Legal
How we handle personal information, written so you can check it rather than trust it. Last updated 19 September 2026.
SupportAndGo is operated by Fintech Development Pty Ltd (ABN 78 655 608 969, ACN 655 608 969), Level 1, 18–20 Knuckey Street, Darwin NT 0800, Australia. We are an Australian company bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
This policy covers the SupportAndGo website and the SupportAndGo service. It is written to be checkable: where it states a region, a retention period or a provider, that is what the running system does, and you are welcome to ask us to demonstrate any of it.
The account you sign in with, which is a MyAndGo account: your name, your email address, and which desks you have access to. Billing details if you pay us. Anything you write to us.
Everything that arrives at a support desk you operate — emails, attachments, phone numbers, whatever the person chose to write. This is yours, not ours. We hold it to run the service for you, we do not use it for anything else, and we do not sell it, share it or use it to train anyone's AI model.
We do not sell personal information. We do not use the contents of your desk for advertising. We do not use your customers' messages to train AI models.
Every ticket, message and attachment is stored in Google Cloud's australia-southeast1 (Sydney) region — the database, the file storage and the service itself. The AI that reads a message to classify it runs in the same region, and the code refuses to call a model on any other endpoint rather than quietly falling back to one overseas.
Being hosted in Australia is not the same as being accountable under Australian law, which is why the operating company matters as much as the region. Ours is Australian; there is no foreign parent that could be compelled to produce your data. The longer argument, including the CLOUD Act, is here.
These are every third party that touches data in the course of running SupportAndGo, what each one does, and where it does it. We publish the list because our own data sovereignty page tells you to ask a vendor this question, and a vendor that will not answer it has told you something.
| Who | What they do | Where | What they see |
|---|---|---|---|
| Google Cloud Platform (Firestore, Cloud Run, Cloud Storage) | Runs the service and stores every ticket, message and attachment | australia-southeast1 (Sydney) | All support content, including whatever a customer writes to a desk |
| Google Cloud Vertex AI (Gemini) | Classifies incoming messages and drafts replies for a person to approve | australia-southeast1 (Sydney) — pinned in code, and the service refuses to call a model on any other endpoint | The text of the message being classified |
| MyAndGo (Fintech Development Pty Ltd) | Sign-in and account identity for support agents; sends outbound email on our behalf | australia-southeast1 (Sydney) | Agent name and email address; the text of replies sent to your customers |
| Twilio SendGrid | Receives inbound email addressed to a desk, and delivers some outbound email | United States | Email in transit: sender address, subject, body and attachments |
| Expo (push notifications) | Delivers alerts to the SupportAndGo mobile app | United States | None. Notifications are content-free by design: no subject, no message text, no customer name or address ever leaves in an alert |
| Twilio (voice) | Receives voicemail for desks that use a phone number | United States | The recording and the caller's number. Not enabled on any desk today |
| Google Analytics 4 | Measures visits to this website | United States | Page paths and standard web analytics. No ticket content and no customer data |
Three of these are overseas, and we would rather name them than imply otherwise. Email arrives and sometimes leaves through SendGrid in the United States; push notifications go through Expo in the United States but carry no content at all; voicemail would go through Twilio in the United States on any desk that enabled a phone number, and no desk has. Everything that is stored — every ticket, message, file and the AI that reads them — stays in Sydney. Under Australian Privacy Principle 8 we remain accountable for what an overseas provider does with information we pass to it.
Only the agents you have invited to that desk. Every ticket, message and file is scoped to your desk in the storage path itself, so a query from another desk has nowhere to go — the isolation is structural rather than a filter that could be forgotten.
Our own staff can access a desk to provide support, and every such access is recorded in an audit log naming who did it, which desk, and when. We would rather tell you the access exists and is logged than claim nobody can ever look.
No system is perfect. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
Write to supportandgo@support.myandgo.com.au and we will respond. If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
If this policy changes we will update the date at the top, and we will tell customers directly about a change that affects how their information is handled. Last updated 19 September 2026.
No. Messages are sent to a Google Vertex AI model in Sydney to be classified and to draft replies, and are not used to train that model or any other. A person approves anything that reaches a customer.
No. Every ticket, message and file is stored in Sydney, and the AI runs there too. Three providers handle data in transit or in passing from the United States — SendGrid for email, Expo for push notifications, which carry no content at all, and Twilio for voicemail on desks that enable a phone number. They are named in the table above.
The agents you invite, and our own staff when providing support. Staff access to a customer desk is recorded in an audit log naming who, which desk and when.
You export it, and we can issue a deletion certificate recording what was erased and when, including the count of stored files. Deleted files remain recoverable from backup for seven days before they are permanently gone.