Privacy Policy
Last updated: April 2026
1. Introduction
SecureMatch is operated by Robert Rees, trading as SecureMatch (ABN 26 238 581 386) ("we", "us", "our"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform, and is designed to align with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy describes how we collect and handle your information and serves as our collection notice under APP 5. We collect personal information for the purposes set out in Section 3, and where the law requires your consent (for example, optional or sensitive information), we ask for it specifically rather than relying on your general use of the platform.
If you do not agree with this policy, please do not use our services. You can contact us about this policy at any time via our contact form.
2. Information We Collect
2.1 For Job Seekers (Candidates)
We collect the following personal information:
- Account Information: Email address, password (encrypted)
- Profile Information: First name, last name, phone number, location (state/territory)
- Professional Information: Job category, skills, licences/certifications, years of experience, work availability, current employer (optional)
- Documents: Resume/CV, Unique Student Identifier (USI) number (optional)
- Premium Content: Profile photo, video introduction, work portfolio images (if applicable)
- Usage Data: Profile views, connection requests, messaging activity
2.2 For Businesses
We collect the following business information:
- Account Information: Email address, password (encrypted)
- Business Information: Company name, ABN/ACN, industry, company size, location
- Contact Information: Business contact name, business phone number
- Optional Content: Company logo, company description
- Usage Data: Candidate searches, connection requests, messaging activity
2.3 Automatically Collected Information
- IP address and device information
- Browser type and version
- Pages visited and time spent on the platform
- Referring website addresses
3. How We Use Your Information
We use your personal information for the following purposes:
- Platform Services: To facilitate connections between job seekers and employers
- Account Management: To create and manage your account, verify your identity
- Communication: To send connection requests, messages, and platform notifications
- Service Improvement: To analyse usage patterns and improve our platform
- Security: To detect and prevent fraud, abuse, and security incidents
- Legal Compliance: To comply with applicable laws and regulations
- Premium Features: To provide analytics and insights to premium subscribers
4. Privacy Protection Model
SecureMatch operates on a privacy-first model designed to protect job seekers:
4.1 Two-Layer Profile System
Public Profile (Visible to All Employers)
- Professional headline (e.g., "Licensed Electrician")
- Job category and skills
- Years of experience
- Location (state only, not specific address)
- Availability status
- Licences and certifications held
- Profile photo (if uploaded)
- Video introduction (premium, if uploaded)
- Work portfolio (premium, if uploaded)
Private Profile (Only After Connection Accepted)
- Full name (first and last name)
- Contact email address
- Phone number
- Resume/CV document
- USI number (if provided)
- Current employer details
4.2 Connection Consent
Your private information is never shared with an employer unless you explicitly accept their connection request. You have full control over who can see your personal details.
5. Information Sharing and Disclosure
We may share your information in the following circumstances:
5.1 With Employers (Candidates Only)
- Before Connection: Only public profile information as described above
- After Connection Accepted: Full profile including private information
5.2 Service Providers (Sub-processors)
We use the trusted third-party service providers ("sub-processors") listed below to operate the platform. They are bound by their own data-protection terms and may only use your data to perform services on our behalf. We keep this list current; if we add or change a sub-processor that handles personal information, we will update this policy.
| Provider | Purpose | Data region |
|---|---|---|
| Google Cloud / Firebase | Database, file storage, authentication, server functions, hosting, push notifications | Australia (Sydney) for database, functions & storage; some auth/push services may operate in other regions (see §10) |
| Resend | Transactional email delivery | United States |
| Australian Business Register (ABR) API | ABN verification for employers | Australia |
| Sentry | Error monitoring (configured not to capture personal information) | United States |
| Stripe | Payment processing for paid subscriptions (not yet active during early access) | United States / global |
Where a sub-processor operates outside Australia, we take reasonable steps to ensure your information is handled consistently with the Australian Privacy Principles (see §10).
5.3 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, privacy, safety, or property.
6. Data Security
We implement appropriate security measures including:
- Encryption of data in transit and at rest
- Secure password hashing (via Firebase Authentication)
- Firebase Security Rules for database access control
- Server-side checks before private data is released, and time-limited links for documents such as resumes
- Access controls limiting access to personal data
While we take reasonable precautions, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.
7. Data Breaches
We have an incident-response process for handling data breaches and comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth).
If we become aware of a data breach that is likely to result in serious harm to affected individuals, we will assess it promptly and, where it is an eligible data breach, notify both the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable. Our notification will describe the breach, the kinds of information involved, and the steps you can take in response.
We monitor our systems for security incidents and maintain an internal breach runbook so we can detect, contain, assess, and report a breach within the timeframes the law requires.
8. Data Retention
We retain your personal information:
- Active Accounts: For as long as your account remains active
- Deleted Accounts: When you delete your account, we remove your profile, uploaded files (including your resume), and the messages you sent
- Messages you received: Messages other users sent to you remain in their own conversation history, as they are also a record of that other person's communication
- Connection Records: For the duration of the connection plus 12 months
- Analytics Data: Aggregated and anonymised data may be retained indefinitely
9. Your Rights Under the Privacy Act
Under the Australian Privacy Principles, you have the right to:
- Access: Request a copy of your personal information we hold
- Correction: Request correction of inaccurate or outdated information
- Deletion: Request deletion of your account and associated data
- Withdraw Consent: Withdraw consent for optional data collection
- Complaint: Lodge a complaint if you believe we have breached your privacy
To exercise these rights, contact us via our contact form or through your account settings. We will respond within a reasonable period, and within 30 days where practicable.
10. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and remember your preferences
- Analyse platform usage and performance
- Improve our services based on user behaviour
You can control cookies through your browser settings. Disabling cookies may affect platform functionality.
11. Data Location and International Transfers
SecureMatch runs on Google Cloud (Firebase) infrastructure. Your profile database is hosted in Google Cloud's Australian region (Sydney, australia-southeast1), and our server functions run in Australia.
Some underlying Google services that support the platform (for example, authentication, push notifications, and file storage) may operate in other regions, so some information may be processed or stored outside Australia. Where that occurs, we take reasonable steps to ensure it is handled in a way consistent with the Australian Privacy Principles, and we remain accountable for that information under APP 8. Google Cloud's infrastructure holds ISO 27001 and SOC 2 certification.
12. Children's Privacy
SecureMatch is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on our platform. Your continued use of SecureMatch after such changes constitutes acceptance of the updated policy.
14. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us at:
Privacy Officer
SecureMatch (Robert Rees, ABN 26 238 581 386)
Contact: securematch.co/contact
We will respond to your complaint within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
15. Contact Us
For questions about this Privacy Policy or our privacy practices, please contact us at:
SecureMatch (Robert Rees, ABN 26 238 581 386)
Website: www.securematch.co
Contact: securematch.co/contact