Skip to main content

Orchard Tech App Privacy Policy

Effective date: 20 September 2026
Policy version: 1.2
App covered: Orchard Tech for iPhone, iPad and compatible Apple-silicon Macs

Short privacy summary

The Orchard Tech app helps workers find published workplace information and save verified documents for offline use. It does not require an account or contain advertising or cross-app tracking. Contact Orchard Tech lets a worker write, review and send a text-only workplace question or support message in the app. The information sent, how it is handled and the limits of a handoff confirmation are explained below.

If approved farm boundaries are published, the app can use one location reading while it is open to suggest a work site. The comparison happens on the device. Orchard Tech does not receive or store the device coordinates or a location history, and a worker can decline location permission and use manual site selection.

The app stores language and tab preferences, cached public information, documents saved for offline use and minimal contact request status on the device. Message drafts are held in memory rather than saved permanently. When the app connects to Orchard Tech’s services, Cloudflare and WP Engine process ordinary internet request information such as IP address, request time, requested path, user agent, response status and security or error information.

Orchard Tech does not sell app information, use it for targeted advertising or track workers across apps or websites.

1. Who is responsible

The Orchard Tech app and connected public worker services are operated by Suvarnabhoomi Pty Ltd ACN 141 241 769 as trustee for the Suvarnabhoomi Discretionary Trust, ABN 16 102 266 894, trading as Orchard Tech.

In this policy, “Orchard Tech”, “we”, “us” and “our” refer to that operator.

This policy is limited to the Orchard Tech app and the public worker services it uses. It does not describe unrelated recruitment, payroll, employment-record, customer, supplier or general business processing, which is addressed in the Orchard Tech Website Privacy Policy or another specific collection notice.

2. What the current app does

The app gives workers access to published workplace information, safety documents, PALM Scheme resources and forms in English, Lea faka-Tonga and Bahasa Melayu. It can save eligible verified documents for offline use. New contact instructions are currently provided in English; existing language controls and available resource translations remain accessible.

The current release:

  • does not require an account or sign-in;
  • does not contain advertising, cross-app tracking or third-party behavioural-analytics SDKs;
  • does not sell personal information or use app information for direct marketing;
  • does not send a worker’s device coordinates to Orchard Tech;
  • does not monitor location in the background; and
  • offers voluntary text-only Contact Orchard Tech messages through the native app interface, when the service is available. Native training uploads and native hazard reports are unavailable in this release. Separate website forms may remain available on Orchard Tech’s website.

We will update this policy and any required collection notice before enabling accounts, additional submission workflows, behavioural analytics beyond the aggregate operational statistics described in section 5, advertising or other materially different data handling.

3. Information handled only on the device

Location

If approved farms and their detection boundaries are published, the app may ask for permission to obtain one precise location reading while the app is open. It compares that reading with approved farm boundaries on the device to suggest the farm the worker appears to be at.

The app:

  • does not monitor location in the background;
  • does not send coordinates, location accuracy or the suggested-farm result to Orchard Tech or another service;
  • does not save a location history; and
  • lets the worker decline permission and select a farm manually.

At the effective date, no approved farms are published in the production worker service, so the app does not request location permission.

Location permission can be changed in Settings > Privacy & Security > Location Services > Orchard Tech on an Apple device.

Preferences, searches and farm selection

The app stores the selected language and last-used tab in its private app storage. Search terms, a manually selected farm and on-device location-matching results remain in the current app session and are not sent to Orchard Tech.

Cached worker information

The app stores a local copy of the public worker catalogue so approved information can remain available when reception is poor. If farms are later published, this may include approved farm details and farm-based weather information. Farm weather is based on the farm’s published coordinates, not the worker’s device location.

The public catalogue and saved files are stored in the app’s private local storage and are designated not to be backed up to iCloud.

Contact draft and request status

The app holds an open contact draft in memory until the worker clears it or the app process ends. It does not save the message body as a persistent draft or automatically send it later. It stores one request identifier, creation time, send status and any returned handoff reference in app preferences until the worker clears that status or the app’s data is removed. A request identifier identifies a submission attempt, not a worker account. Device backup and restoration of app preferences are controlled by Apple.

