Privacy Policy

Privacy Policy - Flowfetti Pty Ltd

Flowfetti Pty Ltd ACN 701 735 597 ABN 83 701 735 597 (Flowfetti, we, us or our) takes your privacy seriously. Please read this Privacy Policy carefully as it contains important information about who we are, how and why we collect, store, use and share your personal information, your rights in relation to your personal information, and how to contact us or a supervisory authority if you have a complaint.

Last updated: 19 September 2026

1. Key terms

1.1In this Privacy Policy:

·we, us and our means Flowfetti Pty Ltd ACN 701 735 597 ABN 83 701 735 597.

·personal information means any information relating to an identified or identifiable individual.

·special category personal information means personal information revealing racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs or trade union membership, genetic and biometric data, and data concerning health, sex life or sexual orientation.

·Privacy Officer means the person responsible for privacy matters at Flowfetti, contactable at privacy@flowfetti.com.

2. Application of privacy laws

2.1Flowfetti is an Australian company based in New South Wales. We handle personal information in accordance with applicable privacy and data protection laws. These may include the Privacy Act 1988 (Cth) and the Australian Privacy Principles; the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth); the General Data Protection Regulation of the European Union (EU GDPR), where applicable; the United Kingdom General Data Protection Regulation (UK GDPR), where applicable; and applicable United States privacy laws, including the California Consumer Privacy Act of 2018 (CCPA), where applicable.

2.2Where the Privacy Act 1988 (Cth) does not apply to a particular act or practice, we will take reasonable steps to handle personal information consistently with the standards described in this Privacy Policy.

2.3For the purposes of the EU GDPR or UK GDPR, where either law applies, Flowfetti is generally the controller of personal information collected directly through the Flowfetti website and platform. In some circumstances, including where instructors enter personal information about students or clients into the platform, Flowfetti may process that information on behalf of the relevant instructor or organisation. The relevant instructor or organisation may be the controller of that information.

2.4You may contact us about privacy matters at privacy@flowfetti.com.

3. Personal information we collect

3.1We may collect and use the following categories of personal information:

·Identifiers - names; business and trading names; email addresses; telephone numbers; postal and billing addresses; account names; IP addresses; IP-derived country; Flowfetti/Supabase user UUIDs; authentication and session identifiers; security-cookie identifiers; analytics and device identifiers; Stripe customer, subscription, account, payment-method and invoice identifiers; card fingerprints supplied by Stripe; referral codes; public-profile tokens; class-plan and teaching-view tokens; student feedback and unsubscribe tokens; invoice numbers; internal record, audit and diagnostic identifiers. Flowfetti does not intentionally collect social security, driver's licence or passport numbers.

·Personal details - names and contact details; addresses and telephone numbers; ABN, GST, VAT or other tax numbers; tax-registration status; country, currency and time zone; business details; payment and remittance instructions, which may contain a user's bank-account information; invoice, payment and transaction information; account-security and multi-factor authentication status; user-entered class content, activities, plans, schedules and notes; student and client information; student ratings, mood, effort, comments, testimonials, requests and consent records; support correspondence; authorised support-access records; security and audit logs. Flowfetti does not directly store complete card numbers, CVCs, clients' bank details, medical information or health-insurance information.

·Commercial information - subscription plan, price and status; trial eligibility; subscription start, renewal and cancellation information; products, features and services purchased, obtained, used or considered; Stripe checkout and billing records; payment status and history; referral participation and credits; invoices, invoice line items, amounts, tax, currency, due dates and payment dates; recurring billing schedules; client billing rates, payment terms and cadence; online payment links; receipts and overdue-reminder history.

·Internet and network activity - IP address; IP-derived country; browser, device and operating-system information; authentication and session activity; pages and screens viewed; page-view events; interactions with the website and application; features used; plans generated; invoices sent; classes marked as taught; account and subscription activity; referral interactions; email delivery, bounce and unsubscribe information; dates and timestamps; error reports; diagnostic and technical-performance data; and product-usage events collected through providers such as Vercel Analytics, PostHog, Sentry and Supabase. PostHog session recording and automatic interaction capture are currently disabled.

