Privacy Policy
Effective 28 August 2026.
Who we are. Hamish Palmer, sole trader, trading as phas (phas.au / phas.nz). Privacy contact: [email protected].
This policy is written to the Australian Privacy Principles (Privacy Act 1988 (Cth)) and the NZ Privacy Act 2020, and it applies to everything we do with personal information.
1. What we collect
- Account data: name, email address, phone number, password (stored hashed), and two-factor secrets.
- Domain registrant data: for each domain contact role — name, organisation, postal address, email, phone; for .au domains, eligibility identifiers (ABN/ACN/trademark details) as auDA requires.
- Billing data: your card is collected and stored by Stripe, our payment processor — we never see or store full card numbers. We keep transaction records (what was bought, amounts, Stripe references).
- Support data: tickets, emails you send us, and a support verification code shown in your account.
- Service data: hosting account metadata, DNS records you configure, email-sending domains and delivery events for the transactional email add-on, backup and monitoring records for those add-ons.
- Technical data: IP addresses, browser user-agent, session and login records (shown to you on your sessions page), and server logs.
We collect it directly from you, from your use of the services, and from our suppliers processing on our behalf. We don't buy data about you.
2. Why we collect it
To deliver and bill the services you've ordered; to verify eligibility where a registry requires it; to secure accounts (login history, 2FA, fraud signals from Stripe Radar); to provide support; to meet legal and registry obligations; and to send service email. Marketing: we don't send marketing email. If that ever changes, marketing messages will be sent only with your consent and with a working unsubscribe in every message, as the Spam Act 2003 (Cth) and the Unsolicited Electronic Messages Act 2007 (NZ) require.
3. Who we disclose it to
We disclose personal information only as needed to run the services:
| Recipient | What | Where |
|---|---|---|
| Stripe (payments, fraud screening) | billing identity, card (held by Stripe), transactions | United States |
| Synergy Wholesale (registrar of record) | registrant contact + eligibility data | Australia |
| Domain registries and their operators (auDA/Identity Digital for .au, InternetNZ for .nz, gTLD registries), and ICANN-approved escrow agents for gTLDs | registrant data as their policies require | varies by registry; escrow typically United States |
| Cloudflare (DNS hosting) | zone and record data you configure | United States |
| Postmark / ActiveCampaign (email delivery, in and out) | email content and delivery metadata for mail we send you, support mail, and the transactional email add-on | United States |
| Hosting infrastructure | your hosted content, on servers in the region you choose at checkout | Australia, New Zealand or Singapore |
| Sentry (error monitoring) | technical error context, which can incidentally include account identifiers | United States |
We also disclose where the law requires it — subpoenas, court orders, or regulator demands — and we tell you when we lawfully can.
WHOIS / public registers. Domain registration data is published according to the registry's rules (WHOIS/RDAP for gTLDs and .au; the .nz Query Service for .nz). .nz individuals not in significant trade can ask us to apply the Individual Registrant Privacy Option, which withholds phone and address from the public register.
4. Cross-border handling
Some recipients above are outside Australia and New Zealand (chiefly the United States). Before disclosing overseas we take the steps the Privacy Act 1988 (APP 8) and the NZ Privacy Act 2020 (IPP 12) require — contractual safeguards with the supplier or your informed consent — and we remain accountable for their handling where the Act makes us so.
5. Security
Passwords are hashed; panel access uses single-sign-on links rather than stored passwords; support and admin access is role-limited; sessions are listed in your account and individually revocable; two-factor authentication is available (and recommended); backups of our own database are encrypted with a key held offline. No internet service can promise perfect security, but we build so that a single failure doesn't cascade.
6. Retention
We keep personal information while your account is active and as long afterwards as the law and registry rules require — tax records (5 years, AU), .nz registration data (6 years after a domain is cancelled or transferred, per InternetNZ rules), and accounting/audit trails. When you delete your account, we anonymise personal data and keep only the event and accounting history the law requires; the deletion record itself is retained as evidence of the deletion.
7. Access, correction, export, deletion
Your account pages let you see and correct most data directly, export a machine-readable copy of everything we hold about you, and delete your account (once no live paid services remain). Anything you can't reach self-service, ask via [email protected] and we'll respond within 30 days.
8. Data breaches
If a breach involving your personal information is likely to cause you serious harm, we will notify you and the relevant regulator — the OAIC under the Notifiable Data Breaches scheme (AU) and/or the Office of the Privacy Commissioner (NZ, where we aim to notify within 72 hours of becoming aware) — with what happened, what data was involved, and what we're doing about it.
9. Cookies
phas uses cookies for sign-in sessions and security (CSRF) only. We set no analytics or advertising cookies.
10. Complaints
Complain to us first at [email protected] — we'll acknowledge promptly and answer within 30 days. If you're not satisfied: in Australia, the Office of the Australian Information Commissioner (oaic.gov.au); in New Zealand, the Office of the Privacy Commissioner (privacy.org.nz).
11. Changes
Material changes are emailed to your account address 30 days before they take effect, matching the Terms of Service change process.