Legal
Privacy Policy
How Aspire 2: CMS handles personal information for the platform, tenant accounts, and tenant website enquiries.
Last updated: 2 June 2026. This MVP policy is written for launch readiness and has not yet been reviewed by a lawyer.
Who We Are
Aspire 2: CMS is a product operated by Mitchell Craig Roemling trading as Aspire 2: X, ABN 21 658 558 016, as a sole trader in Brisbane, Queensland, Australia. In this policy, "Aspire", "we", "us", and "our" means that business.
Our Role
We handle tenant-owner information for our own platform purposes, including account setup, authentication, billing, support, security, and product operations.
When a visitor submits a lead or contact form on a tenant website, we process that information to provide the CMS and lead delivery service to the tenant business. The tenant business decides how it responds to and uses that enquiry.
Information We Collect
- Tenant account details: name, email address, business name, ABN if provided, business profile details, subdomain, and account role.
- Billing details handled by Stripe: customer ID, subscription status, plan, invoices, and payment lifecycle events. We do not store card numbers.
- Tenant website content: pages, services, staff entries, images, files, and profile content uploaded by tenants.
- Lead form details: name, email, phone, service type, message, source URL, and related form metadata.
- Operational data: authentication identifiers, audit/provisioning records, IP-derived request context available to infrastructure providers, logs, and security events.
- Analytics data: admin product analytics if an admin user accepts analytics; public site aggregate analytics that do not use visitor cookies.
Why We Use Information
- To create and manage tenant accounts and websites.
- To authenticate users through WorkOS.
- To process subscriptions and billing through Stripe.
- To deliver lead notifications to tenant businesses.
- To provide support, troubleshoot issues, prevent abuse, and secure the platform.
- To understand product usage where analytics has been accepted or where public analytics are aggregate and low risk.
- To comply with legal, accounting, tax, security, and dispute obligations.
Sensitive Information
Aspire 2: CMS is not designed for tenants to store clinical records, treatment notes, government identifiers, or other high-risk sensitive information in the CMS. A tenant website enquiry may still include sensitive information if a visitor chooses to write it in a form. We only process that enquiry to provide the service to the tenant business and to maintain security and records.
Disclosure And Sub-processors
We use trusted service providers to run the platform. These include Cloudflare, WorkOS, Stripe, Resend, and PostHog. Some providers process data in the United States, Australia, or globally. See our Sub-processor List.
Security
We use reasonable technical and organisational safeguards for the MVP stage, including authenticated admin access, tenant scoping, provider-managed payment handling, anti-spam verification on public forms, and role-based controls. No online service can guarantee absolute security.
Retention
Our current retention targets are documented in the Terms and operationally in
docs/data-retention.md. In summary: leads target 24 months from last interaction, cancelled
tenant account data targets 90 days, Stripe/tax records may be retained for 7 years where required, logs
target 90 days, and backups/cache are removed on normal rotation.
Access, Correction, Deletion, And Complaints
Contact privacy@aspire2cms.com to request access, correction, deletion, or to make a privacy complaint. If your request relates to a tenant website enquiry, we may need to involve the tenant business because they control the customer relationship.
We aim to acknowledge privacy requests within a reasonable time and handle complaints fairly. If you are not satisfied and Australian privacy law applies, you may be able to contact the Office of the Australian Information Commissioner.
EU And UK Visitors
Aspire 2: CMS is built for Australian small businesses and does not actively target EU or UK customers. If EU or UK data protection law applies to your use of the platform or a tenant website, you may have rights to access, rectify, erase, restrict, object to processing, and request portability of your personal data. Contact privacy@aspire2cms.com.
Contact
Privacy: privacy@aspire2cms.com
Support: support@aspire2cms.com
Security: security@aspire2cms.com