Privacy Policy
Last updated: March 24, 2026
Introduction
Vornir Pty Ltd (ABN pending) ("we", "us", "our") operates the Vornir platform at www.vornir.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
Information We Collect
Account information
When you register, we collect your name, email address, password (encrypted), company name (optional), and industry (optional).
Billing information
Payment details are processed and stored securely by Stripe. We do not store your full credit card number on our servers. We retain your Stripe customer ID and transaction history.
Usage data
We collect information about how you use the platform, including scan history, postcodes searched, credits consumed, features accessed, and timestamps.
Technical data
We automatically collect your IP address, browser type, device information, and referral source when you visit our site.
Referral data
If you were referred by another user, we store the referral relationship to manage our referral program.
How We Use Your Information
We use your information to:
- Provide and maintain the Vornir platform.
- Process payments and manage your subscription.
- Send transactional emails (account confirmation, password reset, billing receipts).
- Improve platform performance and user experience.
- Prevent fraud and enforce our Terms of Service.
- Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your data for advertising purposes.
Third-Party Services
We share limited data with the following service providers:
- Supabase (database and authentication): Stores your account data and scan results.
- Stripe (payment processing): Processes your payment information.
- Google Solar API (property data): We send Australian addresses to retrieve solar potential data. No personal information is sent.
- Vercel (hosting): Hosts the web application.
- Resend (email delivery): Sends transactional emails on our behalf.
- Mapbox (mapping): Displays property locations on maps.
Data Storage and Security
Your data is stored on servers with encryption at rest and in transit. We use Row Level Security to ensure users can only access their own data. All API communications use HTTPS. Passwords are hashed and never stored in plain text. We implement rate limiting and security headers to protect against common attack vectors.
Data Retention
- Account data is retained for as long as your account is active.
- Scan history and results are retained for the duration of your account.
- If you delete your account, your personal data will be removed within 30 days.
- Anonymised usage statistics may be retained for analytics purposes.
- Billing records are retained for 7 years as required by Australian tax law.
Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your account and personal data.
- Opt out of non-essential communications.
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached.
To exercise any of these rights, contact us at hello@vornir.com.
Cookies
Vornir uses essential cookies for authentication and session management. We use a referral tracking cookie that expires after 30 days. We do not use advertising or tracking cookies.
Children's Privacy
Vornir is a business platform not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top indicates when it was last revised.
Contact
For privacy-related questions or requests, contact us at:
Vornir Pty Ltd
Email: hello@vornir.com
Website: www.vornir.com