Privacy Policy
Last updated: 28 August 2026
Dragtech Services Pty Ltd (ABN 81 669 539 315) ("Dragtech Services", "we", "us") operates WorkShifts (workshifts.com.au). This Privacy Policy explains how we collect, use, store, and disclose personal information in connection with the Service.
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Two Kinds of Personal Information We Handle
It's important to distinguish between:
- Account and billing information — information about the businesses and individuals who sign up for WorkShifts directly (company name, coordinator name, email, billing details). We are the data controller for this information.
- Customer Data (employee records) — information our business customers ("Customers") input about their own employees or contractors (e.g. name, date of birth, home address, emergency contact details, competency/certification numbers, employer reference numbers). In relation to this data, we act as a data processor on behalf of our Customers, who remain responsible as the primary collector of that information from their own employees. If you are an employee whose data has been entered into WorkShifts by your employer, your relationship regarding that data is primarily with your employer — see section 8.
2. Information We Collect
From Customers (account holders):
- Name, email address, phone number, company details
- Billing information — processed by our payment provider, Stripe; we do not store full card numbers on our own systems
- Usage data (login activity, feature usage, device/browser information) for security and product improvement
Customer Data (input by our Customers about their employees):
- Name, date of birth, home address, emergency contact/next of kin details
- Employment details, shift and roster data, hours worked
- Competency certificates, compliance documents, and external reference numbers (e.g. site access card numbers, unique student identifiers, safety certification numbers)
3. How We Use Information
We use personal information to:
- Provide, operate, and maintain the Service (rostering, scheduling, compliance tracking, quoting)
- Process subscription payments via Stripe
- Communicate with Customers about their account, billing, and service updates
- Provide customer support
- Improve and secure the platform
- Comply with legal obligations
We do not sell personal information to third parties, and we do not use Customer Data (employee records) for our own marketing purposes.
4. Where Data Is Stored
Data is stored using Supabase, with our database hosted in the Singapore region. This means personal information is transferred to and stored outside Australia.
Under Australian Privacy Principle 8, when personal information is disclosed to an overseas recipient, we must take reasonable steps to ensure the overseas recipient does not breach the APPs.
We have entered into a Data Processing Addendum with Supabase that contractually requires Supabase to, among other things: encrypt data at rest (AES-256) and in transit (TLS 1.2+); restrict access to personal data on a least-privilege basis with mandatory two-factor authentication for internal access; notify us of any security incident without undue delay (and in any event within 48 hours of becoming aware of it); maintain SOC 2 Type 2, ISO 27001, and HIPAA compliance; and impose equivalent data protection obligations on any sub-processors it engages. Supabase's Data Processing Addendum is available at supabase.com/legal/dpa.
By using the Service, Customers acknowledge and consent to this overseas storage arrangement, including in relation to the employee personal information they input as Customer Data.
5. Payment Information
Subscription payments are processed by Stripe. We do not store full credit card numbers. Stripe's handling of payment data is governed by Stripe's Privacy Policy. Stripe may store and process payment information outside Australia as part of its global payment infrastructure.
6. Disclosure of Information
We may disclose personal information to:
- Service providers who help us operate the platform (e.g. Supabase for data storage, Stripe for payments, Resend for transactional email, Vercel for hosting)
- Professional advisors (legal, accounting) where necessary
- Regulators or law enforcement where required by law
- A purchaser in the event of a business sale or restructure, subject to appropriate confidentiality protections
We do not disclose Customer Data (employee records) to other tenants of the platform — each Customer's data is logically separated and access-controlled.
7. Data Security
We use reasonable technical and organisational measures to protect personal information, including access controls, encryption in transit, and role-based permissions within the platform. No system is completely secure, and we cannot guarantee absolute security.
8. If You Are an Employee of One of Our Customers
If your employer uses WorkShifts to manage your rostering and employment records, your personal information is entered and controlled by your employer (the "Customer"). Questions about how your data is used, corrected, or deleted should generally be directed to your employer in the first instance, as they determine what information is collected and for what purpose. We assist Customers in fulfilling these obligations as their service provider.
9. Data Retention
- Account and billing information is retained for the duration of the subscription and for a reasonable period afterward for legal, accounting, and dispute-resolution purposes.
- Customer Data is retained for 90 days following subscription termination to allow the Customer to export their data, after which it may be permanently deleted, unless retention is required by law.
10. Access, Correction, and Complaints
Individuals may request access to or correction of personal information we hold, subject to any exceptions under the Privacy Act. Requests can be made to contact@workshifts.com.au.
If you believe we have breached the APPs, you may lodge a complaint with us at the above email, or with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Data Breach Notification
In the event of a data breach likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme, including notifying affected individuals and the OAIC where required.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app notice.
13. Contact Us
Dragtech Services Pty Ltd
ABN 81 669 539 315
Mackay, Queensland, Australia
contact@workshifts.com.au