At a glance
- No advertising, no tracking No tracking pixels, no analytics cookies, and nothing that builds a profile of you.
- Stored in Sydney, encrypted Encrypted in transit and at rest; store credentials are encrypted separately.
- Your customers stay yours For your shop’s records you decide, and we act only on your instructions.
01 Who we are
Surfbase is operated by Surfbase Platforms (ABN 72 119 661 713). You can reach us at hello@surfbase.app.
02 What this policy covers
This policy covers surfbase.app, how signing in to Surfbase works, and what happens to information inside the product once you’re in: your own account, the customers and orders your workspace holds, and anything that arrives from a store you connect.
Two different roles, and the difference matters. In privacy law those are the roles of controller and processor, and the second one is the one we hold for your shop’s records.
Your Surfbase account
We are the controller
We decide what to collect and why, and this policy describes that.
Your shop’s records
You are the controller
Your customers, your orders, the people who buy your boards. We only act on your instructions.
If one of your customers wants to know what is held about them, or wants it erased, you are who they ask, and our job is to make sure you can answer. Our data processing terms set out what we commit to for those records.
03 What we collect
Your account. Your name, your email address, your password (stored only as a one-way hash), the workspaces you belong to and your role in each. If you pay for a plan, we keep the plan, the amount, the outcome of each payment and Stripe’s reference for it. We never see your card number.
The email address you give us. If you join the waitlist, we collect the address you type into the form and the date you submitted it.
Standard server logs. Our host records the usual technical details of a web request — IP address, browser and device type, the page requested, and the time. We don’t use these to identify you.
How the site is used. We use Cloudflare Web Analytics to count visits and see which pages get read. It sets no cookies and stores nothing on your device, it doesn’t fingerprint you, and it can’t follow you to other sites. It records the page you opened, the site you arrived from if any, broad details like your country, browser and device type, and how quickly the page loaded.
04 Signing in with Google, Apple or Microsoft
You can sign in to Surfbase with a Google Account, an Apple Account or a Microsoft account instead of a password. If you do, that provider tells us three things, which we store so we can recognise you next time, and refresh each time you sign in:
- Identifier
- A stable identifier for your account with them.
- Email address
- Your email address, and whether they have confirmed it is yours.
- Name
- Your name.
We only ever ask for your identity. The sign-in request covers your name and email address and nothing else. We cannot read your mail, files, calendar or contacts, we never post anything, and after you have signed in we don’t go back and read anything further from that account.
Apple. If you use Apple’s Hide My Email, Apple gives us a relay address instead of your real one. We store and write to the relay address, and your real address is never disclosed to us. For Apple we also keep one credential, encrypted, for a single purpose: if you delete your Surfbase account, we must tell Apple to disconnect it, and that credential is what lets us do so.
What the provider learns. Signing in this way tells the provider that you signed in to Surfbase, and when.
You can disconnect a provider at any time under Settings, as long as you still have another way to get in. Disconnecting removes what we stored from it.
05 What your workspace holds about your customers
A workspace holds the records a board business runs on: customers, their contact details and delivery addresses, orders, payments, and the designs and stock boards those orders are for. You put that there, or a connected store sends it. We store it so the product works, and we don’t use it for anything else — not to train anything, not to build a profile, and not to market to your customers.
06 Connecting your Shopify store
If you connect a Shopify store, orders placed there arrive in Surfbase so you can work them like any other order. For each order we receive the buyer’s name and email address, their phone number and delivery address if they gave one, any checkout note, and Shopify’s own identifier for them. We ask Shopify only for the permissions that make that work.
We keep a record of who looks at it. Every time someone in your workspace opens a Shopify buyer’s details — a single order, a list, an exported file, an invoice — Surfbase records who, what, when and by what route. You can read that log under Settings → Integrations → Shopify. The log names the record, never the buyer.
Erasure reaches what Shopify sends us. When a shopper asks your store to erase them, Shopify tells us, and we clear the buyer’s name, email address, checkout note and Shopify identifier from the order record, delete the delivery address, and anonymise the customer profile if every order they ever placed came from Shopify. If they also have orders outside Shopify, we leave their profile alone and tell you, because that record is yours.
07 Who else sees your information
Running Surfbase involves a few other companies, and each of them necessarily sees something:
- Amazon Web Services Hosting · Sydney
- Hosts surfbase.app, the product, its database and your files on servers in Sydney. Every request passes through it.
- Cloudflare DNS · Analytics · Global
- Provides DNS for the domain, receives mail sent to our address and forwards it on, and runs the site analytics described above.
- Resend Email · US
- Sends the email Surfbase sends, such as invitations, receipts and notices. Your address and the message pass through it.
- Sentry Errors · US
- Collects error reports when something breaks. If a page fails while you’re using it, Sentry receives the technical details of the failure and of the request that caused it — the page you asked for, and your browser and device type — on servers in the United States. It is configured not to receive what you typed into a form, your cookies, or your IP address.
- Stripe Payments · US, AU
- Takes payment for Surfbase, and from your customers when they pay you through Surfbase. Card details go to Stripe directly; we never hold them.
- Shopify Store · CA, US
- If you connect a store, orders and buyers come from Shopify, and product, stock and fulfilment updates go back. Shopify also holds that information under its own terms with you.
- Xero Accounting · US
- Only if you connect a Xero organisation. The invoices and payments you send to Xero go there, with the customer’s name and email address on them.
- Apple, Google, Microsoft Sign-in · Global
- Authenticate you when you choose to sign in with one of them, as described above. You can use a password instead.
- esm.sh, jsDelivr Code · Global
- Serve the 3D library the board viewer uses when you open a design in 3D. Your browser fetches it directly, so your IP address and browser details are visible to them.
- Bunny Fonts Fonts · No visitor data
- Supplies our typefaces. We download them when we build the site and serve them from our own servers, so your browser never contacts Bunny Fonts and it sees nothing about you.
Some of these providers are outside Australia or store data outside Australia, so your information may be held overseas. We don’t sell your information, rent it, or pass it to anyone else for their own marketing.
08 How we use your email address
To run your account: invitations, receipts, and notices about your plan or changes to these terms. If you joined the waitlist, to tell you about Surfbase becoming available. And to reply if you write to us.
09 How long we keep it
- Your account Until closed
- Until you close your account. Billing records are kept for as long as tax law requires.
- Waitlist address Until you ask
- Until you ask us to delete it, or until we no longer need it for the waitlist, whichever comes first.
- Workspace records Until closed
- For as long as you have an account, because they’re the business’s own books. You can delete customers, orders and designs yourself at any time.
- Raw store messages 90 days
- Emptied after 90 days. We keep the fact a message arrived, so a duplicate can’t be processed twice, but not what was in it.
- Technical logs 14 days
- Logs and failed background work are deleted after 14 days. We take care that a person’s contact details don’t reach them in the first place.
10 Your choices
Every waitlist or news email we send you has an unsubscribe link. You can also email hello@surfbase.app at any time to ask what we hold about you, to correct it, or to have it deleted, and we’ll action it.
11 Complaints
If you think we’ve mishandled your personal information, email hello@surfbase.app first and we’ll try to sort it out. If you’re not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12 Changes to this policy
If this policy changes, we’ll update this page and the date at the top.