Privacy

Privacy at GoalPush

This policy explains how eHustle Pty Ltd handles information when providing GoalPush, a business-use conversion signal service.

Effective
30 July 2026
Version
1.0

Who is responsible

GoalPush is operated by eHustle Pty Ltd from Gold Coast, Queensland 4216, Australia. Privacy enquiries can be sent to privacy@goalpush.io.

Information we handle

  • Account, workspace and support information supplied by authorised users.
  • Meaningful conversion events configured by a customer, such as a lead or purchase, with timestamps, goal state and optional value.
  • Explicit email or phone data only when configured and permitted by the customer’s consent state. GoalPush normalises and hashes these values for matching and keeps reversible enrichment encrypted and server-only.
  • Allowlisted advertising click identifiers where ad storage and ad user data permission allow them. Full URLs, unrelated queries, page-view histories and persistent visitor profiles are not stored.
  • Billing identifiers and billing contact information needed to operate subscriptions. Stripe receives payment information directly; GoalPush does not receive card numbers or CVCs.
  • Bounded security, audit, diagnostic and service-operation records.

Why we use information

We use information to authenticate authorised users, operate and secure workspaces, process configured conversion events, deliver consent-eligible signals to destinations a customer enables, manage billing, provide support, prevent abuse, investigate incidents and meet legal obligations.

GoalPush is not a consent-management platform. Customers decide what events to configure and remain responsible for obtaining any required consent and giving their own users appropriate notices.

Providers and international processing

Firebase and Google Cloud provide core hosting, authentication, database, Functions, logging and monitoring. Stripe processes payments and subscriptions. Google Ads/Data Manager, Meta and Shopify process information only when the customer enables the relevant destination or integration.

Approved providers may process information outside Australia. We use provider data-processing terms, contractual safeguards and technical and organisational controls, and take reasonable steps to require handling consistent with applicable Australian privacy obligations. We do not claim all data remains exclusively in Australia.

Retention and deletion

  • Canonical events and private enrichment: 90 days.
  • Application billing receipts: 90 days.
  • Application and operational logs: 30 days.
  • Security and audit logs: 365 days.
  • Cancelled-account operational data: 90 days after the paid service period ends, then deletion or irreversible anonymisation.
  • Financial, tax, transaction and legally required records: at least five years, or longer where Australian law requires.

Daily backups are retained for seven days and weekly backups for fourteen weeks. Deleted information may remain in encrypted backups until the relevant backup expires. Legal holds, fraud evidence and active disputes may suspend deletion only for affected records.

Your choices

Authorised workspace users can correct account settings, disconnect destinations, export available data and request deletion. GoalPush also provides a scoped erasure workflow for eligible email or phone enrichment while retaining non-identifying canonical and audit evidence where appropriate. See the data deletion process.

Version history

Version 1.0 — 30 July 2026: initial controlled-launch policy.