1. About this policy
Befade Designs, ABN 53 937 307 245 ("we", "us", "our") provides hosted websites, online payments, newsletters and administration tools to sports clubs, trade and local businesses and similar organisations in Australia.
This policy explains how we handle personal information, and applies to our platform, the customer websites we host, and our own marketing and enquiry forms.
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
We are not required to comply with the Privacy Act 1988 (Cth) because we are a small business operator, but we have chosen to handle personal information in accordance with the Australian Privacy Principles.
2. Who does what: us and our customers
Our platform is multi-tenant. Each customer — a sports club, a cafe, a trade business or similar organisation — has its own site and its own administrators. In this policy we call them "clubs and businesses". The personal information collected through a customer's site — orders, playing fees, bookings, newsletter subscribers, enquiries — is collected for that club or business. We hold and process that information as the platform operator so their site can function.
Administrators can see the personal information collected through their own site, including buyer names, email addresses and any player or customer names on orders. They cannot see other customers' data. Clubs and businesses may have their own privacy practices for what they do with information after they receive it, including information forwarded to their own mailbox by our enquiry forms.
We also collect personal information directly for our own purposes — for example when someone enquires about the platform through our marketing form.
In short: we build and host websites for clubs and businesses, and provide each with a dashboard. Information about buyers, players, customers and subscribers is collected for that club or business and held by us on its behalf. Each club or business remains responsible for its own privacy obligations to its members and customers, and this policy covers what we do with the information while we hold it.
3. What personal information we collect
3.1 When you buy something or pay fees through a customer site
| Information | Why we hold it | Source |
|---|---|---|
| First and last name | To identify the purchase, send receipts and notify the club or business | You, at checkout |
| Email address | To process payment, send your receipt, and limit duplicate pending orders | You, at checkout |
| Player name on each item | To tell the club or business who a playing fee, ticket or booking relates to | You, at checkout |
| Order details — items, amounts, currency, payment reference | To fulfil the order and keep a record of the transaction | Generated by the platform and our payment provider |
| A keyed hash of your email address | To match related orders within a club or business and support audit and fraud checks without storing the address itself. Cleared when the order is fully anonymised, along with your email address. | Derived at checkout |
| Your IP address | Held briefly to limit how many checkout attempts can be made — not stored with your order | Your connection |
| Marketing opt-in and the consent wording shown to you | To record that you agreed to receive the club or business's newsletter, if you did | You, at checkout |
3.2 When you subscribe to a customer newsletter
| Information | Why we hold it | Source |
|---|---|---|
| Email address | To send you the club or business's newsletter | You |
| Name (optional) | To personalise messages | You |
| Subscription status and how you opted in | To make sure we only send to people who have agreed | Generated |
| Confirmation and unsubscribe tokens | To make the links in our emails work | Generated |
| The consent wording shown to you, the date and time, your IP address and browser user agent | To keep proof of consent as required by the Spam Act 2003 | Captured at signup |
| A record of each consent event — subscribed, confirmed, unsubscribed | To maintain an accurate consent history | Generated |
3.3 When you register your interest with a club or business
Our enquiry form collects your first and last name, email address, an optional phone number, and any notes or referral information you choose to add. For club customers, the form also asks for an experience level, which includes junior age brackets. This information is not saved to our main database. It is placed in a queue, emailed to the customer's nominated contact address, and the queued copy is scrubbed after 30 days. The copy in the customer's mailbox is then held by that club or business under its own practices. Please do not include health information or other sensitive details in the free-text fields — we do not need them.
3.4 When you visit a customer website
We run our own analytics rather than using third-party advertising trackers. For each page view or button press we record the page, an event tag, referral source, your browser and device type, and a country code supplied by our content delivery network. We do not store your IP address with these records. Instead we create a visitor identifier by hashing your IP address, your browser user agent, the date and a secret value. The identifier changes daily, and we do not hold anything that would let us reasonably identify you from it.
The page that referred you is stored in your browser for the duration of your visit so we can attribute later page views in the same session. It is cleared when you close the tab. We do not set cookies for analytics — see section 8 for what your browser stores and for content provided by other companies.
