• Mini check
  • What it becomes
  • Early access
  • FAQ
Join waitlist

Legal

Privacy Policy

Version 2026-07-30 · Effective 30 July 2026

Flyway Privacy Policy

Applies to: the Flyway website at flyway.au, including the waitlist.

This is our interim policy, and it covers one thing: the flyway.au website and its waitlist. The Flyway app has not launched. There are no accounts, no document vault and no agent portal yet, so nothing in this policy describes them — when those ship, we will publish a fuller policy that does, and we will tell waitlist members before it takes effect. This version was written in-house and is with external privacy counsel for review; we would rather publish an honest, narrow policy today than leave the waitlist running with none at all. Some of the fixed deletion timeframes we intend to commit to are still being settled, and are marked as such below.

Flyway is operated by Excelsior Technology Pty Ltd (ABN 99 689 798 829) ("Flyway", "we", "us"). We are an APP entity bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy is our APP privacy policy under APP 1.

Flyway provides information about Australian visa processes — not migration advice. Under the Migration Act 1958 (Cth) ss 276 and 280, immigration assistance may only be given by registered migration agents, Australian legal practitioners, and certain persons exempted by section 280. Nothing in Flyway is advice about your situation, and this policy does not change that.


1. This policy at a glance

We follow the OAIC's layered-notice approach: the tables below are the short version; the numbered sections that follow are the full version.

1.1 What we collect now (website + waitlist)

WhatWhyWho sees itHow long
Email addressTo hold your waitlist place, send one confirmation email, and send launch updates — the consent box must be ticked to join (section 6)Flyway; our email provider (Resend, US); our database hostUntil you convert your place into an account, or ask us to remove you — see section 14
The visa details you pick from the dropdowns: the visa you hold now (required); the pathway you are heading for, where you are in that journey, and what you are most stuck on or need most (all optional)To understand which visa situations and problems are most common, so we build the right things first, and to decide who to invite into the beta and into user-research conversationsFlyway (grouped for analysis; not published)Same as above
Marketing consent checkbox stateLegal basis to email you marketing (Spam Act 2003)FlywayKept as a consent record
Campaign attribution (UTM parameters, referrer, entry source) and A/B test variantTo know which channels work and which page version convertsFlyway; GrowthBook (experimentation, US)Same as waitlist entry
Bot-check result (Cloudflare Turnstile) and your IP addressTo block automated abuse. IP is used transiently for rate limiting and bot verification and is not stored in our databaseCloudflare (global)Verdict stored with the entry; IP not stored by us
A first-party cookie (fw_vid)Consistent A/B page assignmentFlywayCookie lifetime
Analytics events (pages viewed, interactions)To improve the websiteGoogle Analytics 4 (US), Umami (US)Per analytics tool settings — see section 4

1.2 Key promises

  • The waitlist database is hosted in Australia (Sydney region) — see section 12 for where each provider holds data. Some service providers we use are overseas — mainly the United States — and section 12 lists every one.
  • We never sell personal information, and we do not run advertising on the website.
  • You can ask us to delete your waitlist entry at any time, and we will (section 14).
  • Marketing email requires your express consent, with one-click unsubscribe. Note that right now, joining the waitlist and consenting to waitlist emails are the same act — the consent box must be ticked to join (section 6).

2. Who we are and what this policy covers

Excelsior Technology Pty Ltd operates the Flyway website at flyway.au. Right now, the website does one thing with personal information: it runs a waitlist for the upcoming Flyway app, plus standard website analytics. This policy describes that completely, and nothing more.

Contact for privacy matters:
Privacy Officer, Excelsior Technology Pty Ltd
Email: contact@xcelsior.co
Post: 8 Parramatta Square, Parramatta NSW 2150

3. What we collect on the website today (APP 3, APP 5)

When you join the waitlist we collect, with your knowledge, directly from you:

  • Email address (required). Stored normalised (lowercase) and used to: confirm your place, tell you how many people are on the same pathway if you picked one, and — because the consent box must be ticked to join — send you the product updates, research invitations and beta invitation you agreed to. If you submit an email that is already on the list, we simply do nothing new; we do not reveal whether an email is already registered.

