Privacy Policy

Effective Date:

Last Updated:

PROTOTYPE DOCUMENT: NOT LEGAL ADVICE, NOT YET REVIEWED BY A LAWYER

TradeTicket is a prototype, built to be demonstrated to a training provider, not deployed to real apprentices. This page describes, honestly, what the prototype actually collects and does today. It does not describe a finished, production-ready privacy programme, and it has not been reviewed by a lawyer. Anyone considering handling real apprentices' personal information with software like this must get this reviewed properly first, and must close the gaps this page flags along the way (missing consent capture, no enforced retention policy, and the authentication stub described in section 9, among others).

This Privacy Policy explains how TradeTicket ("TradeTicket", "we", "us", or "our") collects, uses, discloses, and protects personal information, with reference to the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Student Identifiers Act 2014 (Cth).

1. Definitions

  • "Personal Information" has the meaning given in the Privacy Act 1988 (Cth): information about an identified individual, or an individual who is reasonably identifiable.
  • "Card" means a week's record of logged work, described in our Terms of Service.
  • "Evidence" means a photo or PDF an Apprentice attaches to a Card.
  • "Platform" means the TradeTicket web application.
  • "RTO" means a Registered Training Organisation, including a TAFE.
  • "USI" means the Unique Student Identifier defined under the Student Identifiers Act 2014 (Cth): a national identifier issued to VET students, with its own legal handling obligations separate from ordinary personal information.

2. Scope and Application

This Policy applies to Apprentices, Employers and their Supervisors, RTO/TAFE staff, and administrators who use the Platform.

We have written this with regard to the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the Student Identifiers Act 2014 (Cth), and the VET regulatory setting apprentices and RTOs operate in (the ASQA/DEWR Standards for RTOs). We are not a certified or audited APP entity (see the prototype notice above).

3. Information We Collect

This section describes what the Platform actually stores, based on its data model, not a generic list.

CategoryWhat's StoredWho
IdentityFull name, email addressAll Users
Student identifierUSIApprentices only
Logged workWork areas, hours, support level, activities, equipment, units claimed, per CardApprentices
Evidence filesUploaded photos and PDFs, plus the metadata described in section 5Apprentices
EmploymentEmployer name and contact details; the Apprentice's link to that EmployerApprentices, Employers
Supervisor credentialsQualification and licence number fields (present in the data model; not yet collected or verified by any screen; see section 10)Employers/Supervisors
Enrolment & assessment recordsQualification, enrolment status and dates, RTO assessment outcomes and notesApprentices
Decisions and audit recordsEvery approval, rejection, and override, with the actor, timestamp, and reason (see section 9)All Users, about actions they take
Cohort tagsShort grouping labels (e.g. an intake code) used by RTO staff to group apprentices on the cohort screenApprentices

We do not collect Tax File Numbers, payment card details, or biometric data. We do not currently collect a photograph of the person themself as an identity document. "Photograph" in this Policy means Evidence photos of work, covered in section 4.

4. Photographs Taken on Worksites

This is worth being direct about. Evidence photos are taken on active worksites, and worksite photos routinely capture more than the Apprentice's own work: other tradespeople, clients, members of the public, client premises, and equipment that isn't the Apprentice's. None of those other people have been asked for consent by TradeTicket, and TradeTicket has no way to know who else appears in a photo before it's uploaded.

What this means in practice:

  • the person taking the photo (the Apprentice) is responsible for using reasonable judgement about what they photograph, per section 6.2 of our Terms of Service
  • we store whatever is in the photo as uploaded; we do not detect or blur faces, number plates, or client identifying information
  • the photo is visible to the people described in section 8 (Who Sees What), not published publicly
  • if a photo shouldn't have been taken or shared, contact us and we will remove it; we cannot undo the fact that it was captured on-site in the first place

Advice to apprentices: when in doubt, don't photograph a client's face, a client's private documents or screens, number plates, or house/site details that identify a client's home. Photograph the work (the panel, the pipe run, the switchboard), not the people or the property around it.

