Privacy Policy
Last Updated: 17 February 2026
Effective Date: 17 February 2026
Your privacy matters. This Privacy Policy explains how Hey Axel Pty Ltd collects, uses, stores, and discloses your personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. About This Policy
1.1 Who We Are. Hey Axel Pty Ltd (ABN pending) ("Hey Axel," "we," "us," "our") is an Australian company providing vehicle fleet management software-as-a-service (SaaS) for tradies and small businesses.
1.2 Contact Information.
- Email: support@heyaxel.app
- Website: https://heyaxel.app
- Jurisdiction: New South Wales, Australia
1.3 Scope. This Privacy Policy applies to all personal information we collect through:
- The Hey Axel website (https://heyaxel.app);
- The Hey Axel platform (SaaS application);
- Mobile applications (if applicable);
- Email communications, customer support, and marketing.
1.4 Not Personal Information. This Policy does NOT apply to:
- Vehicle data alone: Registration numbers, VINs, make/model/year WITHOUT linkage to an identifiable person are NOT personal information under Australian law;
- Aggregated or anonymized data: Data that cannot identify you;
- Employee records: Information about Hey Axel employees (covered by separate policies).
2. Personal Information We Collect (APP 3 & APP 5)
2.1 Information You Provide Directly. When you create an Account or use Hey Axel, we collect:
Account Information:
- Name (first and last)
- Email address
- Password (hashed and encrypted — we do NOT store plaintext passwords)
- Business name (optional, for Pro/Enterprise users)
- Australian Business Number (ABN) — optional, for invoicing
- Phone number (optional, for SMS reminders)
Vehicle Data:
- Vehicle registration numbers and states
- Make, model, year, colour, body type, VIN
- Service records (dates, costs, odometer readings, service providers)
- Reminders (rego expiry, insurance, CTP, service intervals, custom events)
- Documents (photos of service receipts, logbooks, manuals — uploaded by you)
- Odometer readings and fuel consumption data
Payment Information:
- Credit/debit card details (processed and stored by third-party payment processors — we do NOT store full card numbers)
- Billing address
- Purchase history and invoices
Communications:
- Messages you send to support@heyaxel.app
- Chat transcripts with Ask Axel (AI assistant)
- Feedback, survey responses, and feature requests
2.2 Information We Collect Automatically.
Usage Data:
- Pages visited, features used, time spent on platform
- IP address, browser type, device type, operating system
- Referring URLs and search terms
- Login times and frequency of use
Cookies and Tracking Technologies:
- Essential cookies: Session management, authentication (required for the Service to function)
- Analytics cookies: Anonymized usage statistics
- Advertising cookies: Not currently used (may be added in future — see Section 15 for updates)
2.3 Information We Collect from Third Parties.
Government Vehicle Data APIs:
- When you use rego lookup features, we retrieve vehicle data (make, model, year, rego status) from third-party APIs that access government databases (via authorised NEVDIS brokers)
- This data is matched to vehicles you add to your Account
Telematics Integrations:
- If you connect a third-party telematics account, we access: Vehicle location (GPS), odometer readings, fuel consumption, engine diagnostics, driver behaviour data
- You authorise this data sharing via the telematics provider's OAuth consent process
Authentication Providers:
- If you sign in with Google or Microsoft, we receive: Name, email address, profile photo (as permitted by your OAuth consent)
3. How We Use Your Personal Information (APP 6)
3.1 Primary Purposes. We use your personal information to:
Provide the Service:
- Create and manage your Account
- Store and display your Vehicle Data
- Send reminders (rego expiry, service intervals, insurance, etc.)
