Privacy policy.
Last updated: 30 August 2026
This Privacy Policy explains how Surau Engineering Pty Ltd (ABN 51 696 483 468), trading as “Pitlane HQ” (“PitlaneHQ”, “we”, “us”, or “our”), handles personal information in connection with our workshop management software and related services (the “Service”).
We are bound by the Australian Privacy Principles (“APPs”) in the Privacy Act 1988(Cth) (“Privacy Act”), by the Spam Act 2003 (Cth) for electronic marketing, and by applicable State and Territory legislation, and we are committed to meeting those obligations. This policy describes how we go about it. Where we identify a shortfall we will say so and fix it rather than paper over it — see the cookie section below for a current example. “Personal information” has the meaning given in the Privacy Act.
1. Our two roles: when we control data, and when we only process it
PitlaneHQ handles personal information in two distinct capacities. Understanding which applies determines who is accountable under the Privacy Act and how you exercise your rights.
- As the responsible entity (we decide how data is handled). For information about the workshop business and its users — the account holder's name, login, billing details, and how the workshop itself uses the Service — PitlaneHQ is the APP entity. This policy governs that information directly.
- As a service provider acting on a workshop's instructions (the workshop decides). For the operational data a workshop stores in the Service about its own customers, vehicles, employees, jobs, invoices, and communications, the workshop is the APP entity and is responsible for that data under the Privacy Act. PitlaneHQ processes it only to provide the Service, on the workshop's behalf, under the terms of our Data Processing Addendum. If you are an end customer or employee of a workshop, your privacy enquiries should generally be directed to that workshop; we will assist them in responding.
2. Information We Collect
2.1 Workshop account information (we are the responsible entity)
When a workshop registers for PitlaneHQ, we collect information to create and manage the account:
- Name and contact details of account users (email address, phone number)
- Business name, ABN, and business address
- Billing information (payment method and transaction history are processed and stored by Stripe; we do not store full card numbers)
- Login credentials (passwords are securely hashed and never stored in plain text)
2.2 Workshop operational data (the workshop is the responsible entity)
In the course of running their business, a workshop may store the following in the Service. PitlaneHQ processes this data on the workshop's instructions and does not use it for our own purposes:
- Customer names, contact details, and vehicle information (including registration plate and VIN)
- Job records, inspections, quotes, invoices, payments, and related financial information
- Employee and technician records, including timesheets and payroll information where the workshop uses our HR & Payroll module (see section 8)
- Stock, supplier, and purchase order information
- Uploaded files and documents (photos, PDFs, attachments)
- SMS, email, webchat, and in-app communication history
- Call recordings, transcripts and voicemail, where the workshop uses Pitlane Phones and has enabled recording or transcription. This covers the call audio (if audio storage is on), the automated speech-to-text transcript, any AI-generated summary of it, and call metadata such as the numbers involved and the time and duration. These features are off by default. Because recording is regulated by State and Territory law and the rules differ across Australia, the obligation to record lawfully — including giving whatever notice or consent is required, and telling staff — rests with the workshop. See our Call Recording & Transcription Notice.
- Vehicle records returned by registration and VIN lookups against national vehicle registers, where a workshop uses that feature
- Marketplace listing content and customer reviews, where a workshop lists publicly
2.3 End-customer information (collected directly via customer-facing features)
Where a workshop enables customer-facing features — the customer portal, online booking, or the Pitlane Marketplace — end customers may provide personal information directly to the Service (name, contact details, vehicle, booking and quote details). We process this to deliver the requested feature and make it available to the relevant workshop.
2.4 Usage and technical data
- Browser type, operating system, and device information
- IP address and approximate (city-level) location
- Pages visited, features used, and time spent in the Service
- Error logs and performance data used to operate and improve the Service
2.5 Cookies and analytics
We use cookies and similar technologies for essential functionality (authentication, security, site preferences) and for analytics and marketing measurement:
- Essential cookies — required for login, security, and core Service operation. These cannot be disabled without breaking the Service. Cross-site request forgery protection does not generally use a cookie — it works by checking where the request came from — with one narrow exception: a short-lived cookie set only while you are connecting a third-party account, described in the Cookie & Tracking Notice.
