045 Legal Privacy
Privacy policy
How Zero Four Five collects, holds, uses and discloses personal information across its apps, and how it meets the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Who we are and what this policy covers
This Privacy Policy explains how Thomas James Nicholas and Zachary Gerald Engledow as trustees for the NE Investments Unit Trust (ABN 98 959 967 159) (Zero Four Five, we, us) collects, holds, uses and discloses personal information, and how we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
It covers the merchants and their staff who install and use our apps — StoreChat AI, Social Posts AI and the others listed on this site (each a Service) — and the shoppers who chat with the assistant on a merchant's store. Much of the shopper information we handle is processed on behalf of the merchant whose store it relates to. That merchant is responsible for its own privacy policy and for telling its shoppers how their information is handled; this policy explains what we do with it. Where this policy and a merchant's own policy both apply, this one governs our handling only.
Clauses 1 to 16 apply to every Service. Clause 17 is the additional detail for Social Posts AI — the app that drafts social posts from a store's own products and content and publishes the approved ones to the merchant's Facebook Page and Instagram Business account. If you have come here from Facebook or Instagram, or you are looking for how to have that data deleted, clause 17 is the one you want.
2. The personal information we collect and hold
From merchants (account holders): your name, email address, store/website domain, login credentials (passwords are stored only as a one-way hash — we never see or keep the plain password), your plan and usage records, and the content of any support messages you send us. Payment card details are handled by Shopify or our payment provider — we do not collect or store full card numbers.
From shoppers (via the chat widget, on the merchant's behalf): the messages they send the assistant and any personal information they choose to put in them; details a shopper provides for a specific action — for example an email address and order number or postcode to look up an order, or contact details submitted through lead capture; and a randomly generated visitor/session identifier used to keep a conversation continuous.
Synced from the merchant's store: to answer questions we sync store data through the store platform's authorised API. This includes catalogue and content data, and — for order lookup — order records containing the email address on the order, its shipping city, state and postcode, the items ordered with their quantities and prices, the order total, the payment and fulfilment status, and any tracking number and tracking link. We do not request the customer's name or phone number from the store platform. Order records are read to answer a shopper's question and are not stored by us.
From merchants who connect a Facebook Page or Instagram account (Social Posts AI): the identifiers and public profile details of the business accounts they choose to connect — the Facebook Page or Instagram Business account id, handle, display name and profile picture — the Facebook user id of the person who approved the connection, and the access tokens that let the app publish the posts they approve. We also read the contact email address Shopify holds for the store, so we can send the weekly reminder described in clause 17. No shopper information is involved: that app requests no access to customers or orders from Shopify at all.
Collected automatically: technical and usage information such as log data, device and browser type, and how the Service is used, for security, diagnostics and improving the Service. We do not derive location from IP addresses, and we do not store an IP address against a shopper or a conversation — it is used transiently to rate-limit abusive traffic.
Sensitive information: we do not seek sensitive information (as defined in the Privacy Act) and shoppers should not enter it into the chat. If sensitive information is provided to us anyway, we handle it in accordance with this policy and the APPs.
3. How we collect personal information
- directly from you when you install the Service, create or manage an account, choose a plan, or contact support;
- from shoppers when they interact with the chat widget on a merchant's store;
- from the merchant's store platform (such as Shopify) via its authorised API, using access the merchant grants at install; and
- automatically through your and shoppers' use of the Service, as described above.
Where it is reasonable and practicable, we collect personal information directly from the individual it concerns. Some shopper information reaches us indirectly through the merchant's store — the merchant is responsible for having a lawful basis to provide it and for any notices or consents required where it sells.
4. Why we collect, hold, use and disclose it
We use personal information for the purposes for which it was collected and related purposes you would reasonably expect, including to:
- provide, operate and maintain the Service and generate the assistant's answers;
- send chat content and store data to third-party AI providers so a response can be generated (see clause 5);
- verify and look up orders when a shopper requests it, and capture and forward leads to the relevant merchant;
- set up accounts, manage plans and usage, and provide support;
- secure, monitor, troubleshoot, analyse and improve the Service; and
- meet our legal, tax and regulatory obligations.
