Ridgeline Intelligence — Privacy Policy
DRAFT v0.1 — 21 July 2026 — interim statement pending legal review. Covers Ridgeline Signal and Ridgeline Radar. Published at signal.ridgelineadvisory.com/privacy.
This is an interim statement
This policy is a genuine, current description of how we handle your information, published so that the documents that reference a privacy policy point at a real one. It has not yet been reviewed by a lawyer. When the reviewed version is published here it will replace this draft, and material changes will be noted. If anything below is unclear, or you want to know something it doesn't answer, email [email protected] and you'll get a straight answer.
1. Who we are
Ridgeline Advisory (ABN 81 335 231 816), based in Perth, Western Australia, operates Ridgeline Signal (signal.ridgelineadvisory.com), Ridgeline Radar (radar.ridgelineadvisory.com) and the ridgelineadvisory.com website (together, "the services"). This policy is written to be consistent with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
2. What we collect, and why
Account information — your name, email address and (optionally) organisation, collected when you sign up, so we can operate your account, deliver the product, and contact you about your subscription.
Payment identifiers — payments are processed by Stripe. Your card details are captured and stored by Stripe and never touch our systems; we hold only Stripe's identifiers for your customer and subscription and your billing status.
Free-access verification — if you apply for free access as a verified Traditional Owner corporation, PBC or First Nations community member, we collect what you choose to provide to establish eligibility, use it only for that decision, and do not use it for marketing.
Briefing-list subscriptions — if you join the briefing list we collect your email address, optionally your name, and which site you signed up from, so we can send you the briefing. Nothing else is attached to it.
Usage and technical logs — standard web logs (IP address, pages requested, timestamps) generated by operating the services, used for security, debugging and understanding aggregate usage. Where we record a request against an abuse control we store a salted hash of the IP address, not the address itself.
We do not sell personal information, and we do not use third-party advertising or cross-site tracking on any of the services.
3. Where it's held, and who processes it
We use a small number of processors to run the services:
- Stripe — payment processing (card details live only with Stripe);
- Supabase — authentication and account records;
- Cloudflare — hosting, storage and content delivery for Signal and the website;
- Vercel — hosting for Radar;
- Resend — transactional email (password resets, billing and verification notices).
Some of these providers store data outside Australia (typically in the United States and, for some Cloudflare services, distributed globally). Where that happens, APP 8 (cross-border disclosure) applies and we take reasonable steps to ensure the recipient handles the information consistently with the APPs — primarily through the providers' own contractual privacy commitments.
4. Disclosure
We disclose personal information only: to the processors above, to operate the services; where you direct or consent; where required by law; or as part of a genuine sale or restructure of the Ridgeline business (in which case the recipient inherits the obligations in this policy). We do not disclose subscriber lists, and we will not publicly identify you as a subscriber without your consent.
5. Retention
Account records are kept for the life of your account and for a reasonable period after closure for legal, tax and dispute purposes. Briefing-list entries are kept until you ask to be removed. Logs rotate on short cycles. If you want your information deleted, ask — see section 6 — and we will delete what we are not legally required to keep, and tell you what (if anything) we kept and why.
6. Access and correction
You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, by emailing [email protected]. We will respond within 30 days, and there is no charge for a reasonable request.
7. Complaints
If you think we have mishandled your personal information, email [email protected] with the details and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au, 1300 363 992.
8. Changes to this policy
The current version is always published at signal.ridgelineadvisory.com/privacy. The lawyer-reviewed version will replace this draft at the same address; material changes will be flagged on this page and, for subscribers, by email.