Legal · Privacy

Privacy Policy

Effective: [DATE TBD] · Last updated: [DATE TBD] · Version: 1.0

⚠ Pre-publication notice (delete before going live). This document is a working draft prepared to reflect Tagline's current technical and operational posture as documented in CLAUDE.md. It is intended as a starting point for review by an Australian-qualified privacy lawyer before publication. Items in [SQUARE BRACKETS] are placeholders that need real values. Specific retention periods, security controls, and third-party disclosures reflect current actual practice and must be reviewed if any change is made before launch.
Tagline is operated by [LEGAL ENTITY NAME] (ABN [ABN]), a company registered in Australia ("we", "us", "our"). This Privacy Policy explains how we collect, hold, use, and disclose personal information when you use the Tagline platform at tagline.cloud or any related service.

We are committed to handling personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and — because our infrastructure is hosted in Singapore — also in accordance with the Singapore Personal Data Protection Act 2012 (PDPA).
Contents
  1. Scope & who this applies to
  2. What we collect
  3. How we collect it
  4. Why we collect it
  5. Data residency & hosting
  6. Cross-border disclosure (APP 8 / PDPA)
  7. Third-party services
  8. Retention
  9. Security
  10. Your rights
  11. Cookies & tracking
  12. Children's data
  13. Changes to this policy
  14. Complaints & regulators
  15. Contact

01Scope & who this applies to

This policy applies to anyone who:

"Personal information" has the meaning given by the Australian Privacy Act and PDPA — information or an opinion about an identified or reasonably identifiable individual. In the Tagline context this primarily means account-holder identifiers (name, email) and staff contact details — animal records, paddock data, and NLIS tag information are generally not personal information, but they are still treated as confidential business information of the account holder.

02What we collect

Account information

Property and farm information

Animal and compliance data

This is the core of the platform. It is not personal information about an individual, but it is business-confidential to the property owner:

Usage and technical data

Voluntary submissions

What we do NOT collect

03How we collect it

04Why we collect it

We collect personal information for the following purposes:

  1. To provide the service — operate the Tagline platform, store your records, and present them back to you and your authorised colleagues
  2. To meet your compliance obligations — generate the NLIS, eNVD, LPA, and BREEDPLAN reports you need to satisfy regulatory and program requirements
  3. To secure your account — authenticate you, log access for audit, detect abuse
  4. To respond to you — answer support requests and bug reports
  5. To improve the product — analyse usage in aggregate to fix bugs and prioritise features
  6. To meet our legal obligations — respond to lawful requests from regulators

We do not sell personal information. We do not use your data to train AI models on your behalf or anyone else's. When we use AI extraction (e.g. label-to-batch), your files are processed by our API provider (currently Anthropic) under their commercial terms that prohibit training on customer data.

05Data residency & hosting

Tagline's production data is currently hosted in Singapore:

We have engineered the platform to deploy equivalently to AWS Asia Pacific (Sydney) ap-southeast-2 for Australian data residency. We will migrate any property or organisation to a Sydney-hosted instance on request, at no additional cost, as part of the move to a properly multi-region deployment in 2026.

If Australian data residency is a contractual requirement for you
Email us at [PRIVACY EMAIL] before signing up. We will let you know the current production region, our roadmap for Sydney hosting, and provide a written commitment if needed.

06Cross-border disclosure (APP 8 / PDPA)

Disclosure required under APP 8 of the Privacy Act 1988 (Cth):

Because we currently host your data in Singapore, your personal information will be disclosed to overseas recipients in the following countries:

Singapore is recognised by the Office of the Australian Information Commissioner as having a binding privacy framework (the PDPA) that provides comparable protection to the Australian Privacy Principles. Where overseas providers are located in the United States, we rely on their written commitments (data processing addenda, SOC 2 attestations, and equivalent terms) to provide APP-equivalent protection.

By using Tagline you consent to the transfer of your personal information to Singapore and to the United States for the purposes set out in Section 4. If you do not consent, do not create an account. You may withdraw consent at any time by deleting your account (see Section 10).

PDPA (Singapore) — purposes of collection and use
Where Singapore PDPA applies to processing performed in Singapore, we collect, use, and disclose personal data only for the purposes listed in Section 4 of this policy, and we will obtain fresh consent before using personal data for any new purpose. You can contact our Data Protection Officer at [DPO EMAIL] to access or correct personal data, withdraw consent, or make a complaint.

07Third-party services

We use the following external services to run Tagline. We do not give any of them more data than they need to perform their function, and none of them are authorised to use your data for any purpose other than serving Tagline.

