Privacy policy

Version 1.2 · 21 September 2026

CarbonCut, operated by JobChange Australia (ABN 30 724 947 983), handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This page says what we collect, why, where it lives, and what you can ask of us. Same rule as the product: show the working.

What we collect

  • Account details: your name, work email, and a password we store only as a hash.
  • Workspace details: business entity name and ABN if you add one.
  • Activity data: the figures you enter to measure emissions, such as electricity use, fuel volumes, gas use, billing dates, states, and any notes you attach. This is business data; please do not put sensitive personal information in notes fields.
  • Messages: what you send through the contact form or by email.
  • Technical basics: authentication session cookies and standard server logs.
  • Site analytics: we use Google Analytics to see which pages are visited and roughly where visitors come from. It sets its own cookies and sends usage data to Google; we do not send it names, emails, activity data or anything you type. No advertising trackers, and nothing sold to anyone.

Why we collect it

To run the service: calculating your baseline, generating reports, sending the reminder emails your workspace configures, answering support, and keeping the service secure. We do not sell personal information, and we do not use your data to advertise to you or anyone else.

Where it lives

Your account and activity data are stored in Australia (Sydney region) with our database and authentication provider, Supabase; documents you upload for AI reading (bills, fuel records) are stored there too, inside your workspace. The application is served by Vercel, and transactional email (reminders, invitations) is delivered by Resend; these providers may process request and message metadata on infrastructure outside Australia, primarily in the United States. If you use the bill-upload feature, the uploaded document is also sent to Anthropic (our AI provider, US-based) to extract the printed figures; Anthropic's API terms do not permit it to train models on this data. Manual entry never involves Anthropic. We use these four providers to run the service and no others with access to your data. Separately, Google (US-based) receives website usage data through Google Analytics, as described above; it never sees your account or workspace data.

Who can see it

Members of your workspace, according to the access your workspace grants. Our systems enforce workspace isolation at the database layer. Beyond your workspace and the providers above, we disclose personal information only if the law requires it.

Security

Data is encrypted in transit, access is controlled per workspace at the database layer, and administrative access is limited to what running the service requires. If a data breach occurs that is likely to result in serious harm, we will notify affected people and the OAIC under the Notifiable Data Breaches scheme.

Access, correction, export and deletion

You can see and edit your data in the product, and export it at any time with the built-in CSV downloads and the printable report. To access, correct or delete personal information beyond that, contact us; we respond within a reasonable time and say so plainly if we cannot do what you ask and why. When an account closes, data is deleted from production systems after the 30-day export window in our terms.

Complaints

Raise privacy concerns with us first and we will engage with them honestly. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes and contact

Substantive changes to this policy get a new version and date at the top of this page, and account holders are told by email or in the product. Questions: use the contact page.