Privacy
id.tel Global Privacy Policy
Effective 24 August 2026 · Version 2026-08-24-v2
This Global Privacy Policy explains how IDTEL GROUP PTY LTD (ABN 69 693 776 966) ("IDTEL", "id.tel", "we", "us" or "our") collects, uses, stores, discloses and protects personal information through id.tel websites, dashboards, Action Pages, Partner Hub, AI Assistants, AI Visibility tools, Deep Scan and business research, QR functionality, analytics, communications, subscriptions, APIs and integrations. Privacy enquiries can be sent to support@id.tel.
1. Scope
This Policy may apply when you visit id.tel, create an account, manage a business, buy a subscription, participate in the Partner Program, use an Action Page or AI Assistant, scan an id.tel QR code, submit an enquiry, use an integration or API, contact support, or are identified as a publicly listed business owner or professional through legitimate business research.
2. Global framework
IDTEL is an Australian company and id.tel is intended to operate internationally. This Policy provides a global baseline together with additional information for Australia, the European Economic Area, United Kingdom, United States, New Zealand and South Africa. Mandatory local rights continue to apply where they cannot lawfully be excluded.
3. Business and personal information
Much of id.tel concerns businesses and organisations. Purely organisational information may not be personal information under every law. Business information can nevertheless identify a person, particularly a sole trader, individual professional, owner, employee or contact person, and we treat such information according to applicable privacy law.
4. Our privacy role
IDTEL generally determines the purposes and means of processing for accounts, subscriptions, Partner administration, security, fraud prevention, platform analytics, AI Visibility, business research and service operation. In those contexts, IDTEL generally acts as controller, responsible party or the equivalent role under applicable law.
5. Processing for a business
For some features, IDTEL may process information on behalf of a business Customer. The business may independently control how it later uses information it receives from its customers or prospects. Where required, processor obligations may be documented in a separate Data Processing Addendum.
6. Account information
We may collect names, email addresses, phone numbers, authentication identifiers, account roles, permissions, organisation details, account status, login and security records and other information needed to create and administer an account. Passwords are handled by our authentication infrastructure and are not intended to be available to ordinary id.tel personnel in plain text.
7. Business information
We may process business names, trading names, categories, descriptions, websites, phone numbers, email addresses, locations, service areas, hours, products, services, menus, catalogues, prices, offers, booking and ordering links, social and review profiles, logos, images, FAQs, qualifications, accreditations, policies and related business information.
8. Public-source business research
To make onboarding and business improvement easier, id.tel may collect or analyse information from official websites, public webpages, search engines, directories, maps, public social profiles, review platforms, public databases, documents, structured website data, menus, catalogues, public ordering or booking pages and other publicly accessible business sources.
9. Indirect collection
Public availability does not mean privacy rights disappear. Where public business information identifies a person, we consider the context, purpose, reasonable expectations, necessity, likely impact, applicable notification rules and available correction mechanisms. A person who believes public-source information is inaccurate or should not be processed may contact us.
10. Uploaded content
Businesses may upload or provide text, images, logos, documents, PDFs, menus, catalogues, price lists, products, services, FAQs, offers and other materials. A person providing information about someone else must have a lawful basis or appropriate authority to do so.
11. Billing information
For paid Services we may process Customer name, business, billing email and country, plan, Stripe identifiers, invoices, payment status, refunds, chargebacks, discounts, promo codes, taxes, subscription changes and other billing metadata. Complete payment-card details are generally handled by Stripe or the applicable payment provider rather than stored by id.tel.
12. Partner information
For Partners we may process Partner identity and business details, country, website, application information, Partner type, acceptance version, referrals, links, codes, attribution, Customer relationships, permissions, commissions, wholesale licences, payout details, tax information, conversions, performance information and communications.
13. Partner permissions
Referral or Influencer attribution does not automatically provide access to a business's private data. Managed or Reseller access is permission-based and requires an authorised business relationship. Owners can revoke applicable Partner access through available controls.
14. AI Visibility and research
When a business uses AI Visibility, Deep Scan or similar research, we may process business identity, category, locations, services, products, search questions, AI prompts, AI responses, citations, source URLs, scores, recommendations, information gaps, extracted public content, comparison results and scan timestamps. Historical scans may be retained so Customers can compare progress.
