Privacy policy

This Privacy Policy explains how Mirrormapper collects, holds, uses, and discloses personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Spam Act 2003 (Cth), and the Notifiable Data Breaches scheme. Where we supply to New Zealand, we also handle personal information in accordance with the Privacy Act 2020 (NZ). Where mandatory data protection law of another country applies, we comply with it to the extent it cannot be excluded. By using our products or services, you agree to this Policy.

1 About Mirrormapper

This Privacy Policy applies to Mirror Mapper Pty Ltd, trading as Mirrormapper ("we," "us," or "our"). We supply drone hardware, payloads, SLAM scanners, aerial mapping software (including Thermalmapper and MapShare), equipment hire, and CASA-related consulting and training services. Hardware sales are Australia-wide. SHARE handheld scanners, accessories, software licences and remote training are also supplied to New Zealand and selected Southeast Asian countries as described in our Shipping Policy. DJI products are supplied in Australia only.

We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We are also a data exporter where you upload geospatial information to our cloud services, and we treat that information with the same care. Local processing on your devices is described in our Software and Data Processing Terms.

2 The personal information we collect

We collect personal information that is reasonably necessary for our business functions. The categories of information we collect depend on how you interact with us.

2.1 Information you give us

Identity and contact information: your name, business name, email address, phone number, mailing address, and (where you make a hardware order) delivery address;

Account credentials: username, password (stored hashed), and security questions where applicable;

Billing information: card billing address, business address, ABN, GST status, and purchase order references. Card numbers are entered directly into our payment processor's hosted page and are not stored by us;

CASA and aviation information: where you engage our consulting services or hire aircraft, we collect information necessary to prepare ReOC, SORA, BVLOS, Part 102 or related documents, or to verify hire eligibility. This may include your pilot details, qualifications, ARN, AOC/ReOC references, operational areas, and aircraft serial numbers;

Equipment hire information: Hire Pack Form details, photo ID (sighted / copy retained), ABN, bond and payment references, Equipment serial numbers, Hire OUT and Hire IN dates and times, condition-report photographs, damage or theft reports, and police report numbers where relevant;

Communications: emails, support tickets, call recordings (where notified), webform submissions, and any other correspondence you have with us.

2.2 Information we collect automatically

Device and usage information: IP address, browser type, operating system, device identifiers, the pages you visit on our website and SaaS platforms, the time and duration of visits, and the referring URL;

Cookies and similar technologies: see Section 8 below;

Software telemetry: where you use Landmapper, Airmapper, or other Mirrormapper software, we collect information about the operation of the software (e.g. session duration, feature usage, error logs, crash reports, performance metrics). Telemetry from local/installed tools is limited to what the product enables; full project datasets remain on your devices unless you upload or sync them (see Software and Data Processing Terms).

2.3 Geospatial and aerial imagery you upload

When you upload imagery, point clouds, or related datasets to our SaaS platforms, we process that content to provide the service. It may include incidental personal information (e.g. faces or vehicle plates). You are responsible for lawful capture and any notices to third parties. Processing locations (cloud vs local vs third-party MapShare / manufacturer clouds) are described in the Software and Data Processing Terms.

2.4 Information we collect from third parties

Payment processors confirm the success and partial details (last four digits, card brand) of transactions;

Couriers provide delivery confirmation and tracking events;

Analytics and advertising providers (e.g. Google Analytics, Meta) provide aggregated information about how visitors use our website;

Publicly available business sources (e.g. company websites, ABN Lookup, LinkedIn business pages) where we identify business prospects in the drone and geospatial industries;

Insurers and (where you authorise) references related to hire risk or claims.

3 How we use personal information

We use personal information for the following purposes:

To supply you with the products and services you have ordered or subscribed to (including delivery, account provisioning, technical support, and warranty);

To administer equipment hire (identity checks, bonds, condition reports, claims, and licence verification);

To deliver consulting and training services and to prepare documents required for CASA approvals;

To process payments, refunds, and reconcile accounts;

To maintain, secure, and improve our website, SaaS platforms, and software products (including diagnosing faults, fixing bugs, and developing new features);

To communicate with you about your account, orders, security, changes to policies, and other operational matters (these are not marketing messages and you cannot opt out of them while your account is active);

To carry out direct marketing where permitted by law (see Section 4);

To prevent, detect, and investigate fraud, abuse, security incidents, and violations of our terms;

To comply with our legal obligations (e.g. tax record-keeping under the Corporations Act 2001, AML/CTF where applicable, response to lawful requests from regulators);

Where we have your consent, or where another lawful basis under the Privacy Act applies.

