DadsOrder privacy
Privacy Policy
DadsOrder is operated by OceanX Consulting Pty Ltd (ABN 67 615 055 368) of Sydney, New South Wales (“we”, “us”). This policy explains what personal information we collect, why, who we share it with, and the choices you have. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
DadsOrder is a marketplace: customers post what they need and suppliers respond with offers. Both are users of this service, and this policy covers both.
1. What we collect
Everyone with an account
- Your name, email address and Australian mobile number.
- Your suburb — used to match you with nearby suppliers and to show distances.
- A password. It reaches our server over an encrypted connection, is immediately converted to a one-way hash, and only that hash is stored. We do not retain the password itself and cannot recover it — which is why a reset issues a new one rather than telling you the old one.
- Verification status for your email and mobile. Both must be confirmed before you can book or sell.
Customers
- The briefs you post: category, event date, budget and the structured answers for that category.
- Inspiration photos you upload to a brief.
- Orders, amounts, delivery or pickup details and event dates.
- Messages and photos you send to a supplier.
- Reviews you write, including any review photos and the first name shown publicly.
Suppliers
- Business name, ABN, trading category, description, suburb and Instagram handle.
- Verification evidence you upload — for example identity, insurance or licence documents, and their expiry dates. These are stored outside the public web root and are never served publicly.
- Listings, prices, availability, and up to 200 photos and 6 short video reels.
- GST registration status, and payout details held by Stripe.
Technical information
- Server logs of requests, kept for diagnosis and security. These may include your IP address at the time of the request.
- Product analytics — but only if you agree. Section 5 sets out exactly what is and is not recorded.
2. What we do not collect
- Card numbers. Payments are entered on Stripe’s hosted checkout. Card details never reach our servers.
- Advertising or cross-site trackers. There are none on this service.
- Sensitive information as defined by the Privacy Act (health, racial or ethnic origin, political or religious beliefs, sexual orientation, criminal record) is not requested. Please do not include it in messages or documents.
3. How we use it
- To create and secure your account, and to verify your email and mobile are yours.
- To match briefs to suppliers, and to show prices, distances and availability.
- To take payment, hold it, release it to the supplier, and issue tax invoices.
- To send transactional messages: confirmations, reminders, delivery updates, disputes and receipts.
- To verify supplier businesses, including ABN checks and document review.
- To verify a supplier’s identity before their storefront goes live, using a government-issued ID and a selfie collected by Stripe.
- To detect and prevent fraud and misuse, and to meet our legal obligations.
We do not sell personal information, and we do not use your data to train machine-learning models. One narrow exception is described in section 4: a supplier’s own verification document may be sent to an AI service to extract fields for an administrator to check.
Identity checks and biometric information
Before a supplier’s storefront goes live, we ask them to complete an identity check run by Stripe. Stripe collects a government-issued ID and a selfie and compares them. That comparison uses biometric information, which is sensitive information under the Australian Privacy Principles, so we ask for it only from suppliers, only once, and only because a supplier can be paid from money we are holding for a customer.
Stripe also compares a selfie against others it has seen, to detect one person opening several supplier accounts under different names. We do not receive the image, the selfie or the date of birth— only whether the check passed, and the verified name, so an administrator can see it matches the business.
A failed check is never the final word.It stops a storefront going live, but a person can ask us to review it, and an administrator can verify identity by other means and record how they did so. Automated checks get things wrong — a damaged licence or a poor camera is not fraud — and a decision that stops someone trading should have a human in it.
4. Who we share it with
We share only what each provider needs. Several process data overseas, in the countries named below.
We rely on Australian Privacy Principle 8.1: before disclosing your information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, through the contractual terms of each provider. We are not relying on your consent to remove those protections, and we remain accountable for what these providers do with your information.
| Provider | Purpose | What it receives | Where |
|---|---|---|---|
| Stripe | Payments, held funds, refunds and supplier payouts | Your name, email and order amounts; suppliers give identity and bank details to Stripe directly | United States, Australia |
| Stripe Identity | Confirming a supplier is the person they say they are, before their storefront goes live and they can be paid from money we hold | A photograph of that supplier’s government-issued ID and a selfie, taken in Stripe’s own flow. We receive only the verified name — never the document image, the selfie, or the date of birth | United States, Australia |
| Resend (via Amazon SES) | Transactional email | Your email address and the message content | United States, Asia-Pacific |
| Cellcast | SMS verification codes and delivery updates | Your mobile number and the message text | Australia |
| Google (Gemini) | Reading fields from a supplier’s verification document for an administrator to check | The document that supplier uploaded | United States |
| Australian Business Register | Confirming an ABN matches the business name | The supplier’s ABN | Australia |
AI output is advisory only. It cannot approve or reject a supplier; an authorised administrator makes that decision and it is recorded.
