OnDemandHire

Privacy Policy

Last updated: 11/08/2026

This Privacy Policy explains how On Demand Hire collects, holds, uses, and discloses personal information through the On Demand Hire website, web app, mobile application, and related services.

On Demand Hire is the name of the platform and its apps. The platform is operated by ODH Pty Ltd (ABN 19 697 863 586), and in this policy "On Demand Hire", "we", "us", and "our" mean ODH Pty Ltd. ODH Pty Ltd is the entity responsible for the personal information described in this policy.

On Demand Hire is built for Australian construction hiring. We handle personal information in line with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and other Australian privacy and communications laws where they apply.

1. Who this policy covers

This policy applies to Worker Users, Business Users, business account owners and admins, applicants, accepted workers, invited business members, and anyone who contacts us about the Platform.

The Platform connects businesses and workers. On Demand Hire is not an employer, recruitment agency, labour hire provider, payroll provider, or party to any direct engagement between users.

2. Personal information we collect

  • Account information, such as name, email address, active role, login provider, account identifiers, authentication status, email confirmation status, confirmation that you meet the Platform minimum age requirement, and provider-owned Apple or Google identity details. Passwords are handled through our authentication provider.
  • Worker profile information, such as phone number, date of birth, profile photo, location, skills, certifications, primary languages, preferred working days, work experience, work status, ratings, reviews, saved jobs, job applications, accepted jobs, credential evidence images and metadata you choose to upload, and worker-approved credential evidence share request records.
  • Resume information, where you choose to upload a resume or similar work-history document, such as the file itself, file name, file type, file size, whether you have chosen to make the resume visible to Business Users, and the collection notice version and time you consented to the upload.
  • Business information, such as business name, ABN, business account membership, owner/admin role, business invitations, admin seats, paused admin status, contact title, operating location, business phone, website, profile image, job listings, saved workers, applications, accepted jobs, ratings, and reviews.
  • Platform activity, such as job posts, drafts, direct job-share events and monthly usage, saved worker and saved job records, applications, application outcomes, chat messages, read receipts, hidden chat state, notification deliveries, support requests, account deletion requests, safety or moderation records, reports you make about a job, profile, or business, reports made about your job, profile, or business, and records of announcements shown to you and dismissed by you.
  • Referral and campaign information, such as your referral code, the referral code used when you signed up, who referred you, the campaign a referral belongs to, referral status and the time a referral succeeded, review decisions and reasons recorded by our staff, automated fraud-risk flags, and any record making a referrer ineligible for a campaign reward.
  • Account status and administration records, such as whether your account is active or suspended, the time and reason for a suspension, records of job listings removed by On Demand Hire and the reason given, plans granted or changed directly by our staff, and audit records of administrative actions taken on your account or content.
  • Subscription information needed to manage Business User plans, such as owner-tier state, product identifiers, entitlement status, billing platform (iOS, Android, or web), and renewal/cancellation status made available by RevenueCat and supported app-store payment systems, by RevenueCat Web Billing and its payment processor Stripe for purchases made on the web, and subscription sync events.
  • Web and authentication information, such as web signup/onboarding state, a short-lived OAuth signup intent cookie, a referral cookie set when you open a referral link so the referral can be credited if you create an account, web email confirmation, password reset flow state, and Firebase password bridge migration markers where a controlled migration bridge is enabled for marked accounts.
  • Device and technical information, such as device push tokens, platform type, app or web version, browser/session information needed to keep you signed in, the IP address and browser user agent recorded when a Business User opens an approved worker credential evidence file, basic diagnostic data, and notification preferences.
  • Location information you provide or select, such as suburb, postcode, state, country, and related coordinates used for matching, distance display, job alerts, and profile discovery. The current Platform does not continuously track your live GPS location.
  • Sensitive information only where you choose to provide it, such as information contained in support messages. Do not upload driver licences, passports, Medicare cards, TFN documents, bank details, payslips, police checks, Working with Children Check documents, medical records, third-party information, or unrelated identity documents as credential evidence.

3. How we collect personal information

  • Directly from you when you create an account, complete onboarding, complete or update a profile, post a job, apply for a job, upload images or documents, send messages, change preferences, request support, or delete your account.
  • From Apple or Google if you choose social sign-in, such as verified email and identity details those providers make available to the Platform.
  • From app-store and subscription providers, including RevenueCat, Apple, and Google, and from RevenueCat Web Billing and its payment processor Stripe for purchases made on the web, when a business owner opens or manages a plan and those providers make entitlement or purchase status available to the Platform.
  • From a referral link when you open one, through a cookie that records the referral code on your device so the referral can be credited if you go on to create an account.
  • From other users when they post jobs, review applicants, share listings directly with workers, accept or reject applications, send messages, complete jobs, leave reviews, invite business members, report a job or profile to us, refer you to the Platform, or interact with your profile through normal Platform features.
  • Automatically from the app, web app, and backend when needed to authenticate users, maintain sessions, complete web email confirmation, carry OAuth signup intent, deliver notifications, protect security, operate chat, and keep audit records.

