Cadence

Privacy Policy

Last updated: 19 June 2026

Who we are

Cadence (“we”, “us”, “our”) is a task accountability platform for small-business owners and their teams. Our website is gocadenceapp.com and our app is available on iOS and Android.

If you have any questions about this policy, contact us at hello@gocadenceapp.com.

What data we collect

We collect only what is necessary to provide the service:

  • Account information: your email address and password when you create an owner account.
  • Business information: your business name, industry, timezone, and business hours.
  • Team information: names and contact details of your employees or contractors that you add to the platform.
  • Task data: task titles, due times, completion timestamps, notes, and photos attached to completed tasks.
  • Questions and answers: text messages exchanged between workers and owners through the evening question feature.
  • Push notification tokens: device tokens used to send reminders and alerts to workers and owners.
  • Payment information: billing details are collected and stored by Stripe, our payment processor. We do not store your card details.
  • Usage data: basic logs such as when you sign in, to help us diagnose issues.

How we use your data

We use your data to:

  • Provide and operate the Cadence service
  • Send task reminders and escalation alerts via push notification
  • Enable workers to complete tasks and attach photos
  • Process subscription payments
  • Respond to support requests
  • Improve the product (using aggregated, anonymised data only)

We do not sell your data to third parties. We do not use your data for advertising.

Third-party services

Cadence relies on the following trusted third-party services to operate:

  • Supabase — database and authentication. Data is stored in Australia (ap-southeast-2) where possible. Privacy policy
  • Stripe — subscription billing and payment processing. Privacy policy
  • Expo / Expo Push — push notification delivery to iOS and Android devices. Privacy policy
  • Vercel — web hosting. Privacy policy
  • Apple / Google — mobile app distribution via the App Store and Google Play.

How we protect your data

We take reasonable steps to protect your information from unauthorised access, loss, or misuse:

  • Encryption in transit: all data sent between your device and our servers is encrypted using TLS (HTTPS).
  • Encryption at rest: your data is stored in Supabase, which encrypts all data at rest using AES-256.
  • Access control: we use Row Level Security (RLS) in our database, meaning each user can only access their own company's data.
  • Authentication: owner accounts are protected by password authentication managed by Supabase Auth. Worker accounts use a secure invite-only flow.
  • Payment security: card details are handled entirely by Stripe, which is PCI DSS Level 1 certified — we never see or store your card number.

No method of transmission over the internet is 100% secure. While we use commercially reasonable measures, we cannot guarantee absolute security.

Data breach notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware of the breach, in accordance with applicable law. We will provide information about what happened, what data was affected, and the steps we are taking to address it.

Data retention

We retain your data for as long as your account is active. If you cancel your subscription and request deletion, we will delete your data within 30 days, except where we are required to retain it for legal or financial record-keeping purposes (such as invoices, which we retain for 7 years).

Task photos are stored in cloud storage and are deleted when you delete the associated task or close your account.

Your rights

Depending on where you are located, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Export your data in a portable format

To exercise any of these rights, email us at hello@gocadenceapp.com. We will respond within 30 days.

Australian Privacy Act

Cadence is based in Australia and complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you believe we have handled your personal information in a way that breaches the APPs, you may contact us to make a complaint. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

GDPR (European users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR). Our lawful basis for processing your personal data is the performance of a contract (providing the Cadence service to you). You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

Cookies

Our website uses only essential cookies required for authentication and session management. We do not use tracking or advertising cookies.

Children

Cadence is not directed at children under 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top of this page. For significant changes, we will notify you by email or through the app.

Contact

For any privacy-related questions or requests, contact us at hello@gocadenceapp.com.