Back to home

Privacy Policy

Effective date: 17 July 2026

This Privacy Policy explains how PTY Unlimited Pty Ltd (ABN 98 693 284 525), trading as Off the Tools ("Off the Tools", "we", "us", or "our"), collects, uses, stores, discloses and protects personal information when you visit offthetools.ai, use our web and mobile applications, or otherwise interact with our business management software and related services (together, the "Service"). It also serves as our collection notice under Australian Privacy Principle 5.

We offer the Service to businesses in Australia, New Zealand, the United States, Canada, the United Kingdom, the European Economic Area (EEA) and other regions, and this policy is written to meet the requirements of the privacy laws of those regions, including the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the EU and UK General Data Protection Regulation (GDPR / UK GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA) and other US state privacy laws, Canada's PIPEDA, and New Zealand's Privacy Act 2020. Region-specific rights are set out in Section 14.

1. Who we are and how to contact us

The entity responsible for your personal information (the data controller) is:

  • PTY Unlimited Pty Ltd (ABN 98 693 284 525), trading as Off the Tools
  • 3/490 The Boulevard, Kirrawee NSW 2232, Australia
  • Privacy Officer, by email at Contact@offthetools.ai (attention: Privacy Officer)

Our Privacy Officer is accountable for our handling of personal information and for responding to questions and complaints. If you are an individual in the EEA or the United Kingdom: we have not yet appointed representatives under Article 27 of the GDPR / UK GDPR. We are working to appoint them and will list them here once we do; in the meantime, EEA and UK individuals may contact us directly using the details above.

2. Our two roles: controller and processor

The Service involves two kinds of data, and we act in a different role for each:

  • Your account and business data. For the personal information of the owners, staff and users who sign in, we are the controller and this policy governs how we handle it.
  • Your Customer Data. For the information you enter about your own customers, you are the controller and we act as your processor / service provider, handling it only on your instructions to provide the Service. Business customers can request our standard Data Processing Addendum (DPA), which sets out these obligations and lists our sub-processors, at Contact@offthetools.ai.

3. Information we collect

  • Account information: your name, email, phone number, password (stored only as a secure hash), business name and details, ABN or equivalent, role and preferences.
  • Your Customer Data: the contact details, site addresses, job details, notes, photos, quotes, invoices and message history of your own customers that you or your team enter.
  • Operational data: quotes, jobs, schedules, timesheets, materials, invoices, payments and other records created through your use of the Service.
  • Payment and billing data: processed by Stripe and, where you subscribe through an app store, by Apple or Google. We store billing metadata (plan, status, last four digits of a card) but not full card numbers.
  • Accounting data: where you connect Xero or QuickBooks Online, invoices, contacts and payment records exchanged with that provider.
  • Communications data: the content, phone numbers, email addresses and metadata of the SMS, calls and email you send or receive through the Service, and — where the AI receptionist is used — call audio and transcripts.
  • Connected email data: where you connect Gmail or Outlook, restricted OAuth permissions used to send email on your behalf and read replies for in-app threading, as described in Section 10.
  • Usage and device data: pages and features used, IP address, device and browser type, app version and timestamps.
  • Location data: where your team uses our mobile app and enables it, device location while the app is in use, for scheduling and travel-time features.
  • Sensitive information. Some of the above is "sensitive" information under Australian law and "sensitive personal information" under the CPRA — in particular precise geolocation (mobile app), the contents of the communications you send and receive through the Service, and audio recordings and transcripts of calls handled by the AI receptionist. We collect and use this only to provide the features you enable, and we do not use or disclose it to infer characteristics about you.
  • Mobile permissions: the app may request access to your camera and photos (job photos), microphone (calls), location and notifications. Each is optional and used only for the related feature.

4. How we use information and our legal bases

We use personal information to provide, operate, secure and support the Service; authenticate users and protect accounts; process payments and manage subscriptions; deliver the AI, messaging, scheduling and automation features you enable; send transactional and service communications; improve and develop the Service; send you marketing about our own services (which you can opt out of at any time); and comply with legal obligations and enforce our terms. Where the GDPR / UK GDPR applies, our legal basis is:

  • Performance of our contract — to set up your account and provide the Service you subscribe to.
  • Legitimate interests — to secure and improve the Service and to market our own services, where not overridden by your rights (our balancing assessment is available on request).
  • Consent — for optional integrations and, where required, analytics cookies and certain marketing; you may withdraw consent at any time.
  • Legal obligation — to meet tax, accounting and other legal requirements.

5. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. The AI receptionist and AI assistant generate drafts, suggestions and bookings that the business using the Service reviews and controls. Where any feature would make such a decision, individuals in the EEA and UK have the right to obtain human review, to express their view and to contest the decision, and we will provide equivalent transparency where Australian and other laws require it.

