REGISTER RADAR
How it worksCross enrolmentsPricingArticlesSign inFree scope check

Privacy policy

This page says exactly what we store, where it lives, and how to make us delete it. It matches what our systems actually do — nothing here is boilerplate.

Last updated: 5 August 2026

Who is responsible

Register Radar is operated by its founder, based in Spain (sole trader registration in progress). For anything in this policy, write to contact@registerradar.com — the founder answers.

What we store, and where

DataWhere it livesWhy
Watch subscriptions: your RTO code, your email, an optional nameSupabase (Postgres), EU region (Paris)To run the daily scope watch you asked for
Sign-in accounts: your verified email and provider (Google or email link)Supabase Auth, EU. No passwords exist — we never store anyTo show you your watches when you sign in
CorrespondenceZoho Mail, EU data centreNormal business email
Billing details, if you become a paying customerStripe. We never see or store card numbersPayment processing

What we never store

Your students' data never reaches us — by architecture, not by promise. The enrolment cross on /cross parses your CSV entirely in your browser; the file is never uploaded. Only public training-product codes are sent to our server to be checked against the national register.

  • No cookies, no third-party analytics, no tracking. We keep first-party, cookieless page counts — the path you visited, the referring site's host, and the country Vercel infers. No cookies, no fingerprinting, no identifiers, and your enrolment file still never leaves your browser.
  • If you sign in, your session token is kept in your browser's localStorage — strictly necessary for the sign-in to work, and it never leaves your device except to authenticate you.
  • We hold no phone numbers or personal details beyond what the public register itself publishes.

Why we may have emailed you first

If we contacted your organisation, it is because training.gov.au publishes your organisation's public contact details, and our email contained specific, verifiable data about your own scope (legitimate interest, B2B). Reply "stop" once and we never contact you again.

Legal bases

  • Consent — when you start a watch or create an account.
  • Contract — when you buy paid work from us.
  • Legitimate interest — one-time B2B outreach to publicly listed organisational contacts, with immediate opt-out.

How long we keep things

  • Watch subscriptions: until you say "stop" — then the row is deleted.
  • Accounts: until you ask us to delete yours.
  • Correspondence: for as long as is reasonable for normal business records.

Your rights

Under the GDPR you can ask for access, correction, deletion, portability, or object to processing — email contact@registerradar.com and it gets done, not queued. You can also complain to the Spanish supervisory authority, the AEPD.

Who processes data for us

  • Supabase — database and sign-in (EU region)
  • Vercel — website hosting
  • Zoho Mail — email (EU data centre)
  • Stripe — payments
  • Cloudflare — DNS

If this policy ever changes, the date at the top changes with it — and nothing in it will ever quietly start storing more than it says.

Register Radar · built on public data from training.gov.au · contact@registerradar.com · Privacy · Terms