Back to home

Privacy Policy

Last updated: 27 September 2026

1. Who We Are

ShareAndGo is a product of Fintech Development Pty Ltd (ACN 655 608 969, ABN 78 655 608 969), an Australian company. We operate from Darwin, Australia. When we say "we", "us", or "our", we mean Fintech Development Pty Ltd.

2. Information We Collect

We collect information you provide directly:

  • Account information (name, email address, organisation name)
  • Documents you upload to data rooms
  • Communications with our support team

We automatically collect:

  • IP addresses and browser information for security audit logging
  • Usage data (pages visited, features used) via Google Analytics
  • Document access times and durations for audit trails

3. How We Use Your Information

  • To provide and maintain the ShareAndGo service
  • To verify your identity when accessing data rooms
  • To generate tamper-evident audit trails for compliance
  • To send transactional emails (access invitations, verification codes)
  • To process payments via Stripe (we do not store card details)
  • To improve the service through aggregated, anonymised analytics

4. Data Sovereignty

Your documents and their contents — including all storage, backups and AI search/OCR processing — are stored and processed exclusively in Australia (Google Cloud Platform, Sydney region: australia-southeast1). Your documents never leave Australian infrastructure, and all data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Limited operational metadata is processed by vetted subprocessors, some located overseas, solely to deliver the service: outbound email via SendGrid (e.g. recipient email address, subject and message body of an invitation), SMS notifications via Twilio (recipient phone number), and payment processing via Stripe (billing details). These providers process that metadata overseas under data processing agreements and handle delivery and billing metadata only, never your document content. We disclose this cross-border processing so our APP 8 position is precise rather than absolute.

AI features (document OCR, summaries, tagging, PII detection, Q&A and semantic search) are performed by Google Vertex AI in the Sydney region (australia-southeast1); we do not use your documents to train any model. If you choose to connect an external AI assistant (for example Claude or ChatGPT) to a data room via our optional MCP connector, the document content you expose to it is transmitted to that provider and processed under that provider's own privacy policy, which may be outside Australia. This egress is initiated by you and is off by default.

5. Data Sharing

We do not sell your personal information. We share data only with:

  • Service providers: Google Cloud Platform, Sydney (hosting, document storage, database, and Vertex AI for OCR, search and summaries, all in australia-southeast1), SendGrid (email delivery), Twilio (SMS delivery), Stripe (payments), all bound by data processing agreements
  • Data room participants: When you share a data room, invited participants can view documents you have granted them access to
  • Legal requirements: When required by Australian law or valid legal process

6. Data Retention

We keep your account data and your documents for as long as you have an account with us. That is deliberately not the same as "while your account is active": if your subscription lapses, or your trial ends, or you simply stop signing in, we do not delete anything. We keep your rooms, documents, folders and audit history exactly as you left them, so that they are intact if you come back. Work you paid for, or spent hours organising, is not something we take away because a payment stopped.

We do not currently offer a setting that deletes documents automatically after a period of time. Nothing is removed unless you ask us to remove it, we are required to remove it by law, or your account is closed or terminated under our Terms of Service — in which case your data is kept for 30 days so you can export it, and then permanently deleted.

Audit logs are retained for 7 years to meet Australian regulatory requirements. Because an audit log is a record that a document was viewed rather than a copy of the document, it is kept even after the document itself is deleted.

You can ask us to delete your account and everything in it at any time, by emailing privacy@shareandgo.com.au. We will confirm what has been removed. Deletion is permanent and we cannot recover a deleted workspace for you afterwards, so we will always confirm before acting.

7. If You Were Invited to Someone Else's Data Room

Most people who use ShareAndGo were invited to a data room by someone else — a seller, an adviser, an accountant or a lawyer. If that is you, this section is the one that matters, because the person who invited you can see a detailed record of what you did in their room.

We record, and show to the owner of that room:

  • The email address you were invited with, and the times you entered the room
  • Every document you opened, and how long each one was open for
  • Which documents you were given access to and never opened
  • An engagement score from 0 to 100, with a label such as Hot or Cold, calculated from how many documents you opened, how long for, how much of the room you covered and how recently. The room owner sees invited parties ranked by it
  • Your activity contributes to a short plain-English summary of the room’s overall engagement, written by an AI model for the room owner. That summary describes the room, not you individually
  • The network address you connected from
  • If you export a whole room, or request a copy of a document without its watermark, that request is recorded. We do not record printing, and we do not separately record opening a single document for download beyond the view itself

We tell you this before you enter a room, not afterwards: you are shown a notice describing what is recorded and you have to accept it to continue. You can also read your own record at any time from inside the room — the same information the owner sees about you, presented to you.

We collect this because a data room exists to give its owner an auditable record of who saw what, which is frequently a legal or transactional requirement for them. We do not use it for our own marketing, we do not sell it, and we do not use one room's activity to target you in another.

How long we keep it, and what we can and cannot do about it. You do not have an account with us, so the retention rules in section 6 do not describe your position and we should say what does. Your record belongs to the data room you were invited to, and it is kept for as long as that room is, plus the 7 years that audit logs are retained for. It is deleted when the room owner deletes the room or closes their account.

You can ask us about it at any time at privacy@shareandgo.com.au, and we will tell you what is held and correct anything that is wrong. We will not promise to erase your activity from a room’s audit trail, and you are entitled to know why: that trail is the record the room exists to produce, our customer may be required to keep it, and removing one participant’s entries would make it an unreliable record for everyone else in the transaction. If you ask us to, we will pass your request to the room owner and tell you that we have. If you believe we have this balance wrong, you can complain to the Office of the Australian Information Commissioner, and section 8 says how.

8. Your Rights

Under the Australian Privacy Act 1988, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Complain to the Office of the Australian Information Commissioner (OAIC)

9. Cookies

We use essential cookies for authentication and session management. We use Google Analytics (GA4) for anonymised usage analytics. We do not use advertising or tracking cookies.

10. Contact

For privacy enquiries, contact us at privacy@shareandgo.com.au