At a glance
- You’re the controller We’re your processor, and we act only on your instructions.
- 48-hour breach notice We tell you within 48 hours of becoming aware, with what we know.
- Deleted or returned When you close your workspace, your customers’ data is deleted or returned to you.
01 Who decides what, and who does what
These terms govern personal information that Surfbase handles on your behalf when you use the product — your customers, their orders, and anything a store you connect sends us. They form part of your agreement with us and apply automatically from the moment you create a workspace. Nothing here reduces what the privacy policy says about information we hold about you.
Your customers’ information
You are the controller
It’s your data, and you decide what happens to it.
Surfbase
We are your processor
We only act on your instructions. Using the product is how you give them.
Creating an order, connecting a store, exporting a list: that is how you instruct us. We won’t do anything else with it.
Surfbase Platforms (ABN 72 119 661 713) is an Australian company, bound by the Privacy Act 1988 and the Australian Privacy Principles. If you or your customers are in the European Union or the United Kingdom, these terms are also intended to satisfy Article 28 of the UK and EU GDPR, and the obligations below are written to that standard.
02 What we process, and why
- Why
- To provide the product: to hold your records, to sell boards through channels you connect, to take payment, and to send the notifications you ask for.
- How long
- For as long as you have a workspace, plus the retention periods in the privacy policy. When you close your account we delete or return your data; ask us and we’ll do it sooner.
- Whose information
- Your customers and prospective customers, the people who buy from a store you connect, and the people you invite into your workspace.
- What kinds
- Names, email addresses, phone numbers, delivery and billing addresses, order and payment history, messages people send you through a share link or an enquiry form, and anything else you choose to type into a record.
We don’t ask for, and the product has no place to put, government identifiers, health information or anything else the law treats as sensitive.
03 What we commit to
Only on your instructions. We process your customers’ information to run the product for you and for nothing else. We don’t sell your customers’ information, rent it, use it to market to your customers, or use it to train machine-learning models. If the law ever compelled us to do something you hadn’t asked for, we’d tell you first unless that law forbade it.
Confidentiality. Everyone with access is bound to keep it confidential.
Security. Information is encrypted in transit and at rest. Credentials for connected services are separately encrypted in our database. Access is limited to the people who need it, and every read of data that arrived from a connected store is recorded in a log you can read yourself.
Helping you answer your customers. If one of your customers asks what you hold about them, or asks for it to be corrected or erased, the product is built so you can answer without our help: you can find, edit, export and delete their records yourself. Where a request needs something only we can do, ask and we’ll help.
Deciding whether a breach is notifiable — to the Office of the Australian Information Commissioner, to a European supervisory authority, or to the people affected — is yours to make as controller. 48 hours is meant to leave you time to make it.
Deletion. When you close your workspace, or when you ask, we delete your customers’ information or return it to you, and tell our sub-processors to do the same. The exceptions are anything the law requires us to keep, and backups, which age out on their own cycle rather than being edited.
Showing our work. We’ll give you the information you reasonably need to satisfy yourself that we’re meeting these terms, and accept an audit where the law entitles you to one, at reasonable notice and no more than once a year unless a regulator or an actual incident calls for more.
04 Who else we use
A small number of providers run the product. The ones that handle your customers’ information are bound by terms at least as protective as these, and each sees only what it needs to do its job. This list matches the one in our privacy policy:
- Amazon Web Services Hosting · Sydney
- Hosts the product, its database and your files in Sydney. This is where your data lives.
- Cloudflare DNS · Analytics · Global
- Provides DNS and email routing for the domain, and the site analytics described in the privacy policy. It doesn’t receive your customer records.
- Resend Email · US
- Delivers the email the product sends, so a recipient’s address and the message pass through it.
- Sentry Errors · US
- Receives error reports when something breaks. It’s configured not to receive request bodies or form contents, and we strip contact details out of error messages before they leave our servers.
- Stripe Payments · US, AU
- Takes payment from you, and from your customers when they pay you through Surfbase. Card details go to Stripe directly; we never hold them.
- Shopify Store · CA, US
- Where a connected store’s orders and buyers come from, and where product, stock and fulfilment updates go back.
- Xero Accounting · US
- Only if you connect a Xero organisation. Receives the invoices and payments you send it, with the customer’s name and email address.
- Apple, Google, Microsoft Sign-in · Global
- Authenticate the people in your workspace who choose to sign in with them. They don’t receive your customer records.
- esm.sh, jsDelivr Code · Global
- Serve the 3D viewer’s code to the browser. They see a visitor’s IP address and browser details, never your customer records.
- Bunny Fonts Fonts · No data
- Supplies our typefaces when we build the site. We serve them ourselves, so it receives no personal information at all.
05 Changes
If these terms change we’ll update this page and the date at the top, and tell you if the change is material.
06 Questions
Email hello@surfbase.app.