Australian owned & operated
Legal

Privacy Policy

What we collect, why we collect it, who we share it with, and the choices you have. Written to be read, not to hide behind.

Last updated: 3 September 2026

1. Who we are

This policy applies to ProjectFund Pty Ltd (ABN 75 690 379 330) (“ProjectFund”, “we”, “us”), based in Townsville, Queensland, Australia, and to the ProjectFund website and platform.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where Open Banking data is involved, that regulated data sharing is performed by our accredited provider (see section 5).

2. What we collect

We collect only what we need to run verifications and support your account:

  • Account details: first and last name, email address, phone number, password (stored only as a salted hash), and role (contractor, team member, client or admin).
  • Business details you choose to provide: business or trading name, ABN, address, contact details and business logo.
  • Project and verification records: project or job name, the amount you ask us to check, project totals and amounts billed, milestone dates, and the outcome and timestamp of each check.
  • Client contact details supplied by a contractor when sending a verification request: name, email and (optionally) mobile number, together with the contractor's confirmation that the client agreed to receive the request.
  • Support information: contact form submissions, support tickets, and messages you send to our support assistant.
  • Billing information: subscription plan, status and invoice history. Card details are entered directly with our payment processor and are never received or stored by ProjectFund.
  • Technical information: IP address, device and browser information, log and audit records of key actions in the platform, and essential cookies used to keep you signed in.

3. What we do not collect

We do not collect, see, store, save or hold your or your client's online banking credentials — logins, passwords, PINs or one-time codes. Authentication happens directly between the account holder and their bank.

We do not display or retain account balances to contractors. A verification result tells the contractor only whether the required amount appeared to be available at the moment of the check.

We do not sell personal information, and we do not use it for third-party advertising.

4. Why we use it

We use personal information to:

  • create and administer accounts, teams and permissions;
  • send, run and record verification requests and scheduled re-checks;
  • notify you about verification outcomes, milestones, consent expiry and account activity;
  • provide support, respond to enquiries and handle complaints;
  • manage subscriptions, invoicing and payments;
  • keep the platform secure, investigate misuse, and maintain audit records; and
  • meet our legal obligations.

5. Open Banking and the Consumer Data Right

Bank data used in a verification is retrieved by Fiskil, a third party accredited under Australia’s Consumer Data Right (CDR). ProjectFund is not itself a CDR accredited person; we rely on our accredited provider for the regulated data-sharing step, and that step is governed by Fiskil’s CDR policy and the consent the account holder gives directly to their bank.

Consent is given by the account holder, is time-limited, and can be withdrawn at any time with their bank or with the provider. When consent is withdrawn or expires, scheduled re-checks stop and the account holder is asked to reconnect if further checks are needed.

From that process we retain a record of the consent (that it was given, when, and for which request) and the verification outcome — not the underlying transaction data feed.

6. Who we share it with

We share personal information only with service providers who help us operate the platform, and only for that purpose. These include our Open Banking provider (Fiskil), our cloud hosting and database provider, our email delivery provider, our payment processor, and our AI provider for the in-app support assistant.

Some of these providers may store or process information outside Australia. We take reasonable steps to ensure they protect information consistently with the APPs.

We may also disclose information where required or authorised by law, or to protect our legal rights.

7. Security

Traffic to the platform is protected with TLS, data is encrypted at rest by our hosting provider, access to production data is restricted to authorised personnel, and key actions are recorded in audit logs. Accounts support strong passwords and, where enabled, additional authentication.

No online service can be guaranteed as completely secure. If a data breach occurs that is likely to cause serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme.

8. How long we keep it

We keep account, project and verification records for as long as your account is active and afterwards only for as long as we need them for legal, tax, dispute-resolution or audit purposes. Support and email logs are retained for a shorter period. When information is no longer needed, we delete or de-identify it.

9. Access, correction and deletion

You can review and update most of your details in your account settings. You may also ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account. We will respond within a reasonable period and will tell you if we are required to keep some information.

10. Emails and notifications

Operational emails — verification requests, results, milestone reminders, security and billing notices — are part of the service. Every marketing or non-essential email includes an unsubscribe option, and you can reply to any of our emails asking to stop receiving them.

11. Cookies

We use essential cookies and local storage to keep you signed in and to remember basic preferences. We do not use third-party advertising cookies. Blocking essential cookies will prevent you from signing in.

12. Children

ProjectFund is intended for business users and is not directed at anyone under 18.

13. Changes to this policy

We may update this policy from time to time. The current version is always available on this page, with the date it was last updated shown above.

14. Contact and complaints

For privacy questions, access or correction requests, or to make a complaint, email support@projectfund.com.au or use our contact form. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

More on our security posture and Open Banking: Trust & Security.