15. AI Assistant messages
When someone uses a public AI Assistant, id.tel processes the submitted message, relevant approved business context, selected business location, a privacy-conscious visitor/session identifier and the generated answer as necessary to provide the response. The message may be sent to the configured AI provider for generation.
16. Raw question retention in id.tel analytics
Our current customer-question analytics do not store the raw message text as the analytics label. The system derives an anonymised or lossy question label and general intent topic before inserting customer-question analytics. The underlying AI provider may process the submitted message under its applicable business/API terms and retention controls.
17. Question anonymisation
Before customer questions are surfaced in owner or Partner analytics, our current design attempts to mask or remove direct identifiers such as email addresses, phone numbers, URLs, names, street addresses and booking or reference identifiers. Businesses may see the anonymised question, topic, whether the assistant lacked information and aggregate trends.
18. Action Page analytics
On trackable public business pages, id.tel may record page views, sessions, QR scans, calls, SMS actions, directions, website visits, booking, quote and order clicks, reviews or social links, AI Assistant activity, location actions, referral source, device category and event timing.
19. No raw IP in ordinary Action Page analytics
The id.tel Action Page analytics pipeline is designed not to write raw IP addresses into business analytics. Network information such as an IP address may still be processed transiently by hosting, security and network infrastructure, and the AI Assistant endpoint may use a network address transiently for rate limiting or abuse prevention.
20. Business-scoped identifiers
Our current public analytics create random first-party visitor and session identifiers scoped to the individual business Action Page. This allows useful reach and session measurement without intentionally correlating the same browser across unrelated id.tel businesses.
21. QR attribution
When an id.tel QR code is scanned, we may process the QR campaign, business, location, placement label, scan event, session identifier and subsequent customer actions so the business can understand whether a placement such as a vehicle, counter, menu, flyer or location generated activity.
22. Partner referral attribution
id.tel may use a protected first-party referral cookie or token to identify whether a Customer was introduced by a Partner. The current standard attribution period may be up to 90 days. Referral attribution is used to administer the Partner Program and does not itself give a Partner management access to the referred business.
23. Technical information
Our systems and infrastructure providers may process browser type, device type, operating system, referrer, requested URL, timestamp, network and security information, error details, logs, cookie or session identifiers and similar technical information needed to deliver, troubleshoot and protect the Services.
24. Support and communications
If you contact us, we may process your name, email, business, message, attachments, support history, account information and other information reasonably required to investigate and respond. Relevant support records may be retained for service, dispute, fraud, security, quality and legal purposes.
25. Marketing information
Where permitted by law, we may process marketing consent, preferences, subscription status, campaign engagement, business or Partner interest and unsubscribe status. Transactional communications necessary for account, security, billing or legal purposes are treated separately from optional marketing.
26. Information we generally do not need
id.tel is not designed as a repository for government identifiers, passwords, complete card numbers, medical records, genetic information, biometric templates, criminal records or other highly sensitive information unless a specific feature is lawfully designed for it. Do not place unnecessary sensitive information in a public AI Assistant.
27. Regulated and sensitive sectors
Businesses in healthcare, law, finance, counselling or other regulated sectors should not configure ordinary public id.tel experiences to solicit sensitive records unless the relevant feature has been specifically designed for that purpose and appropriate legal safeguards are in place.
28. How we use information
We use information to create and secure accounts, verify authority, build and operate Action Pages, provide AI Assistants and AI Visibility, research and organise business information, create structured data, process billing, administer Partners, provide delegated access, operate QR and analytics, provide support and communications, prevent fraud and abuse, comply with law, resolve disputes, diagnose issues, improve id.tel and develop new functionality.
29. Service improvement
We may analyse aggregate usage, privacy-minimised analytics, feature adoption, error patterns, anonymised question themes, information gaps and performance data to improve id.tel. Where reasonably possible, we prefer aggregated, anonymised, de-identified or synthetic information for product analysis.
30. AI model training
IDTEL does not treat optional training of third-party general-purpose models on identifiable Customer or end-user content as a normal purpose for which we collect information. We do not intentionally opt identifiable Customer content into optional general model-training programmes unless separately disclosed and lawfully authorised. We may use anonymised, aggregated or synthetic information to improve id.tel subject to applicable law.
