← setu.

Privacy Policy

Last updated: 29 March 2026

Who we are

Setu SMS is operated by Mantilam Pty Ltd, an Australian company. We are committed to protecting the privacy of your school's data and the personal information of students, staff and parents in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).

What data we collect

We collect: (1) Account data — name, email address, school name, phone number provided during sign-up. (2) School operational data — student records, staff information, attendance, class schedules, fee records, and related data that you enter. (3) Usage data — pages visited, features used, login times. (4) Payment data — handled entirely by Stripe. We never see or store card numbers.

How we use your data

We use your data solely to: provide and improve the Setu SMS service, send transactional emails (OTP codes, invoices, notifications), provide customer support, and comply with legal obligations. We do not use your data for advertising or sell it to third parties.

Data storage and security

All data is stored in AWS ap-southeast-2 (Sydney, Australia). Data is encrypted in transit (TLS 1.2+) and at rest. Access is controlled through Supabase Row Level Security — each school's data is strictly isolated from other schools. We conduct regular security reviews.

Sub-processors

We use the following sub-processors, each subject to their own privacy policies: Supabase (database hosting, Sydney region), Stripe (payment processing), Resend (transactional email), Twilio (WhatsApp messaging, when enabled by the school), Cloudflare (bot protection), Upstash (rate limiting). We maintain data processing agreements with each sub-processor.

Student data

Student personal information is treated with particular care. We collect only the information you provide. We do not share student data with third parties beyond the sub-processors listed above. Parents and students may request access to their data through the school administrator.

WhatsApp and communications

If your school enables WhatsApp messaging, phone numbers provided by parents/staff are used only to send school-related notifications. Parents can opt out at any time by sending STOP to the school's WhatsApp number. We retain message logs for 90 days.

Data retention

We retain your data for as long as your account is active. If you cancel, we retain data for 30 days before deletion to allow for data export. You can request immediate deletion by emailing us. Stripe retains payment records as required by law.

Your rights

Under Australian privacy law you have the right to: access the personal information we hold about you, correct inaccurate information, request deletion of your data, object to certain processing, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

Cookies

We use only essential cookies required for authentication (session tokens). We do not use tracking cookies or advertising cookies. Our booking and payment pages use Cloudflare Turnstile for bot protection, which may set a short-lived cookie.

Contact and complaints

Privacy enquiries: support@setu.com.au. We will respond within 5 business days. If you are not satisfied with our response you may contact the OAIC at oaic.gov.au.

Changes to this policy

We will notify you by email before making material changes to this policy. The updated date at the top of this page indicates when it was last revised.

Terms of Service →Sign up →