CommonMind
How it worksPlatform demoAbout
Sign inTry it free
Legal

Privacy Policy

What we collect, what we do with it, and what we will never do. Your data is yours.

Last updated 23 September 2026

1. About This Policy

CommonMind Pty Ltd (“CommonMind”, “we”, “us”, “our”) operates the CommonMind platform at commonmind.co. This Privacy Policy explains how we collect, use, store, and share information when you use our platform.

We take privacy seriously. Your data is yours. We will never sell your raw data, and we do not train artificial intelligence models on it. This policy explains exactly what we do with the data you provide and how we protect it.

CommonMind operates two products, and on the question of data shared between customers they differ — deliberately. The Venue Intelligence product (hospitality) operates a network layer described in section 3.3. The Construction Intelligence product (tender analysis, shown in the application as “Trace”) does not: nothing from your tenders, findings, decisions or outcomes is shown to another customer, and nothing is counted across customers unless your organisation opts in (section 3.3). Wherever a section below applies to only one product, it says so.

By using CommonMind, you agree to this Privacy Policy. If you do not agree, please do not use our platform.

Questions about this policy: contact@commonmind.co

2. Information We Collect

2.1 Information You Provide Directly

When you sign up and use CommonMind, you may provide:

Both products:

  • Account information — name, work email address, business name, location, role
  • Communications — messages sent to us via the platform or email

Construction Intelligence:

  • Tender documents — specifications, drawings, bills of quantities, contracts, addenda and scans, uploaded or forwarded to your project’s intake address
  • Commercial data — your declared estimate, supplier quotations, bid and no-bid decisions, awards and outcomes
  • Judgements — the verdicts, severities and assignments your team records against findings
  • Company profile — sectors, geography, value range, delivery methods, capabilities and preferences

Tender documents may incidentally contain personal information about named individuals — a contact on a title block, a signatory. We process it only as part of the document and do not extract, index or use it separately. We do not ask for and do not want employee records, payroll, or personal information about site workers.

Venue Intelligence:

  • Sales data — transaction records exported from your point-of-sale system
  • Invoice and supplier data — forwarded supplier invoices and cost information
  • Menu and pricing information — your venue’s current menu items and prices
  • Staff and operational information — roster data, trading hours, capacity
  • Qualitative information — responses to in-platform questions about your venue

2.2 Information Collected Automatically

When you use our platform, we automatically collect:

  • Usage data — which features you use, how often, and when
  • Device information — browser type, operating system, IP address
  • Log data — page views, actions taken, errors encountered
  • Performance data — response times, feature engagement metrics

2.3 Information from Third Parties

With your permission, we may collect data from:

  • Point-of-sale systems — Square, Lightspeed, Toast, Impos (via OAuth or CSV export)
  • Accounting software — Xero, MYOB (via OAuth)
  • Google My Business — reviews, popular times, business information
  • Public data sources — weather, events, demographic data, foot traffic sensors

3. How We Use Your Information

3.1 To Provide the Service

We use your information to:

  • Generate intelligence and insights specific to your venue
  • Produce your daily morning brief, tonight’s playbook, and other AI-generated content
  • Detect revenue leakage, pricing gaps, and operational inefficiencies
  • Provide causal analysis of your venue’s performance
  • Generate demand forecasts for your venue
  • Process and respond to invoices forwarded to your ingest address

3.2 To Improve the Platform

We use aggregated, anonymised usage data to:

  • Improve the accuracy and relevance of our intelligence systems
  • Develop new features and capabilities
  • Fix bugs and technical issues
  • Monitor platform performance and reliability

3.3 Construction Intelligence: nothing crosses to another customer without your opt-in

This is the section construction customers should read first.

Your tender documents, findings, judgements, decisions and outcomes are used to serve your organisation only. They are never shown to another customer, never licensed to anyone, and never used to train AI models.

Two things can be counted across customers, and only if your organisation opts in — separately, by your administrator in the Team settings or in writing to us. Neither ever defaults to on, and a policy update is never how it happens.

  • Published totals — how many tenders, how much tender value, how many pages and how many risks have gone through CommonMind, shown on our website. They are rounded down, published only once at least five consenting firms and A$100 million of tender value are counted, and never name a firm
  • De-identified patterns — which kinds of issue recur across firms, counted only across at least five consenting firms, with identifiers removed. Until five firms have opted in, nothing across firms is shown to anyone; after that, a firm sees only counts, never another firm or its tenders

To make the second possible, we keep a de-identified record of the kinds of issue found in each tender — no document text, names, prices or values — marked with whether your organisation has consented. Without that consent it is never counted. It is deleted when the tender, or your organisation, is deleted.

You can withdraw either consent at any time. Your tenders are then left out of every later count; totals already published are not recalculated retrospectively.

