Minimal data by design
Privacy
You can browse public fault-code and coverage pages without creating an account or uploading personal information.
What we collect and the protections that apply
Independent identification service
Heat Pump Fault Finder AU is an independent site. Brand names and trade marks are used for identification only. We are not affiliated with, endorsed by, or acting for the manufacturers listed.
Takedowns and corrections
Send any concern, correction, rights complaint, or takedown request toreports@heatpumpfaultfinder.com.au. We immediately unpublish affected pages after any complaint while it is reviewed and resolved.
Australian Consumer Law
Nothing on this site excludes, restricts, or modifies any right or remedy you may have under the Australian Consumer Law. A voluntary manufacturer warranty does not limit those rights or remedies.
Minimal personal information
We ask only for the fields and optional equipment photos shown in a form. The dedicated contribution form is the exception: it requires at least one equipment photo. Photos are stripped of EXIF/location metadata and kept private unless a separately consented, high-confidence automated privacy review approves publication. Uncertain and rejected photos remain private. A contribution credit is public only with separate permission. We put no PII in URLs, logs, or analytics. Form records stay in D1 and the founder inbox, image objects stay in private R2, and we delete them on an email request to the contact above.
How form data is handled
If you choose to use a contact, notification, or service-request form, we collect only the fields shown in that form so we can respond or provide the requested route. Unknown-code and repair forms also let you attach up to three optional model-plate or controller photos. The contribution form requires at least one photo plus a public credit name and separate consent for both publication and that credit. The server removes EXIF and location metadata, discards the supplied filename, and stores each photo privately under a random identifier.
Installer outreach uses reviewed business-role addresses published on the business’s own contact page. D1 retains the business name, address, exact source URL, review date, sequence status and any unsubscribe time. Every message identifies the sender and offers a no-login unsubscribe; an unsubscribed row is suppressed from every later send.
A repair lead with a consented email, or an unknown-code submission whose notification box was ticked, receives one fault-outcome question after seven days. The linked form stores fixed choices for the outcome, item involved, cost band and warranty status. Its optional note remains private and is never returned by the public aggregate API or rendered on a code page. An unsubscribe is permanent for later outcome follow-ups.
Photos remain private unless the separate publication permission is ticked and an automated privacy review gives a high-confidence approval. The review rejects or permanently holds any photo containing a person, face, location or document context, and any uncertain result. An unticked photo cannot be approved for publication. Submitted form data remains in the site’s D1 database and founder inbox, while image objects remain in private R2 storage and approved files are served only through a guarded random-id route. We do not put this data in page URLs, application logs, or analytics, and we do not sell personal information. Emailreports@heatpumpfaultfinder.com.auto request deletion.
Anonymous fault-code lookups are counted without name, email, phone, cookie, or browser identifier fields. The popular-code module uses only resolved aggregate groups with a minimum frequency, then returns reviewed catalogue labels rather than submitted free text. Sparse groups remain private and the page shows a static reviewed fallback.