1. Introduction
At Dinopix, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services.
Dinopix Pty Ltd is an Australian company. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we comply with the Notifiable Data Breaches (NDB) scheme. We do not rely on the small-business exemption in section 6D of the Privacy Act: we handle personal information on behalf of our customers as a core part of the service, and we hold ourselves to the APPs regardless of turnover.
This policy covers two different relationships. Where you are a Dinopix customer, we are the controller of your account information. Where your customers' details reach us through your connected review platforms, store or web forms, you are the controller and Dinopix acts as a processor, handling that information only on your instructions and only to provide the service.
2. Information We Collect
Personal Information
- Name and email address (when you register or contact us)
- Payment information (processed securely by third-party providers)
- Profile information and preferences
- Communication history with our support team
Usage Information
- Review and comment data from connected platforms
- Platform usage patterns and feature interactions
- Subscription plan and feature usage
- Connected platform preferences and settings
- Device information and browser type
- IP address and location data
- Cookies and similar tracking technologies
Review and Reputation Data
- Records of reviews, comments, and messages synced from connected platforms
- AI sentiment classifications and reply suggestions generated
- Brand voice settings and response templates
- Analytics data and exported reports
3. How We Use Your Information
Service Provision
- Provide AI-powered sentiment analysis and reply suggestions for your reviews and comments
- Maintain and improve our platform functionality
- Provide customer support and technical assistance
- Process payments and manage subscriptions
Marketing and Communications
- Send service updates and platform notifications
- Share marketing materials about our products and services
- Provide educational content and reputation management tips
- Announce new features and platform improvements
- Send personalized recommendations based on usage patterns
4. Email Marketing Consent
By providing your email address through any of the following methods, you explicitly consent to receive marketing communications:
- Creating an account on our platform
- Submitting our contact form
- Subscribing to our newsletter
You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email or contacting us directly. This will not affect service-related communications necessary for platform operation.
5. Dinopix Reviews — Social Platform Data
Dinopix Reviews is our review and comment management platform that connects to social media platforms. This section specifically covers how we handle data obtained through Facebook, Instagram, and other connected platforms.
5.1 Data We Access from Facebook & Instagram
When you connect your Facebook account to Dinopix Reviews, we access the following data through Meta's Graph API:
- Facebook Page information: Page names, categories, profile pictures, and store locations for pages you manage
- Page posts and comments: Public comments and reviews posted on your Facebook Pages, including author names, comment text, and timestamps
- Instagram Business account information: Instagram accounts linked to your Facebook Pages
- Instagram comments: Comments on your Instagram Business posts, including author usernames, comment text, and timestamps
- Messenger conversations: Private messages sent to your Facebook Page through Messenger, including message text, sender information, and attachments
- Ad account information: Ad account IDs and names for syncing comments on sponsored posts
- Engagement data: Reaction counts, comment counts, and review ratings on your pages
5.2 How We Use Social Platform Data
- Display and management: Showing your comments, reviews, and messages in a unified dashboard so you can monitor and respond from one place
- AI sentiment analysis: Analysing comment and review text using Anthropic's Claude AI to classify sentiment (positive, neutral, negative) and identify themes. Comment text is sent to Anthropic's API for processing — see section 5.4 for details
- AI-suggested replies: Generating draft reply suggestions based on comment content and your brand voice settings. Comment text and conversation context is sent to Anthropic's API for this purpose
- Analytics and reporting: Aggregating review and comment data to provide sentiment trends, response rate metrics, and AI-generated insights
- Notifications: Sending you email and in-app alerts when new comments or reviews are posted on your pages
- Webhook processing: Receiving real-time notifications from Facebook when new comments are posted, enabling immediate alerts and sentiment analysis
5.3 Data Storage and Retention
- Social platform data is stored in our database hosted on Supabase (AWS infrastructure, Singapore region) with encryption at rest
- Facebook/Instagram OAuth access tokens are stored securely and automatically refreshed before expiry
- Comment and review data is retained for as long as your account is active and the platform connection exists
