Privacy Policy
Who we are
Arxiom(“Arxiom”, “we”, “us”, “our”) is committed to protecting the privacy of personal information collected from clients, prospective clients and visitors to our website. This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
The two roles we play
A. Information we hold for ourselves. When you visit our website, enquire about Arxiom, or use our tools as a subscriber, we decide how that information is handled and this policy governs it in full.
B. Information we hold on behalf of our customers. When a homeowner or user submits and enquiry through a tool branded for a trade business, that business is collecting the information and is responsible for it. Arxiom stores and processes it on their instructions only, under our subscriber agreement. We do not use it for our own marketing, do not sell it, and do not share it between subscribers.
If you’re a homeowner who enquired through an Arxiom-powered tool, contact the trade business you enquired with, their privacy policy applies. If you can’t reach them, contact us and we’ll help you get to the right place.
What we collect from subscribers
Account details: name, business name, email, phone, ABN, trade type, business address, login credentials.
Billing information: plan, invoices, payment status, and the verification details required for payouts. We do not store card or bank account numbers.
Configuration and content: branding, logos, pricing settings, page content, templates.
Business data you enter: quotes, variations, invoices, price books, safe work methods, job records, and voice notes recorded for transcription.
Connected accounts: access tokens and sync data for any CRM, accounting or advertising service you connect.
Usage and technical data: IP, browser or device, features used, and action logs kept for security and support.
Mirador and address lookups
Our roof estimator send the address or map location you enter to third-party mapping services, OpenStreetMap (Nominatim, Photon, Overpass) for the address and building outline, and Esri for satellite imagery. Some operate overseas, including in the United States. When the tool is used without an enquiry form, no contact details are collected and the address is not stored by us.
Why we use it
To run and support your account; provide the tools you subscribe to and route enquiries to your CRM; take payment and process payouts; provide support; secure the platform against fraud and unauthorised access; improve our product through aggregated and de-identified analysis; send service notices and release notes; market Arxiom to trade businesses; and meet our legal obligations.
We do not use your customers’ personal information to train models, build cross-customer profiles, or market to them.
Who we share your data with
We do not sell personal information. Our providers are Supabase (database, authentication, hosting), Stripe (billing and payouts), Resend (transactional emails), GoHighLevel (our CRM and the integration that delivers enquires to subscribers), OpenStreetMap and Ersi (mapping), Xero (where connected), Meta and Google (our own advertising and analytics), and GoDaddy (hosting).
Overseas disclosure. Several providers process information outside Australia, principally in the United States. We take responsible steps to ensure they handle it consistently with the Australian Privacy Principles.
Separation between subscribers
Each subscriber’s data is logically separated and protected by access controls enforced at the database level. A subscriber can only see their own account, configuration and enquires. Arxiom staff access subscriber data only where necessary for support, faults or legal obligations, and that access is logged.
Cookies and advertising
On arxiom.com.au we use essential, analytics and advertising technologies for our own marketing. In subscriber-branded tools, any advertising pixel that fires belongs to the trade business operating that tool, using their own advertising account. Arxiom does not operate tracking pixel across subscriber websites and does not build advertising profiles of their customers.
Security
Encrypted connections, encryption at rest, row-level access controls, role-based permissions, restricted administrative access, secret management for third-party credentials, and regular security review. If a breach is likely to result in serious harm we notify affected individuals and the OAIC. Where a breach affects data held on subscriber’s behalf, we notify that subscriber without undue delay so they can meet their own obligations.
How long we keep it
Subscriber account and business records, for as long as needed to fulfil subscriber subscription services. Enquiry data held for a subscriber, while their subscription is active or until they delete it; on cancellation retained 90 days for export, then deleted. βWhen no longer required, we securely delete or de-identify the information.β¬
Access, correction and complaints
Subscribers can update most account information in the portal. Email info@arxiom.com.au for a copy, a correction or deletion; we respond within 30 days. Complaints are acknowledged within 5 business days and resolved within 30. If you’re not satisfied, complain to the OAIC at oaic.gov.au or 1300 363 992.
Automated decision making
Arxiom’s tools generate indicative estimates. These are calculations and drafting aids, not decisions about a person, every quote, price and document is reviewed and issued by the trade business. We do not make automated decisions with legal or similarly significant effects.
Last updated: August 2026