Privacy and file access
Privacy and Document Handling Policy
Effective and last fact-checked: 2 August 2026
This policy explains the current LodgeHQ Translations data flow identified in the production application code. LodgeHQ Translations is operated by LodgeHQ Pty Ltd (ABN 52 696 192 677). It is important to read this policy before uploading a passport, identity record, police certificate, health record, court document or other sensitive file.
1. Information we collect
| Category | Examples and purpose |
|---|---|
| Quote and source files | Documents, file names, size, language direction, page count, document type, notes and automated-analysis results used to quote and complete work. |
| Account and contact details | Name, email, optional phone, password hash, email preferences and authentication/session records used for accounts, order updates and support. |
| Order activity | Order number, status, messages, attachments, revisions, reviews, payment references, translator assignment and delivery records. |
| Translator information | Practitioner number, credential type, language directions, certificate uploads, profile information, application status and bank-account details used for manual payouts. |
| Payment information | Stripe processes payment-method details. LodgeHQ records transaction and refund references but does not receive or store complete card numbers through the current checkout. |
| Technical and measurement data | For a successfully priced instant quote, the first-party QuoteEvent record can contain language direction, page and price data, file name, R2 storage key, analysis layer, a user agent truncated to 200 characters and the first 16 hexadecimal characters of an unsalted SHA-256 hash of the available IP address. That truncated IP-derived value is pseudonymous and is not represented as anonymous. If you arrive through the translation link in a LodgeHQ client portal, a first-party ReferralVisit record stores the channel name (lodgehq_portal), the landing path, the time and the same truncated IP-derived value, and a first-party cookie named lhq_ref holding only that channel name is set for 30 days. While that cookie is present, the channel name is also added to QuoteEvent and order records so LodgeHQ can count the quotes and orders the portal link produces. The link and the cookie carry no client, firm or matter details. Necessary session storage supports quote drafts. Google advertising or analytics events are available only when the operator switch, verified public tag and corresponding affirmative choice are all present. |
Do not upload information that is unnecessary for the receiving body. If another person's information appears in a file, make sure you are authorised to provide it for translation.
2. Automated document reading and quote assessment
When a document is added to the instant-quote tool, the file is first stored in Cloudflare R2. The application then renders document pages or prepares the uploaded image and sends that material to Anthropic's API. The automated analysis can return a document classification, translatable-word estimate, page count, likely language, short subject description and confidence score.
Common, high-confidence files can be priced using LodgeHQ's rate logic. A document outside that path may be sent to Anthropic again for a bounded quote assessment. If automated pricing refuses, fails or cannot provide a reliable result, the customer can request manual review; an authorised LodgeHQ administrator then receives access to the staged file and contact details.
3. Who can access documents
- The customer can access documents connected to their own authenticated order.
- Authorised LodgeHQ administrators can access documents for manual quoting, order administration, support, disputes, auditing and incident response.
- Approved matching translators before assignment: depending on the order workflow, a translator whose approved language pair matches an open job may see order details and a watermarked preview before bidding or accepting. They do not receive unrestricted source-file downloads through the ordinary file endpoint before assignment.
- The assigned translator can access the full source document and relevant order messages to complete the translation.
- Technology providers process information to provide storage, automated analysis, payments, email, hosting, database and measurement functions.
Translator terms prohibit using or redistributing client material outside the work. A contractual restriction reduces risk but cannot eliminate it. Avoid uploading unnecessary pages or identifiers.
4. Service providers and overseas processing
| Provider or category | Current role |
|---|---|
| Cloudflare R2 | Object storage for quote files, order documents, message attachments and translator certificate uploads. |
| Anthropic | Automated document analysis and, for some documents, automated quote assessment. |
| Stripe | Customer payment processing, payment references and refunds. |
| Resend | Transactional email such as account, order, quote and marketplace notifications. |
| Google measurement tools | Third-party Google loading is disabled by default. If the operator explicitly enables it, usage analytics and Google Ads conversion measurement remain separate optional choices. A corresponding tag is rendered only on an approved public route after that choice is granted and its verified public ID is configured. Advertising personalisation remains disabled. |
| Hosting and database providers | Application hosting, logs and structured account/order records. |
Third-party Google measurement is disabled by default in the application configuration. While it is disabled, this application does not request Google's measurement script. Before enabling it, the operator is instructed to disable GA4 Enhanced Measurement page views based on browser history changes. If enabled, the application renders a configured tag only on its canonical public-route allowlist after the corresponding category is granted. Public links from those pages into account, administrator, translator-dashboard, authentication, order-tracking or tokenised routes are changed to full-document navigation, with Google consent denied before navigation; a direct render of those excluded routes does not render the Google script. The application event layer also rejects events whose actual current path is not allowlisted.
