Privacy Policy
Last updated: March 2026 Jurisdiction: South Australia, Australia
PostMyDoc (ABN: 22 813 598 932) (“we,” “us,” “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard your personal information when you use the PostMyDoc website (postmydoc.au) and the PostMyDoc mobile application (“the App”), collectively referred to as “the Service.”
This Privacy Policy is written in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using the Service you consent to the collection and use of your information as described in this Privacy Policy.
1. Who We Are
PostMyDoc ABN: 22 813 598 932
PostMyDoc provides a digital-to-physical document mailing service. Customers upload a PDF document via the PostMyDoc website or mobile app. PostMyDoc prints the document and posts it via Australia Post to a nominated recipient address.
2. Information We Collect
2.1 Information you provide directly
When you use the Service we collect the following information:
Sender information:
- Your name or company name
- Your email address — used for order confirmation and service communications
Recipient information:
- Recipient name or company name
- Recipient physical delivery address — street address, suburb, state, postcode and country
Document content:
- The PDF file you upload for printing and posting
- The page count of your document
Order information:
- Print type selected (Black and White or Colour)
- Postage service selected
- Order value and payment confirmation
Communications:
- Any messages you send to PostMyDoc via the contact form or by email
2.2 Information collected automatically
Website:
- IP address and approximate location
- Browser type and version
- Pages visited and time spent on pages
- Referring website
- Device type and operating system
- Cookies and similar tracking technologies (see Section 8)
Mobile App:
- Device type and operating system version
- App version
- Firebase Analytics data — see Section 7 for full details
- FCM device token — used to send push notifications about your order
- Crash reports and error logs — used to improve app stability
2.3 Information we do not collect
We do not collect:
- Full payment card details — payment is processed entirely by Stripe
- Government identifiers such as tax file numbers or driver licence numbers
- Sensitive information such as health, racial or ethnic origin, religious beliefs or biometric data
- Location data beyond what is necessary for address autocomplete
- Your contacts or address book
- Browsing history outside of the PostMyDoc Service
3. The Burn After Reading Policy — How We Handle Your Documents
The handling of uploaded documents is governed by our Burn After Reading Policy which is a core commitment of the PostMyDoc service.
3.1 Encryption in transit All PDF documents are transmitted using 256-bit SSL encryption. Your document is encrypted between your device and our server at all times during upload.
3.2 Restricted storage Uploaded documents are stored in a restricted server directory that is not publicly accessible. Files cannot be accessed via direct URL and require authenticated server-side access only.
3.3 Purpose limitation Your uploaded document is used solely for the purpose of printing and posting your order. PostMyDoc personnel access your document only to the extent necessary to print and prepare it for dispatch.
3.4 Automatic deletion Your uploaded document is permanently and automatically deleted from PostMyDoc’s systems within 24 hours of your order being dispatched. This is an automated process — it does not require any action from PostMyDoc personnel.
3.5 No retention Once deleted your document cannot be recovered by PostMyDoc or provided to any third party. No backup copies of your document are retained.
3.6 What we retain The Burn After Reading Policy applies to uploaded PDF documents only. The following order information is retained as part of PostMyDoc’s order records:
- Your name and email address
- Recipient name and delivery address
- Order details — print type, postage service, page count, order value
- Payment confirmation from Stripe
- Dispatch date and tracking number where applicable
4. How We Use Your Information
We use the information we collect to:
- Process and fulfil your order — printing and posting your document
- Send order confirmation, dispatch and tracking notifications to your email address
- Send push notifications to your mobile device about your order status (App only)
- Respond to your enquiries and provide customer support
- Improve the Service — website and app performance, user experience and features
- Monitor and analyse usage patterns via Firebase Analytics to understand how customers use the App
- Detect, investigate and prevent fraudulent transactions and abuse of the Service
- Comply with legal obligations including tax record keeping
- Enforce our Terms and Conditions
We do not use your information for unsolicited marketing communications. We will only send you service-related communications related to your orders.
5. Disclosure of Your Information
We disclose your personal information to third parties only where necessary to provide the Service or where required by law.
5.1 Australia Post
Recipient name and delivery address are provided to Australia Post for the purpose of delivering your document. Australia Post’s privacy policy applies to their handling of this information and is available at auspost.com.au.
5.2 Stripe
Payment information is processed by Stripe Inc. Stripe may process payment data on servers located outside Australia including in the United States. Stripe is PCI DSS Level 1 certified. Stripe’s privacy policy is available at stripe.com/au/privacy. PostMyDoc does not receive or store your full card details.
5.3 Afterpay
If you choose to pay via Afterpay your payment information is processed by Afterpay. Afterpay’s privacy policy applies and is available at afterpay.com/en-AU/privacy-policy.
5.4 Klarna
If you choose to pay via Klarna your payment information is processed by Klarna. Klarna’s privacy policy applies and is available at klarna.com/au/privacy.
