Privacy

Kaido privacy policy

Last updated 9 October 2026

This explains what personal information Kaido handles, why, and the choices you have. Questions: support@kaido.com.au.

1. Who we are

  • Kaido is a software platform for logistics businesses: third-party warehouses (3PLs), the brands whose stock they hold, and businesses that run their own warehouse. It is provided by [Company name] (ABN [to be added]) ("we", "us").
  • We follow the Australian Privacy Principles in the Privacy Act 1988 (Cth).

2. Whose information this covers

  • People who use Kaido: staff of our business customers who are invited to sign in.
  • Our customers' own customers: people who order from a store that uses us, whose delivery details reach us so the order can be shipped. For this information we act on behalf of the business that owns the order; that business decides what happens to it.

3. What we collect

  • For people who sign in: name, work email, a securely hashed password (we never see the password itself), two-factor sign-in details, and a record of sign-ins and key actions (for example approvals and data exports) for security.
  • Business data our customers connect or upload: orders, products, stock, inbound deliveries, carriers, rates and charges.
  • Delivery details on orders sent to a warehouse: recipient name, street address, suburb, state, postcode, phone and email — only because the warehouse needs them to ship the parcel.
  • Questions asked of Kaido (our assistant) and its answers.
  • We don't collect payment card details; stores keep those.

4. How we collect it

  • From you, when you accept an invitation, sign in or use the platform.
  • From the systems our customers connect (for example Shopify, a warehouse system or a carrier) or the files they upload.

5. Why we use it

  • To provide the platform: show each business its own operation, send orders to its warehouse, choose carriers, check invoices and flag problems early.
  • To keep accounts secure: sign-in, two-factor checks, and investigating misuse.
  • To send account emails: invitations, sign-in links, password resets and email-change confirmations.
  • We don't sell personal information, use it for advertising, or send marketing to our customers' customers.

6. Who we share it with

  • Within the platform, only as our customers set up: a store's orders are visible to the warehouse it has linked to ship them, and never to other businesses on the platform.
  • Service providers who run parts of the platform for us, under contract: Amazon Web Services (hosting, email and backups, in Sydney), Supabase (database and sign-in, on AWS in Sydney), Anthropic (the AI model behind the assistant and document reading) and GitHub (which runs our nightly backup job).
  • If the law requires it, for example a valid court order.

7. Information sent overseas

  • Everything is stored in Australia (Sydney). Two things are processed outside Australia. First, the AI features: when someone asks Kaido a question, or has Kaido read a supplier invoice, rate card, carrier price list or safety data sheet, that question or document and the business data needed are sent to Anthropic in the United States to produce the answer. Under its commercial terms Anthropic doesn't use this data to train its models.
  • Second, our nightly backup is made by an automated job on GitHub's servers, which may be outside Australia. The copy is encrypted there and stored in Sydney, and the unencrypted copy is deleted when the job ends.
  • The assistant is never given delivery names, addresses, phones or emails — it doesn't need them to answer questions about the operation.

8. How we protect it

  • Data is encrypted in transit and at rest. Each business's data is walled off from every other business's inside the database itself.
  • Two-factor authentication is available to everyone, and each business can require it for its members. Keys to connected systems are kept in an encrypted vault.
  • Our own staff can't see a customer's data unless that customer grants time-limited support access (at most 7 days). To set up a brand-new account before anyone from the business has joined, staff may act as an administrator for at most 7 days; after that, only the business can grant access. Every grant is recorded.
  • Encrypted backups are kept in Sydney and locked against deletion for 30 days.

9. How long we keep it

  • Delivery names, street addresses, phones and emails are cleared automatically once they're no longer needed for delivery and claims (180 days after delivery by default; each business can set this). Suburb, state and postcode are kept for freight history.
  • Questions asked of Kaido are deleted after 12 months.
  • When a store asks us (through Shopify) to erase a customer's details, we clear that person's name, address, phone and email from its orders. When a store disconnects, we stop syncing straight away and erase its customers' details within 48 hours.
  • Account details are kept while the account is active, and removed or anonymised when a business leaves, except where the law requires us to keep records.

10. Cookies

  • We use only the cookies the platform needs to work: keeping you signed in, remembering your light or dark setting, and protecting test sites. No advertising or tracking cookies.

11. Access, correction and complaints

  • You can ask to see or correct the personal information we hold about you by emailing support@kaido.com.au. We'll respond within 30 days.
  • If you ordered from a store that uses us, please contact that store first — it controls your details and can ask us to share, correct or erase them.
  • If you have a privacy complaint, email support@kaido.com.au. If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).

12. Changes

  • We'll update this policy when the platform changes how it handles personal information, and show the date at the top. Significant changes will be told to our customers before they take effect.

Terms of service · Sign in