Legal
Thyme — Privacy Policy
Last updated 10 June 2026
On this page
This policy explains how Thyme handles personal information. Thyme is owned and operated by Greenhat Group Pty Ltd (ABN 41 601 776 943) ("Greenhat Group", "we", "us"). We respect your privacy and handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we handle the information of people in New Zealand, we also act consistently with the New Zealand Privacy Act 2020.
By using our Site or Services, you agree to this policy. It should be read with our Terms of Service.
How this works
Most of the personal information held in Thyme belongs to our customers. Thyme is a tool that consulting firms use to run their own commercial operations, and the data a firm imports may include personal information about its own staff, contractors, clients and related entities.
- For that customer data, our customer is responsible for it and controls it. We process it on the customer's behalf to provide the Service, under our Terms. If you are an individual whose information sits inside a firm's Thyme account, please contact that firm about your information in the first instance.
- This policy covers the personal information we are responsible for — mainly the information of our website visitors, prospects, account holders and users.
What we collect
- Account and contact details — such as your name, work email, company name, role and phone number, when you request early access, sign up, or are added as a user. (For example, our early-access form asks for your name, work email, firm name and approximate team size.)
- Usage and device data — log data, IP address, browser and device information, and how you use the Site and Service.
- Billing details — handled by our payment provider; we do not store full card numbers.
- Communications — the content of emails and support messages you send us.
We do not knowingly collect sensitive information unless you choose to provide it, and we do not sell your personal information.
How we collect it
We collect information directly from you (through forms, email and calls), automatically (through cookies, analytics and server logs), and sometimes from our customer (when a firm adds you as a user or includes your details in its account).
Why we use it
We use personal information to:
- provide, secure, support and improve the Service;
- set up and manage accounts, complete onboarding, and take payment;
- communicate with you, including service messages and occasional product updates (you can opt out of marketing at any time);
- create aggregated and de-identified insights, benchmarks and statistics, and develop, test, train and improve our products, features and models (see Analytics, benchmarking and product development below); and
- meet our legal obligations.
Analytics, benchmarking and product development
We may use information from across the platform to create aggregated and de-identified insights, and to develop, test, train and improve our products, features and models, including future analytics and machine-learning features. We use information for these purposes only in aggregated or de-identified form, designed not to identify you, any individual, or any single customer or its clients. We do not sell your personal information.
Cookies and analytics
We use essential cookies to run the Site and Service, and analytics to understand how they are used. You can control or block cookies through your browser settings, though some features may not work without them.
Sharing and overseas storage
We share personal information only with trusted service providers who help us run Thyme — for example hosting, email, analytics, payments and support — and who are bound to protect it. Some of these providers may store or process information outside Australia; where they do, we take reasonable steps to ensure it is handled consistently with this policy and applicable law. We may also disclose information where required by law, to protect our rights or safety, or as part of a business sale or transfer. Otherwise, we do not disclose your personal information without your consent.
Keeping and securing your information
We take reasonable technical and organisational steps to protect personal information from misuse, loss and unauthorised access. We keep it only for as long as we need it for the purposes above or as our Terms require, after which we delete or de-identify it. Account data is handled on cancellation as described in our Terms. No system is completely secure, and we cannot guarantee absolute security.
Accessing and correcting your information
You can ask us to access or correct the personal information we hold about you by emailing privacy@truethyme.com. We will respond within a reasonable time, and will let you know if we cannot meet a request and why. If your information sits inside a customer's account, please contact that customer.
Complaints
If you have a privacy concern, please contact us first and we will work to resolve it. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes and contact
We may update this policy from time to time. The current version is always on our Site, and we will note the date it was last updated above.
For any privacy question, contact:
Greenhat Group Pty Ltd (ABN 41 601 776 943)
10 Prospect Street, Fortitude Valley QLD 4006, Australia
privacy@truethyme.com