5.5 Google
PostMyDoc uses the following Google services:
- Google Places API — used in the PostMyDoc app to provide address autocomplete on the recipient details screen. Address search queries are sent to Google’s servers. Google’s privacy policy applies and is available at policies.google.com/privacy
- Firebase Analytics — used to collect anonymous usage data about how customers use the PostMyDoc app. This data is used to improve the app experience. Firebase Analytics data is processed by Google on servers that may be located outside Australia. See Section 7 for full details
- Firebase Cloud Messaging (FCM) — used to send push notifications to your mobile device. Your FCM device token is stored against your order in PostMyDoc’s systems and used only to send order-related notifications
5.6 Legal requirements
We may disclose your personal information where required or authorised by law including to:
- Comply with a court order, subpoena or other legal process
- Respond to a lawful request from a government authority or law enforcement agency
- Protect the rights, property or safety of PostMyDoc, its customers or the public
5.7 Business transfers
In the event PostMyDoc is acquired, merged or sold, your personal information may be transferred to the acquiring entity as part of that transaction. You will be notified of any such transfer.
We do not sell, rent or trade your personal information to third parties for marketing purposes.
6. Overseas Data Transfers
Some of our third party service providers process data on servers located outside Australia. These include:
| Service | Location | Purpose |
|---|---|---|
| Stripe | United States | Payment processing |
| Google Firebase | United States | App analytics and push notifications |
| Google Places API | United States | Address autocomplete |
Where we disclose your personal information to overseas recipients we take reasonable steps to ensure those recipients handle your information in accordance with the Australian Privacy Principles or a comparable privacy framework.
7. Firebase Analytics and App Data Collection
The PostMyDoc app uses Firebase Analytics to collect anonymous usage data. This data helps us understand how customers use the app and identify areas for improvement.
Data collected by Firebase Analytics includes:
- App open events
- Order flow steps completed and abandoned
- Payment completion and failure events
- Device type and operating system version
- App version
Firebase Analytics does not collect:
- Your name or email address
- The content of documents you upload
- Your recipient’s address
- Payment card details
Firebase Analytics data is aggregated and anonymised. PostMyDoc uses this data only to improve the app experience.
You can opt out of Firebase Analytics data collection by disabling analytics tracking in your device settings.
8. Cookies and Tracking Technologies
Website: The PostMyDoc website uses cookies and similar technologies to:
- Remember your selections on the order form
- Analyse website traffic via Google Analytics (Site Kit)
- Ensure the checkout process functions correctly
You can control cookies through your browser settings. Disabling cookies may affect the functionality of the order form.
App: The PostMyDoc app does not use traditional browser cookies. The app uses local device storage for the following purposes:
- Saving your sender name and email address if you tick “Save my details for next time” — stored locally on your device only
- Storing your order history locally on your device
9. Data Security
PostMyDoc implements industry-standard security measures to protect your personal information including:
- 256-bit SSL/TLS encryption for all data transmitted between your device and our servers
- Restricted server directory storage for uploaded PDF documents
- Automated deletion of uploaded documents within 24 hours of dispatch
- Secure payment processing via Stripe — PostMyDoc never receives or stores full card details
- Login attempt limiting on the PostMyDoc website administration
- Regular security audits of the website and app codebase
While we take every reasonable precaution to protect your information, no online transmission or storage system is 100% secure. You provide your information at your own risk.
10. Data Retention
We retain your personal information for the following periods:
| Data Type | Retention Period |
|---|---|
| Uploaded PDF documents | Deleted within 24 hours of dispatch |
| Order details (name, email, recipient address, order value) | 7 years — required for Australian tax record keeping obligations |
| Payment records | 7 years — required for Australian tax record keeping obligations |
| Customer communications | 3 years from the date of the communication |
| Firebase Analytics data | 14 months — Google’s standard retention period |
| App crash logs | 90 days |
11. Your Rights Under the Australian Privacy Principles
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles you have the right to:
11.1 Access your information You may request access to the personal information we hold about you. Due to the Burn After Reading Policy we will not have access to your uploaded PDF document after it has been deleted. We can provide access to your order details, email address and recipient address information.
11.2 Correct your information If you believe any personal information we hold about you is inaccurate, incomplete or out of date you may request that we correct it.
11.3 Anonymity Where practical you may interact with us anonymously or using a pseudonym. However providing accurate information is required to process and deliver your order.
11.4 How to exercise your rights To request access to or correction of your personal information please contact us at postmydoc.au/contact-us/ or via the contact details in Section 13. We will respond within 30 days.
12. Children’s Privacy
The PostMyDoc Service is not directed at children under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a child please contact us immediately and we will delete it.
13. Complaints
If you have a complaint about how PostMyDoc handles your personal information please contact us:
PostMyDoc postmydoc.au/contact-us/
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner oaic.gov.au 1300 363 992
14. Changes to This Privacy Policy
PostMyDoc may update this Privacy Policy from time to time to reflect changes to our practices, the Service or applicable law. Updated versions will be posted on the website and app with a revised “Last updated” date. Continued use of the Service after an updated Privacy Policy is posted constitutes your acceptance of the updated policy.
For significant changes we will notify you by email if we hold your email address.
15. Contact Us
For any questions about this Privacy Policy or how we handle your personal information:
PostMyDoc info@postmydoc.au OR postmydoc.au/contact-us/