We do not sell personal information. We do not use chat content or store data to train our own AI models, and we use third-party AI providers under commercial terms that do not use the data we send them to train their models. We only use or disclose personal information for another purpose where the law permits (for example, with consent, or where required or authorised by law).
5. Who we disclose it to
We disclose personal information to:
- the merchant whose store a shopper interacted with — shopper chat data, leads and order-lookup activity are made available to that merchant in its dashboard;
- our service providers (sub-processors) who help us run the Service, currently including the store platform (Shopify), our AI providers (Anthropic, which provides Claude, and OpenAI, which generates the scene images in Social Posts AI's image studio), our transactional email provider (Resend) and our cloud hosting provider (Railway). They may only use the information to provide their service to us;
- Facebook and Instagram (Meta Platforms), where a merchant using Social Posts AI has connected a channel — we send them the post that merchant has approved, so it can be published on the merchant's own Page or account. Clause 17 sets out what we send and what we hold;
- professional advisers, or a buyer, in connection with a business sale, restructure or advice, subject to confidentiality; and
- others where required or authorised by law, or to protect the rights, safety or property of any person.
6. Overseas disclosure
Some of our service providers are located, or store data, outside Australia. This means personal information may be disclosed to, or accessed from, overseas recipients — likely in the United States and other countries where our providers operate. Before disclosing personal information overseas we take steps that are reasonable in the circumstances to have the recipient handle it consistently with the APPs. By using the Service you acknowledge that, to the extent an overseas recipient handles your information other than in accordance with the APPs, APP 8.1 may not apply.
7. Direct marketing
We may send merchants service messages (such as billing, security and product notices) and, where permitted, occasional marketing about our apps. Social Posts AI's weekly reminder is a service message of that kind; clause 17 explains where its address comes from and the two ways to stop it. You can opt out of marketing at any time using the unsubscribe link or by contacting us, and we'll action it promptly. We do not use shopper information for our own direct marketing. Any marketing also complies with the Spam Act 2003 (Cth).
8. Cookies, storage and tracking
The chat widget stores a small identifier and session data in the shopper's browser (for example in local storage) so a conversation stays continuous and the widget works correctly. We and our providers may use log data and similar technologies for security and to understand and improve how the Service is used. Shoppers can clear this data through their browser; doing so may reset an in-progress chat.
9. How we keep information secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure — including encryption of data in transit, one-way hashing of passwords, access controls, and use of reputable infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. We also take reasonable steps to destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed and we are not required by law to keep it.
10. How long we keep it
We keep personal information for as long as needed to provide the Service and for the purposes described in this policy — generally while your account is active — and afterwards only as long as we need it to meet legal, tax, accounting or dispute-resolution obligations, after which we delete or de-identify it. Merchants may request deletion of their account data; some records may be retained where the law requires.
Shopper information has fixed limits, applied automatically by a daily job rather than on request:
- Chat conversations and their messages — 12 months from the date of the conversation. Deleting a conversation also deletes the product recommendations and escalation records attached to it.
- Leads (contact details a shopper submitted through a form) — 24 months from the date of submission. Leads are kept longer than conversations because a lead is a business contact the merchant may still be following up.
- Our record of who accessed personal data — 12 months.
- Order records — not retained. They are read from the store platform to answer a shopper's question and are not written to our database.
Social Posts AI holds no shopper information at all. Its own limits are in clause 17: published, failed and skipped posts are removed after 12 months by a daily job; drafts and anything still scheduled are never removed by age; and everything held for a store is destroyed when the app is uninstalled.
When a merchant uninstalls, we act on the mandatory erasure requests the store platform sends us within the times it requires, which erases that store's data ahead of the periods above.
11. Accessing and correcting your information
You may ask us for access to the personal information we hold about you, and to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details in clause 14. We will respond within a reasonable time (usually within 30 days), and may need to verify your identity first. Access is generally free, though we may charge a reasonable cost for retrieving and supplying it; there is no charge to make a request or a correction. If we refuse access or correction, we'll explain why and how you can complain.
