Privacy Policy
Last updated 11 September 2026.
Who we are
Nado is a freight dispatch platform operated by NADO FM PTY LTD (ACN 701 783 931, ABN 32 701 783 931), a company registered in Victoria, Australia. Contact us at hello@nadofm.com.
What we collect
When you create an account: your company name, a username, your email address, and a password. When you use the app: the freight items you create, the customers and addresses you add, GPS location of your vehicles during active runs (drivers only, when signed in and on a scheduled run), the time and location at which a delivery is marked complete, photos and hand-signed signatures captured as proof of delivery, messages sent between dispatchers and drivers inside the app, and transactional data we sync with Xero on your behalf if you connect it. Like most online services we also keep operational records — sign-in events, device identifiers for push notifications, and an audit trail of actions taken in your account.
How we use it
To operate the dispatch software you've signed up for — show your drivers their runs, send your customers booking confirmations and tracking links, generate invoices, surface analytics in your admin dashboard. We do not sell your data. We do not use it to train AI models. We do not share it with advertisers.
Visiting the Nado website
When you visit nadofm.com we record how the site is used: which pages and sections you look at and for how long, how far you scroll, which of our buttons and links you press, the kind of device and browser you're on (never its exact model or version), and which website, search or ad brought you here. On the sign-up form we note which fields were filled in or left empty — never what you typed. Two small cookies of our own recognise a returning browser (for a year) and group the pages of one visit (for 30 minutes); only we use them. We don't record your name, email address or IP address as part of this, and we never sell it, share it or use it for advertising. If you go on to create an account, we link your visit to it so we can see which parts of the site led to sign-ups. Each visit's detailed record is deleted after 90 days; after that we keep only daily totals, which don't identify anyone. It's kept on Nado's own servers in Australia and in the encrypted backups described below.
Sharing
Your data is shared only with the services that make Nado work, and with Australian regulators or law enforcement when legally required. Specifically:
Services you explicitly connect. Xero (invoicing and contact sync) and, if you connect it, your own Gmail account for sending email as you (see below).
Services that operate the platform. Cloudflare carries our web traffic. Google provides mapping, address search, geocoding and route services — vehicle coordinates and the addresses you search are sent to Google to power those features. Apple delivers push notifications to your devices. The driver app fetches local weather from Open-Meteo using depot and vehicle coordinates. Subscription payments are processed by Stripe — your card details go directly to Stripe and never touch our servers. Encrypted database backups are stored with Backblaze. When something goes wrong on our servers, the error report goes to Sentry so we can fix it; those reports are configured to carry no request contents, sign-in tokens or personal details.
Overseas disclosure
Nado's own servers are in Australia. Some of the providers above process data overseas: Google, Apple, Cloudflare, Stripe, Backblaze and Sentry operate primarily from the United States, and Open-Meteo from Germany. We take reasonable steps to ensure these providers handle your information consistently with the Australian Privacy Principles.
Google account data
If you connect a Google account so Nado can send email as you, we
ask Google for one permission:
https://www.googleapis.com/auth/gmail.send. That
permission lets us send a message on your behalf and nothing else.
It does not let us read, search, download, modify or delete
anything in your mailbox, and we do not request any permission
that would.
We use it only to send the mail you have asked Nado to send — booking confirmations, delivery notifications, quotes and invoices to your own customers — so those arrive from your address instead of ours. We also read your Google account's email address and name, once, at the moment you connect, so the app can show you which account is connected.
What we store: the access and refresh tokens Google issues, encrypted at rest, plus the connected address and the granted permission. We do not store the contents of sent messages beyond the freight, invoice or booking record the message was generated from.
Google account data is never sold, never shared with anyone other than Google itself in the course of sending your mail, never used for advertising, and never used to train AI or machine-learning models. Nado's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time from Settings → Email inside Nado, which deletes the stored tokens, or revoke Nado's access directly at myaccount.google.com/permissions. Either way Nado immediately stops sending as you — customer-facing email stays unsent until you connect an account again.
Retention + deletion
Your freight, contact and account records are retained as long as your account is active. Some records are deleted automatically on a schedule, whether or not you ask: vehicle GPS location history after 90 days; proof-of-delivery photos and signatures when the freight record they belong to is deleted, and in any case after 7 years; the audit trail and sign-in records after 7 years; the detailed record of each visit to our website after 90 days; the one-time codes and links used to sign in to the booking portal after 30 days.
You can request export or deletion at any time by emailing hello@nadofm.com. We action deletion requests within 30 days. Some records we are legally required to keep for tax reasons (typically 5 years) are retained even after account closure; everything else is purged.
Security
Data is encrypted in transit (TLS) and at rest. Passwords are hashed with PBKDF2 + SHA-256. The iOS app stores its auth token in iOS Keychain. We do not log passwords or sensitive personal identifiers.
Your rights
You may access and correct your personal information at any time via your admin account, and request deletion by emailing us. We comply with the Australian Privacy Principles under the Privacy Act 1988.
Changes to this policy
If we change this policy materially, we'll email all account admins at least 14 days before the change takes effect.