Privacy
Privacy Policy
How we collect, use, store and protect your personal information. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
Who we are
This site is operated by Rinto Ismail trading as exit codes (ABN 58 712 323 217), an independent security practice based in Sydney, New South Wales. In this policy, "we" and "us" mean that business.
We operate three public surfaces: this website at exit.codes, the free tools at
tools.exit.codes, and the enquiry forms at onboard.exit.codes. This
policy covers all three, and the personal information we handle when working with clients.
What we collect
When you visit this website
We use Google Analytics, loaded through Google Tag Manager, to understand which pages people read. That records things like the pages you view, roughly where you are, and what kind of device and browser you use. Our content delivery provider, Cloudflare, also records standard request logs including your IP address, which it uses to serve the site and to block abuse.
We do not use advertising or cross-site tracking, and we do not sell or rent personal information to anyone.
When you send us an enquiry
Our enquiry forms ask for your business or trading name, a short description of what you do, how long you have been operating, your name and your email address. Optionally you may give your ABN, a phone number, your preferred way of being contacted, and whatever detail you choose to include about what you need. Everything you type into the form is stored with the submission.
Enquiries use double opt-in. We email you a confirmation link, and until you click it your submission is not treated as a real enquiry and does not reach us. Unconfirmed submissions are automatically deleted after seven days.
We use Cloudflare Turnstile to tell humans from bots on those forms, and we apply rate limits based on IP address to prevent abuse. Both involve Cloudflare processing your IP address and basic request information.
When you create an Exit Tools account
To use the free tools you provide an email address and a password, and optionally a name. We store your password only as a cryptographic hash, never in a form we can read. We also store the domains you choose to monitor, your display preferences, and a record of the scan results and changes for those domains, so we can tell you when something changes.
We send you email about your own monitored domains, such as an alert when a DNS record or a certificate changes. You can delete your account, which removes your monitoring data with it.
When we work with you as a client
Security work often involves access to systems that contain personal information about your staff, your customers or third parties. During an engagement we may collect logs, forensic images, configuration and account data. What we may access, what we do with it, how long we keep it and how it is destroyed are all set out in the written agreement for that engagement, which takes precedence over this page.
We apply data minimisation as a matter of practice: we take what the investigation needs and no more, and we prefer to hold evidence ourselves rather than distribute copies.
How we use it
- To answer your enquiry and, if it goes further, to scope and deliver work for you
- To provide the free tools and send you alerts about the domains you monitor
- To send transactional email such as confirmations, alerts and password resets
- To keep our systems secure and available, including blocking abuse
- To meet our legal, insurance and record keeping obligations
We do not send marketing email to people who have not asked for it. If we ever add a mailing list it will be opt-in and separately unsubscribable.
Who else handles your information
We use a small number of service providers to run the business:
- Cloudflare for content delivery, bot protection, network access and encrypted offsite backups
- Resend to send transactional email
- Google for website analytics and Search Console
These providers may store or process information outside Australia, including in the United States. We share information with them only so they can perform those functions for us. We do not otherwise disclose your personal information, except where we are required to by law, or where you have asked us to.
Where it is stored
Our applications and databases run on infrastructure we own and operate in Australia. Backups are encrypted before they leave that infrastructure and are stored with Cloudflare.
How long we keep it
- Unconfirmed enquiries: deleted automatically after seven days
- Confirmed enquiries: kept while the opportunity or relationship is live, and afterwards only as long as we need for our business and legal records
- Exit Tools accounts: kept until you delete the account
- Client engagement material: per the written agreement for that engagement, after which it is destroyed or returned
How we protect it
Traffic to all of our sites is encrypted in transit. Administrative interfaces sit behind identity based access control as well as application login. Passwords are stored hashed. Backups are encrypted. Access to client material is limited to the people doing the work, and credentials are held in a password manager rather than in code or documents.
No system is perfectly secure, and we will not claim otherwise. If a data breach occurs that is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
Cookies and analytics
This website uses cookies set by Google Analytics to distinguish visitors and sessions. The tools site additionally sets a session cookie when you log in, which is required for the service to work. You can block or delete cookies in your browser, and you can opt out of Google Analytics using Google's browser add-on. Blocking analytics cookies does not affect anything on this site.
Accessing or correcting your information
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email contact@exit.codes and we will respond within a reasonable period, normally within 30 days. We may need to verify who you are before acting on a request.
If you have an Exit Tools account you can view and change most of your information yourself in your account settings, and delete the account outright.
Complaints
If you think we have mishandled your personal information, tell us first at contact@exit.codes. We will investigate and write back to you. If you are not satisfied with how we handle it, you can escalate to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
We will update this page when what we do changes. The date at the top tells you when it was last revised. If a change materially affects people who have already given us information, we will tell them directly rather than relying on this page.