Privacy Policy
Effective date: 23 July 2026
This policy explains how Jadon Irwin trading as JP Irwin Academy (ABN 68 645 483 536) (“we”, “us”) handles personal information collected through Bondipos (bondipos.com). We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
1. What we collect
- Account details: your name, email address, shop name, and (for staff you add) staff names and email addresses.
- Credentials: passwords and till PINs, stored only as salted argon2 hashes — we never store or see the originals.
- Business records: the products, prices, stock levels, sales, refunds and GST figures you record. These are business data about your shop; they generally do not identify your customers — Bondipos does not collect customer names or card details.
- Billing: subscription status and payment records. Card details are collected and held by Stripe, our payment processor — they never touch our servers.
- Technical data: standard server logs (IP address, browser type, pages requested) used for security and debugging.
Where you (as account owner) add staff or enter personal information about other people, you are responsible for having the authority to give it to us and for telling those people how their information is handled, including by making this policy available to them.
2. How we use it
- to provide and operate the Service for your shop;
- to bill subscriptions and manage trials;
- to send transactional email (account welcome, password resets, billing notices) — not marketing, unless you separately opt in;
- to secure the Service, prevent abuse, and debug faults;
- to comply with legal obligations.
We do not sell personal information or share it for advertising.
3. Cookies
Bondipos uses a single essential session cookie to keep your till signed in. We do not use advertising or cross-site tracking cookies.
4. Who we share it with
We share personal information only with the service providers needed to run Bondipos:
- Stripe — subscription payments (Stripe’s own privacy policy applies to card data);
- Postmark — delivery of transactional email;
- Our hosting and database providers (currently Render and Neon) — running the application and storing its data.
Some of these providers store data outside Australia (typically in the United States). Where that happens, we take reasonable steps consistent with APP 8 to ensure it is handled in line with this policy. We may also disclose information where required by law.
5. Security
- All traffic is encrypted in transit (HTTPS).
- Passwords and PINs are hashed with argon2id; session and reset tokens are stored only as SHA-256 digests.
- Each shop’s data is isolated per tenant; staff access is role-based.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected users and the OAIC as required by the Notifiable Data Breaches scheme.
6. Retention
We keep your data while your account is open. Sales records are kept as an immutable ledger while the account exists, since they are your business’s financial history. After an account closes we retain data for a reasonable wind-down period (so you can export or reopen), then delete it, except records we are legally required to keep. Password-reset tokens expire after one hour; server logs rotate on a short cycle.
7. Access and correction
You can view and edit most of your information directly in the app. You may also ask us for access to, correction of, or deletion of your personal information by emailing support@bondipos.com. We will respond within a reasonable time. If you are unhappy with our handling of a complaint, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
8. Changes
We may update this policy from time to time; material changes will be notified by email or in the app. The current version always lives at bondipos.com/privacy.
9. Contact
Privacy questions: support@bondipos.com.