  • Your visa details, chosen from fixed dropdown lists — there is no free-text box on the form, so you cannot accidentally tell us more than you meant to:

    • the visa you currently hold (student 500, temporary graduate 485, a bridging visa, offshore, or not sure) — required;
    • the pathway you are heading for (485 to PR, 189, 190, 491, employer sponsored, or not sure) — optional;
    • where you are in that journey (researching, preparing documents, submitted EOI, lodged, waiting) — optional;
    • what you are most stuck on, or what you want from Flyway most — optional.

    If you skip an optional dropdown we store nothing for it; we do not guess a value to fill the gap. These answers tell us which situations to build for first. They relate to your migration circumstances, and we treat them carefully, but they are not "sensitive information" as defined in s 6 of the Privacy Act.

  • Marketing consent: the state of the consent checkbox. Marketing email is sent only if this was expressly ticked (see section 6).

  • Attribution data: UTM campaign parameters, the referring page, and the entry point label — so we know which channel brought you.

  • A/B test variant: which version of the page you saw, derived on our server from a first-party visitor cookie (fw_vid).

  • Bot-check outcome: we use Cloudflare Turnstile to verify you are human. We pass the Turnstile token and your IP address to Cloudflare for verification and use the IP for rate limiting. We do not store your IP address in our waitlist database — only the pass/fail verdict. Our forms also include an invisible honeypot field; submissions that fill it are discarded entirely and nothing is stored.

We collect this information directly from you when you submit the form (APP 3.6; collected by lawful and fair means, APP 3.5), and this policy plus the notice at the form is our APP 5 collection notice for it.

After you join, we send one confirmation email (via Resend). If you told us which pathway you are heading for, it includes the number of people on that pathway — an aggregate about the group you just joined, not information about any other individual. If you skipped that question, the email simply omits the line rather than guessing a group for you. It carries standards-compliant one-click unsubscribe (RFC 8058).

4. Website cookies, analytics and tracking

The website currently uses:

ToolWhat it doesData involvedWhere
fw_vid cookie (first party)Gives your browser a random visitor ID so A/B page assignment is consistentRandom identifier; no name or emailYour browser + our server
Google Analytics 4Page and event analyticsPseudonymous identifiers, pages viewed, device/browser dataGoogle (US/global)
UmamiPrivacy-focused page analytics. No cookies; IP addresses are hashed in memory and discardedAggregate page countsUmami Cloud — Umami Software, Inc. (United States); its servers are in the United States and the European Union
Cloudflare TurnstileBot protection on the waitlist formToken, IP address, browser signalsCloudflare (global)
GrowthBookA/B experiment assignment and conversion analysis, run server-sideHashed visitor ID for bucketing; experiment resultsGrowthBook Cloud (US) — see section 12 for its database access scope

We do not run third-party advertising trackers on the website, and we do not use website data to build advertising profiles. We do not currently run session-replay or heatmap recording on the website. If we turn one on, we will update this policy before it starts recording.

You can control cookies through your browser settings. Blocking the fw_vid cookie means A/B assignment resets between visits; blocking analytics does not affect the waitlist.

5. How we use waitlist information (APP 6)

We use the information in section 3 only to:

  1. hold your place and confirm it (primary purpose of collection);
  2. understand demand — how many people hold which visa, are heading down which pathway, are at which stage, and are stuck on what — to prioritise what we build;
  3. decide who to invite first, both into the beta and into user-research conversations (an invitation is only ever an invitation; declining costs you nothing and does not affect your place);
  4. attribute signups to marketing channels and choose between page variants;
  5. prevent spam and abuse of the form;
  6. send you product updates and launch marketing only with your express consent (section 6);
  7. at app launch, connect your waitlist entry to your new account if you create one with the same email — so we stop sending you waitlist emails, keep your answers with your profile, and can attribute the conversion to its channel.

