Privacy policy

How we handle your information.

Last updated 17 August 2026 · Applies to archivebridge.app and app.archivebridge.app

Who we are

ArchiveBridge is operated by ArchiveBridge Pty Ltd (ABN 68 701 459 261), an Australian company. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Questions or requests: hello@archivebridge.app.

What we collect

Account information — your name, work email, company, and (for partner applications) job title, phone and website. Provided by you at signup.

Microsoft 365 metadata — when your Global Administrator grants consent, we read file and site metadata from your tenant: names, paths, sizes, timestamps and content hashes. This is what scans, backup verification and the console are built on.

File content, in transit— during backup, archiving and restore, file content passes through the processing region you selected between Microsoft 365 and the storage bucket configured for your account. Content is transferred over TLS, verified with SHA-256, and stored only in that bucket — the processing worker does not intentionally retain it and we don’t keep a separate copy of your files.

Billing information — usage metering (terabytes protected per day) and payment records. Card details are collected and stored by our payment provider, Airwallex; we never see or store full card numbers.

Website analytics — our sites use Google (advertising measurement) and Vercel Analytics. These collect standard usage and device information via cookies or similar identifiers.

How we use it

To provide the service (scanning, backup, archiving, restore, the console), to bill for it, to send service email (run failures, weekly digests, receipts, account notices), to respond to support requests, and to measure whether our advertising works. We don’t sell personal information, and we don’t use your file content or metadata for anything except operating the service you configured.

Where it lives

Our service control plane, databases and customer metadata are hosted in Australia. Data-processing workers operate in Australia (Sydney), the United States (Virginia) and Thailand (Bangkok), selected by the customer during onboarding. Managed storage defaults to the nearest Wasabi region to the processing location: Sydney, Virginia, and Singapore for Thailand processing, because Wasabi operates no Thai region. Bring-your-own buckets live wherever you put them. Selecting a processing region outside Australia means file content and the job data required to perform the operation are processed in that country — and, on managed storage, stored in the region named above — while service metadata remains in Australia. Some providers we use (Microsoft, RackCorp, Supabase, Wasabi, Airwallex, Google and Vercel) may process data outside Australia under their own safeguards.

Who we share it with

Only the providers needed to run the service: Microsoft (Graph API access you consented to), RackCorp (regional compute), Supabase (service database), your configured storage provider, Airwallex (payments), our email delivery provider, and Google/Vercel (site analytics). If your account is managed by an IT provider or MSP, they can see your account’s data in the console as part of managing your service. We disclose information where required by law. If the ArchiveBridge business is restructured or acquired, personal information held to run the service may transfer to the related or acquiring entity, which remains bound by this policy; we’ll tell you at your account email if that happens.

Security and control

Access to Microsoft 365 is application-level and revocable by your administrator at any time from your own Entra admin centre. Revoking consent prevents ArchiveBridge obtaining further access; a short-lived access token already issued by Microsoft may remain valid until it expires. Data is encrypted in transit; stored secrets are encrypted at rest; every action the engine takes is written to an audit log you can export.

Retention and deletion

Backup and archive data is retained according to the policies you configure, in your account’s bucket. If you close your account, we delete our copies of your metadata after a wind-down period, except records we’re required to keep (such as tax and billing records). If a paid account enables the 1–90 day S3 Object Lock compliance-retention option on ArchiveBridge-managed, lock-capable storage, retained objects cannot be deleted — including by us — until their retention date.

Your rights

You can ask us to access, correct or delete your personal information at hello@archivebridge.app. If you’re not happy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).