The optional Google event layer sends only approved event names, page categories, broad source/medium attribution and a random session key. It does not send document contents, file names, names, contact details, visa or legal facts, free text, practitioner numbers or order identifiers. Successful quotes and subsequent order/payment states are separately recorded in LodgeHQ's first-party operational database; those records are used for internal funnel evidence and are not copied into the optional Google event payload. When optional measurement is enabled, use the “Privacy choices” control to change either choice later.
The current application configuration does not make an Australia-only processing or storage promise. These providers may operate infrastructure or support functions in other countries. If a receiving body, contract or professional duty requires a particular data location, contact LodgeHQ before uploading and do not proceed until the requirement is confirmed in writing.
5. Retention and deletion
- Unpaid quote uploads: abandoned files under the quote-staging path are scheduled for deletion after they are more than 35 days old. An emailed quote link may expire sooner than the stored file.
- Successful checkout: the file is copied from quote staging into the order-file path and the staging copy is then scheduled for immediate deletion as part of checkout.
- QuoteEvent audit records: deleting or relocating a staged R2 object does not delete the separate database audit row created for a successfully priced instant quote. That row can continue to hold the file name, former R2 key, page and pricing data, analysis layer, truncated unsalted IP-derived hash and user agent described above. An R2 key retained in the row may no longer resolve to an object after object deletion. The current code has no fixed automatic deletion period for QuoteEvent rows.
- Referral records: the lhq_ref cookie expires 30 days after it is set and can be deleted in your browser at any time. The current code has no fixed automatic deletion period for ReferralVisit rows or for the channel name stored on QuoteEvent and order records.
- Order files and message attachments: the current code does not apply a fixed automatic deletion period. They can remain with the order record for delivery, revisions, disputes, support and record integrity.
- Translator certificate files: the current code does not apply a fixed automatic object-deletion period to uploaded credential evidence.
- Account deletion: deletion is blocked while an order or payout is active. An account with no shared transaction history can be hard deleted. Where transaction history exists, the account is soft deleted and direct profile fields are scrubbed, but related orders, messages, reviews and documents can remain.
You may contact LodgeHQ to ask about access, correction or deletion of a retained file or related personal information. A request is assessed case by case, subject to identity verification, applicable law, active work, another party's records, disputes, fraud prevention and record-keeping needs. A quote audit row may not be reliably linkable to a person where no account or contact detail was recorded, and LodgeHQ does not promise that every record can or must be deleted. Deleting an account or storage object does not automatically delete every order or QuoteEvent database record.
6. Security controls and limitations
Current controls include HTTPS in production, hashed passwords, authenticated file routes, role and order-ownership checks, approved-language-pair checks for translator previews, watermarked preview pages and time-limited signed storage links. Some administrator manual-review links can remain valid longer than ordinary one-hour order-file links.
No internet service can promise absolute security. If the sensitivity of a document makes the described processing or pre-assignment preview model unsuitable, do not upload it and contact us first.
7. Access, correction, deletion and complaints
Email [email protected] to ask what personal information LodgeHQ holds, request access or correction, request account or file deletion, withdraw optional email communications, or make a privacy complaint. Include enough information to verify your identity and locate the relevant account or order, but do not email a new identity-document copy unless requested through a suitable channel.
LodgeHQ will investigate the request and explain the outcome. Where the Australian Privacy Act applies and you are not satisfied after giving LodgeHQ a reasonable opportunity to respond, the Office of the Australian Information Commissioner provides information about privacy complaints.
8. Suspected data breaches
Report suspected unauthorised access, disclosure or loss immediately to [email protected] with the subject “Privacy incident”. LodgeHQ will assess and contain the issue, preserve relevant evidence, review who may be affected and notify affected people and the OAIC where notification is required by applicable law. The OAIC explains the current Notifiable Data Breaches framework.
9. Changes to this policy
This policy will be reviewed when the upload, automated-analysis, storage, translator-access, payment, email or retention architecture changes. Material changes should update the date above and be described through the corrections or revision process.
Related: Terms of Service, Corrections Policy and Contact.