Privacy Policy
Effective 30 July 2026
Cloche is a hospitality jobs app for Australia, operated by Jintang Zhao, ABN 39 810 897 188 ("we", "us"). This policy explains what personal information we collect, why, who else sees it, and how to get it corrected or deleted. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Information you give us
When you create an account and build a profile, we collect:
- Account details: your email address or Australian mobile number, and a password. We send a one-time code to confirm it belongs to you.
- Profile details: your name, a short bio, your suburb and state, and the search radius you set.
- Photos: a profile photo and any additional photos you add.
- Work information (workers): the roles you can do, past experience you enter, and images of certifications such as an RSA. A résumé document if you upload one.
- Venue information (hirers): venue name, an optional street address, and the contact name.
- Content you create: posts, comments, likes, expressions of interest, job applications, follow requests, and direct messages with any attachments.
Certification images and résumés are sensitive to you, so treat them accordingly: they are visible to venues you apply to, and to nobody else.
2. Information we collect as you use Cloche
- Location: we do not track you. If you tap "Use my current location" we ask the operating system for a coarse fix, convert it immediately to the nearest listed suburb, and keep only that suburb. You can type a suburb instead and never grant the permission.
- Which posts you have seen: recorded so the feed does not keep showing you the same jobs. This list stays on your device and is never uploaded.
- Technical and diagnostic data: device type, app version, and error reports, used to keep the app working.
Job ranking happens on your device. The signals that personalise your feed (your role picks, your suburb, what you have already seen) are combined locally, so we do not build a server-side profile of your browsing.
3. Public posts we import
Part of the Cloche feed comes from job posts that were already published publicly: for example, publicly accessible hospitality job groups and pages. Cloche works like a search engine for those posts: we index what is already public so people looking for shifts can find it in one place, alongside a link back to the original.
How we handle that content:
- We only access what is public. We collect only content that is publicly accessible without logging in to any account. We do not use content from private or members-only spaces, and we do not get around access restrictions, log-in walls or technical protections.
- What we display is the facts of the job. From each post we extract and show the factual details (the role, the location, the shift type, and any pay stated) together with a short excerpt, the name and profile image shown publicly on the original post, and a link to that post. We do not republish posts wholesale.
- Imported posts delete themselves. Every imported post is kept for a maximum of 30 days from the time we collect it, then removed automatically. Nothing imported is retained indefinitely.
- We link back rather than pass it off as ours. Every imported post shows where it came from and links to the original, and applicants are directed to the original poster.
- We never sell imported content, we do not license it to anyone else, and we do not use it for advertising.
Separately, a Cloche user can share an individual public post they have found themselves into the app to turn it into a job listing. Those imports are initiated manually by that user, one post at a time (there is no bulk import) and the resulting draft belongs to that user and is not published to anyone else until they choose to publish it. The retention, link-back and removal rules above apply to these imports too.
If you posted something we imported, you can ask us to stop. Email us at hello@cloche.au and we will (a) delete the copies we hold, and (b) add you to an exclusion list so your posts are not imported again. That choice is entirely yours and you do not have to give a reason. You can also ask us to remove a single post rather than exclude you altogether, or claim the profile so you control it yourself.
We act on exclusion and removal requests promptly. Because imported posts expire on their own within 30 days, the practical effect of an exclusion request is permanent.
4. How we use personal information
- To run your account and show your profile to the people you interact with.
- To match workers and venues: ranking the feed and the map by role, distance and recency.
- To carry messages, applications and expressions of interest between you and the other party.
- To summarise and categorise job posts, including with automated tools and third-party AI services, so a post shows its role, shift type and location consistently. Summaries are labelled in the app.
- To keep Cloche safe: investigating misuse, spam, impersonation and breaches of our Terms.
- To fix problems and improve the product.
- To send you service messages you need (verification codes, notifications you have enabled, important changes).
We do not sell your personal information, and we do not use it for third-party advertising.
5. What other people can see
Your name, photos, bio, suburb, roles, experience and the posts you publish are visible to other Cloche users. Your email address, phone number, password, résumé and certification images are not, except where you deliberately share them, such as applying to a job or sending a message.
Anything you send another user in a message or an application is visible to that user, and stays visible to them.
6. Service providers
We use a small number of providers to run the app, and give each only what it needs:
- Supabase: database, authentication and file storage for everything above.
- Email and SMS providers: to deliver verification codes.
- Map tile providers: to draw the jobs map. A map request reveals the area being viewed.
- AI providers: to summarise and categorise job posts (see section 4).
- Push notification services operated by Apple and Google, if you enable notifications.
Some of these providers store or process data outside Australia. Where that happens we take reasonable steps to ensure your information is handled consistently with the Australian Privacy Principles.
We may also disclose information where the law requires it, or where it is necessary to protect someone's safety or our legal rights.
7. How long we keep it
- Account and profile data: while your account exists. Delete your account and we delete it, other than anything we must keep by law.
- Imported public posts: a maximum of 30 days, then deleted automatically.
- Messages and applications: while the account exists, because they are a record for both sides of the conversation.
- Your seen-posts list: on your device only; clearing the app data clears it.
8. Security
Access to data is enforced at the database level, so one account cannot read another's private data. Traffic is encrypted in transit, and files such as certifications and résumés are stored in access-controlled buckets. No system is perfectly secure; if a data breach ever puts you at likely risk of serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
9. Your rights and choices
- Access: ask for a copy of the personal information we hold about you.
- Correction: fix it yourself in the app, or ask us.
- Deletion: delete your account, or email us and we will do it.
- Exclusion from imports: see section 3.
- Permissions: location and photo access are asked for in context and can be revoked in your device settings at any time. Notifications can be turned off the same way.
Email hello@cloche.au for any of these. We aim to respond within 30 days. If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
10. Children
Cloche is not for people under 18. We do not knowingly collect information from anyone under that age; if we learn that we have, we delete it.
11. Changes to this policy
If we change this policy we will update the date at the top and, for anything significant, tell you in the app. Continuing to use Cloche after a change means you accept the updated policy.
12. Contact us
Privacy questions, requests and complaints: hello@cloche.au (Jintang Zhao, ABN 39 810 897 188).