Privacy policy
How Shufti collects, uses and protects your information.
Last updated: 26 September 2026
This Privacy Policy should be read together with our Terms of Service ("Terms"), which use the same defined terms ("Shufti", "we", "us", "the "Service"). Where a topic is fully covered in the Terms (for example, the licence you grant us in your content, or our liability), this Policy cross-refers to that clause rather than restating it in different words.
1. Who we are and how to contact us
Shufti is operated by Frontpoint Digital Pty Ltd (ABN 23 669 870 366) of 7/232 Barkly St, St Kilda, VIC 3182 ("Shufti", "we", "us"). We are bound by the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
We treat the APPs as applying to us regardless of whether we fall under the $3 million annual turnover small-business threshold that would otherwise exempt many small businesses. This is a deliberate choice, not a legal conclusion that the threshold doesn't apply to us — app store policies require a privacy policy regardless, and it is materially cheaper to build compliant habits now than to migrate later.
If you have any question, complaint, or request about how we handle your personal information, contact us at support@shufti.io. See clause 10 (access and correction) and clause 11 (complaints) for how we handle specific requests.
2. What personal information we collect, and why
We collect personal information to provide the Service described in our Terms — helping you research and inspect a used vehicle before you buy it. We collect the following categories:
2.1 Account identity. If you create an account, we collect your email address and (if you provide it) your name, through our authentication service provider. If you sign in with Google or Apple, we receive the name and email address that provider shares with us (for Apple, this may be a private relay address if you choose to hide your email). Guest use of the Home screen does not require an account and is not linked to any account identity (see Terms clause 14.2).
2.2 Audio clips you record. The guided walkthrough lets you record short audio clips — for example, engine or brake noise — and attach them to a check. If you record one, the clip is uploaded to our storage alongside your photos and is used to help assess the vehicle's condition and to maintain your Garage history. Recording is always your choice, per clip; nothing is recorded automatically, and your answers to checks are the text you type, not anything spoken.
2.3 Photos and video clips. During a guided walkthrough, you capture photos and short clips of the vehicle you're inspecting. These are collected to generate your findings and negotiation report and to maintain your Garage history. Because these photos are taken at a seller's home or business, often in public view, they may incidentally capture other people, number plates, house numbers, or other identifying information visible in the frame. This is a known limitation of photographing a vehicle in a real-world setting, not something we can claim to fully prevent — see clause 6 of the Terms for the responsibility this places on you, and clause 6 below for what we do to reduce (not eliminate) this risk.
2.3A Location — asked at the test drive, used live, not stored. When the guided walkthrough reaches the test-drive section and you tell us you're the one driving, we ask your device for your location.
Route planning uses only your approximate location: your coordinates are sent to our server, converted into a suburb name to plan routes near you that cover the checks for that vehicle, used to draw them on a map, and are not stored against your inspection or your account — only the resulting route descriptions are. A suburb is all a route plan needs.
In-app navigation: if you then choose to drive one of the suggested routes, Shufti gives you turn-by-turn navigation inside the app instead of sending you to a separate maps app. Turn-by-turn needs your precise location, updated continuously while you drive, and — so guidance doesn't cut out if your screen locks mid-drive — it may keep updating in the background for as long as that navigation screen is open. This location is used live by our mapping provider to place you on the road and speak the next instruction. Shufti does not store your position, your speed, or the path you actually drove.
Declining costs you the routes. If you refuse the permission, turn location services off, or use the web app on a browser that can't get a fix, you still get suggested routes, described by the type of road to look for — but without your own position there's no map to draw and no in-app navigation. We don't ask again, and we don't ask anywhere else in the Service. (The web app is the one exception: it always falls back to a fixed, non-personal demonstration location rather than asking your browser, since a browser tab is rarely the device you'd actually drive with, and in-app navigation is mobile-only.)
2.4 Listing and vehicle details. The listing URL you paste (for example from carsales.com.au, gumtree.com.au, or ebay.com.au) and the vehicle details we derive from it or you provide — make, model, year, VIN, odometer reading, and registration number where you supply one.
We treat a VIN or registration number as personal information where it is capable of being linked to an identifiable person (for example, to you as the buyer investigating it, or in principle to a seller/registered owner), and we handle it accordingly.
2.5 Purchase records. Receipts, credit balances, and transaction identifiers relating to your purchases of vehicle check credits. Purchases made through Apple's App Store or Google Play are verified by us against the store's server, but Apple and Google are separate, independent data controllers for the payment transaction itself — your payment card details, for instance, go to them, not to us. See their own privacy policies for how they handle that information, and Terms clause 7.4 for how purchases work.
2.6 Negotiation outcomes and chat/walkthrough history. The questions asked, your answers, the findings generated, and the negotiation report produced for each vehicle you evaluate, stored in your Garage.
