Privacy policy
Last updated 13 September 2026
ServiceFast (“ServiceFast”, “we”, “us”) provides a workspace that Australian construction and service businesses use to manage enquiries, estimates, jobs, invoices and aftercare. This policy explains what personal information we handle, why, and the choices you have. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Who is responsible for which information
Each business that uses ServiceFast has its own workspace. The business decides what records it keeps there, such as its clients, contacts, leads, estimates, jobs, documents and photos, and it is responsible for that information. We store and process it on the business’s behalf to provide the service. We are responsible for the account information we need to run ServiceFast itself.
Information we collect
- Account details. When you sign in with Google we receive your name, email address, profile picture and a Google account identifier. When you join a workspace by invitation we receive your email address and confirm it with a single-use sign-in link. We never receive your Google password.
- Workspace records. Information you or your team enter or upload, including customer names, contact details, site addresses, estimates, job records, invoices, documents and photos.
- Connected channels. If your business connects them, messages and enquiries received through WhatsApp or Meta lead forms, call records from a connected phone number, and invoices, payments and bills sent to Xero or QuickBooks Online.
- Billing. Subscription status and invoice history for your business. Card details are entered with Stripe and are not stored by ServiceFast.
- Technical information. The IP address and browser details recorded with each sign-in session, and service logs used to keep ServiceFast secure and working.
Information from Google
ServiceFast requests only your basic Google profile (name, email address and profile picture) so you can sign in and so your account can be identified. We do not use Google user data for advertising, we do not sell it, and we do not share it except with the service providers listed below where needed to run ServiceFast. ServiceFast’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
- To provide ServiceFast: sign-in, workspace access, the records your team manages, and the connections your business turns on.
- To send service emails such as team invitations and sign-in links.
- To manage subscriptions and billing for your business.
- To keep ServiceFast secure, investigate misuse, and meet legal obligations.
- To respond when you contact us.
We do not sell personal information, and we do not use advertising cookies or third-party analytics trackers.
Cookies
ServiceFast uses essential cookies only: a secure sign-in session cookie and a preference that remembers which workspace you last opened. Sign-in sessions end after seven days without use.
Where information is stored and who processes it
Workspace records are stored in a database hosted in Sydney, Australia. Uploaded files, email delivery and the ServiceFast application run on Cloudflare’s network, which may process information in other countries. We use these service providers to run ServiceFast:
- Cloudflare (application hosting, file storage and email delivery)
- Neon (database hosting in Sydney)
- Google (sign-in)
- Stripe (subscription billing)
- Meta, Twilio, Xero and Intuit, only when a business connects those services
Some of these providers are based in, or process information in, countries outside Australia, including the United States. We take reasonable steps to ensure they protect personal information consistently with the Australian Privacy Principles.
Security
Information is encrypted in transit. Each workspace is isolated from every other workspace, access is limited by team role, connection tokens for third-party services are encrypted at rest, and invitation and sign-in links are stored only as one-way hashes and expire.
Keeping and deleting information
We keep workspace records while the business’s workspace is active. Workspace owners and admins can export their records at any time; export files are deleted after seven days. When a workspace is closed we delete or de-identify its records within a reasonable period unless we are required by law to keep them.
Access, correction and complaints
You can ask to access or correct your personal information, or ask a question about this policy, by emailing support@servicefast.dev. If your information is held in a business’s workspace, we may refer your request to that business. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
We will update this page when our practices change and revise the date above.