Privacy and Cookies Policy

Last updated: April 2026

1. Introduction

1.1 We are committed to safeguarding the privacy of our website visitors and customers. This policy explains how we handle your personal data.

1.2 This policy applies where we are acting as a data controller with respect to your personal data — in other words, where we determine the purposes and means of the processing of that personal data.

1.3 We use cookies on our website. Where cookies are not strictly necessary for the provision of our website and services, we will ask for your consent when you first visit.

1.4 In this policy, "we", "us", and "our" refer to BOMExplorer.

2. How We Use Your Personal Data

2.1 Categories of data and purposes

Usage data. We may process data about your use of our website and services, including your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views, and navigation paths. This data is processed for the purposes of analysing and improving the use of the website and services. The legal basis for this processing is our legitimate interests, namely monitoring and improving our website and services.

Account data. We may process your account data, including your name and email address. This data is processed for the purposes of operating our website, providing our services, ensuring the security of our website and services, maintaining back-ups of our databases, and communicating with you. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business.

BOM and project data. We process the BOM files, project data, and matched component results that you upload or generate within the service. This data is processed solely for the purpose of providing the BOMExplorer service to you. We do not use your BOM data for any other purpose, including training AI models, without your explicit consent. The legal basis for this processing is the performance of a contract between you and us.

Enquiry data. We may process information contained in any enquiry you submit to us regarding our services. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business.

Transaction data. We may process information relating to purchases of subscriptions or AI tokens, including your contact details and the transaction details. Transaction data is processed for the purpose of supplying the purchased services and keeping proper records of those transactions. The legal basis for this processing is the performance of a contract between you and us.

Notification data. We may process information that you provide for the purpose of subscribing to email notifications or product updates. The legal basis for this processing is our legitimate interests, namely communicating with our customers.

Communication data. We may process information contained in any communication that you send to us, including the communication content and metadata. The legal basis for this processing is our legitimate interests, namely communicating with website visitors and customers and the proper administration of our website and business.

2.2 Additional processing

We may also process any of your personal data where necessary for:

  • the establishment, exercise, or defence of legal claims;
  • compliance with a legal obligation to which we are subject; or
  • the protection of your vital interests or the vital interests of another natural person.

3. Providing Your Personal Data to Others

3.1 We may disclose your personal data to any member of our group of companies insofar as reasonably necessary for the purposes set out in this policy.

3.2 We may disclose your personal data to our insurers and/or professional advisers insofar as reasonably necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, obtaining professional advice, or the establishment, exercise, or defence of legal claims.

3.3 Your personal data held in our website database will be stored on the servers of our hosting services providers.

3.4 Financial transactions relating to our website and services are handled by our payment services provider, Paddle. We will share transaction data with Paddle only to the extent necessary for the purposes of processing your payments, refunding such payments, and dealing with complaints and queries relating to such payments and refunds. You can find information about Paddle's privacy policies and practices at paddle.com.

3.5 We do not sell your personal data to third parties.

3.6 In addition to the specific disclosures set out in this section, we may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.

4. International Transfers of Your Personal Data

4.1 Our operations are based in Australia.

4.2 Hosting facilities for our website may be situated in the United States of America or the European Union.

4.3 Third-party service providers we use (including payment processing and analytics) may process data in jurisdictions outside Australia. Where this occurs, we take steps to ensure that appropriate safeguards are in place.

4.4 You acknowledge that personal data that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent the use or misuse of such personal data by others.

5. Retaining and Deleting Personal Data

5.1 Personal data that we process for any purpose shall not be kept for longer than is necessary for that purpose.

5.2 We will retain your personal data as follows:

  • Usage data — retained for a minimum period of 3 years following collection, and for a maximum period of 10 years following that date.
  • Account data — retained for a minimum period of 1 month following the date of closure of the relevant account, and for a maximum period of 1 year following that date.
  • BOM and project data — retained for the duration of your account, and deleted within 90 days of account closure upon request.
  • Enquiry data — retained for a minimum period of 1 year following the date of the enquiry, and for a maximum period of 10 years following that date.
  • Transaction data — retained for a minimum period of 1 year following the date of the transaction, and for a maximum period of 10 years following that date, in accordance with applicable tax and financial record-keeping requirements.
  • Notification data — retained for a minimum period of 1 month following the date that we are instructed to cease sending the notifications, and for a maximum period of 1 year following that date.
  • Communication data — retained for a minimum period of 1 year following the date of the communication, and for a maximum period of 10 years following that date.

