Skip to content
Thrive Code Labs

Privacy Policy

Last updated: 26 August 2026

Who we are

Thrive Code Labs ("we", "us", "our") is a software development business based in Australia, registered as Thrivecode Labs, ABN 55 843 989 120. We build and maintain web applications for our clients.

You can reach us about anything in this policy at hello@thrivecodelabs.com.

This policy covers thrivecodelabs.com and the client portal. It explains what personal information we collect, why, who we share it with, and what you can do about it.

Who this applies to

We serve clients in Australia and the United States. We are an Australian business, so the Australian Privacy Principles under the Privacy Act 1988 (Cth) are our reference framework. If you are in the United States, your state may give you additional rights, covered below.

What we collect

We collect only what we need to run the business. We do not buy personal information from third parties, and we do not sell it.

When you contact us or request a site check

  • your name
  • your email address
  • your company name, if you give it
  • the message or request you send us
  • which form you came through, and the campaign or referring site that brought you to us

We do not store your IP address against these submissions. We use it only in the moment, to rate limit the form against abuse, and it is not written to our records.

When you create an account

  • your name and business name
  • your email address
  • a password, stored only as a cryptographic hash that we cannot read or reverse

When you use the client portal

  • the work requests you submit, including the subject and full description
  • any screenshots you upload with a request
  • messages you exchange with us about a request
  • your credit balance, billing history and subscription status
  • access to a GitHub repository, if you connect one

Please do not put passwords, API keys or other credentials into a work request or a screenshot. If you need to share a credential with us, ask and we will arrange a secure method.

When you submit a website to the site check tool

We fetch the homepage of the URL you give us and run public DNS lookups against that domain, to identify the platform, hosting provider, CDN, email provider and DNS host. This looks only at publicly available information. We do not log in to the site or access anything private.

Automatically, as you use the site

  • your IP address and browser user agent, stored against your login session
  • pages you visit and how you interact with them, covered under cookies and analytics below
  • the campaign or referring site that first brought you to us

Why we use it

  • to respond to your enquiry
  • to create and run your account
  • to quote and deliver the work you ask for
  • to take payment
  • to keep you logged in and keep the service secure
  • to prevent spam and abuse
  • to understand how the site is used, so we can improve it
  • to understand which marketing works
  • to send you service messages about your account

We do not use automated decision making that produces a legal or similarly significant effect on you. Our system does propose a price for a work request automatically, but a person reviews that quote before you are asked to approve it.

Attribution

When you arrive from a marketing campaign or an external website, we store a first-party cookie named thrive_attribution for 90 days. It records the campaign parameters in the link you clicked, the domain of the site that referred you, the page you landed on, and the time.

It records the referring domain only, never the full URL, so no page path or search query from the referring site is captured. The cookie is encrypted. Only your first visit is recorded, and later visits never overwrite it.

Cookies, analytics and session recording

Essential cookies

We use a session cookie to keep you logged in, and a token cookie to protect forms against cross-site attacks. The site does not work without these.

Google Analytics

We use Google Analytics to understand traffic and which pages are useful. It sets cookies and reports to Google.

Microsoft Clarity

We use Microsoft Clarity for heatmaps and session replay on our public marketing pages. Clarity records how visitors move, scroll and click, and can replay a visit so we can see where a page confuses people.

Session replay deserves specifics, so here they are:

  • Clarity runs on our public marketing pages only. It does not run inside the client portal, so your work requests, credit balance and connected repositories are never recorded.
  • It is switched off on our login, password reset, forgot password and invitation pages.
  • Clarity masks form input by default, so text you type into fields is not captured.
  • Recordings are stored by Microsoft in the United States.

Meta Pixel

We use the Meta Pixel to measure whether our advertising works. It sets cookies, including one named _fbp, and reports to Meta. This one is advertising rather than analytics, so here are the specifics:

  • On our public marketing pages it records the pages you visit.
  • It does not record your browsing inside the client portal. There it reports only that you finished signing up, or that a payment completed, so we can tell which advertising leads to real clients.
  • When you send the contact form or run a site check, it reports that a submission happened. The name, email and message you typed are not sent to Meta.
  • Data is stored by Meta in the United States.
  • Meta may use this to show you our ads on Facebook and Instagram. Some US state laws treat that as sharing for cross-context behavioural advertising, covered under "If you are in the United States" below.
  • If your browser sends a Global Privacy Control signal, we do not load the pixel at all and nothing about your visit reaches Meta.