- Google Analytics 4 (GA4) — understanding aggregate usage to improve the Service.
- Meta Pixel — measuring the effectiveness of our marketing campaigns. This involves disclosure to Meta Platforms (United States); see section 11.
- Sentry — error and performance monitoring.
- Our own advertising conversions — not a cookie and not a tag. When you send us an enquiry or demo request through this website, start a trial, or become a paying subscriber, our servers report that to PitlaneHQ's own Google Ads, Meta and Microsoft Advertising accounts so we can tell which of our ads worked, and to our own Google Analytics 4 property. Your email address goes with it to the three advertising platforms, SHA-256 hashed first, and your phone number too where you gave us one on an enquiry form — the trial and subscription events carry the email alone. Google Analytics 4 receives neither. The field-by-field list is on our Sub-processors page.
Being straight with you about the current position: non-essential analytics and advertising tags (Google Analytics 4 and the Meta Pixel) load when you visit our public marketing website, and we do not yet present a consent banner that lets you refuse them beforehand. We are not going to describe that as consent obtained by your continued use of the site — a preference control is the right answer and it is planned. Until it ships, browser-level controls genuinely work and do not depend on us, and you can ask us to exclude you at privacy@pitlanehq.com.au. Note that those browser-level controls act on tags in your browser, so they stop the Google Analytics 4 tag and the Meta Pixel but do not reach the conversion sends in the bullet above, which run on our servers. There is no self-service switch for those; ask us and we will stop sending further events about you, which we do by hand. Full detail, including who receives what, is in our Cookie & Tracking Notice. None of this applies inside the product: no advertising or analytics tag is loaded there, and no advertising cookie is set. Marketing attribution is a separate thing, it runs on our servers rather than in your browser, and it does reach advertising platforms — section 5.1 sets out what is sent, to whom, and when.
3. How We Use Personal Information
We use personal information only for purposes connected with providing and operating the Service:
- Provide and maintain the Service — deliver workshop management features and process data on the workshop's behalf
- Communicate with you — send transactional messages (invoices, booking confirmations, password resets), service announcements, and support responses
- Process billing — manage PitlaneHQ subscription billing via Stripe
- Improve the Service — analyse aggregate usage, diagnose issues, and develop features
- Security and fraud prevention — detect and prevent unauthorised access, abuse, and other threats
- Legal compliance — meet our obligations under Australian law
We will not use or disclose personal information for a purpose other than the one for which it was collected unless you would reasonably expect it, you consent, or the use is otherwise permitted under the APPs.
4. Artificial Intelligence and Automated Processing
Some optional features (collectively, “Ask the Boss” and our AI assistance features) use machine-learning models to generate draft text and suggestions — for example, drafting SMS replies, polishing quote and invoice wording, cleaning up technician notes, and assisting with job estimation. Where these features are enabled:
- Relevant workshop data is processed by our AI sub-processor to generate the output. This processing occurs to deliver the feature you requested. The provider engaged for this purpose, and its location, are named in our Sub-processors list.
- Outputs are drafts for human review by default. We do not make decisions that produce legal or similarly significant effects about an individual by automated means alone. A workshop user reviews and decides whether to use an AI-generated output — unless that workshop has switched on automatic sending of SMS replies, which is off unless enabled and gated for each message.
- Where the insights come from. The insights and history a workshop sees about its own jobs draw only on that workshop's own data. Where a workshop uses AI job estimation, the prompt may also draw on the pooled records described below — records from which we remove the customer details we hold, carrying no workshop name or account identifier — so that suggestions reflect patterns seen across the network.
