Effective: 26 April 2026
This Privacy Policy explains how AZNConnecT (ABN 66 606 519 696) collects, uses and protects your personal information when you use the AzNConnect mobile app and website.
Who we are
AZNConnecT (ABN 66 606 519 696) (“we”, “us”, “our”) operates the AzNConnect mobile application and website (together, the “Service”). We are based in New South Wales, Australia.
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have. We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
Information we collect
We collect personal information that you provide to us directly when you use the Service:
- Account details: email address and password (passwords are stored as a salted hash; we never see them in plain text).
- Profile details: first name, last name, mobile number, date of birth, occupation, industry, region, bio and profile photo.
- Event activity: event reservations, ticket codes and RSVP status.
- Payment metadata: order amount, currency, status and Stripe Checkout session ID. Card numbers and CVVs are processed by Stripe and never touch our servers.
- Push notification token: an Expo/Apple/Google push token if you enable notifications, used so we can send you event and membership notifications.
- Device and usage data: app version, OS, IP address (used for rate limiting and security) and basic request logs.
How we use your information
We use your information to:
- Create and manage your account and verify your email address via one-time codes.
- Show your profile, RSVPs and tickets inside the app.
- Process payments for events and Premier Membership through Stripe.
- Send you transactional notifications (RSVP confirmations, ticket details, password resets).
- Send region-targeted and industry-targeted notifications about events that match your profile, where you have enabled push notifications.
- Provide customer support and respond to your enquiries.
- Detect and prevent fraud, abuse and security incidents (including IP-based rate limiting on sign-up and OTP endpoints).
- Comply with our legal obligations, including tax and accounting record-keeping.
Legal bases
We collect and use your personal information on the basis of: (a) the contract we form with you when you create an account and use the Service; (b) your consent (which you can withdraw at any time, e.g. by disabling push notifications or deleting your account); and (c) our legitimate interests in operating, securing and improving the Service.
Who we share information with
We do not sell your personal information. We share limited information only with the following service providers and only to the extent needed to operate the Service:
- Stripe Payments Australia Pty Ltd — to process payments. Stripe is the data controller for card data. See https://stripe.com/au/privacy.
- Expo / Apple Push Notification service / Firebase Cloud Messaging — to deliver push notifications to your device.
- Our hosting provider (WordPress hosting and Cloudflare) — to host the backend API and protect against abuse.
- Our administrators — staff with manage_options permission on the WordPress backend can view profile data in order to manage events, membership and support requests.
- Law enforcement, courts or regulators — where we are legally required to disclose information.
Overseas disclosure
Our backend is hosted in Australia, but some of our service providers (Stripe, Apple, Google, Cloudflare) operate global infrastructure and may process your information overseas, including in the United States and the European Union. When this happens we take reasonable steps to ensure recipients comply with the Australian Privacy Principles or substantially similar protections.
How long we keep your information
We keep your information only for as long as needed:
- Account, profile and push token: until you delete your account.
- Payment / order records: 7 years after the transaction (required by Australian tax law). When you delete your account, your name and email are removed from these records and only a non-identifying transaction reference remains.
- OTP codes: deleted immediately after use, or expire after 10 minutes.
- Server logs: typically up to 90 days.
Your rights
Under Australian law you have the right to:
- Access the personal information we hold about you.
- Ask us to correct information that is inaccurate or out of date (you can edit most fields directly in the app under Profile → Edit Profile).
- Ask us to delete your account and personal information at any time. You can do this in-app under Profile → Delete Account, which permanently removes your profile and detaches your information from our records.
- Withdraw consent for push notifications by disabling them in the iOS or Android settings, or by signing out.
- Lodge a complaint with us, and if not satisfied, with the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.
Children
AzNConnect is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we will delete it.
Security
We protect your information using industry-standard measures including HTTPS/TLS in transit, encrypted password hashes, JWT tokens stored in iOS Keychain / Android Keystore via Expo Secure Store, and rate-limiting of authentication endpoints. No system is perfectly secure, however. If you suspect a breach, please contact us immediately.
Changes to this policy
We may update this Privacy Policy from time to time. The “Effective” date at the top of this document indicates when it was last revised. If the changes are material we will notify you in-app or by email before they take effect.
How to contact us
Privacy queries, access requests and complaints:
admin@aznconnect.com.au
AZNConnecT
Shop R 104/28 Broadway, Chippendale NSW 2008, Australia
ABN: 66 606 519 696
For general support: admin@aznconnect.com.au