IMPORTANT — READ THIS PRIVACY POLICY CAREFULLY BEFORE ACCESSING OR USING THIS SAAS SERVICE. BY ACCESSING OR USING THIS SAAS SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS PRIVACY POLICY, THAT YOU UNDERSTAND IT, AND THAT YOU AGREE TO BE BOUND BY ITS TERMS. IF YOU DO NOT AGREE TO THE TERMS AND CONDITIONS OF THIS PRIVACY POLICY, PROMPTLY EXIT THIS PAGE WITHOUT ACCESSING OR USING THE SAAS SERVICE.
1. Introduction
This Privacy Policy describes how iMagic Pty Ltd ("we", "us", or "our") collects, uses, discloses, stores, and protects personal information in connection with the "Sticky Guest" SaaS service (the "Service") and related offerings. We are committed to protecting your privacy and complying with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and other applicable privacy laws. This policy is effective as of October 24, 2023, and applies to personal information we collect from or about you through the Service.
"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
2. Kinds of Personal Information We Collect and Hold
We may collect and hold the following types of personal information, depending on your interactions with us and the Service:
- Account and contact details — name, email address, phone number, organisation name, and billing address (e.g. when you create an account, subscribe, or contact support).
- Payment information — credit card details processed through secure third-party providers for subscriptions.
- Usage data — IP address, browser type, device information, login times, session activity, and interaction logs (e.g. for security, analytics, and improvements).
- User-generated content — guest details (names, contacts, preferences, check-in data) that you input or upload to the Service, which is stored on our servers.
- Sensitive information — for example, health or accessibility data for guests — only if necessary and with your explicit consent.
We do not collect personal information unless it is reasonably necessary for our functions or activities related to providing the Service.
3. How We Collect Personal Information
We collect personal information directly from you when you:
- Sign up for an account, subscribe to the Service, or log in.
- Use the Service's features, such as entering guest data or generating reports.
- Contact us via email, chat, our website, or support portals.
- Participate in webinars, surveys, or provide feedback.
We may also collect information automatically through the Service (e.g. via cookies or analytics tools) or indirectly from third parties, such as integration partners or payment processors. If you connect third-party services (e.g. payment gateways), we may receive data from them.
4. How We Hold Personal Information
Personal information is stored securely on our cloud servers located in Australia or with trusted global providers compliant with Australian privacy standards. We use industry-standard security measures, including encryption (at rest and in transit), multi-factor authentication, access controls, regular vulnerability scans, and data backups, to protect against unauthorised access, loss, misuse, or alteration. As a SaaS provider, we manage server infrastructure and apply security patches and monitoring continuously.
5. How We Use Personal Information
We use your personal information for the following purposes:
- To provide, host, maintain, and enhance the Service, including user authentication, data storage, and feature functionality.
- To process subscriptions, payments, and billing.
- To communicate with you, including service updates, security alerts, newsletters, or promotional materials (with opt-out options provided).
- To monitor and analyse usage for performance optimisation, troubleshooting, and product improvements.
- To ensure security, prevent fraud, and comply with legal obligations.
- For internal operations, such as auditing, data analysis, and research.
6. Disclosure to Third Parties
We may disclose personal information to:
- Service providers — hosting providers (e.g. AWS), payment processors (e.g. Stripe), and analytics tools (e.g. Google Analytics).
- Integration partners — if you connect to external APIs or services.
- Professional advisors — lawyers and auditors.
- Government authorities — if required by law or for legal proceedings.
Disclosures are limited to what is necessary, and we require third parties to handle data securely and in compliance with applicable laws, often through data processing agreements. We do not sell or rent your personal information to third parties.
7. Disclosure to Overseas Recipients
As a SaaS provider, we may disclose personal information to overseas recipients, such as cloud providers or support teams in the United States, European Union, or other regions with adequate data protection. Before disclosure, we take reasonable steps to ensure compliance with the APPs (e.g. via standard contractual clauses or binding corporate rules). By using the Service, you consent to such overseas transfers where necessary for service delivery.
8. Cookies and Tracking Technologies
The Service and our website use cookies, pixels, local storage, and similar technologies to remember your preferences, maintain your session, and gather analytics. You can configure your browser to refuse cookies, but doing so may affect some functionality of the Service. Where we use analytics tools such as Google Analytics, data is collected in aggregated or anonymised form wherever possible.
9. Anonymity and Pseudonymity
Where practical, you may interact with us anonymously or using a pseudonym (e.g. when making a general enquiry). However, to use the full features of the Service, you must provide accurate account information so we can provide the subscription services.
10. Your Rights — Access and Correction
Under the Australian Privacy Principles, you have the right to request access to the personal information we hold about you and to request corrections if it is inaccurate, out of date, incomplete, irrelevant, or misleading. To make a request, please contact us using the details below. We will respond within a reasonable timeframe, and in most cases within 30 days. We may need to verify your identity before providing access.
11. Complaints
If you believe we have breached the APPs or mishandled your personal information, please contact us with details of your concern. We will investigate and respond in writing within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. We will notify you of material changes by posting the updated policy on our website or by sending you an email. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions or concerns about this Privacy Policy or the way we handle your personal information, please contact us via our contact page or email us at care@stickyguest.com.