4 Direct marketing

We may send you marketing communications (including emails, SMS, and in-app messages) about our products, training, events, software releases, and offers.

4.1 Marketing to existing customers

If you have purchased from us or registered an account, we treat that as a reasonable expectation that you would receive marketing from us about related products and services, in accordance with APP 7. You can opt out at any time using the methods in Section 4.3.

4.2 Marketing to business contacts

Where we contact you using a business email address that you have made publicly available in a business context, our marketing relates to your professional role, and we identify ourselves clearly and offer a functional unsubscribe in every message. This is consistent with the Spam Act 2003 (Cth) and APP 7.

4.3 How to opt out

You can opt out of all marketing communications at any time by:

Clicking the unsubscribe link at the bottom of any marketing email;

Replying to any marketing email with the word "STOP" or "UNSUBSCRIBE";

Emailing us at info@mirrormapper.com.au with "Unsubscribe" in the subject line;

Updating your notification preferences in your account settings.

We action all unsubscribe requests within 5 business days. Once you opt out, we will continue to send you operational messages relating to your account and any active orders, subscriptions, or services.

5 When we share personal information

We disclose personal information only where reasonably necessary for the purposes set out in this Policy:

Service providers and processors: cloud hosting providers, payment processors, email and CRM providers, analytics and monitoring providers, shipping carriers, customs brokers, our accountant, and our legal advisers, all bound by written confidentiality and data-protection obligations;

Manufacturer partners: where you raise a warranty claim or use a manufacturer's product (e.g. DJI, Phase One, SHARE), we may share information with the manufacturer or their authorised service provider to facilitate repair, replacement, or technical support;

Carriers, customs brokers and border authorities: where you place an international Order, we disclose your name, delivery address, contact details and order contents to carriers, customs brokers and border authorities in Australia and in the destination country so the shipment can be exported, cleared and delivered;

Regulators and law enforcement: where required by law, court order, or to respond to a lawful request from a government authority (e.g. ATO, ASIC, CASA, ACMA, AFP);

Professional advisers: our lawyers, accountants, auditors, and insurers under their professional duties of confidentiality;

Business transfers: in the event of a merger, sale of assets, or restructure, personal information may be transferred to the acquirer; we will notify you where required.

We do not sell personal information to third parties for their own marketing purposes.

6 Anonymised and aggregated data

We may convert personal information into aggregated or de-identified datasets (data from which an individual cannot reasonably be identified). We use such datasets to analyse trends, benchmark performance, train and improve our software (including the algorithms underpinning Landmapper and Airmapper), and report on the drone industry. We may also share or commercialise aggregated or de-identified data without restriction. Data that is properly de-identified is not personal information and is not subject to the Privacy Act.

7 Use of data for AI and software development

Where you upload imagery or datasets to our SaaS platforms, we may use that data, in de-identified form and consistent with the SaaS terms applicable to your account, to train, test, validate, and improve the machine-learning and computer-vision models that power our software. If your SaaS plan or written agreement excludes this use, that agreement prevails.

We do not use customer data to train third-party AI models without your consent.

8 Cookies and tracking

Our website and SaaS platforms use cookies and similar technologies for the following purposes:

Strictly necessary: to keep you signed in, maintain your shopping cart, and run essential security and load-balancing functions;

Performance and analytics: to measure how visitors use our website and platforms (e.g. Google Analytics);

Functionality: to remember your preferences (e.g. language, layout);

Advertising and remarketing: to show relevant ads on third-party platforms and measure their effectiveness.

You can manage or block cookies in your browser settings, or via the cookie banner on first visit. Blocking strictly-necessary cookies will prevent some parts of the website from working.

9 Storage, security, and retention

9.1 Where data is stored

We host data primarily on servers located in Australia. Some service providers we use (e.g. cloud platforms, email delivery, analytics) may store or process data in other countries. See Section 10.

9.2 Security measures

We use industry-standard technical and organisational measures to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. These include:

Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent);

Access controls and role-based permissions for staff and contractors;

Multi-factor authentication on administrative accounts;

Logging, monitoring, and periodic security review;

Confidentiality obligations on all personnel and service providers;

Secure destruction or de-identification of records once they are no longer needed.

