Privacy Policy
Effective date: From the date this version is first published by FOUNDORX.
1. Privacy position
FOUNDORX Pty Ltd operates FPTF.
Whether FOUNDORX is legally an APP entity under the Privacy Act 1988 (Cth) turns on annual turnover and, independently, on a fixed list of statutory exceptions — OAIC guidance is explicit that an exception makes a small business covered regardless of turnover. Both limbs have now been assessed (assessment completed 2026-08-29; threshold $3 million annual turnover, counted as all income from all sources). On current FOUNDORX facts, FOUNDORX Pty Ltd is presently a small business operator and is not generally required to comply with the Privacy Act or the Australian Privacy Principles solely by reason of its current FPTF business activities.
This is a current position, not a permanent one, and not a statement that privacy obligations do not matter. It is reassessed if turnover exceeds the threshold, if any statutory exception begins to apply, if FOUNDORX voluntarily opts in under s 6EA, or if the law or the business model materially changes. FOUNDORX has not opted in under s 6EA. Opting in remains available to FOUNDORX as a separate choice, and this policy will be updated if that position changes.
FPTF applies its privacy commitments regardless of that status. The protections described in this policy — data minimisation, transparency about the providers used, sensible security, and access and deletion pathways as they are implemented — are how FPTF operates, not a by-product of legal compulsion, and they are not reduced because an exemption presently applies.
Privacy contact: info@frompaycheck2freedom.com.
2. Information FPTF may collect
We collect only the categories described below, and only where they are actually implemented in the product.
Account and authentication
- email address;
- internal user/account identifiers;
- account/profile fields actually offered;
- email-confirmation, recovery and session/security metadata;
- authentication-provider identifiers.
Passwords and authentication secrets should remain within the approved authentication system and must not be exposed to staff or ordinary logs.
Learning and progress
Where implemented:
- lesson completion/progress state;
- current/next learning position;
- private lesson/workspace responses;
- Freedom Plan entries and notes;
- other learner-created planning information expressly shown in-product.
Your written answers — your private lesson responses and Freedom Plan entries — are stored alongside your lesson progress and position, and are deleted when your account is deleted. This is the most sensitive information the product holds. How long we keep it is governed by section 10, which does not promise a fixed period.
Optional product feedback
Where implemented, we may ask you for feedback twice, and both times it is optional: a one-tap check-in after you complete Phase 4, and a short feedback form once you have completed all 64 lessons. Answering is never required, and it never affects your lessons, your progress or your access. If you respond — including by choosing "No thanks" — we record, linked to your account:
- which of the two it was, and whether you answered or chose "No thanks";
- your Phase 4 check-in answer, if you give one;
- your star rating, if you send the feedback form;
- your answers to "What did you find most useful?" and "Is there anything we could add that would make FPTF even more helpful?", only if you write them;
- whether you ticked "I'm happy for FPTF to contact me about using my feedback as a testimonial";
- when it was recorded.
This is private product feedback, used to understand and improve FPTF. It is not published, and it is not automatically turned into a review or a testimonial. Ticking the testimonial box means only that we may contact you to ask about possibly using your feedback — it is not permission to publish your feedback as a testimonial. Any public testimonial use would need your separate permission, through our separate testimonial process. Your feedback is deleted when your account is deleted, and section 10 governs how long we keep it.
Starter Guide and marketing
- email address;
- name only if the form actually requests it;
- guide-delivery status;
- consent wording/version, source, timestamps and unsubscribe/suppression status;
- limited campaign/source fields where approved.
Support/contact
Support is currently offered by email only, at the published support address. There is no in-product contact form. Where a person emails support, the message itself may contain:
- their sender email address;
- a sender/display name, where their mail client supplies one;
- a subject line and message contents;
- any attachments they choose to send;
- ordinary mail thread metadata.
Support mail is handled in FOUNDORX's Google Workspace business email environment. Google Workspace does not offer Australia as a selectable data region — the options are the United States or Europe, and not every edition has that control — so we cannot choose Australia for this mail. Google may handle it in the United States, in Europe, or elsewhere in its global infrastructure, and Google's data-region controls do not in any case cover logs or cached content. Section 8 sets out the wider overseas position. Support mail is kept only for as long as it is needed to deal with the enquiry and anything arising from it, under section 10. No fixed retention period for support mail is promised here, and none should be read into this policy.