3.5 Customer administrators and platform enquiries
Administrators of the clubs and businesses we host sign in through our authentication provider. We store the user and organisation identifiers issued by that provider and attribute administrative actions to them in our audit log.
If you enquire about the platform through our own marketing form, we collect your name, business name, email address and phone number. We delete that record from our systems after 30 days. A copy of your enquiry also arrives in our email inbox, and we keep that copy only as long as we need it to respond to you.
3.6 Sensitive information and government identifiers
We do not ask for sensitive information as defined in the Privacy Act — health, biometric, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record or union membership — and there are no fields for it in our systems. We do not collect government related identifiers such as tax file numbers, Medicare numbers, driver licence or passport numbers. Where a free-text field allows it, please leave sensitive details out.
3.7 Images uploaded by customers
Administrators can upload images to their site — for example team photographs, product shots or images used on club or business pages. Those images may contain personal information, including photographs of club members or of a business's staff and customers. We store them so the customer's website can display them. We do not analyse them, and we do not use facial recognition or any similar technology on them.
Clubs and businesses decide what to upload, and are responsible for having permission to publish images of the people shown. If you would like an image removed, please contact the relevant club or business in the first instance, or contact us using the details in section 16. We keep an image for as long as the customer keeps it on its site. When a customer deletes an image, or when its account closes, we delete the stored file — see section 12.2.
4. How we collect personal information
- Directly from you, when you buy something, subscribe, or submit a form.
- Automatically, when you use a customer website — the analytics described in section 3.4.
- From our payment provider, when it confirms the status of a payment.
- From our email provider, when a message bounces or is reported as spam.
- From a club or business, where its administrator enters, uploads or manages information in its dashboard.
5. Why we use personal information
We use personal information for the purpose it was collected for, and for directly related purposes you would reasonably expect. In practice that means:
- Taking payments, issuing receipts and telling the club or business about the order.
- Recording who a playing fee, ticket or booking is for.
- Sending customer newsletters and campaigns you have opted in to, and honouring unsubscribes.
- Passing enquiries to the relevant club or business.
- Producing aggregate website statistics for club and business administrators.
- Keeping the platform secure — rate limiting, fraud prevention, audit logging and backups.
- Operating, maintaining and improving the platform — diagnosing faults, investigating errors, and understanding how the platform is used in aggregate.
- Meeting our legal and record-keeping obligations.
We do not sell personal information. We do not use it for automated decision-making or profiling, and there are no artificial intelligence or machine learning systems in the platform that process it. Decisions to approve or decline a card payment are made by our payment provider, not by us.
6. Dealing with us anonymously
You can browse a customer website without telling us who you are — the analytics described above are pseudonymous. You cannot complete a purchase or subscribe to a newsletter anonymously, because we need an email address to take payment, send a receipt or send the newsletter.
7. Marketing and electronic messages
Customer newsletters are opt-in. Where you subscribe through a club or business's signup form, we use double opt-in by default — you subscribe, then confirm by clicking a link in an email. Where you tick the newsletter box during checkout, you are subscribed directly without a confirmation email, and we record the exact wording you agreed to at the time.
Every marketing email contains an unsubscribe link, and our campaign emails also carry one-click unsubscribe headers so your email app can do it for you. Unsubscribing takes effect immediately, and we add your address to a suppression list so that you are not contacted again even if your details are later re-imported or re-entered. We also add addresses to that list when a message bounces repeatedly or is reported as spam. The suppression list is kept indefinitely, because its purpose is to make sure we never contact you again.
Transactional messages — receipts, order confirmations, newsletter confirmations — are not marketing and are sent regardless of your marketing preferences.
Marketing emails sent through our platform identify the club or business as the sender and include its name, postal address and a contact email address. If you need to contact us about a message you have received, you can use the details in section 16.
8. Cookies and tracking
We do not set cookies on the customer websites we host, and we do not place advertising pixels or trackers on them.
Our own website, befade.com, uses the Meta pixel so we can measure and target our advertising on Facebook and Instagram. This applies only to our own marketing site, not to any customer website. Meta sets its own cookies and receives information about your visit under its privacy policy. You can control this through your Facebook ad preferences and your browser settings.
