SharePass Pty Ltd (ACN 647 015 601) (SharePass, “we”, “our”, “us”) respects your privacy. This Privacy Policy explains how we collect, hold, use and disclose personal information when you visit sharepass.com, use the SharePass web applications, mobile applications (including the SharePass Keyboard), browser extension and API, or open a SharePass link (together, the Services).
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the General Data Protection Regulation of the European Union or of the United Kingdom (GDPR) applies to you, section 13 also applies. This policy should be read together with our Terms of Service and Cookies Policy.
Last updated: 13 September 2026.
1. How SharePass Protects the Content You Share
SharePass is built so that we do not need to see what you share. When you create a secret, it is encrypted on your own device (in your browser, our mobile app or our browser extension) before it is sent to us. We store only the encrypted content. The key needed to decrypt it is placed in the link you share and is not sent to our servers. We therefore cannot read the content of your secrets, and neither can anyone who obtains our stored data without the link.
Envelopes (requests for information) work the same way in reverse: what the other person enters is encrypted in their browser with a key that only the requesting account holds.
One exception: if you or your organisation use our API with the option that asks SharePass to encrypt on your behalf (X-SharePass-Input: plaintext), the content reaches our servers over an encrypted connection, is encrypted immediately and is not stored or logged in readable form.
2. The Personal Information We Collect
Depending on how you use the Services, we collect:
- Account information: your name, email address, organisation, role and licence, your settings, templates, labels and security settings (for example multi-factor authentication and registered security keys). Your password is managed by our authentication provider and is never stored by us in readable form.
- Secret and envelope information: the encrypted content (which we cannot read, see section 1) and the settings and details you add to it, such as its type, label, description, expiry, availability, number of views, allowed IP addresses, PIN settings and, if you choose email verification, the recipient’s email address. Labels and descriptions are stored in readable form so that we can show them to you; do not put confidential information in them.
- Access information when a link is opened: the IP address, browser and device type (user agent), date and time of each attempt to open a secret or envelope and whether it succeeded. We use this to apply the security checks the sender chose (for example IP restrictions and one-time links) and we show it to the sender in the secret’s access log.
- Billing information: subscriptions are processed by our payment providers (Paddle, which acts as reseller and merchant of record, and Chargebee on our older platform). We receive your name, email address, country, plan and payment status, but not your full card details.
- Enquiries and forms: when you contact us or complete a form on our website (contact, enterprise sales, partnership, whitepaper or newsletter, MSP interest), the details you provide, such as your name, email address, company, country, company size and type, phone number and message.
- Technical information: IP addresses, browser and device information and request logs kept by our servers and security systems to operate, secure and troubleshoot the Services.
- Website analytics and marketing information: only if you consent, as described in section 10 and our Cookies Policy.
The SharePass Keyboard does not record what you type. It only processes the text you choose to send with SharePass. Our browser extension only acts on the page and the text you select when you use it. Our applications do not contain advertising or third-party analytics tools.
You can visit our website without telling us who you are. You may also use a pseudonym when contacting us, but we need your real email address to provide an account.
3. How We Collect Personal Information
We collect personal information directly from you (when you register, use the Services, complete a form or contact us), from the organisation that gives you access to SharePass (for example when an administrator invites you or assigns you a licence), from the person who sends you a SharePass link or envelope (for example your email address if they choose email verification), from our payment providers, and automatically when you use the Services (see sections 2 and 10).
4. Why We Collect, Hold and Use Personal Information
We use personal information to:
- provide, operate and maintain the Services and your account;
- apply the security settings of each secret and show senders who opened their links;
- authenticate users and protect the Services, our users and us from fraud, abuse and attacks;
- manage subscriptions, billing and licences, including for your organisation’s administrators;
- respond to enquiries and provide support;
- send service messages (for example security alerts, verification codes and billing notices);
- improve the Services and our website, using aggregated information where possible;
- send you news and offers about SharePass, where permitted by law (see section 6); and
- comply with our legal obligations and enforce our Terms of Service.
If you do not provide the information we ask for, we may not be able to provide the Services or respond to your enquiry. We do not sell personal information.
5. Who We Disclose Personal Information To
We disclose personal information only as needed for the purposes above, to:
- Your organisation: if your account is part of an organisation, its administrators can see your account details, licence and activity information (not the content of your secrets).
- Senders of links you open: the access information described in section 2.
- Service providers who process information on our behalf under contract: Amazon Web Services (hosting, authentication, email delivery and security), Paddle and Chargebee (payments), Google (reCAPTCHA and, with your consent, Google Analytics), LinkedIn (with your consent), the provider that hosts our website’s content management system, and YouTube and Wistia when you choose to play a video on our website.
- our professional advisers, insurers and auditors;
- a buyer or successor if we sell or restructure our business, on condition that they protect the information as this policy does; and
- law enforcement agencies, courts, regulators or others where required or authorised by law. Because of how SharePass is designed, we cannot provide the content of encrypted secrets.
6. Direct Marketing
We may send you news about SharePass if you have asked for it or if you are a customer and it relates to the Services, in line with the Spam Act 2003 (Cth). Every marketing email includes a way to unsubscribe, and you can also opt out at any time by writing to legal@sharepass.com. Service messages about your account are not marketing and will still be sent.
