Tranche Capital

Privacy policy

Last updated 11 August 2026.

This policy explains how Tranche Capital Pty Ltd (ABN 83 700 835 687) — “Tranche Capital”, “we”, “us” — handles personal information in the course of providing the Tranche Capital platform, deal management software licensed to commercial finance and private credit firms. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

In short. We hold what a firm's own work puts in front of us and nothing else. Every firm's data is separated by the database, not by convention. A connected personal mailbox is readable by exactly one person — its owner. All data is stored in Australia. We do not sell personal information, and we do not use it to train AI models.

1. Two different roles, and why the difference matters

Almost everything in the platform is information a customer firm put there in the course of its own business — its borrowers, its sponsors, its lenders, its correspondence. For that information, the firm decides what is collected and why; we hold and process it on the firm's instructions, under our agreement with that firm.

If your dealings are with a finance firm that uses our software and you want to know why your information was collected or ask for it to be corrected or deleted, that firm is the right place to start — it holds the relationship and it controls the record. We will help any firm meet such a request, and you may also contact us directly using the details in section 11.

A smaller category — the account records of the people who sign in, and our own billing and support records — we determine ourselves. This policy covers both, and says which is which where it matters.

2. Information we collect

Account information

Name, work email address, role and permissions within a firm, sign-in and session activity, and an audit record of significant actions taken in the platform. Accounts are created by a firm's administrator or by us at a firm's request — there is no public sign-up, and signing in with Google never creates an account.

Information a firm places in the platform

Deal records and the parties to them (borrowers, guarantors, sponsors, brokers, lenders and their contact details), security and property details, facility terms and financial figures, documents uploaded to a deal, information supplied by a borrower through the borrower portal, and correspondence relating to a deal.

Information from connected Google accounts

Only where a user explicitly connects one — see section 3.

Technical information

Server logs recording requests to the service, including IP address, time and the page or endpoint requested, kept for operating and securing the platform. This website (tranchecapital.net) sets no cookies, runs no analytics and makes no request to any third party; the pages are static files. The application itself uses a session token strictly to keep you signed in.

3. Google user data

Connecting a Google account is optional and is always initiated by the user, from within the application. Nothing is accessed until you grant it, and access can be withdrawn at any time (section 8).

What we request, and why

ScopeWhat it allowsWhy the product needs it
openid, userinfo.email, userinfo.profile Confirm the email address and basic profile of the person signing in. Sign-in only. Establishes which existing account is signing in. It cannot create an account.
gmail.readonly Read messages in a mailbox the user connects. Bring a firm's deal correspondence onto the deal record, so the thread and the file are the same thing.
gmail.send Send messages as the connected mailbox. Send replies and deal correspondence from the user's own address, so recipients reply where they expect to.
drive.readonly Read files in Google Drive that the connecting user can already see. Import a firm's existing deal archive from its own Drive folder into the deal record.

What we never do with Google data

Limited Use

Tranche Capital's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. The two boundaries the database enforces

These are not undertakings the application is trusted to remember. They are row-level security policies in PostgreSQL: a query that failed to respect them would be refused by the database itself.

When our support staff enter a firm's workspace to help — which is recorded in that firm's own audit trail, and shown on screen throughout — the session carries no user identity, and therefore no personal mailbox is visible to it. Support sees strictly less mail than the firm's own administrator does.

5. How information is stored and protected

No system is perfectly secure, and we do not claim otherwise. If a data breach occurs that is likely to result in serious harm, we will notify affected parties and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

6. Who we share information with

We do not sell personal information. We disclose it only:

Service providerPurposeLocation
Amazon Web ServicesHosting, storage, and AI processing (Amazon Bedrock)Australia
GoogleSign-in, and Gmail/Drive access at the user's directionPer Google's terms
StripeBilling and payments for firms. Receives billing details only — never deal data or Google data.Per Stripe's terms
CloudflareDNS and delivery of this websiteGlobal network

7. Artificial intelligence

The platform uses large language models to draft replies, summarise correspondence and answer questions about a firm's own records. The limits below are enforced in the software, not merely instructed:

8. Withdrawing access, retention and deletion

9. Your rights

You may ask us for access to the personal information we hold about you, and to correct it if it is wrong. Where the information sits in a customer firm's workspace, we will refer you to that firm or act on its instructions, as section 1 explains. We will respond within a reasonable period and will tell you if we cannot give access and why.

If you are unhappy with how we have handled your personal information or your request, write to us first (section 11). If we do not resolve it, you may complain to the Office of the Australian Information Commissioner — oaic.gov.au.

10. Changes to this policy

We may update this policy as the platform changes. The date at the top records the current version. Where a change materially affects how personal information is handled, we will tell customer firms directly rather than rely on this page being re-read.

11. Contact

Privacy questions, access and correction requests, and complaints:
privacy@tranchecapital.net

Tranche Capital Pty Ltd
ABN 83 700 835 687 · ACN 700 835 687
Sydney, New South Wales, Australia.