Legal

Privacy policy

How we handle personal information, written so you can check it rather than trust it. Last updated 19 September 2026.

SupportAndGo is operated by Fintech Development Pty Ltd (ABN 78 655 608 969, ACN 655 608 969), Level 1, 18–20 Knuckey Street, Darwin NT 0800, Australia. We are an Australian company bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

This policy covers the SupportAndGo website and the SupportAndGo service. It is written to be checkable: where it states a region, a retention period or a provider, that is what the running system does, and you are welcome to ask us to demonstrate any of it.

Two different kinds of information, handled differently

Information about you, our customer

The account you sign in with, which is a MyAndGo account: your name, your email address, and which desks you have access to. Billing details if you pay us. Anything you write to us.

Information your customers send to your desk

Everything that arrives at a support desk you operate — emails, attachments, phone numbers, whatever the person chose to write. This is yours, not ours. We hold it to run the service for you, we do not use it for anything else, and we do not sell it, share it or use it to train anyone's AI model.

What we do with it

  • Run the desk: receive messages, organise them into tickets, and let your agents answer them.
  • Classify and summarise incoming messages, and draft replies, using AI that runs in Sydney. A person approves anything that reaches a customer — the AI never sends on its own.
  • Send your replies to the people who wrote to you.
  • Keep an audit record of what happened to a ticket, which you can export.
  • Keep the service secure, diagnose faults, and meet our legal obligations.

We do not sell personal information. We do not use the contents of your desk for advertising. We do not use your customers' messages to train AI models.

Where it is stored

Every ticket, message and attachment is stored in Google Cloud's australia-southeast1 (Sydney) region — the database, the file storage and the service itself. The AI that reads a message to classify it runs in the same region, and the code refuses to call a model on any other endpoint rather than quietly falling back to one overseas.

Being hosted in Australia is not the same as being accountable under Australian law, which is why the operating company matters as much as the region. Ours is Australian; there is no foreign parent that could be compelled to produce your data. The longer argument, including the CLOUD Act, is here.

Who else handles the information

These are every third party that touches data in the course of running SupportAndGo, what each one does, and where it does it. We publish the list because our own data sovereignty page tells you to ask a vendor this question, and a vendor that will not answer it has told you something.

WhoWhat they doWhereWhat they see
Google Cloud Platform (Firestore, Cloud Run, Cloud Storage) Runs the service and stores every ticket, message and attachment australia-southeast1 (Sydney) All support content, including whatever a customer writes to a desk
Google Cloud Vertex AI (Gemini) Classifies incoming messages and drafts replies for a person to approve australia-southeast1 (Sydney) — pinned in code, and the service refuses to call a model on any other endpoint The text of the message being classified
MyAndGo (Fintech Development Pty Ltd) Sign-in and account identity for support agents; sends outbound email on our behalf australia-southeast1 (Sydney) Agent name and email address; the text of replies sent to your customers
Twilio SendGrid Receives inbound email addressed to a desk, and delivers some outbound email United States Email in transit: sender address, subject, body and attachments
Expo (push notifications) Delivers alerts to the SupportAndGo mobile app United States None. Notifications are content-free by design: no subject, no message text, no customer name or address ever leaves in an alert
Twilio (voice) Receives voicemail for desks that use a phone number United States The recording and the caller's number. Not enabled on any desk today
Google Analytics 4 Measures visits to this website United States Page paths and standard web analytics. No ticket content and no customer data

Three of these are overseas, and we would rather name them than imply otherwise. Email arrives and sometimes leaves through SendGrid in the United States; push notifications go through Expo in the United States but carry no content at all; voicemail would go through Twilio in the United States on any desk that enabled a phone number, and no desk has. Everything that is stored — every ticket, message, file and the AI that reads them — stays in Sydney. Under Australian Privacy Principle 8 we remain accountable for what an overseas provider does with information we pass to it.

How long we keep it

  • Your desk's tickets have no automatic expiry. A customer's support history is not scratch data, and deleting it on a timer would destroy the record you may need. It stays until you delete it or close your account.
  • Our own test traffic is deleted after 30 days.
  • When you delete something, deleted files remain recoverable from backup for seven days and are then permanently gone. We say so rather than claiming instant erasure, because instant erasure would not be true.
  • When you leave you can export everything, and we can issue a deletion certificate recording exactly what was erased and when, including the count of files.

Who can see your desk

Only the agents you have invited to that desk. Every ticket, message and file is scoped to your desk in the storage path itself, so a query from another desk has nowhere to go — the isolation is structural rather than a filter that could be forgotten.

Our own staff can access a desk to provide support, and every such access is recorded in an audit log naming who did it, which desk, and when. We would rather tell you the access exists and is logged than claim nobody can ever look.

Security

  • Traffic is encrypted in transit, and data is encrypted at rest by the storage platform.
  • Sign-in is handled by MyAndGo; we never see or store your password.
  • Every change to a ticket is recorded in an audit log you can export.
  • Files you receive are stored in a private bucket that refuses public access.

No system is perfect. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

Your choices

  • Access and correction. Ask us what we hold about you and we will tell you, and correct anything wrong.
  • Export. Your desk's data is yours; you can take it with you.
  • Deletion. You can delete your own account from the mobile app or by asking us. Deleting your access does not delete the desk's conversations, which belong to the business that operates it.
  • Analytics. This website uses Google Analytics to count visits. Your browser's Do Not Track and ad-blocking settings are respected; nothing we measure includes ticket content.

Complaints

Write to supportandgo@support.myandgo.com.au and we will respond. If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Changes

If this policy changes we will update the date at the top, and we will tell customers directly about a change that affects how their information is handled. Last updated 19 September 2026.

Common questions

Do you use our customers' messages to train AI?

No. Messages are sent to a Google Vertex AI model in Sydney to be classified and to draft replies, and are not used to train that model or any other. A person approves anything that reaches a customer.

Is any of our data stored outside Australia?

No. Every ticket, message and file is stored in Sydney, and the AI runs there too. Three providers handle data in transit or in passing from the United States — SendGrid for email, Expo for push notifications, which carry no content at all, and Twilio for voicemail on desks that enable a phone number. They are named in the table above.

Who at SupportAndGo can read our tickets?

The agents you invite, and our own staff when providing support. Staff access to a customer desk is recorded in an audit log naming who, which desk and when.

What happens to our data if we leave?

You export it, and we can issue a deletion certificate recording what was erased and when, including the count of stored files. Deleted files remain recoverable from backup for seven days before they are permanently gone.