Customer websites store a small amount of information in your browser so the site works: your shopping cart, and the page that referred you, used for the visitor statistics described in section 3.4. This stays on your device. Your cart is cleared when you complete a purchase, and the referral information is cleared when you close the tab.
After you complete a purchase, your order details — including your name, email address and any player names — are kept in your browser so the confirmation page can display them. This is cleared when you close the tab. If you are using a shared or public computer, close the tab when you are finished.
Some customer pages include content provided by other companies, which may set their own cookies when that content loads:
- Square — the payment form at checkout
- Google Maps — embedded maps showing a business or club's location
- OpenTable — the booking widget, on customer sites that take reservations
These companies set and read their own cookies under their own privacy policies, and we do not control what they collect. Apart from confirmation of whether a payment succeeded, we do not receive it.
9. Who we share personal information with
We share personal information with service providers who help us run the platform, and with the club or business whose site you used. We require providers to protect the information and to use it only for the services they provide to us.
| Recipient | What they receive | Purpose | Where it is handled |
|---|---|---|---|
| OVH | All platform data — orders, buyer and player names, email addresses, newsletter subscribers | Hosting the database, cache and application server | Sydney, Australia |
| Square | Buyer email address, payment amount and currency | Payment processing | United States |
| Resend | Recipient email addresses and full message content, including names, player names and order details | Sending transactional and marketing email | United States |
| Clerk | Administrator authentication data | Signing customer administrators in | United States |
| Cloudflare | Encrypted database backups, images uploaded by customers, and network-level data including IP address and country | Storage, backups and content delivery | Oceania region; provider is a United States company |
| Axiom | Request logs including IP address, user agent, path and administrator identifier | Operational logging | United States |
| Meta (if a customer connects a page) | Page access tokens and public page content | Syncing a customer's social feed | United States |
| Meta (our own website only) | Information about your visit to befade.com, collected by the Meta advertising pixel described in section 8 | Measuring and targeting our own advertising | United States |
| Vercel | Customer domain and site routing data (no buyer information) | Website routing | Sydney, Australia; provider is a United States company |
| Discord | Operational alerts, which can include an IP address in rate-limiting alerts | Internal engineering alerts | United States |
| The relevant club or business | Order, subscriber and enquiry information from that customer's site | Running the club or business | Australia |
We may also disclose personal information where the law requires or authorises it, or where it is reasonably necessary to protect someone's safety or to enforce our rights.
10. Overseas disclosure
Our database and the servers that run the platform are located in Sydney. Some of the service providers listed in section 9 are based in the United States, and the following information is accessed or stored there:
- Buyer email addresses and payment details, sent to our payment provider.
- The content of emails — including names, player names and order details — sent through our email provider.
- Administrator sign-in data, held by our authentication provider.
- Our request logs, including IP addresses, held by our logging provider.
- Page access tokens and public page content, where a customer connects a social media page.
- Operational alerts, which can include an IP address.
- Information about visits to our own website, collected by the advertising pixel described in section 8.
Our encrypted database backups and images uploaded by customers are stored in the Oceania region by a United States company.
Before disclosing personal information to an overseas recipient we take steps we reasonably believe are appropriate to ensure it is handled consistently with the Australian Privacy Principles. For Cloudflare, Clerk, Axiom, Vercel, Square and Resend we rely on the provider's published data processing terms — either terms that require the provider to process personal information only on our instructions, or, where the provider acts as an independent controller, terms that name the Australian Privacy Principles or the Privacy Act 1988 directly. The countries involved are the United States and, through those providers' own subprocessors, other countries listed in their published subprocessor lists.
Where a customer connects a social media page, we rely on the Standard Contractual Clauses that Meta's Platform Terms apply to international transfers of this data. These clauses are not Australian-specific, so we treat them as part of our reasonable steps under APP 8.1 rather than as a finding that Meta's handling is substantially similar to the Australian Privacy Principles.
We do not yet have an equivalent mechanism for the Meta advertising pixel on befade.com.
