ShedOS

ShedOS

Job & business management for shed builders

Privacy Policy

Last updated: 8 July 2026

This Privacy Policy explains what information ShedOS collects, how it is used, and what rights you have over it. ShedOS is a job and business management platform used by trade and construction businesses (“tenant organisations”, “we”, “our” in the context of your employer or principal contractor) and their staff, subcontractors, and clients. It applies to the ShedOS web application and mobile apps (iOS and Android).

1. Who this policy covers

ShedOS is provided as software to businesses (“tenants”) who use it to run their own operations. If you are a worker, subcontractor, or client of a business that uses ShedOS, that business is the data controller for your information within their ShedOS account, and ShedOS acts as their data processor. This policy describes how ShedOS, as the platform operator, handles information across all tenant accounts, including the security and processing commitments we make to every tenant.

2. Information we collect

We collect the following categories of information:

  • Account and contact information — name, email address, phone number, role, and password (or magic-link authentication) when an account is created for you by your organisation.
  • Location data — GPS coordinates are captured at the moment you clock in or out of a timesheet, and when you check in to a job site via QR code. This is used to verify attendance and site access, and is not tracked continuously or in the background.
  • Photos and site documentation — photos you take or upload for job progress, defects, inspections, and pre-start checks, including the timestamp, uploader, and GPS location stamped on each photo.
  • Push notification tokens — a device token (FCM for Android, APNs for iOS) is registered when you enable notifications on the mobile app, so we can deliver alerts such as overdue invoices, safety incidents, and timesheet reminders.
  • Safety and compliance records — SWMS (Safe Work Method Statements) sign-offs, safety incident reports, induction records, and related signatures.
  • Business records — quotes, invoices, purchase orders, timesheets, forms, and messages created in the ordinary course of using the platform.
  • Integration credentials— if your organisation connects third-party services such as Xero, GoHighLevel, or Stripe, we store the resulting access tokens. These are encrypted at rest and used only to exchange data with that service on your organisation’s behalf.
  • Cookies and session data — authentication and session cookies are managed via Supabase Auth to keep you signed in securely. We do not use third-party advertising or tracking cookies.
  • Usage and device information — standard technical data such as browser type, device type, and error logs, used for security and troubleshooting.

3. How we use information

  • To provide and operate the core features of ShedOS — jobs, quoting, invoicing, timesheets, safety records, and the client portal.
  • To verify timesheet clock-ins and site attendance via GPS and QR check-in.
  • To send transactional notifications (email, in-app, and push) relevant to your role — e.g. an invoice becoming overdue, a milestone falling due, or a safety incident being raised.
  • To synchronise data with third-party services your organisation has explicitly connected (Xero, GoHighLevel, Stripe).
  • To maintain safety and compliance records as required by workplace health and safety law.
  • To secure the platform, detect abuse, and troubleshoot technical issues.
  • Where a tenant organisation enables AI-assisted features (for example, task scheduling assistance), relevant task or job data may be sent to our AI provider, Anthropic, to generate a response. This data is used only to service that request and is not used by Anthropic to train models on our plans with them.

4. Who we share information with

We do not sell personal information. We share information only as follows:

  • Within your organisation — information you enter is visible to authorised users within your tenant organisation according to their role (e.g. admins, supervisors), and to clients where a client portal has been shared with them, scoped to their own jobs only.
  • Sub-processors — service providers who process data on our behalf, under contract, and only for the purposes described here:
    • Supabase — application hosting, database, file storage, and authentication.
    • Stripe — payment processing for invoices paid through the client portal, and subscription billing.
    • Resend — transactional email delivery.
    • Anthropic — AI-assisted features, where enabled by a tenant.
  • Tenant-configured integrations — if your organisation connects Xero, GoHighLevel, or Stripe, data is exchanged directly with that service as configured by your organisation. We are not responsible for how that third-party service handles data once received — refer to their own privacy policies.
  • Legal requirements — where required by law, regulation, legal process, or to protect the rights, property, or safety of ShedOS, our users, or others.

5. Data retention

We generally retain information for as long as your organisation’s account is active, or as needed to provide the service. Some records are retained for longer for legal and safety reasons:

  • SWMS and safety records are retained indefinitely and cannot be deleted — only archived. This reflects obligations under workplace health and safety legislation (WHS Act), which requires safety documentation to remain available well beyond a job’s completion.
  • Financial records (invoices, quotes) are retained in line with standard business record-keeping obligations.
  • When an account is deleted (see Section 6), personal identifiers are removed or anonymised, but records that other users, your organisation, or the law require us to keep (safety records, financial records, audit logs) are retained in de-identified or archived form rather than permanently erased.

6. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information.

  • Access and correction— you can view and update most of your own information directly within the app, or by asking your organisation’s administrator.
  • Export — business records such as jobs, invoices, and reports can be exported (CSV) directly from the relevant screens in ShedOS.
  • Deletion — you can delete your own account from Settings at any time. This deactivates your login and removes your personal profile information. As explained in Section 5, records your organisation is legally required to retain (such as SWMS signatures or financial records) are kept in de-identified form rather than deleted outright.

To exercise any of these rights beyond what is available in-app, or if you have questions about this policy, contact your organisation’s administrator (for data they control) or us directly at support@shedos.app.

7. Security

We use industry-standard measures to protect information, including encryption in transit (TLS/HTTPS) and at rest for sensitive fields such as integration credentials, role-based access control, and tenant data isolation (every record is scoped to a single organisation, enforced at the database level). No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable and appropriate steps to protect your information.

8. Children's privacy

ShedOS is a business tool intended for use by adults in a workplace context. It is not directed at, and we do not knowingly collect information from, children.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page. Continued use of ShedOS after a change constitutes acceptance of the updated policy.

10. Contact us

Questions about this Privacy Policy can be sent to support@shedos.app.