Users should not send passwords, security codes, government identifiers or full payment-card details.
Payments and access
When you buy FPTF, or start a purchase:
- product/plan/access status;
- payment-provider customer and order references — FPTF's current commercial model is a one-time purchase, so no subscription references exist;
- transaction status and limited transaction/payment-status metadata (checkout-session, payment-intent and charge identifiers, amount, currency, status and event type);
- cancellation/refund status;
- entitlement/audit events;
- the country you tell us you are buying from, and the country your payment provider reports for the payment, which we compare to check FPTF is available where you are.
FPTF must not store full card numbers or card security codes unless a separately approved PCI-compliant architecture specifically requires it. No such architecture is currently approved.
Technical, usage and security information
Where actually implemented:
FPTF application code currently collects none of the following. Each is handled, if at all, by the hosting and service providers named in section 7, under their own privacy notices and their own retention rules. FPTF's application code does not read or receive those platform logs. Where we need to investigate a fault or a security incident we may view them in the provider's own console, under that provider's controls and retention. Our hosting provider publishes that it processes request IP address and the city and country derived from it — expressly not precise location — together with browser and device details and request metadata such as response times, errors and timestamps, and it states its retention only as the minimum period necessary for its legal and contractual obligations rather than as a fixed number of days. Where a provider does not publish a period, this policy does not invent one:
- IP address and security/network metadata needed to operate/protect the service;
- browser/device class and technical diagnostics;
- logs, rate-limit/security events and error information.
FPTF runs no analytics of its own. FPTF runs no analytics SDK, tag manager or session-replay tool, and there is no analytics contract. Route, page or feature event collection is a future feature and is not described here as current. If you choose to pay with PayPal, PayPal's own checkout technology collects information directly, as described in section 6.
Public tools
Launch tools work without an account and do not save your answers, unless the page you are on clearly says that a governed feature does. If that ever changes, we update this notice and our internal data inventory before the change goes live, not after.
3. How information is collected
Information may come directly from the person when they create an account, use learning features, request the Starter Guide, contact support, make a purchase, change preferences or make a privacy request. Approved service providers may return limited technical, delivery, authentication or billing status information. If you choose to pay with PayPal, PayPal's checkout technology also collects information directly from your browser, as described in section 6; that information goes to PayPal, not to FPTF.
4. Why information is used
Subject to actual implementation and applicable law, purposes may include:
- creating and securing accounts;
- providing the requested learning/service features;
- saving authorised learner progress and private workspace information;
- delivering the Starter Guide;
- sending marketing only where there is an appropriate consent/legal basis;
- verifying payment and entitlement;
- handling support, refunds, complaints and privacy requests;
- preventing abuse, fraud and security incidents;
- maintaining, debugging and improving FPTF using appropriately minimised data;
- where you have ticked the testimonial box on the optional feedback form, contacting you to ask whether you would be willing for your feedback to be used as a testimonial;
- complying with legal obligations and resolving disputes.
We do not treat editing this policy as permission to use your information for a new purpose.
5. Direct marketing
We keep marketing consent separate from the processing we must do to run your account and your purchase, wherever affirmative consent is required.
Users must be able to unsubscribe without logging in. Suppressed recipients must not be silently re-added without fresh valid consent.
Transactional account, security, purchase/access and requested guide-delivery messages must remain correctly classified and must not be relabelled to evade consent/suppression rules.