2.7 PPSR search results. Where you explicitly request a paid PPSR search, we obtain and display to you the result of that search against the vehicle identifier (VIN or registration number) you provide. PPSR results are a third-party government data source that we re-present to you — see Terms clause 3.2.
2.8 Technical and usage information. Standard technical information generated by using the app or website — device type, operating system, app version, and in-app events such as which screens you open and how far you get through an inspection — which we use to operate, troubleshoot, and understand how the Service is used. In the mobile app this is collected through a third-party analytics service; the events are tied to an app-instance identifier assigned by that service, not to your name, but that identifier persists on your device. We do not use an advertising identifier (the Android "advertising ID" permission is removed from the app, and we do not access the iOS IDFA), and we do not use this information to track you across other companies' apps or websites or for targeted advertising. See clause 5 (cross-border disclosure) and clause 9 (cookies and analytics) for more on this.
Notice at the point of capture. Before you capture your first photo or transcript, the app shows you an in-the-moment notice describing this collection and its uses. This Privacy Policy is the durable, backstop disclosure — it does not replace that point-of-capture notice, which exists because a notice given at the time of collection is more meaningful than one buried in a policy you read once (or never).
3. How we use your personal information
3.1 Primary purpose — operating the Service. We use the personal information above to decode your vehicle, check recalls and PPSR status on request, generate your checklist, run your guided walkthrough, score findings, produce your negotiation report, maintain your Garage history, process your purchases, and provide customer support.
3.2 Secondary purpose — improving Shufti and training its models. We may also use your content, transcripts, findings, and outcomes to improve the Service and to train or evaluate the AI models it relies on. This is a genuinely separate use from 3.1, and we treat it as such. The mechanics of this use, including the "Help improve Shufti" opt-out toggle in Profile → Settings, the fact that it is on by default, and that turning it off is forward-looking only (it does not remove content already captured before you turned it off from a training corpus already assembled), are set out in full in Terms clause 5.3 — this Policy adopts that clause by reference rather than restating it, so the two documents cannot say different things about the same mechanism.
We aim to reduce the amount of identifiable third-party (bystander) information that reaches any training use — see clause 6. This is a mitigation, not a guarantee.
3.3 We do not use your personal information for a purpose you would not reasonably expect, beyond what is described in this Policy and the point-of-capture notice, except where required or authorised by law.
4. Who we disclose your personal information to
We disclose personal information to:
- Our cloud hosting provider, which hosts our database, file storage, and authentication. Data at rest in our database and file storage is held in Australia.
- AI providers, for processing — see clause 5 (cross-border disclosure) below; this is a distinct and important disclosure and we've given it its own section rather than folding it in here.
- Our mapping provider — where we plan and draw a test-drive route (clause 2.3A), your approximate location and the route's road names are sent to our mapping provider's geocoding, directions, map and routing services. If you then start in-app navigation for a route, your precise location is streamed to that provider's navigation service for as long as that navigation screen is open, so it can guide you turn by turn. All of this happens only if you allow the location permission at the test-drive step; without it, no route is planned, drawn, or navigated, and nothing is sent anywhere.
- Government data sources — vehiclerecalls.gov.au (recall lookups) and ppsr.gov.au (PPSR searches, on your explicit request), which we query on your behalf and whose results we then hold and display to you.
- Apple and Google, as the store operators processing your purchase and any promotional-code redemption made through their own redemption mechanism — see Terms clause 7.3 and 7.4.
- Professional advisers, regulators, or law enforcement, where required or authorised by law.
- A purchaser of our business or assets, in the event of a sale, merger, or restructure of Frontpoint Digital Pty Ltd, subject to that purchaser being bound by terms consistent with this Policy in respect of personal information already held.
We do not sell your personal information to third parties for their own marketing purposes.
5. Cross-border disclosure — where your information goes overseas
This clause is central to this Policy. Please read it carefully.
While our database and file storage are hosted in Australia, some processing genuinely happens overseas:
- AI model providers process photos and the text of your answers that you provide during a walkthrough, to assess vehicle condition, highlight where a part is in your own photo, and power chat and guidance features.
- Our analytics provider receives the technical and usage events described in clause 2.8. This is a continuous background flow while you use the app, not a one-off request, and the provider processes and stores this data on infrastructure outside Australia (primarily the United States). It does not include your photos, transcripts, walkthrough answers, or PPSR results.
Sending a photo or transcript to an AI model provider for this processing means that personal information (which may include the incidental bystander information described in clause 2.3) leaves Australia for the time it takes that provider to process the request; the analytics flow sends technical and usage information overseas on an ongoing basis.
We take reasonable steps to ensure information sent overseas for this purpose is handled appropriately, including limiting what we send to what each feature needs and choosing providers with their own security and data-handling commitments. However, under APP 8, we remain accountable for how an overseas recipient handles your personal information, even where an APP 8.2 exception might otherwise apply — we are not attempting to avoid that accountability by using overseas providers, and we want that stated plainly rather than left as a technicality.
