Last updated: 1 June 2026
๐ Privacy-first by design
Your transaction files are processed entirely in your browser and are never uploaded to or stored on our servers.
AML Shield Pro ("we", "us", "our") is an Australian-based software company providing automated anti-money laundering (AML) and counter-terrorism financing (CTF) compliance screening tools for small and medium enterprises, accountants, financial institutions, and fintechs.
This Privacy Policy applies to all users of our website at amlshieldpro.com and our SaaS platform. It complies with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and to the extent applicable, the General Data Protection Regulation (GDPR) for users in the European Economic Area.
Account information: When you create an account, we collect your name, email address, company name, and country. We use this to identify you, provide the service, and communicate with you.
Billing information: If you subscribe to a paid plan, payment processing is handled entirely by Stripe. We never see, receive, or store your full card number, CVV, or banking details. We only receive a tokenised reference and the last 4 digits of your card from Stripe.
Usage data: We collect anonymised data about how you use the platform (pages visited, features used, scan counts) to improve the product. This does not include the content of your transaction files.
Support communications: If you contact us via the contact form or email, we retain those communications to respond to you and improve our service.
Your transaction files never leave your device.
All AML screening, rule execution, anomaly detection, sanctions screening, and report generation occurs entirely within your browser using client-side JavaScript. When you upload a CSV or Excel file:
The only data saved to our database are aggregate scan statistics (e.g. "100 transactions scanned, 3 alerts generated") โ never individual transaction records.
If you choose to save individual alerts or cases to Supabase for investigation workflow purposes, that data is stored under your account with full row-level security, meaning only you can access it.
All payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you enter payment details:
We take security seriously and implement the following measures:
Despite these measures, no system is 100% secure. Please use a strong, unique password for your account.
We use only essential cookies required for the service to function:
We do not use advertising cookies, third-party tracking cookies, or sell your data to advertisers. We do not use Google Analytics or similar tracking services.
Under the Australian Privacy Act and GDPR, you have the following rights:
To exercise these rights, contact us at privacy@amlshieldpro.com. We will respond within 30 days.
We retain your personal data for as long as your account is active or as needed to provide the service:
Upon account deletion, all personal data is permanently deleted within 30 days, except where required by law.
We share data with the following trusted third parties only to the extent necessary to provide the service:
Supabase (Supabase, Inc.)
Database, authentication, and storage. Data processed in AWS ap-southeast-2 (Sydney). supabase.com/privacy
Vercel (Vercel, Inc.)
Web hosting and edge network. vercel.com/legal/privacy-policy
Stripe (Stripe, Inc.)
Payment processing. PCI-DSS Level 1 certified. stripe.com/privacy
Anthropic (Anthropic, PBC)
AI narrative generation for SAR reports and copilot features (optional). anthropic.com/privacy
We do not sell your data to any third party.
Our primary infrastructure is located in Australia (AWS ap-southeast-2). Some service providers (Vercel, Stripe) may process data in other countries including the United States. All transfers are protected by appropriate safeguards including Standard Contractual Clauses (SCCs) for GDPR compliance.
For privacy inquiries or complaints:
AML Shield Pro โ Privacy Officer
privacy@amlshieldpro.com
If unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or for EEA users, your local Data Protection Authority.