PalletLoop
ProductSecurityPricing
Sign inSign up

Privacy Policy

Effective date: 21 June 2026  ·  PalletLoop Pty Ltd  ·  Australian Privacy Act 1988 compliant

Contents

  1. 1. About This Policy
  2. 2. Who We Are
  3. 3. What Personal Information We Collect
  4. 4. How We Collect It
  5. 5. Why We Collect It
  6. 6. How We Use & Disclose It
  7. 7. Sub-Processors & Third Parties
  8. 8. International Data Transfers
  9. 9. Data Security
  10. 10. Retention
  11. 11. Your Rights Under the Australian Privacy Act
  12. 12. Data Processing (B2B)
  13. 13. Cookies & Analytics
  14. 14. Children's Privacy
  15. 15. Changes to This Policy
  16. 16. Contact Us

1. About This Policy

This Privacy Policy explains how PalletLoop Pty Ltd collects, uses, discloses, and protects personal information in connection with the PalletLoop platform ("Service"). It applies to all users of the Service, including parent company admins, customer engagement staff, warehouse team members, and transporter users.

PalletLoop is committed to complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy describes our practices in plain language.

2. Who We Are

PalletLoop Pty Ltd is an Australian company that provides a returns visibility and logistics coordination platform for FMCG operators and their 3PL partners. For the purposes of this policy, we are the "operator" of the Service and, where we process personal information on behalf of our business customers, we act as a "data processor" on their behalf.

Contact: hello@palletloop.io

3. What Personal Information We Collect

We collect the following categories of personal information:

  • Account information: Name, email address, job title, and employer when you register or are invited to the Service.
  • Authentication data: Hashed passwords and authentication tokens (managed by Supabase Auth). We never store passwords in plain text.
  • Usage data: IP addresses, browser type, pages visited, actions taken within the Service, and session data, collected for security and product improvement.
  • Business operational data: Return records, warehouse and transporter details, customer names and contact details, SKU and inventory data, checklist results, and audit trail entries — entered by users in the course of using the Service. This data may include the names and contact details of individuals at your partner organisations.
  • Billing information: Billing name, address, and payment method details. Payment card data is handled directly by Stripe and is not stored on PalletLoop systems.
  • Communications: Email correspondence and support requests you send to us.

4. How We Collect It

We collect personal information:

  • Directly from you when you sign up, fill in forms, or communicate with us;
  • From your organisation when a company administrator creates an account on your behalf, invites you to the platform, or enters your details into the system;
  • From your 3PL partner organisations when they are invited by a parent company and create accounts;
  • Automatically via cookies, server logs, and analytics tools when you use the Service.

5. Why We Collect It

We collect personal information for the following purposes:

  • To create and manage user accounts;
  • To provide and operate the Service, including return tracking, notifications, and reporting;
  • To send transactional emails (return status updates, aging alerts, discrepancy notifications);
  • To process subscription payments and manage billing;
  • To respond to support enquiries;
  • To detect and prevent fraud, abuse, and security incidents;
  • To improve the Service through anonymised usage analytics;
  • To comply with legal obligations.

6. How We Use & Disclose It

We do not sell personal information. We do not share personal information with third parties except:

  • Sub-processors: Third-party services we use to operate the Service (see Section 7);
  • Within your organisation: Users you have authorised (e.g. admins see all user profiles within their tenant; partner users see only their scoped data);
  • Legal requirements: Where required by law, court order, or to protect the rights, property, or safety of PalletLoop, our users, or the public;
  • Business transfers: In connection with a merger, acquisition, or sale of all or substantially all of our assets, where the acquiring party agrees to honour this policy.

7. Sub-Processors & Third Parties

We use the following sub-processors to operate the Service. Each is subject to a data processing agreement and appropriate security controls:

  • Supabase (database, authentication, file storage) — data hosted in AWS ap-southeast-2 (Sydney, Australia);
  • Vercel (hosting and edge compute) — servers globally distributed; compute may run outside Australia but does not store personal data persistently;
  • Stripe (payment processing) — subject to PCI DSS compliance;
  • Resend (transactional email delivery) — email content may transit servers in the United States;
  • PostHog (product analytics) — usage data anonymised before transmission; EU-region instance used;
  • Sentry (error monitoring) — error logs may include partial request data; data retained in the United States.

