Skip to content
CockatooMind

Privacy policy

Version 1.0 — last updated 19 September 2026

These terms are pending final legal review. The operational facts on this page — trial length, retention periods, what happens on non-payment — are read from the live configuration and are accurate. The legal wording has not yet been signed off by counsel and may change; account owners will be emailed before a material change takes effect.

Privacy policy

1. Who we are and what this covers

CockatooMind operates cockatoomind.com, the CockatooMind subscription quoting system for window and door fabricators.

This policy covers two different groups of people, and the difference matters:

Our customers — the fabricating businesses who subscribe, and the staff they give accounts to. We are the entity responsible for their personal information.

Our customers' customers — the homeowners and builders a fabricator quotes for. We hold their information on the fabricator's behalf. The fabricator decides what to collect and why; we store and process it under our agreement with them. If you are a homeowner who received a quote, the business named on that quote is who to contact first, and this policy tells you what we do with the information they gave us.

This policy covers the product pages and workspaces of the service. Other pages published on the same host by their own owners are covered by their own policies.

2. What we collect

From a fabricator and their staff

InformationWhy we have it
Business name, ABN, business addressIdentifying the account and issuing tax invoices
Name, email address, mobile number of each userSigning in, sending the emails the service depends on, support
PasswordStored only as a bcrypt hash on the customer's own workspace, never in plain text and never in our central directory
Payment detailsWe never see or store card numbers. Payment is handled by Stripe; we hold only a Stripe customer identifier
Usage counts (quotes created, AI actions, SMS sent, storage used)Enforcing plan allowances and billing
IP address and browser user-agent, stored as a keyed hashRate limiting, fraud prevention, and showing a user their own active sessions
Support correspondenceAnswering it

On behalf of a fabricator, about their customers

Names, addresses, email addresses, phone numbers, photographs of properties and window openings, hand-drawn sketches, quote and project history, records of when a quote link was opened, and payment records for deposits.

We do not sell any of this, we do not use it to train models, and we do not use it for any purpose other than providing the service.

Automatically

Server logs (request paths, response codes, timings, hashed IP addresses) for security and diagnosis.

Cookies strictly necessary for signing in and for cross-site request protection — no advertising or tracking cookies. On the product pages that is a cross-site request protection seed named sydtech_cs (one day) and, once you sign in, a session cookie scoped to your own workspace. Cookies set by unrelated plugins on the same host are stripped from the product pages' responses.

3. How we use it

To provide the service; to bill for it; to keep it secure and available; to support you; to tell you about changes to the service, your subscription or a security incident. Nothing else. We do not send marketing to a fabricator's customers.

4. Who else touches it (sub-processors)

Every one of these is a company we depend on; none of them may use the data for their own purposes.

Sub-processorWhat they handleWhere
Cloudflare, Inc.Traffic routing, TLS, security filteringGlobal edge; requests are terminated at the nearest point of presence
Stripe Payments Australia Pty LtdSubscription payments and, if a fabricator enables it, their customers' depositsAustralia / United States
Mobile Message Pty LtdSMS, when a fabricator enables itAustralia
BrowserlessRendering quote PDFs: the quote page is sent to a headless browser and the PDF returned; nothing is retainedThe region configured by the operator; may be outside Australia
DeepSeekAI features only. The text of an AI request and, for "size from a photo", the image itselfOutside Australia — see section 5

5. Overseas disclosure — read this one

AI features. When a user asks the system to fill a schedule, check a quote, draft a message or estimate a size from a photograph, the relevant text — and for size estimation the photograph — is sent to DeepSeek, which processes it outside Australia. A photograph of a window is usually a photograph of somebody's home. AI features are included or excluded by plan, every one of them is something a user chooses to run, and the service works fully without them; a fabricator who does not want them at all can ask us to disable them for their whole workspace.

PDF rendering. A quote PDF is produced by sending the quote page to a headless-browser service, which returns the file and retains nothing. The region is configured by the operator and may be outside Australia.

Cloudflare. Requests are routed through Cloudflare's global network, so traffic metadata may transit outside Australia even though the data at rest does not leave the country.

Everything else — the database and uploaded files — is stored in Australia.

6. How long we keep it

DataRetention
A live workspace's dataFor as long as the subscription runs
After the workspace is closed 90 days if the account ever paid; 30 days if it never did. It can be restored in full during that window
Final export after deletion 12 months (paid) / 30 days (never paid), then destroyed
Server and application logs30 days
App diagnostic uploads30 days
Administrative audit log 2 years
Workspace address reservation after deletion 12 months, so a quote link in someone's inbox can never be taken over by a different business
Billing records7 years, as Australian tax law requires

7. Security

Data is encrypted in transit (TLS 1.2+, HSTS). Passwords are bcrypt hashes. Access tokens are stored hashed, expire, and can be revoked per device. Service credentials are encrypted at rest with a key held outside the database. Each fabricator's data lives in its own database tables, its own file directory and its own cookie scope. Our staff cannot read a fabricator's quotes casually: doing so requires a deliberate support session that is recorded in the fabricator's own activity log and in our audit log, and the workspace owner is emailed when one is opened.

No system is perfectly secure, and we would rather say so than imply otherwise.

8. If something goes wrong

We assess any suspected breach within 72 hours internally. Where a breach is likely to result in serious harm, we notify the Office of the Australian Information Commissioner and every affected individual as the Notifiable Data Breaches scheme requires. Where the affected information belongs to a fabricator's customers, we notify the fabricator first and coordinate with them, because they hold the relationship.

9. Your rights

You may ask for a copy of the personal information we hold about you, ask us to correct it, or complain about how we have handled it. A fabricator can export their entire workspace at any time from the console — a complete, portable archive, not a summary — and can delete the workspace themselves.

Contact [email protected]. We respond within 30 days. If you are not satisfied, you may complain to the OAIC at oaic.gov.au.

10. Changes

We will post any change here and, where it materially affects you, email account owners before it takes effect.

Version 1.0 · Last updated 19 September 2026