Who we share it with

We share personal information with the providers below, only so they can perform their function for us. We do not sell personal information. We do share limited information with Meta for advertising, which some US state laws treat as sharing for cross-context behavioural advertising, and you can opt out of that.

  • Stripe (United States): payment and subscription data. Card numbers go directly to Stripe. We never see or store them.
  • Anthropic (United States): the text of a work request, so our system can propose a price for it.
  • Resend (United States): your email address and the content of emails we send you.
  • Google (United States): site usage data, through Google Analytics.
  • Microsoft (United States): session recordings and heatmap data from our public pages.
  • Meta (United States): that you visited our marketing pages, and that you signed up or paid, for advertising measurement.
  • GitHub (United States): repository access, if you connect one.
  • DigitalOcean (Sydney, Australia): hosting for the application and its database.
  • Team Cymru (United States): the IP address of a website submitted to the site check tool, for a public network lookup. No personal information about you.

We may also disclose personal information where the law requires it, or to protect our rights or someone's safety.

Please note the Anthropic entry. When you submit a work request, its text is sent to Anthropic's API so our system can assess and price it. Do not include personal information about other people, or any credentials, in a work request.

Where your information is stored, and when it goes overseas

Your account data and work history are stored in Australia, on a server in Sydney. It does not leave the country at rest.

Some of it is disclosed to the overseas service providers listed above so they can do their job. By using our services you acknowledge that. We take reasonable steps to use reputable providers who are contractually obliged to protect your information, but overseas recipients are subject to the laws of their own country, and those laws may differ from Australian privacy law. We cannot guarantee an overseas recipient will handle your information in a way that complies with the Australian Privacy Principles.

Security

Traffic to and from the site is encrypted. Passwords are stored as hashes and cannot be reversed. Access to production systems is limited to people who need it.

No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify you, and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme applies to us.

How long we keep it

We keep your information for as long as your account is open, and afterwards for as long as we need it to meet tax, accounting and business record obligations. Enquiries that do not become client relationships are kept while they are still commercially useful to us.

You can ask us to delete your information at any time, and we will unless the law requires us to keep it. Analytics and session recording data is held by those providers under their own retention settings.

Your rights

You can ask us to:

  • give you a copy of the personal information we hold about you
  • correct anything wrong or out of date
  • delete your information, where we are not required to keep it
  • stop sending you marketing email

Email hello@thrivecodelabs.com. We will respond within 30 days, and we do not charge for this.

If you are in the United States

Several states, including California, Virginia, Colorado and Connecticut, give residents rights to know what is collected, to request deletion, to correct inaccuracies, and to opt out of the sale or sharing of personal information.

Those laws generally apply to businesses above revenue or volume thresholds we do not currently meet. We honour these requests regardless. We do not sell personal information. We do share information with Meta for advertising, which those laws treat as sharing for cross-context behavioural advertising. We honour the Global Privacy Control signal, so if your browser or an extension sends it, we do not load advertising pixels for you and nothing goes to Meta. No email needed. You can also email us and we will stop sharing your information with Meta, or change how Meta uses your data in your Facebook or Instagram ad preferences. We will not treat you differently for exercising any of these rights.

Marketing

If we send you marketing email, every message includes an unsubscribe link that works. We comply with the Spam Act 2003 (Cth) and the US CAN-SPAM Act. Service messages about your account are not marketing and will continue while your account is open.

Children

Our services are for businesses. They are not directed at anyone under 16 and we do not knowingly collect information from children. If you believe we have, contact us and we will delete it.

Complaints

If you are unhappy with how we have handled your personal information, email hello@thrivecodelabs.com first and we will try to sort it out.

If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992.

Changes to this policy

We may update this policy. The date at the top shows when it last changed. If a change is significant we will tell account holders by email.

Contact

Thrive Code Labs
ABN 55 843 989 120
hello@thrivecodelabs.com