Skip to content
Legal

Privacy Policy

Last updated: 2 June 2026

MaterialSales (“we”, “us”, “our”) is an Australian-owned business operating the materialsales.com.au marketplace. This policy explains how we handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.

The data controller is Chevron Sands Pty Ltd (ACN 615 508 337, ABN 19 615 508 337), registered office 51 Barron Street, Hendon QLD 4362, Australia. Privacy questions or access/correction requests: hello@materialsales.com.au.

What we collect

When you use the platform, we may collect:

  • Account details: email, password (hashed), name (optional)
  • Supplier business details: business name, ABN, phone, address, supplier type
  • Listing content you publish: titles, descriptions, photos, prices
  • Buyer enquiry details: name, email, phone, company, message
  • Payment metadata: amount, date, plan (card details are processed by Square and never reach our servers)
  • Technical: IP address, user-agent, pages visited, search queries (used for security, gap analysis and platform improvement)

How we use it

  • To operate the marketplace and connect buyers with suppliers
  • To send transactional emails (signup verification, listing approvals, enquiry notifications, tax invoices)
  • To detect and prevent abuse (rate limiting, spam filtering)
  • To improve the platform (anonymous analytics, search query analysis)
  • To comply with our legal obligations (tax records, ABN verification)

What we don’t do

  • We don’t sell your data to third parties.
  • We don’t use your enquiries for marketing other suppliers.
  • We don’t share your contact details outside of legitimate platform use.
  • We don’t collect facial images or biometric data.

Who we share with

We share data only with vendors necessary to operate the platform, under equivalent privacy obligations:

  • Supabase (database, auth, file storage) — hosted in Sydney, AU
  • Square Australia (payment processing) — PCI-DSS Level 1 provider; receives card details directly from the browser via Square’s hosted Web Payments SDK iframe
  • Resend (transactional email delivery) — receives recipient address + email body
  • Vercel (web hosting + CDN) — handles HTTP requests

We will disclose information when required by Australian law (court order, warrant, ATO request) or to protect platform safety.

Overseas disclosure

Our primary database, authentication and file storage (Supabase) are hosted in Sydney, Australia. However, some of the service providers above operate overseas, so your information may be stored or processed outside Australia:

  • Resend (transactional email) — United States
  • Vercel (web hosting + global CDN) — United States and other regions via its content-delivery network
  • Square (payments) — operates in Australia; card data is handled under its global PCI-DSS Level 1 environment

We take reasonable steps to ensure these providers handle your information consistently with the Australian Privacy Principles. By using MaterialSales you consent to this overseas disclosure for the purposes described above.

How we protect your information

We take reasonable steps to protect personal information from misuse, loss and unauthorised access, in line with APP 11:

  • All traffic is encrypted in transit (HTTPS/TLS).
  • Passwords are hashed — we never store them in plain text, and card details never touch our servers.
  • Database access is governed by row-level security so accounts can only reach their own data.
  • Administrative access is restricted, and sensitive actions are logged.

No online service can guarantee absolute security. If a data breach likely to cause serious harm ever occurs, we will notify affected users and the OAIC as required by the Notifiable Data Breaches scheme.

How long we keep it

  • Account data: while your account is active, then 30 days after deletion
  • Listings: 30 days after deletion (soft delete window for support / disputes)
  • Payment records: 7 years (Australian tax retention requirement)
  • Audit logs: 12 months
  • Search query logs: 90 days, anonymised

Your rights

Under the Privacy Act, you can:

  • Access the personal information we hold about you
  • Request corrections
  • Request deletion (use the “Delete account” option in dashboard settings, or email us)
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au

Cookies

We use only essential cookies for authentication and session management. We don’t use third-party advertising cookies. Optional analytics cookies (Google Analytics 4 and Vercel Analytics) are opt-in: when you first visit, a banner lets you choose “Accept all” or “Essential only”, and choosing essential only means no analytics cookies are set. You can change your mind any time by clearing this site’s cookies in your browser settings.

Children

MaterialSales is a B2B marketplace for businesses. We don’t knowingly collect data from anyone under 18.

Changes

We’ll update this page as the platform evolves. Material changes will be communicated by email to all account holders at least 14 days in advance.

Contact

Questions or requests: hello@materialsales.com.au