Legal
Privacy Policy
This policy explains how Jumi Solutions Pty Ltd handles personal information when you use SaaSMetricsHQ.
Last updated: 3 August 2026
Who we are
SaaSMetricsHQ is operated by Jumi Solutions Pty Ltd (ABN 11 691 132 715), based in Victoria, Australia. In this policy, “we”, “us”, and “our” refer to Jumi Solutions Pty Ltd. We manage personal information in accordance with applicable Australian privacy law, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
Information we collect
Depending on how you use the service, we may collect and hold:
- account and profile details, including your name, email address, organisation, role, timezone, and avatar;
- authentication, session, security, support, and audit information, including IP address and browser details;
- billing details and subscription status (payment card details are handled by Stripe and are not stored by us);
- communications, support requests, notification preferences, and email-delivery records;
- Shopify Partner information you authorise us to retrieve, including app details, transactions, app events, subscriptions, installations, and related reporting data; and
- technical logs, usage events, queue and integration status, and diagnostic information.
We do not intentionally collect sensitive information. Please do not send passwords, access tokens, payment-card details, or other secrets through support channels.
How we collect information
We collect information directly from you when you create or manage an account, contact support, configure an integration, or use the service. We also receive information from people who invite you to a workspace, from Shopify when you connect a Partner account, and from the service providers described below.
Why we use information
We use personal information to:
- provide, secure, maintain, and improve SaaSMetricsHQ;
- authenticate users and administer organisations, integrations, reporting, notifications, and billing;
- respond to support requests and send service, security, billing, and product communications;
- detect abuse, investigate faults, maintain audit records, and comply with legal obligations; and
- create aggregated or de-identified analysis that does not identify an individual.
Service providers and disclosures
We disclose information only as reasonably required to operate the service, with your direction or consent, or where required by law. Our current service providers and integration partners include:
- DigitalOcean for application and managed database hosting in an Australian region;
- Shopify for the Partner API data that you authorise SaaSMetricsHQ to access;
- Stripe for subscription billing, payment processing, and billing-event reconciliation;
- Amazon Web Services (Amazon SES) for transactional and digest email delivery;
- Google when you choose Google OAuth for account authentication;
- BoldDesk (Syncfusion) for customer support, live chat, and support contact management; and
- Loops for lifecycle email and contact management when that integration is enabled.
These providers process information under their own terms and privacy policies. We may also disclose information to professional advisers, regulators, law enforcement, or a successor in connection with a business transaction, where legally permitted.
Storage and overseas processing
Our primary SaaSMetricsHQ application and database infrastructure is hosted by DigitalOcean in Australia. Some service providers listed above are global businesses and may process or support information outside Australia, including in the United States and other countries where they or their subprocessors operate. Those countries may have different privacy laws. Where Australian Privacy Principle 8 applies, we take reasonable steps appropriate to the circumstances before disclosing personal information overseas.
Cookies and authentication
SaaSMetricsHQ uses essential cookies for login sessions, account security, admin authentication, and impersonation safeguards. We do not currently use third-party advertising cookies. Google may set or receive cookies if you choose Google authentication, and an enabled support widget may use the storage required to provide chat.
Security and retention
We use reasonable technical and organisational safeguards. Integration credentials are encrypted at rest, access is restricted, and session cookies are HTTP-only and validated server-side. No internet service can guarantee absolute security.
We retain information for as long as needed to provide the service, meet legal and accounting obligations, resolve disputes, and protect the service. Retention periods vary by record type. We delete or de-identify information when it is no longer reasonably required, subject to backups and legal requirements.
Access, correction, and complaints
You may request access to or correction of personal information we hold about you, or make a privacy complaint, by emailing [email protected]. We may need to verify your identity. We will respond within a reasonable period and explain any lawful reason we cannot fulfil a request.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
Changes and contact
We may update this policy as our practices or legal obligations change. We will publish the revised version here and update the date above. Contact Jumi Solutions Pty Ltd at [email protected], or visit jumisolutions.com.