Who we are
Nightshift Lane (ABN 45 280 632 686) is a digital operations partner based in Margaret River, Western Australia. We work with small businesses across Australia, mostly remotely.
The short version
We collect the minimum information needed to do our work for you. We never sell your data. We do not use behavioural tracking or advertising cookies. The longer detail below explains what data we hold, why, who else touches it, how long we keep it, and how you ask for it back or deleted.
What we collect, and why
We collect most personal information only when you provide it directly. We also collect a small amount of technical information automatically, as set out below:
- Free website audits at /audit: business name, website URL, email address, optional phone number, the industry you choose, and the audit results for your site. Used to run the audit, deliver the report, and follow up if you ask us to.
- Calls to our AI receptionist (currently +61 8 6615 7784): your caller ID (the phone number you called from), a transcript of what was said, a short AI-generated summary, any details you give (such as your name, email, business and reason for calling), any booking made, and the full call report our voice provider sends us. If a recording of the call is made, a link to it may be kept with that call report. Used so we can call you back, and to maintain the service.
- The chat assistant on this website: the messages you send and receive, and the page you were on. If you type an email address, phone number or website into the chat, we store that too and save it as an enquiry so we can follow up. A copy of the conversation is also kept in your own browser so it survives a page reload. Used to answer your questions and follow up if you leave contact details.
- Contact and enquiry forms: your name, email address, the content of your message, and any phone number, website, business name or plan details you include. Used to respond to you.
- Client engagements: business name, ABN, contact details, billing information, and technical credentials necessary to manage your services (domain registrar, DNS, hosting, mail provider, CMS, Google Business Profile). Used to do the work we have been engaged to do.
- The Night Watch newsletter: your email address, if you subscribe. Used to send the newsletter until you unsubscribe.
- Chat assistants and AI receptionists we run for our clients: when we run one of these for a client business, conversations and calls with that business's customers are stored in the same systems described here, on that client's behalf.
- Standard server logs: IP address, browser, page requested, timestamp. Used for security monitoring and to identify abuse. Not used for analytics or advertising.
We do not use behavioural tracking cookies, and we do not load third-party advertising or profiling scripts (no Google Analytics, no Meta Pixel, no LinkedIn Insight Tag). We do run privacy-friendly visitor measurement on this website. It records the page you viewed, the address of the page that referred you, the campaign tag on the link you followed if it carried one (for example, which website sent you), broad location (country only) and device type (mobile or desktop). It also stores a random id in your browser, not a cookie, so we can recognise a repeat visit to this site from the same browser; that id stays until you clear your browsing data. A separate, shorter-lived id is set per browser tab and clears when you close it. Neither id is shared with other websites, tied to your name or other identifying details, or used to build an advertising profile of you. Strictly necessary cookies may be set for session management when you interact with forms.
Third-party services we use
We run on a small number of trusted providers. Each has its own privacy policy linked below. We share only what each provider needs to do its job.
- Vercel hosts our website and our customers' websites, supplies the country-level signal behind the broad location noted above, and separately runs its own cookieless analytics script on this site. Vercel Privacy Policy.
- Cloudflare manages DNS, SSL, and DDoS protection. Standard DNS and edge logs. Cloudflare Privacy Policy.
- Neon hosts the Postgres database holding audit submissions, client data, AI receptionist call records, chat assistant conversations, and the page view records (including the browser ids) from our visitor measurement. Neon also hosts the separate archive database that older chat conversations are moved to, so no further provider is involved. Neon Privacy Policy.
- Resend delivers transactional email (audit reports, callback confirmations, client invoices) and holds the subscriber list for The Night Watch newsletter. Resend Privacy Policy.
- Stripe processes payments for paid services. Billing data is handled per their policy. Stripe Privacy Policy.
- Twilio provides the phone number for our AI receptionist and handles call routing. Twilio Privacy Policy.
- Vapi powers the voice and language understanding behind our AI receptionist. Vapi Privacy Policy.
- Anthropic provides the Claude language model used by our AI receptionist, the chat assistant on this website, and our internal tooling. We do not share customer data with Anthropic except where strictly necessary for the model to process a call or chat, and we use API endpoints that do not retain inputs for training. Anthropic Privacy Policy.
- Discord carries our internal team notifications. New audit requests, callback requests, enquiries captured by the chat assistant, and AI receptionist call summaries are posted to a private channel so we can respond quickly. These can include your name, email, phone number and a short excerpt of your message. Discord Privacy Policy.
- Google PageSpeed Insights receives the website address you submit for a free audit, to measure its performance. Google Privacy Policy.
We also run our own separate billing system, which receives your business name, email, website and project details when you start a paid service.
How long we keep data
- Audit submissions, enquiries and leads: we do not currently delete these automatically. They are kept until you ask us to delete them.
- AI receptionist call records: we do not currently delete these automatically. They are kept until you, or the client business you called, ask us to delete them.
- Client data: for the duration of the engagement plus 7 years after termination for Australian tax and legal compliance (the ATO record-keeping requirement).
- Server logs: kept by our hosting and network providers (Vercel and Cloudflare) under their own log retention settings.
- Page view records (including the browser ids): 12 months, then deleted.
- Chat assistant conversations: 6 months in the live database, then moved to a separate archive database we control, and deleted for good at 2 years from the date of the conversation. Enquiries captured from a chat, copies in our team notifications, and the copy in your own browser are not covered by this schedule.
- Newsletter subscriptions: until you unsubscribe.
You can request earlier deletion at any time. We will action within 30 days unless we are legally required to retain specific records (e.g., tax invoices).
Your rights under Australian law
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988. That means you can:
- Request access to the personal information we hold about you.
- Request correction of it if it is wrong.
- Make a privacy complaint to us, and if we have not handled it properly, to the Office of the Australian Information Commissioner. We would much rather hear about it from you first.
As our own policy, beyond what the law requires, we will also:
- Consider requests to delete your information where we no longer need the records (subject to legal retention requirements).
- Honour reasonable requests not to be referenced in future case studies.
To exercise any of these rights, email connect@nightshiftlane.com. We will respond within 30 days.
Data breaches
If a notifiable data breach affects your personal information, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, within the timeframes that scheme sets. Separately, as our own operational target, we aim to tell you within 72 hours of becoming aware of a breach that affects you.
Changes to this policy
When this policy changes materially, we update the "Last updated" date at the top of this page and email active clients. Older versions are available on request.
Contact
If you have questions about this privacy policy, how we handle your data, or want to exercise any of your rights above:
Nightshift Lane
ABN 45 280 632 686
connect@nightshiftlane.com
Margaret River, Western Australia