We do not publish what you tell us. An earlier version of this website published an anonymous, aggregated "map" of waitlist journeys, and asked for your consent to be included in it. That feature no longer exists and that consent is no longer sought. Your answers are used internally, in grouped form, to decide what we build.

We do not use waitlist information for any unrelated secondary purpose, and we do not disclose it except to the service providers in section 12 or as required by law.

6. Direct marketing and email (APP 7, Spam Act 2003)

  • We only send commercial electronic messages with your express consent — the marketing checkbox is unticked by default and must be actively ticked (Spam Act 2003 (Cth) s 16).
  • Plain disclosure: right now, joining the waitlist and agreeing to our emails are the same act — the consent box must be ticked to join. If you do not want emails, do not join; you can unsubscribe at any time afterwards.
  • One tick covers three things, and they are all email: product updates, research invitations, and your beta invitation. It does not authorise anything else — it is not consent to publish your answers, and there is nothing to publish them to.
  • Where the Spam Act 2003 applies to a message, it governs in place of APP 7 (APP 7.8); we honour the APP 7.6 source-request and opt-out standards across all channels regardless.
  • Every marketing email identifies us as the sender and includes a functional unsubscribe, including one-click unsubscribe headers (RFC 8058). Unsubscribing is free and takes effect promptly.
  • The single waitlist confirmation email is sent to everyone who joins, because it is the service message that confirms the thing you just asked for; it still carries unsubscribe headers.
  • You may also opt out of marketing at any time by contacting us (section 22), and you may ask us where we got your information (APP 7.6 — the answer will be: from you, at the waitlist form).

Sections 7 to 11 are not published yet. They describe the Flyway app — accounts, the eligibility quiz, journey tracking, the document vault and sharing with a migration agent, the community forum, in-app advertising and notifications — and none of that exists today. The numbering is left as it is so that the sections keep the same numbers when the app launches and they come into force.

12. Who we disclose personal information to (APP 6, APP 8)

We disclose personal information only to: (a) service providers that process it for us under contract; and (b) where required or authorised by law (e.g. subpoena, tribunal or regulator notice). We never sell personal information.

12.1 Where your data lives

Primary storage is hosted in Australia (Sydney region: ap-southeast-2): the website runs on AWS in Sydney, and the waitlist database runs on an interim managed database host (Supabase) provisioned in the same Sydney (ap-southeast-2) region, pending migration into our own AWS environment. Content is delivered through a global CDN, which means data in transit passes through edge servers outside Australia.

12.2 Service providers — including overseas recipients (APP 8)

Several providers are based overseas, mainly in the United States. Before disclosing personal information overseas we take reasonable steps, including contractual safeguards, to ensure the recipient handles it consistently with the APPs (APP 8.1).

ProviderServicePersonal information involvedLocation
AWSWebsite hosting and computeWebsite trafficAustralia (Sydney); global CDN edges in transit
SupabaseInterim waitlist database, pending migration to AWSWaitlist entriesAustralia (Sydney, ap-southeast-2)
ResendTransactional and (consented) marketing emailEmail address, pathway label, group sizeUnited States
CloudflareTurnstile bot protectionVerification token, IP address, browser signalsGlobal network (US company)
Google Analytics 4Website analyticsPseudonymous IDs, page events, device dataUnited States / global
UmamiPrivacy-focused analyticsAggregate page statistics; hashed transient IPsUmami Cloud — Umami Software, Inc. (US); servers in the US and the EU
GrowthBookA/B experimentationHashed visitor IDs; GrowthBook Cloud connects to our database as a data source to compute experiment results — its access is for aggregate statistical analysisUnited States

Our website content management system runs on our own infrastructure and holds editorial content only — no personal information.