6. AI features and call recording

The Service includes AI features, including an AI voice receptionist that can answer calls and book jobs, and an in-app AI assistant. When these are used:

  • calls answered by the AI receptionist may be recorded, transcribed and processed to understand the caller and capture the enquiry;
  • we use third-party AI providers, including Retell AI (real-time voice) and Anthropic (AI language processing);
  • the AI receptionist can be configured to announce at the start of a call that the call is handled by an automated assistant and may be recorded;
  • AI outputs can be inaccurate, are not professional advice and should be reviewed; and
  • we do not use your content or Your Customer Data to train generalised AI models.

Call recording, monitoring and automated-voice disclosure laws vary by country and by US state, and several jurisdictions require the consent of all parties and/or that an artificial voice identify itself (for example, NSW, WA, SA, Tasmania and the ACT in Australia, and states such as California, Illinois and Washington in the US). Where you enable call answering or recording, you are responsible for enabling the announcement and for providing any notice to, and obtaining any consent from, callers that the law requires.

7. SMS, calls and phone numbers (messaging)

Messaging and calling features are delivered through Twilio and carrier networks, which process the phone numbers and content needed to send and receive them. If you receive SMS from a business using Off the Tools, you can reply STOP to opt out and HELP for help; message and data rates may apply, and message frequency varies. Message categories include booking confirmations, on-the-way alerts, quote and invoice notifications, and review requests. No mobile information is shared with third parties or affiliates for their own marketing or promotional purposes, and consent to receive SMS is not a condition of any purchase. Businesses using the Service are responsible for obtaining consent to contact their own customers, as set out in our Terms of Service.

8. Information you upload about your customers

You may upload information about your own customers and their jobs. You are the controller for Your Customer Data and we process it as your processor. You are responsible for ensuring you have a lawful basis, and have given any required notices to and obtained any required consents from your customers, to collect that data and share it with us. We use Your Customer Data only to provide the Service to you.

9. How we share information — service providers and sub-processors

We share personal information with the following recipients, each under contractual data-protection obligations:

  • Supabase — database, authentication, file storage and backend functions (hosted on AWS in the Asia-Pacific (Sydney) region).
  • Cloudflare — application hosting, content delivery and security.
  • Stripe — card payment processing.
  • Twilio — SMS, voice calls and phone numbers.
  • Retell AI — real-time AI voice receptionist.
  • Anthropic — AI language processing for the assistant and AI features.
  • Resend — transactional and marketing email delivery.
  • Xero and Intuit (QuickBooks Online) — accounting sync, where you connect them.
  • Google and Microsoft — maps and geocoding, Google Business Profile reviews, and email sending / sign-in, where you use those features.
  • Apple and Google Play — subscription billing and app delivery where you use the mobile apps.
  • Legal and safety: where required by law, court order, or to protect the rights, safety or property of Off the Tools, our users or others.
  • Business transfers: in a merger, acquisition or sale, subject to this policy.

We do not sell your personal information or Your Customer Data, and we do not share it for cross-context behavioural advertising. A current list of sub-processors is available on request. You can disconnect any integration in Settings, and you can revoke Microsoft account access at account.live.com/consent/Manage.

10. Google API Services — Limited Use disclosure

Off the Tools' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google account data (via Gmail OAuth scopes) only to send email on your behalf from your connected account and to read email replies so we can show them in the relevant job or invoice thread inside the Service.
  • Google Calendar (if you connect it). We use the calendar permission to do two things, and only these: (1) write your own jobs, tasks, blocked time and appointments from Off the Tools into the calendar you choose, as events we create and can later update or remove; and (2) read the times of the events in that calendar, so the people you work with can see when you are already busy and do not book over it. You choose how much of your calendar we keep: nothing, only that you are busy (the time, with no title), or the event titles as well. We do not store event descriptions, guests or attachments, and we never turn a calendar event into a job, task or contact. The titles and times we keep are used only to show your availability inside the Service. When you disconnect, or switch to a narrower option, the stored copies are deleted at once and our access is revoked with Google.
  • Google Business Profile (if you connect it): we use that permission only to show and reply to your own business's reviews inside the Service.
  • We do not transfer Google account data to third parties except as necessary to provide or improve user-facing features that are prominent in our interface, and only with your consent or as required by law.
  • We do not use Google account data for advertising.
  • We do not allow humans to read your Google account data unless we have your explicit consent for specific data, it is necessary for security or to comply with law, or the data has been aggregated and anonymised.
  • We do not use Google account data, or data derived from it, to train, develop or improve generalised or non-personalised AI or machine learning models.

You can revoke our access at any time by disconnecting your email account in Settings or at myaccount.google.com/permissions.

11. International data transfers

Your information is stored primarily on infrastructure in the Asia-Pacific (Sydney) region of Australia. Because we serve customers globally and use the service providers in Section 9, personal information is likely to be disclosed to overseas recipients located in the United States, the European Union, the United Kingdom and other countries in which those providers operate. Where we transfer personal information out of the EEA, the United Kingdom, Australia or other regions with transfer restrictions, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision or certification (for example the EU-US Data Privacy Framework where a US provider is certified), or another lawful mechanism — and a copy of the relevant safeguards is available on request. For New Zealand personal information, we disclose overseas only where the recipient is subject to comparable safeguards, consistent with Information Privacy Principle 12.

