Last updated: 10 June 2026
1. Introduction
Cloud Inn Pty Ltd (“Cloud Inn”, “we”, “us” or “our”) is an Australian company that builds and operates BitOculus, a privacy-first, AI-powered people-counting sensor for physical shopfronts, together with a cloud analytics dashboard. “BitOculus” is our product and brand name; the legal entity responsible for your personal information (and the entity that invoices customers) is Cloud Inn Pty Ltd. This Privacy Policy explains how we handle personal information in connection with:
- our website, waitlist and analytics dashboard (the “Site”); and
- the BitOculus sensor installed in our customers’ venues (the “Sensor”).
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we have designed our product and processes to be ready for the EU General Data Protection Regulation (GDPR) where it applies.
2. The Sensor: no footage, no faces, no personal information
This is the most important section of this policy, so we will say it plainly:
- All video processing happens on the device itself (edge AI). The Sensor analyses its camera feed in real time, on the Sensor’s own hardware, inside the venue.
- No video footage is ever stored or transmitted. Frames are processed in memory and immediately discarded. There is no recording capability, no footage on the device, and no footage in our cloud.
- There is no facial recognition. The Sensor does not create biometric templates, faceprints or any other identifier of an individual.
- No individual is identified or identifiable. The only data that leaves the device is anonymous, aggregate event data: counts of passers-by, entries, exits and U-turns (“bounces”), with timestamps and derived metrics such as capture rate, conversion, bounce rate, hourly traffic curves and an anonymous audience mix.
In short: if you walk past or into a venue that uses a BitOculus Sensor, BitOculus does not collect any personal information about you. We see that “someone” walked in — never who.
As a matter of best practice and transparency, we provide our customers with signage guidance so they can inform visitors that anonymous people-counting technology is in use, and we ask customers to comply with any notice requirements that apply under local law.
3. What we collect on the Site
While the Sensor collects no personal information, our website and dashboard do collect some, as any online service does:
- Waitlist information: when you join our beta waitlist, we collect your work email address and, optionally, your venue type.
- Account data: when you create a dashboard account, we collect your name, email address, authentication credentials, organisation details and role.
- Usage and device data: we collect aggregate analytics about how the Site is used (pages visited, features used, approximate location derived from IP, browser type) and standard server logs for security and reliability.
- Support and communications: if you contact us, we keep the correspondence and any information you choose to provide.
- Billing information (later): when paid plans launch, invoices will be issued by Cloud Inn Pty Ltd and payments will be processed by Stripe. We will receive limited billing details (such as name, billing address and payment status) but we never see or store full card numbers.
- Cookies: see our Cookie Policy for details of the cookies used on the Site.
- When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout.
4. How we use personal information
- to operate the waitlist and contact you about the beta;
- to provide, secure and improve the Site and the dashboard;
- to provide customer support and respond to your enquiries;
- to send service communications and, with your consent where required, product updates (you can opt out at any time);
- to process payments once billing launches;
- to detect, investigate and prevent fraud, abuse and security incidents (including via captcha verification); and
- to comply with our legal obligations.
We do not sell personal information, and we do not use it for third-party advertising.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Contract: to provide the Site, dashboard and Sensor services you or your organisation have signed up for.
- Legitimate interests: to secure and improve our services, prevent abuse and communicate with business contacts, balanced against your rights and expectations.
- Consent: for optional communications and non-essential cookies, which you may withdraw at any time.
- Legal obligation: where processing is required by law (for example, tax and accounting records).
6. Australian Privacy Principles (APPs)
We manage personal information in line with the APPs, including by: collecting only what we reasonably need (APPs 3 and 4); being transparent through this policy (APPs 1 and 5); using and disclosing information only for the purposes described here or as otherwise permitted by law (APP 6); not using personal information for direct marketing without an opt-out (APP 7); taking reasonable steps before any overseas disclosure (APP 8); keeping information accurate, secure and deleting or de-identifying it when no longer needed (APPs 10, 11); and providing access and correction on request (APPs 12, 13).
7. Your rights
7.1 Everyone
You may request access to, or correction of, the personal information we hold about you, and you may unsubscribe from marketing communications at any time.
7.2 Individuals in the EU/EEA and UK
Where the GDPR (or UK GDPR) applies, you also have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Eraseyour data (“right to be forgotten”) in certain circumstances;
- Port your data to another provider in a structured, machine-readable format;
- Object to processing based on legitimate interests, and restrict processing in certain cases; and
- lodge a complaint with your local supervisory authority.
To exercise any of these rights, email privacy@bitoculus.com. We will respond within the timeframes required by applicable law.
8. Data retention
- Waitlist data is kept while the waitlist is active and deleted or de-identified within 12 months of the beta concluding, unless you become a customer.
- Account data is kept for the life of the account and deleted or de-identified within a reasonable period after closure, subject to legal retention requirements.
- Aggregate count data produced by Sensors contains no personal information and may be retained to provide historical analytics to the relevant customer.
- Server logs are retained for a short period for security purposes and then deleted or aggregated.
9. Security
We take reasonable technical and organisational measures to protect personal information, including encryption in transit (HTTPS/TLS for all Site traffic and authenticated, encrypted channels — HTTPS, MQTT over TLS and webhooks — for Sensor event data), encryption at rest with our hosting providers, role-based access controls and row-level security in our database, least privilege access for staff, and captcha protection against automated abuse. No system is perfectly secure, but our architecture means the most sensitive data imaginable for a camera product — footage of people — simply never exists outside the device’s memory.
10. Third-party processors
We share personal information only with service providers who help us run our business, under contracts that restrict their use of it:
- Hosting and backend: cloud infrastructure and database services (including Supabase) that host the Site and dashboard;
- Payments: Stripe, once billing launches;
- Email delivery: transactional and (where opted in) product email providers;
- Captcha and analytics: bot-protection and aggregate site-analytics providers.
We may also disclose information if required by law, or in connection with a corporate transaction (in which case this policy will continue to apply to your information).
11. International transfers
We are based in Australia, and some of our service providers store or process data in other countries (for example, the United States or the European Union). Where personal information is transferred overseas, we take reasonable steps to ensure it is protected to a standard consistent with the APPs and, where the GDPR applies, we rely on appropriate safeguards such as standard contractual clauses.
12. Children
The Site and dashboard are intended for business users and are not directed at children under 16. We do not knowingly collect personal information from children online. The Sensor counts people of all ages anonymously and collects no personal information about anyone, including children.
13. Data breach notification
If a data breach occurs that is likely to result in serious harm to individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act, and any applicable supervisory authority within the timeframes required by the GDPR where it applies.
14. Complaints
If you have a concern about how we have handled your personal information, please contact us first at privacy@bitoculus.com and we will aim to respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992. If you are in the EU/EEA or UK, you may also complain to your local data protection authority.
15. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for significant changes, notify you via the Site or by email.
16. Contact us
Cloud Inn Pty Ltd (trading as BitOculus)
Privacy Officer
Email: privacy@bitoculus.com