4. Documents saved for offline use

When a worker chooses Save for offline use, the app downloads the approved document from Orchard Tech’s website and stores the document and related details on the device. Those details can include:

  • document title and language;
  • whether it is a company or farm document;
  • associated farm name and identifier, if applicable;
  • file type and size;
  • an integrity fingerprint;
  • the date saved; and
  • whether the saved copy is current, archived or not yet verified against the live catalogue.

Orchard Tech cannot remotely view the worker’s saved-document list. A worker can remove a saved document from the Saved tab. If a document is withdrawn from the live catalogue, the app may label the local copy as archived, but it remains on the device until the worker removes it or removes the app.

5. Information processed when the app connects online

The app makes encrypted HTTPS requests to Orchard Tech’s public worker services to:

  • request the catalogue in the selected language;
  • obtain published farm context and farm weather, if available;
  • check whether contact messages are available;
  • download a document selected by the worker; and
  • send the contact information a worker chooses to submit, after review and confirmation.

Catalogue and document requests do not include an Orchard Tech login, worker ID, advertising identifier, device coordinates, suggested-farm result, search terms or saved-document list. Contact requests additionally contain the message information described in section 5A. The app does not automatically add location or information from other apps to a contact message.

As with an ordinary internet request, Orchard Tech’s hosting and security providers process technical request information. This can include:

  • IP address and network-routing information;
  • request date and time;
  • requested URL, including the selected language or document path;
  • user-agent, device/browser and request-header information;
  • referrer, response status, file size, cache and routing information; and
  • security, diagnostic and error information.

An IP address can indicate an approximate country or region and can distinguish a network or device for security and visit-counting purposes. The requested language, page or document path can show how the public service was used.

The current public service is delivered through Cloudflare and hosted by WP Engine. These providers can generate aggregate traffic, request, cache, performance, error and security statistics. Orchard Tech can use technical information and those operational statistics only to deliver requested content, understand whether the public service is functioning, maintain availability and security, investigate faults, respond to privacy or support requests, and comply with legal obligations. Orchard Tech does not use them to create worker profiles or advertising profiles, or to track workers across apps or websites.

WP Engine currently makes edge access logs available to customers for up to the previous 72 hours and origin access logs as the most recent 1,500 requests. Orchard Tech does not intentionally export routine app access logs into a separate long-term worker profile. Cloudflare and WP Engine may retain separate operational, security and network records as needed to provide and protect their services or comply with law, under their service terms and privacy policies.

Apple may separately process App Store, TestFlight, device or diagnostic information under Apple’s own terms and privacy policy.

5A. Contact Orchard Tech messages and separate website forms

Messages sent from the app

Contact Orchard Tech collects your chosen topic, message, whether you include a name, any name and reply phone number you provide, whether a reply is requested, your privacy confirmation, and a request identifier and notice version. We use this information to handle your enquiry or requested reply and to prevent duplicate submissions. The app does not accept attachments, worker IDs or training evidence in this contact workflow.

If you choose “Send without my name”, the app omits the name and phone fields and does not request a reply. The server also discards any name or phone values supplied in that mode. Your message may still identify you, and ordinary hosting and security logs may exist. We do not promise anonymity.

The app sends the information over HTTPS to Orchard Tech’s website. The website passes a contact email to workerforms@orchardtech.com.au through Orchard Tech’s authenticated email service. The message is handled by authorised Orchard Tech personnel and the hosting, security and email providers needed to process it. The WordPress contact feature does not store the message body as a database record or attachment. The configured mail plugin’s email-content logging and asynchronous email queue are disabled.

The server keeps duplicate-prevention metadata, including a protected request key and content fingerprint, state, expiry and any handoff reference. This is not a copy of the message. The duplicate-prevention window is 24 hours; expired entries are eligible for scheduled cleanup. Security and rate-limit controls can also process technical request information. Actual deletion can occur after expiry when cleanup runs, and provider backups and logs have separate retention.

A successful result means that the server accepted the message for email handoff. It does not confirm arrival in the mailbox, staff review, a response, investigation, resolution or completion of an employer duty. If a result is uncertain, the app keeps that uncertainty visible. It does not automatically resend a message on reconnect or relaunch. Clearing the app does not cancel or recall a message that may already have been sent.

