Legal Document

Privacy Policy

Effective Date: 20 June 2026Company: A1 RETAIL AI (trading as RetailAI) (ABN 41 661 675 207)
RetailAI is committed to protecting your privacy. This Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights in relation to it. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and where applicable, the EU General Data Protection Regulation (GDPR).

1. Overview

A1 RETAIL AI (trading as RetailAI)(“RetailAI”, “we”, “us”, or “our”) operates the RetailAI platform, accessible at retailai.com.au, which provides AI-powered retail operations software as a service (“Services”).

This Privacy Policy applies to all personal information collected by RetailAI through our website, platform, APIs, and any associated applications. It covers information about our customers (“Users”), their employees and end-users, visitors to our website, and any individuals whose data is processed through our Services.

RetailAI acts as a data controller for information collected about Users for account management and service improvement purposes. RetailAI acts as a data processor for personal data that Users upload or input into the platform in the course of using the Services.

2. Information We Collect

Information you provide directly:

  • Account information: name, email address, password, company name, job title, and phone number when you register
  • Billing information: payment card details (processed by Stripe — we do not store card numbers), billing address, and invoice preferences
  • Profile information: profile photo, user preferences, and any information you add to your profile
  • Communication: messages you send to our support team, responses to surveys, and feedback you provide
  • Customer Data: product information, inventory data, order data, customer records, and any other data you upload or create within the platform

Information collected automatically:

  • Usage data: features used, pages visited, actions taken within the platform, session duration, and error logs
  • Device information: IP address, browser type and version, operating system, screen resolution, and device identifiers
  • Log data: access timestamps, API requests, and system events for security and debugging purposes
  • Cookies and similar technologies: session cookies, authentication tokens, and analytics identifiers (see Section 9)

Information from third parties:

  • OAuth providers: when you sign in with Google, Facebook, or Microsoft, we receive your name, email address, and profile photo from those providers
  • Enterprise SSO/SAML: your identity provider may send us your name, email, and group memberships for role assignment
  • Payment processors: Stripe provides us with transaction confirmation and anonymised fraud risk signals

3. How We Use Your Information

We use personal information for the following purposes:

  • Providing and improving the Services: creating and managing your account, processing transactions, delivering features you use, and improving platform performance
  • Authentication and security: verifying your identity, detecting and preventing fraud, monitoring for unauthorised access, and enforcing our policies
  • Communications: sending service notifications, product updates, billing receipts, security alerts, and (with your consent) marketing communications
  • Customer support: responding to enquiries, troubleshooting issues, and providing technical assistance
  • Analytics and research: understanding how users interact with the platform in aggregated, anonymised form to improve our features and user experience
  • Legal compliance: complying with applicable laws, regulations, legal process, and government requests
  • Business operations: invoicing, accounting, and internal administration

Legal bases (GDPR): For users in the EU and UK, we process personal data on the following legal bases: (a) performance of our contract with you; (b) compliance with legal obligations; (c) our legitimate interests in operating and improving our business, provided these interests are not overridden by your rights; and (d) your consent where required.

4. Sharing and Disclosure

We do not sell your personal information. We share personal information only in the following circumstances:

  • Service providers: we engage trusted third-party processors to help deliver the Services, including Supabase (database and authentication), Stripe (payment processing), Google Cloud Platform (infrastructure, storage, and hosting), and OpenAI and Anthropic (AI features, including the AI agents). These processors are contractually bound to use your data only to provide services to us.
  • Your organisation: if you access the Services as part of a company account, your account administrator may have access to your usage information and content
  • Legal requirements: we may disclose information if required by law, court order, or to protect the rights, property, or safety of RetailAI, our users, or the public
  • Business transfers: if RetailAI is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is subject to a different Privacy Policy
  • With your consent: in any other case, we will share your information only with your explicit consent

5. International Data Transfers

RetailAI is based in Australia. Some of our service providers are located in other countries, including the United States and the European Union. When we transfer personal data outside Australia or the EU, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Processing only by providers certified under recognised frameworks such as the EU-US Data Privacy Framework
  • Binding corporate rules or other adequacy mechanisms recognised under Australian and GDPR law

By using the Services, you acknowledge that your information may be transferred to and processed in countries other than your country of residence. We take all reasonable steps to ensure your data receives an equivalent level of protection wherever it is processed.

