Privacy Policy
Last updated: 13 September 2026
This policy covers Escape Velocity Ventures Pty Ltd (ACN 701 425 809), trading as BrickTrack, ABN 13 701 425 809. “We” and “us” mean that company.
1. Information We Collect
When you use BrickTrack, we collect information you provide directly:
- Account information (name, email address)
- Property details you enter
- Documents you upload
- Export job records created when you request a data export
- A deletion log entry (hashed identifiers only) when your account is hard-deleted, retained for compliance evidence
2. How We Use Your Information
We use your information to:
- Provide and improve our services
- Generate reports and analytics for your properties
- Send service-related notifications
- Provide customer support
3. Data Storage
Your portfolio records and documents are stored on secure servers located in Australia. Some supporting services process limited data offshore; each one is listed in the sub-processor table below, with the region it operates in where the provider publishes one. We use encryption at rest and in transit to protect your information.
We use Supabase with point-in-time recovery (PITR) backups enabled. After your account is hard-deleted, residual data may remain in PITR snapshots for up to 7 days (preview) or the configured production backup retention window. If a database restore is performed from a pre-deletion snapshot, we re-run our deletion cron to purge any user whose deletion log confirms they were hard-deleted before the snapshot was taken.
4. Data Sharing
We do not sell your personal information. We share data only with the sub-processors below, each bound by a Data Processing Agreement or equivalent contractual terms. Deletion-mode footnotes reflect the current implementation state as of September 2026.
| Sub-processor | Hosting region | Purpose | On account deletion |
|---|---|---|---|
| Stripe | US (AU presence) | Payment processing & billing | Customer record anonymised at T+30 days; fully deleted at T+120 days via automated cron.1 |
| Supabase (Postgres + Storage) | Australia (ap-southeast-2) | Primary database & file storage | DB rows cascade-deleted; Storage objects owned only by your account are purged on hard-delete. Files attached to a completed ownership transfer remain for the recipient.2 |
| PostHog | United States (us.i.posthog.com) | Product analytics (event capture) and session replay (see section 6) | A $delete_person integration to remove your analytics profile on hard-delete is in development.3 |
| Sentry | United States (ingest.us.sentry.io) | Error monitoring and session replay (see section 6) | PII scrubbing is configured at the SDK level (beforeSend filter). A Sentry on-delete REST API call is in development.4 |
| Axiom | US (AWS us-east) | Log aggregation & observability (request logs including user id, request ids, and error context) | Request logs auto-expire per the configured Axiom retention window; no per-account on-delete purge. |
| Resend | US | Transactional email delivery (account, billing, digest, alerts) | Email address suppressed on deletion; transactional send records retained for 90 days then deleted. |
| Vercel | Sydney (syd1) | Web hosting & serverless compute | No persistent user data stored at the platform layer. Server logs retained per Vercel platform defaults (typically 30 days). |
| Cloudflare (Turnstile) | Global edge | Bot-protection challenge on sign-up / sign-in | Challenge tokens are transient and not linked to your account after verification. No on-delete action required. |
| Alibaba Cloud (Qwen), via Vercel AI Gateway | Region not published by the provider | Answers questions you ask the in-app assistant. Your question and the portfolio figures needed to answer it — property addresses, loan balances, transactions — are sent to the model. Only used when you open the assistant.5 | Nothing is stored on our behalf, so there is no record tied to your account to delete. What the provider retains is governed by its own terms. |
| Anthropic (Claude) | United States | Categorises imported transactions and reads figures out of documents you upload — settlement statements, depreciation schedules, receipts. The text of the document or transaction is sent; the file itself is not. | Nothing is stored on our behalf, so there is no record tied to your account to delete. What the provider retains is governed by its own terms. |
1 Stripe customer records are anonymised at deletion and fully deleted at T+120 days via the cleanup-stripe-deletions cron.
2 Supabase Storage objects (documents and exports) are purged on hard-delete via recursive prefix purge. A document path still referenced by another account after an ownership transfer is excluded because those bytes belong to the recipient's live records.