Provider Role What is shared
Supabase Authentication + database All account data and platform records (Singapore region)
Render Application hosting All data passes through Render's app servers in Singapore
Mapbox Satellite map tiles for the Paddock Map page Paddock coordinates (no personal information)
Anthropic AI vision extraction (label scan, invoice extract, kill sheet parse) Only the photo or PDF you upload; commercial API terms prohibit training on customer data
Resend Transactional email (welcome, invites, password reset) Recipient email address and the email content
Integrity Systems Company (MLA) NLIS database API and eNVD GraphQL API Tag IDs, animal movements, eNVD declarations; only when you authorise an API call
GitHub Bug-tracking repository Only the content of bug reports you choose to submit via the in-app reporter

Each provider has its own privacy policy. We have selected providers who publish data-processing terms, are certified under recognised security frameworks (SOC 2, ISO 27001), and provide contractual commitments to data protection that meet or exceed our obligations under the APPs and PDPA.

08Retention

We keep your data only for as long as we have a lawful reason to. Specific retention periods we have committed to (these are contractual where they appear in our agreement with Integrity Systems Company; any change requires renegotiation):

Data class Retention How it is removed
Active account & property data Until you close the account By you, in Settings, or by request to us
NLIS-derived records (Device Query, eNVD) Within 30 days of property off-boarding Automated purge job
Access & transaction logs Maximum 90 days, then auto-purged Automated retention policy at log store
Database backups Encrypted rotating schedule per Supabase (typically 7 daily / 4 weekly) Automatically expire from the backup chain
Email delivery records Per Resend's standard 7-day log retention Automatically purged
Bug reports (GitHub Issues) For the life of the repository, unless you ask us to delete On request to [PRIVACY EMAIL]

Our log retention specifically excludes credentials, authentication tokens, and payment information — these are filtered out of logs at the application layer before write.

09Security

We protect your data with controls that are commercially reasonable for a B2B SaaS at our scale:

Transport & storage

Access control

Engineering controls

No system can be made entirely secure. If you become aware of a security vulnerability please contact [SECURITY EMAIL] and we will respond within 72 hours.

10Your rights

Under the Privacy Act 1988 (Cth) and Singapore PDPA, you have the right to:

  1. Access the personal information we hold about you. We will respond within 30 days of a written request. We do not charge a fee.
  2. Correct information that is inaccurate, out of date, incomplete, or misleading. You can update most fields directly in your account; for those you cannot, email us.
  3. Delete your account. We will remove your account, your personal information, and any NLIS-derived records associated with you within 30 days of receipt of the request, subject to records we are required to retain by law.
  4. Withdraw consent for processing, by closing your account.
  5. Port your data — we will provide a machine-readable export of records owned by you (CSV / JSON) on request.
  6. Make a complaint — see Section 14.

Requests to exercise these rights should be sent to [PRIVACY EMAIL]. We may need to verify your identity (for example by confirming control of the email address on your account) before acting on a request.

11Cookies & tracking

Tagline uses a small number of essential cookies — for example, the authenticated session cookie set by Supabase Auth that keeps you logged in. We do not use these to track you across other websites.

We do not currently use any third-party analytics, advertising, or marketing tracking cookies. If we add product analytics in the future (for example a privacy-respecting analytics tool like Plausible or Fathom), this policy will be updated and a banner will be shown to existing users.

Our marketing website (tagline.cloud) may load fonts from Google Fonts. No identifying cookies are set by this; only the font files are loaded.

12Children's data

Tagline is a business-to-business service for cattle producers. It is not directed at children and we do not knowingly collect personal information from anyone under the age of 18. If you become aware that a child has provided us with personal information, please contact us and we will delete it.

13Changes to this policy

We may update this policy from time to time to reflect changes in our practice or in the law. The version number and effective date at the top of this page will be updated whenever changes are made. If a change is material (for example, we add a new third-party service that receives your data, or we change a retention period), we will notify account holders by email at least 14 days before the change takes effect.

Continued use of Tagline after a policy update constitutes acceptance of the updated terms. If you do not accept the updated terms, you may delete your account before the effective date.

14Complaints & regulators

If you believe we have breached the Australian Privacy Principles or the Singapore PDPA, please contact us first at [PRIVACY EMAIL]. We will acknowledge your complaint within 7 days and respond substantively within 30 days.

If you are not satisfied with our response, you may escalate to:

Australia — Office of the Australian Information Commissioner (OAIC)

Singapore — Personal Data Protection Commission (PDPC)

15Contact

How to reach us

Questions about this policy, requests to access or delete your data, and complaints:

Privacy enquiries

[PRIVACY EMAIL]

Data Protection Officer (PDPA, Singapore)

[DPO EMAIL]

Security disclosures

[SECURITY EMAIL]

Postal

[LEGAL ENTITY NAME]
[STREET ADDRESS]
[SUBURB STATE POSTCODE]
Australia

ABN

[ABN]