Zero Political Funding Pledge — Version 1.2 — 10 August 2026 McGovern Solutions Pty Ltd (ABN 83 632 212 849) — operator of zeropoliticalfunding.com.au
1. Who we are
McGovern Solutions Pty Ltd operates the Zero Political Funding Pledge scheme. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Contact: privacy@zeropoliticalfunding.com.au.
2. What we collect and why
| Information | Source | Purpose |
|---|---|---|
| Contact name and email of the applicant's representative | You | Administering the application and membership |
| Signatory name, role, IP address and timestamp of each attestation | Recorded at attestation | Evidence that the Pledge, declaration and Member Agreement were accepted, and by whom |
| Director names of the applicant group | You | Sole purpose: screening the applicant group against the published AEC Transparency Register |
| Controlled entities and trading names | You | Defining the group covered by the pledge and screening |
| Legal name, ABN, certification dates | Australian Business Register / generated | Public register of current members |
| AEC Transparency Register records (which include names of individual donors as published by the AEC) | AEC public data | Screening. We do not republish these records |
| Screening reports and AI rationales | Generated | Internal decision support; never published |
| Payment records | Stripe | Billing. We never receive or store card details; Stripe is the payment processor and we are the merchant of record |
| Aggregate site usage — page views, referring site, approximate country, browser and device type | Your visit to the Site | Understanding which pages are read and where applications are abandoned. Cookieless and not linked to you or to any application — see section 10 |
We collect director names only because screening a corporate group against the AEC register is not possible without the names of the natural persons who may have made disclosable donations. We do not collect more than we need, and we do not use director names for any other purpose.
3. Automated and AI-assisted processing
Screening uses deterministic name matching, with an AI model (provided by Anthropic) used only to help disambiguate shortlisted candidate records. Every decision to grant, decline, suspend or revoke certification is made by a person. No decision is made solely by a computer program. AI outputs are recorded as rationales and reviewed by the human decision-maker. From 10 December 2026, additional transparency requirements for computer programs that make or substantially assist decisions apply under APP 1.7–1.9; this policy is intended to satisfy them and will be reviewed before that date.
4. What is published — and what never is
Published while you are certified: legal name, ABN and certification dates, on the public register and via the verification API and badge.
Never published: director names, contact details, signatory and attestation records, screening reports, AI rationales, declined applications, and the reason a business is not currently listed. Public status is limited to "certified" or "not currently certified".
5. Overseas disclosure (APP 8)
| Recipient | Location | What is disclosed |
|---|---|---|
| Anthropic (AI provider) | United States | Declared entity names, trading names and director names, where needed to disambiguate a screening match |
| Netlify (application hosting) | Serverless functions run in Sydney (ap-southeast-2); Netlify is a United States company | Data processed in transit through application functions |
| Stripe (payments) | Global (US parent) | Billing contact details; card data is collected directly by Stripe |
| Plausible Analytics (site measurement) | European Union | Aggregate site-usage data only. No cookie and no persistent identifier is set; IP addresses are used transiently to count unique visits and are never stored or disclosed to us |
Our database is hosted by Supabase in Sydney (ap-southeast-2), our application functions run in the same Sydney region, and our email provider (Maileroo) was selected for Australian data sovereignty. Netlify remains listed above because it is a United States company and so is an overseas recipient regardless of where the processing physically occurs. Where we disclose personal information overseas we take reasonable steps, including contractual terms with the providers listed above, to ensure it is handled consistently with the APPs. Anthropic does not use data submitted via its API to train models by default.
6. Security (APP 11)
Data is stored in access-controlled infrastructure in Australia, encrypted in transit and at rest. Access is limited to personnel who need it to operate the scheme. An append-only audit log records administrative actions. We review our providers' security certifications.
7. Retention
| Information | Retention |
|---|---|
| Declined applications (including director names) | Purged 12 months after decision; a minimal decision record (without director names) is retained |
| Saved but unsubmitted applications (including any director names entered) | Deleted 30 days after the application was last saved. Nothing is submitted and no screening takes place, so no decision record is created or kept |
| Membership records | Life of membership plus the period required for legal and accounting obligations |
| Attestation records (signatory name, role, IP, timestamp, instrument version) | Retained as evidence of consent and contract formation |
| Audit log | Append-only; not deleted. It records actions, and is corrected by annotation rather than deletion |
| Aggregate site-usage data | Retained by our analytics provider as aggregate statistics only; it contains no identifier that could be linked back to a visitor |
8. Access, correction and complaints (APP 12–13)
You may request access to, or correction of, your personal information by emailing privacy@zeropoliticalfunding.com.au. We respond within 30 days. Because our audit log is deliberately immutable, corrections to logged records are made by appending a correction notice to the record rather than altering history; current-state records (such as contact details and group composition) are corrected directly.
If you have a privacy complaint, contact us first; we will acknowledge within 7 days and respond within 30. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992).
9. Data breaches
We comply with the Notifiable Data Breaches scheme. If a breach is likely to result in serious harm, we will notify affected individuals and the OAIC as required.
10. Cookies and analytics
Cookies. The public site sets only the cookies necessary to operate it — a session cookie when you sign in to the member portal, and nothing else. We use no tracking cookies, no advertising cookies, and no cross-site tracking. The badge embed and verification API do not set cookies on host sites.
Analytics. We measure how the Site is used with Plausible Analytics, which is cookieless by design. It records the page visited, the referring site, an approximate country, and browser and device type. It sets no cookie, stores no IP address, creates no persistent identifier for a visitor, and does not follow visitors to other websites. Because it carries no identifier, this data cannot be linked to you, to your business, or to an application.
Application form measurement. We count how many visitors reach each step of the application form, so that we can find and fix the steps where people get stuck. These are counts of steps reached. The content of form fields is never captured — not your ABN, not entity or director names, not contact details — and the counts are not linked to your application or to your identity.
What we do not do. We do not use session recording, screen capture, heatmaps, or any tool that reproduces what an individual visitor typed or clicked.
11. Changes
We may update this policy from time to time. The current version is always published on the Site, and material changes affecting members will be notified by email.
12. Version history
| Version | In force | Change |
|---|---|---|
| 1.0 | 1 August 2026 | First published version. |
| 1.1 | 6 August 2026 | Section 10 rewritten to permit cookieless, aggregate site analytics and step-level measurement of the application form, and to state expressly that session recording is not used. Section 2 and section 5 updated to record what that measurement collects and that it is processed in the European Union; section 7 updated for its retention. No change to what is collected from applicants or members, to how it is used, or to what is published. |
| 1.2 | 10 August 2026 | Two changes. Section 7 given a retention period for saved but unsubmitted applications, following the addition of save-and-resume to the application form: a part-finished application can now hold director names before it is submitted, and those are deleted 30 days after it was last saved. Section 5 updated because application functions were moved from the United States to the Sydney (ap-southeast-2) region, removing a cross-border transfer rather than merely documenting one; Netlify remains listed as an overseas recipient because it is a United States company. No change to what is collected, to why it is collected, to how it is used, or to what is published. |