the information is held against where you can. Tell us whether you want a specific thread removed or everything we hold.

What deletion does

Effect of a deletion request, category by category
CategoryOn deletionReason for anything retained
Support correspondenceDeleted within 30 days, including from the sent folderNothing is retained
Attachments you sentDeleted with the threadNothing is retained
Complaint correspondenceRetained for 7 years, then deletedEvidence of how a complaint was handled. Deleting it on request would remove the record that protects both sides
Privacy request recordsThe bare record that a request was made, and when, is retained for 7 yearsDemonstrating that requests were answered in time. It holds no content beyond that
Invoice and tax records, if you ever become a customerRetained for 7 yearsRequired by Australian tax law and not waivable by either of us
Website request logsExpire on the provider's own cycle, under 30 daysThey are not keyed to a person and cannot be searched by identity, so a targeted deletion is not possible. They are already short lived
BackupsOverwritten on the ordinary rotation within 35 daysWe do not restore a deleted record from a backup. If a restore is ever needed, deletions are reapplied afterwards

We confirm in writing when a deletion is complete, and we say what was retained and under which row of that table. A confirmation that does not say what survived is not a confirmation.

18Children and young people

This website and the tooling described on it are aimed at professional software teams. They are not directed at children, they are not designed to appeal to children, and there is nothing here that a child would have any reason to use.

The Australian position

The Privacy Act does not fix an age at which a person can consent for themselves. The guidance published by the Information Commissioner is that an organisation should assess capacity individually where that is practicable, and that as a general rule an individual aged 15 or over is presumed to have capacity unless something suggests otherwise. We apply that presumption.

The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code as and where it applies to us once it is registered and in force. We will update this section at that point, rather than writing a paragraph now that guesses at terms nobody has seen.

In practice

  • We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
  • There is no account, no profile, no social feature, no chat, no user generated content and no advertising on this website, so there is no mechanism through which a child's information would ordinarily reach us.
  • If a child emails us, the message is treated the same way as any other correspondence, and it is deleted on request without argument.

If a child's information has reached us

Write to [email protected]. We will delete it. We will not require you to prove a legal relationship beyond what is needed for us to be satisfied the request is genuine, and we will confirm in writing when it is done.

19Automated decisions

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of such decisions that are made. That requirement commences on 10 December 2026.

Our position, disclosed ahead of the commencement date

We make no automated decision that significantly affects your rights or interests. Nothing we operate decides whether you get credit, a job, a service, a benefit, a price, or any legal entitlement. There is no scoring, no ranking and no eligibility model anywhere in this company.

Automated processing does occur in one place and it does not come close to that threshold. The hosting provider's abuse protection decides automatically whether a request looks like it came from a person or from a script, and may present a challenge. If that ever blocks you from reading a page, email us and we will look into it, and there is nothing behind the page that you are being denied.

The tooling, and why the gate is not an automated decision either

The second reader gate described elsewhere on this site refuses to proceed until a named human has approved a file. It automates the refusal, never the approval. A machine cannot approve a release under that design, which is close to the opposite of an automated decision, and it is the reason the feature exists.

If any of this changes, this section is where the change will be described, and it will be described before the processing starts rather than after somebody notices it.

20Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to [email protected] with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

21The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

22Cookies on this website

This website sets no cookies of its own. It runs no analytics, no advertising and no tracking of any kind. A strictly necessary security cookie may be set by the hosting provider to tell automated traffic apart from human traffic.

There is no consent banner, because there is nothing here that consent would be for. Australia has no separate cookie consent regime in any event, and the reasoning behind that, together with a complete list of what may be stored on your device, is in the cookie notice.

Cookies are a website mechanism. Nothing in the tooling described on this site uses them, because it has no browser and no session.

23Complaints

Step one: tell us

Email [email protected] with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

24If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to [email protected] and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. Personalised advertising is off unless you turn it on, which places us outside the sharing definition by default. Global Privacy Control signals sent by your browser to this website are honoured.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

25Changes to this policy

We may change this policy. When we do, the effective date and the version number in the header of this page change with it.

Where a change materially reduces your rights, or materially widens what we collect, we will give notice before it takes effect. That means a note at the top of this page for at least 30 days beforehand. We will not make a material change effective retrospectively, and we will not treat continued use of a static website as consent to something you have not read.

Previous versions are not published as separate pages, but they are kept. If you want to know what this document said on a particular date, ask and we will send you that version.

This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner about your own circumstances.

26How to contact us

All privacy matters reach one address.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information (APP 12)Privacy request30 days
Correction of your personal information (APP 13)Privacy request30 days
Deletion of the information we hold about youDelete my data30 days
Complaint about our handling of personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
Anything elseAnything sensible5 business days

Email: [email protected]

Entity: SCRIPTSHIFT TECHNOLOGIES PTY LTD, ACN 698 500 542, ABN 21 698 500 542, an Australian proprietary company, Western Australia.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 698 500 542 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.