3 PostHog event capture and session replay; a $delete_person integration is in development. Replays expire on PostHog's retention schedule and there is no per-account purge for them today.
4 Sentry error capture and session replay; PII scrubbing is configured at the SDK level; an on-delete REST API call is in development. Replays expire on Sentry's retention schedule and there is no per-account purge for them today.
5 The assistant reaches the model through Vercel AI Gateway, which routes the request to Alibaba Cloud. We ask the gateway to use only providers it holds a zero-retention agreement with, but we have not been able to verify that it refuses a provider without one, so we do not describe this as a retention guarantee.
We may also share data:
- When required by law or to protect our rights
- With your consent (e.g., sharing reports with your accountant)
5. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Export your data as a structured archive, at any time and on every plan, from the Delete Account page in Settings
When you request an export, BrickTrack generates a ZIP archive containing your properties, transactions and other personal data in JSON and CSV formats, plus any valuation evidence you have attached. Other uploaded documents are not included yet. Your download link is valid for one hour.
An audit log of significant account actions (e.g., property additions) is included in your export. When your account is hard-deleted, audit log entries are anonymised (the actor reference is set to null) and retained as compliance evidence for any shared portfolio you were a member of. Stripe payment records are anonymised at T+30 days and fully deleted at T+120 days; a copy of your billing history is included in your export before deletion.
6. Cookies, tracking & session replay
We classify cookies and similar storage into three categories:
- Essential. Authentication session cookies, CSRF tokens, sidebar/UI preference state, and Cloudflare Turnstile challenge tokens. Always on — these are required for BrickTrack to function.
- Analytics. Product-usage events captured via PostHog (pageviews + activation funnel events), tied to your account once you sign in. Off by default until you accept analytics in the cookie banner. Your choice is stored locally (
bt_cookie_consent); declining keeps PostHog uninitialised, so nothing is captured and no session is recorded. Accepting analytics also turns on PostHog session replay, described below. - Marketing. BrickTrack does not currently set any marketing or advertising cookies, nor does it allow third-party advertising trackers.
Your cookie-consent choice is stored locally on your device and replayed on subsequent visits. Clearing browser storage will reset the choice.
Session replay
Two things record your screen, and they record different amounts. Sentry captures only the moments before an error: it holds a short rolling buffer in memory and discards it unless something goes wrong, at which point we upload that buffer. PostHog records ordinary sessions from start to finish, and only if you accepted analytics in the cookie banner — decline, and PostHog never loads and nothing is recorded.
These recordings cover whichever page you were on, which across most of BrickTrack means property valuations, loan balances, rent figures and tax positions. The same two limits apply to both recorders. We replace every piece of text on the page with placeholder characters before the recording leaves your browser, so the actual dollar amounts, addresses and lender names are not readable in it. We also block images, uploaded documents and other media outright.
What masking does not hide is the shape of the session: page layout, the URLs you visited, where you clicked, how you scrolled and moved the pointer, and the timing of all of it. Someone watching a replay can see that you opened a property and moved from the loans tab to the tax tab. They cannot read the numbers on either. We do not describe these recordings as anonymous. A Sentry replay is attached to an error that is linked to your account, and once you sign in we tell PostHog who you are, so a PostHog replay is linked to you too.
The recorder does not load on the sign-in or sign-up pages when you arrive there directly, and it runs independently of the analytics choice in the cookie banner, because its purpose is diagnosing faults rather than measuring usage. Declining analytics stops PostHog; it does not stop error reporting. Sentry holds this data in the United States.
7. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or in-app notification.
8. Contact Us
If you have questions about this privacy policy, please contact us at privacy@bricktrack.au.
9. Data Retention
BrickTrack retains your personal data for as long as your account is active. After you request account deletion, a 30-day grace period applies during which you may cancel the request. After the grace period expires, your database records, uploaded documents, and storage objects that remain owned only by your account are permanently deleted. Documents attached to a completed ownership transfer remain available to the recipient. Hashed identifiers are retained in a deletion log for compliance evidence under the Australian Privacy Principles (APP 11.2).