- When you disconnect a platform or unassign pages, you can choose to keep or delete the associated data
- Deleting your Dinopix Reviews account will permanently delete all stored social platform data
5.4 Third-Party AI Processing
We use Anthropic's Claude AI for sentiment analysis and reply suggestions. When processing your data:
- Comment/review text (up to 200 characters per item) is sent to Anthropic's API for sentiment classification
- For reply suggestions, the relevant comment text, your business name, and brand voice settings are sent to Anthropic's API
- For AI sentiment insights, a sample of up to 200 recent comments is sent for thematic analysis
- Anthropic does not use data sent via their API to train their models (per their commercial API terms)
- No personally identifiable information beyond comment author names and text is sent to Anthropic
5.5 Facebook Platform Terms Compliance
Our use of Facebook and Instagram data complies with Meta's Platform Terms and Developer Policies:
- We only access data that you explicitly authorize through Facebook's OAuth permission flow
- We do not sell, license, or otherwise transfer Facebook or Instagram user data to third parties for purposes unrelated to providing our service
- We do not use Facebook data for advertising, surveillance, or profiling purposes
- We provide mechanisms for you to disconnect your Facebook account and delete associated data
- We request only the minimum permissions necessary for our service to function
5.6 Data Deletion
You can delete your social platform data at any time by: (1) unassigning pages from businesses in Settings > Connected Accounts and choosing "Delete data", (2) disconnecting your Facebook account entirely, or (3) deleting your Dinopix Reviews account. You may also contact us at support to request complete data deletion. We will process deletion requests within 30 days.
6. Dinopix Reviews — Google Business Profile Data
Dinopix Reviews can connect to your Google Business Profile so that reviews of your locations appear alongside the rest of your feedback. This section covers data obtained through Google's Business Profile APIs, and applies only if you choose to connect a Google account.
6.1 Data We Access from Google
Connecting your Google account grants Dinopix the business.manage scope. Using it, we access:
- Business account information: The Google Business Profile accounts your Google login administers, so you can choose which to connect
- Location information: Location name, title and street address for the locations in those accounts
- Reviews: Review text, star rating, the date it was posted or updated, and a Google-assigned review identifier
- Reviewer information: The reviewer's public display name and profile photo, as shown publicly on your listing
- Existing owner replies: Replies already published on a review, so the dashboard shows what has been answered
We do not access Google account data unrelated to your business listings. We do not read your Gmail, Drive, Calendar, Contacts, or any other Google service, and we do not request the scopes that would allow it.
6.2 How We Use Google Data
- Display and management: Showing Google reviews in the same dashboard as your other platforms, so you can monitor and respond from one place
- Replying: Publishing owner replies that you write in Dinopix back to the review on your Google Business Profile. Replies are only ever sent when you choose to send them; we never post on your behalf without your action
- AI sentiment analysis and suggested replies: On the same basis as other platforms, and subject to the same limits — see section 5.4
- Analytics and reporting: Including Google reviews in your sentiment trends and response-rate metrics
- Notifications: Alerting you when a new Google review is posted
6.3 Limited Use of Google User Data
Dinopix's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described above
- We do not sell Google user data, and we do not transfer it to advertising platforms, data brokers, or information resellers
- We do not use Google user data for advertising, for building advertising profiles, or to train generalised artificial-intelligence models
- No human reads Google user data, except with your explicit consent (for example, where you ask our support team to investigate a problem), where it is necessary for security purposes such as investigating abuse, or where we are required to do so by law
- We request only the scope our features require, and access ends when you disconnect your Google account
6.4 Storage, Retention and Deletion
- Google review data is stored in our database hosted on Supabase (AWS infrastructure, Singapore region) with encryption at rest
- Google OAuth tokens are encrypted before they are stored, and are used only to call the Business Profile APIs on your behalf
- Review data is retained for as long as your account is active and the Google connection exists
- Disconnecting your Google account revokes our access. You can choose to keep or delete the review data it created
- Deleting your Dinopix Reviews account permanently deletes all stored Google data
You can also revoke Dinopix's access directly from your Google account permissions page at any time. To request complete deletion, contact support; we process deletion requests within 30 days.
