NexHub — Privacy Policy

Version 1.0 · Effective date: 6 August 2026
Who we are: James Stanislaus Brennan (ABN 98 617 876 699), trading as NexHub ("NexHub", "we", "us"), Queensland, Australia. We operate the NexHub field-service platform, websites and related services (the "Service").

This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It covers website visitors, trial and Early Access users, subscribing businesses ("Subscribers") and their staff, and the customers of those businesses ("End Clients") whose information is stored in the Service.


1. The two kinds of data we handle

(a) Account data — we're responsible for it. Information about Subscribers, their owners and staff, and website visitors: this is personal information we collect and hold for our own purposes (running, securing, billing and improving the Service). For this data, NexHub is responsible and handles it in accordance with the APPs.

(b) Customer Data — your business is responsible for it; we hold it on your behalf. Information Subscribers store about their End Clients — names, addresses, phone numbers, property details and maps, job notes, site photos, quotes, invoices, chemical application records. We host and process this solely to provide the Service to the Subscriber. Other than creating de-identified, aggregated data that cannot identify anyone (section 6), we don't use it for our own purposes; we don't sell it, and we don't use it to train AI models. If you're an End Client of a business that uses NexHub, that business controls your information — please direct access, correction or deletion requests to them; we'll assist them to respond. Subscribers are responsible for having told their End Clients how their information is handled and for any consents their business needs. If an End Client signs into the client portal, the login credentials and security log data we collect to run the portal are handled by us as account-style data under (a).

2. Personal information we collect

Account & contact: name, business name, ABN, email, phone, role, password (hashed).
Billing: plan, transaction history. Full card details go directly to our payment processor (Stripe) — we don't store card numbers.

Staff details entered by the Subscriber: names, contact details, roles, licence/credential records (for example chemical accreditation details) where the business chooses to record them.

Customer Data entered by the business (section 1(b)), including property locations and mapped boundaries.

Photos & files: job photos and attachments, including the date/time a photo was taken and, where the device includes it, embedded location metadata.

Location data: see section 3.

Device & usage: IP address, browser/device type, pages and features used, log data, approximate location derived from IP.

Communications: support conversations, emails, and messages sent through the Service.

We don't seek sensitive information (such as health information) and ask that you don't store it in the Service except where a record legitimately requires it (for example an incident note your business is required to keep).

3. GPS and location tracking of field staff

Some features collect device location from staff devices while enabled by the Subscriber and permitted on the device: job check-in/out, travel and timesheet locations, route planning, and fetching site-specific weather readings at the moment a task (such as a spray job) starts.

  • Who can see it: the Subscriber's account owner and the administrators/staff the Subscriber authorises. NexHub staff access it only for support and troubleshooting.
  • What it's used for: scheduling and dispatch, timesheets and job records, route planning, site condition records — not advertising.
  • Your controls: staff can disable location permissions on their device at any time; doing so limits location-dependent features. The Subscriber decides whether location features are enabled for its team and is responsible for giving staff any notice required by workplace surveillance laws in its state or territory before using them.

4. How we collect

Directly from you (signup, settings, support); automatically as you use the Service (logs, usage, cookies — section 11); from your staff and colleagues (when they add you to an account); and from integrations you connect (section 5). Where practicable we collect personal information directly from the individual concerned.

5. Integrations (Xero, QuickBooks and others)

When a Subscriber connects a third-party product — for example Xero or QuickBooks Online (Intuit) for accounting, a weather data provider, or a payment provider — we exchange only the data needed for that integration (for example pushing invoices, contacts and payments to your accounting file).

Our commitments for data obtained from integration APIs (including the Xero and Intuit APIs):

  • used only to provide the Service to the account that connected the integration, and kept siloed to that account;
  • never sold, and not disclosed to any other third party without the user's consent;
  • never used to train, fine-tune, adapt or enhance any AI model;
  • protected with the security measures in section 8 and deleted per section 9 when no longer required;
  • accessible to the connected provider under its terms and privacy policy, which govern the data once it's in their systems.

Disconnecting an integration stops further data exchange at any time.

6. Why we use personal information

To provide, secure and support the Service; to set up and administer accounts and billing; to communicate service messages; to provide features you use (scheduling, quoting, records, routing, weather readings); to improve the Service — including analytics on de-identified, aggregated data that cannot identify any person or business; to meet our legal obligations; and, with the ability to opt out at any time, to tell you about product updates and offers (section 12).

AI features: where a feature uses artificial intelligence (for example drafting or diagnostic suggestions), we disclose this in the product. We do not use identifiable Account Data or Customer Data to train AI models, and integration data is never used for AI training (section 5). AI outputs are suggestions for a human in your business to review.

