Pay Audtr
Legal Document

Privacy Policy

๐Ÿ“… Effective: 1 May 2026 ๐Ÿข Pay Audtr (ABN: TBC) ๐ŸŒ Jurisdiction: Commonwealth of Australia
Contents
  1. Who we are
  2. What we collect
  3. How we use your data
  4. Sub-processors & sharing
  5. AI features
  6. Data storage & security
  7. Retention
  8. Your rights
  9. Cookies & local storage
  10. Future features
  11. Contact us
Section 1

Who We Are

Pay Audtr is an online payroll compliance tool designed to help workers in the Social, Community, Home Care and Disability Services (SCHADS) industry verify that their pay is consistent with the SCHADS Award (MA000100).

In this Policy, "Pay Audtr", "we", "us" and "our" refers to the operator of pay-audtr.com. "You" refers to any person who registers for or uses the Pay Audtr service.

We are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Section 2

What Personal Information We Collect

2.1 Information you provide directly

CategoryExamplesWhy collected
Account detailsEmail address, password (hashed)Create and authenticate your account
Employment detailsEmployer name, award stream, classification level, pay point, employment type, agreed hoursCalculate your correct Award entitlements
Roster dataShift dates, start/end times, break details, shift types, leave entries, on-call daysCompute hours worked and penalty rates
Payslip dataGross pay, net pay, base rate, hours paid, allowances, super contributions, tax withheldCompare actual pay against Award minimum
Quick Audit dataHourly rate, pay period, employment type, hours worked โ€” entered via the Quick Audit onboarding flowProvide an instant estimate before full audit
FeedbackFree-text responses to targeted questions (confusion points, result accuracy, likelihood to return)Improve the tool

2.2 Information collected automatically

2.3 Information we do not collect

We do not collect your tax file number (TFN), bank account details, Medicare number, or any government-issued identity document. We do not store your full credit card number โ€” payment processing is handled entirely by Stripe.

Section 3

How We Use Your Information

We will never use your employment data, payslip data, or roster data for marketing, advertising, or profiling purposes. We do not sell your data.

Section 4

Sub-Processors and Data Sharing

ProviderPurposeData sharedLocation
SupabaseDatabase, authentication, and file storageAll account and app dataAustralia (ap-southeast-2)
Stripe SoonPayment processing and subscription billingName, email, billing address, payment method detailsAustralia / USA
AnthropicAI payslip and roster scanning (Claude API)Cropped payslip or roster image/PDF (opt-in, per scan)USA
VercelWeb application hosting and deploymentHTTP request metadata, IP address (transient)Australia / Global CDN

4.1 We will never share your data with:

Section 5

AI Features and Data Processing

AI scanning is an opt-in feature. You are never required to use it. All payslip and roster data can be entered manually.

5.1 What happens when you scan

When you use the AI Scan Payslip or Scan Roster features, a cropped image or PDF of the document you select is transmitted to Anthropic's Claude API. Claude extracts structured data (pay figures, shift times) from the image and returns it to the app.

5.2 Correction learning (local only)

If you correct a field after a scan, the app stores the field name, the AI's extracted value, and your corrected value in your browser's localStorage under the key payauditr_ps_corrections. This data is used only to improve accuracy on your next scan and never leaves your device. Up to 10 corrections are stored; older corrections are automatically removed.

5.3 Data minimisation

We strongly encourage you to use the crop tool to remove personal identifiers โ€” your name, address, bank account details, and TFN โ€” before scanning. The crop tool is presented before every scan.

5.4 Anthropic's data practices

Anthropic does not use API inputs to train its models. Scanned content is processed transiently and not retained by Anthropic beyond the API call. See anthropic.com/privacy.

5.5 Cross-border transfer

Anthropic processes data in the United States. By using the scan feature, you consent to this transfer. Data is transmitted over TLS and is not stored in the USA after the API call completes.

Section 6

Data Storage and Security

Your data is stored in Supabase's managed PostgreSQL database hosted in the ap-southeast-2 (Sydney, Australia) AWS region.

No internet-based service can guarantee absolute security. You are responsible for maintaining the security of your account credentials and enabling two-factor authentication.
Section 7

Data Retention

Section 8

Your Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

RightWhat it meansHow to exercise it
AccessRequest a copy of your personal informationEmail privacy@pay-audtr.com
CorrectionRequest that inaccurate information be correctedUpdate in-app or email us
DeletionRequest deletion of your account and all associated dataEmail privacy@pay-audtr.com โ€” processed within 30 days
PortabilityRequest an export of your data (JSON/CSV)Use Settings โ†’ Export, or email privacy@pay-audtr.com
ComplaintLodge a complaint if you believe we have breached the APPsContact us first; if unresolved, contact the OAIC at oaic.gov.au
Section 9

Cookies and Local Storage

Pay Audtr uses minimal localStorage for the following purposes only:

We do not use advertising cookies, cross-site tracking, or third-party analytics cookies.

Section 10

Future Features and Data Implications

The following features are planned. This Policy will be updated before each is released, with 14 days' notice to registered users.

FeatureData implicationStatus
Stripe payment integrationBilling details (name, email, card last 4) shared with Stripe. No card data stored by Pay Audtr.Planned
Introductory pricing / promo codesDiscount usage tracked in subscription record. No additional personal data.Planned
Hospitality Award supportSame data types as SCHADS โ€” employment details and shift data. No additional personal data.Planned
Period comparison (Pro)Historical audit results stored in reports table โ€” already collected, no new data types.Planned
Rate update email notificationsEmail sent to registered users when SCHADS rates are updated. Requires email address already held.Planned
Section 11

Contact Us

For any privacy-related queries, access requests, or complaints:

We will respond to all requests within 30 days.

Policy updates

Material changes will be communicated by email to registered users at least 14 days before they take effect. The current version is always available at pay-audtr.com/privacy.