Roper Digital Group
Privacy Policy for Capstone Ready
Effective date: 7 August 2026
This policy explains what personal information Roper Digital Group collects for Capstone Ready and the Sparky's Ready family, how it is used, who can access it and how deletion requests are handled.
Who we are and who this covers
Roper Digital Group operates Capstone Ready as part of the Sparky's Ready family. This Privacy Policy applies to Capstone Ready, Sparky's Ready, AM2 Ready, Journeyman Ready, Red Seal Ready, EWRB Ready, SOLAS Ready, Sparky Pro, the Admin Portal, the Learn Portal, the RTO Portal and related support websites.
Our role and organisation responsibilities
Capstone Ready is built for apprenticeship profiling, employer/approver review, internal messages, learning support and portal administration. Apprentices, employers, supervisors, managers, assessors, teachers and RTO users must only enter information they are authorised to use. Employers, schools, RTOs and other organisations using the service remain responsible for giving any workplace, learner or guardian notices that apply to their own collection and use of records.
Data we collect
- Identity, account and authentication data, including name, email address, selected app mode, target app, Sign in with Apple account identifier, Supabase user ID, session state and support contact details.
- Organisation and role data, including employer, apprentice, supervisor, manager, approver, assessor, teacher or RTO details, company names, ABN or organisation details, addresses, role permissions and team relationships.
- Training and profiling data, including job sites, work dates, hours, units of competency, supervision details, answers, notes, assessment progress, approval decisions, signatures and audit history.
- Evidence and user content, including photos, videos, files, documents, generated profile-card PDFs, portfolio/archive records, internal message content and attachments you choose to add.
- Trusted-device and security data, including device name, device model, public device key, trusted-device status, pairing session metadata, last-seen time, revoked status, audit logs and security events. Private device keys stay on the device where the operating system allows it and are not uploaded.
- Notification and messaging data, including push notification tokens, delivery state, notification status, message sender/recipient details, read state and delete state.
- Portal, subscription and administration data, including organisation membership, access approvals, learner consent, subscription status, invoice or payment reference details, content publishing activity and admin audit records. We do not intentionally store full card numbers.
- Diagnostics and analytics, including crash reports, performance information, app version, target, environment and product interaction events used to keep the app reliable. These are not used for third-party advertising or cross-app tracking.
- Website and portal technical data, including browser storage, session state, IP address, device/browser information and hosting logs needed to run secure web portals.
How we collect data
- Directly from you when you sign in, select a mode, fill in forms, submit cards, upload evidence, send messages or manage your account.
- From authorised employers, supervisors, managers, assessors, teachers or RTO users when they approve, reject, amend, upload or administer records connected to your organisation or training pathway.
- Automatically from the app and portals when they create audit events, push notification records, device trust records, profile-card PDFs, sync events, diagnostics or security logs.
- From service providers that run the app, including Apple services, Supabase, push notification delivery, crash reporting, payment providers where used and website hosting.
Why we use data
- To run onboarding, account access, QR trusted-device pairing, internal messaging, push notifications, profiling cards, approvals, PDF generation and admin/RTO review.
- To keep records accurate for apprentices, employers, supervisors, managers, assessors, teachers and RTO users who are authorised to work together.
- To upload approved profile-card PDFs and related metadata to the authorised admin or RTO portal where that workflow is enabled.
- To provide support, troubleshoot issues, secure accounts, prevent misuse, maintain audit trails and meet legal, training, compliance or record-keeping obligations.
- To manage subscriptions, access requests, billing references and portal entitlements where those features are used.
- To improve reliability and performance using limited analytics and diagnostic information that avoids raw evidence text, signatures, private URLs, tokens and message contents.
Sharing and access
We do not sell personal data and we do not use it for third-party advertising tracking. Data may be visible to users you are paired with or connected to in the same approved organisation, such as apprentices, employers, supervisors, managers, assessors, teachers, RTO users and authorised admin users. We also use service providers such as Supabase, Apple, APNs/push notification services, Sentry crash reporting, Bluehost or other website hosting providers, and payment providers where subscription features are used. We may disclose information where required by law, where needed to protect users or the service, or where needed to preserve training record integrity.
Storage, security and retention
We use HTTPS, Supabase access controls, role-based portal access, audit events, trusted-device controls and platform security features such as Keychain/Secure Enclave where available. QR pairing tokens are short-lived, single-use and stored server-side as hashes rather than raw secrets. Approved training records, generated PDFs, signatures, audit events and billing records may need to be retained for evidence integrity, training administration, legal, tax, accounting, dispute or compliance reasons. Other account data is kept only as long as needed for the service, support, security and lawful record keeping.
Account deletion and choices
You can start account deletion inside the app from Account settings. Deletion is intended to remove the account and app-owned personal data that is not legally, operationally or contractually required to preserve training evidence, audit integrity, approved records or payment/accounting records. If you used Sign in with Apple, we revoke Apple tokens where available as part of account deletion. You can also contact us to request access, correction or deletion of your data, to revoke device trust, or to ask how a training record is retained.
Notifications
Push notifications are used for app functionality such as pairing requests, profiling approvals, sent-back cards, internal messages and important account events. You can control notification permissions in iOS settings. Turning off notifications may stop timely alerts, but in-app notification records may still appear when you open the app.
Cookies, browser storage and third-party links
Our websites and portals may use browser storage, session cookies or similar local storage to keep you signed in, remember portal state and protect the service. We do not use advertising cookies in the app. The service may link to third-party websites or services; their privacy practices are controlled by those third parties.
Children, learners and supervised users
The service is designed for trade training and workplace/RTO workflows. If a learner is under the age required to consent in their location, the employer, school, RTO or guardian responsible for the training arrangement must make sure appropriate permission is in place before the learner uses the service.
International processing
Service providers may process or store data in Australia and countries other than your own. We take reasonable steps to use providers with appropriate security and privacy protections for the data they process for us.
Access, correction and complaints
You can ask to access or correct personal information we hold about you, or make a privacy complaint, by contacting support@sparkysready.com or support@capstoneready.com.au. We will respond as soon as reasonably practicable. If you are not satisfied with our response and Australian privacy law applies, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
Updates
We may update this policy when the app, portals, providers, laws or business processes change. The latest version will be published on our website and linked from the app.