Privacy
Privacy Policy
A plain-English explanation of the information Lake & Line handles when you visit the website, contact us, use a client account or receive a managed website service.
Last updated: 4 October 2026
1. Who we are and what this covers
Lake & Line is a Canberra-based managed website business. This policy applies to information handled through the Lake & Line public website, enquiries, client portal, support conversations, managed website services, billing-related systems and related service communications.
For privacy questions, access or correction requests, or concerns about this policy, please contact Lake & Line through the website.
2. Information we handle
The information involved depends on how you interact with us. We may handle:
- Contact and business information — your name, business name, email address, optional phone number, current website address and the contents of an enquiry.
- Account and authentication information — email address, account/profile details, authenticated session information and account access status.
- Client, website and service information — business and website records, website URLs, service configuration, account status and analytics/monitoring configuration relevant to a managed site.
- Support information — support requests, messages, statuses, timestamps and optional image attachments.
- Billing and Change Credit records — Stripe customer, Checkout Session, subscription, invoice/payment status and provider-reference identifiers; Change Credit balances, purchases, use and refunds where applicable.
- Technical and analytics information — page URLs and paths, interaction events such as a contact-form submission or a phone-link click, and the technical information that analytics or hosting providers process when serving or receiving a request.
Our public enquiry form includes a hidden anti-spam field. It is used to help reject automated submissions and is not a normal visible form field.
3. How information is collected
We collect information directly when you complete a form, create or use a client account, use support, provide website materials, or communicate with us. We also receive relevant service and payment status information through the systems used to provide the service, and technical/analytics information when the website or portal is used.
4. How we use information
Lake & Line uses information to respond to enquiries; set up and operate client accounts and managed website services; provide support; administer billing and Change Credits; send transactional service communications; monitor managed websites; improve the website and service; protect the security and integrity of our systems; and meet applicable legal or record-keeping obligations.
We do not use the public enquiry form to obtain marketing consent, and we do not sell or trade personal information.
5. Payments and Stripe
Online billing, Checkout and the customer billing portal are provided by Stripe. Lake & Line receives the billing and subscription information needed to administer a client service, such as Stripe customer and subscription identifiers, payment or invoice status, billing period information and relevant refund references.
Lake & Line does not collect or store full payment-card numbers, CVCs or complete card details in its own application. Card entry and payment-method handling take place on Stripe-hosted pages and systems. Stripe processes information under its own terms and privacy practices; see the Stripe Privacy Center.
7. Managed-site monitoring
For websites where monitoring is enabled, Lake & Line records the site address and bounded check results: availability, HTTPS and a non-destructive contact-path check, together with timestamps, response time, HTTP status and a short diagnostic reason where relevant. The monitoring service does not retain raw page bodies or stack traces. Monitoring history is automatically removed after 90 days; the latest result for each check is kept while it remains relevant to the managed site.
8. Service providers and disclosures
We use specialist providers to operate the service. Depending on the interaction, information may be handled by:
- Supabase for database, authentication and private file storage;
- Stripe for payments, subscriptions, Checkout and the billing portal;
- Resend for transactional emails, including enquiry, account, support and payment-recovery communications;
- PostHog for the analytics described above;
- Netlify for hosting and server-side application functions; and
- Cloudflare for domain, DNS and security infrastructure.
We may also disclose information where reasonably necessary to provide the service, where you ask us to do so, to professional advisers, or where required or permitted by law. Providers may process information under their own terms, privacy practices and legal obligations, including for service delivery, security, fraud prevention and compliance.
Some providers may handle information from locations outside Australia or use global infrastructure. We do not represent that all information remains in Australia, and do not list specific overseas locations where this is not reliably established for the particular provider configuration.
9. Security and retention
We use reasonable technical and organisational safeguards appropriate to the service, including authenticated access controls, tenant-scoped database rules, HTTPS, a private support-image storage bucket and time-limited signed download links issued after account authorisation, and server-side credentials for privileged operations. No internet service can be guaranteed completely secure.
Except for the 90-day monitoring history described above, the application does not set a single fixed retention period for every category. We keep information for as long as reasonably necessary for the relevant service, support, security, legal or record-keeping purpose. Where an authorised client-account deletion workflow completes successfully, it is designed to remove the client's application account, authentication user and stored support images. It does not guarantee immediate removal from every system; separate provider records, including Stripe financial records, may be retained by the provider or where required by law.
10. Access, correction and complaints
You may ask us for access to, or correction of, personal information we hold about you by contacting Lake & Line. We may need to verify your identity and may have to retain or withhold limited information where permitted or required by law.
If you have a privacy concern, please tell us what happened and how we can contact you. We will review it and respond appropriately. If you remain dissatisfied, you may be able to contact the Office of the Australian Information Commissioner. This policy reflects Lake & Line’s current practices and does not make a representation about the legal application of the Privacy Act to every circumstance.
11. Children
Lake & Line’s services are intended for businesses and their authorised representatives, not for children. Please do not provide a child’s personal information unless it is necessary and you are authorised to do so.
12. Changes to this policy
We may update this policy as the service or applicable requirements change. The current version will be published on this page with its last-updated date.