- Pooled repair records for platform improvement (optional). If a workshop enables Ask the Boss by accepting its terms and does not tick the contribution opt-out offered on the same screen, repair and inspection records from its completed jobs are pooled into our platform intelligence and combined into cross-network statistics — such as how often a repair is seen on a given make, model and mileage band, typical labour-hour ranges, repairs that commonly occur together, and seasonal patterns. Before pooling we remove the customer details we hold for the job — names, contact details, plates, VINs and addresses — and we strip prices we can detect from the text. That removal is automated and works from what we hold, so it is not a guarantee: someone we have no record of, named only in a technician's note, can survive it. A pooled record has no price fields and no workshop name or account identifier. A pooled repair record keeps an internal reference to the job classification it came from, so we can trace it and delete it on request; it includes the vehicle's make, model, year, class, fuel and engine details, driver-assistance features and mileage band; the repair type and parts categories; redacted symptom and fix summaries and a numeric vector derived from them, used to find similar repairs; diagnostic trouble codes; labour hours, turnaround time, staff count and repeat-repair, sublet and third-party-billing flags; the job completion date; and, where recorded, the state or territory of the workshop's registered business address. A pooled inspection record includes the vehicle's make, model, year, class and mileage band; the standardised inspection item checked and its result; the inspection date; and, where recorded, the same state or territory — it keeps no reference back to its source workshop, so once pooled it cannot be attributed to any workshop or individually deleted for one. It is never your raw data shared with another workshop. A workshop can opt out at any time from Settings → Ask the Boss, and we will exclude it from this contribution going forward.
- What we keep if you leave. The cross-network statistics we derive from pooled records — how often a repair is seen on a given make, model and mileage, and similar patterns — store no workshop or customer identifier, and a group is only published once at least five contributing jobs sit behind it. They are part of PitlaneHQ's own product data and are retained if your workshop closes. The pooled repair records your workshop contributed are deleted with the rest of your data, located through the internal reference each one keeps. Pooled inspection records are not: they keep no reference back to your workshop, so they cannot be located or deleted for one, and they remain in the pool.
- Technical reference data sourced from licensed third-party providers is excluded from any model training, consistent with our licensing obligations.
5. Disclosure and Sub-processors
We do not sell personal information. We disclose information only to the service providers (“sub-processors”) needed to deliver the Service, and only as necessary for that purpose. The list — including each provider's location, purpose, and the categories of data they process — is published at pitlanehq.com.au/legal/sub-processors and is kept current as providers change. It also names the analytics providers used on our own marketing website. If you believe a recipient is missing from it, tell us at privacy@pitlanehq.com.au and we will correct it.
Categories of recipient include:
- Infrastructure — hosting, database, and encrypted backups (Microsoft Azure in Australia; Cloudflare; AWS and Backblaze for backups)
- Payments and communications — Stripe (PitlaneHQ subscription billing), Global Payments (Pitlane Pay — card payments a workshop takes from its own customers, including counter sales), Twilio (SMS), Resend (email), RingCentral (telephony, and call recording or transcription where a workshop enables it)
- Observability — Sentry (error and performance monitoring)
- Opt-in integrations — engaged only when a workshop activates them: accounting providers (Xero, QuickBooks Online), vehicle data and visualisation providers. Data flow stops when the workshop disconnects the integration.
- Advertising platforms — engaged only where a workshop connects its own advertising accounts: Google (Google Ads, and the workshop's own Google Analytics 4 property), Meta, Microsoft Advertising, TikTok, and LinkedIn. Section 5.1 explains what they receive.
We provide workshops at least 30 days' notice before engaging a new sub-processor that will process workshop or customer personal information. We may also disclose information where required by law, court order, or governmental authority, or to protect the rights, property, or safety of PitlaneHQ, our users, or others.
Franchise and enterprise groups. Where this workshop is part of a franchise or enterprise group, your information may be accessed by that group's head office for reporting and oversight, consistent with Australian Privacy Principles 5 and 6. This access is read-only and is recorded in an access log. The same notice appears on invoices and quotes issued by member workshops.
5.1 Marketing attribution (advertising platforms)
Correcting an earlier version of this policy: it said the product “carries no advertising or third-party tracking”. That was wrong, and had been since the marketing-attribution feature shipped. There is no advertising shown in the product and no ad network tag loaded in it, but end-customer data does leave our servers for advertising platforms in the case described here.