6. Cookies, browser storage and analytics
What is set in your browser depends on which optional providers are configured:
- Essential — set when you sign in. The Supabase authentication/session cookie(s) are set by our server when you sign in. Their exact names, count and expiry are controlled by the Supabase library rather than by FPTF, so they are not stated here;
- Written if you arrive through a partner link — the referral record. A first-party cookie, `fptf_affiliate_ref`, records which partner referred you, so that a partner who genuinely introduced you to FPTF can be credited if you later buy. We do not ask you to decide this. Crediting the right partner is our arrangement with them, not a choice we think it is fair to put on you, and you are never asked to approve it, to pick a partner or to enter a code. It holds three things and nothing else: a format version, the partner's own referral code, and the time it was saved. It holds nothing about you — no name, no email address, no account identifier, no IP address, no device or browser details and no location — and the referral code identifies the partner, not you. It is not used for advertising, analytics or profiling, and it is not combined with anything else, except in one way: if it is still within its 30 days when you confirm your email address after registering, or when you continue to payment at checkout, its referral code is sent to FirstPromoter together with your email address, as described under FirstPromoter in section 7. It lasts 30 days, the same window the partner terms use, and it is limited to this site (`Path=/`, `SameSite=Lax`, and `Secure` over HTTPS). It is removed once the referral has been passed to our partner provider — when you confirm your email address after registering, or at checkout once our partner provider has accepted it — and in any case once it is older than 30 days. If it cannot be passed on, it is kept until its 30 days end, so that the referral can be passed on when you try again. You can also remove it at any time by clearing cookies or site data for this site. If you arrive through a different partner link inside that window, the most recent one replaces it;
- A former preference cookie, now retired. FPTF used to offer a choice about an optional FirstPromoter browser script, and a first-party cookie, `fptf_affiliate_tracking`, recorded the answer. That choice and that script have both been retired. FPTF no longer uses this cookie, and if your browser still holds one from an earlier visit, FPTF removes it the next time you open the site. It never held a name, email address, account identifier, referral identifier or analytics identifier, and it has no effect on whether a partner is credited;
- No affiliate tracking script from the provider. FPTF does not load FirstPromoter's browser tracking script, and FPTF does not need it to credit a partner — the referral record above does that. If your browser still holds referral cookies that FirstPromoter's script set during an earlier visit, FPTF does not remove them: FirstPromoter set them, not FPTF, so FPTF cannot reliably reach them. FPTF no longer causes them to be set or refreshed, and you can remove them at any time by clearing cookies or site data for this site;
- The PayPal checkout script is loaded from `paypal.com` into your browser only if you choose to pay with PayPal at checkout, after you have chosen your country and agreed to the terms. If you pay by card without first choosing PayPal, the PayPal checkout script is not loaded. Once it loads, your browser connects directly to PayPal. PayPal may then receive technical, device and internet-activity information, such as your IP address and details of your browser, and may use cookies or similar technologies, including an item in your browser's local storage. PayPal's own privacy and cookie statements describe the purposes of such technologies on sites where it provides its services as including providing those services, recognising users, analytics, advertising and personalisation, preventing fraud and managing risk, and trust and safety. PayPal also states that it does not use local-storage-type technologies to target advertising. FPTF does not know the exact purpose of the item PayPal stores, or how long PayPal keeps it. What PayPal collects in this way is governed by PayPal's own privacy and cookie statements: FPTF does not set it, does not receive it and cannot control it, and paying by card after choosing PayPal does not remove anything PayPal has already stored;
- FPTF itself runs no analytics SDK, tag manager, session-replay or advertising pixel — none is installed in the application, and FPTF injects none while you browse: the only third-party script loaded by FPTF is the PayPal checkout script described above, and only if you choose PayPal. *(The free Freedom Starter Guide loads one small script of our own, from the guide's own folder, to make its answer spaces usable and to assemble the final plan. It is not analytics, it is not a third-party script, and it sends nothing anywhere.)* and PayPal may itself receive technical and diagnostic information through its script, as described above;
- FPTF's own code uses browser storage in exactly two places, and both are described here. *(This replaces an earlier statement that `localStorage` and `sessionStorage` were “never used” by FPTF's own code. That was inaccurate: the appearance preference below was already stored, so the sentence is corrected rather than left standing.)*
- Your appearance preference. If you choose dark appearance, that choice is stored in your browser under `fptf-appearance` so the site does not flash the wrong theme the next time you open it. It holds only that preference;
- Your Freedom Starter Guide answers. The free Freedom Starter Guide has spaces for you to write your own answers. What you type is stored in your browser under `fptf-starter-guide-answers`, so that your answers are still there when you come back to the guide on the same browser on the same device, and so the guide's final plan can be assembled from the answers you already gave instead of asking you to write them out again. It holds your guide answers and a version number for the stored format, and nothing else — no email address, no name, no account identifier, no referral or tracking identifier, no IP address, no device or browser details, and no location. It is not account storage, not stored on our servers, and not synchronised across your devices, so it will not follow you to another browser or another device, and we cannot see it. It is not used for analytics, advertising or affiliate attribution. You can remove it at any time by clearing site data or browsing data for this site in your browser, and if your browser blocks storage the guide still works for as long as the page is open;
- `sessionStorage` and IndexedDB are not used by FPTF's own code. Outside FPTF's own code, third-party library and provider code FPTF does not call for that purpose may use browser storage — the PayPal checkout script's item is described above;
- application code reads no IP address, user-agent or geolocation.