No system is 100% secure. We cannot guarantee that information transmitted to us via the internet is secure, but we take all reasonable steps to protect it once received.

9.3 Retention

We retain personal information only for as long as we need it for the purposes set out in this Policy, or as required by law. Examples:

Tax and financial records: a minimum of 7 years (Corporations Act 2001, A New Tax System (GST) Act 1999);

Customer account data: while your account is active and for a reasonable period after closure for support, warranty, and dispute resolution purposes;

SaaS-uploaded geospatial data: as set out in your SaaS agreement, typically while your subscription is active and 90 days post-cancellation;

Equipment hire packs, ID copies, condition photos, and claim records: typically 7 years from the Hire IN date (tax, insurance, and dispute purposes);

Marketing data: until you opt out or we determine the data is no longer relevant;

CASA-related consulting deliverables: 7 years from delivery, as evidence of advice given.

10 International data transfers

Some of our service providers store or process data outside Australia, including in the United States, the European Union, Singapore, New Zealand, and other jurisdictions where major cloud providers operate. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the APPs in relation to the information, including by using contractual protections aligned with APP 8.

If you are in New Zealand, we handle your personal information in accordance with the Privacy Act 2020 (NZ) as well as the Privacy Act 1988 (Cth). If you are elsewhere, we handle it in accordance with the Privacy Act 1988 (Cth) and any mandatory data protection law of your country, including (where they apply) Singapore's PDPA, Malaysia's PDPA, Indonesia's PDP Law, the Philippines Data Privacy Act and Vietnam's PDPD.

Placing an international Order requires us to disclose your name, address, contact details and order contents to carriers, customs brokers and border authorities in Australia and in the destination country so the shipment can be exported, cleared and delivered. Those recipients are in the destination country you nominated.

11 Notifiable Data Breaches

If we become aware of a data breach that is likely to result in serious harm, we will assess it and, where the Notifiable Data Breaches scheme requires it, notify affected individuals and the Office of the Australian Information Commissioner. If you are in New Zealand, we will also notify the Office of the Privacy Commissioner where the Privacy Act 2020 (NZ) requires it.

12 Your rights

Under the Privacy Act 1988 (Cth) and the APPs, you have the following rights:

12.1 Access

You may request a copy of the personal information we hold about you. We will respond within 30 days. We may need to verify your identity before releasing information. In limited cases (e.g. where access would breach another person's privacy, or where the information is legally privileged) we may decline access, in which case we will give reasons in writing.

12.2 Correction

You may request that we correct personal information you believe is inaccurate, out of date, incomplete, irrelevant, or misleading. We will action verified corrections within 30 days.

12.3 Deletion

You may request that we delete personal information about you. We will action verified requests where we are not required to retain the information by law (e.g. tax records) or for legitimate business purposes (e.g. ongoing dispute resolution).

12.4 Marketing opt-out

See Section 4.3.

12.5 Complaints

If you believe we have breached the APPs or this Policy, contact us. We will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:

Website: www.oaic.gov.au

Phone: 1300 363 992

Mail: GPO Box 5218, Sydney NSW 2001

If you are in New Zealand, you may also complain to the Office of the Privacy Commissioner:

Website: www.privacy.org.nz

Phone: 0800 803 909

13 Beta and pre-release products

From time to time we make pre-release or beta products available to selected customers. These products may collect additional diagnostic and telemetry information to help us identify issues and improve functionality. By participating in a beta or pre-release program you acknowledge:

The product may be unstable, incomplete, or contain errors;

Additional logging and telemetry may be enabled by default;

Feedback you provide may be used to improve the product without compensation;

Pre-release products should not be used for safety-critical or production work.

14 Third-party services

Our website, SaaS platforms, and software may link to or integrate with third-party services (e.g. payment gateways, mapping APIs, social media). Those services are governed by their own privacy policies. We are not responsible for the privacy practices of third-party services and recommend you review their policies before using them.

15 Children

Our products and services are not directed at children. We do not knowingly collect personal information from anyone under the age of 16. If you believe we have collected information from a child without parental consent, please contact us so we can delete it.

16 Changes to this Policy

We may update this Policy from time to time to reflect changes to our practices, technology, legal requirements, and other factors. The version that applies is the version published on our website on the date you interact with us. We will notify customers of material changes by email or via the SaaS platform.

Questions about privacy: Contact us.

Effective 14 June 2026. Version 2.2.