·Professional information - professional name; business and trading names; occupation or teaching discipline; professional headline and biography; qualifications, certifications, credentials and training; employment and teaching history; professional experience; prior classes taught; years or period of experience; availability; public professional contact email; booking URL; client, studio, school or organisation relationships; class formats; professional testimonials; business tax information; and statistics selected for inclusion in a professional profile or Value Report.

·Education information - qualifications; professional certifications; training courses completed; educational or professional credentials; teaching disciplines and areas of expertise; institutions or training providers attended; dates or periods of study or training; and teaching and employment history entered in a professional profile.

·Inferences - operational inferences about preferred class formats, activities, levels, focus areas, schedules, invoice settings, payment terms, reminder preferences, currency and time zone; frequency of product and feature use; completion of activation events; subscription and feature eligibility; trial or possible duplicate-trial activity; referral or possible self-referral eligibility; overdue invoice status; scheduled automation requirements; generated class plans based on the user's library and selected settings; and aggregate teaching, invoicing, income and student-engagement statistics. Flowfetti does not intentionally infer psychological trends, intelligence, personality, medical status or other sensitive characteristics.

3.2The personal information described above is required to provide the Flowfetti platform and services to you. If you do not provide personal information we ask for, it may delay or prevent us from providing products or services to you.

3.3Flowfetti is an administrative tool for instructors and education businesses. The platform is not designed to collect, store or process health, medical or other special-category personal information. Users must not enter health, medical, biometric or other special-category personal information about themselves or any other person into the platform. If Flowfetti becomes aware that special-category personal information has been entered, it may be deleted without notice.

4. How we collect personal information

4.1We collect personal information:

·directly from you when you create or use an account, subscribe, contact us, complete a profile, create a class plan, issue an invoice, provide feedback or otherwise use the website or platform;

·automatically through the website and platform, including through cookies, authentication systems, security logs, analytics, error-monitoring and similar technologies;

·from payment, authentication, hosting, analytics, communications and other service providers involved in operating the platform;

·from another user, such as an instructor, studio, school or organisation, where that user enters information about a student, client, worker or other person into the platform;

·from publicly available sources where reasonably necessary for the operation, security or administration of our services; and

·from another source where you have consented to the collection or where the collection is authorised or required by law.

4.2If another user provides us with your personal information, that user is responsible for having a lawful basis for doing so and for giving you any notice required by applicable law.

4.3Flowfetti does not independently perform credit checks, sanctions screening or customer due-diligence checks on users. However, Stripe and other payment providers we use may perform identity verification, fraud detection, know-your-customer, anti-money-laundering and sanctions checks as required by applicable financial services laws. Those checks are conducted by the relevant payment provider under its own terms and privacy policy.

4.4You may choose not to provide personal information requested by us. However, this may prevent or delay us from creating your account, processing payment, providing a feature, responding to your request or otherwise supplying the relevant service.

5. How and why we use your personal information

5.1Under applicable data protection law, we may only use your personal information if we have a proper reason for doing so. Those reasons include: to comply with our legal and regulatory obligations; for the performance of our contract with you or to take steps at your request before entering into a contract; for our legitimate interests or those of a third party, where those interests are not overridden by your rights and interests; or where you have given consent.

5.2The table below explains what we use your personal information for and our reasons for doing so:

PurposeLawful basis
To provide products or services to youPerformance of our contract with you
To prevent and detect fraud against you or FlowfettiLegitimate interests: to minimise fraud that could be damaging for us and for you
Verifying user identity and account eligibilityLegal and regulatory obligations; legitimate interests: to protect the security and integrity of the platform
Other processing necessary to comply with professional, legal and regulatory obligationsLegal and regulatory obligations
Gathering and providing information required by or relating to audits, enquiries or investigations by regulatory bodiesLegal and regulatory obligations
Ensuring business policies are adhered to, including policies covering security and internet useLegitimate interests: to make sure we are following our own internal procedures
Operational reasons, such as improving efficiency, training and quality controlLegitimate interests: to be as efficient as we can
Ensuring the confidentiality of commercially sensitive informationLegitimate interests: to protect trade secrets and other commercially valuable information; legal and regulatory obligations
Statistical analysis to help us manage our businessLegitimate interests: to be as efficient as we can
Preventing unauthorised access and modifications to systemsLegitimate interests: to prevent and detect criminal activity; legal and regulatory obligations
Updating and enhancing customer recordsPerformance of our contract with you; legal and regulatory obligations; legitimate interests: keeping in touch about existing orders and new products
Statutory returnsLegal and regulatory obligations
Ensuring safe working practices, staff administration and assessmentsLegal and regulatory obligations; legitimate interests: following our own internal procedures
Sending promotional communications to existing and former customers and to persons who have previously expressed an interest in our services, where permitted by applicable lawLegitimate interests: to promote our business, subject to consent where required
External audits and quality checksLegitimate interests: to maintain our accreditations; legal and regulatory obligations