Because much shopper information is held on a merchant's behalf, if you are a shopper we may need to refer your access, correction or deletion request to the merchant whose store you used, and we'll help facilitate it where we can.
12. Data breaches
We comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). If a data breach involving personal information is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law, and take reasonable steps to contain and remediate it.
13. Complaints
If you think we have breached the APPs or mishandled your personal information, please contact us first using the details below so we can try to resolve it. We will acknowledge your complaint and aim to respond within a reasonable time (usually 30 days). If you are not satisfied with our response, you can complain to the OAIC: www.oaic.gov.au, phone 1300 363 992.
14. Contact us
For privacy questions, requests or complaints, contact our privacy contact:
Thomas James Nicholas and Zachary Gerald Engledow as trustees for the NE Investments Unit Trust (ABN 98 959 967 159)
Email: info@zerofourfive.com.au
Post: PO Box 1107, Mount Ommaney QLD 4074, Australia
15. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal information from children. Shoppers who use a merchant's chat should meet the minimum age set by that merchant and its region.
16. Changes to this policy
We may update this policy from time to time to reflect changes to our practices or the law. The current version is always available at this page, with the "last updated" date at the top. If a change is material we'll take reasonable steps to notify merchants (for example, in-app or by email). Continuing to use the Service after a change takes effect means you accept the updated policy.
17. Social Posts AI — Facebook and Instagram
This clause is the detail for Social Posts AI, and it is written to be read on its own. Clauses 1 to 16 still apply to it; where this clause is more specific, this clause governs.
Social Posts AI drafts social posts from a store's own products, collections, blog articles and pages, shows each draft to the merchant, and publishes the ones they approve to the Facebook Page and Instagram Business account that merchant has connected. It is installed by a merchant on their own Shopify store, and connected by that merchant to their own business accounts.
What it reads from the store, and what it never asks for
Two read-only Shopify permissions, and no others. read_products covers products and collections — title, description, vendor, product type, tags, images, price, compare-at price, availability and the storefront address. read_content covers blog articles and pages. The app also reads the store's name, domain, primary storefront address, currency and time zone, and the contact email address Shopify holds for the store.
It asks for no access to customers or orders, and for no permission to write anything — it never creates, changes or deletes anything in a Shopify store. So we hold no shopper names, email addresses, phone numbers, delivery addresses or order records from any store using this app. When Shopify sends us a customer data request or a customer erasure request for one of those stores, there is genuinely nothing to return and nothing to erase, and that is what we answer.
The Facebook and Instagram permissions we ask for
When a merchant presses Connect they are sent to Facebook, and Facebook — not us — asks them to approve the app. We request five permissions and use them only for what is written beside them:
- pages_show_list — to list the Facebook Pages they manage, so they can choose which one this store posts to.
- pages_manage_posts — to publish an approved post to that Page.
- pages_read_engagement — to read the Page's own name, id and picture, so the app can show which channel it is about to post to and tell them when a connection has stopped working.
- instagram_basic — to find the Instagram Business account linked to that Page, read its handle and picture, and read that account's own published posts for the optional link page described below.
- instagram_content_publish — to publish an approved post to that Instagram account.
We do not ask for, and cannot see, a merchant's Facebook profile or friends, their private messages, their followers, comments, ads or advertising audiences.
What we store from Facebook and Instagram, and why
- The connected accounts — the Facebook Page id and Instagram Business account id, the handle, the display name and the profile picture address. These identify the merchant's own business accounts, and are shown in the app so they can see exactly what is connected.
- The Facebook user id of the person who approved the connection. It is the only thing Meta names a person by when it tells us someone has removed the app or asked for their data to be deleted, so without it such a request could not be honoured.
- Access tokens for that Page and Instagram account. The app publishes at a scheduled time, when nobody is at the keyboard, so it has to hold a credential to publish with. Tokens are used to publish and to check that a connection still works, and for nothing else. They are never displayed in the app, never sent to an AI provider, and never given to anyone else.