12.3 Government, courts and regulators

We disclose personal information where required or authorised by Australian law — for example under a subpoena, a tribunal direction, or a notice from a regulator such as the Office of the Migration Agents Registration Authority. Where such an obligation applies, it can also pause deletion (section 14.4).

13. How we keep information secure (APP 11.1)

What we do:

  • Encryption in transit (TLS) everywhere, and encryption at rest for the waitlist database.
  • Staff access to the waitlist database is role-limited, and internal admin surfaces are network-restricted.
  • Anti-abuse controls (bot verification, rate limiting) on public forms.

What we deliberately do not claim:

  • No system is impenetrable. We describe our data-breach response in section 17.

We review our security posture as the product grows, and we harden it before each expansion of what we store.

14. How long we keep your waitlist entry — and how to have it deleted (APP 11.2)

Australian privacy law works differently from the European "right to erasure": there is no general right to demand erasure on request. Instead, APP 11.2 places the duty on us to proactively destroy or de-identify personal information once we no longer need it for a permitted purpose. We take that duty seriously. This section explains, in plain language and without overclaiming, how retention and deletion actually work.

14.1 What we keep, and for how long

DataRetention approach
Your waitlist entry (email, the visa details you picked, consent record, attribution)Kept while the waitlist is running, so we can send you what you signed up for and understand who is waiting. We destroy or de-identify entries once we no longer need them — at the latest, after the app launches and the waitlist has served its purpose. We are settling the exact periods with our privacy lawyer and will state them here once they are fixed.
If you unsubscribeYou stop receiving email straight away. We keep a minimal record that you unsubscribed, so we do not email you again by mistake, and delete the rest of your entry.
If you ask us to delete your entryWe delete it — see 14.5. Right now this is done by hand on request rather than by an automated schedule, which is exactly why the timeframes above are not yet stated as fixed numbers.
System backupsShort-cycle backups for disaster recovery, so a deleted entry can persist in backup media briefly until that cycle rolls off.
Operational server logsShort retention, with personal information scrubbed.

What remains after we delete a waitlist entry. If you unsubscribe or ask us to delete your entry, we keep a minimal suppression record so that we do not email you again by mistake, plus counts that contain nothing identifying you. We do not keep a way to link those counts back to you. We do not use them to contact you or to re-create your entry.

We would rather publish this honestly than publish a schedule we cannot yet enforce automatically. When the automated destruction schedule ships, this section gets specific numbers and we will tell you before it changes.

14.2 and 14.3 are not published yet. They describe what happens when you delete a Flyway account and what survives that deletion. There are no accounts today.

14.4 Legal holds

Deletion is the default, not an absolute guarantee: if specific records are subject to a legal obligation — a subpoena, an Administrative Review Tribunal matter, or a regulator's notice — those records are placed under a legal hold and destruction is suspended for the required records until the hold lapses, after which normal destruction resumes.

14.5 You can still ask

Even though Australian law frames retention as our proactive duty, you can always ask us to delete your waitlist entry — email us at contact@xcelsior.co (section 22) and we will delete it and confirm when it is done. You can also ask what we still hold (APP 12), and complain if you think we kept something longer than this policy allows (section 18). Unsubscribing from our emails takes one click in any email we send and does not require you to contact anyone.

15. Automated tools (transparency about automated decision-making)

Some computer programs make decisions about people. New privacy rules (from 10 December 2026) require us to tell you when we use programs that make decisions that could reasonably be expected to significantly affect your rights or interests (the Privacy Act, as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth)). Ahead of that date, here is our position:

  • On the website today the only automated tools we run are the bot check on the waitlist form and the A/B assignment that decides which version of the page you see. Neither makes a decision about you.
  • We do not use fully automated decision-making that produces legal effects on users. If that ever changes, this policy will describe it before it happens.

16. Access and correction (APP 12, APP 13)

You may request access to the personal information we hold about you, and correction of anything inaccurate, out-of-date, incomplete, irrelevant or misleading.