This is not an emergency service. For immediate danger, move to safety and contact your supervisor; call 000 for an emergency. Do not wait for a message response. Do not include passport, visa, bank, tax, medical or other private-document details, or information about another worker.

Separate website forms

Orchard Tech’s website separately offers hosted training, hazard-alert and contact forms at the website Forms page. The app’s former Forms launcher has been removed. If you separately use a website form, its collection notice explains the fields, purpose and restrictions for that workflow.

Those website forms may collect a name and worker ID; training and induction details; trainer, language-assistance and work-site information; a hazard description and location; messages, notes and an optional contact phone number; selected training-page images or an optional hazard photo; and form confirmations. They route handoff emails to workerforms@orchardtech.com.au. Accepted images are rebuilt as JPEG images before handoff, removing source filenames and EXIF/GPS metadata. The forms do not publish uploaded images or store them in the WordPress Media Library. Rebuilding an image is not malware scanning. Website contact messages do not accept attachments. Their no-name mode discards identity fields before constructing the email but does not guarantee anonymity.

Website submissions are handled by authorised Orchard Tech personnel and necessary providers for the relevant training, hazard or contact purpose. They are not used for advertising or cross-app tracking. Follow each form’s instructions about permitted information. A form confirmation or email handoff does not establish completed training verification, formal incident reporting or a response. These channels do not replace emergency action or required workplace processes.

6. How information is used and disclosed

Information handled through the app is used only to:

  • receive, match and review submitted training and induction evidence, assess and respond to hazard alerts, and handle worker messages or requested replies as described in section 5A;
  • provide the public worker-content service;
  • return information in the selected language;
  • deliver documents a worker requests;
  • review aggregate operational traffic, performance, error and security statistics;
  • maintain service security and reliability;
  • investigate and resolve technical issues;
  • answer privacy requests or complaints; and
  • meet lawful obligations.

Orchard Tech does not use app information for behavioural advertising, cross-app tracking or sale to data brokers.

Technical request information may be disclosed to service providers needed to host, secure and deliver the service, including Cloudflare and WP Engine, or where disclosure is authorised or required by law. Those providers process end-user information under their applicable service terms, data-protection terms and legal obligations.

Native contact messages and separate hosted website submissions are handled as described in section 5A and the relevant collection notice.

7. External websites, maps, calls and email

The catalogue can contain user-initiated links to government departments, PALM Scheme resources, workplace-safety regulators, workplace-relations bodies, insurers and other approved publishers. An external page opens in a separate in-app browser view and is governed by the destination organisation’s privacy policy. The external website can receive ordinary browser-request information such as IP address, browser details and the requested page.

If a worker chooses to open a farm in Apple Maps, the app supplies the published farm address, not the worker’s device coordinates, to the Maps link. Apple Maps may independently use device location according to the worker’s Apple settings and Apple’s privacy policy.

If a worker taps a phone or email link, the device’s Phone or Mail service, the telecommunications provider and the recipient handle that communication. The Orchard Tech app does not read contacts and does not capture call or email content.

8. Overseas processing

Cloudflare is a United States-based global provider and says it primarily stores information in the United States and European Economic Area, with transfers and access from other locations in which its group operates. WP Engine is a United States-based provider and may use international infrastructure and subprocessors.

Technical request information may therefore be processed outside Australia, including in the United States and the European Economic Area, and may be accessed from other countries in which those providers or their approved subprocessors operate.

Where Australian privacy law applies to an overseas disclosure, Orchard Tech takes the reasonable steps required by that law, subject to any applicable exception.

9. Retention and deletion

The app applies the following local retention:

  • a location reading and matching result are held temporarily in memory and are not written to app storage;
  • search terms and manual farm selection last only for the current app session;
  • language and tab preferences remain until changed or the app’s data is removed;
  • the public catalogue remains locally cached until refreshed or the app’s data is removed, and the app treats the cache as stale after 24 hours;
  • cached farm context is not used for automatic detection after it is stale or when a live refresh fails; and
  • offline documents and their metadata remain until the worker removes them or removes the app;
  • a contact draft remains only in memory until cleared or the app process ends; and
  • the contact request identifier, creation time, status and handoff reference remain in app preferences until cleared or the app’s data is removed.

