Skip to main content
Legal

Privacy policy

What One Piece Automation does with personal information — on this website, when you enquire, and inside the OPFCC Manager platform we build, install and support.

Last updated 31 August 2026

Who this policy is from

One Piece Automation (ABN 50 690 467 577) of Seaford, Victoria, builds OPFCC Manager — the One Piece Forecourt Controller Manager — and installs and supports it on Australian forecourts. In this policy, “we”, “us” and “our” mean One Piece Automation.

It covers this website, enquiries you send us, our dealings with customers and suppliers, and the personal information we handle in the course of providing and supporting the OPFCC Manager platform.

“Personal information” has the meaning it has in the Privacy Act 1988 (Cth): information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded.

Our commitment

We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth), and we apply this policy to everything we do regardless of whether the Act obliges us to. A forecourt is not the place to take a narrow view of the question.

We also apply the Notifiable Data Breaches scheme to information we hold, and the Spam Act 2003 (Cth) to any message we send.

Two roles, and which one we are in

Most of the personal information that passes through OPFCC Manager at a forecourt is not ours. It belongs to the station operator running that site. They decide what is collected there and why; we hold and process it on their behalf, under their instructions, as the supplier of the platform and its support. Their own privacy policy governs it, and their trading name and ABN are the ones on the receipt.

So if you fuelled at a station running OPFCC Manager and want to know how your information is used, the operator of that station is the place to start. Tell us and we will put you in touch, and we act on any request the operator asks us to carry out.

Where we are acting for ourselves — this website, the enquiries sent to us, our own customers, suppliers and staff — the rest of this policy is a description of what we do.

What this website collects

Nothing is asked of you to read this site. There is no account, no login and no sign-in anywhere on it.

  • There is no analytics, no advertising or tracking pixel, no session recording and no third-party script on any page. Fonts, images and code are served from this site itself, so reading it does not report your visit to another company.
  • We do not use cookies. The one thing the site stores in your browser is your light-or-dark theme choice, under the key fz-theme in local storage. It stays on your device, is never sent to us, is not personal information, and clearing your browser data removes it.
  • Like any website, the web server that delivers these pages may keep ordinary technical logs of requests — network address, date and time, the page asked for and the browser making the request — used to run and secure the site and diagnose faults. We do not use them to build a profile of you, and we do not combine them with anything else.

What we collect when you enquire

The contact form asks for your name, your station or business name, the number of sites you run, your pump controller brand, your email address, your phone number, and your message. Your name, your business name and your email address are required; the rest are optional and the form works without them.

When you send it, the enquiry is delivered to our mailbox by email and kept there and in our record of the enquiry. Two other things happen at the same time, and you should know about both:

  • The relay records the network address the enquiry came from, so it can apply a limit on how many enquiries one address can send in a period. That is what stops the form being used to flood the inbox.
  • It writes a line to its own log noting that an enquiry was delivered, with the sender’s email address and business name, so a failure to deliver one can be found and fixed rather than silently losing a customer.

Please do not put sensitive information — health, biometric, racial or ethnic origin, political, religious or similar — into the form. We do not ask for it, do not need it, and would rather not hold it.

What OPFCC Manager collects at a forecourt

This is the information handled inside an installed site. It is collected for the station operator, held in that site’s own database, and used to authorise a pump, take the payment, issue the refund, produce the receipt and keep the operator’s records straight.

From a customer at the pump

  • The site and pump scanned, the grade chosen, the limit set, the fuel actually delivered, the rate and the amount charged.
  • A payment token, the card scheme and a masked card number returned by the payment gateway — never a full card number.
  • The email address given for the receipt, and the language and theme chosen at the pump.
  • Session and device signals used to score the risk of the transaction and route it to allow, challenge or block.
  • Where the operator has switched geofencing on, the approximate position of the device at the moment a pump is requested.

On a fleet or account sale

  • The fleet card or account presented, and the result of the hot-card check run before the sale is accepted.
  • The odometer reading entered at the pump, and the vehicle or account the sale is billed to.