7. Overseas Disclosure and Storage
Our main platform is hosted by Amazon Web Services in Sydney, Australia. Organisations using a dedicated SharePass One instance may choose to have it hosted in another region (for example the United States, Singapore, France or the United Arab Emirates), and their data is stored there.
Some of our service providers process information outside Australia, mainly in the United States, the United Kingdom and the European Union. Before disclosing personal information overseas we take reasonable steps, including contractual commitments, to ensure it is handled in a way that is consistent with the APPs.
8. How We Protect Personal Information
Besides the end-to-end encryption of secrets described in section 1, we protect personal information with encryption in transit and at rest, access controls and multi-factor authentication for our staff, network protection, monitoring and logging. No system is completely secure, and you are responsible for keeping your password, devices and SharePass links safe: anyone holding a valid link may be able to open it within the limits you set.
If a data breach is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
9. How Long We Keep Personal Information
We keep personal information only for as long as we need it for the purposes in this policy or as required by law. Encrypted secret content is deleted when the secret is erased, expires or is deleted by you, and disappears from our backups when they are rotated. Access logs are kept for as long as needed to show senders who opened their links and to investigate security incidents. Account information is kept while your account is active and deleted or de-identified after it is closed, unless we must keep it longer (for example for tax records). Enquiries from our website forms are kept for as long as needed to respond to them and follow up.
10. Cookies, Analytics and Similar Technologies
Our website uses a small number of cookies and similar technologies. Those that the website needs to work are always on. Analytics and marketing cookies are used only if you accept them in the cookie banner, and you can change your choice at any time from “Cookie settings” at the bottom of every page. Annex A lists them; our Cookies Policy explains cookies in more detail.
Our applications store your session and preferences on your device (for example in your browser’s storage or your phone’s secure keychain) so you stay signed in. These are necessary for the Services and are not used for advertising.
11. Accessing and Correcting Your Personal Information
You can see and update most of your account information in the Services. You may also ask us for access to, or correction of, the personal information we hold about you by writing to legal@sharepass.com. We will respond within 30 days. We may need to verify your identity first, and in limited cases the law allows us to refuse access, in which case we will tell you why.
12. Questions and Complaints
If you have a question or a complaint about how we handle personal information, please contact our privacy officer at legal@sharepass.com or by post to SharePass Pty Ltd, 3 Albert Coates Lane, Suite 37, Melbourne VIC 3000, Australia. We will acknowledge your complaint promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au, 1300 363 992) or, if you are in Europe, to your local data protection authority.
13. Additional Information for the European Union and the United Kingdom
For personal information we collect for our own purposes (for example website visitors, enquiries and account administration), SharePass is the controller. For information that an organisation manages in SharePass about its own users, the organisation is the controller and we process it on its behalf under our agreement with it.
We rely on these legal bases: performing our contract with you (providing the Services), our legitimate interests (securing and improving the Services, responding to enquiries and business marketing, balanced against your rights), your consent (analytics and marketing cookies and, where required, marketing emails; you may withdraw it at any time) and legal obligations.
You have the right to access, correct, delete or receive a copy of your personal information, to restrict or object to its processing (including direct marketing at any time) and to withdraw consent. Write to legal@sharepass.com to exercise them. Transfers of personal information outside the European Economic Area or the United Kingdom are protected by the European Commission’s standard contractual clauses or another lawful transfer mechanism.
14. Children
The Services are not directed to children. You must be of the age of majority in your jurisdiction (usually 18) to use the Services, as set out in our Terms of Service. If we learn that we hold personal information of a child without appropriate consent, we will delete it.
15. Changes to This Policy
We may update this policy from time to time. We will publish the new version on this page with its date and, if the changes are significant, tell account holders by email or in the Services before they take effect.
Annex A: Cookies and Similar Technologies on Our Website
Durations are those set by each provider at the time of writing and may change. Videos on our website come from YouTube (privacy-enhanced mode) and Wistia; they store information only when you choose to play a video.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| sp-cookie-consent (local storage) | Remembers your cookie choice | 12 months | sharepass.com |
| sp-theme (local storage) | Remembers light or dark mode, if you choose one | Until you change it | sharepass.com |
| _GRECAPTCHA | Google reCAPTCHA: protects our forms from spam and abuse (form pages only) | 6 months | google.com |
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| _ga | Google Analytics: distinguishes visitors to count visits | 2 years | sharepass.com |
| _ga_<ID> | Google Analytics: keeps the state of a visit | 2 years | sharepass.com |
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| bcookie, li_sugr, lidc | LinkedIn: identifies the browser to measure our campaigns | Up to 1 year | linkedin.com |
| UserMatchHistory, AnalyticsSyncHistory | LinkedIn: ad measurement and sync | 30 days | linkedin.com |
| li_fat_id | LinkedIn: attributes visits to our LinkedIn campaigns | 30 days | sharepass.com |
| Review badges | SourceForge / Slashdot badges showing our ratings | Set by the provider | sf-syn.com |