Removing the app asks the operating system to remove its app-managed local data. Apple controls device restoration and other operating-system behaviour.

Removing the app or clearing contact status does not delete information already submitted to Orchard Tech or held in its mailbox. Contact messages are retained for as long as reasonably necessary to handle the enquiry, document its outcome and meet applicable recordkeeping requirements. They are then deleted or de-identified when permitted. If a message must be kept for a workplace matter or legal obligation, deletion may not be available. Requests about access, correction or deletion can be made using section 11. Provider backups, mail-system records and security logs may have separate retention and deletion arrangements; a deletion request does not promise immediate erasure from every backup. Orchard Tech will explain any applicable limits when responding. The server’s duplicate-prevention metadata has the 24-hour expiry and scheduled cleanup described in section 5A.

Routine WP Engine access-log availability is described in section 5. Cloudflare and WP Engine may keep separate operational or security records for the periods necessary to provide, secure and audit their services or meet legal obligations. Orchard Tech keeps a privacy enquiry or complaint only for as long as reasonably necessary to respond, document the outcome and meet applicable legal recordkeeping requirements, then destroys or de-identifies it when permitted.

10. Security

The app minimises information sent off the device. It uses HTTPS, does not attach app-login credentials to public-content requests, restricts external links to approved HTTPS destinations, and verifies the type, size and integrity of documents saved offline.

Local information is kept within the app sandbox and is also protected by the worker’s device passcode and Apple security settings. Workers should keep the operating system updated and report a lost or compromised device promptly.

Orchard Tech uses reasonable technical and organisational safeguards appropriate to the information and risks. No internet or storage system is completely secure. Orchard Tech assesses suspected eligible data breaches and, where the Notifiable Data Breaches scheme applies, notifies affected people and the Office of the Australian Information Commissioner as required.

11. Access, correction, deletion and complaints

The app does not require a worker account. Orchard Tech cannot remotely access information that exists only inside the app on a worker’s device. Orchard Tech may hold information the worker submits through native contact or separate hosted website forms, and the access, correction, deletion and complaint process below applies to that information.

A worker can:

  • revoke location permission in device Settings;
  • change the app language;
  • remove offline documents from the Saved tab;
  • clear a contact draft or local request status from Contact Orchard Tech; and
  • remove remaining app-managed local data by uninstalling the app.

A person can contact Orchard Tech to ask whether it holds personal information about them, request access or correction, request deletion where appropriate, or make a privacy complaint. Orchard Tech may need to verify identity before acting.

Orchard Tech aims to respond within 30 calendar days. If it cannot provide access, correction or deletion, it will explain the reason and available complaint avenues where required.

Please first send a complaint to Orchard Tech using the contact details below. If Orchard Tech does not respond within 30 days, or the person is not satisfied with the response, they may contact the Office of the Australian Information Commissioner.

12. Children

The app is not designed for young children and is not submitted in Apple’s Kids Category. It is intended for people who need Orchard Tech worker information. The app does not invite users to create an account. Its contact feature and separate hosted forms are intended for people using Orchard Tech’s worker services and collect the information described in section 5A when a person submits information.

13. Changes to this policy

Orchard Tech will review this policy before materially changing app or server data handling, including materially changing native contact or hosted forms, or enabling additional submission workflows, accounts, additional location processing, behavioural analytics beyond the aggregate operational statistics described in section 5, or advertising.

The revised effective date will be published, and an appropriate prominent notice will be provided when a change materially affects users’ privacy.

14. Contact

Privacy contact: Hari Yellina
Legal operator: Suvarnabhoomi Pty Ltd ACN 141 241 769 as trustee for the Suvarnabhoomi Discretionary Trust, ABN 16 102 266 894, trading as Orchard Tech
Email: hari@orchardtech.com.au
Phone: +61 439 323 232
Postal address: 12 Happy Valley Road, Robinvale VIC 3549, Australia

Please use the subject line Privacy request.