From the operator’s back-office users

  • Name, work email address and phone number, and which sites that person may reach.
  • Login credentials and the two-factor codes sent to their email address, with a record of login attempts and lockouts.
  • An audit record of the changes they make — a price change, a refund or a site setting is recorded against the person who made it and the time they made it.

Card details

Card details are entered into a payment form supplied by the payment gateway and are tokenised in the customer’s own browser. They do not pass through, and are not stored on, the station’s server, and they are not stored by us.

What the platform keeps is what the gateway hands back: a token, the card scheme, a masked number and the outcome of the transaction. That is enough to email a receipt, issue the automatic refund when the nozzle goes back, and reconcile the day — and it is not enough to charge a card anywhere else.

The gateway is a separate company with its own terms and its own privacy policy, and its handling of card data is governed by them. This is a description of how the platform works rather than a claim to a certification it does not hold.

Location, when it is used at all

Geofencing is optional and off unless a station operator turns it on for a particular site. Where it is on, the customer’s browser asks their permission before any position is read, and declining means no location is collected — that is the browser’s own control, not ours.

  • A position is used once, at the moment a pump is requested, to check the phone is on that forecourt before the controller is asked to authorise anything.
  • It is not a movement history, is not used for marketing, and is not shared with anyone.

How we collect it

  • Directly from you — the contact form, an email, a phone call, a site walkthrough, the back office, or the payment page at the pump.
  • From a station operator, where they give us information about their staff, their site or their customers so we can install and support it.
  • From the payment gateway or fleet card provider, in the result they return when a transaction is processed.

If we ever collect your personal information from someone other than you, we take reasonable steps to make sure you know we hold it and why, unless the Act says otherwise.

What we use it for

  • Answering your enquiry, arranging a site walkthrough, running the site survey and preparing a quote against your forecourt.
  • Installing, commissioning, supporting, maintaining and improving an OPFCC Manager site, and investigating faults on it.
  • Authorising a pump, taking the payment, issuing the automatic refund and emailing the receipt.
  • Detecting and preventing fraud, drive-offs and misuse — card blacklist counters, device risk scoring, optional geofencing, rate limits and login lockouts.
  • Producing the operator’s transaction history, audit trail, fuel sales reporting and GST-correct documents.
  • Keeping the platform and our own systems secure, and keeping the backups that let a site be restored.
  • Running our business — invoicing, accounts, insurance and keeping in touch with a customer about the service they have.
  • Meeting our obligations under Australian tax, consumer, privacy and record-keeping law.

We do not use personal information for any purpose you would not reasonably expect from the list above, unless you have agreed to it or the law requires it.

Marketing, and what we will not do

We do not run marketing lists, we do not send bulk email, and we do not sell, rent, trade or otherwise disclose personal information to anyone for their own marketing.

If we contact you it is about an enquiry you sent us or a service you have with us. You can tell us to stop at any time and we will, and every message we send carries a way to do that.

Who we disclose it to

We disclose personal information only where it is needed to do the things listed above:

  • The payment gateway that processes the card payment, and the fleet card or account provider where the customer pays that way.
  • The station operator whose forecourt the transaction happened at — the records of their site are theirs.
  • Our email provider, which delivers enquiries to us and receipts to customers.
  • The IT, hosting and infrastructure providers who help us run, monitor and back up the platform, under confidentiality obligations and only as far as their work requires.
  • Our professional advisers — accountants, lawyers and insurers — where they genuinely need it.
  • Anyone you ask us to disclose it to, or have consented to.
  • Anyone we are required or authorised to disclose it to by law — a court order, a subpoena, a regulator, or where it is needed to prevent a serious threat to someone’s life, health or safety.

Nobody else. We do not sell personal information, and we do not disclose it to a third party so that they can market to you.

Whether anything goes overseas

OPFCC Manager runs on hardware at each station. The payment and pump bridge are on the forecourt in Australia rather than in a distant data centre, which is why a dropped internet link does not close the site — and it means the transaction data of a site sits at that site.

