Privacy Policy
What we collect, why we collect it, how it is protected, and your rights under the Privacy Act 1988 (Cth).
RecoverLater (Brisbane Device Preservation, ABN 54 640 598 412) ("we", "us") is committed to handling your personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth). This policy explains what we collect, why, how it is protected, and your rights.
What we collect
- The contents of your device — this is the most significant information we hold, so we state it first and plainly. While your device is in our custody we hold everything stored on it: photographs, messages, contacts, documents, app data, location history, and anything else present, including sensitive information such as health, financial, or identity records.
- Contact details — your name, email address, and phone number, so we can respond to your inquiry and keep you informed about your device. We no longer ask for a postal address when you mail a device in — you buy your own postage, so we have no need for it — and we collect one only if you later ask us to post the device back.
- Device information — device model, age, physical condition, software and lock state, what happened to it, and the data you hope to recover.
- Custody records — intake photographs of the device exterior, condition notes, and a device profile linked to your reference ID.
- Credentials, only where required and only at intake — if a recovery pathway needs a passcode or account credential, we collect it under a signed authority at intake, never through the website form. Please do not submit passcodes through the website.
Why we collect it
We collect this information solely to carry out the recovery analysis you have booked, perform or quote a recovery, preserve and monitor your device where no method exists yet, maintain an accurate chain-of-custody record, verify that you own or are lawfully authorised to act for the device, contact you when a recovery pathway becomes available, and meet our legal obligations. We do not sell personal information, and we do not use it for third-party marketing.
We access the contents of your device only to perform the analysis or recovery you have authorised, and only to the extent that work requires. We do not browse, copy, publish, or use your data for any other purpose. Data we recover is delivered to you, and working copies held on our systems are securely destroyed once you confirm you have received it — we do not keep a copy of your recovered data.
How your information is protected
- All website traffic, including the inquiry form, is encrypted in transit using TLS (HTTPS).
- Inquiry submissions and custody records are stored in access-controlled systems limited to personnel who need them to provide the service.
- Credentials collected at intake are stored separately from the device, encrypted at rest, and destroyed when no longer required for the authorised recovery.
- Devices in our custody are stored powered down in protected, access-limited storage, exactly as you sent them — still locked and encrypted — and are never accessed except under the service you have authorised.
Who we share it with
We never hand over the contents of your device to a third party for marketing, research, or any purpose other than the recovery you have authorised. The categories of recipient are:
- Specialist forensic laboratories and repair partners — only where a recovery pathway requires one, only the minimum device information necessary, and only after you approve that pathway and its quote.
- Postage — we no longer use a third-party shipping platform, and mail-in customers buy their own postage, so we disclose nothing to a carrier when your device travels to us. If you later ask us to post the device back, your name and address go on that parcel and are handled by Australia Post.
- Payment processing — payment for your recovery analysis is processed by Stripe. We never receive or store your card details. Stripe handles your payment and limited contact information under its own privacy policy.
- Website, email and inquiry infrastructure — our site and inquiry handling run on Cloudflare, and service emails are sent through Resend. These providers process contact and technical data on our behalf under their own security obligations.
- Advertising measurement — Google, as described under Cookies and analytics below.
- Where Australian law requires it — including in response to a lawful request from a law-enforcement or regulatory body.
Overseas disclosure
Some of the providers above are located outside Australia, or store data outside Australia, including in the United States. This applies to Stripe, Cloudflare, Resend, and Google. Where we disclose personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. Devices themselves, and their contents, remain physically in our custody in Queensland; we do not send devices or their recovered contents overseas without telling you first and obtaining your approval as part of the quoted pathway.
Data retention
Inquiries that do not proceed are deleted within 12 months. Custody records — your reference ID, intake photographs, and condition report — are retained for as long as we hold your device and for 7 years after it is returned, as they form the chain-of-custody evidence you may rely on. Credentials collected at intake are destroyed as soon as the authorised recovery is complete or you end the service, whichever comes first. Your device and its contents are held until recovery, return, or your request, and are returned to you on request at any time as set out in our Terms & Custody. You may request earlier deletion of an inquiry at any time.
If something goes wrong: data breach notification
We hold devices containing a great deal of personal information, so we treat any suspected loss of, or unauthorised access to, that information seriously. If we suspect a breach we act immediately to contain it and assess it promptly — within 30 days at the outside. If we conclude the breach is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as soon as practicable, telling you what happened, what information was involved, and what you can do in response, as required by the Notifiable Data Breaches scheme.
Access, correction and complaints
You may request access to, or correction of, the personal information we hold about you by emailing contact@recoverlater.com.au or calling 0423 056 889. If you believe we have breached the Australian Privacy Principles, contact us first and we will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Cookies and analytics
This website does not use local storage for display preferences. If you start a checkout, the email address you entered is held briefly in your browser's session storage — on your device only — so the payment confirmation page can report the conversion; it is cleared once used. When our Google search ads are running and you arrive here by clicking one of them, Google Ads conversion measurement may set cookies so we can tell that the ad led to an inquiry or a booking. If you then submit an inquiry or book a recovery analysis, we also send Google a hashed (scrambled and not reversible by us or by Google) version of the email address you entered, which Google uses only to match that conversion to the ad click when cookies are blocked — a feature Google calls enhanced conversions. Your readable email address never leaves this site for advertising purposes. This measurement tells us which searches our customers came from; it does not give us your browsing history, and we do not use cross-site trackers of our own. You can read how Google handles this data in the Google advertising privacy notice.
If you call the number shown in one of our Google search ads, that number may be a Google forwarding number rather than our own. Google then tells us the time, length and outcome of the call, and the number you called from, so we can tell which search led to the call. We do not record the audio of your call. Calling the number published on this site, rather than one shown in an ad, does not involve Google at all.