31. Automated processing
Automated systems may perform extraction, classification, research, AI Visibility scoring, FAQ generation, recommendations, question classification, spam and bot detection, fraud controls, analytics and conversational responses. Ordinary AI Visibility scores and AI Assistant answers are not intended to be solely automated decisions producing legal or similarly significant effects on individuals.
32. Future automated decisions
If id.tel later uses personal information in automated decisions that could reasonably be expected to significantly affect an individual's rights or interests, we will provide the transparency and safeguards required by applicable law.
33. Future AI agents
id.tel may develop agent-to-business functionality for information requests, availability, quotes, bookings, orders, purchases, payments or sales assistance. If this materially changes the categories or purposes of personal-information processing, we will update our disclosures and provide additional notices where required.
34. GDPR and UK GDPR lawful bases
Where the GDPR or UK GDPR applies, we may process personal data because it is necessary to perform a contract, pursue legitimate interests that are not overridden by individual rights, comply with a legal obligation, act on valid consent where required, or in exceptional cases protect vital interests. Legitimate interests may include operating a useful business-information platform, improving data quality, protecting security, preventing fraud, providing privacy-safe analytics and researching publicly available business information.
35. Consent
Where processing relies on consent, consent can be withdrawn subject to applicable law. Withdrawal does not make earlier lawful processing unlawful. We seek consent where legally required for matters such as certain marketing, non-essential browser storage or other consent-dependent processing.
36. Cookies and browser storage
id.tel uses authentication cookies and first-party browser storage for functions described in our Cookie & Browser Storage Notice, including secure sessions, business-scoped analytics, QR attribution and Partner referral attribution.
37. Advertising
id.tel does not currently operate as a consumer cross-site advertising network and does not currently intend to sell personal information or share it for cross-context behavioural advertising as those concepts are defined under California privacy law. If this materially changes, we will update our disclosures and implement required opt-out mechanisms.
38. Transactional email
We may send account verification, welcome, security, payment, failed-payment, subscription-change, cancellation, Partner invitation and other service-related messages. These may be delivered using a transactional email provider and are distinct from optional marketing.
39. Supabase
We use Supabase for database, authentication and related application infrastructure. Depending on the feature, Supabase may process account, authentication, business, Partner, analytics, AI scan, permission, catalogue and other application data. Our primary application data environment may be hosted in a selected region, including Australia where configured.
40. Vercel
We use Vercel for web application hosting, deployment, content delivery and related infrastructure. Vercel may process technical request, network, log and security information necessary to serve and protect id.tel.
41. Stripe
We use Stripe for subscription billing and payment functionality. Stripe may process payment information, billing details, Customer identifiers, subscriptions, invoices, refunds, disputes, tax information and transaction metadata.
42. OpenAI
We use OpenAI API services for certain AI-powered functionality. Depending on the feature, information sent for processing may include business information, public-source information, AI Visibility questions, AI Assistant messages and context, catalogue content, images or documents, and prompts required to provide the feature. We seek to send only information reasonably necessary for the function.
43. You.com and web research
Certain website-reading or research functions may use You.com or another search/content provider to retrieve public online business information. A provider may receive business name, website URL, public search query or related research context. We do not intentionally use these services to build unrelated sensitive profiles about individuals.
44. Resend
We use Resend for transactional email delivery. Resend may process recipient email address, name where used, message content and email-delivery metadata.
45. Other service providers
We may use reputable providers for security, DNS, monitoring, email, support, accounting, legal services, corporate administration, backups and infrastructure. Providers may change as id.tel evolves. We assess provider access and contractual protections in light of the service performed.
46. Disclosures
We may disclose relevant information to service providers, authorised Partners, professional advisers, insurers, auditors, regulators, courts, law enforcement, corporate-transaction participants or other persons where lawfully required or directed by you. We seek to limit disclosure to what is reasonably necessary.
47. Public Action Page information
Information a business chooses to publish on an Action Page is public and may include business name, contact details, locations, hours, products, services, prices, FAQs, offers, images and external links. Businesses should not publish private personal information unless they intend it to be public and have authority to publish it.
48. Search engines and AI systems
Public id.tel pages may be crawled, cached, indexed, analysed or reproduced by independent search engines, AI systems, archives and other internet services. Removing information from id.tel does not necessarily cause immediate deletion from third-party caches or indexes outside our reasonable control.