5. Evidence Metadata and Duplicate Detection

The whole point of attaching Evidence is that a signed-off Card should mean something. So when a file is uploaded, we automatically extract and store:

  • A SHA-256 hash of the file's content: a fingerprint used for tamper-evidence (if the stored file ever stops matching this hash, it was altered after upload) and for duplicate detection, below.
  • For photos only: the camera's own capture timestamp and camera make/model, read from the file's EXIF data where present. PDFs carry no camera EXIF, so only the hash is extracted for them.

We do not currently extract location/GPS data from photos. The metadata we read is limited to capture time and camera make/model. If a photo's EXIF data includes GPS coordinates, we do not read, store, or display them in this build.

A Supervisor reviewing a Card is shown, per photo: whether it carries real camera data or none at all, and whether the camera's own timestamp falls outside the week being claimed. This does not block a sign-off; it puts the questions a careful reviewer would ask in front of them at the point of deciding.

5.1 Duplicate Detection Is Cross-User

This is a genuine cross-user data flow and we want to be explicit about it: when Evidence is uploaded, its content hash is compared against every other Evidence file already stored on the Platform, not just the same Apprentice's own uploads but everyone's. If an identical file has already been uploaded by a different Apprentice, the Supervisor reviewing the Card is told that a byte-for-byte identical file exists elsewhere in the system, uploaded by a different apprentice. They are not shown that other apprentice's name or account, only that a match exists, but the practical effect is that uploading a file can surface information connecting your Evidence to someone else's account.

We do this because the same photograph cannot honestly evidence two different apprentices' work. If your Evidence gets flagged this way and you believe it's a mistake, talk to your Supervisor or contact us.

6. Your USI

If you are an Apprentice, we may hold your Unique Student Identifier (USI). The USI is a nationally regulated identifier under the Student Identifiers Act 2014 (Cth), with its own legal handling requirements separate from ordinary personal information. It identifies your VET records across every training provider you ever use, for life.

Honestly: in this prototype, the USI is stored as a plain text field like any other record. It does not currently receive any additional technical protection beyond the rest of your account data (see section 10 on what security actually exists today). Before this platform handles a real USI, it needs handling that meets the Student Identifiers Act's requirements specifically, which a lawyer and the Student Identifiers Registrar's guidance should confirm.

7. Purpose of Collection

We collect and use this information to:

  • let an Apprentice log workplace experience and attach Evidence to it
  • let a Supervisor review, and approve or reject, that logged work
  • let an RTO/TAFE oversee a cohort, record assessments, and override a decision where warranted
  • compute progress towards each unit of competency and overall readiness
  • run the authenticity checks described in section 5
  • keep the audit trail described in section 9
  • let an administrator manage Users and Employers on the Platform

We do not sell personal information, use it for advertising, or use it for any purpose unrelated to the apprenticeship record-keeping this Platform exists to do.

8. Who Sees What

Access is role-based, enforced both in the page itself and, as a second check, at the network level before a page renders. In outline:

  • You can see your own logged work, Evidence, and progress.
  • Your Employer's Supervisors can see the Cards and Evidence you submit to them for sign-off, and your progress summary.
  • Your RTO/TAFE staff can see your full cohort record (logged work, Evidence, assessments, and enrolment) across every Employer, because their oversight role spans the whole qualification, not just one employer's slice of it.
  • Administrators can see account and employer records needed to manage Users and Employers on the Platform.
  • As described in section 5.1, a duplicate-file match can surface a limited signal (not identity) about another Apprentice's upload to a Supervisor reviewing your Card.

We do not disclose your personal information outside these roles, except where required by Australian law, or with your consent.

9. The Audit Trail

Every approval, rejection, RTO override, and enrolment change is recorded permanently: who did it, what it affected, when, and (for overrides and enrolment changes) the reason given.

This audit trail is not something you, as the apprentice a record is about, can have deleted. It exists precisely so a sign-off means something later. An RTO or auditor needs to be able to trust that a record wasn't quietly altered after the fact. If you dispute what a record says, the right path is to contact whoever made the decision, or your RTO, not to have the record erased.

10. Data Security: What Actually Exists Today

We would rather tell you plainly what this prototype does and doesn't do than list generic security claims that don't apply to it.