5.3 Notwithstanding the above, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.

6. Security of Personal Data

6.1 We will take appropriate technical and organisational precautions to secure your personal data and to prevent the loss, misuse, or alteration of your personal data.

6.2 All personal data is stored on secure servers. Passwords are stored in hashed form. We do not store payment card details; these are handled directly by Paddle.

6.3 Data transmitted between your web browser and our web server is protected using TLS encryption.

6.4 You acknowledge that the transmission of unencrypted data over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.

6.5 You are responsible for keeping the password you use for accessing our service confidential. We will not ask you for your password except when you log in.

7. Your Rights

7.1 Under applicable data protection law, you have the following principal rights:

  • Right of access — you can ask for copies of your personal data.
  • Right to rectification — you can ask us to rectify inaccurate personal data and to complete incomplete personal data.
  • Right to erasure — you can ask us to erase your personal data in certain circumstances.
  • Right to restrict processing — you can ask us to restrict the processing of your personal data in certain circumstances.
  • Right to object to processing — you can object to the processing of your personal data in certain circumstances.
  • Right to data portability — you can ask that we transfer your personal data to another organisation or to you.
  • Right to complain to a supervisory authority — you can complain about our processing of your personal data to a relevant data protection authority.
  • Right to withdraw consent — where the legal basis for processing is consent, you can withdraw that consent at any time.

7.2 You can access and export your account data from your account settings page. You can request deletion of your account and associated data by contacting us using the contact form on our website.

7.3 To exercise any of these rights, please contact us using the contact form on our website.

8. Third-Party Websites

8.1 Our website includes hyperlinks to third-party websites, including component distributors and providers.

8.2 We have no control over, and are not responsible for, the privacy policies and practices of third parties.

9. Personal Data of Children

9.1 Our website and services are targeted at persons over the age of 13.

9.2 If we have reason to believe that we hold personal data of a person under that age in our databases, we will delete that personal data.

10. Updating Information

Please let us know if the personal information that we hold about you needs to be corrected or updated by using the contact form on our website.

11. About Cookies

11.1 A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.

11.2 Cookies may be either "persistent" (remaining valid until their expiry date unless deleted) or "session" cookies (expiring when the web browser is closed).

11.3 Cookies do not typically contain information that personally identifies a user, but personal data that we store about you may be linked to the information stored in and obtained from cookies.

12. Cookies That We Use

We use cookies for the following purposes:

  • Authentication and session management — to identify you when you visit our website and as you navigate, and to maintain your logged-in session.
  • Preferences — to store information about your preferences and to personalise the website for you.
  • Security — as an element of the security measures used to protect user accounts, including preventing fraudulent use of login credentials.
  • Analysis — to help us analyse the use and performance of our website and services.
  • Cookie consent — to store your preferences in relation to the use of cookies.

13. Cookies Used by Our Service Providers

13.1 Our service providers may use cookies, and those cookies may be stored on your computer when you visit our website.

13.2 We use analytics tools to gather information about the use of our website. The information gathered is used to create reports about website usage and to improve our service.

14. Managing Cookies

14.1 Most browsers allow you to refuse to accept cookies and to delete cookies. You can obtain up-to-date information about blocking and deleting cookies via the help documentation for your browser:

14.2 Blocking all cookies will have a negative impact upon the usability of many websites. If you block cookies, you will not be able to use all the features of our service.

15. Amendments

15.1 We may update this policy from time to time by publishing a new version on our website.

15.2 We may notify you of significant changes to this policy by email.

15.3 You should check this page occasionally to ensure you are aware of any changes.

16. Our Details

This website and service is owned and operated by BOMExplorer.

You can contact us using the contact form on our website.