Legal

Privacy Policy

Last updated 15 July 2026

1. Who we are

TeeUp is an HR, CRM and project management platform built and operated by Garaj Pty Ltd (ABN 60 663 528 130) of 84 Hotham Street, Preston VIC 3072, Australia. In this policy, "we", "us" and "our" mean Garaj Pty Ltd. "You" means anyone whose personal information we handle.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. What this policy covers

This policy applies to the letsteeup.com website, the TeeUp platform when we host it for you, and the TeeUp Chrome extension.

Self-hosted installations are different. TeeUp is open source. If you run it on your own infrastructure, your data never reaches us and we have no access to it — you are the data controller and this policy does not govern what happens inside your instance. The sections below about storage, retention and disclosure apply only where we host TeeUp for you on a Standard, Business or Enterprise plan.

3. What we collect

Information you give us

  • Account details — name, work email, and the password hash for your login.
  • Billing details — business name, billing contact and address. Card payments are handled by Stripe; card numbers go directly to Stripe and we never see or store them.
  • Enquiries — anything you send us by email, ticket, chat or on a call.

Information you put into TeeUp

When we host TeeUp for you, your instance holds whatever you choose to put in it — employee records, contracts, leave requests, payslips, expense claims, documents, contacts, deals, quotes, invoices, projects and timesheets. Some of this is sensitive information about your employees.

We hold this on your behalf. You decide what goes in, who can see it, and when it's deleted. We do not use it for our own purposes, do not mine it, and do not sell it.

Information we collect automatically

  • Server logs — IP address, browser type, pages requested and timestamps, kept for security and troubleshooting.
  • Audit trail — TeeUp records who approved or changed a record and when, because that's a feature of the product.
  • Website analytics — on the letsteeup.com marketing website only, we use Google Analytics and the Meta Pixel. See Cookies for what they collect and how to refuse them. These do not run inside the TeeUp application.

4. How we use it

We use personal information to provide and run the platform, authenticate you, take payment, respond to support requests, notify you about service changes, meet our legal obligations, and investigate misuse or security incidents.

We do not sell personal information. We do not use the data inside your TeeUp instance — your employee, customer, project and financial records — for advertising, and we do not use it to train machine learning models. Nothing you put into TeeUp is used to target ads at anyone.

Separately, and only on the public letsteeup.com marketing website, we run Google Analytics and the Meta Pixel. The Meta Pixel is an advertising tool: it lets us measure our ads and show ads to people who have visited the site. It runs on the marketing website only and never inside the TeeUp application, so it never touches your instance data. See Cookies.

5. The TeeUp Chrome extension

The TeeUp Chrome extension does one thing: it lets you save an email from Gmail into TeeUp without copying and pasting it across. This section explains exactly what it touches.

What it stores

The extension stores a login token in your browser's local extension storage, so you stay signed in to TeeUp between browser sessions and don't have to log in every time you open Gmail. That token stays on your device. It is sent only to your own TeeUp instance, and only to authenticate you.

That is the only thing the extension retains.

What it sends, and only when you ask it to

When you click the TeeUp button on an email, the extension sends that email — sender, recipients, subject, date, body, and any attachments you include — to your TeeUp instance, where it's attached to the record you picked.

Nothing leaves Gmail unless you click that button. The extension does not read, scan, index or transmit the rest of your mailbox.

Emails you save are sent only to your TeeUp instance — never to any third party. If you self-host TeeUp, that instance is your own server and the email never reaches us at all. If we host TeeUp for you, the saved email is stored in your instance and handled exactly like everything else you put into TeeUp, as described in this policy.

What it does not do

  • It does not collect your browsing history, or run on any site other than Gmail and your TeeUp instance.
  • It does not track your behaviour, profile you, or run analytics.
  • It does not read your mailbox in the background or on a schedule.
  • It does not sell, rent or share your data with anyone.
  • It contains no advertising and no third-party trackers.

Permissions it asks for

  • Access to mail.google.com — to show the TeeUp button in Gmail and read the specific email you choose to save.
  • Access to your TeeUp instance — to send the saved email and authenticate you.
  • Storage — to hold the login token described above.

Google user data

The extension's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used solely to provide the save-to-TeeUp feature you invoke, and is never used for advertising, sold, or transferred to others except as needed to provide that feature.

Removing it

Uninstall the extension from chrome://extensions. The stored login token is deleted with it. Emails you already saved stay in TeeUp, because they're your records — delete them in TeeUp if you want them gone.