The feature does nothing until a workshop connects its own advertising accounts in the Marketing module. Once it has, PitlaneHQ sends an event from its servers as one of that workshop's customers moves through the funnel — an enquiry created, a quote sent, a quote accepted, an invoice paid — to whichever of Google Ads, Meta, Microsoft Advertising, Google Analytics 4, TikTok and LinkedIn that workshop has switched on. Where the workshop has separately accepted the platform's customer-data terms, hashed contact lists are also uploaded to Google Customer Match, Meta Custom Audiences and Microsoft Customer Match; connecting the account alone does not turn that on. Google and Meta receive a hashed email and a hashed phone number, each only where we hold it for that customer; Microsoft receives a hashed email and never a phone number, because its list format has no phone field. Two lists are built: customers with an invoice paid in the last 540 days, and customers sent a quote in the last 90 days that has not converted.
Email addresses and phone numbers are SHA-256 hashed before they leave our servers, and so are names, for every platform that receives them but one. Some things are not hashed, because those platforms will not match a hashed value. Ad click identifiers and advertising cookie values are sent as they are; Meta and TikTok also receive the customer's IP address and browser user-agent; Google Ads receives country and postcode in plain text; and LinkedIn receives a plain-text first and last name where we hold no hashed email or LinkedIn identifier for that person. The field-by-field list per platform is on the sub-processors page.
A customer who has opted out of marketing is excluded: no conversion event about them is sent. The audience uploads exclude them too, and go further by also excluding anyone who has asked to be erased. Coming off a list we have already uploaded works differently by platform: an erasure request sends Google and Meta an active instruction to remove that person's identifiers, while for Microsoft no such instruction exists — the daily upload replaces the whole list, so they drop out when the next daily replace runs, and stay in the list Microsoft already holds if that sync stops before it. Consent mode is on by default for workshops outside Australia, New Zealand and the United States, or whose country we do not hold, and any workshop can switch it on. Where it is on, a conversion event is suppressed unless that customer granted the matching consent — advertising consent for the advertising platforms, analytics consent for Google Analytics 4. It works differently for the audience uploads: consent mode does not stop them, it changes what we tell Google, which is that consent is unspecified rather than granted. For these records the workshop is the responsible entity (section 1, second role): it decides whether an advertising account is connected at all. The send itself is performed by our servers and we choose the fields, so a workshop switching this on should tell its own customers what it means for them. Disconnecting the account stops further sends; removing someone from an audience already uploaded is what the erasure path does.
6. Direct Marketing and the Spam Act
We may send you marketing communications about PitlaneHQ where permitted. In doing so we comply with APP 7 and the Spam Act 2003 (Cth):
- We send commercial electronic messages only with your express or inferred consent
- Every marketing message identifies us and includes a functional unsubscribe facility
- We action unsubscribe requests promptly (within the statutory period)
Note for workshops using the Marketing module: when a workshop sends SMS or email campaigns to its own customers through the Service, the workshop is the sender and is responsible for holding the necessary consents and complying with the Spam Act for those messages. The Service provides consent-management and unsubscribe tooling to assist, but the workshop remains accountable for its own marketing.
7. Data Security
We implement technical and organisational measures appropriate to the sensitivity of the data, including:
- Encryption in transit — all traffic to and from the Service uses TLS/HTTPS
- Encryption at rest — sensitive credentials and integration tokens are encrypted at rest using strong, industry-standard encryption
- Access controls — role-based permissions restrict users to data relevant to their role
- Multi-tenant isolation — each workshop's records are logically segregated and inaccessible to other workshops; only the pooled records described in section 4, from which customer details are removed, cross that boundary
- Secure authentication — passwords are securely hashed; user sessions use secure, short-lived tokens; optional two-factor authentication
- Australian primary hosting — the application and the primary database are located in Australia (Azure Australia East), with point-in-time recovery and geo-redundant encrypted backups. This is not an Australia-only guarantee: some sub-processors necessarily operate overseas (for example SMS delivery, error monitoring in Germany, and a secondary encrypted backup copy in the United States). Section 11 sets out the cross-border position and the Sub-processors list states each provider's location
- Audit logging — data modifications are logged for accountability
No system is perfectly secure. While we take reasonable steps to protect personal information as required by APP 11, we cannot guarantee absolute security.
