Privacy Policy
Last updated: 26 August 2026
1. Who we are
Vontra (“we”, “us”) provides software for chauffeur and limousine operators at vontra.au. This policy explains how we handle personal information under the Australian Privacy Principles in the Privacy Act 1988 (Cth).
2. Two kinds of people use Vontra
Operators — the transport businesses and their staff who hold Vontra accounts. For them, we are the organisation collecting personal information (name, email, business details, usage).
Operators’ customers and chauffeurs — people whose details an operator puts into its workspace (passengers, booking contacts, drivers). We process that information on the operator’s behalf and under its instructions; the operator is responsible for collecting it lawfully. If you are a passenger with a question about your data, contact the transport company you booked with first — we will help them help you.
3. What we collect
Account details (name, email, password hash), organisation details (company name, contact details, pricing, fleet), the CRM data operators enter or their customers submit (contacts, quotes, bookings, messages, payment status), call and messaging records generated through the platform (including transcripts where AI phone or chat agents are used), device push-notification subscriptions where enabled, and technical logs needed to run and secure the service. We do not store full card numbers — card payments are handled by Stripe.
4. How we use it
To provide and improve the platform: producing quotes, managing bookings and dispatch, sending the emails, SMS and push notifications operators configure, powering AI-assisted features, billing subscriptions, providing support, and keeping the service secure. We do not sell personal information, and we do not use one operator’s business data to benefit another.
5. Service providers
We use a small set of processors to run Vontra: Vercel (hosting), Neon (database), Stripe (payments and billing), Twilio (SMS and voice), Resend (email), Google Maps Platform (address and route lookups) and Anthropic (AI features). Some of these providers store or process data outside Australia, including in the United States; we take reasonable steps to ensure they protect it consistently with the Australian Privacy Principles. Each processes only what its role requires — for example, message content goes to Twilio or Resend to be delivered, and text used by AI features goes to Anthropic to generate the response.
6. Cookies and sessions
We use essential cookies to keep you signed in and the platform working. We do not run third-party advertising trackers. Aggregate, privacy-respecting performance analytics may be collected to keep the product fast.
7. Security and retention
Data is encrypted in transit, passwords are stored only as salted hashes, access links use unguessable tokens, and each operator’s workspace is isolated. We keep personal information while the relevant account is active and for a short period afterwards for export and legal purposes (30 days after termination for workspace data), then delete or de-identify it. No system is perfectly secure; if a data breach is likely to cause serious harm we will notify affected people and the OAIC as the law requires.
8. Your rights
You can ask us to access or correct personal information we hold about you, or to delete your account. Operators can export their workspace data from the platform at any time. If you have a privacy concern, contact us below — if you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
9. Changes and contact
We will post updates to this policy here and note material changes in the product. Questions or requests: notifications@vontra.au. See also our Terms of Service.