mise.
Draft document. This page was drafted with AI assistance as a starting point and has not yet been reviewed by a qualified Australian/NZ lawyer. Legal entity details below are placeholders. Do not treat this as final or legally binding until a qualified professional has reviewed it and the placeholders have been replaced with real details.

Privacy Policy

Last updated: [DATE — set when this is finalised]

This Privacy Policy explains how [COMPANY LEGAL NAME](ABN [ABN NUMBER]) (“we”, “us”, “mise.”), an Australian-registered company, collects, holds, uses, and discloses personal information in connection with the mise. hospitality operations software (the “Service”).

We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Where we handle personal information of individuals in New Zealand, we also have regard to the Information Privacy Principles (IPPs) under the Privacy Act 2020(NZ) — see the “New Zealand users” section below.

1. Who this policy covers

This policy applies to: (a) the individual who signs up a business for the Service (a “Manager”); (b) staff members that a Manager invites to join their business on the Service (“Staff”); and (c) anyone else whose personal information a customer enters into the Service (for example, a staff member's certification expiry date entered by their manager).

If you are a Staff member invited by a business using mise., that business is generally responsible for the accuracy of information it enters about you, and for telling you how it uses the Service. We act as the software provider and data processor for that business.

2. Information we collect

We collect the following categories of personal information:

  • Account information: name, email address, and a securely hashed password. If you enable two-factor authentication, we store an encrypted authentication secret and hashed backup codes.
  • Business information: business name, business type, location (city/country), and currency preference.
  • Staff information: name, job title, training/certification records, and shift/rota times, entered by a Manager or by Staff themselves.
  • Operational data: content Managers and Staff choose to enter or exchange through the Service, such as stock levels, menu pricing, event bookings, revenue figures, and messages sent in team communication channels.
  • Technical information: IP address, browser/device information, and session activity, collected automatically for security purposes (for example, detecting repeated failed login attempts).

3. How we collect information

We collect personal information directly from you when you create an account, accept a staff invite, or otherwise use the Service. We do not currently collect personal information from third parties or public sources.

4. Why we collect, hold, and use personal information

We use personal information to:

  • provide, operate, and maintain the Service;
  • authenticate your identity and keep your account secure (including password hashing, two-factor authentication, and login rate-limiting);
  • send account-related communications, such as password-reset links and staff invites;
  • diagnose and fix technical problems (error monitoring); and
  • comply with our legal obligations.

We do not use personal information for advertising, and we do not sell personal information to third parties.

5. Disclosure to third parties, including overseas recipients

We disclose personal information to the following service providers, who process it on our behalf to help us run the Service:

  • Hosting and database — our application and database infrastructure providers, configured where possible to host data in Australia (Sydney).
  • Email delivery — a transactional email provider, used to send password-reset and staff-invite emails.
  • Error monitoring — a service that receives technical error reports (which may occasionally include fragments of request data) to help us find and fix bugs.

Some of these providers are based in, or process data in, the United States or other countries outside Australia and New Zealand. By using the Service, you acknowledge that personal information may be disclosed to overseas recipients. We take reasonable steps to ensure these providers protect personal information consistently with the APPs. Contact us using the details below for a current list of sub-processors and their locations.

We do not otherwise share personal information with third parties except: with your consent; where required by law; or in connection with a business transfer (such as a merger or acquisition), in which case we will notify affected users.

6. Data security

We take the security of personal information seriously. Technical measures currently in place include:

  • passwords hashed with bcrypt and never stored in plain text;
  • optional two-factor authentication (TOTP) with single-use backup codes;
  • encrypted connections (HTTPS/TLS) between your browser and our servers;
  • account lockout and rate-limiting after repeated failed login attempts; and
  • session cookies that are HttpOnly and not accessible to page scripts, with CSRF protection on all account-changing requests.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the relevant regulator as required by the Notifiable Data Breaches scheme (Australia) or Part 6 of the Privacy Act 2020 (New Zealand).

7. Data retention

We retain personal information for as long as your account remains active, plus a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated personal information at any time (see “Access, correction, and complaints” below).

8. Access, correction, and complaints

You may request access to, or correction of, the personal information we hold about you. To make a request, or to raise a privacy complaint, contact us at [PRIVACY CONTACT EMAIL]. We will respond within a reasonable time.

If you are not satisfied with our response, Australian individuals may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, and New Zealand individuals may complain to the Office of the Privacy Commissioner at privacy.org.nz.

9. New Zealand users

Although we are an Australian-registered company, we welcome businesses and staff based in New Zealand. For New Zealand users, we aim to meet the Information Privacy Principles (IPPs) under the Privacy Act 2020 (NZ) as well as the APPs, including in relation to access and correction rights (IPPs 6–7) and notification of a privacy breach that has caused, or is likely to cause, serious harm.

10. Cookies

We use two cookies, both strictly necessary for the Service to function: a session cookie (to keep you signed in) and a CSRF token cookie (to protect against cross-site request forgery). We do not use advertising or analytics tracking cookies.

11. Children

The Service is a workplace tool intended for business owners and their staff. It is not directed at, and we do not knowingly collect personal information from, children.

12. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify account holders (for example, by email or an in-app notice) before the changes take effect.

13. Contact us

For privacy questions, access/correction requests, or complaints, contact: [COMPANY LEGAL NAME], [PRIVACY CONTACT EMAIL], [BUSINESS ADDRESS].