5.3The table in clause 5.2 does not apply to special category personal information. As noted in clause 3.3, users must not enter special-category personal information into the platform.

6. Promotional and operational communications

6.1Flowfetti sends two types of email:

·Promotional emails - messages about new features, offers, tips, referral programmes and other marketing content. These are commercial electronic messages for the purposes of the Spam Act 2003 (Cth) and require consent and an unsubscribe facility.

·Operational emails - messages that are necessary to provide the service, including account creation and verification, subscription confirmations, billing receipts, payment failures, overdue invoice reminders sent on your behalf, password resets, security alerts, scheduled maintenance notices and other purely transactional or administrative messages. These messages do not contain promotional content and are not subject to the unsubscribe requirement under the Spam Act 2003 (Cth). You will continue to receive operational emails while you hold an account with us.

6.2We will only send promotional emails where we have your express or inferred consent as required by the Spam Act 2003 (Cth). We will record the basis and timing of consent. Where consent is required and has not been obtained, we will not send promotional emails.

6.3Certain automated emails relate to your use of the platform, such as onboarding sequences, feature-adoption prompts, re-engagement messages and referral invitations. Where these messages contain promotional content, they are treated as promotional emails under clause 6.1(a) and require consent. Where they are purely informational and relate to your existing account or subscription, they are treated as operational emails under clause 6.1(b).

6.4You may opt out of promotional emails at any time by selecting the unsubscribe link in the email, or by emailing privacy@flowfetti.com. We will process your unsubscribe request within five business days as required by the Spam Act 2003 (Cth). Unsubscribing from promotional emails will not affect operational emails described in clause 6.1(b).

6.5When you unsubscribe, we will add your email address to our suppression list and will not send further promotional emails to that address. We retain suppression records for as long as necessary to honour your opt-out, including after account closure.

6.6We may ask you to confirm or update your marketing preferences if you instruct us to provide further products or services, or if there are changes in applicable law or the structure of our business.

6.7We do not sell personal information for monetary consideration. We do not disclose personal information to third parties for their own independent direct-marketing purposes without the consent required by applicable law.

7. Who we share your personal information with

7.1We routinely share personal information with:

·service providers we use to help deliver our products or services to you, such as payment service providers, hosting providers and communications platforms;

·other third parties we use to help us run our business, such as analytics, security, error-monitoring and email service providers;

·third parties approved by you, including social media sites you choose to link your account to or third-party payment providers;

·our insurers and brokers; and

·our bank.

7.2We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you.

7.3We may share personal information with external auditors in relation to the audit of our accounts or applicable accreditation requirements.

7.4We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.

7.5We may need to share some personal information with other parties, such as potential buyers of some or all of our business or during a restructuring. We will typically anonymise information, but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.

7.6We will not share your personal information with any other third party except as described in this Privacy Policy or as required or permitted by law.

8. Overseas processing and data location

8.1Flowfetti's primary application data, including its production database, is stored in Sydney, Australia.

8.2Certain personal information is also stored or processed outside Australia by the service providers described in clause 8.4. The countries involved depend on the provider, the feature used and the provider's own infrastructure and approved subprocessors.

8.3There is a distinction between where data is stored and where it may be accessed. Storage refers to where data is held at rest by a provider's infrastructure. Access refers to where provider personnel, automated systems or subprocessors may retrieve or process data for support, security, maintenance, service delivery or incident response. Access may occur from countries other than the country of storage.

