BaselineRTK

Privacy policy

Last updated 3 October 2026. This policy explains what personal information BaselineRTK collects, why, who it shares it with, how long it keeps it, and how to ask for it.

1. Who we are

BaselineRTK Pty Ltd (ABN 95 702 812 002) runs the BaselineRTK correction service. In this policy, "we", "us" and "our" mean BaselineRTK Pty Ltd.

Make any privacy request, question or complaint by email to support@baselinertk.com.

2. What this policy covers

This policy covers the personal information we handle when you:

  • visit our website, www.baselinertk.com;
  • create and use an account in our customer app, app.baselinertk.com;
  • connect a rover to our correction service at ntrip.baselinertk.com;
  • email us.

Personal information is information about a person who is identified, or who can reasonably be identified. Most of our customers are businesses. Information about a business is not always personal information, but information about the people in it is, such as your name and email address. A rover's position can be too, because it can show where a person is working. We treat all of it with care.

We follow the Australian Privacy Principles in the Privacy Act 1988 (Cth) in how we handle personal information.

3. The short version

  • We collect what we need to run your account, bill you and send your rovers corrections.
  • Your rover tells our server where it is. We use that to choose its base station, and we keep a record of it in our server logs for 90 days.
  • Stripe handles your card. We never see your full card number.
  • We do not sell personal information, and we do not use it for advertising.
  • Some of the companies that help us run the service are overseas.
  • You can ask to see or correct what we hold about you, or make a complaint, by emailing support@baselinertk.com.

4. What we collect

Your account

  • Your email address and a password, when you create an account. Supabase, our sign-in provider, keeps the password for us. We do not keep a copy.

Your subscription and billing

  • How many rovers you pay for, whether you pay monthly or yearly, the state of your subscription (for example on trial, active, payment overdue, paused or ended), when it last changed, and the reference numbers Stripe gives your customer record and subscription.
  • Through Stripe, our payment provider: your card details, and your name, billing address, phone number and ABN or other tax number if you give them; your invoices and payments; and your reason for cancelling, if you choose to give one.
  • We never see your full card number.

Your rovers' logins

  • We create a login for each rover you pay for. We choose its name, for example brtk0007-01. It does not contain your name.
  • We create each rover's password on our correction server. The server keeps it so it can check your rover when it connects.
  • To show you a new password, we place it in our database for you to collect. It is deleted the moment you press "Show new passwords". Until you press it, the password waits there. If it is never shown, we delete it once it has waited at least 7 days without being shown; it can wait longer, for example while our system is paused for a check. After that you can reset the rover's password to get a new one.
  • When you ask to reset a rover's password, we record which rover and when. We delete that request once the new password is issued.

When your rovers connect

  • The rover's login, and the mountpoint it asks for: NEAREST_20 or NEAREST_94, or one of our base stations by name.
  • Its position. Your rover sends its position in a standard NMEA "GGA" message when it connects, and then regularly while it stays connected. That message also carries the time, the height and the quality of the rover's fix. We use only the latitude and longitude: on NEAREST_20 and NEAREST_94, to choose the nearest working base station, and to keep choosing it as the rover moves. A rover that asks for a base station by name gets that base and is never switched, so its position is not needed; if it sends one, we use it only to see how far the rover is from its base while it is connected.
  • A record in our server logs each time a base is chosen for your rover, or a switch to a nearer base starts. It holds the rover's latitude and longitude (to about one metre), the base, and the distance to it.
  • A record when a connection ends: the login, the mountpoint, the last base used, and why the connection ended.
  • The caster's record of each connection, written when it ends: the date and time, the login, the mountpoint, the name of the NTRIP software that connected, how long the connection lasted and how much data was sent.
  • Your rover's internet (IP) address. Our server needs it while the rover is connected. For a rover set up as our setup guides describe, on port 2101, our current software does not write it to our logs. A rover that connects straight to our caster on another port has its address in the caster's record of the connection.
  • For your dashboard: whether each rover is connected, which base it is using, and since when. We keep this for about a day.

