GraphRetail← Back to home

Privacy Policy

Last updated: 8 August 2026

GraphRetail (Confumo Pty Ltd, ABN 24 160 002 700)("we", "us", "our") operates the graphretail.com website and the GraphRetail platform. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service. Where we rely on your consent for a particular use — such as marketing emails — we ask for that consent separately, and you can withdraw it at any time without affecting your use of the Service.

1. Information We Collect

We collect the following types of information across all modules of the Service:

  • Account information: Your name, email address, password (hashed), company name, and store details when you create an account.
  • Staff data: Names, email addresses, roles, and permissions for staff accounts you create within the Service.
  • Transaction data (POS): Sales records, payment methods, receipt details, refund records, gift card balances, and held sale data processed through the Point of Sale module.
  • Inventory data: Product catalogues, stock levels, purchase orders, supplier information, and stock transfer records entered into the Inventory module.
  • Customer data (CRM): Information about your customers that you store in our CRM, including names, contact details, purchase history, and segmentation tags.
  • Repair data: Repair job records, device details, repair status history, parts used, customer notifications, and repair-specific invoices managed through the Repair Tracking module.
  • Invoicing data: Invoice records, recurring invoice configurations, payment terms, and PDF-generated invoice content.
  • Marketing data: Campaign records, recipient lists, message content, and delivery status for SMS and email campaigns sent via the Marketing module.
  • Analytics & reporting data: Dashboard metrics, KPI snapshots, revenue reports, and performance data generated from your usage.
  • Usage data: How you interact with the platform, including pages visited, features used, and actions taken.
  • Device information: Browser type, operating system, IP address, and device identifiers.

2. How We Use Your Information

We use the collected information to:

  • Provide, operate, and maintain all modules of the GraphRetail platform
  • Process POS transactions and generate receipts and invoices
  • Track inventory levels and facilitate stock transfers between your locations
  • Manage repair workflows and send customer status notifications
  • Generate and deliver invoices, including recurring invoices
  • Provide CRM features including customer profiles and purchase history
  • Facilitate marketing campaigns via SMS and email integrations
  • Provide AI-powered features including sales coaching, executive reports, analytics insights, and upsell recommendations
  • Generate dashboard analytics, reports, and KPI metrics
  • Send you technical notices, updates, and support messages
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our Terms of Service

3. AI Data Processing

Our Service includes AI-powered features that process your business data to provide analytics, sales coaching, executive reports, and automated upsell recommendations. When using AI features:

  • Your data may be processed by third-party AI model providers to generate responses and insights
  • We transmit only the minimum data necessary to provide the requested AI functionality
  • We do not use your business data to train general-purpose AI models
  • AI outputs are generated algorithmically and we make no guarantees regarding their accuracy

4. Data Storage and Security

Your data is stored in tenant-isolated databases on infrastructure we operate in Amazon Web Services' Sydney region (ap-southeast-2), with encrypted backups held in the same region. Our security measures include:

  • Automated encrypted backups with off-site replication
  • Automated backup integrity verification and restoration testing
  • Encryption in transit (HTTPS/TLS) and at rest
  • Tenant-isolated database architecture
  • Role-based access controls and audit logging
  • Continuous infrastructure monitoring and alerting

Important: No method of transmission over the Internet or of electronic storage is completely secure, so we cannot guarantee absolute security. We take the steps described above, and our liability if something goes wrong is dealt with in our Terms of Service — nothing in this policy or those terms excludes rights you have under the Australian Consumer Law or the Privacy Act 1988.

5. Data Retention

We keep personal information only as long as we need it, or as long as the law requires us to. Our standard periods are:

  • Account and staff records: for the life of your account, then 30 days after termination.
  • Sales, invoice, refund and payment records: 5 years, because Australian tax law requires business records to be kept for that period. Deleting your account does not shorten this.
  • Repair records: for the life of your account, then 30 days after termination. Device passcodes are removed once a repair is collected.
  • CRM and marketing records: for the life of your account. Unsubscribe and suppression records are kept indefinitely, because we need them to keep honouring an opt-out.
  • Backups: encrypted backups roll off on their retention schedule, so deleted data may persist in backups for a short period after deletion.
  • Aggregated, de-identified statistics: may be kept indefinitely. These cannot be linked back to an individual.

After account termination you have 30 days to export your data. We may then delete it. If you ask us to delete a specific individual's personal information sooner, we will do so — except where a record must be retained for tax or legal reasons, in which case we de-identify it instead of deleting it.

6. Data Sharing and Who Processes Your Data

We do not sell, trade, or rent your personal information. We use the following service providers:

  • Amazon Web Services — hosting, database and encrypted backups. Sydney, Australia (ap-southeast-2).
  • Stripe — subscription billing and payment processing. Card details are entered directly with Stripe and never reach our servers. United States and Australia.
  • Twilio — SMS delivery, where you enable it. United States.
  • Anthropic — AI model provider for AI features. United States.
  • OpenAI — AI model provider for AI features. United States.
  • Meta Platforms — advertising measurement on our public marketing pages only (see Cookies below). United States.
  • Your own email provider — outbound email from the Service is sent through the SMTP credentials you configure, so your provider handles those messages.