8. Employee and Payroll Data
Where a workshop uses our HR & Payroll module, the Service processes employee personal information — which may include contact details, employment records, timesheets, pay and superannuation details, and tax identifiers. This information is treated with heightened care:
- The workshop is the employer and the responsible entity for its employees' personal information; PitlaneHQ processes it solely to provide the HR and payroll features and, where the workshop enables it, to sync payroll records to the workshop's connected accounting platform.
- Tax File Numbers and similar identifiers are subject to additional protections; we handle them only as necessary to deliver payroll functionality and in line with the relevant Tax File Number Rule.
- The same encryption, access-control, and Australian-residency measures in section 7 apply.
9. Data Retention
We retain personal information only for as long as necessary for the purposes set out in this policy, or as required by law:
- Workshop operational data (jobs, invoices, customers, vehicles) is retained for the duration of the workshop's subscription so the workshop can run its business.
- After cancellation, we retain data for a limited reactivation and wind-down window, then delete it from the live Service, except where longer retention is required by law (for example, financial and tax records) or as described in the next point. A workshop may request earlier deletion of its data.
- Deletion snapshot — at the point a workshop's data is deleted we write one snapshot of it to storage only PitlaneHQ can reach, held with the rest of the Service's data in Australia (section 7). It contains the workshop's own record and its sites, its users' names, email addresses and roles, its customers, vehicles, jobs, invoices, quotes and bookings — including records the workshop had already deleted within the Service — and a summary of its billing and phone-number setup with our payment and messaging providers. It excludes passwords, two-factor secrets, API credentials, bank account details, director identity details, and uploaded files. We keep it so a deletion made in error can be reversed and so we can evidence what was deleted, and we destroy it 90 days after the deletion.
- Audit and security logs are retained for a defined period (currently at least 90 days, and longer in tamper-evident archive where required for compliance) to support security and accountability.
- Backups — operational backups are retained on a rolling basis (up to approximately six months) and cycle out automatically. In addition, an encrypted compliance snapshot is retained in cold storage for up to seven years to meet Australian financial-record and related legal obligations. When data is deleted from the live Service it is removed from operational backups as they expire; a copy may remain in the encrypted compliance snapshot until that snapshot expires, after which it is deleted. The deletion snapshot described above is not a backup — it is written at the point of deletion and destroyed 90 days later, and it is included in each backup taken while it exists.
10. Your Rights (APP 12 and APP 13)
Subject to the Privacy Act, you have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — request correction of inaccurate, out-of-date, or incomplete information
- Deletion — request deletion of your personal information, subject to legal retention obligations
- Complaint — complain to us and, if unsatisfied, to the Office of the Australian Information Commissioner (OAIC)
- Data export — workshops can export their data via the Service's export features at any time
If your request concerns data a workshop holds about you as its customer or employee (section 1, second role), we will refer you to, and assist, the relevant workshop, who is the responsible entity for that data. To exercise a right or make an enquiry, contact privacy@pitlanehq.com.au. We aim to respond within 30 days.
11. Cross-Border Disclosure (APP 8)
Some sub-processors process data outside Australia (see the sub-processors page for each provider's location and the safeguards that apply). Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs — through Data Processing Addendums, Standard Contractual Clauses, or reliance on the recipient being bound by substantially similar protections. For overseas disclosures that depend on your consent, your use of the relevant feature indicates that consent.
12. Notifiable Data Breaches
We are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of an eligible data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC as soon as practicable, in accordance with the scheme. Where PitlaneHQ acts as a processor for a workshop, we will notify the affected workshop without undue delay so it can meet its own obligations, and we will reasonably assist its response.
13. Children's Privacy
The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have done so, we will take steps to delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice in the Service. The “Last updated” date above reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
For privacy enquiries or to exercise your rights, contact us:
- Privacy: privacy@pitlanehq.com.au
- General enquiries: hello@pitlanehq.com.au
- Phone: 07 4800 9005
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.