Version 4 · Last updated: July 19, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between TrackMyPlace (the "Processor") and the agency customer that subscribes to the TrackMyPlace platform (the "Controller") and applies to the Processor's handling of Personal Information on the Controller's behalf.
The Processor handles Personal Information solely to provide the TrackMyPlace platform to the Controller and its authorised users. Processing is described below:
The Processor will:
The Controller authorises the Processor to engage the sub-processors listed below to deliver the platform. The authoritative list of sub-processors, including data categories and country of processing, lives in our Privacy Policy (Section 7) and is reproduced here for convenience.
| Sub-processor | Purpose | Country of processing |
|---|---|---|
| Supabase | Authentication, primary database (Postgres), file storage. | Australia (Sydney, ap-southeast-2) |
| Vercel | Application hosting, edge/serverless execution. | US |
| Stripe | Subscription billing and payment processing. | US / Ireland |
| Xero | Accounting ledger for TrackMyPlace's own billing records (invoices, payments, refunds). | US |
| Twilio | SMS delivery to clients you contact through TrackMyPlace. | US |
| Resend | Transactional email delivery. | US / EU |
| Google (Workspace APIs) | Gmail, Calendar, Contacts and Drive integrations (opt-in per user). | US |
| Google Maps Platform | Address geocoding and Places autocomplete. | US |
| Microsoft (Graph) | Outlook email integration (opt-in per user). | US / EU |
| VaultRE (MRI Software) | CRM integration - property, listing and contact lookup (opt-in per team). | Australia |
| Slack | Team messaging integration (opt-in per team). | US |
| Anthropic | Optional AI features (assistant, message drafting, summaries, text analysis) and the weekly agency digest narrative. Disabled by default at the platform level; only request text is sent - never client email/phone, document files, or images. | US |
| Sentry | Application error and performance monitoring. | US / Germany |
| Linear | Engineering issue tracking for in-app feedback submissions. | US |
| Upstash | Redis-backed rate limiting and short-lived caching, and the background-job queue (QStash) that runs deferred work such as email and SMS delivery; job payloads may transiently include a recipient email address in transit. | US |
The Processor will give the Controller at least 30 days' notice before engaging a new sub-processor or replacing an existing one. The Controller may object on reasonable data-protection grounds within that period. If the parties cannot agree on a resolution, the Controller may terminate the affected service and receive a pro-rata refund of any pre-paid fees that cover the remainder of the subscription term.
The Processor will provide the Controller with self-service tools (data export, deletion, agent-level revocation of integrations) sufficient to satisfy data-subject access, correction, and deletion requests under APP 12 and APP 13. Where a request cannot be fulfilled through the self-service tools, the Processor will assist the Controller on a best-efforts basis within 5 business days.
The Processor will notify the Controller as soon as practicable, and in any event within 72 hours, of becoming aware of an eligible data breach (as defined in Part IIIC of the Privacy Act 1988 (Cth)) affecting the Controller's Personal Information.
Notifications will be sent to:
The Processor will provide the information the Controller reasonably needs to fulfil its own notification obligations to the Office of the Australian Information Commissioner (OAIC) and affected data subjects.
The Processor maintains the following controls:
On reasonable written notice and no more than once per calendar year, the Controller may request either:
The parties will agree on the audit scope in writing in advance and will conduct the audit in a way that does not unreasonably disrupt the Processor's services to other customers.
On termination of the Controller's subscription, the Processor will:
Liability under this DPA is subject to, and aggregated with, the liability cap in the agreement between the parties governing the Controller's subscription to the TrackMyPlace platform (which, for most agency customers, is our published Terms of Service). Nothing in this DPA limits:
The Controller may countersign this DPA either at signup or, at any time after signup, by clicking Accept DPA in Settings → Compliance. The acceptance is recorded against the team and is binding on behalf of the agency. Re-acceptance is required whenever TrackMyPlace publishes a new version of this document.
Questions about this DPA, requests for the countersigned PDF, or NDB-related notifications: privacy@trackmyplace.com.
Strictly necessary cookies keep you signed in and the platform working. Optional analytics and marketing cookies help us improve TrackMyPlace. You can change your choice at any time. Learn more.