11. How we protect personal information
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. No system can be guaranteed secure, but the measures we use include:
- Encrypted connections (HTTPS) enforced in production, with HSTS.
- Encryption of payment and social integration access tokens where they are stored.
- Encryption of database backups before they are uploaded to storage.
- Filtering of personal information out of application error logs and queued task records.
- Rate limiting on public endpoints to reduce abuse.
- Authenticated administrator access, with each customer's administrator restricted to their own site's data.
- An audit log recording administrative actions, including actions taken by us.
- Multi-factor authentication on administrative sign-in and on all provider accounts.
- Request logging through a third-party service to help us detect and investigate problems.
Who can access what
Direct access to the production database and server infrastructure is limited to the operator of Befade Designs. A small number of Befade Designs personnel hold platform staff accounts, which allow them to operate and support the platform across the clubs and businesses we host. Each person signs in under their own named account with multi-factor authentication, access is limited to what their role requires, is subject to confidentiality obligations, and is removed when it is no longer required.
Support access
Where necessary to operate or support the platform, Befade Designs personnel may access a customer's dashboard. We do so under our own named accounts with platform staff permissions — we do not sign in as, or act under the identity of, a club or business administrator. These actions are recorded in our audit log against the individual who took them, and retained for 24 months.
12. How long we keep personal information
We keep personal information only while we need it, then delete it or remove the identifying parts. Current periods are:
| Information | Period | What happens then |
|---|---|---|
| Buyer and player names on paid orders | 1,095 days after payment | Names removed; the order record remains |
| Buyer email address on paid orders | 2,555 days after payment | Email removed and the order fully de-identified |
| The keyed hash of your email address on an order | 2,555 days after payment, cleared at the same time as the email it's derived from | Cleared when the order is fully de-identified |
| Abandoned checkouts | 30 days | De-identified |
| Failed checkouts | 540 days | De-identified |
| Website analytics events | 730 days | Deleted |
| Queued email tasks containing your details | 30 days | Contents scrubbed |
| Platform enquiry leads | 30 days | Deleted |
| Newsletter subscribers | Until you unsubscribe, then 730 days | Record deleted; your address is kept on our suppression list so we do not contact you again |
| Newsletter consent and unsubscribe records | 730 days after you unsubscribe | Deleted; email and technical details removed sooner if you ask us to erase your record |
| Campaign send records | 90 days | Your email address and name are removed; the send history remains |
| Email suppression list | Indefinite | Kept so we do not contact you again |
| Images uploaded by customers | For as long as the customer keeps the image on its site, and until its account closes | The stored file is deleted — see 12.2 |
| Administrative audit log | 365 days; 24 months for actions by Befade Designs personnel and for ownership, billing and logging changes | Deleted — see 12.1 |
| Customer administrator accounts held by our authentication provider | While the person is an administrator of a club or business we host | Deleted when the person's access is removed or the customer's account closes |
| Social media page access tokens | While the customer keeps its page connected | Deleted when the customer disconnects the page |
| IP addresses used for rate limiting | Up to 60 seconds | Deleted automatically |
| Operational alerts sent to our internal chat tool | Governed by that tool's own retention, not our | Not deleted by us |
| Request logs held by our logging provider (including IP address, browser and page requested) | 30 days | Deleted |
| Encrypted database backups | 30 days | Expired by the storage provider |
Some information necessarily survives de-identification: transaction amounts, item names and the payment reference are kept as a financial record. Records already sent to our payment and email providers are held under their own retention rules, and we ask them to delete on request rather than deleting automatically.
12.1 Our administrative audit log
We keep a log of administrative actions taken in the platform — who changed a setting, who was given or removed access, who edited or deleted a record. The log exists so that we and the clubs and businesses we host can answer questions about who did what, including if something goes wrong.
We keep this log for 365 days for actions taken by a club or business administrator. Actions taken by Befade Designs personnel, and actions taken automatically by the platform's own systems, are kept for 24 months. The log remains searchable for its full retention period rather than being archived.
