Legal
Privacy Policy.
Last updated: 11 April 2026
Control Stack is a free public catalogue of Australian security controls operated by Mindset Cyber PTY LTD (ABN 90 681 814 446). This policy explains what data the Control Stack website (controlstack.au) and the Control Stack mobile app collect, how we use it, and your choices.
Information we collect
On the website: when you visit controlstack.au, our hosting provider (Cloudflare) records standard server logs including your IP address, browser type, referring page, and the URLs you request. We use Google Analytics 4 to measure aggregate, anonymised usage of the site (page views, sessions, device type, country). IP addresses are anonymised before being stored in Google Analytics.
In the Control Stack mobile app: the app loads pages from controlstack.au inside a native shell. Google Analytics is disabled when the site is loaded inside the app, so no usage tracking happens there. Bookmarks you save in the app are stored only on your device and never transmitted to us.
We do not require accounts. We do not collect names, email addresses, or any personal information unless you voluntarily contact us via email.
How we use information
- To operate, secure, and improve the Control Stack website and app.
- To understand which controls and frameworks visitors find most useful (aggregate website analytics only).
- To respond to enquiries you send us by email.
We do not sell, rent, or share personal information with third parties for marketing.
Cookies and local storage
The website uses Google Analytics cookies to measure aggregate usage. The mobile app uses on-device storage (sessionStorage, Preferences) only to remember your bookmarks and detect that you are using the app. None of this data leaves your device.
Third-party services
- Cloudflare — hosting and content delivery (server logs, security).
- Google Analytics 4 — aggregate, anonymised website usage (website only, not the app).
- Supabase — the controls library backend; only accessed at build time, not from your browser or app.
Your rights
Under the Australian Privacy Principles you may request access to or correction of any personal information we hold about you. Because we do not collect personal information from website or app visitors, in most cases there is nothing for us to provide. If you have contacted us by email and want your correspondence deleted, email us using the address below.
Children
Control Stack is intended for adult cyber security and compliance professionals and is not directed at children under 13.
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision.
Contact us
If you have questions about this policy or how Control Stack handles data, contact us at info@controlstack.au.