Privacy policy
Last updated: 10 October 2026
Dockit (“we”, “us”) is based in Melbourne, Australia. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what our digital receipt service collects and what happens to it.
What we handle
- Receipt contents. When a shop using Dockit issues a digital receipt, we store a copy of it (usually a PDF). A receipt can include personal information the shop's system printed on it, such as a staff or customer name, a loyalty number or the last digits of a payment card. We never receive full card numbers unless the shop's system prints them.
- Whether a receipt was opened. When the receipt page has loaded on your device, or you save or download it, we record the time it was opened, so the till display can clear.
- Technical logs. Our servers keep short-lived logs (for example, request times and errors) to keep the service running. These logs don't contain receipt contents and are deleted after 14 days.
We don't ask you to create an account, we don't use advertising or tracking cookies, and we don't sell or share personal information for marketing.
How long we keep it
A receipt link works for 24 hours. After that the receipt is deleted from our systems, usually within a further 24 hours. Please save or download your receipt if you need to keep it.
Who can see a receipt
Anyone who has the link can open the receipt until it expires, so please don't share it. Links are long random codes that can't practically be guessed. The shop that issued the receipt already holds its own copy in its sales system.
Where it is stored
Receipts and logs are stored with Amazon Web Services in its Sydney region, in Australia. To display the receipt, the receipt page loads the open-source PDF.js viewer from the cdnjs content network (operated by Cloudflare). That request doesn't include your receipt.
Security
All connections use HTTPS, receipts are encrypted at rest, and access to our systems is restricted. No system is perfectly secure; if a data breach is likely to cause serious harm we will notify affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
The shop's own privacy practices
The shop is responsible for the information it puts on your receipt and for its own sales records. For questions about those, please contact the shop directly.
Access, correction and complaints
You can ask what personal information we hold about you, ask us to correct it, or make a complaint by emailing info@dockit.digital. We aim to respond within 30 days. If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
We may update this policy. The date at the top shows when it last changed.