7. Connected Store Data (Shopify, WooCommerce & Web Forms)
Where you connect an online store or website form to Dinopix, we process personal data belonging to your customers. In this relationship you are the data controller and Dinopix acts as your processor: the data is yours, we hold it on your behalf, and we act on your instructions.
7.1 What We Access
From a connected Shopify or WooCommerce store, and from website forms you point at us, we read:
- Customer name — to identify the contact record and address the customer when you reply
- Email address — the key we use to deduplicate a person across sources, and the address used to contact them
- Phone number — shown on the contact record so you can contact the customer about their order
- Billing and shipping address — we store the company name and contact phone from it so orders group under the correct business; we do not retain full street addresses
- Order history — order number, date, total, status, line items and delivery timestamp
Access is read-only. We never create, modify or delete orders, products or customers in your store. We do not access payment card details, bank information or checkout credentials at any time.
7.2 Why We Process It
- Store management — building and maintaining the customer records, order history and company relationships that make up your CRM
- Customer service — giving you the context to answer a review, comment or enquiry from the person who left it
- Review requests and NPS surveys — only where you have explicitly enabled that automation, and only to the customers it applies to
We do not use your customers' personal data for our own marketing, we do not sell or licence it, and we do not use it to profile individuals or train third-party models on your behalf.
7.3 Protection and Retention
Customer data from connected stores is encrypted in transit and at rest, including backups. Access is restricted by role and enforced at the database level, access to personal data is logged, and test and production environments are kept separate.
We retain this data for as long as the source remains connected and your account is active. When you disconnect a store you may choose whether to keep or delete the records it created. Deleting your Dinopix account removes it entirely.
7.4 Requests From Your Customers
If one of your customers asks you to access or delete their personal data, you can export or delete the relevant contact directly in Dinopix, which removes it from our systems. Where your store platform sends us a deletion or data request on that customer's behalf, we action it automatically. Your store remains the source of record, so any request should also be actioned there. If you need help, contact us at support and we will respond within 30 days.
8. Information Sharing and Disclosure
The third-party services we rely on to run Dinopix — what each is used for and which region it operates in — are listed in full on our sub-processors page. The terms on which we process personal information on your behalf are set out in our Data Processing Agreement.
We do not sell, trade, or otherwise transfer your personal information to third parties except in the following circumstances:
- Service Providers: Trusted partners who help us operate our platform (hosting, payment processing, analytics)
- Legal Requirements: When required by law or to protect our rights and safety
- Business Transfers: In connection with mergers, acquisitions, or asset sales
- Consent: With your explicit permission for specific purposes
9. Data Security
We implement industry-standard security measures to protect your personal information, including encryption, secure servers, and regular security audits. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Your Rights and Choices
You have the right to:
- Access, update, or delete your personal information
- Opt-out of marketing communications
- Request a copy of your data
- Restrict or object to certain processing activities
- Data portability (where technically feasible)
To exercise any of these, contact us through our contact page. We will respond within 30 days, as required by the APPs.
If you are not satisfied with how we have handled your personal information or a privacy complaint, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001. We ask that you raise it with us first so we have a chance to put it right.
Where your customers' personal information is held in Dinopix on your behalf, requests from those individuals should be directed to you as the controller. We will assist you in responding to them.
11. Cookies and Tracking
We use cookies and similar technologies to enhance your experience, analyze usage patterns, and provide personalized content. You can manage cookie preferences through your browser settings, though some features may not function properly if cookies are disabled. Separately, where one of our customers has enabled website visitor tracking on their own site, section 11 describes exactly what is recorded and how to opt out.
12. Website Visitor Tracking
This section applies in two situations: when one of our customers has added the Dinopix tracking script to their own website, and on this website, where we use the same script ourselves. If you are reading it because you visited a business's site that uses Dinopix, or because you are browsing dinopix.ai, this is what is recorded and how to stop it.
On dinopix.ai specifically, we are the controller: we record the pages you view here against a random identifier, and if you later contact us or sign up, that history is attributed to your record with us. Everything described below — no fingerprinting, no query strings, Global Privacy Control and Do Not Track honoured, the 30-day and 12-month retention — applies to us on our own site exactly as it applies to our customers on theirs.
