Tradie website privacy policy Australia

Does a small tradie business need a privacy policy?

Check the rule. Map the data. Explain the real process.

Direct answer

Not always. An Aussie trade firm covered by the Privacy Act must have a clear, current privacy policy. Turnover above $3 million is one test. Some firms at $3 million or less are covered too. Check the exceptions first. Then map every form and tool on the site. Make sure the public words match the real process.

A tradie website privacy policy is the broad account of how a covered firm manages personal information. The Act uses that term for data about a person who is known or can be worked out. We use “customer data” for short in this guide.

A policy is not the short notice a customer may need at a quote form. The Office of the Australian Information Commissioner (OAIC) treats those as two jobs.

If the Act does not cover the firm, the OAIC still backs good privacy practice. That does not make a free choice a legal duty. A short, true page can still help the firm explain its process. Clear form words can do the same.

This guide gives general facts, not legal advice. If the coverage test affects your duties, check the OAIC guide. Get advice for your own firm.

Five-step privacy map for an Australian tradie website: check Privacy Act coverage, list collection points, record purposes and providers, add clear notices, then review changes
Start with the real data path. A policy cannot be accurate if the forms, tools and providers have not been mapped.

Quick check: test Privacy Act coverage. List each form and tool. Record the data, the need, where it goes and who can see it. Then write the policy and form notices from those facts.

Start with the Privacy Act coverage test

The $3 million figure is key, but it is not the whole test. The OAIC calls a firm small when its yearly turnover is $3 million or less. Most small firms are not covered by the Privacy Act. Some are covered due to what they do or how they use data.

A firm may be covered below that sum. This can apply to a health service. It can apply to a firm that trades in personal information. A Commonwealth contractor, a firm tied to a covered firm or one that opts in may also be covered. The OAIC lists more types.

Use the OAIC small-business coverage guide. Do not guess that “small” means exempt.

A trade firm can change over time. New work may change the answer. So can a new company, a government job or higher turnover. Record why the firm reached its view. Check it again when the firm changes.

Privacy policy and collection notice do different jobs

A privacy policy sets out the firm's broad data rules. A collection notice deals with one data request at the right time. A link to the full policy can help. But it may not say why one quote form asks for a home address. It may not say that a booking tool gets the details.

Difference between an APP privacy policy and an APP 5 collection notice
QuestionPrivacy policyCollection notice
What does it explain?How the firm manages personal information in all parts of its work.What a person needs to know about one data request.
Where does it appear?On a clear public page that is easy to find.At the form, call, upload or other data point.
When is it given?Kept live and up to date.Before or at the data request. If that is not practicable, give it as soon as practicable after.
Can one replace the other?Not by itself when it only states broad rules.It can link to the policy for more facts, but must fit that data request.

The OAIC says an APP entity must take reasonable steps to tell a person about key collection matters. It can also make sure the person knows those facts. For a web form, a clear and easy-to-see notice can work. So can a clear link to the notice. Keep the short text close to the button. Do not hide the only clue in the footer.

Map every place the tradie site collects data

Do not draft from memory. Walk through the site as a new customer. Note each point where data moves. Include tools that load in the back end. Do not list only the boxes a customer can see.

Questions to answer for common information collection points on a tradie website
Site featureQuestions to answer before publishing
Contact or quote formWhich fields must be filled? Why is each one needed? Which inbox, job tool or staff member gets it?
Booking formDoes a booking firm handle the details? What is sent? Where is it held? What text or email will follow?
Photo uploadCould a photo show a person, address, number plate or file? Who checks it? Who keeps it?
Chat or call toolAre chats, calls or notes kept? What notice shows first? Which firm holds the record?
Site stats or adsWhich tools load? What do they learn about the phone or site use? Are the settings and claims still right?
Online paymentWhich firm takes the money? Does the trade site get full card data, a token, or just a status and receipt?

Use facts from the tool settings and terms. Do not write “we never share your data” if another firm gets it to do a task. That can include a booking, host, email, site stats or payment firm. “Share” does not only mean sell.

Job photos need their own check. The tradie job-photo guide shows how to screen an address, person and other private details. Do this before a photo goes live.

Build an accurate privacy page in six steps

  1. Check if the Privacy Act covers the firm. Check yearly turnover and each OAIC exception that fits. Record the date and the reason for the result.
  2. List each data point. Test forms, bookings, calls, chats, uploads, site stats and payments. Use both phone and desktop.
  3. Trace the data path. Note the data and why it is needed. Add where it is held, who can see it and who else gets it. Note if it goes abroad. Set a time to delete it or strip out the name.
  4. Write from the map. If the firm is an APP entity, cover the APP 1 topics. A free-choice page must be true too. Do not add legal claims that do not fit.
  5. Add a notice at the form. An APP entity must take reasonable steps to give the key APP 5 facts at or before collection. If that is not practicable, it must act as soon as practicable after. A short layer and link can make the facts easy to read.
  6. Test and check again. Ask someone outside the firm to find the page. Ask them what happens to a quote. Check the page when forms, tools, staff or work change.

Put the page in the footer. Link to it near forms when that helps a person grasp the data request. FreshTech's own public privacy page shows a place for the link. It is not text to copy. Each firm has its own map.

What an APP privacy policy needs to cover

The OAIC says a covered entity needs a clear and up-to-date APP privacy policy. Its guide starts with a data audit. The words must match the entity's real acts.

The OAIC says to use plain and exact words. It says not to use a broad template from a different entity. A short and true page beats a long page full of “may”. Do not list acts the firm does not take.

Avoid seven common privacy-page mistakes

Questions tradies ask before publishing

Is $3 million annual turnover the only Privacy Act test?

No. It is a main test. But the OAIC lists firms that can be covered at $3 million or less. Check the work, deals, linked firms and all other exceptions. Check yearly turnover too.

Does a quote form collect personal information?

A quote form may ask for a name, phone, email or home address. Those facts may point to one person. Map each field. Do not ask for more than the job needs.

Can a tradie copy a privacy policy from another website?

Do not copy a tradie website privacy policy as a short cut. The OAIC says an APP privacy policy must fit the entity. It should not just use a broad template from a different entity. Build the data map first.

Is a privacy policy the same as a notice under a form?

No. The policy states broad rules. A collection notice deals with one data request and its time. A short form notice can link to the full page. The link must give clear and easy access.

Where should the privacy link go?

Make the public policy easy to find. The footer is a common place. For a covered firm, put a clear notice or clear link at the form where APP 5 calls for it.

Do analytics, chat or payment tools change the policy?

They can change the facts in the policy and notices. Check what each live tool gets. Check why, where it is held and who can see it. Also check how the firm deals with a request to see or fix data, or make a complaint.

Map the real site before writing the page

Start with the coverage test. Then fill in the data map. Remove each field with no clear aim. Use the Aussie tradie site checklist to test the rest of the customer path.

Get legal advice if the test is not clear. Do the same if the site holds sensitive data. For help with the site map, ask FreshTech Community for a plain site check.

See all FreshTech guides

Sources

  1. OAIC: Small business, viewed 26 August 2026.
  2. OAIC: What is a privacy policy?, viewed 26 August 2026.
  3. OAIC: Guide to developing an APP privacy policy, viewed 26 August 2026.
  4. OAIC: Chapter 5 — notification of the collection of personal information, viewed 26 August 2026.
  5. business.gov.au: Protect your customers' information, viewed 26 August 2026.

Note: FreshTech Community prepared this general guide from current Australian Government and OAIC sources. It is not legal advice or a privacy-policy template. It has no paid link, fake review, made-up fine, rank promise or invented data.