3.4 Venue Intelligence: the network layer (hospitality only)

This section applies only to the venue product. It does not apply to Construction Intelligence and grants no rights over tender data.

The venue product operates a collective intelligence network (“HIVE”). With your consent, provided by accepting our Terms:

  • What we do: derive de-identified aggregate patterns from contributing venues’ data
  • What we produce: aggregate patterns and trends (for example, “Espresso Martini orders up 25% across Melbourne bars”)
  • Minimum threshold: at least 5 distinct businesses must contribute before any aggregate is produced. Below that, nothing is produced at all
  • What we never do: identify your venue in an aggregate output, or relay another venue’s prices, figures or commercial positions to you — or yours to them
  • Identifying details are stripped from any evidence attached to a pattern

We describe these aggregates as de-identified, not anonymous. De-identified means identifying details have been removed and a minimum-contributor threshold applies, which is what we implement. “Anonymous” would claim more than we can support, and we would rather use the accurate word.

You may opt out at any time and your own venue intelligence continues to work. See Section 7 (Your Rights).

3.5 Licensing aggregate intelligence (venue product only)

CommonMind may licence de-identified aggregate venue intelligence to third parties such as suppliers, distributors, government bodies and industry associations. Such intelligence:

  • Does not identify your venue
  • Does not contain your raw data
  • Does not contain your specific sales figures, costs or financial information
  • Consists only of aggregate patterns meeting the five-business threshold in 3.4

No construction data is ever licensed to anyone, in any form, aggregated or otherwise. Opting out of 3.4 also removes you from this.

4. How We Share Your Information

4.1 We Do Not Sell Your Raw Data

We will never sell, rent, or trade your raw venue data to any third party. This is an unconditional commitment.

4.2 Service Providers

We share data with trusted service providers who help us operate the platform:

Construction Intelligence:

  • Amazon Web Services (AWS), Sydney — application hosting, the database and encrypted document storage
  • Vercel — web application hosting
  • Supabase — sign-in
  • OpenRouter, and the host it routes to for the configured AI model (currently Anthropic’s Claude Opus 5.5, which writes the findings, and OpenAI’s GPT-6 Luna, which checks them) — the AI reading of passages from your tender documents, restricted to providers that do not train on what they are sent. A provider may keep what it is sent for a limited time to monitor abuse. This processing may take place outside Australia, and it can be switched off
  • Resend / Postmark — email, such as invitations and notices you choose to send

Venue Intelligence:

  • Supabase — authentication and database services
  • Railway — backend hosting and infrastructure
  • Vercel — frontend hosting
  • Amazon Web Services (AWS) — file storage
  • Databricks — data processing and analytics
  • OpenRouter / Anthropic / OpenAI — AI language model processing
  • Resend / Postmark — transactional and outbound email delivery
  • Twilio — SMS delivery (only for messages you approve to send)
  • Square — POS price updates (only when you connect Square)

All service providers are bound by data processing agreements and may only use your data to provide services to CommonMind. They may not use your data for their own purposes.

4.3 Legal Requirements

We may disclose information if required by law, court order, or government authority. We will notify you of any such disclosure unless prohibited by law.

4.4 Business Transfers

If CommonMind is acquired or merges with another entity, your data may be transferred as part of that transaction. We will notify you and provide an opportunity to delete your data before any such transfer.

5. Data Security

We take security seriously and implement the following measures:

  • Encrypted data storage — uploaded files in object storage use server-side AES-256 encryption; other stored data sits on provider-managed encrypted volumes
  • Encrypted transmission — all data transmitted over HTTPS/TLS
  • Per-tenant isolation — each business’s data is strictly isolated. In the construction platform this is enforced twice: by the application’s own tenant gate, and by database row-level security beneath it. A request that has not established whose data it may read fails loudly rather than returning an empty result
  • Existence is not leaked — another customer’s record returns “not found”, never “forbidden”, because the second answer would confirm it exists
  • Application-layer encryption — construction documents are encrypted by the application before they reach disk or object storage. In production the service refuses to start without a working encryption key
  • Sign-in — short-lived signed tokens. In the construction pilot, people sign in with a one-time code sent to their work email; deleting or exporting tender data, and changing who has access, also needs a code from an authenticator app
  • No standing staff access — in the construction platform, CommonMind staff cannot open your tenders through the product. When support needs to, it is a read-only grant with a written reason, lasting an hour by default and eight at most, which your administrator can see and revoke, and every use is recorded
  • Audit trail — every access to a project and every change is recorded against a named account
  • Malware scanning — every uploaded construction file is virus-scanned before it is read; a file that is not clean, or that could not be scanned, is held back and named, never silently dropped
  • Untrusted document handling — text from your documents is passed to AI models as data and never as instructions, and an assertion whose quoted evidence cannot be found in the document it cites is discarded before you see it
  • Regular security reviews — ongoing internal audits and automated adversarial testing on every change

We have not yet had an independent penetration test. The testing above is extensive and automated, but it is ours. An independent test is planned before confidential live use expands. We would rather tell you this than let you assume otherwise.

