These terms are pending final legal review. The operational facts on this page — trial length, retention periods, what happens on non-payment — are read from the live configuration and are accurate. The legal wording has not yet been signed off by counsel and may change; account owners will be emailed before a material change takes effect.
Privacy policy
1. Who we are and what this covers
CockatooMind operates cockatoomind.com, the CockatooMind subscription quoting system for window and door fabricators.
This policy covers two different groups of people, and the difference matters:
Our customers — the fabricating businesses who subscribe, and the staff they give accounts to. We are the entity responsible for their personal information.
Our customers' customers — the homeowners and builders a fabricator quotes for. We hold their information on the fabricator's behalf. The fabricator decides what to collect and why; we store and process it under our agreement with them. If you are a homeowner who received a quote, the business named on that quote is who to contact first, and this policy tells you what we do with the information they gave us.
This policy covers the product pages and workspaces of the service. Other pages published on the same host by their own owners are covered by their own policies.
2. What we collect
From a fabricator and their staff
| Information | Why we have it |
|---|---|
| Business name, ABN, business address | Identifying the account and issuing tax invoices |
| Name, email address, mobile number of each user | Signing in, sending the emails the service depends on, support |
| Password | Stored only as a bcrypt hash on the customer's own workspace, never in plain text and never in our central directory |
| Payment details | We never see or store card numbers. Payment is handled by Stripe; we hold only a Stripe customer identifier |
| Usage counts (quotes created, AI actions, SMS sent, storage used) | Enforcing plan allowances and billing |
| IP address and browser user-agent, stored as a keyed hash | Rate limiting, fraud prevention, and showing a user their own active sessions |
| Support correspondence | Answering it |
On behalf of a fabricator, about their customers
Names, addresses, email addresses, phone numbers, photographs of properties and window openings, hand-drawn sketches, quote and project history, records of when a quote link was opened, and payment records for deposits.
We do not sell any of this, we do not use it to train models, and we do not use it for any purpose other than providing the service.
Automatically
Server logs (request paths, response codes, timings, hashed IP addresses) for security and diagnosis.
Cookies strictly necessary for signing in and for cross-site request protection — no advertising or tracking cookies. On the product pages that is a cross-site request protection seed named sydtech_cs (one day) and, once you sign in, a session cookie scoped to your own workspace. Cookies set by unrelated plugins on the same host are stripped from the product pages' responses.
3. How we use it
To provide the service; to bill for it; to keep it secure and available; to support you; to tell you about changes to the service, your subscription or a security incident. Nothing else. We do not send marketing to a fabricator's customers.
4. Who else touches it (sub-processors)
Every one of these is a company we depend on; none of them may use the data for their own purposes.
| Sub-processor | What they handle | Where |
|---|---|---|
| Cloudflare, Inc. | Traffic routing, TLS, security filtering | Global edge; requests are terminated at the nearest point of presence |
| Stripe Payments Australia Pty Ltd | Subscription payments and, if a fabricator enables it, their customers' deposits | Australia / United States |
| Mobile Message Pty Ltd | SMS, when a fabricator enables it | Australia |
| Browserless | Rendering quote PDFs: the quote page is sent to a headless browser and the PDF returned; nothing is retained | The region configured by the operator; may be outside Australia |
| DeepSeek | AI features only. The text of an AI request and, for "size from a photo", the image itself | Outside Australia — see section 5 |
5. Overseas disclosure — read this one
AI features. When a user asks the system to fill a schedule, check a quote, draft a message or estimate a size from a photograph, the relevant text — and for size estimation the photograph — is sent to DeepSeek, which processes it outside Australia. A photograph of a window is usually a photograph of somebody's home. AI features are included or excluded by plan, every one of them is something a user chooses to run, and the service works fully without them; a fabricator who does not want them at all can ask us to disable them for their whole workspace.
PDF rendering. A quote PDF is produced by sending the quote page to a headless-browser service, which returns the file and retains nothing. The region is configured by the operator and may be outside Australia.
Cloudflare. Requests are routed through Cloudflare's global network, so traffic metadata may transit outside Australia even though the data at rest does not leave the country.
Everything else — the database and uploaded files — is stored in Australia.
6. How long we keep it
| Data | Retention |
|---|---|
| A live workspace's data | For as long as the subscription runs |
| After the workspace is closed | 90 days if the account ever paid; 30 days if it never did. It can be restored in full during that window |
| Final export after deletion | 12 months (paid) / 30 days (never paid), then destroyed |
| Server and application logs | 30 days |
| App diagnostic uploads | 30 days |
| Administrative audit log | 2 years |
| Workspace address reservation after deletion | 12 months, so a quote link in someone's inbox can never be taken over by a different business |
| Billing records | 7 years, as Australian tax law requires |
7. Security
Data is encrypted in transit (TLS 1.2+, HSTS). Passwords are bcrypt hashes. Access tokens are stored hashed, expire, and can be revoked per device. Service credentials are encrypted at rest with a key held outside the database. Each fabricator's data lives in its own database tables, its own file directory and its own cookie scope. Our staff cannot read a fabricator's quotes casually: doing so requires a deliberate support session that is recorded in the fabricator's own activity log and in our audit log, and the workspace owner is emailed when one is opened.
No system is perfectly secure, and we would rather say so than imply otherwise.
8. If something goes wrong
We assess any suspected breach within 72 hours internally. Where a breach is likely to result in serious harm, we notify the Office of the Australian Information Commissioner and every affected individual as the Notifiable Data Breaches scheme requires. Where the affected information belongs to a fabricator's customers, we notify the fabricator first and coordinate with them, because they hold the relationship.
9. Your rights
You may ask for a copy of the personal information we hold about you, ask us to correct it, or complain about how we have handled it. A fabricator can export their entire workspace at any time from the console — a complete, portable archive, not a summary — and can delete the workspace themselves.
Contact [email protected]. We respond within 30 days. If you are not satisfied, you may complain to the OAIC at oaic.gov.au.
10. Changes
We will post any change here and, where it materially affects you, email account owners before it takes effect.