4. Why we use personal information

  • Create, authenticate, manage, and secure user accounts across the mobile app, web app, and related services.
  • Confirm that account holders meet the Platform minimum age requirement, including using a Worker User date of birth during onboarding.
  • Set up worker profiles, business profiles, business memberships, business invitations, business admin seats, and business ABN checks.
  • Show relevant job listings, worker profiles, applicant details, business profiles, ratings, reviews, public business summaries, and accepted-job information to the users who need that information to use the Platform.
  • Process job posts, saved jobs, saved workers, direct job-share credits, applications, acceptances, rejections, completed-job status, chat access, and reviews.
  • Store worker credential evidence for the worker, record credential metadata and consent details, show Business Users credential summaries, and allow application-specific evidence access only when a Worker User approves a Business User request.
  • Send service messages, in-app notifications, notification-bell updates, and push notifications about account activity, applications, accepted jobs, chat messages, profile views, direct job shares, nearby job matches, completion reminders, and review prompts.
  • Manage Business User subscriptions, entitlement state, owner-only plan controls, plan limits, active job-listing limits, saved-worker limits, direct-share monthly limits, and business member seat limits.
  • Support controlled migration and account-continuity flows, including Firebase password bridge checks for marked migrated users where that bridge is enabled.
  • Run referral programs and campaigns, credit a referral to the right referrer, work out whether a referral has succeeded, count and rank referrals for a campaign, apply automated fraud-risk checks, review flagged or invalid referrals, and contact reward recipients.
  • Show in-app and on-site announcements to the relevant audience, and remember which announcements you have dismissed so the same announcement is not shown again.
  • Support users, respond to complaints, investigate misuse, review reports made about jobs, profiles, or businesses, remove or take down listings and content, suspend or restrict accounts, block signups using disposable email addresses, moderate unsafe or unlawful content, enforce our Terms, and protect users and the Platform.
  • Keep audit records of administrative actions taken by On Demand Hire staff, including account suspensions and reactivations, listing removals, moderation outcomes, subscription grants, and referral review decisions.
  • Maintain, test, improve, and troubleshoot the Platform, including security, audit, backup, aggregate platform statistics, de-identified reporting, and product-quality checks.
  • Comply with legal obligations, regulatory requests, court orders, law enforcement requests, dispute resolution, and business record requirements.

5. Visibility to other users

The Platform works by showing some user information to other users. Worker profile and hiring-safe details may be shown to active Business Users so they can discover workers, save workers, share open listings directly with visible workers, and review applicants. Business profile, public business summary, rating, review, and job information may be shown to Worker Users so they can decide whether to apply for or accept work.

Worker credential evidence files are not public. Raw files and storage paths are visible to the worker who uploaded them. Business Users see credential summaries on profiles and applicant screens, and may receive short-lived signed access to a specific evidence file only after the Worker User approves that request for a specific application. When a Business User opens an approved file, we record who opened it and when.

A resume you upload is private by default. It is shown to Business Users only if you choose to make it visible on your profile, and you can change that choice or delete the resume at any time.

Chat messages, read receipts, and accepted-job information are visible to the participants in the relevant job thread and may be used by On Demand Hire for support, safety, legal, and moderation purposes. Public review surfaces are limited to rating and review information intended to be shown in the marketplace.

Profile-view notifications are anonymous to workers. Direct job-share notifications and in-app update rows identify the relevant listing and business context needed for the worker to view the shared job.

6. Who we disclose personal information to

  • Supabase and related hosting, database, authentication, storage, Edge Function, Realtime, and security services.
  • Expo and mobile platform services needed to register device tokens and deliver push notifications.
  • RevenueCat and supported app-store payment systems, including Apple and Google, and RevenueCat Web Billing together with its payment processor Stripe for subscriptions purchased on the web, when needed to take payment, calculate tax, and manage Business User subscriptions and entitlement state.
  • Email delivery and email marketing providers used to send account and service emails, business invitations, and any marketing messages we are permitted to send.
  • Apple and Google when you use their sign-in services, app-store services, or device platform services.
  • Firebase only where a controlled migration bridge is enabled for marked migrated users and the bridge needs to verify an existing Firebase password server-side before setting the corresponding Supabase password.
  • A related company, purchaser, or successor if On Demand Hire restructures, or if the Platform or the business that operates it is transferred. Personal information may be transferred as part of that change, and the recipient must continue to handle it in line with this policy and the Australian Privacy Principles.
  • Professional advisers, insurers, auditors, dispute-resolution providers, regulators, courts, law enforcement bodies, or government agencies where reasonably necessary or legally required.
  • Service providers who help us operate, secure, support, test, or improve the Platform, under appropriate confidentiality and security expectations.

7. Overseas disclosures

Some service providers may store or process personal information outside Australia. Where practicable, this may include the United States and other countries where our authentication, cloud infrastructure, storage, notification, payment, email, app-store, analytics, support, or mobile platform providers operate.

When we disclose personal information overseas, we take reasonable steps required by the Australian Privacy Principles to protect that information, unless an exception applies.

