Legal
Privacy Policy
Last updated: 3 July 2026 · Effective: 3 July 2026
This Privacy Policy explains how CombineIT Pty Ltd (ABN 64 167 910 634) ("CombineIT", "we", "us" or "our"), which owns and operates the Dspatch platform, collects, uses, holds and discloses your personal information. We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) (the "Privacy Act") and the Australian Privacy Principles ("APPs").
This policy applies to our website at dspatch.com.au, our web and mobile applications, and any related services (together, the "Services"). By using the Services you agree to the collection and use of your information in accordance with this policy.
1. What personal information we collect
"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable. The types of personal information we may collect include:
- Account and contact details: name, email address, phone number, business/organisation name, and login credentials.
- Billing information: subscription plan and payment details (card payments are processed by our third-party payment provider; we do not store full card numbers).
- Operational data you enter: consignment notes (connotes), jobs, customer and location records, delivery dockets, proof-of-delivery photos and signatures, files and documents you attach to a job or exchange via EDI, and related transport records.
- Location information: location data captured through the Services, for example the location recorded when a pickup or proof of delivery is completed on a mobile device.
- Device permissions: with your consent, access to features on your mobile device such as the camera (to capture photos and signatures) and location. You can manage these permissions in your device settings.
- Contacts of third parties: details of your customers, subcontractors and recipients that you add to the Services so you can create and share connotes.
- Integration data: where you connect a third-party service such as Xero, information exchanged with that service (see section 4).
- Technical and usage data: device information, IP address, browser type, and how you use the Services, collected via analytics and similar tools.
2. How we collect personal information
We collect personal information directly from you when you register, use or communicate with us about the Services. We may also collect it from your authorised users, from third-party integrations you connect (such as Xero), and automatically through your use of the Services.
Where you provide us with personal information about another individual (for example a customer or subcontractor), you represent that you are authorised to do so and that you have made them aware of this Privacy Policy.
3. Why we collect, hold and use your information
We collect, hold and use personal information to:
- provide, operate, maintain and improve the Services;
- create and manage your account and authenticate users;
- enable core features such as creating, sharing and delivering connotes and dockets;
- process payments, subscriptions and renewals;
- provide customer support and respond to your enquiries;
- enable integrations you choose to connect, such as Xero;
- enable features that use third-party artificial intelligence systems, such as extracting and processing information from documents you provide;
- send you service-related and, where permitted, marketing communications; and
- meet our legal, regulatory and record-keeping obligations.
4. The Xero integration
If you connect your Dspatch account to Xero, you authorise us to access and exchange data with your Xero organisation using Xero's secure OAuth 2.0 authorisation. Depending on your settings, this may include creating draft invoices in Xero from your completed jobs, and reading your Xero contacts, account codes and tax rates to help prepare those invoices.
We access your Xero data only to provide the integration you have enabled. You can disconnect the integration at any time from within Dspatch or from your Xero account. Your use of Xero is governed by Xero's own terms and privacy policy, which are separate from this policy.
5. When we disclose your information
We do not sell your personal information. We may disclose it to:
- Service providers who help us run the Services (for example cloud hosting, data storage, email/SMS delivery, analytics, and payment processing), who are only permitted to use it to provide services to us;
- Third-party integrations you connect, such as Xero, in accordance with your instructions;
- Third-party AI providers whose systems we use to enable certain features (for example data extraction, document processing or automation), who are only permitted to use the information to provide those features to us and not to train their own models;
- Recipients you nominate, such as the customers or subcontractors you share connotes and delivery documents with;
- our professional advisers, or a purchaser in connection with a sale of our business; and
- a person or authority where we are required or authorised by law to do so.
6. Overseas disclosure
We host your core account data on Amazon Web Services (AWS) infrastructure located in Australia. Some of our service providers may, however, store or process personal information outside Australia, for example our website analytics and customer-enquiry tools. Where personal information is disclosed overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs.
7. How we keep your information secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These measures include encryption in transit, access controls, and secure hosting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. How long we keep your information
We retain personal information for as long as needed to provide the Services and for a reasonable period afterwards to meet our legal, tax and record-keeping obligations. When we no longer need it, we take reasonable steps to destroy or de-identify it.
9. Direct marketing
We may send you marketing communications about Dspatch where you would reasonably expect it or where you have consented. You can opt out at any time using the unsubscribe function in the message or by contacting us. We comply with the Spam Act 2003 (Cth).
10. Cookies and analytics
Our website uses cookies and similar technologies, including Google Analytics, to understand how the site is used and to improve it. You can control cookies through your browser settings. Some features may not work correctly if cookies are disabled.
11. Accessing and correcting your information
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete, consistent with APP 12 and APP 13. To make a request, contact us using the details below. We may need to verify your identity before responding.
12. Complaints
If you believe we have breached the APPs or mishandled your personal information, please contact us first using the details below so we can investigate. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13. Changes to this policy
We may update this Privacy Policy from time to time. The current version will always be available on this page, with the "Last updated" date shown above. Material changes will be notified through the Services or by other reasonable means.
14. Contact us
For any privacy questions, requests or complaints, contact our Privacy Officer:
CombineIT Pty Ltd (operator of Dspatch)
Email: privacy@combineit.com.au
Phone: 1300 009 386
Post: PO Box 648, Parkholme SA 5043