6. Photos may contain other people's information
Because inspections happen at a seller's property, often visible to neighbours, other vehicles, and passers-by, a photo you capture may incidentally include another person's personal information — their face, number plate, or an identifying detail like a house number.
We cannot obtain that person's consent, because we have no relationship with them and no way of reaching them. What we can do, and do, is apply mitigations aimed at reducing this risk: minimising what we prompt you to capture, and (before any training use of an image) filtering for identifiable faces or number plates so that images containing them are excluded from any training corpus we assemble. These mitigations reduce risk; they do not eliminate it, and we do not represent that no third-party personal information will ever be captured, stored, or processed by the Service. This mirrors the position in Terms clause 6, deliberately — the two documents describe the same limitation the same way.
7. Data quality and security
We take reasonable steps to keep the personal information we hold accurate, complete, and secure, including:
- encryption of data in transit and at rest, consistent with the default protections provided by our cloud hosting provider;
- access controls limiting who inside Frontpoint Digital Pty Ltd can access personal information, and for what purpose; and
- server-side verification of every purchase (including store promotional- code redemptions), so that purchase records reflect what a store has actually confirmed.
We do not hold any specific security certification (for example, ISO 27001 or SOC 2), and this Policy does not claim one. If that changes, we will update this clause to reflect it accurately rather than in advance of it being true.
No method of storing or transmitting information online is completely secure, and we cannot guarantee absolute security.
8. Retention and deletion
We retain your personal information for as long as your account is active, and for a reasonable period afterwards as needed to comply with our legal obligations, resolve disputes, and enforce our agreements.
Deleting your account. You can delete your account yourself in the app, under Profile → Settings → Remove account. We ask you to confirm who you are first. When you do, we permanently delete your account and the personal information held in it: the vehicles in your garage, your inspections, photos, audio, answers and reports, your negotiation chats, your sharing invitations, your preferences and any unused vehicle check credits (which are not refundable). This cannot be undone.
A small amount of information is kept after deletion, without anything that identifies you:
- Store transaction records. For each in-app purchase you made, we keep the store's transaction identifier, with your account removed from it, so that the same purchase cannot be redeemed twice. Apple or Google keeps the purchase record itself under its own privacy policy.
- Your reason for leaving. If you tell us why you are removing your account, we keep that answer (and any optional comment you type), along with how you signed in and which kind of device you used. We do not store it with your name, email address or account.
Deletion is forward-only for model training: it removes every copy we hold in the Service, but content that was already included in a training dataset under clause 3.2 before you deleted your account is not recalled from that dataset, consistent with the position in Terms clause 5.3 for opting out of training use.
Other requests. Shufti does not yet have a self-service data-export feature. If you would like us to access or correct the personal information we hold about you, or to delete it without using the app, please contact us at support@shufti.io and we will handle your request manually, responding within a reasonable time consistent with our obligations under the Privacy Act.
9. Cookies and analytics
The mobile app uses a third-party analytics service to understand basic usage — which features are used, and how far people get through an inspection — so we can find and fix problems and decide what to build next. The website uses standard web technologies (such as cookies or local storage) to keep you signed in, and may record basic, aggregate usage of the site. Where you reach the site by scanning or tapping a link in a shared inspection report, that link carries a generic campaign marker so we can tell how many visitors arrived that way; it does not identify you or the person who shared the report.
We do not use any of this for targeted advertising, we do not use an advertising identifier, and we do not share it with other companies to track you across their apps or websites. See clause 2.8 for what is collected and clause 5 for where it goes.
10. Access and correction
You have the right to request access to, and correction of, the personal information we hold about you. To make a request, contact us at support@shufti.io. We may need to verify your identity before responding, and there are some circumstances in which the Privacy Act allows us to refuse a request (for example, where providing access would unreasonably impact another person's privacy) — if we refuse, we will tell you why.
11. Complaints
If you believe we have mishandled your personal information, please contact us first at support@shufti.io so we can investigate and try to resolve your concern directly. We will acknowledge your complaint and respond within a reasonable time.
If you are not satisfied with our response, or believe we have not dealt with your complaint appropriately, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
12. Children
The Service is not directed at, or designed for, children. Using Shufti assumes a buyer old enough to hold a driver's licence and to be personally negotiating the purchase of a vehicle, including test-drive-related content described in Terms clause 8. We do not knowingly collect personal information from children, and if we become aware that we have, we will take reasonable steps to delete it.
13. Changes to this Policy
We may update this Policy from time to time, for example to reflect changes to the Service, the providers we use, or the law. Where a change is material, we will take reasonable steps to notify you (for example, an in-app notice), consistent with how we handle material changes to our Terms (see Terms clause 15). Continuing to use the Service after a change takes effect means you accept the updated Policy.
14. Contact
Questions, requests, or complaints about this Policy or how we handle your personal information can be sent to support@shufti.io.