No system is completely secure. In the event of a data breach affecting your information, we will notify you within 72 hours and take immediate steps to mitigate harm.

6. Data Retention

We retain your data as follows:

  • Active account data — retained for the duration of your account
  • Sales and invoice data — retained for the duration of your account to enable historical analysis
  • Account information — retained for 30 days after account closure
  • Your raw data (venue) — permanently deleted 30 days after account closure upon request
  • Your data (construction) — tender documents, findings, judgements, outcomes and the de-identified pattern records are removed from the live service as soon as you ask (your administrator can also delete a tender, or the whole organisation). Copies in database backups and in the document store’s version history expire within 90 days. Deleting a project removes its event history with it
  • Audit trail (construction) — the record of who accessed or changed what is kept after deletion, so that the deletion itself can be verified. It holds account and action details, not your documents
  • De-identified aggregate data (venue product only) — may be retained as part of the HIVE network, as it identifies no business and cannot be disentangled from other contributions. For construction, published totals already on our website are not recalculated retrospectively; nothing else derived from your tenders is kept after deletion
  • Usage logs — retained for 90 days

7. Your Rights

You have the following rights regarding your data:

Access

You may request a copy of all data we hold about your business at any time. We will provide this within five (5) business days at no cost. Contact: contact@commonmind.co

Correction

If any data we hold is inaccurate, you may request correction. We will update it within two (2) business days.

Deletion

You may request deletion of all your raw data at any time.

Construction: your data, including the de-identified pattern records, is removed from the live service as soon as you ask, and backup and version copies expire within 90 days. Totals already published on our website are not recalculated retrospectively. Venue: we will permanently delete it within thirty (30) days. De-identified aggregate data already contributed to the HIVE network identifies no business and cannot be disentangled from other contributions, so it cannot be individually withdrawn.

Export

You may request a complete export of your data in a machine-readable format (CSV or JSON) at any time. We will provide this within five (5) business days.

Construction customers can also export at any moment without asking us: the Project Risk Passport — what was found, what was decided, what was done and what is still open — exports from the application as JSON, CSV or plain text.

Opt In, and Out, of Anything Shared

Construction: nothing is counted across customers unless your organisation opts in (section 3.3). Your administrator can switch either consent on or off at any time in the Team settings, or ask us to. If you use the venue product, you may opt out of contributing to the HIVE network at any time. Your individual venue intelligence will continue to function. To opt out, contact contact@commonmind.co or change your settings in the platform.

Withdraw Consent

You may withdraw consent to data processing at any time by closing your account. This will trigger deletion of your raw data as described above.

8. Cookies and Tracking

CommonMind uses the following cookies and tracking technologies:

  • Session cookies — required for authentication, deleted when you close your browser
  • Preference cookies — remember your settings and preferences
  • Analytics — we use Mixpanel to understand how the platform is used. This data is aggregated and does not identify individual users to third parties

The construction workspace loads no analytics or advertising scripts. It keeps your sign-in in your browser’s local storage, and signing out removes it.

You may disable cookies in your browser settings. This may affect some platform functionality.

9. Children’s Privacy

CommonMind is a business platform intended for use by adults operating commercial venues. We do not knowingly collect data from persons under 18 years of age. If you believe we have collected data from a minor, contact contact@commonmind.co immediately.

10. International Data Transfers

CommonMind is based in Australia. Your data may be processed by service providers in other countries including the United States. We ensure all international transfers are protected by appropriate safeguards including data processing agreements.

Today, construction documents and records are held in AWS’s Sydney region. The AI reading sends passages of your tender documents to the host serving the configured AI model, which may be outside Australia. If that is a problem for a tender, tell us: the AI reading can be switched off, and CommonMind’s own checks still read every page.

If you are located in the United Kingdom or European Economic Area, we process your data in accordance with UK GDPR and GDPR respectively. Our lawful basis for processing is legitimate interests (providing the intelligence service you have contracted for) and, where required, explicit consent.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address at least fourteen (14) days before changes take effect. Continued use of the platform after that date constitutes acceptance of the updated policy.

12. Contact Us

CommonMind Pty Ltd

Email: contact@commonmind.co

Website: commonmind.co

For privacy-related enquiries, data access requests, or complaints:

  • Email: contact@commonmind.co
  • Response time: within 2 business days

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

How it worksPlatform demoAboutQuestionsSign in© 2026 CommonMind Pty Ltd · Melbourne
PrivacyTermsData Processing