Privacy Policy
Last updated: 24 June 2026
AllSorted (“we”, “us”, “our”) provides event-planning software to businesses (“customers”) who use it to manage their own clients and events. This policy explains how we handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It applies to the AllSorted website and application.
Information we collect
We collect personal information in the course of providing the service, including:
- Account information — names, email addresses, passwords (stored only as a secure hash), and role within a workspace.
- Customer and event records — information our customers enter about their own clients (names, contact details, event dates, venues, budgets, preferences) and their suppliers.
- Communications — emails sent and received through the platform, message content, and attachments (quotes, contracts, inspiration images).
- Enquiries — information submitted through public enquiry forms.
- Technical data — IP address, browser type, and usage logs for security and diagnostics.
How we use information
- To provide, operate and improve the service.
- To authenticate users and secure accounts.
- To send transactional emails (verification, password reset, invitations, notifications) and, where enabled by a workspace, follow-up communications to its clients.
- To provide AI-assisted features (for example, drafting replies, classifying enquiries, summarising threads and extracting details from transcripts). Content processed for these features is sent to our AI sub-processor solely to generate the requested output; it is not used to train third-party models.
- To process billing and subscriptions.
- To comply with legal obligations and prevent fraud or abuse.
Disclosure to third parties (sub-processors)
We use trusted service providers to operate AllSorted. We disclose only the information necessary for them to perform their function:
- Anthropic — AI text generation and classification.
- Brevo — sending and receiving email.
- Stripe — subscription billing and payment processing.
- Vercel — application hosting and content delivery.
- Neon — managed database hosting.
- Upstash — rate-limiting and caching.
- Sentry — error monitoring.
- Where a workspace connects an integration, the relevant provider (for example Google, Microsoft, Xero or Twilio).
Cross-border disclosure (APP 8)
Some of our sub-processors store or process data outside Australia, including in the United States and the European Union. By using AllSorted you acknowledge that your information may be processed overseas. We take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs.
Data security
Each workspace’s data is logically isolated using database row-level security. Passwords are hashed, traffic is encrypted in transit, and access is restricted on a need-to-know basis. No system is perfectly secure, but we take reasonable steps to protect personal information from misuse, loss and unauthorised access.
Retention and deletion
We retain personal information for as long as a workspace is active. When a workspace is closed, its data is scheduled for deletion and permanently removed after a grace period. Workspace administrators can export their data at any time from the settings area, and can request earlier deletion by contacting us.
Accessing and correcting your information
Under the APPs you may request access to, or correction of, the personal information we hold about you. If your information was provided to a workspace (for example, you are a client of a business that uses AllSorted), please contact that business directly, as they control that data. Otherwise, contact us using the details below.
Complaints
If you believe we have breached the APPs, contact us and we will investigate and respond. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Contact us
Privacy Officer, AllSorted — privacy@allsorted.com.au.