We do not share personal information with advertising networks, data brokers, or social media platforms.

8. International Data Transfers

Your primary account and return data is stored in Australia (AWS ap-southeast-2). Some sub-processors (Resend, Sentry) may process limited data outside Australia. In each case we ensure appropriate protections are in place, including contractual clauses consistent with Australian Privacy Principle 8.

9. Data Security

We implement technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration, and destruction, including:

  • Encryption in transit: All data transmitted to and from the Service uses TLS 1.3;
  • Encryption at rest: Data stored in Supabase is encrypted at rest using AES-256;
  • Row-level security: Each tenant's data is isolated at the database layer — other customers cannot access your data even if they know your IDs;
  • Role-based access: Users see only the data appropriate to their role and assigned scope (warehouse, transporter, or company-wide);
  • Audit logging: All significant actions are recorded with actor identity and timestamp in an immutable audit log.

No method of transmission over the internet or electronic storage is 100% secure. If you become aware of a security incident relating to your account, notify us immediately at hello@palletloop.io.

10. Retention

We retain personal information for as long as necessary to fulfil the purposes described in this policy:

  • Active accounts: Data retained for the duration of the account;
  • Closed accounts: Personal information in live systems deleted within 30 days of account closure. You may request an export of your data before closure;
  • Audit logs: Immutable audit log entries may be retained for up to 7 years for finance reconciliation and legal compliance purposes, in anonymised or pseudonymised form;
  • Backups: Encrypted backups may persist for up to 90 days after account closure before being purged;
  • Legal holds: We may retain data for longer if required by law or in connection with a legal claim.

11. Your Rights Under the Australian Privacy Act

Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:

  • Access: Request a copy of the personal information we hold about you;
  • Correction: Request correction of inaccurate, incomplete, or out-of-date information;
  • Deletion: Request deletion of your personal information (subject to legal retention requirements);
  • Complaints: Lodge a complaint with us, and if unresolved, with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

To exercise any of these rights, contact us at hello@palletloop.io. We will respond within 30 days. In some cases, we may need to verify your identity before processing your request.

12. Data Processing (B2B)

PalletLoop's business customers (FMCG operators) are "data controllers" in respect of the personal information of their employees, customers, and 3PL partner contacts that they enter into the Service. PalletLoop acts as a "data processor" on their behalf for that data.

Our Terms of Service govern the processing relationship. Key terms include: we process Customer Data only on the instructions of the customer; we do not subcontract processing to parties not listed as sub-processors without notice; and we implement the security measures described in Section 9.

If you are an individual whose data has been entered into PalletLoop by one of our business customers and you wish to exercise your privacy rights, you should contact that business directly. We will cooperate with their requests on your behalf.

13. Cookies & Analytics

We use the following types of cookies and similar technologies:

  • Session cookies (essential): Required for authentication and to maintain your logged-in session. These cannot be disabled without breaking the Service.
  • Analytics (PostHog): We use PostHog to collect anonymised usage data to understand how the product is used and to improve it. This data does not identify you personally. You can opt out of PostHog analytics by contacting us.

We do not use advertising cookies, tracking pixels, or third-party retargeting technologies.

14. Children's Privacy

The Service is intended for business users aged 18 and over. We do not knowingly collect personal information from individuals under 18. If you believe a minor has provided us with personal information, please contact us so we can delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days before the change takes effect. The effective date at the top of this page indicates when it was last updated. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

16. Contact Us

For privacy enquiries, access requests, or complaints, contact us at:

PalletLoop Pty Ltd
Email: hello@palletloop.io
Subject line: Privacy enquiry

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):

  • Website: oaic.gov.au
  • Phone: 1300 363 992

This policy was last updated on 21 June 2026.

PalletLoop

Returns visibility for FMCG operations. Built with operators and their 3PLs.

Product
  • How it works
  • Security
  • Pricing
Company
  • Contact
  • About us
Legal
  • Privacy policy
  • Terms of service
  • Data processing
© 2026 PalletLoop · hello@palletloop.ioStatus · all systems normal ●