Trust & security
Your money, protected by design.
Money platforms live or die on clarity. Here's exactly how we treat yours, where the rules apply, and what we are and aren't.
Payment processing through Stripe
Payment processing is handled through Stripe when card payment is required. Full-job upfront funding is confirmed before work starts, then TradeFlo+ tracks milestone releases after approval and dispute-window checks. TradeFlo+ is a payment platform, not a bank, builder, insurer, legal adviser, or building contract.
- Stripe Connect Separate Charges & Transfers
- Server-tracked funded job state
- Milestone release checks before payout instructions
Australian regulatory alignment
TradeFlo+ is designed to work alongside applicable contract, regulator, insurance, and consumer-law requirements; those obligations remain separate.
- Deposit and progress-payment rules remain separate legal obligations
- Regulator pathways remain available
- Consumer-law obligations remain outside the app
Audit log on every dollar
Quote sent. Quote viewed. Job funded. Milestone submitted. Photos uploaded. Milestone approved. Funds released. Every event is logged with a timestamp, an actor, and an immutable record.
- Append-only audit log
- Exportable transaction history
- Timestamped to the second
Dispute resolution with a clock
48-hour window. Both sides upload evidence. Structured review on a fixed timeline. Most disputes resolve in days, not the 14 months to 3 years a VCAT pathway typically takes.
- 48-hour dispute window
- Evidence-based decision
- BPC and VCAT pathway preserved
The legal layer
Where Australian rules apply
TradeFlo+ launched Melbourne-first, so Victoria's framework gets the most weight in our build.
Victorian deposit and cooling-off rules
Caps deposits at 5% on contracts $20,000 and over, 10% on contracts under $20,000. Mandates 5 clear business days cooling-off after signing (s.34/35).
Building & Plumbing Commission (BPC)
Replaced the Victorian Building Authority on 1 July 2025. Operates the public register of registered builders and the regulator-led dispute pathway.
Domestic Building Insurance (DBI)
Legally required for any domestic build of $16,000 or more. Covers up to $300,000 — 6 years structural, 2 years non-structural. TradeFlo+ does not provide DBI; it sits separately.
Security of Payment Act 2002 (Vic) — the gap
Domestic homeowner-to-builder payments are not covered by the Security of Payment Act in Victoria. This is exactly the gap TradeFlo+ exists to close.
2025 building-law reforms
Most reforms commence 1 December 2026. We're tracking them and will update the platform ahead of commencement.
Honesty page
What we are, and what we aren't
We are
- A milestone payment platform for Australian residential trades.
- A regulated-payments-partner integration (Stripe).
- A structured dispute process with a fixed timeline.
- An audit-grade record of every job we touch.
We aren't
- We are not a bank.
- We are not a registered builder, lawyer, or accountant.
- We are not Domestic Building Insurance — that's a separate, legally required policy for builds over $16,000.
- We do not write your contract — your tradie should issue the required building contract where one is required.
- We do not replace the Building & Plumbing Commission or VCAT — they remain the regulator backstop.
Receipts, not promises
Every milestone leaves a paper trail.
When a tradie submits a milestone, the photos, notes and timestamps go straight into the job record. When a homeowner approves or disputes, that's logged too. If anything ever needs to go to BPC or VCAT, the evidence is already gathered.
- Photos timestamped per milestone
- Notes attached to every submission
- Append-only audit log of approvals and releases
- Exportable as PDF for any external review

Under the hood
Security practices
- Card details never touch our servers — Stripe Elements collects them directly.
- All traffic encrypted in transit (TLS 1.2+).
- Data encrypted at rest in PostgreSQL.
- Role-based access control on every internal tool.
- Mandatory 2FA for all team members with production access.
- Append-only audit log on every money-impacting action.
- Regular dependency and security review.
Read it. Question it. Then try it.
If anything on this page raises a concern, email us and we'll answer it on the record.