1. About this policy
BribieNow (“BribieNow”, “we”, “us”, “our”) is operated by [Full legal name], a sole trader based in Queensland, Australia (ABN [XX XXX XXX XXX]). This policy explains how we collect, hold, use, disclose and protect your personal information when you use the BribieNow website at https://bribienow.com.au and any related services (the Service).
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). While small businesses are not always required to comply with the Privacy Act, BribieNow chooses to apply the APPs in full to the personal information we handle.
If you do not agree with this policy, please do not use the Service.
2. What is personal information
“Personal information” has the meaning given in the Privacy Act, broadly, information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
3. What personal information we collect
We only collect personal information that is reasonably necessary to operate the Service. What we collect depends on how you use BribieNow.
Account and profile
- Email address (required for sign-in).
- Display name (optional).
- Profile avatar and banner images, if you upload them.
- Account role (most users are USER; ADMIN and OWNER roles are used internally to manage the Service).
- The date your account was created and last updated.
If you sign in with Google, we receive a basic profile (email address, name and an avatar URL where available) through Google’s OAuth service. We do not receive your Google password.
Content you submit
When you submit an event, garage sale, business listing, missing-pet listing or pet sighting, we collect the information you provide. This may include:
- Title, description, photos and category information.
- Suburb and (for garage sales) a public address you choose to share, plus a separate private address used internally for moderation.
- Dates, times and contact details where you choose to provide them.
- For pet sightings: optional reporter name and contact, and a one-way hashed value derived from the reporter’s IP address used to limit abuse. This hash cannot be reversed to recover the IP address.
Saved items and notifications
- The events and businesses you save to your account.
- Notifications generated for your account (read/unread status and links to the relevant item).
Technical and log data
- Server-side request logs (IP address, user agent, timestamp, URL, response status) used for security, abuse prevention, debugging and rate limiting.
- Error and performance data collected by our error monitoring provider, which may include a redacted snapshot of the page or request when an error occurs.
- Cookies and similar storage used for authentication sessions and to remember your theme preference (see section 13).
Information we do not deliberately collect
- We do not run advertising trackers.
- We do not collect payment card details (BribieNow is free to use today).
- We do not knowingly collect information from children, see section 12.
4. How we collect personal information
- Directly from you when you create an account, submit content, save items, or contact us.
- From Google when you choose to sign in with Google.
- Automatically through cookies, request logs and our error monitoring provider.
- Occasionally from publicly available sources, for example, when we import event listings from public Facebook event pages or ticketing partners (see section 6).
5. Why we collect, hold and use your personal information
- To provide, operate and improve the Service, including signing you in, displaying your submissions, sending transactional notifications, and showing your saved items.
- To moderate user-submitted content for accuracy, safety and legal compliance.
- To detect, prevent and investigate fraud, spam, abuse and security incidents, including rate limiting and IP hashing for pet sightings.
- To comply with legal obligations and respond to lawful requests.
- To communicate with you about your account or your submissions.
We only send transactional messages today (such as sign-in links and notifications you have opted into within the app). We do not send marketing emails. If we introduce marketing emails in the future, we will obtain your separate consent in accordance with the Spam Act 2003 (Cth) and include an unsubscribe mechanism in every message.
6. Who we share or disclose personal information to
We disclose personal information to a limited number of trusted service providers who help us run BribieNow. Each provider is required to handle personal information in line with their own privacy and security obligations.
Providers that process personal information
- Supabase, database, authentication and file storage. Holds your account, content and uploaded images.
- Vercel, web hosting and edge network. Processes server requests, which include your IP address.
- Sentry, error monitoring. Captures diagnostic data when something goes wrong, which may include IP address and request context.
- Upstash, rate-limiting cache. Tracks request counts against a hashed identifier to prevent abuse.
- Google, OAuth sign-in. Receives only what is needed to verify your identity when you choose to sign in with Google.
Read-only data providers
The following providers supply content shown on the Service. We do not send your personal information to them in normal operation:
- WillyWeather, weather, tides and marine.
- Mapbox, travel-time estimates for the Bribie Island bridge route.
- Ticketmaster, public event listings.
- Apify, importing public Facebook event listings.
We do not sell, rent or trade your personal information.
We may also disclose personal information where required or authorised by law, for example, in response to a court order, a subpoena, or a lawful request from a law-enforcement agency.
7. Overseas disclosure (APP 8)
Some of the providers listed above may store or process information outside Australia. Where that occurs, we take reasonable steps to ensure those providers handle the information consistently with the APPs. By using BribieNow you acknowledge that your personal information may be stored or processed in countries other than Australia, including:
- The United States, Vercel, Sentry, Upstash and Google.
- Other regions where Supabase data centres operate.
If you would like more information about where a particular item of your personal information is held, email privacy@bribienow.com.au.
8. Public information
Information you submit for publication on BribieNow (for example, an approved event, garage sale, business listing or missing-pet listing) is public once approved. Do not include personal information in those submissions that you do not want to be publicly available. We treat the following submission fields as private and do not publish them:
- The submitter’s email address and account identifier.
- A garage sale’s private address, we publish only the public address or suburb you choose.
- Moderation notes.
- Reporter IP hashes for pet sightings.
9. How we store and protect personal information
We store personal information using reputable cloud providers (primarily Supabase and Vercel) with administrative, technical and physical safeguards including:
- Encrypted transport (HTTPS/TLS).
- Encrypted storage at rest by our hosting providers.
- Strict role-based access, only ADMIN and OWNER accounts can access moderation tools.
- Rate limiting and bot mitigation.
- Error monitoring and security logging.
No method of transmission or storage is 100% secure. If we experience a data breach that is likely to result in serious harm to affected individuals, we will notify those individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
10. How long we keep personal information
- Account data is kept while your account is active. You can delete your account at any time from your account settings. When you do, we remove or anonymise the linked personal information, retaining only what we are required to keep for legal, audit or abuse-prevention reasons.
- Submissions that are rejected or archived are retained for moderation history.
- Server logs and error data are typically retained for up to 90 days by our providers.
11. Your privacy rights
Under the APPs you have rights to:
- Access the personal information we hold about you (APP 12).
- Correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13).
- Make a complaint about how we have handled your personal information.
To exercise any of these rights, email privacy@bribienow.com.au. We will respond within a reasonable time (usually within 30 days). We may need to verify your identity before acting on a request. There is no charge to make a request, although in unusual cases we may charge reasonable cost recovery and will tell you in advance.
If you are not satisfied with our response, you may complain to the OAIC:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
12. Children
BribieNow is intended for general audiences but is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact privacy@bribienow.com.au and we will delete it.
13. Cookies and similar technologies
We use a small number of cookies and similar storage technologies:
- A Supabase session cookie used to keep you signed in.
- A local-storage entry recording your light/dark theme preference.
- A small service-worker registration in production for offline support.
We do not use third-party advertising cookies. You can block or delete cookies through your browser settings, but doing so may stop you from being able to sign in.
14. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be highlighted on the website. Continued use of the Service after a change indicates acceptance of the updated policy.
15. Contact us
For any privacy question or request:
- Email: privacy@bribienow.com.au
- Postal: [postal address]
- Operator: [Full legal name], ABN [XX XXX XXX XXX], Queensland, Australia.
See also our Terms and Conditions.
This policy is a general framework intended to comply with the Australian Privacy Principles. It does not constitute legal advice. Before launching commercially or changing how the Service handles personal information, have it reviewed by an Australian lawyer.