12.2 When a customer leaves the platform
If a club or business closes its account, we delete the personal information collected through its site within a reasonable period after the account closes, and we will notify its registered contact of the date on which its data will be deleted. Copies in our encrypted backups are removed as those backups expire, within 30 days of deletion.
Audit log entries are kept for the remainder of the periods described in section 12.1 and then deleted, so that questions about who accessed the customer's data — including access by Befade Designs personnel — can still be answered during that window.
12.3 Newsletter consent and campaign records
We keep a record of each newsletter consent event — when you subscribed, confirmed or unsubscribed, and the wording you agreed to — as evidence of consent under the Spam Act 2003. We keep these records while you are subscribed and for two years after you unsubscribe, then delete them. If you ask us to erase your subscriber record, we remove your email address, name, IP address and browser details from these records straight away, keeping only the date of each event and the wording you agreed to.
We also keep a record of which campaigns were sent to you. We remove your email address and name from those records after 90 days, keeping only the send history. If you ask us to erase your subscriber record, we remove your email address and name from those records immediately.
If you subscribe but never confirm, we delete your record entirely after 30 days.
13. Children and young people
Some of our customers are clubs that run junior sport. When a membership or playing fee is paid through one of those sites, the person paying is asked to enter the player's name, and that player may be a child. We ask that a parent or guardian make the purchase and provide that information. Most of our other customers — trade and local businesses — do not collect information about children, and this section does not apply to their sites.
From the person paying, we collect the player's name only — no date of birth, no contact details for the child, and no sensitive information. Player names are shown to the club's administrators and appear on receipts and order notifications sent by email. They are not sent to our payment provider. Player names are removed from paid orders after the retention period in section 12.
Clubs may also upload photographs to their own sites, which can include images of junior members. Clubs and businesses decide what to upload — see section 3.7.
If you believe a child's personal information has been given to us and you would like it removed, contact us using the details in section 16.
14. Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong, out of date or incomplete. Contact us using the details in section 16.
We will ask you to verify your identity before we act on a request, and we aim to respond within 30 days. If we refuse access or correction we will tell you why in writing and explain how to complain. There is no charge for making a request or for us providing access.
For information held on behalf of a club or business, we may need to work with that customer to fulfil your request. Where we have shared your information with our payment or email provider, we will ask them to act on erasure requests, but their systems are outside our direct control. Where we delete information at your request, copies may remain in our encrypted backups until those backups expire, within 30 days.
Requests are handled by our Privacy Officer using the contact details in section 16. We do not currently offer a self-service facility, so requests are actioned manually.
15. Data breaches
If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information we hold, we will contain it, investigate what happened, and assess whether it is likely to result in serious harm.
Although the Notifiable Data Breaches scheme does not apply to us as a small business operator, we have chosen to follow it. We aim to complete that assessment within 30 days of becoming aware of a suspected breach. Where a breach is likely to result in serious harm, we will notify the individuals affected and the Office of the Australian Information Commissioner as soon as practicable after we form that view. Where a breach affects information collected through a customer's site, we will also notify that club or business so it can inform its members or customers.
16. Contact us and complaints
If you have a question about this policy, want to access or correct your information, or wish to complain about how we have handled your personal information:
| Contact | Details |
|---|---|
| Privacy contact | Privacy Officer |
| privacy@befade.com | |
| Postal address | PO BOX 4, FITZROY, AUSTRALIA |
We will acknowledge your complaint and respond within a reasonable time, usually 30 days. If you are not satisfied with our response, please tell us and we will escalate it internally.
As a small business operator we are generally exempt from the Privacy Act 1988 (Cth), which means the Office of the Australian Information Commissioner usually cannot investigate a complaint about us. You can still contact the OAIC for general information about privacy at oaic.gov.au or on 1300 363 992. If your complaint concerns information held by a club or business whose site we host, you may also raise it with that customer directly.
17. Changes to this policy
We may update this policy from time to time. The current version is always available at befade.com/privacy-policy, and the effective date appears at the top. Where changes are significant, we will publish a notice on our website and, where we hold your email address for that purpose, tell you by email.
Effective date: 16/08/2026. Version: 1.0