We may also disclose personal information:

  • Where the law requires it: under a law, regulation, subpoena or legal process.
  • On a business transfer: in connection with a merger, acquisition, or sale of assets.
  • To protect rights and safety: where disclosure is necessary to protect our rights, your safety, or the safety of others.

7. Multi-Tenant Data Isolation

The GraphRetailplatform operates a multi-tenant architecture where each customer's data is logically isolated in separate databases. Your data is never accessible to or shared with other tenants. Staff accounts you create operate within your tenant boundary and are subject to the role-based access controls you configure.

8. Overseas Disclosure

Your data is stored in Australia. Some of the providers listed above are located overseas — principally in the United States — so using those features involves disclosing personal information to an overseas recipient:

  • Using an AI feature sends the data needed for that request to Anthropic or OpenAI in the United States. We send the minimum needed and do not permit your business data to be used to train general-purpose models.
  • Sending an SMS sends the recipient number and message to Twilio in the United States.
  • Billing involves Stripe in the United States and Australia.
  • Visiting our public marketing pages discloses page and device data to Meta Platforms in the United States.

We take reasonable steps to ensure these recipients handle personal information consistently with the Australian Privacy Principles. If you do not want data disclosed overseas, do not enable the AI or SMS features.

9. Your Rights

Subject to applicable law, you have the right to:

  • Access and receive a copy of your personal data
  • Correct inaccurate personal data
  • Request deletion of your personal data
  • Object to processing of your personal data
  • Export your data in a portable format
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at privacy@graphretail.com. We will acknowledge your request within 5 business days and respond within 30 days. Access and correction are free; we will tell you in advance if a request is unusually large and would attract a cost.

9.1 How to Complain

If you think we have mishandled your personal information, email privacy@graphretail.com with the details. We will acknowledge the complaint within 5 business days, investigate, and give you a written outcome within 30 days. If the investigation will take longer, we will tell you why and when to expect an answer.

If you are not satisfied with our response, you can take the complaint to the Office of the Australian Information Commissioner: oaic.gov.au, or 1300 363 992.

9.2 Data Breaches

If we become aware of unauthorised access to, or loss of, personal information, we assess it promptly and within 30 days. Where the breach is likely to result in serious harm, we notify the affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. Where the affected data belongs to a business customer's own customers, we notify that business without undue delay so they can meet their own notification obligations.

10. Your Customer Data Obligations

When you store your customers' personal data within the CRM, Marketing, or Repair modules, you act as the data controller for that information. You are solely responsible for:

  • Obtaining appropriate consent from your customers to store and process their data
  • Complying with applicable privacy laws (including the Australian Privacy Act 1988)
  • Responding to your customers' data access, correction, or deletion requests
  • Ensuring marketing communications comply with anti-spam legislation

11. Cookies and Tracking

Inside the app(after you sign in) we use essential cookies only — they keep you signed in and remember preferences such as your theme. There is no advertising or analytics tracking inside the Service, so your business data and your customers' data are never shared with an advertising network.

On our public marketing pages (our home page, feature and pricing pages, and the sign-up page) we run the Meta advertising pixel to measure the performance of our own advertising. It records the page you visited, your IP address, browser and device information, and whether you reached the sign-up page, and it discloses that information to Meta Platforms in the United States. It does not run on any page inside the app.

You can stop it by blocking third-party scripts in your browser, using a tracker-blocking extension, or adjusting your Meta ad preferences. Blocking it does not affect your ability to sign up or use the Service.

12. Automated Decision-Making

Some features generate suggestions automatically — sales insights, upsell recommendations, executive report summaries, natural-language reporting answers and AI-assisted repair diagnostics. These produce information for a person to act on. They do not decide anything about an individual on their own, and we do not use them to make decisions that affect a person's rights, finances, access to services or employment.

Where a suggestion is generated automatically, the Service labels it as AI-generated. Outputs can be wrong, so a human should check anything that matters before acting on it. If we ever introduce automated decisions that could significantly affect an individual, we will update this policy to say what information is used, what kinds of decisions are involved, and how to ask for human review.

13. Children's Privacy

Our services are intended for business use and are not directed at individuals under 18. We do not knowingly collect personal information from children.

14. Backups

We run automated encrypted backups and test restores, but you should keep your own copies of business-critical data as well — you can export your data at any time from the app. How responsibility for data loss is shared between us is set out in our Terms of Service, and does not affect your rights under the Australian Consumer Law.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy and updating the "Last updated" date. Continued use constitutes acceptance.

16. Contact Us

If you have questions about this Privacy Policy, contact us at privacy@graphretail.com.

© 2026 GraphRetail (Confumo Pty Ltd, ABN 24 160 002 700). All rights reserved.