What our hosting and service providers publish about their own processing is described in section 2. The settings inside our accounts with them are our internal configuration, and they do not change the categories of information described here or who processes them. Whether any cookie notice or banner is legally required on these facts is not decided by this policy and is assessed separately. Non-essential analytics, advertising pixels or marketing trackers are not authorised merely by this policy.
7. Service providers and disclosures
Current project evidence identifies:
- Supabase — active; authentication, database, learner records and consent ledger. Where it processes that information is described in section 8;
- Resend — active; governed FPTF email provider, receives email addresses for delivery. Where it processes them is described in section 8;
- PayPal — an optional second payment method in the same purchase path, used only if you choose it at checkout. When it is used, FPTF sends PayPal only opaque internal references — an attempt reference, the account identifier and the product name — together with the amount and currency. FPTF sends no name, email address or postal address. Customers deal with PayPal directly to authorise the payment. Once you choose PayPal, PayPal's checkout script also collects information directly from your browser, as described in section 6; FPTF does not receive that information. FPTF reads back the payer's country, to check the purchase comes from a country where FPTF is available, and, where PayPal provides one, an email address, to send the purchase confirmation;
- Google Workspace — active; FOUNDORX's business email environment, which receives support mail sent to the published support address. See sections 4 and 8;
- Vercel — active; hosting platform. Platform-side connection metadata and logs are handled by Vercel, not by application code;
- Stripe — card payment provider, used where checkout offers card payment to you. FPTF sends Stripe a pseudonymous account identifier, the item being purchased and the country you told us you are buying from. Customers enter their email and payment credentials directly into Stripe-hosted Checkout. Stripe's signed payment and refund event payloads may contain customer details and non-secret payment-method information. FPTF's current handlers use and store only the limited account, transaction, payment-status and refund information needed to reconcile access. FPTF does not store full card numbers, card security codes, the customer's Stripe Checkout email, or card/payment-method metadata.
- FirstPromoter — active; the affiliate platform FPTF uses for referral attribution in the partner program. FPTF does not load FirstPromoter's browser tracking script. Partner referrals are recorded by FPTF's own first-party referral record, described in section 6. If that record is present and still inside its 30-day window when you confirm your email address after registering, or when you continue to payment at checkout — before you pay, and whether or not you then complete the payment — FPTF's server sends FirstPromoter the partner's referral code and your email address: the address you registered with, or at checkout the address you are buying with (or, if you are signed in, your account's address), so that FirstPromoter can record you as that partner's referral before any payment and operate the partner program. FPTF sends nothing else about you on that path, and sends nothing at all if there is no referral record. FirstPromoter remains the source of truth for referral attribution and partner commissions. Attribution depends on actual platform and system behaviour and on the partner program rules: it is not promised for every click, browser or device.
No analytics, error-monitoring or session-replay vendor is active. FirstPromoter, described above, is an affiliate-attribution provider rather than an analytics one, and FPTF does not load its click-tracking script. The tracking and consent treatment for customers outside Australia remains under separate assessment, and this policy is updated when that assessment is settled; it is not made in this document. Any analytics, error-monitoring or support vendor that is not named above is not in use. If FOUNDORX ever adds one, this policy and FOUNDORX's internal data inventory must be updated to describe it before it is switched on, not afterwards. The production configuration of each provider named above — the settings inside FOUNDORX's own accounts with them — is internal configuration; it does not change which categories of information are collected, who processes them, or what this policy says about them.