7. Who we disclose personal information to

We disclose personal information only: to our service providers (subprocessors) below, strictly to run the Service; to a provider you connect via an integration (section 5); to your account's administrators (your data is visible within your business's account per its own settings); to professional advisers, or where required by law or to protect safety; and to a buyer of our business, who must honour this policy. We do not sell personal information.

Subprocessors (current categories and locations — kept up to date on this page):

ProviderPurposeLocation
Lovable (Lovable Cloud)Application hosting & build platform, transactional email delivery, AI gatewayUnited States
Supabase (via Lovable Cloud)Database, authentication, file storageAWS cloud infrastructure (may include the United States)
StripePayment processingAustralia / United States
Google Maps PlatformProperty mapping & geocodingUnited States / global
Weather providers (e.g. WillyWeather / Open-Meteo)Site weather readings (receive job-site coordinates only)Australia / EU
AI model providers (via our AI gateway)Process only the content submitted to AI-assisted featuresUnited States
Browser push services (Apple / Google / Mozilla)Push notifications you enableUnited States / global

If we add SMS features or analytics tools, the provider will be added to this table before those features launch.

8. Overseas disclosure (APP 8)

Our application and database run on cloud infrastructure provided by Lovable and Supabase (built on AWS), which currently may include hosting in the United States, and several of the subprocessors above process data in the United States and other countries as listed. Where personal information goes overseas, we take reasonable steps — including contractual safeguards — to ensure recipients handle it consistently with the APPs. We'll update the table above if locations change.

9. Security, retention and deletion

Security. Encryption in transit (TLS) and at rest; role-based access controls and row-level security separating each business's data; least-privilege internal access; credential hashing; secrets held in managed, encrypted storage — never in client-side code. No system is perfectly secure, but we treat security as a first-class obligation (including the minimum-security requirements of our integration partners such as Xero).

Retention. We keep personal information only as long as needed for the purposes above, then delete or de-identify it. Specifics: financial and tax records are kept for 7 years; chemical application records are retained per the Subscriber's configured retention (statutory minimum retention periods vary by state — the business selects its retention to meet its obligations); backups cycle out on a rolling schedule.

Account closure. After closure, your data remains exportable for 30 days, then is deleted or de-identified within a reasonable period, except records we're legally required to keep. You can request earlier deletion in writing.

10. Data breaches

We maintain a data breach response plan under the Notifiable Data Breaches scheme (Part IIIC, Privacy Act). If a breach is likely to result in serious harm, we'll notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required. Where a breach affects Customer Data, we'll also notify the affected Subscriber promptly so it can meet its own obligations, and we honour the breach-notification commitments in our integration partners' terms (including notice to Xero within its required window).

11. Cookies and analytics

Our website and app use cookies and similar technologies for sign-in and session security (essential). We don't currently run third-party analytics or advertising cookies; if we add an analytics tool, we'll name it in this policy first. You can control cookies in your browser — blocking essential cookies may break sign-in.

12. Marketing

We only send marketing (product news, offers) to people who've signed up or otherwise opted in, in accordance with the Spam Act 2003 (Cth). Every marketing message includes a working unsubscribe. Service and billing messages aren't marketing and continue while you hold an account. We never use Customer Data (your End Clients' details) for our own marketing.

13. Access and correction

You can access and correct most of your information directly in the Service. For anything else, contact us (section 16) — access is free, and we respond within 30 days. If we refuse a request (for example where the law requires us to), we'll tell you why and how to complain. End Clients should contact their service business first (section 1); we'll help that business respond.

14. Children

The Service is a business tool and isn't directed at children. We don't knowingly collect personal information from anyone under 16 except as Customer Data controlled by a Subscriber (for example a parent's account noting a site access instruction). If you believe a child's information has been provided to us directly, contact us and we'll delete it.

15. Users outside Australia

If you use NexHub from outside Australia, note your information is processed in the locations listed in sections 7 and 8, which include the United States. Where overseas privacy laws (such as the NZ Privacy Act 2020 or the GDPR) give you additional rights — including erasure, restriction, portability and objection — we'll honour valid requests. Our lawful bases under such laws are contract performance, legitimate interests in running and securing the Service, legal obligation, and consent where relied on.

16. Contact, complaints and the OAIC

Privacy contact: The Privacy Officer (James Brennan), NexHub (ABN 98 617 876 699), Queensland, Australia — james@nexhub.au.

If you have a privacy concern or complaint, contact us first — we'll acknowledge it promptly, investigate, and respond within 30 days. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au · 1300 363 992 · GPO Box 5218, Sydney NSW 2001.

17. Changes to this policy

We'll update this policy as the Service and the law evolve. The current version, with its effective date, is always at nexhub.au/privacy; material changes will be notified by email or in-app before they take effect, and we keep a dated version history.