When you use our websites

  • The customer app uses cookies to keep you signed in. It has no analytics or advertising cookies.
  • Our public website, www.baselinertk.com, runs on Webflow. It has no analytics, no advertising and no tracking cookies, and no forms that collect personal information.
  • The website loads its fonts through Google Fonts, so your browser contacts Google to fetch them, which tells Google your IP address and browser details.
  • The website asks the customer app whether you are signed in, so that it can show "My account" instead of "Log in". If you have signed in to the customer app in that browser, your browser sends the app's own sign-in cookie with that question. The answer is only yes or no, and nothing about you is passed to the website.
  • The companies that host our websites and our sign-in may keep technical records of the requests they handle, such as IP addresses and browser types, under their own privacy policies.

When you contact us

  • Your email address, your name if you give it, and what you write to us.

5. How we collect it

  • From you: when you create an account, subscribe, use your dashboard or email us.
  • From your rovers, automatically, while they are connected.
  • From Stripe: each time your subscription changes, Stripe tells us its new state.
  • From our own systems: we create rover logins and passwords, and our servers keep the records described above.

6. Why we use it

  • To provide the service: to create and check rover logins, choose the nearest working base for each rover, and show you your rovers and your subscription.
  • To bill you, through Stripe, and to turn your corrections on or off to match your subscription.
  • To help you: to answer your questions and fix problems, including looking at a rover's connections when you ask us for help.
  • To keep the service working and secure: to find and fix faults, to tune how we choose and switch bases, and to spot misuse, such as one login used on several machines.
  • To tell you about your account and the service: for example sign-in links, billing notices and notice of changes to our terms or prices.
  • To meet our legal obligations, such as keeping tax records.

We do not sell personal information. We do not use it for advertising. We use rover positions only to run and improve the correction service.

Emails

We send the emails you need to use the service, such as sign-in links and notices about your account. We do not send marketing emails. If we ever do, we will send them only to people who have agreed to receive them, and every one will tell you who sent it and have a working way to unsubscribe.

7. Who we share it with

We share personal information only with the companies that help us run the service, and each gets only what it needs.

CompanyWhat it does for usWhat it handlesWhere
StripePayments, invoices and the billing page ("Manage billing")Your billing and card details, subscription and invoicesStripe says it may transfer information to other countries, including the United States and India
SupabaseOur database and sign-inYour email address and password, your subscription's state, rover login names, rover status, new passwords waiting for you, and reset requestsSydney, Australia (Supabase's ap-southeast-2 region). Supabase is a United States company
VercelHosts the customer appEverything that passes through the customer appThe United States and other countries
PostmarkSends the customer app's emails, such as the link to confirm your sign-up and password emailsYour email address and the content of those emailsPostmark is a United States service. Its owner, ActiveCampaign, lists the United States, Australia, Ireland, Brazil and Costa Rica
WebflowHosts our public websiteThe requests your browser makes when you visit it, such as its IP address and browser type. The website has no forms that collect personal informationThe United States and other countries
GoogleSupplies the fonts our public website uses (Google Fonts)Your browser's requests for the fonts, which include its IP address and browser detailsThe United States and other countries
CloudflareRuns the address book (DNS) for our domain names, and forwards email sent to support@baselinertk.com to our mailboxThe lookups of our domain names, and the emails you send to our support address as it passes them on. Your rover's connection to our correction server does not pass through Cloudflare: Cloudflare answers the lookup of the server's name, and your rover then connects to our server directlyMainly the United States and the European Economic Area
MicrosoftOur support mailbox (Outlook.com), to which email to support@baselinertk.com is forwardedEmails you send us, and our repliesMicrosoft is a United States company. It stores the mailbox's data in the United States and other countries
Binary LaneHosts our correction serverRover logins and passwords, rover positions in our logs, and connection recordsAustralia

We may also share information with our professional advisers, such as our accountant or lawyer, where they need it, and with authorities where the law requires it.

We do not send your rover's position or login to Geoscience Australia, or to any other operator of the base stations we use. Our server collects their base station data using our own account.

