🚧 This website is under construction — please do not purchase any applications yet. 🚧
✉️ support@businessformationaustralia.com.au
Mon to Fri 9am to 5pm AEST

Last updated: June 2026

When you register a business with us, you share real, sensitive information: your identity, your Tax File Number, and your payment details. We don't take that lightly. Everything described below is something we actually do, not an aspiration. We've kept it specific enough that you can hold us to it.

1. Your card details never touch our servers

Card payments are handled entirely by Stripe, a payment provider certified to PCI DSS Level 1, the most rigorous level of payment security compliance in the industry. When you pay, your card number is entered directly into Stripe's own secure, hosted payment fields and sent straight to Stripe. It never passes through, and is never stored on, our servers or our database.

We receive only a confirmation that a payment succeeded, and even that is cryptographically signed by Stripe and verified on our side before any order is marked as paid, so a payment result can't be faked. The amount you're charged is always calculated on our server from a fixed price list, never from anything your browser sends.

2. Everything is encrypted in transit

Every page and form on this site is served exclusively over HTTPS, so the information you send is encrypted on its way to us. We enforce this with HTTP Strict Transport Security (HSTS) and apply a strict Content Security Policy and other hardening headers that tightly limit what code is allowed to run on the site, a key defence against tampering and cross-site scripting.

3. Where your data is stored

Your account and application details are stored in a managed PostgreSQL database (Supabase) running on Amazon Web Services (AWS) infrastructure. Your data is encrypted both in transit and at rest.

4. We collect only what's needed

We ask only for the information genuinely required to complete the specific registrations you've chosen with ASIC and the ATO, nothing more. If a detail isn't needed for your application, the form doesn't ask for it.

5. Your Tax File Number and identity documents

Where a registration requires it, we collect your Tax File Number (TFN) for a single purpose: to verify your identity with the Australian Taxation Office as part of your lodgement. We handle TFNs strictly in accordance with the Privacy (Tax File Number) Rule 2015 and the Australian Privacy Principles (APPs). They are used only for that purpose, disclosed only to the ATO for your registration, and never used to identify you for anything else. Where identity documents are needed, we request them through a secure link rather than ordinary email.

6. Defences against fraud and abuse

Our forms are protected by Cloudflare Turnstile, a privacy-respecting bot check that keeps automated abuse and spam out without tracking you. Sensitive operations, such as starting a payment, are rate limited to prevent abuse and runaway requests.

7. Who can see your data

Access is restricted at the database itself, not just in the app. Row-level security ensures each signed-in customer can only ever read their own records, and administrative access is enforced on the server, never decided in your browser, so it can't be bypassed by anything running on your device. Your account is protected by your password; please choose a strong, unique one.

8. Privacy and your rights

This page focuses on how your data is secured. For the full picture of what we collect, how we use it, who we share it with, and how to access or correct it, see our Privacy Policy. You can request access to, or correction of, your personal information at any time by emailing support@businessformationaustralia.com.au.

9. Reporting a security concern

We welcome reports from customers and security researchers. If you believe you've found a vulnerability in our website, please email support@businessformationaustralia.com.au with the details. We'll acknowledge your report and work to resolve it. Please act in good faith: don't access or alter other people's data, and give us a reasonable opportunity to fix an issue before disclosing it publicly.

10. Contact

For any security or data handling enquiries:
Business Formation Australia
ABN 66 289 309 387
Email: support@businessformationaustralia.com.au

← Back to Home