49. International processing
IDTEL is based in Australia and uses international technology providers. Depending on the Service and provider, information may be processed, accessed or stored in Australia, the United States, countries in the European Economic Area, the United Kingdom and other countries in which contracted providers lawfully operate. We will identify more specific destinations where required and reasonably practicable.
50. Transfer safeguards
Where applicable privacy law requires safeguards for international transfers, we may use contractual data-protection terms, Data Processing Addenda, EU Standard Contractual Clauses, UK-approved transfer mechanisms, adequacy decisions, binding schemes, vendor commitments or another legally recognised mechanism.
51. Australian cross-border obligations
Where the Australian Privacy Act applies, IDTEL will take steps required by Australian Privacy Principle 8 for applicable overseas disclosures, subject to statutory exceptions. This can include reasonable steps intended to ensure an overseas recipient handles personal information consistently with applicable Australian privacy obligations.
52. Security
We use reasonable technical and organisational measures intended to protect information, including authentication, role and permission controls, database security policies, restricted service access, encryption in transit, provider encryption at rest where supported, protected credentials, audit records, server-side authorisation, payment-provider security, abuse controls, backups and software updates. No online system can guarantee absolute security.
53. Data minimisation
Our privacy-by-design measures include avoiding raw IP storage in ordinary Action Page analytics, anonymising customer questions before they are shown in business analytics, separating Partner attribution from management permissions, limiting Partner access, using server-side validated analytics ingestion and preferring aggregate reporting where appropriate.
54. Accuracy
Businesses can review, edit, approve and update business information. Public-source information may be inaccurate or outdated, so owners should verify material information. Individuals may contact us to request correction of personal information where applicable.
55. Retention principle
We retain personal information only for as long as reasonably necessary for the relevant purpose and legitimate legal, accounting, security, fraud-prevention, dispute and operational needs. Retention periods differ by information type and applicable law.
56. Account and business retention
Account information may be retained while active and for a reasonable period after closure for deletion processing, dispute handling, security, fraud prevention and legal obligations. Business information may remain while a listing is active and may temporarily remain in backups or audit records after deletion.
57. Billing and tax retention
Billing, transaction, commission and tax records may be kept for periods required by applicable accounting, corporate and tax law. Some Australian business records commonly require multi-year retention.
58. AI and analytics retention
AI Visibility scans may be retained to provide history and comparison. Privacy-minimised Action Page analytics may be retained to provide historical reporting and improve Services. Aggregated or irreversibly de-identified information may be retained longer because it no longer identifies an individual.
59. Deletion
Where applicable law gives you a deletion right, you may request deletion. Exceptions may apply for legal compliance, tax, accounting, fraud prevention, security, legal claims or other lawful retention. Deletion from id.tel cannot guarantee removal of copies previously cached by independent third parties.
60. Backups
Deleted information may remain for a limited period in protected backups used for resilience and disaster recovery and should age out through applicable backup cycles unless legal preservation is required.
61. Security incidents
We assess suspected personal-information security incidents under applicable law. Where legally required, we will notify affected people and relevant regulators within applicable timeframes.
62. Business Customer responsibilities
If a business receives an enquiry or contact detail through id.tel and then exports or uses it in its own CRM, email platform, booking system, marketing list or sales process, the business is responsible for the privacy and marketing law governing its independent processing.
63. Partner responsibilities
Partners who receive personal information through id.tel must use it only for authorised purposes, protect it appropriately and comply with applicable privacy law and the Partner Agreement.
64. Children
Business and Partner accounts are intended for adults who can legally enter commercial arrangements. id.tel is not designed to knowingly solicit children's information for profiling or behavioural advertising. Parents or guardians may contact us about concerns involving a child's personal information.
65. General privacy rights
Depending on applicable law, you may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, direct-marketing opt-out, information about processing or transfers, rights concerning certain automated decisions, and complaint to a regulator.
66. Exercising rights
Send privacy requests to support@id.tel and describe the information or account concerned and the right you wish to exercise. We may request information reasonably necessary to verify identity and will respond within applicable legal timeframes.
67. Authorised representatives
Where permitted by law, an authorised representative may make a privacy request on another person's behalf. We may request reasonable evidence of the representative's identity and authority.
68. Australia
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, individuals may have rights relating to transparent practices, access, correction, direct marketing, security, use and disclosure, cross-border disclosure and complaints. If you are dissatisfied after contacting us, you may have a right to complain to the Office of the Australian Information Commissioner.