12. Data retention

We keep each category of personal information only as long as needed for the purposes in this policy and to meet legal obligations, applying the following criteria:

  • Account and operational data — kept for the life of your account; financial and transaction records are kept for up to seven years to meet tax and accounting laws.
  • Communication content, call recordings and transcripts — kept for a limited period to provide and support the feature, then deleted or de-identified.
  • Usage, device and log data — kept for a limited period for security and analytics, then deleted or aggregated.
  • Support communications — kept for a limited period to handle and improve support.

When your account is closed we delete or de-identify personal information within a reasonable period (generally within 30 days of a verified request), except where we are required to keep it longer. You can request deletion earlier, and the specific retention periods we apply are available on request, by contacting Contact@offthetools.ai.

13. How we protect information

We apply industry-standard safeguards, including encryption in transit (HTTPS/TLS) and at rest, role-based access controls, tenant isolation, regular backups and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Your privacy rights

Depending on where you live, you may have some or all of the rights below. To exercise a right, email Contact@offthetools.ai. We may need to verify your identity, and you may use an authorised agent to submit a request (we will require proof of the agent's authority). We will not discriminate against you for exercising a right. If you are a customer of a business that uses Off the Tools, please direct requests to that business, which is the controller; we will assist them as their processor. We will acknowledge complaints within a reasonable time and aim to respond within 30 days.

  • Australia (Privacy Act / APPs): access and correct your personal information, and complain to us or to the Office of the Australian Information Commissioner (oaic.gov.au).
  • EEA and UK (GDPR / UK GDPR): access, rectification, erasure, restriction, data portability, objection, rights in relation to automated decision-making (Section 5), and the right to withdraw consent and to complain to your local supervisory authority or, in the UK, the Information Commissioner's Office (ico.org.uk).
  • California (CCPA/CPRA): know, access, delete and correct your personal information; opt out of sale or sharing (we do not sell or share personal information for cross-context behavioural advertising); limit the use of sensitive personal information (which we collect only to provide the features you enable); and non-discrimination. We collect the statutory categories of identifiers, commercial information, internet/ device activity, geolocation, audio/electronic information, professional/employment information and inferences, from you and your use of the Service, for the purposes in Section 4, and disclose them only to the service providers in Section 9. If we deny a request you may appeal by replying to our decision. California residents may also request details under the "Shine the Light" law.
  • Other US states: residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota and Maryland — may access, delete, correct and obtain a portable copy of their personal information, opt out of sale, targeted advertising and certain profiling, and appeal a denied request. Minnesota residents may question the result of profiling that produces legal or similarly significant effects.
  • Canada (PIPEDA): access and correct your personal information and raise concerns with our Privacy Officer or the Office of the Privacy Commissioner of Canada.
  • New Zealand (Privacy Act 2020): access and correct your personal information and complain to the Office of the Privacy Commissioner.

15. Deleting your account and data

You can delete your account and associated personal information at any time from within the Service (Settings → Delete account) or by emailing Contact@offthetools.ai, which you can do without signing in. When you delete your account we delete or de-identify your personal information as described in Section 12, subject to legal retention obligations.

16. Cookies, tracking and opt-out signals

We use first-party cookies that are strictly necessary to sign you in and keep the Service secure. Where we use analytics, in the EEA and UK we set non-essential (analytics) cookies only after you consent, and you can withdraw consent at any time; elsewhere you can control cookies through your browser. We do not use cookies for cross-site advertising, and our mobile apps do not track you across other companies' apps or websites. Because we do not sell or share personal information for cross-context behavioural advertising there is nothing to opt out of, but where your browser sends a Global Privacy Control or Do-Not-Track signal we honour it as an opt-out preference and do not set non-essential tracking.

17. Children

The Service is a business tool intended for use by people aged 18 and over and is not directed at children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact Contact@offthetools.ai and we will delete it.

18. Data breach notification

If a data breach occurs that is likely to result in serious harm or meets the notification threshold under applicable law, we will notify affected individuals and the relevant regulators as required — including under Australia's Notifiable Data Breaches scheme, the GDPR / UK GDPR (generally within 72 hours to the supervisory authority), New Zealand's Privacy Act 2020, and applicable US and Canadian breach-notification laws. Where we act as a processor, we will notify the relevant business customer without undue delay so they can meet their own obligations.

19. Changes to this policy

We may update this Privacy Policy from time to time. The effective date at the top reflects the most recent revision, and we will communicate material changes through the Service or by email where appropriate.

20. Contact us

For any question or request about this policy or your personal information, contact our Privacy Officer at PTY Unlimited Pty Ltd, 3/490 The Boulevard, Kirrawee NSW 2232, Australia, or Contact@offthetools.ai.