6. Who we share it with

We disclose personal information only to the service providers below, who are bound to use it solely to provide their service to us; to law enforcement or regulators where we are legally required to; and to a buyer if the business is sold, subject to this policy continuing to apply.

Our sub-processors

  • Supabase — database, authentication and file storage for hosted instances. Region: Southeast Asia (Singapore).
  • Railway — hosting for the core application. Region: Southeast Asia (Singapore).
  • Stripe — card payments and billing.
  • Google LLC — Google Analytics, on the marketing website only.
  • Meta Platforms, Inc. — Meta Pixel, on the marketing website only.
  • Flow VPS (Melbourne and Sydney) — only where you choose to have your instance deployed there.

Overseas disclosure

On our default hosting, your instance data is stored in Singapore — the records, documents and attachments you put into TeeUp, including your employees' personal and payroll information. It is not stored in Australia unless you arrange for us to deploy your instance elsewhere.

Supabase and Railway are United States companies. Even though your data sits in their Singapore region, a US-incorporated provider can be subject to US legal process, including requests reaching data held outside the United States.

Google and Meta process marketing-website analytics in the United States. Stripe processes payment data in the United States and Ireland.

TeeUp users can also sign in from anywhere in the world, and where a user accesses TeeUp from is where their activity data originates.

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. You should be aware that overseas recipients may be subject to foreign laws that compel disclosure to authorities in that country, and that Australian law may not be enforceable against them.

If your data must stay in Australia, tell us before you sign up. Our default hosting stores your instance data in Singapore, not Australia. We can deploy your instance to a server of your choosing instead — we recommend Flow VPS, whose Melbourne and Sydney data centres keep your instance data onshore.

7. Where it's stored and how it's protected

Where we host TeeUp for you, the core application runs on Railway and your instance data — records, documents and attachments — is stored in Supabase. Both run in their Southeast Asia (Singapore) region, so your data is held in Singapore rather than Australia. See section 6.

If you have data-residency requirements, we can deploy your instance to a server of your choice instead. We recommend Flow VPS and its Melbourne or Sydney data centres, which keep your instance data in Australia.

We encrypt data in transit with TLS and at rest, restrict access by role, and log administrative access.

No system is perfectly secure, and we can't guarantee absolute security — but we take reasonable steps to protect information from misuse, loss, unauthorised access, modification and disclosure.

8. How long we keep it

We keep your instance data for as long as your account is active. After you close your account we delete it within one month, except where we must keep records longer to meet legal or tax obligations — for example, records we are required to retain under Australian tax law. You can export everything you've put in at any time.

Export before you close your account. One month is a deliberately short window: after it passes your data is gone and we cannot recover it for you.

Server logs are kept for 12 months.

9. Cookies

The TeeUp application uses a session cookie to keep you signed in. It's essential to the product working and can't be switched off.

The public letsteeup.com marketing website additionally sets non-essential cookies:

  • Google Analytics (Google LLC) — measures how visitors find and move through the site. Data is processed in the United States.
  • Meta Pixel (Meta Platforms, Inc.) — measures the performance of our advertising and allows us to show ads to people who have visited the site. Data is processed in the United States.

Neither is necessary for the site to work, and neither runs inside the TeeUp application.

Neither loads until you accept them. We ask on your first visit, and until you choose "Accept" no analytics or advertising script is loaded and no such cookie is set. If you decline, nothing is loaded at all.

You can change your answer at any time using the button below, or by blocking cookies in your browser settings.

We also use Google Search Console. It reports on how letsteeup.com appears in Google Search using Google's own search data — it does not set cookies on your device or collect information about your visit, which is why it isn't listed above.

10. Your rights

Under the APPs you may ask us to give you access to the personal information we hold about you, correct it if it's wrong, or delete it where we're not required to keep it. You can also withdraw consent to marketing at any time.

Email hello@letsteeup.com and we'll respond within 14 days. We may need to verify who you are first.

If you're an employee of a TeeUp customer and want to access or correct your records, contact your employer — the data is theirs and they control it. We'll refer such requests to them.

11. Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

12. Changes to this policy

We may update this policy. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle your information, we'll tell you before it takes effect.

13. Contact and complaints

Questions, requests or complaints about privacy: hello@letsteeup.com, or write to the Privacy Officer, Garaj Pty Ltd, 84 Hotham Street, Preston VIC 3072, Australia.

We'll acknowledge your complaint and let you know the outcome. If you're not satisfied with how we handle it, you can escalate to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.