Privacy Policy
Last updated: July 2026
This document is provided for information and does not constitute legal advice.
1. About this policy
This Privacy Policy explains how Anthony Phillip Carle trading as MDMS ("MDMS", "we", "us", "our"), based in Queensland, Australia, handles personal information in connection with the Modern Dealer Management System website and software-as-a-service platform (the "Service").
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle health, tax file number, or other sensitive information on behalf of a customer, we do so only as permitted by law and by our agreement with that customer.
2. Information we collect
- Account information — name, business name, email, phone, role, and authentication identifiers.
- Customer Data — records you upload into the Service (customers, equipment, parts, invoices, quotes, work orders, etc.). You control this data; we process it on your behalf.
- Billing information — ABN, billing address, plan, invoices. Card details are handled by our payment processor and not stored by us.
- Technical and usage data — IP address, device and browser data, log files, pages visited, feature usage.
- Diagnostic error logs — automatic technical records of faults you encounter in the Service, scrubbed of contact and financial identifiers before storage. See section 7.
- Trial usage monitoring — during a free trial only, additional records of pages visited and data exports/downloads, each with IP address and device, used to prevent trial abuse. See section 8.
- Communications — support tickets, sales enquiries, survey responses.
- Cookies and similar technologies — see our Cookie Policy.
3. How we collect it
We collect information directly from you when you sign up, use the Service, or contact us; automatically through your use of the Service; and occasionally from third parties such as identity providers, referrers, or publicly available sources.
4. Why we use it (APP 6)
- Provide, maintain and improve the Service.
- Authenticate users and secure accounts.
- Process billing and manage subscriptions.
- Provide support and respond to enquiries.
- Send service notices and, with consent, product updates and marketing.
- Detect and prevent fraud, misuse and security incidents.
- Comply with legal obligations and enforce our terms.
5. Disclosure to third parties (APP 6 & APP 8)
We disclose personal information to trusted sub-processors who help us run the Service, including cloud hosting, database, email delivery, analytics and customer-support providers. We require them to handle information consistently with this policy.
We use Paddle.com Market Limited ("Paddle") as our Merchant of Record to process payments, manage subscriptions, calculate and remit sales taxes, and issue invoices. When you make a purchase, billing and payment information you provide at checkout is collected and processed by Paddle as an independent data controller in accordance with Paddle's Privacy Notice. We do not store full payment card details.
Some of these providers operate, or process data, outside Australia (for example in the United States or the European Union). By using the Service you acknowledge that your information may be transferred to and processed in those jurisdictions. We take reasonable steps to ensure overseas recipients handle personal information in a way consistent with the APPs.
We may also disclose information where required or authorised by law, including to law enforcement, regulators, courts or in connection with a sale or restructure of our business.
6. Data security
We use industry-standard safeguards including encryption in transit (TLS) and at rest, role-based access controls, audit logging, network segregation, multi-factor authentication for staff, and regular vulnerability scanning. No system is completely secure, and we cannot guarantee absolute security.
7. Diagnostic error logs
When something goes wrong while you are using the Service, we automatically record a technical description of the fault so that we can find and fix it. This is the only purpose for which these records exist.
Identifiers are stripped before the record is stored. Error text is automatically scrubbed — on your device before it is sent to us, and again on our servers before it is written — to remove email addresses, phone numbers, payment card numbers, ABNs, TFNs, street addresses and authentication tokens. These are replaced with placeholders such as [email] and are never stored.
Each record is linked to the user account and business it came from, and keeps technical context such as the screen, the error code and the software build. We need that link to know who is affected and to tell you when a fault is fixed — so these records are treated as personal information under this policy, not as anonymous data.
Because some error messages are written by hand by our software, we cannot promise that an incidental reference to a person is never captured in the text of an error. We do not rely on scrubbing alone: access to these records is restricted to authorised MDMS personnel, and they are never readable from within your account or by any other customer.
We never sell these records and never share them externally. They are not visible to any other customer, are never used for advertising, marketing, profiling, or to train third-party services, and are not sent to any analytics or error-reporting provider. The only parties that hold them are MDMS and the infrastructure providers that host the Service on our behalf (section 5), and the only other circumstance in which we would disclose them is where we are required to by law. They are used solely by MDMS to diagnose faults and improve the Service for the people who use it, and they do not give us a route into your Customer Data.
Diagnostic error records are automatically and permanently deleted 90 days after the error last occurred.
8. Trial usage monitoring
During a free trial, and only during a free trial, we automatically record how the trial account uses the Service — the pages visited, and actions that take data out of the Service such as exports, downloads, generated PDFs, printed labels and opened documents. The purpose is security and the prevention of trial abuse: for example, an account created to systematically copy the Service or to bulk-export data.
Each record includes the IP address and device/browser (user-agent) the action came from, together with the user account and business, the action, and the time. We keep the IP address in full because it is the signal that lets us recognise automated scraping and multiple trial accounts operated from one source.
This monitoring applies only while an account is on a free trial (including an expired trial that has not subscribed). When you subscribe to a paid plan it stops, and we do not apply it to paying customers' everyday use of the Service.
These records are restricted to authorised MDMS personnel and are never readable from within your account or by any other customer. We never sell them, never share them externally, and never use them for advertising, marketing, profiling, or to train third-party services. The only parties that hold them are MDMS and the infrastructure providers that host the Service on our behalf (section 5). Because each record is linked to the user and business it came from, we treat it as personal information under this policy.
Trial usage records are automatically and permanently deleted 90 days after they are created, and are deleted sooner if the trial's data is deleted (section 9).
9. Data retention
We retain Customer Data while your account is active and for a reasonable period afterwards to allow data export and to meet our legal, accounting and tax obligations. After that period we securely delete or de-identify the information unless we are required to retain it by law. Diagnostic error records are deleted on the 90-day cycle described in section 7.
Free trials that are not converted to a paid subscription: if your trial ends and you do not subscribe, we keep the data from your trial for 60 days after the trial end date, then permanently delete it along with the associated user accounts. We tell you the exact deletion date when your trial ends, and remind you again roughly 14 days and 3 days beforehand. Subscribing at any point before that date keeps your data intact. If you would like a copy of your trial data before it is deleted, contact us at customersupport@moderndms.com.au and we will provide it. This 60-day rule applies only to trials that never became paid subscriptions.
10. Your rights (APPs 12 & 13)
You may request access to, or correction of, personal information we hold about you by contacting privacy@moderndms.com.au. We will respond within a reasonable time (generally within 30 days) and will not charge for reasonable requests.
11. Direct marketing and the Spam Act
Where we send marketing communications we comply with the Spam Act 2003 (Cth). Every commercial email includes an unsubscribe link, and you can opt out at any time by using it or by contacting us.
12. Notifiable Data Breaches scheme
If we suffer a data breach that is likely to result in serious harm to an individual whose personal information is involved, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required by Part IIIC of the Privacy Act.
13. Cookies and analytics
We use a small number of essential and analytics cookies. See our Cookie Policy for details.
14. Children
The Service is intended for business users aged 18 and over. We do not knowingly collect personal information from children.
15. Changes to this policy
We may update this policy from time to time. Material changes will be notified through the Service or by email. The "Last updated" date above always reflects the current version.
16. Complaints and contact
If you have a privacy concern, contact us first at privacy@moderndms.com.au and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Anthony Phillip Carle trading as MDMS
Queensland, Australia
privacy@moderndms.com.au