Privacy Policy
Last updated: 20 June 2026
1. Overview
Unite-Group Nexus Pty Ltd ABN (“we”, “our”, “us”) operates the Unite-Group Application (the “Application”) available at https://unite-group.in. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with the Application.
The Application is a private, single-operator business management platform. It is not a public-facing SaaS product and is not intended for use by the general public. By accessing or using the Application, you acknowledge this policy.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in that Act. Where we interact with users or data subjects in the European Economic Area, we also comply with the General Data Protection Regulation (GDPR) to the extent applicable.
2. Information We Collect
2.1 Account and Authentication Data
We use Google OAuth (via Supabase Auth) for sign-in. When you authenticate, we receive your Google account email address, name, and profile picture. We do not receive or store your Google password.
2.2 Third-Party Integration Data
The Application connects to third-party services on your behalf. The following data may be accessed and stored in an encrypted credentials vault:
- Xero: OAuth access tokens, refresh tokens, and tenant identifiers for linked Xero organisations. Financial data (invoices, transactions, revenue figures) is fetched in real time and may be temporarily cached.
- Gmail / Google Calendar / Google Drive: OAuth tokens permitting read and send access to email, calendar events, and Drive documents. Message content, calendar entries, and file metadata are processed locally within the Application and not transferred to third parties.
- Linear: API token for project and issue management. Issue titles, descriptions, and status updates are accessed.
- Social Platforms (Facebook, LinkedIn, TikTok): OAuth tokens for publishing and analytics. Post content and engagement metrics are accessed.
All OAuth tokens are encrypted at rest using AES-256-GCM via the Supabase Vault (pgsodium). Tokens are stored in a private Supabase PostgreSQL database hosted on Supabase’s AWS infrastructure in ap-southeast-2 (Sydney).
2.3 Usage and Technical Data
We collect standard server logs including IP addresses, browser type, pages visited, and timestamps. Vercel (our hosting provider) retains deployment and request logs, provides error monitoring via Vercel Observability, and Vercel Analytics for aggregated usage data.
3. How We Use Information
We use collected information for the following purposes:
- Operating and improving the Application’s functionality
- Authenticating and authorising access to the Application
- Fetching, displaying, and acting on business data from connected integrations
- Generating reports, dashboards, and AI-assisted insights
- Diagnosing technical errors and maintaining system health
- Complying with legal obligations under Australian law
We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not use your data to train AI models or share it with AI providers beyond the minimum required to process a given request (e.g., sending an excerpt to the Anthropic API to generate a summary).
4. Google API Scopes
The Application requests the following Google OAuth scopes to provide its features. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
openid,profile,email— identity and sign-ingmail.readonly,gmail.modify,gmail.send— email inbox access and outgoing emailcalendar.readonly— calendar events for scheduling featuresdrive.readonly— reading documents from a designated Drive folder for the notes vaultoffline_access— refresh tokens so connections persist without repeated sign-in
Data obtained through Google APIs is used solely to provide the Application’s features to the authorised operator. It is not transferred to third parties, used for advertising, or combined with data from other sources except as necessary to operate the Application.
5. Data Storage and Security
All data is stored in a Supabase PostgreSQL database hosted in the ap-southeast-2 (Sydney) AWS region. Row-Level Security (RLS) policies ensure data is accessible only to the authorised account holder.
OAuth tokens and credentials are encrypted at rest using AES-256-GCM. Database connections use TLS in transit. The Application is hosted on Vercel’s global edge network with HTTPS enforced.
We retain audit logs of sensitive operations (credential access, financial data changes) for a minimum of seven years in accordance with Australian financial record-keeping requirements under the Corporations Act 2001 (Cth).
6. Third-Party Service Providers
We engage the following sub-processors in providing the Application:
| Provider | Purpose | Data Region |
|---|---|---|
| Supabase (Auth + DB) | Authentication, database | AWS ap-southeast-2 |
| Vercel | Hosting, edge functions | Global / US |
| Anthropic | AI completions (Claude API) | US |
| Google (OAuth + APIs) | Authentication, Gmail, Calendar, Drive | Global |
| Xero | Accounting data | AU / NZ |
Each provider is bound by its own privacy policy and data processing agreements. We only share the minimum data necessary for the provider to deliver its service.
7. Your Rights
As the authorised operator of the Application, you have the right to:
- Access and download a copy of data associated with your account
- Correct inaccurate information
- Request deletion of your account and associated data (subject to legal retention requirements)
- Withdraw consent for third-party integrations at any time (by disconnecting them within the Application or revoking OAuth access at the provider)
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au
If you are located in the EEA or UK, you may also have rights under GDPR / UK GDPR including portability and the right to object to processing.
8. Cookies and Tracking
The Application uses a single session cookie managed by Supabase Auth (PKCE flow) to maintain your authenticated session. No third-party advertising cookies are used. Vercel Analytics uses privacy-preserving, aggregated data without fingerprinting or cross-site tracking.
9. Children's Privacy
The Application is not intended for, and does not knowingly collect information from, persons under 18 years of age.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page indicates when the most recent revision was made. Continued use of the Application after changes are posted constitutes acceptance of the revised policy.
11. Contact Us
For privacy enquiries, to exercise your rights, or to report a concern, contact:
Unite-Group Nexus Pty LtdAustralia
Email: contact@unite-group.in
We will respond to privacy requests within 30 days in accordance with the Australian Privacy Principles.