We may also disclose information where the law requires it, or to establish or defend a legal claim.
5. Analytics and your choice
We count anonymous product events — that a signup completed, or a checkout started — so we can see which parts of the service work. This is first-party: the data goes to our own server and nowhere else.
Nothing is recorded until you choose “Allow”. Specifically:
- Before you choose, no event is sent and no identifier is created for you.
- If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as a refusal and never ask.
- If you choose “No thanks”, or later withdraw, we stop sending events and delete the random identifier from your device.
If you do agree, each event carries only:
- the event name, from a fixed published list of twenty-one;
- one value from a fixed list defined for that event — a category such as “cake”, an order status such as “delivered”, or, when you arrive through a link a supplier shared, the name of the channel it was shared on (for example “whatsapp”). Any value outside that list is recorded as “other”. Free text cannot be sent, so an email address, message or street address is structurally unable to travel this way;
- your role (customer, supplier, administrator or anonymous). Your browser does not send this; the server records it from the session the request already carries;
- a random identifier generated on your device, with no link to your account.
No IP address, browser fingerprint or page URL is stored with an analytics event.
6. Storage on your device
We use browser storage, not tracking cookies:
- Session — your sign-in credential is notstored here. It is an HttpOnly cookie, which means the page’s own JavaScript cannot read it and neither can a script injected into it. What browser storage holds is your profile for display — your name, role and verification state — so the interface can render before the server answers.
- Analytics consent — your answer, so we do not ask again.
- Analytics identifier — only if you agreed; deleted if you withdraw.
- Saved items — the suppliers and listings you have hearted.
Clearing site data in your browser removes all of these.
7. How long we keep it
- Account and order records — while your account is open, then for as long as we must keep financial records. Australian tax law generally requires five years.
- Messages — while the related conversation or order exists.
- Verification documents — while a supplier is active, and for as long as needed to show a verification decision was properly made.
- Server logs — a short operational period for diagnosis and security.
- Analytics events — aggregate product events, not tied to your identity.
8. Security
- Traffic is served over HTTPS, with a strict Content Security Policy.
- Passwords are stored as one-way hashes.
- Provider credentials are encrypted at rest and are never returned by the API.
- Verification documents sit outside the public web root and cannot be fetched by URL.
- Uploaded images are re-encoded on receipt, which removes embedded metadata such as camera EXIF and GPS location. The original file is not kept.
- Both your email and mobile must be verified before money can move.
No system is perfectly secure. If we become aware of a breach likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
9. Your rights
You may ask us to:
- give you a copy of the personal information we hold about you;
- correct anything inaccurate or out of date;
- delete your account and the information we are not required to keep;
- stop sending marketing messages — every such email carries a one-click unsubscribe link.
Transactional messages about an order you have placed are not marketing, and cannot be unsubscribed from while that order is live.
Email help@dadsorder.com. There is no charge to ask. We aim to respond within 30 days, which is the period the Australian Privacy Principles set for access requests.
Deleting your account
You can delete your account yourself from Settings. You retype the email address on the account, and we send a confirmation link that expires in an hour and works once — so a phone someone else is holding cannot destroy your account, and neither can a stale browser tab.
Deletion is refused while money is in flight: an order with funds held, or an order with a payment page that could still take a card. A held payment has two sides, and erasing one of them leaves the other with a counterparty nobody can contact or refund.
This is what is erased:
- your name, email address, phone number and street address
- your events, the briefs you posted and the answers on them, including dietary notes
- every message thread and the photographs in it
- your saved items, notifications and any sign-in codes still outstanding
- for suppliers: your storefront, listings, gallery, and every identity and compliance document you uploaded — including superseded copies — with the files themselves queued for destruction, not merely unlinked
And this is what is kept, with the reason:
- completed orders and their tax invoices, because we are required to keep financial records — with your delivery instructions, arrival notes and anything else you wrote on them removed
- the star rating and attributes you left on a review, because a supplier's rating is earned; your name and the words you wrote are removed
- the amounts and outcome of any dispute, without either side's account of it
- a one-way digest of your email and mobile, held for one purpose only: so a future marketing import cannot contact you again. It holds no name, address or profile and cannot be turned back into a contact list
Deletion cannot be undone, and we do not keep a shadow copy to restore from. If you would rather talk to a person first, email help@dadsorder.com — but the button does the same thing, immediately, without anyone reading your data to action it.
10. Complaints
If you think we have mishandled your personal information, email help@dadsorder.com with “Privacy complaint” in the subject. We will acknowledge within 5 business days and respond substantively within 30 days.
If you are not satisfied, you can refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
11. Children
DadsOrder is not intended for people under 18. If we learn we hold information about a child, we will delete it.
12. Changes
We will update the version and effective date above when this policy changes. For a change that materially affects your rights, we will tell you by email or in the app before it takes effect.
See also our Terms of Service.