Legal

Privacy Policy

Exactly which ServiceM8 data Tradie Base reads, what else we collect, and how it is used, stored, shared, retained and deleted.

Last updated: 25 September 2026

1. Who we are

Tradie Base is an independent ServiceM8 Partner that helps Australian trade and service businesses get more out of ServiceM8. One of our tools is a free ServiceM8 audit: you connect your ServiceM8 account, we analyse how it is set up and used, and we give you a Health Score and a prioritised list of improvements.

This policy explains exactly what data the Tradie Base audit accesses, what else we collect, and how that data is used, stored, shared, retained and deleted. It applies to the Tradie Base website and the Tradie Base ServiceM8 integration.

2. The ServiceM8 data we access

When you connect ServiceM8, you approve access on ServiceM8's own authorisation page. Tradie Base requests read-only access only — we can never create, change or delete anything in your ServiceM8 account. The permissions we request, and what we read with each, are:

  • Business details (vendor) — your business name, shown back to you so you can confirm the right account is connected.
  • Jobs (read_jobs) — job status, dates (quote, work order, completion), invoiced amounts, whether invoices were sent and payments processed, and which staff member and queue each job is linked to.
  • Customers (read_customers) — customer record identifiers and activity dates only, used to measure how your customer records are used. We do not read or store customer names, addresses, phone numbers or email addresses.
  • Staff (read_staff) — staff record identifiers and activity status, used to measure team adoption. We do not read or store staff personal details.
  • Schedule (read_schedule) — whether scheduled activities were recorded, and start and end dates, used to measure scheduling discipline.
  • Forms (read_forms) — form names, which jobs they relate to, and completion timestamps, used to measure form usage.
  • Materials and inventory (read_inventory) — item names, amounts and categories, used to assess whether materials are tracked.
  • Job payments (read_job_payments) — payment amounts and timestamps, used to measure how quickly invoices are paid.

3. What we deliberately do not collect

Before any ServiceM8 data is stored or analysed, we strip out personal information. Names, street addresses, phone numbers, email addresses and free-text notes from your jobs, customers and staff are discarded at the point of collection and never reach our database.

What remains are identifiers, dates, statuses, amounts and configuration names — the minimum needed to measure how your ServiceM8 system is set up and used.

4. Other data we collect

  • Account details — your first name, last name, business name, email address and a password (stored only as a secure hash) when you create a Tradie Base account.
  • Connection credentials — the access token ServiceM8 issues after you click Allow, stored encrypted so we can read your account on your behalf and keep the connection alive.
  • Audit results — the metrics, findings, scores and report generated from your ServiceM8 data.
  • Enquiries — anything you send us through the contact or enquiry forms.
  • Basic technical logs — standard server logs such as timestamps and error messages, used to keep the service running and secure. Access tokens and personal information are never written to logs.

5. How we use your data

We do not sell your data, rent it, or use it for advertising. We do not use your ServiceM8 data to train general AI models.

  • To run your audit: calculating your Health Score, the seven category scores, findings and recommended actions.
  • To show your results back to you and to the people signed in to your own Tradie Base account.
  • To keep your ServiceM8 connection working, including renewing access before it expires.
  • To respond when you ask us for help, a quote, or implementation work based on your results.
  • To maintain, secure and improve the service.

6. How AI is used

Your audit report is written with the help of an AI model. The AI only ever receives aggregated numbers and findings — for example, how many jobs were completed on time or which categories scored lowest. It never receives personal information about your customers or staff, and it never receives raw ServiceM8 records.

The AI interprets results that have already been calculated by our audit rules. It does not decide your scores, and it cannot access your ServiceM8 account.

7. How your data is stored and secured

  • Your ServiceM8 access token is encrypted before it is stored and is never sent to your browser after the initial connection.
  • Your audit data is stored in our hosted database, isolated so that only people signed in to your own Tradie Base account can see it.
  • All connections to Tradie Base and to ServiceM8 are made over encrypted HTTPS.
  • Access tokens are renewed automatically and old tokens are replaced. One-time authorisation codes are used once and discarded.

8. Who we share data with

We share data only with the service providers needed to run Tradie Base, and only the minimum each one needs. We do not share your data with anyone else, we never disclose it to other Tradie Base customers, and we may disclose information only if required by law:

  • Our hosting and database provider, which stores your account details and audit results.
  • Our AI provider, which receives only the aggregated, de-identified metrics and findings described above.
  • ServiceM8, when we read your account data through their API on your behalf.

9. How long we keep your data

  • Account details — kept while your Tradie Base account is active.
  • ServiceM8 connection — kept until you disconnect ServiceM8 or ask us to delete it.
  • Audit results — kept so you can review past audits and track progress over time, until you ask us to delete them.
  • Enquiries — kept for as long as needed to handle your request and any follow-up work.

10. Disconnecting and deleting your data

You can disconnect ServiceM8 at any time from the Connect page in Tradie Base, or from the Add-ons section inside your ServiceM8 account. Disconnecting immediately removes our stored access to your ServiceM8 account.

To delete your audit results, your connection record or your entire Tradie Base account, email hello@tradie-base.com.au from the email address on your account and we will delete them. We aim to complete deletion requests within 30 days.

11. Your rights and choices

  • You can choose not to connect ServiceM8 — the audit simply won't run.
  • You can request a copy of the data we hold about you.
  • You can ask us to correct inaccurate account details.
  • You can ask us to delete your data at any time (see above).
  • If you are in Australia, you can complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your personal information.

12. Changes to this policy

If we change what data we access or how we use it, we will update this page and change the date below. If a change requires new ServiceM8 permissions, you will be asked to approve them on ServiceM8's authorisation page the next time you connect.

13. Contact us

Questions about this policy, your data, or a deletion request: email hello@tradie-base.com.au. We reply within one business day (Australian business hours).

Need help?

Our Help & Support page covers connecting ServiceM8, running your audit and deleting your data, or email us at hello@tradie-base.com.au.