Introducer Hub

Privacy Policy

Last updated: 24 July 2026

Who we are

Introducer Hub (“we”, “us”) provides a referral-management platform that lets businesses exchange client referrals with each other and track them through to completion. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Contact us about privacy at info@introducerhub.com.au.

Two different roles we play

This matters, because it decides who is responsible for what:

  • For our customers’ own information (business details, staff names and logins, billing) we are the entity deciding how it is handled.
  • For the client information a customer puts into the platform(the people they refer) we act on that customer’s instructions. The customer is responsible for having the right to share those details, and our referral form requires them to confirm the client has agreed before a referral can be sent.

What we collect

  • Business information — trading name, profession, contact details, address, referral code.
  • User information — name, email address, phone, job title, role and permissions, and authentication data including two-factor enrolment.
  • Referral information — the referred person’s name, phone, email and any notes the referring business adds, plus the estimated value, stage history and outcome.
  • Commercial information — partnership terms, commission rates and payment status.
  • Records of activity — audit logs of significant actions (who changed what, and when), and a log of emails we send.
  • Payment information — handled by Stripe. We never see or store your full card number.

Why we collect it

To operate the platform: to route a referral to the right business, show both sides its progress, calculate and track commission, manage team access, send notifications, take payment for subscriptions, and keep the security and audit records we are expected to keep. We do not sell personal information, and we do not use referral data to advertise to anyone.

Who can see what

Access is enforced in our database, not merely hidden in the interface. Each business can only read its own records and the referrals it is a party to. A referral is deliberately visible to both the sending and receiving business — that shared view is the point of the product, and the referring business should only send details the client has agreed to share.

Where your data is stored

Customer data is stored in Australia (Sydney), and our application also runs in Sydney. Some of our suppliers are overseas companies, so limited data may be accessible to them for support and operational purposes. Card payments are processed by Stripe.

Who we share it with

We use a small number of service providers, and only for the purposes below:

  • Supabase — database, authentication and file storage. Hosted in AWS Sydney, Australia.
  • Vercel — application hosting and delivery. Our functions run in the Sydney region.
  • Stripe — subscription billing and card payments.
  • Resend — outbound email, such as password resets, team invitations and referral notifications. Resend is based in the United States, so the recipient’s email address and the contents of these messages are sent overseas.

We may also disclose information where the law requires it.

How we protect it

  • Encrypted in transit (TLS) and at rest.
  • Separation between businesses enforced by database security policies, with an automated test suite that proves one business cannot read another’s records.
  • Two-factor authentication required for account owners and for our own administrators.
  • Least-privilege access, with per-user permissions set by the account owner.
  • Audit trails recording significant changes and administrative actions.

No system is perfectly secure, but these are the controls we actually run — not aspirations.

How long we keep it

  • Referral records are kept while your account is open. Once a referral has been closed for seven years, the personal details of the referred client are automatically removed, while the record of the transaction remains for financial record-keeping.
  • Our email log is deleted after twelve months.
  • If you delete your account, we remove your business and staff details and erase the client details on referrals you sent. Referrals remain on your partner’s side as a record of their work, stripped of your clients’ personal details — we cannot delete another business’s records.

Your rights

You can access everything your account holds at any time — Settings has a one-click export of your complete records in a machine-readable file. You can correct your details in the app, and you can delete your account from Settings. If you want us to act on a request about a specific individual, contact us and we will respond within a reasonable period, and in any case within 30 days.

Data breaches

We maintain an incident response process. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we will tell affected customers promptly.

Complaints

Contact us first and we will investigate. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes

We will update this page when our practices change and revise the date above. Material changes affecting how we handle personal information will be communicated to account owners.

© 2026 Introducer Hub