SaaS builders & SMBsAustralian software teams, startups, and anyone moving off Supabase or Firebase
Most teams on WattleDB are building ordinary Australian software: a booking system, a portal, an internal tool, a product for one of the sectors below. Their customers ask two questions in writing: where is the data, and who can reach it. WattleDB answers both with one Australian company, and a Postgres database with an instant REST API that developers already know how to use.
If you are moving from Supabase, WattleDB shares its open-source core. PostgREST clients and tooling work against the REST API, and migration is a standard pg_dump and pg_restore over your direct connection string.
Privacy Act 1988, APP 11
Reasonable steps to protect personal information now expressly include technical and organisational measures. You remain accountable for personal information your provider holds for you.
Notifiable Data Breaches scheme
Assess a suspected eligible breach within 30 days and notify the OAIC and affected individuals as soon as practicable. The 31 August 2026 exposure draft proposes 72 hours to the Commissioner.
Statutory tort, June 2025
Individuals can sue any person or company for a serious invasion of privacy, including misuse of information. It is not gated by the small-business exemption.
How WattleDB helps
Your database runs on a primary in Sydney with automated backups and a continuous change log streamed to Melbourne, both inside Australia, both on Australian-owned infrastructure. Every connection is TLS. Row-level security lets you enforce tenant isolation in the database rather than in application code. You can restore to a point in time yourself from the console, and export at any time. The Data Processing Addendum states where data lives and who our sub-processors are. If your app collects Australian addresses, WattleAddr, our sister product, gives you address autocomplete and verification from the same company.
What you still have to do:
- Publish your own privacy policy and breach response plan.
- Write the row-level security policies for your schema.
- Keep your own master copy of files you cannot re-create; the Melbourne copy of object storage guards against losing Sydney, not against deleting a file.
- Tell us in writing if a customer’s obligations flow down to us.