Privacy Policy

Last updated: February 5, 2026

1. Introduction

Ghostlytic ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our competitive intelligence monitoring service, currently offered as a private beta.

Ghostlytic operates from Australia. This policy is designed to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you are located in the European Economic Area, United Kingdom, or California, you may have additional rights described in Section 6 below.

2. Information We Collect

2.1 Information You Provide to Us

  • Account Information: Name, email address, business name, business location, phone number
  • Payment Information: Billing details (processed securely through a third-party payment processor; we do not store full card numbers)
  • Profile Information: Business category, monitoring preferences, competitor selections
  • Communications: Messages you send us, support requests, feedback
  • Contact Form Submissions: If you contact us through the website contact form, we collect your name, email address, phone number, and message content. We store a hashed (non-reversible) version of your IP address with each submission for security and spam-prevention purposes

2.2 Information We Collect Automatically

  • Usage Data: Pages visited, features used, time spent on the platform, interaction patterns
  • Device Information: Browser type, operating system, device identifiers, IP address
  • Location Data: Approximate geographic location based on IP address (not precise GPS)
  • Cookies and Tracking: Session data, preferences, authentication tokens (see Section 7 below)

2.3 Publicly Available Business Information We Collect

Ghostlytic monitors publicly available Google Maps business listings and public social media profiles of nearby businesses that you choose to track. We obtain this data through licensed third-party data providers, including Apify, SerpAPI, and Google Places. This may include:

  • Business names, addresses, categories, and public contact details listed on Google Maps
  • Google Maps ratings and review text, with the reviewer's identity stored in hashed, non-reversible form
  • Public social media posts and engagement metrics
  • Metrics we derive from this data, such as rating and review trends over time

Important: This data is limited to information that is publicly accessible online and that any individual could manually access. We do not access private accounts or non-public information, and we do not store the original, un-hashed identity of review authors.

3. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Monitor competitors, generate reports, send alerts and insights
  • Account Management: Create and maintain your account, process payments, manage subscriptions
  • Communication: Send transactional emails, service updates, respond to inquiries
  • Product Improvement: Analyze usage patterns, develop new features, enhance user experience
  • Security: Detect and prevent fraud, abuse, and security incidents
  • Legal Compliance: Comply with legal obligations, enforce our terms, protect our rights
  • Marketing: Send promotional emails (only with your consent, which you can withdraw at any time)

4. How We Share Your Information

We may share your information with:

4.1 Service Providers

  • Licensed Data Providers: Apify, SerpAPI, and Google Places, which we use to source the publicly available business information described in Section 2.3
  • Payment Processor: A third-party payment processor, to process subscription payments
  • Cloud Hosting Provider: To store data and host our infrastructure
  • Analytics Provider: To understand how users interact with our website and Service
  • Email Service Provider: To send transactional and, where consented, marketing emails

All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.2 Business Transfers

In the event of a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred to the successor entity.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal process (subpoenas, court orders)
  • Government investigations
  • Protecting the safety of our users or the public
  • Detecting or preventing fraud or security issues

4.4 Aggregated and De-identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you for research, marketing, or business purposes.

We do not sell your personal information.

5. Data Retention

We retain your personal information for as long as:

  • Your account is active
  • Necessary to provide you with the Service
  • Required by law or to resolve disputes
  • Needed for legitimate business purposes (e.g., fraud prevention)

After account deletion, we will delete or de-identify your personal information within a reasonable period of time, except where retention is required by law.

6. Your Privacy Rights

6.1 Rights for Australian Users

Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may:

  • Access: Request access to the personal information we hold about you
  • Correction: Ask us to correct inaccurate, out-of-date, or incomplete information
  • Complain: Lodge a complaint with us, or with the Office of the Australian Information Commissioner (OAIC), if you believe we have mishandled your personal information

6.2 Rights Under GDPR (for EU/EEA/UK Users)

If you are located in the European Economic Area or United Kingdom, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Restriction: Request we limit processing of your data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests or direct marketing
  • Withdraw Consent: Withdraw consent for data processing at any time

6.3 Rights Under CCPA (for California Residents)

If you are a California resident, you may have the following rights:

  • Know: Request disclosure of categories and specific pieces of personal information we collect
  • Delete: Request deletion of your personal information
  • Opt-Out: Opt out of the "sale" of personal information (Note: We do not sell personal information)
  • Non-Discrimination: Exercise your rights without discrimination

6.4 Exercising Your Rights

To exercise any of these rights, contact us at privacy@ghostlytic.com. We will respond within a reasonable time and, where applicable, within any timeframe required by law (for example, 30 days under GDPR or 45 days under CCPA).

7. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Essential Cookies: Necessary for authentication, security, and core functionality
  • Analytics Cookies: Understand how users interact with our Service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling essential cookies may impair Service functionality.

8. Data Security

We take reasonable technical and organizational measures to protect your data, including:

  • Encryption of data in transit (TLS)
  • Access controls and authentication mechanisms to limit who can access your data
  • Incident response procedures in the event of a data breach

However, no method of transmission over the internet, or method of electronic storage, is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

9. International Data Transfers

Ghostlytic operates from Australia. Some of our licensed data providers and service providers (see Section 4.1) may store or process data outside Australia.

Where we transfer personal information overseas, we take reasonable steps to ensure the overseas recipient handles your information consistently with the Australian Privacy Principles, as required under the Privacy Act 1988 (Cth).

10. Children's Privacy

Ghostlytic is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will promptly delete it.

11. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes via email or through a prominent notice on our Service.

Your continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related questions or requests, contact us at:

Email: privacy@ghostlytic.com
Entity: [LEGAL ENTITY NAME] (ABN [ABN])
Mail: [BUSINESS ADDRESS]

14. Privacy Complaints and Further Information

If you have concerns about how we handle your personal information, please contact us first at privacy@ghostlytic.com so we can try to resolve the issue directly.

If you are not satisfied with our response, Australian users may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au. Users in the EU/EEA or UK may contact their local data protection supervisory authority.