QSTDIO / Website notice
Privacy Policy
What the QSTDIO website handles, why, where it goes, how long it is kept and the choices available to you.
The short version
- Analytics stays off unless you choose to allow it.
- A supported browser Do Not Track signal keeps analytics off.
- The site strips URL queries, fragments and referrer paths, and groups unknown paths as “/other”, before analytics capture.
- Autocapture, heatmaps, dead-click capture, exception capture and session replay are disabled.
- The contact dialog does not transmit, receive or store the values you enter.
- You can reopen Analytics settings from the footer and turn capture off.
Scope and operator
This policy covers the public marketing website at qstdio.com. The site is operated under the QSTDIO brand by Q.STDIO PTY LTD(“QSTDIO”, “we”, “us” or “our”).
It does not describe every way QSTDIO may handle information in a client engagement, a system built for a client, recruitment, supplier dealings or a future QSTDIO product. Those activities need their own notices and contract terms where applicable.
Information the website handles
Analytics preference and local browser state
The site stores your analytics choice (allow or keep off) in local storage on your browser. If you allow analytics, PostHog also uses local storage for anonymous browser and session state. QSTDIO does not configure PostHog to use an analytics cookie on this site.
Limited analytics after you allow it
After consent, the site sends selected events to PostHog’s EU ingestion service. Depending on what you do, those events can include:
- the known page path, or “/other”, without the URL query string or fragment;
- the site section, chapter, workflow or navigation item selected;
- an external destination’s domain, not the full destination URL;
- viewed sections, meaningful engagement, visible active time and maximum scroll percentage;
- browser performance signals, including limited Web Vitals;
- the external referrer’s domain and origin, without its path, query or fragment;
- allowlisted campaign labels for source, medium and campaign; and
- whether analytics was allowed from the first prompt or reopened settings, or later revoked.
The PostHog browser library and ordinary network requests may also process technical data needed to distinguish, receive and protect a visit, such as a pseudonymous identifier, IP address, date and time, browser and operating-system details, language, screen or viewport size and request metadata. The site does not call PostHog’s identify function or create a named analytics profile.
Contact-dialog interaction states, not field values
If analytics is allowed, the site can record that the contact dialog was opened, that entry began, that the local acknowledgement appeared and that the dialog closed. Those events can include placement, close method and simple state such as whether entry began. The analytics layer does not read or send field names, field values or message content. The local acknowledgement is not recorded as a delivered enquiry, lead or conversion.
The contact dialog itself
The dialog displays fields for name, work email, company and message, but it is a static prototype. Submit only runs browser validation and displays a local acknowledgement. The website has no contact endpoint and does not transmit, receive or store those values. Closing the dialog resets its fields. Browser autofill, extensions and device features are outside QSTDIO’s control.
Website-delivery data
Hosting and network systems receive ordinary request data needed to deliver and secure the site. This can include an IP address, requested path, date and time, browser information and security or error logs.
How information is collected
The site obtains browser and request information directly when your device loads a page. PostHog loads only after a granted analytics choice and then receives the limited events and technical data described above.
The current site has no user accounts, payment checkout, newsletter registration or working contact submission. QSTDIO therefore does not claim to collect account, payment, mailing-list or enquiry content through those absent features.
Why it is used
- to remember the analytics choice made in that browser;
- to understand, after consent, whether pages and interactions are useful;
- to find navigation, content and performance problems;
- to measure broad acquisition and engagement patterns; and
- to deliver, operate, diagnose and protect the website.
The current analytics configuration is not used for targeted advertising. QSTDIO does not use contact-dialog values because they never reach QSTDIO.
Your analytics choices
Analytics is off by default. Choosing Keep analytics off from the first prompt records the preference locally and sends no decline event. Choosing Allow analytics loads PostHog and sends a consent-granted event before later site events can be captured.
If the browser reports Do Not Track through the signal this site supports, analytics remains off and the allow control is disabled. Not every modern browser sends that signal, so it is a best-effort additional control rather than a substitute for the consent choice.
Use Analytics settings in the footer to review or change your choice. If you previously allowed analytics, turning it off can send one consent-revoked settings event immediately before the site opts the current PostHog client out, resets its local PostHog state and stops future capture on that browser. Clearing site storage also clears the remembered QSTDIO choice.
Providers and overseas processing
PostHog
When analytics is allowed, the site sends the limited data described above to PostHog’s EU-hosted service through eu.i.posthog.com. This processing occurs outside Australia. PostHog explains its own practices in its privacy policy and privacy documentation.
Website hosting and delivery
QSTDIO uses AWS Amplify Hosting to build and serve the website. AWS hosting and network components may process the request, security and error data needed to make the site available.
What is not yet settled
QSTDIO has not completed an owner-approved inventory of every vendor, subprocessor, infrastructure component or processing country, including the complete country chain for PostHog and AWS services. This policy therefore does not promise that all processing stays in the EU, Australia or any single country, or that provider personnel can never access data elsewhere.
Retention and security
The QSTDIO analytics choice remains in the browser until you change it, clear the site’s storage or QSTDIO changes the consent version. Turning analytics off resets local PostHog state for the current browser.
Server-side analytics and infrastructure-log retention depends on the current QSTDIO project settings and provider arrangements. QSTDIO has not approved a fixed public retention period for either category, so this policy does not invent one. Confirming the settings and a justified retention schedule remains an owner and legal-counsel review item.
The implemented safeguards include consent gating, limited event names, URL and referrer reduction, campaign-value filtering, disabled autocapture, disabled session replay, disabled surveys and no named visitor identification. No internet service can guarantee absolute security, and this policy does not make that guarantee.
Enquiries, requests and complaints
You may ask about website data, request access or correction, ask for deletion, or raise a privacy concern. QSTDIO does not yet publish a dedicated privacy email address. Use the public contact options on the existing QSTDIO founder profile and label the message “QSTDIO privacy enquiry”. Do not use this site’s contact dialog because it does not send.
QSTDIO may need enough information to locate a record and to check that a disclosure or change is being requested by the right person. Because website analytics is not connected to a named profile, QSTDIO may be unable to associate a person with a particular analytics record.
The Office of the Australian Information Commissioner explains its privacy complaint process. That link is provided as public guidance, not as a statement that the OAIC can consider every QSTDIO matter.
Legal coverage and limits
This policy describes the site’s current practices whether or not a particular provision of the Privacy Act 1988 applies. The OAIC explains that most Australian small businesses are not covered by that Act, while some are covered because of their activities, relationships or an opt-in. See the OAIC’s small-business guidance.
QSTDIO has not published the turnover, activity and opt-in facts needed to decide its exact status in this policy. Nothing here claims APP-entity status, certification, regulatory approval or compliance with every privacy law. Applicable rights and obligations depend on the facts and require owner and qualified legal-counsel review.
Changes to this policy
The effective date and version at the top identify the current policy. If the website’s data handling changes materially, QSTDIO will update this page. A material expansion of analytics collection should also be reflected in the consent mechanism before the expanded collection begins.
Drafting references include the OAIC’s guide to what a privacy policy explains and APP 1 transparency guidance. These sources informed the structure; this policy uses original QSTDIO language and is not legal advice.