8. Information that goes overseas

Some of the companies in section 7 are based overseas, or may store or reach information overseas. Based on what they publish, that includes the United States, India, Ireland, Brazil, Costa Rica and countries in the European Economic Area, and other countries where Vercel, Webflow, Google and Microsoft keep information. Our database and sign-in (Supabase) are kept in Sydney, and our correction server (Binary Lane) is in Australia.

We choose established providers that publish how they protect personal information, and we give each only what it needs to do its job. Each handles personal information under its contract with us and its own published privacy policy, which say how it protects information it moves between countries.

9. How we protect it

  • Each customer sees only their own records. The database itself enforces this, not just the app.
  • Each part of our system has only the access it needs. For example, the customer app's key for Stripe can open a checkout or the billing page, and little else.
  • The system that manages rover logins is not reachable from the internet.
  • A new rover password is shown to you once, then deleted from our database. One that is never shown is deleted too (section 10).
  • Our connections to the database are encrypted, and they check that they are talking to the right server.
  • The connection between your rover and our correction server is not encrypted. This is usual for NTRIP correction services. Your rover's login, password and position travel over the mobile network in plain form. The password we create for each rover is used for nothing else, so do not replace it with one you use elsewhere.
  • No system is completely secure. If a breach of your personal information is likely to cause you serious harm, we will tell you, and we will notify the Office of the Australian Information Commissioner (OAIC) as its Notifiable Data Breaches scheme describes. We make this commitment ourselves, whether or not the scheme applies to us.

10. How long we keep it

InformationHow long we keep it
Your account and subscription recordsWhile you have an account, then 5 years
Invoices and payment records5 years, as the Australian Taxation Office requires. Stripe keeps its own records under its own policy
The reference numbers of billing events Stripe sends us (no other content)While you have an account, then 5 years
Rover status for your dashboardAbout a day
A new rover password waiting for youUntil you press "Show new passwords". One never shown is deleted once it has waited at least 7 days without being shown
A password reset requestUntil the new password is issued
Server log records of rover positions, base choices and connections90 days
The caster's record of each connection90 days
Rover logins and passwords on our correction serverWhile your subscription lasts. After it ends, a login is turned off, not deleted, so that it works again unchanged if you subscribe again. We delete it if you ask us to
Backup copies of the correction server's login file, made before each change to it90 days
Our record of changes to rover logins90 days
Emails between you and usWhile you have an account, then 5 years

When we no longer need information, we delete it or remove what identifies you.

11. Your choices

  • Anonymity. You can ask us general questions without telling us who you are. To subscribe, you need to give us an email address, and Stripe needs your payment details.
  • Rover logins do not contain your name.
  • Marketing emails: we do not send them. If we ever do and you agree to receive them, you can unsubscribe at any time.

12. Seeing, correcting and deleting your information

  • To see what we hold about you, email support@baselinertk.com. It costs nothing to ask. We will reply within 30 days. If we cannot give you something, we will tell you why in writing, and how to complain.
  • To correct it: change your billing details yourself in Manage billing. For anything else, including the email address you sign in with, email us.
  • To close your account and delete your information, email us from the address you sign in with. We will cancel any subscription you still have, delete your sign-in and your rovers' logins and passwords, and delete what we do not need to keep. We keep your account and billing records, including invoices, for 5 years, because tax law requires it for invoices and payment records, and then delete them. Records in our server logs are deleted after 90 days.

13. Complaints

If you think we have mishandled your personal information, email support@baselinertk.com and tell us what happened. We will reply within 30 days.

If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner:

The OAIC generally asks you to complain to us first and give us 30 days to respond. A complaint to the OAIC must be in writing.

14. Changes to this policy

We will publish any change on this page with its date. If a change significantly affects how we handle your information, we will also email you before it takes effect.

15. Contact

BaselineRTK Pty Ltd, ABN 95 702 812 002 support@baselinertk.com

We do not publish a postal address. Make privacy requests by email to support@baselinertk.com.

BaselineRTK Pty Ltd, ABN 95 702 812 002, ACN 702 812 002, Victoria, Australia. support@baselinertk.com