Privacy Policy
Last updated 2 September 2026
This policy explains how MIA FreightOS (“we”, “us”) handles personal information when you visit our website or use the MIA FreightOS platform. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It is written in plain language rather than as legal advice.
1. Who is responsible for your data
For the marketing website, beta-tester applications and platform accounts, MIA FreightOS is the entity responsible for the personal information described below. When a transport operator uses the platform, that operator controls the operational records it enters about its own staff, drivers and customers, and we handle those records on the operator’s behalf as a service provider.
2. What we collect
- Account information: name, email address, password hash (we never see your password), role and the organisation you belong to.
- Organisation information: trading name, ABN, business contact details and business addresses.
- Operational records you enter: customers and their contacts, drivers and licence details, vehicles and registrations, jobs, pickup and delivery addresses, consignment details, proof of delivery (photos, signer name, timestamp), incident reports, maintenance and compliance records, quotes and invoices.
- Safety and audit records: acceptance of the safety and legal acknowledgement (user, organisation, version, timestamp, browser/device details) and audit entries for critical changes to jobs and invoices.
- Billing information: plan, subscription status, trial dates and payment-provider identifiers. We do not collect or store card numbers — see section 5.
- Beta-tester applications: name, Google-account email, optional company and role, Android device model, and your consent records.
- Technical information: IP address (stored only as a one-way hash for spam and rate-limit protection on public forms), browser type, pages requested and error diagnostics.
- Marketing attribution: campaign parameters such as utm_source, utm_medium, utm_campaign, a referral code or an advertising click identifier, stored in your browser for the current session.
We do not ask for government identifiers beyond what an operator chooses to record for its own compliance obligations (for example driver licence details), and we do not seek sensitive information such as health records unless an operator enters it as part of a driver medical or incident record.
3. Why we use it
To create and secure accounts; to run the dispatch, fleet, driver, customer, quoting, invoicing, document, maintenance and compliance features you ask for; to keep safety, acknowledgement and audit records; to provide support; to manage subscriptions and issue tax invoices; to protect the service against abuse, spam and fraud; to contact beta-test applicants about the closed test they applied for; and to measure the effectiveness of our advertising where you have consented.
4. How data is separated
Every operational record is bound to an organisation. Database-level row security restricts access to members of that organisation, further restricts drivers to their assigned work, and restricts customer-portal users to their own bookings. Beta-tester applications are not readable by the public or by other applicants; only authorised administrators can view them. Uploaded documents and proof-of-delivery files are stored in a private bucket that cannot be browsed publicly.
5. Payments
Subscription payments are processed by Stripe using Stripe’s hosted checkout and customer portal. Card details are entered on Stripe’s pages and never pass through or get stored by MIA FreightOS. We keep only the subscription status, plan, billing dates and the identifiers Stripe returns. Stripe handles that payment data as its own controller under its privacy policy.
6. Service providers we use
- Cloud application and database hosting, including authentication and private file storage, for the platform itself.
- Stripe, for subscription payments and the billing portal.
- Email delivery and support handling for messages you send us.
- TikTok, for advertising measurement — only where you have given marketing consent.
We use these providers only to deliver the service. We do not sell personal information, and we do not disclose it to third parties for their own marketing.
7. Overseas and cloud processing
Our hosting, payment and advertising providers are global businesses, so personal information may be stored or processed outside Australia, including in the United States and the European Union. Where that happens we rely on providers that offer contractual protections and security practices consistent with the APPs. By using the platform you acknowledge that this overseas processing occurs.
8. Security
Data is transmitted over TLS and stored in managed cloud infrastructure with encryption at rest. Access is controlled by authentication, role-based permissions and database row-level security. Administrative credentials and API secrets are held as server-side environment secrets and never included in the browser application, in page source or in logs. Critical changes are recorded in an audit log. No system is perfectly secure; if a data breach is likely to cause serious harm we will act under the Notifiable Data Breaches scheme.
9. Retention and destruction
- Operational records stay available while your organisation is open, so you can meet your own record-keeping obligations.
- After an organisation is closed we delete or de-identify its records within 12 months, except where a longer period is required by law (for example tax and financial records, generally 5 years, and safety or compliance records for the period required by transport law).
- Beta-tester applications are kept for up to 12 months after the closed test ends, then deleted.
- Hashed IP records used for spam protection are kept for up to 30 days.
- Billing and audit event records are retained for 7 years for financial and accountability purposes.
10. Access, correction and deletion
You can view and correct most of your own information inside the app. Organisation owners can request an export or deletion of their organisation’s data, and individuals can ask us for access to, or correction of, the personal information we hold about them. Email miafreight@outlook.com and we will respond within 30 days. If you ask a transport operator’s records to be changed and we hold them on that operator’s behalf, we will refer you to that operator.
11. Marketing and consent
We only send marketing or beta-test communications where you have asked for them or opted in, and every message includes an unsubscribe option. Beta-test applicants are contacted about that test only. You can withdraw consent at any time by emailing us or using the unsubscribe link.
12. Cookies and analytics
We use essential browser storage to keep you signed in and to remember your cookie choice — the platform cannot work without it. Non-essential marketing and analytics tags are not loaded until you accept them in the consent bar. If you choose “Essential only”, or ignore the bar, no advertising or analytics pixel is loaded. You can change your mind by clearing your site data and choosing again. Campaign parameters used to attribute a visit are stored only for the current browser session.
13. Complaints
If you think we have mishandled your personal information, email miafreight@outlook.com with the details. We will acknowledge your complaint within 5 business days and give a written response within 30 days. If you are not satisfied you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
14. Changes and contact
We will update this page when our handling of personal information changes and will change the “last updated” date. Questions about privacy go to miafreight@outlook.com, which is our only contact channel for privacy requests.