  • Sign-in is a demo stub, not real authentication. There are no passwords. A cookie remembers which seeded person you're acting as. This is fine for a laptop demo and must never be used with real people's data as-is.
  • The whole database is a single local file, and uploaded Evidence is saved to local disk on whichever machine runs the Platform, not to encrypted cloud storage.
  • There is no rate limiting, no dedicated intrusion detection, and only the input validation each part of the Platform performs for itself, not a uniform, audited layer.
  • Role-based access control does exist, and is checked both on the page and, separately, before a protected page is even allowed to render.

Supervisor qualification and licence number fields exist in our data model, reflecting that Victorian employer obligations require on-the-job training be supervised by "a suitably qualified or experienced person", but no screen in this build currently collects, verifies, or displays them yet.

This build is not production-hardened. None of the above should be read as a security certification. A production version needs real authentication, encrypted storage appropriate to the sensitivity of USIs and worksite photos, and a proper security review, none of which this prototype claims to have.

11. Data Retention

Nothing in this prototype currently enforces how long records are kept or automatically disposes of them. There is no scheduled deletion job and no configured retention period. That is a gap, not a policy choice, and it needs to be closed before this platform holds real records.

What we can say about intent: VET records generally need to be kept for a substantial period to support later verification of a person's qualification (the exact period is set by the VET Quality Framework and the relevant RTO's own record-keeping obligations, not by us), so a real retention policy for TradeTicket would need to be at least that long for competency-relevant records, and would need a lawyer and the operating RTO to confirm the actual figure, rather than us guessing one here.

Also unresolved: because the audit trail (section 9) and Cards contributing to a competency decision are not deletable by the person they concern, a "right to deletion" conversation for this product is more nuanced than a typical consumer app's. See section 12 and our Terms of Service's termination section.

12. Your Rights

Under the Privacy Act 1988 and the Australian Privacy Principles, you have rights including:

  • Access (APP 12): you may ask what personal information we hold about you.
  • Correction (APP 13): you may ask us to correct inaccurate, incomplete, or out-of-date information.
  • Complaint (APP 1.4): you may lodge a complaint about how we've handled your information (see section 16).

These rights sit alongside, not above, the audit-trail and sign-off integrity described in sections 9 and 11: a correction request about a fact will be considered on its merits, but a signed-off record isn't simply rewritten on request, because doing so would undermine the thing the record exists to prove.

To exercise any of these rights, email us at nick.patterson [at] origae.dev.

13. Cookies

The Platform sets a small number of strictly necessary cookies used to remember which demo user you're signed in as (session/role identification). We do not use analytics cookies, advertising cookies, or any third-party tracking on this build.

A production deployment might reasonably add analytics later; if it does, this section will need updating to name the tool and describe what it collects, rather than us describing a tool that doesn't exist yet.

14. Apprentices Under 18

Australian trade apprenticeships can start while a person is still a minor. Where an Apprentice is under 18, a parent or guardian may request access to their child's personal information or ask us to correct inaccurate information, subject to their training contract and applicable law.

We only collect information necessary for logging, evidencing, and signing off apprenticeship work: the same categories described in section 3, regardless of the Apprentice's age.

15. Automated Processing

Two things in the Platform are automated:

  • Evidence authenticity checks (section 5): camera-data presence, duplicate detection, and out-of-week timestamps. These flag things for a human reviewer to consider; they never approve, reject, or otherwise decide anything by themselves.
  • Progress computation: a rules engine turns your approved Cards and RTO assessments into a percentage-complete view per unit and an overall readiness view. This is a calculation, not a competency decision; only your RTO makes that decision.

No adverse decision about you is made solely by either of these. A human (a Supervisor or an RTO assessor) always makes the actual call, and can see the same information you would want them to weigh.

16. Changes to This Policy

We may update this Privacy Policy as the Platform changes. The "Last Updated" date above will be revised when we do. Because this is a prototype, we don't yet run a formal notice process for changes; a real deployment would need one.

17. Complaints

If you believe we have mishandled your personal information, you can complain to us directly at nick.patterson [at] origae.dev. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner (OAIC)

GPO Box 5218, Sydney NSW 2001

Phone: 1300 363 992

Website: www.oaic.gov.au

18. Contact Us

For any questions about this Privacy Policy or our privacy practices:

TradeTicket

Email: nick.patterson [at] origae.dev

This Privacy Policy is governed by the laws of Australia. By using TradeTicket, you acknowledge that you have read and understood this Privacy Policy.