Who is responsible. The business whose website you visited decides to collect this information and is the controller of it. Dinopix is the processor and holds it on their behalf. Requests about your information should go to that business; we will help them respond. The feature is off by default and only operates where a business has switched it on and confirmed that consent is handled on their site.
What is recorded:
- A randomly generated visitor identifier, stored in a cookie belonging to the website you are visiting, for up to 12 months
- The address of each page viewed — the site and path only, with any query string removed
- The page title, and the address of the page that referred you, also with its query string removed
- The date and time of each view
What is deliberately not done:
- No fingerprinting. The identifier is random. Nothing is derived from your device, browser, screen or IP address, so clearing the cookie genuinely makes you a new visitor
- No tracking across devices or across unrelated websites. Each site and each browser is separate
- No reverse-IP company identification
- Query strings are discarded before anything is stored, because they routinely carry email addresses, booking references and similar details
- The cookie belongs to the site you are visiting and is never sent to Dinopix. The identifier travels in the request instead
You are anonymous until you identify yourself. Page views are recorded against the random identifier, which is not connected to a name or an email address. If you later identify yourself to that business — by clicking a link in an email they sent you, or by submitting a form on their site — the identifier is linked to your contact record with them, and the pages already recorded against it become attributed to you. Everything before that moment stays anonymous, and a different browser or device starts again from scratch.
Your choices:
- We honour Global Privacy Control and Do Not Track. If your browser sends either signal, nothing is recorded — regardless of what the website operator has configured
- Clearing cookies for that website removes the identifier and makes you an unlinked visitor again
- Use the website's own cookie or consent controls, where it provides them
- Ask the business to delete your record. Their tracking history for you is deleted with it
How long it is kept. Visitors who never identify themselves are deleted after 30 days without activity. Page view records are deleted after 12 months.
13. Children's Privacy
Our platform is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
14. Where Your Data Is Stored
We are an Australian company, but our infrastructure is not all located in Australia. We would rather say so plainly than leave it to be discovered.
- Primary database and file storage — Supabase, on AWS in the Singapore (ap-southeast-1) region. This is where your account data and your customers' details are held at rest.
- Database backups — daily encrypted snapshots, retained on a rolling 7-day window, also held in the Singapore region.
- Website and application hosting — Netlify, served from a global content delivery network.
- Background synchronisation — Railway, in the Southeast Asia (Singapore) region, which processes review and message data in transit.
- Third-party services — the sub-processors listed in section 7, which operate in their own regions, including the United States and the European Union.
Because personal information is disclosed to overseas recipients, APP 8 applies. We take reasonable steps to ensure those recipients handle it consistently with the Australian Privacy Principles, including through the data processing terms in our agreements with them. Where personal information originates in the European Economic Area or the United Kingdom, transfers are made under the European Commission's Standard Contractual Clauses.
15. Data Retention and Deletion
We retain your personal information only as long as necessary to provide our services and fulfil the purposes outlined in this policy, unless a longer retention period is required by law.
Deletion happens in two stages, and it is worth being precise about the difference:
- Removal from the live service — when you delete a record, or close your account, the data is removed from the running system within 30 days and is no longer accessible to you, to us, or through the product.
- Expiry from backups — encrypted database backups are retained on a rolling 7-day window for disaster recovery. Deleted data persists in those snapshots until they age out, after which it is gone. We do not restore backups to recover individual deleted records.
So “deleted within 30 days” describes the live service. Backups are the reason we do not claim instantaneous erasure everywhere; a service that could truly erase a record from every copy the moment you asked would be a service with no disaster recovery.
16. Data Breach Notification
We are covered by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988. If we suffer a data breach that is likely to result in serious harm to any individual whose personal information we hold, and we cannot prevent that harm through remedial action, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable.
Where the breach affects personal information we hold on a customer's behalf as a processor, we will notify that customer without undue delay so they can meet their own notification obligations, and we will provide the detail they need to do so.
17. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of any material changes by email or through a prominent notice on our platform. Your continued use constitutes acceptance of the updated policy.
18. Contact Us
If you have questions about this Privacy Policy or how we handle your information, please contact us at our contact page.