Privacy Policy
Last updated: [launch date]
This Privacy Policy explains how JES WEB PTY LTD (ABN 38 667 034 148) ("we", "us", "our") handles personal information in connection with Operanse (the "Service"). We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, the EU/UK GDPR.
1. Our privacy-first design
Operanse is built to hold as little personal information as possible. The agent you install on your site sends operational telemetry — counts, statuses, amounts, currencies, durations, software names and versions, hook names, error classes — and never the personal information of your visitors or customers.
Specifically, the agent does not collect names, email addresses, postal addresses, phone numbers, IP addresses of visitors, cookies, session contents, request headers, URLs with query strings, referrers, form field contents, card data or raw checkout bodies. Free-text fields that could carry such data by accident (for example an error message) are redacted on your site before they are sent, and redacted again when received. The agent never reads your wp-config.php, environment files, keys or certificates. The agent is read-only: it has no capability to change anything on your site.
2. Information we collect
- Account information: name, email address and password hash, and the organisations you belong to.
- Site inventory: the WordPress, PHP and database versions, installed plugins and themes and their versions, WooCommerce configuration such as enabled payment gateways (by identifier, never credentials), scheduled tasks, REST routes and, where you enable structural analysis, structural facts about custom code. Source code is not stored; where you opt in to deep analysis, redacted excerpts are sent to our AI provider and summaries are kept rather than source.
- Site telemetry: order, subscription, payment and renewal events by identifier, status, amount and currency; scheduled-task and background-job counts; the hosts your site makes outbound HTTP calls to (host name, outcome class and timing, never the path, query, headers or body); form submission counts by form; sampled request timings; PHP error classes with redacted messages. Order and subscription identifiers are operational identifiers and are treated as your confidential information.
- Host resources: load average, CPU, memory and disk usage of the server or container your site runs on, database server status counters (connection and thread counts, slow-query and lock-wait counts, uptime; never query text), PHP opcache statistics, and counts of entries in your site's PHP error log by level. Up to three sample log messages per level are kept per reading, each redacted and truncated, with file paths reduced to a file name. On shared hosting these figures describe the shared machine, and each reading records this.
- Uptime probes: the response code and timing of requests our servers make to your site's public address.
- Billing information: processed by Stripe. We receive limited billing metadata (plan, status, the last four digits of your billing card); we do not receive your full payment card number.
- Usage and device data: log data, IP address, browser type and similar technical information about your use of the dashboard and API.
3. How we use information
We use personal information to provide and operate the Service, authenticate you, learn your sites' normal behaviour and detect deviations, send the alerts you configure, process payments, provide support, maintain security, comply with legal obligations and improve the Service. Where we rely on consent, you may withdraw it at any time.
4. AI processing
On plans that include AI review, labelled, redacted evidence about an incident on your site (the telemetry and inventory described above, never shopper personal information) is sent to our AI provider, Anthropic, to produce a review. Our agreement with the provider does not permit the use of your data to train models. Every review is recorded with the evidence it cited and is never presented as an observed fact. You can interrogate your own data with an AI client of your choice through our MCP server; what that client does with the answers is governed by its provider's terms.
5. Disclosure
We disclose personal information to service providers who help us run the Service (see our Sub-processors list), including hosting, database, email, AI and payment providers. We may disclose information if required by law or to protect our rights and users. We do not sell your personal information.
6. Overseas disclosure
Our servers are located in the United States, and some of our service providers may store or process data outside Australia. Where we disclose information overseas, we take reasonable steps to ensure it is handled consistently with the APPs.
7. Security
We use technical and organisational measures to protect personal information, including encryption in transit (TLS), signed requests between the agent and the Service, encryption of site credentials at rest, and row-level access controls scoped to your organisation and enforced in the database. Our minimal-data design means a breach would not expose your customers' personal information. No method of transmission or storage is completely secure, however.
8. Retention
Raw telemetry events are retained for 30 or 90 days depending on your plan; aggregated metrics are retained to provide baselines and history; incident evidence is retained with the incident. Account information is retained for as long as your account is active or as needed to provide the Service, and thereafter as required for legal, accounting or security purposes. You can request deletion as described below.
9. Your rights
Subject to applicable law, you may access, correct or request deletion of your personal information, and may object to or restrict certain processing. To exercise these rights, contact privacy@operanse.com. If you are in the EU/UK, you have rights under the GDPR, including the right to lodge a complaint with a supervisory authority.
10. Cookies
We use cookies and similar technologies as described in our Cookie Policy.
11. Children
The Service is not directed to children under 18 and we do not knowingly collect their personal information.
12. Changes
We may update this Policy from time to time and will post the updated version with a new "Last updated" date.
13. Contact and complaints
For privacy questions or complaints, contact privacy@operanse.com or write to JES WEB PTY LTD (ABN 38 667 034 148), 1/26 Ellingworth Parade, Box Hill VIC 3128, Australia. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).