6. Data Retention

We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically:

  • Account data: retained for the duration of your subscription plus 90 days following termination
  • Customer Data (platform content): retained for the duration of your subscription plus 90 days, after which it is deleted or anonymised
  • Billing records: retained for 7 years as required by Australian tax law
  • Security and audit logs: retained for up to 12 months
  • Communication records: retained for 3 years from the date of last interaction

You may request earlier deletion of your data by contacting us at privacy@retailai.com.au, subject to our legal obligations to retain certain records.

7. Security

We implement comprehensive technical and organisational security measures to protect your personal information against unauthorised access, disclosure, alteration, or destruction, including:

  • Encryption of all data in transit using TLS 1.2 or higher
  • Encryption of data at rest using AES-256
  • Role-based access control (RBAC) and Row Level Security (RLS) at the database level
  • Multi-factor authentication options for all accounts
  • Regular security assessments and vulnerability testing
  • Employee security training and access controls on a need-to-know basis
  • Incident response procedures for data breaches

In the event of a data breach that is likely to result in harm to individuals, we will notify affected users and relevant authorities (including the Office of the Australian Information Commissioner, where required) within the timeframes mandated by law.

8. Your Rights

Depending on your location, you may have the following rights with respect to your personal information:

  • Access: the right to request a copy of the personal information we hold about you
  • Correction: the right to request correction of inaccurate or incomplete information
  • Deletion: the right to request deletion of your personal information (“right to be forgotten”), subject to legal retention obligations
  • Portability: the right to receive your personal information in a structured, machine-readable format (EU/UK users)
  • Objection: the right to object to processing based on our legitimate interests
  • Restriction: the right to request restriction of processing in certain circumstances
  • Withdraw consent: the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal
  • Complaints: the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or, for EU/UK residents, your local supervisory authority

To exercise any of these rights, please contact us at privacy@retailai.com.au. We will respond within 30 days (or within 30 calendar days as required by GDPR). We may need to verify your identity before processing your request.

9. Cookies and Tracking Technologies

We use cookies and similar technologies for the following purposes:

  • Essential cookies: required for authentication, session management, and platform security. These cannot be disabled without affecting functionality.
  • Security cookies: Cloudflare Turnstile for bot protection on authentication flows

We do not use advertising or tracking cookies. You can control non-essential cookies through your browser settings. Blocking essential cookies will prevent you from using the Services.

10. AI Features and Your Data

RetailAI uses third-party AI providers (currently OpenAI and Anthropic) to power features such as product description generation, the AI shopping assistant, and the AI agents. When you use these features:

  • Product images, text, and relevant operational data you submit are sent to the AI provider for processing
  • We do not use your Customer Data to train AI models — data is processed only to generate the immediate output you requested
  • AI providers are contractually bound by data processing agreements that prohibit use of your data for model training without explicit consent
  • AI-generated outputs may be imperfect or inaccurate — you are responsible for reviewing all AI-generated content before use

AI agents and automated decision-making. Where you enable AI agents, they process your Customer Data to take or recommend actions you have configured (for example, drafting purchase orders, adjusting inventory, or evaluating returns). These features are designed to operate with human oversight that you control, and you remain responsible for reviewing their actions (see our Terms of Service). To the extent any processing involves automated decision-making within the meaning of the GDPR, you may contact us to exercise applicable rights, including the right to obtain human review.

We take steps to minimise data sent to AI providers, including stripping personally identifiable information where possible before transmission.

11. Children's Privacy

The Services are not directed to children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided personal information to us, please contact us immediately at privacy@retailai.com.au and we will take steps to delete that information.

12. Third-Party Links and Integrations

The Services may contain links to third-party websites (such as GamesOn365) or integrate with third-party services (such as Stripe, Google, Facebook). This Privacy Policy does not apply to those third-party sites and services. We encourage you to review the privacy policies of any third-party services you use in connection with RetailAI.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email or by posting a prominent notice in your account dashboard at least 14 days before the changes take effect.

We encourage you to review this Policy periodically. The date at the top of this page indicates when the Policy was last updated. Your continued use of the Services after the effective date of any changes constitutes acceptance of the updated Policy.

14. Contact and Complaints

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our Privacy Officer:

Privacy Officer — A1 RETAIL AI (trading as RetailAI)

Glen Waverley, VIC 3150, Australia

Email: privacy@retailai.com.au

If you are not satisfied with our response, you have the right to lodge a complaint with:

  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • EU/UK: Your local data protection supervisory authority

Last updated: 20 June 2026. Document version: 1.1