Some of the providers we use to run our own business — email, IT support and infrastructure — are global companies that may store, back up or access information outside Australia, including in the United States and Europe. Before we disclose personal information to an overseas recipient we take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles.

If we ever need to send your personal information overseas for a reason not described here, we will tell you first.

How we keep it secure

Security on an unattended forecourt is the product, not a policy paragraph, so most of this is the same list the Security page carries:

  • The back office is reached with a password plus a two-factor code sent by email, on short-lived sessions with rotating refresh tokens, with login rate-limiting and lockout, and a second passcode on the settings that can take a site down — checked on the server rather than hidden in the browser.
  • Each site has its own database and its own scoped credentials. Nothing at one station can read another.
  • Station-owned hardware can be delivered as a sealed appliance with an encrypted disk, no local logins and remote support access only.
  • Deployment is containerised, with automated nightly database backups and alerting on the parts that matter.
  • Card numbers are never in the system, so they are not there to be taken.
  • Access is limited to the people who need it to do their job, and what they change is written to the audit trail.

No system is perfectly secure, and information sent over the internet always carries some risk. We do not pretend otherwise, and we do not guarantee it — but if something goes wrong we act on it, as the next section describes.

If something goes wrong

We investigate any suspected loss of, or unauthorised access to or disclosure of, personal information we hold. Where a breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we notify the individuals at risk and the Office of the Australian Information Commissioner as the Privacy Act requires.

Where the information involved is held for a station operator, we tell that operator promptly, with what we know and when we knew it, so they can meet their own obligations to their customers.

How long we keep it

  • Enquiries: kept while we are dealing with you and for a reasonable period afterwards, then deleted. Ask us and we will delete yours sooner.
  • Transaction and audit records at a site: kept for as long as the operator needs them for reconciliation, refunds, disputes and their own legal obligations. Records that support a tax position generally have to be kept for at least five years under Australian law.
  • Backups: overwritten on their own cycle, so information deleted from a live system can persist in a backup for a short period before it ages out.
  • Rate-limit records: held in memory only, for the length of the window, and gone when the relay restarts.

When we no longer need personal information and are not required by law to keep it, we destroy it or de-identify it.

Dealing with us anonymously

You can read every page of this website without telling us anything at all, and you can call or email us with a general question about the platform without giving your name.

Some things cannot be done anonymously: a site survey, a quote, an installation or support for a live site all require us to know who you are and where the forecourt is. A customer at the pump creates no account and gives no name — the email address the receipt goes to is the only contact detail asked for.

Getting a copy, and correcting it

You can ask for a copy of the personal information we hold about you, and you can ask us to correct anything in it that is wrong, out of date, incomplete or misleading. Email info@onepieceauto.com.au and tell us what you want.

  • We will ask you to verify your identity first, then respond within a reasonable time — normally within 30 days.
  • There is no charge for making a request. If supplying the information in a particular form has a real cost, we will tell you what it is before we do it, and it will never be a charge for the request itself.
  • If we cannot give you access, or cannot make a correction, we will tell you why in writing and how to take it further. Those grounds are the ones the Privacy Act sets out, not ones of our own.
  • If the information is held for a station operator, we will refer you to them or act on their instruction, and we will say which of the two we have done.

Complaints

If you think we have mishandled your personal information, tell us first. Email info@onepieceauto.com.au or write to us at the address below, with enough detail for us to work out what happened. We will acknowledge it, investigate it, and respond in writing — normally within 30 days.

If you are not satisfied with our response, you can take the complaint to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.

Changes to this policy

We update this policy as the platform and our practices change. The version published here is always the current one, and the date at the head of the page is the date it last changed. Where a change materially affects a live site, we tell that operator directly rather than leaving them to notice it here.

How to contact us about privacy

Privacy questions, access requests, corrections and complaints all reach the same people:

Post
One Piece Automation, Seaford, VIC 3198, Australia
ABN
50 690 467 577
Hours
Mon–Fri, 5 am – 4 pm. Closed weekends.