8. Matching and automated decisions

We use profile, job, application, notification, and location information to help match workers with relevant jobs, surface worker profiles to businesses, rank and filter search results, and send job alerts or reminders. These features support marketplace discovery and workflow.

The current Platform does not use automated systems to make final hiring, employment, pay, safety, insurance, or legal-status decisions about users. Business Users and Worker Users remain responsible for direct engagement decisions and off-platform work arrangements.

Some Platform outcomes are decided automatically. A referral is recorded as successful automatically when the person you referred completes their worker profile within the campaign period. Automated checks may also flag a referral as higher risk, for example where two accounts share a phone number or where an unusual number of referrals succeed in a short period. Those flags are advisory only: no referral is rejected automatically, and a person always makes the final decision on whether a referral counts or a reward is awarded.

Account suspension, restriction, and the removal of a job listing or other content are decisions made by On Demand Hire staff, not by automated systems. Signups using disposable email addresses may be blocked automatically; you can contact us if you believe an address was blocked in error.

9. Referral programs and campaigns

On Demand Hire may run referral programs and time-limited campaigns. When you open a referral link, we store the referral code in a cookie on your device so the referral can be credited if you create an account. If you sign up, we record who referred you, the code used, the campaign the signup falls within, and the time of signup. That record is created once and the underlying facts are not changed afterwards.

We use this information to work out whether a referral has succeeded, to count and rank referrals within a campaign, to run automated fraud-risk checks, and to review referrals before a reward is awarded. Those checks may compare phone numbers across accounts and look at the timing and volume of referrals.

Your referral counts are shown only to you. There is no public leaderboard, and other users cannot see your referral activity, your ranking, or who referred you. On Demand Hire staff can see referrer rankings and the name, email address, signup time, and status of referred people in an internal console used to confirm or reject referrals.

Where a campaign offers a reward, we may use your contact details to confirm eligibility and arrange the reward. Rewards are arranged outside the Platform. Referral and campaign records are kept after a campaign ends so we can evidence how rewards were decided and handle any dispute.

10. Communications and marketing

We may send service communications about your account, security, applications, jobs, chats, notifications, reviews, support, subscriptions, business invitations, direct job shares, referrals, and changes to the Platform. These are part of operating the Platform.

We may also show announcements to signed-in users in the app and on the web, including news about features, campaigns, and promotions. Announcements can be dismissed where a dismiss control is shown, and we record that dismissal.

If we send marketing or promotional electronic messages, we will do so with consent or where otherwise permitted by Australian law, identify the sender, and provide a functional unsubscribe method where required by the Spam Act 2003 (Cth). You can also manage notification preferences in the app where available.

11. Security

We take reasonable steps, including technical and organisational measures, to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. This includes role-based access controls, Supabase row-level security, private storage for worker credential evidence, signed preview URLs where used, expiring worker-approved share access, revocation controls, account authentication controls, internal procedures, and incident-response practices.

No mobile app, web app, network, or storage system can be guaranteed to be completely secure. Users should keep login credentials secure and only upload information they are comfortable using for the Platform purpose.

12. Retention and account deletion

We keep personal information while it is needed for the purposes described in this policy, including account operation, marketplace records, legal compliance, dispute handling, security, backup, audit, subscription records, and legitimate business needs.

Worker-deleted credential evidence files are removed from storage and metadata promptly. Account deletion removes worker credential evidence files under that worker storage folder before the account is deleted. If prohibited documents are identified, they may be deleted promptly.

Active credential evidence is marked for review at least annually. Automated retention cleanup is deferred until upload volume justifies it, but On Demand Hire maintains a manual monthly retention checklist before launch.

When personal information is no longer needed, we take reasonable steps to delete or de-identify it, unless we are required or permitted to retain it. Account deletion requests can be made in the app, but some records may be retained where needed for legal, security, dispute, audit, backup, subscription, migration, or Platform-integrity reasons.

Some records are deliberately kept after an account is deleted. These include the ABN, business name, and aggregate rating history of a deleted business account, together with re-registration cooldown records, so that ratings and limits cannot be reset by deleting and recreating an account; referral and campaign records, so we can evidence how rewards were decided; reports, moderation decisions, and takedown records; and audit records of administrative actions taken by our staff.

13. Access and correction

You can update many profile details in the app or web app where those controls are available. You may request access to personal information we hold about you, or ask us to correct it, by contacting info@ondemandhire.com.au.

We may need to verify your identity before actioning a request. If we refuse access or correction where Australian privacy law allows, we will explain why and tell you how to complain.

14. Data breaches

If we suspect a data breach, we will contain it, assess it expeditiously and generally within 30 days where practicable, and take reasonable steps to reduce the risk of harm. Where the Notifiable Data Breaches scheme requires it, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable after deciding an eligible data breach has occurred.

15. Complaints and contact

For privacy questions, access or correction requests, or privacy complaints, contact info@ondemandhire.com.au. Please include enough detail for us to understand and investigate the issue.

We aim to respond to privacy complaints within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.

16. Changes to this policy

We may update this Privacy Policy as the Platform changes or legal requirements develop. The latest version will be available through the app or website. Continued use of the Platform after an update means the updated policy applies from its stated effective date.