Legal

Privacy Policy

Effective 22 August 2026

01

Scope and roles

This Privacy Policy explains how Incld handles personal information when you visit incld.dev, create or use an account, contact us, or use the service. It does not govern your own application or the independent practices of third parties.

For account, website, support, and direct commercial information, Incld generally acts as controller or business. For personal data that a customer submits through projects, APIs, schedules, approvals, audit events, bulk operations, and webhooks, Incld generally acts as processor or service provider on the customer's instructions.

02

Information we collect

Account and identity information, such as name, email address, profile image, locale, authentication method, organisation or project membership, and identifiers received through WorkOS.

Service and Customer Data, such as action definitions, schedules, external user identifiers, approval requests and decisions, audit events, bulk-operation payloads and metadata, callback configuration, notification destinations, and support content.

Technical and usage information, such as IP address, device and browser details, timestamps, request and error logs, security events, feature usage, and diagnostic information.

Commercial information, such as plan, subscription, usage meter, order, invoice, tax location, and customer identifiers. Polar independently collects and processes payment-card and checkout information as merchant of record; Incld does not receive complete payment-card details.

03

How we use information

To provide, authenticate, operate, meter, secure, maintain, and support the service; deliver configured webhooks and notifications; prevent fraud and abuse; troubleshoot incidents; communicate service and legal notices; administer billing and entitlements; improve product reliability and usability; and comply with legal obligations.

Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the service, compliance with law, and consent where required. We do not sell personal information or use Customer Data for third-party advertising.

04

How information is disclosed

We disclose information to subprocessors that help provide infrastructure, authentication, billing, communications, analytics, and error monitoring; to integrations you deliberately configure; to professional advisers under confidentiality; during a corporate transaction; and where required to comply with law or protect rights and safety.

Our current provider list and processing purposes are published on the Subprocessors page. Polar is an independent controller for its checkout and merchant-of-record obligations. A customer-configured Slack workspace or webhook recipient processes data under the customer's direction.

05

International transfers

Incld and its providers may process information in Australia, the United States, and other countries where they operate. Those countries may have different privacy laws. Where required, we use contractual and organisational safeguards, including applicable standard contractual clauses and provider data-processing agreements.

Business customers may request our DPA. Provider locations and links to their current legal terms are listed on the Subprocessors page.

06

Retention and deletion

We retain personal information only as long as reasonably necessary for the purposes described here, including providing the service, maintaining security and audit records, resolving disputes, preventing fraud, and meeting tax, accounting, and legal obligations.

Retention depends on data type and plan. Active project data is generally retained for the life of the account. After account or project termination, production data is scheduled for deletion or de-identification after a reasonable export and recovery period, while encrypted backups expire on their normal rotation. Billing, security, and legal records may be kept longer where required.

07

Security

We use technical and organisational measures designed to protect information, including encrypted transport, access controls, scoped credentials, signed webhooks, environment separation, logging, backups, and managed providers. No method of storage or transmission is completely secure.

Please report suspected vulnerabilities to [email protected] and do not include sensitive production data in the initial report.

08

Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, or complain to a regulator. You may also have rights to know categories of information collected and disclosed and to receive equal service when exercising privacy rights.

Account profile information can be updated in the dashboard. Send other requests to [email protected]. We may verify identity and authority before acting. If we process information solely for a customer, we will direct the request to that customer and assist as required by our DPA.

You may complain to us first so we can investigate. You may also contact the privacy or data-protection authority in your jurisdiction, including the Office of the Australian Information Commissioner where applicable.

09

Children

Incld is a developer and business service not directed to children. We do not knowingly collect personal information directly from children under 16. Customers are responsible for determining whether their application may lawfully submit children's information and for obtaining any required parental consent.

10

Changes and contact

We may update this Policy as the service, providers, or law changes. We will post the updated effective date and provide additional notice for material changes where appropriate.

Privacy questions, requests, or complaints may be sent to [email protected]. We aim to acknowledge privacy complaints promptly and respond within the period required by applicable law.