- Process payments and issue invoices
- Provide customer support and respond to inquiries
- Enable integrations (telematics, government APIs)
Improve and Develop the Service:
- Analyze usage patterns to improve features and user experience
- Train and improve our AI models (see Section 4)
- Conduct research and analytics (using aggregated/anonymized data)
- Test new features and perform A/B testing
Legal and Security:
- Detect and prevent fraud, abuse, and security threats
- Comply with legal obligations (e.g., tax reporting, law enforcement requests)
- Enforce our Terms and Conditions and EULA
- Respond to Notifiable Data Breach incidents
Marketing and Communications (with consent):
- Send promotional emails about new features, updates, or offers (you may opt out)
- Conduct surveys and request feedback
- Send transactional emails (account notifications, billing alerts — cannot opt out)
3.2 Secondary Purposes. We may use personal information for purposes other than those listed above if:
- You consent to the secondary use;
- The secondary use is related to the primary purpose and within your reasonable expectations;
- We are required or authorised by law.
4. How We Use AI and Your Data
4.1 AI-Powered Features. Hey Axel uses artificial intelligence for:
- Ask Axel (Chat Assistant): Answering vehicle-related questions, providing service advice, analyzing vehicle health
- Rego Lookup Fallback: Analyzing registration plate formats to suggest vehicle details when API lookup fails
- Future Features: Service record summarization, predictive maintenance alerts, cost optimization
4.2 Data Sent to AI Providers. When you use AI features, the following data is sent to third-party AI service providers:
- Your chat prompts/questions
- Vehicle data relevant to your query (make, model, year, service history, odometer readings)
- Registration plate numbers (for rego lookup fallback)
4.3 AI Provider Data Usage. Our AI service providers:
- Process your data to generate responses
- May use data to improve service quality and detect abuse
- Do NOT use your data to train foundational AI models (as of February 2026)
- Process data in cloud data centers (which may be located outside Australia — see Section 8)
4.4 AI Data Retention. We do NOT permanently store your AI chat transcripts unless you explicitly save them. Temporary prompts are deleted within 30 days.
4.5 Opting Out of AI. You can avoid using AI features by not interacting with Ask Axel. Core platform features (vehicle management, reminders) do NOT require AI usage.
5. How We Share Your Personal Information (APP 6)
5.1 Third-Party Service Providers. We share personal information with trusted third parties to deliver the Service:
| Service Type | Purpose | Data Shared | Location |
|---|---|---|---|
| Cloud database hosting | Data storage and management | All Account and Vehicle Data | Australia (primary), USA (backup) |
| Authentication services | User login and identity verification | Email, name, password hash | USA, EU |
| Payment processing | Subscription billing and payments | Billing details, card info | USA, global |
| AI service providers | Chat assistant and analysis | Chat prompts, vehicle data | USA, global |
| Telematics providers (optional) | Fleet tracking integration | Vehicle GPS, diagnostics | Canada, global |
| NEVDIS brokers | Vehicle data lookup | Rego numbers, state | Australia |
| Cloud hosting and CDN | Website hosting and delivery | Usage analytics, IP addresses | USA, global |
| Email delivery services | Transactional and marketing emails | Email addresses, message content | USA |
5.2 We Do NOT Sell Your Data. We will never sell, rent, or trade your personal information to third parties for marketing purposes.
5.3 Legal Disclosures. We may disclose personal information if required by law:
- In response to court orders, subpoenas, or warrants;
- To comply with Australian tax laws (ATO reporting);
- To law enforcement agencies investigating crimes;
- To protect our rights, property, or safety, or that of our users.
5.4 Business Transfers. If Hey Axel is acquired, merged, or sold, your personal information may be transferred to the successor entity. We will notify you via email before such transfer.
6. Data Retention (APP 11)
6.1 How Long We Keep Data.
- Account Data: Retained while your Account is active + 30 days after deletion (to allow recovery if accidental);
- Vehicle Data: Retained while your Account is active + 30 days after deletion;
- Payment Records: Retained for 7 years (ATO tax compliance requirement);
- Support Emails: Retained for 2 years;
- Analytics Data: Aggregated/anonymized data retained indefinitely (no longer personal information);
- AI Chat Logs: Deleted within 30 days unless you explicitly save them.
