Legal
Privacy policy
Last updated: 17 May 2026
Placeholder text — replace this page with the lawyer-reviewed policy before any production launch. The structure is a starting point only.
Who we are
Overview (“we”, “us”) operates the business platform at overview.software and the per-tenant subdomains and custom domains our customers attach to their accounts. We are based in Australia and our infrastructure is hosted in Australia (Sydney region).
What we collect
We collect only what we need to run the product:
- Account info — email, name, the agency or business you signed up for, and the magic-link tokens used to sign you in.
- Billing info — handled by Stripe end-to-end. We never see your card number; Stripe sends us a customer reference, the plan you're on, and charge / refund events.
- Connected-channel data — when you connect Google Ads, Meta, GBP, GA4 etc., we store OAuth tokens (encrypted at rest) and pull the reporting data the channel exposes. Used only to render your dashboards and feed the AI agent.
- Operational logs — IP addresses + user agents on auth events, email delivery status, audit trails on admin actions, and AI agent run history.
- Customer-facing data your tenants send — tickets, contacts, email lists, etc. We act as a data processor for that; the business or agency whose workspace you interact with is the data controller.
What we don't do
- We don't sell your data. Ever.
- We don't train external AI models on your tenants' data.
- We don't share your data with advertisers. We use Plausible-style privacy-first analytics, no third-party trackers on the dashboard.
Where your data lives
Primary database + object storage: Australia (Sydney region, Cloudflare R2 with AU bucket). Stripe holds billing data in their own infrastructure (US + EU datacentres). Resend handles email delivery from their infrastructure. Anthropic (Claude) processes AI prompts under our zero-retention enterprise agreement.
Your rights
Under the Australian Privacy Act 1988 you can ask to access, correct, or delete any personal information we hold about you. Use our contact form (topic: “General question”, message: “Privacy request”) and we'll action it within 30 days. EU visitors have the equivalent GDPR rights (Articles 15–22).
Cookies
A single session cookie (HTTPOnly, SameSite=Lax, scoped to the host you signed in on). No tracking pixels, no third-party ad cookies, no cross-site identifiers.
Changes
Material changes get an email to every active admin at least 30 days before they take effect. Minor wording fixes happen silently with the “Last updated” date above bumped.
Questions
Use our contact form — read by a human, in Australia, usually same-day.