FOUNDORX may also disclose information where required or authorised by law, to protect rights/security, or with the person's direction/consent where appropriate.
8. Overseas handling
Information handled by FPTF is processed outside Australia. This is now evidenced rather than assumed:
- Resend, which delivers our email, states that its primary processing operations take place in the United States;
- Stripe, which processes payments, processes data globally, including transfers to the United States;
- Vercel, which hosts the site, transfers data internationally;
- Google Workspace, which handles support email, offers data residency in the United States or Europe only — not Australia;
- PayPal, where you pay with it, states that it and its service providers may process personal information outside the customer's country, including in the United States and other countries.
Our main database is hosted in Australia (Sydney). That does not mean everything stays here — as the list above shows, email delivery, payment processing, hosting and support email all involve processing outside Australia. We do not claim that all data stays in Australia. Our email provider retains message and log data for 30 days, keeps backups for 7 days, and deletes remaining customer data within 90 days of an account closing. Stripe is required to keep transaction records for five or more years, and longer where anti-money-laundering law applies. PayPal states that it keeps information for the duration of the relationship plus a period of 10 years, or such period as applicable law requires. We cannot shorten either period, and we will not imply otherwise.
If APP 8 ever applies to FOUNDORX, cross-border disclosure obligations would be assessed and implemented.
9. Security
FPTF's security baseline requires proportionate technical and organisational controls, including least privilege, privileged-user MFA, secret management, protected server-side access decisions, safe logging, backups/recovery, environment separation, incident response and vendor review.
No security control is absolute, and we do not claim otherwise.
10. Retention and deletion
We keep personal information only for as long as it is needed for the purpose it was collected for, or for as long as the law requires us to keep it. Where a tax, accounting or other legal obligation sets a minimum period, we keep that record for that period and no longer than we need it. The specific periods are set in our internal retention schedule and are reviewed as those obligations are confirmed.
When information is no longer needed for a lawful purpose, we delete or de-identify it, consistent with the legal baseline that applies to us. If APP 11 applies, reasonable destruction/de-identification obligations include copies/backups within FOUNDORX's control, subject to lawful retention exceptions.
Limited records may need to be retained for tax/accounting, fraud/security, chargebacks, legal disputes, evidence of consent/terms acceptance or suppression. Those records must be minimised and access-restricted.
11. Access, correction, deletion and complaints
Users may request access/correction, make a privacy complaint, withdraw marketing consent or request deletion by contacting info@frompaycheck2freedom.com. That is the route: requests are handled by a person, and there is deliberately no separate privacy dashboard to sign into.
Identity checks must be proportionate and must not collect unnecessary sensitive information. We will need to confirm the request comes from the account holder before acting on it.
Closing an account does not erase everything, and we will not say otherwise. Account details, saved lesson work, Freedom Plan entries and any optional product feedback are removed. A limited set of records remains: transaction and access history in de-identified form, and the minimum unsubscribe record needed to make sure a closed account is not marketed to again — deleting that would defeat the request it was made under. Records held by our providers are governed by their own terms, and our payment providers keep their own transaction records regardless, as described in section 8.
Any response timeframe we give is a service commitment we choose to make, not a statutory deadline on the position currently assessed to apply to us.
12. Children and young people
FPTF is 18+ only for customers and affiliates. FPTF is not directed at children, must not make child-directed privacy claims, and does not intentionally collect personal information from people under 18. Parental-consent logic must not be implemented by assumption. 18+ eligibility is enforced at account creation through a required self-declaration validated server-side ("I confirm I am 18 years or older."). This is an attestation, not identity or age verification: no date of birth, age or identity data is collected or stored.
13. Policy changes
We version this policy, archive the version it replaces, and update it when the data categories, purposes, vendors, retention, tracking or jurisdictions materially change. Material changes may require new notice and/or consent; updating text alone does not authorise a new data practice.
14. Contact
FOUNDORX Pty Ltd Privacy contact: info@frompaycheck2freedom.com Location: Lakelands, Western Australia ACN 699 504 517