Skip to content

Legal

Privacy Notice

A plain-language draft describing the intended handling of host accounts, guest participation and event photos. It must be reconciled with the final product, vendors and Australian privacy obligations before launch.

Draft prepared 2 August 2026 · Version 0.1

1. Privacy contact and operator

The proposed data controller/operator is [legal entity name and ABN/ACN], located at [address]. Privacy enquiries, access requests and complaints should go to [verified privacy email]. Do not publish this notice until those details and the operator’s Privacy Act 1988 (Cth) obligations are confirmed.

2. Information we may collect

  • Host account: name, email address, password verifier, account settings and sign-in/security records.
  • Event: names, dates, event type, stories, trivia, prompts, guest limits and moderation choices.
  • Guest participation: display name, answers, scores, mission progress, event session and timestamps.
  • Media: uploaded source images, captions, technical metadata, metadata-stripped display copies and moderation status. Invited guests receive only the display copy; an authorised host may download the private source file, which can retain device metadata such as capture time or location.
  • Transactions: plan, amount, currency, payment status and processor reference. Full card details should be handled by the payment processor, not stored by us.
  • Technical and support: IP address, browser/device information, audit and abuse-prevention logs, correspondence and consent records where applicable.

3. Why we use information

We use information to create and operate events, authenticate hosts, let guests participate, process payments, moderate and deliver media, provide support, prevent misuse, diagnose reliability issues, meet legal obligations and improve the product using appropriately aggregated information. We should obtain consent before sending optional marketing messages.

4. Host and guest choices

Hosts choose what story information and prompts to provide and should avoid unnecessary sensitive information. Guests can choose not to upload a photo or complete a mission. Hosts must give invitees an appropriate event notice and obtain permissions needed for children, private venues, memorials or other sensitive contexts.

5. Sharing and service providers

Information may be shared with invited event participants according to event settings and with contracted providers needed for hosting, storage, payments, email, security, analytics or support. The intended infrastructure providers include [confirm Cloudflare products and data locations] and the intended payment provider is [confirm Stripe contracting entity and terms]. A final vendor register and overseas disclosure assessment are required before launch. We do not intend to sell personal information or photos.

6. Retention and deletion

Event galleries remain available for the plan’s stated period: 7 days, 30 days or 12 months after the configured event end. Operational backups may take a limited additional period to expire. Account, transaction, fraud-prevention and audit records may be retained where reasonably needed for legal, accounting or security purposes. The final schedule and backup windows must be verified against the deployed system. Automated jobs close guest access, purge realtime rooms and remove stored media when that period ends.

7. Security

We intend to use access controls, encrypted transport, secure password derivation, restricted storage bindings, audit logging and upload validation. No system is perfectly secure. We will maintain an incident response process and handle eligible data breaches under applicable law, including the Notifiable Data Breaches scheme where it applies.

8. Cookies and local storage

Essential cookies or browser storage may keep a host signed in, maintain a guest event session, protect requests and remember required preferences. Optional analytics or advertising storage must not be enabled until a current disclosure and, where required, consent choice are provided.

9. Children

The service is purchased by adults but event photos can include children. Hosts are responsible for appropriate guardian notice and consent. The service is not designed for a child to create a host account or independently purchase a pass. Reports involving a child’s privacy or safety should receive priority handling.

10. Access, correction and complaints

You may ask for access to or correction of personal information we hold about you, or request deletion where applicable. We may need to verify your identity and may lawfully refuse or limit a request in some circumstances, with reasons. Privacy complaints should first be sent to [privacy contact]; the final notice should explain external complaint rights, including the Office of the Australian Information Commissioner where applicable.

11. Changes

We will date material updates and notify hosts where a change materially affects how their information is handled. The practices stated in the published notice must stay aligned with the deployed service and vendor contracts.