- The posts themselves — the caption, the image, the alt text, the link, the time it is scheduled for, and afterwards the id and public address of the post on the platform.
Nothing is published without the merchant
The app drafts; the merchant approves. A merchant may also switch on automatic approval, in which case the app publishes what it has drafted under the rules and the schedule they set, and they can switch it off again whenever they like. Captions are written from a fact sheet built out of the store's own published content, and the app shows what each figure in a caption traces back to.
Once a post is published it is an ordinary public post on the merchant's own Page or Instagram account, and Facebook's and Instagram's terms and privacy policies govern it there. Removing it from this app does not remove it from them.
Images
Instagram fetches the picture for a post from a web address rather than accepting the file, so pictures a merchant uploads, and pictures made in the app's image studio, are served from a long random address on our servers for as long as the app is installed, and are deleted when it is uninstalled.
The image studio is optional. When a merchant uses it, one of the store's own product photographs and the scene description they typed are sent to OpenAI, which returns that product photographed in that scene. Nothing else goes with it — not the store's identity, not a token, not the caption.
The link page
If a merchant switches it on, the app builds a public page at an address they choose, showing tiles of their own recent Instagram posts — the picture, the caption, and a link to the product the post is about. Those posts are the merchant's own and are already public on Instagram. An Instagram caption can mention other people — an @handle, or someone thanked by name — and where it does, that text appears on the tile as the merchant wrote it. Any tile can be hidden, and switching the page off removes it.
Who else sees any of it
- Anthropic writes the caption, and receives the fact sheet it is written from — the title, summary, price, tags and availability of one product or article, every field of it taken from a page the store already publishes — together with the merchant's own brand-voice settings. It receives no Facebook or Instagram data, no access token, no email address, and nothing about any shopper.
- OpenAI receives what is described under Images above, and only when a merchant uses the image studio.
- Meta Platforms receives the approved post — caption, image and alt text — because that is what publishing is.
- Resend sends the weekly reminder, and so receives the address it goes to and what it says.
- Railway hosts the application, its database and those images, in the United States, on storage the platform encrypts. Clause 6 covers overseas disclosure.
None of them may use what we send for their own purposes, and our terms with our AI providers do not permit them to train models on it. We do not sell any of it, and one merchant's data is never used for another merchant.
The weekly reminder
This app produces drafts that wait for a person, so an app nobody opens is a calendar that quietly stops. Once a week, on the day and at the hour the merchant chooses, and only when there is something to say, we email them what is waiting. It goes to the address they enter in the app; if they have not entered one it goes to the contact address Shopify holds for the store, which we read when the app is installed. It is a service message about their own drafts, not marketing. It can be switched off in the app's settings, or with the one-click unsubscribe link in the email itself, which needs no login and does nothing else.
How long it is kept
- Published, failed and skipped posts — 12 months, removed by a daily job. Anything still ahead of the merchant — a draft, an approved post, anything scheduled — is never in range, whatever its age.
- The synced content library is kept in step with the store for as long as the app is installed.
- Facebook and Instagram access tokens are held until the merchant disconnects the channel, removes the app from their Facebook account, asks for their data to be deleted, or uninstalls — whichever comes first.
- Everything held for a store is destroyed when the app is uninstalled — the database records and the uploaded images alike — and the same happens if Shopify sends us a shop erasure request afterwards.
How to have Facebook and Instagram data deleted
Any of these works:
- In the app — disconnect the channel in Social Posts AI. That account and its access token are deleted straight away.
- On Facebook — Settings & privacy, then Settings, then Apps and Websites, and remove Social Posts AI. Facebook tells us, and we delete every Page and Instagram account connected through that person's approval, and the tokens with them.
- Through Facebook's data deletion request — we act on it when it arrives, and answer with a confirmation code and a page that says what was removed.
- By uninstalling the app from the Shopify store, which deletes everything held for that store.
- By writing to us at info@zerofourfive.com.au, and we will do it by hand.
Posts that have already been published stay on Facebook and Instagram. They belong to those accounts and we have no way to remove them — delete them there if you want them gone.
Last updated 25 August 2026