69. Australian automated-decision transparency
From 10 December 2026, additional Australian Privacy Policy transparency obligations apply in specified circumstances where a computer program uses personal information in decisions that could reasonably be expected to significantly affect an individual's rights or interests. IDTEL will apply these requirements to relevant future functionality where they are triggered.
70. European Economic Area
Where the GDPR applies, rights may include information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent and safeguards relating to certain automated decisions. You may also complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred.
71. EEA transfers
Because IDTEL is located in Australia, EEA personal data may be transferred outside the EEA. Where required, we use an appropriate transfer mechanism such as an adequacy decision, Standard Contractual Clauses or another recognised safeguard. If Article 27 or another rule requires an EU representative as our activities expand, we will publish that representative's details.
72. United Kingdom
Where the UK GDPR and Data Protection Act 2018 apply, individuals may have rights including access, correction, erasure, restriction, portability, objection, withdrawal of consent, certain automated-decision rights and complaint rights. Restricted international transfers will use an applicable UK mechanism where required. If a UK representative becomes legally required, we will publish the details.
73. California and United States
Where California or another applicable US state privacy law applies to IDTEL, residents may have rights to know or access information, correct inaccuracies, request deletion, obtain portability, opt out of certain sale, sharing or targeted advertising, limit certain uses of sensitive information, appeal some decisions and receive non-discriminatory treatment for exercising privacy rights.
74. California sale and sharing
IDTEL does not currently sell personal information for money and does not currently share personal information for cross-context behavioural advertising as those concepts are defined by the California Consumer Privacy Act. Use of service providers to operate id.tel is not intended to constitute a sale merely because a provider processes information for us.
75. New Zealand
Where the New Zealand Privacy Act 2020 applies, individuals may have rights including access and correction. From May 2026, Information Privacy Principle 3A imposes notice obligations for certain personal information collected indirectly, subject to statutory exceptions. This is relevant to public business research, and IDTEL will apply the required notice or an available lawful exception according to the circumstances.
76. New Zealand overseas disclosures
Where New Zealand Information Privacy Principle 12 applies, we will use the legally required basis or safeguards for applicable overseas disclosures. Individuals may also have complaint rights through the Office of the Privacy Commissioner of New Zealand.
77. South Africa
Where the Protection of Personal Information Act 4 of 2013 (POPIA) applies, IDTEL may act as a Responsible Party or Operator depending on context. Data subjects may have rights relating to access, correction, deletion, objections, direct marketing and complaints. International transfers and security-compromise notifications will be handled according to applicable POPIA requirements.
78. Other countries
Where mandatory privacy law in another country applies, we will comply with applicable obligations to the extent required and may introduce additional regional notices as id.tel expands.
79. Corporate transactions
If IDTEL or the id.tel business is involved in an investment, financing, merger, acquisition, restructuring, sale of shares or assets, personal information may be disclosed to advisers, counterparties and successors where reasonably necessary and legally permitted. A successor remains subject to applicable privacy law.
80. Legal requests
We may preserve, access or disclose information where reasonably necessary to comply with law or valid legal process, investigate fraud, protect safety, enforce agreements, protect rights or systems, respond to security incidents or establish, exercise or defend legal claims. Where lawful and appropriate, we may challenge requests we reasonably believe are invalid or excessive.
81. Anonymised information
We may use information that has been irreversibly anonymised or aggregated for product development, statistics, benchmarking, research, platform planning, security and understanding search or AI trends. We do not intentionally attempt to re-identify irreversibly anonymised data except where lawfully necessary for security validation.
82. Changes to this Policy
We may update this Policy for new features, providers, laws, jurisdictions, AI functionality, security improvements or changes in information practices. If a change materially affects how we use personal information, we will provide additional notice where required. We may retain prior versions for audit and compliance purposes.
83. Complaints
Send privacy questions or complaints to support@id.tel. Please include enough information for us to investigate. We will seek to respond within a reasonable period and within any legally required timeframe. You remain free to use regulatory or judicial remedies available under applicable law.
84. Controller contact
Principal platform operator: IDTEL GROUP PTY LTD, ABN 69 693 776 966, Queensland, Australia. Email: support@id.tel. We intentionally do not publish a private residential address as the public contact address.