6.2 Deletion Requests. You may request Account deletion at any time via:
- Account settings → "Delete Account" button; OR
- Email: support@heyaxel.app with subject "Account Deletion Request"
We will delete your data within 30 days, except where legal retention is required (e.g., tax records).
7. Data Security (APP 11)
7.1 Security Measures. We implement industry-standard security practices:
- Encryption: Data encrypted in transit (HTTPS/TLS) and at rest (AES-256)
- Access Controls: Role-based access, multi-factor authentication (MFA) for admin accounts
- Password Security: Passwords hashed with bcrypt (we do NOT store plaintext passwords)
- Infrastructure Security: Hosted on secure cloud platforms with SOC 2 Type II compliance
- Regular Audits: Penetration testing and vulnerability scans
- Data Backups: Daily automated backups with 30-day retention
7.2 No System is Perfect. Despite our efforts, no security system is 100% secure. We cannot guarantee absolute security of your data. You are responsible for keeping your password confidential.
7.3 Notifiable Data Breaches (NDB Scheme). If a data breach occurs that is likely to result in serious harm, we will:
- Notify affected users within 72 hours (via email);
- Notify the Office of the Australian Information Commissioner (OAIC) as required under the Privacy Act 1988 (Cth), Part IIIC;
- Take remedial action to contain and mitigate the breach.
8. Cross-Border Data Transfers (APP 8)
8.1 Where Your Data is Stored. While Hey Axel is an Australian company, some of our service providers are located overseas:
- Primary Storage: Cloud database services (Australia-based servers)
- Backup Storage: Cloud redundancy (USA-based)
- Authentication: Authentication services (USA, EU)
- Payments: Payment processors (USA, processed globally)
- AI Processing: AI service providers (USA, global cloud data centers)
- Email Delivery: Email services (USA)
- Hosting: Cloud hosting and CDN (USA, global)
8.2 Overseas Disclosure. By using Hey Axel, you consent to your personal information being disclosed to overseas recipients in the countries listed above. These recipients may not be subject to the Privacy Act 1988 (Cth) or equivalent privacy protections.
8.3 Your Rights. You can withdraw consent to overseas transfers by ceasing to use the Service. Note that certain features (e.g., AI chat) require overseas processing and cannot function without it.
9. Your Privacy Rights (APPs 6, 12, 13)
9.1 Access Your Information (APP 12). You may request access to your personal information by:
- Logging into your Account and viewing your profile/vehicles; OR
- Emailing support@heyaxel.app with subject "Privacy Access Request"
We will provide access within 30 days, free of charge (unless the request is excessive or unreasonable).
9.2 Correct Your Information (APP 13). You may update inaccurate information by:
- Editing your Account details or Vehicle Data in the platform; OR
- Emailing support@heyaxel.app to request corrections
9.3 Delete Your Information (APP 13). You may request deletion of your Account and data (see Section 6.2 above).
9.4 Opt Out of Marketing (APP 7). You may opt out of promotional emails by:
- Clicking "Unsubscribe" in any marketing email; OR
- Updating your email preferences in Account settings
You CANNOT opt out of transactional emails (e.g., billing alerts, Account notifications).
9.5 Data Portability. You may export your Vehicle Data in CSV format via Account settings → "Export Data".
10. Cookies and Tracking (APP 1)
10.1 Types of Cookies We Use.
Essential Cookies (Required):
- Session cookies: User authentication and login state
- Database session tokens: Secure database access
- These cookies are necessary for the Service to function and cannot be disabled.
Analytics Cookies (Optional):
- Web analytics: Anonymized usage statistics (pages viewed, session duration)
- Performance monitoring: Load times, error tracking
- You can disable analytics cookies via your browser settings or opt-out tools.
10.2 Do Not Track. We do not currently respond to "Do Not Track" browser signals, as there is no industry standard for interpreting DNT requests.