  • Contact us (section 22). We will respond within a reasonable period — our target is 30 days. There is no charge for making a request; if giving access involves unusual cost we may charge a reasonable, non-excessive amount, and we will tell you before proceeding (APP 12.8).
  • If we refuse access or correction (the Privacy Act permits refusal in limited circumstances), we will give you written reasons and the complaint mechanisms available to you (APP 12.9, APP 13.3). If we refuse correction, you may ask us to attach a statement of your requested correction to the record (APP 13.4).

17. Data breaches (Notifiable Data Breaches scheme)

We are subject to the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If we suspect an eligible data breach — unauthorised access to or disclosure of personal information, or loss in circumstances where access is likely, and a reasonable person would conclude serious harm to affected individuals is likely — we will:

  1. contain the incident and assess it promptly (the Act allows up to 30 days for assessment; we aim to be far faster);
  2. if the breach is an eligible data breach, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, describing what happened, what information was involved, and what you should do (ss 26WK, 26WL);
  3. cooperate with any OAIC direction (s 26WR).

The waitlist holds far less than the app will, but an email address paired with a stated visa pathway is still information people can be harmed by, so we treat breach readiness as an engineering concern now rather than at launch.

18. Complaints (APP 1.2; OAIC pathway)

If you think we have mishandled your personal information or breached the APPs:

  1. Contact us first (section 22, or contact@xcelsior.co). Tell us what happened; we will acknowledge your complaint, investigate, and respond — our target is within 30 days.

  2. If you are not satisfied, you may complain to the regulator:

    Office of the Australian Information Commissioner (OAIC)
    Website: oaic.gov.au (online complaint form available)
    Phone: 1300 363 992
    Post: GPO Box 5288, Sydney NSW 2001

Nothing in this policy limits your rights under the Privacy Act, including rights arising from the 2024 amendments (such as the statutory cause of action for serious invasions of privacy, in force since June 2025).

19. Users outside Australia

Flyway is built for people migrating to Australia, and our services, storage and this policy are designed around Australian law. If you use Flyway from outside Australia (as many visa applicants do), your information is transferred to and handled in Australia — and by the providers in section 12 — as described in this policy. If the privacy law of your location (for example, the EU/UK GDPR) grants you additional rights, contact us and we will engage with your request in good faith; note that we do not currently offer region-specific storage.

20. Children and young people

Flyway is designed for people 16 and older managing their own migration, and the waitlist is not aimed at children. We do not knowingly collect waitlist details from anyone under 16; if you believe we have, tell us at contact@xcelsior.co and we will delete the entry. If you are 16 or 17, involve a parent or guardian. The minimum age for Flyway accounts will be set in our Terms of Service before the app launches.

21. Changes to this policy

This policy will be replaced by a fuller one when the Flyway app launches, and it may be revised sooner once our external privacy lawyer has finished reviewing it. Material changes are announced by email to waitlist members before they take effect, with the effective date shown at the top of this page. Earlier versions remain available on request. We will never use a policy update to retroactively authorise a practice this policy prohibited when your data was collected.

22. Contact us

Privacy Officer
Excelsior Technology Pty Ltd (ABN 99 689 798 829)
Email: contact@xcelsior.co
Post: 8 Parramatta Square, Parramatta NSW 2150

For anything about your migration case itself: Flyway cannot advise you. Speak to a registered migration agent — every registered agent in Australia is listed on the official OMARA register at mara.gov.au.

No one waits alone.

Flyway publishes community patterns and planning tools — not migration advice, and not an assessment of your eligibility. Community signals are anonymous aggregates with confidence labels. Screens shown are prototype builds with illustrative data. Always confirm current requirements with the Department of Home Affairs or an OMARA-registered agent.

  • X
  • Threads
  • Instagram
  • Facebook
  • Reddit
  • TikTok
  • YouTube
  • Bluesky
© 2026 Xcelsior Software · PrivacyCrafted with care by