11. Children's Privacy
11.1 Age Restriction. Hey Axel is NOT intended for children under 18. We do not knowingly collect personal information from children.
11.2 Parental Notice. If you are a parent or guardian and believe your child has provided personal information to Hey Axel, contact us immediately at support@heyaxel.app. We will delete the information within 7 days.
12. Australian Privacy Principles (APPs) Compliance Summary
Hey Axel complies with all 13 APPs under the Privacy Act 1988 (Cth):
| APP | Requirement | How We Comply |
|---|---|---|
| APP 1 | Open and transparent management of personal information | This Privacy Policy is publicly accessible; contact details provided |
| APP 2 | Anonymity and pseudonymity | Not practicable (Account required to use Service) |
| APP 3 | Collection of solicited personal information | We only collect information necessary for Service delivery |
| APP 4 | Dealing with unsolicited personal information | Unsolicited info deleted within 30 days unless lawful to retain |
| APP 5 | Notification of collection | This Privacy Policy notifies users of collection; displayed at signup |
| APP 6 | Use or disclosure of personal information | Data used only for stated purposes; consent obtained for secondary uses |
| APP 7 | Direct marketing | Opt-out available in all marketing emails; comply with Spam Act 2003 |
| APP 8 | Cross-border disclosure of personal information | Users notified of overseas recipients (Section 8); consent obtained |
| APP 9 | Adoption, use, or disclosure of government related identifiers | We do NOT use government identifiers (Medicare, driver's license) as user IDs |
| APP 10 | Quality of personal information | Users can update info anytime; we verify accuracy where reasonably practicable |
| APP 11 | Security of personal information | Encryption, access controls, regular audits (Section 7) |
| APP 12 | Access to personal information | Users can access data via Account settings or by emailing us (Section 9) |
| APP 13 | Correction of personal information | Users can correct data via Account settings or by emailing us (Section 9) |
13. Other Australian Laws We Comply With
- Spam Act 2003 (Cth): All marketing emails include unsubscribe links; we do NOT send unsolicited SMS without consent
- Telecommunications Act 1997 (Cth): We do NOT intercept or access telecommunications data beyond what's necessary for Service delivery
- Electronic Transactions Act 1999 (Cth): Electronic consents (e.g., Terms acceptance) are legally binding
- State Road Transport Legislation: We access vehicle data only via authorised APIs (no illegal scraping of government portals)
14. Complaints and Dispute Resolution (APP 1)
14.1 How to Complain. If you have concerns about our privacy practices:
- Email us at support@heyaxel.app with subject "Privacy Complaint"
- Provide details of your concern (what happened, when, what information was involved)
- We will acknowledge your complaint within 7 days and respond within 30 days
14.2 Office of the Australian Information Commissioner (OAIC). If you are not satisfied with our response, you may lodge a complaint with the OAIC:
- Website: https://www.oaic.gov.au/
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
- Mail: GPO Box 5218, Sydney NSW 2001
15. Changes to This Privacy Policy
15.1 Updates. We may update this Privacy Policy to reflect:
- Changes in Australian privacy law;
- New features or services;
- Changes to our data practices.
15.2 Notification. Material changes will be notified via:
- Email to your registered email address (at least 14 days before taking effect);
- In-app notification;
- Updated "Last Updated" date at the top of this page.
15.3 Continued Use. Your continued use of Hey Axel after changes take effect constitutes acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information:
Hey Axel Pty Ltd
Email: support@heyaxel.app
Website: https://heyaxel.app
Jurisdiction: New South Wales, Australia
Your Privacy Matters
We take your privacy seriously. If you have any questions or concerns about how we handle your personal information, please don't hesitate to reach out at support@heyaxel.app.
Remember: You have the right to access, correct, or delete your personal information at any time. You can also lodge a complaint with the OAIC if you're not satisfied with our response.