8.4The categories of overseas service providers that may process personal information, and the countries or regions in which they are likely to be located, are:

·Hosting, database and authentication: primarily Sydney, Australia, with support and infrastructure access from other countries, and static assets served from global content-delivery edge nodes.

·Payment processing and billing: Australia, Ireland and the United States, and potentially other locations depending on transaction routing and applicable financial services requirements. These providers may perform identity, fraud, know-your-customer, anti-money-laundering and sanctions checks as required by law.

·Email delivery: email despatched from Japan; account and log data held in the United States.

·Product analytics and error monitoring: the European Union, with support and infrastructure access from other countries.

·Business communications and document storage: Australia and/or the United States, depending on tenant configuration and data residency settings.

·Source code hosting and development workflows: United States. These systems hold application code rather than customer records, and automated workflow logs must not contain sensitive personal data.

·Uptime monitoring: United States. These systems observe public endpoints only and do not receive application data or authenticated user content.

8.4AEach provider may engage approved subprocessors whose locations are described in that provider's own privacy and subprocessor documentation. Access by a provider's support or infrastructure teams may occur from countries other than the country of storage. You may contact privacy@flowfetti.com for the identity of the providers currently used in any category.

8.5We will update the list in clause 8.4 when we add or remove a category of service provider, or when the countries or regions for a category materially change. We will notify you of material changes in accordance with clause 19.

8.6Before disclosing personal information to an overseas recipient, we take reasonable steps required by applicable law to protect the information. These steps may include assessing the provider's privacy and security practices; entering into contractual privacy, confidentiality and security obligations; limiting access to what is reasonably necessary; applying appropriate technical and organisational security measures; and using approved international transfer mechanisms where the EU GDPR or UK GDPR applies.

8.7Where the Australian Privacy Principles apply, we take reasonable steps to ensure that an overseas recipient does not breach the Australian Privacy Principles in relation to personal information disclosed by us, subject to any applicable legal exception. In some circumstances, we may remain accountable under Australian law for the overseas recipient's handling of that information.

8.8Where the EU GDPR or UK GDPR applies, we use a lawful transfer mechanism where required. This may include an adequacy decision, approved standard contractual clauses, the United Kingdom International Data Transfer Agreement or Addendum, or another mechanism permitted by applicable law.

8.9You may contact privacy@flowfetti.com for further information about the countries in which your personal information is likely to be processed and the safeguards used for international transfers.

9. How long your personal information will be kept

9.1We will keep your personal information while you have an account with us or while we are providing products or services to you. Thereafter, we will keep your personal information for as long as is necessary to respond to any questions, complaints or claims made by you or on your behalf; to show that we treated you fairly; or to keep records required by law.

9.2We will not retain your personal information for longer than necessary for the purposes set out in this Privacy Policy. Different retention periods apply for different types of personal information.

9.3When it is no longer necessary to retain your personal information, we will delete or anonymise it.

10. Data security and data breaches

10.1We take reasonable technical and organisational measures to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.

10.2These measures may include access controls based on business need; authentication and session-security controls; encryption where appropriate; logging, monitoring and error detection; secure hosting and service-provider controls; confidentiality obligations for personnel and contractors; backup, recovery and incident-response procedures; and periodic review of access, security settings and material service providers.

10.3No internet transmission or electronic storage system is completely secure. We cannot guarantee absolute security, but we will take reasonable steps appropriate to the nature of the information and the risks involved.

10.4We maintain procedures for identifying, containing, investigating and responding to suspected data breaches. We will assess a suspected breach under applicable law and take reasonable steps to limit harm and prevent recurrence.

10.5If a breach is an eligible data breach under the Privacy Act 1988 (Cth), we will notify the Office of the Australian Information Commissioner and affected individuals where required by the Notifiable Data Breaches scheme.

10.6Where the EU GDPR, UK GDPR or another applicable law imposes additional breach-reporting obligations, we will notify the relevant regulator and affected individuals within the period and in the circumstances required by that law.

10.7You should report any suspected unauthorised access to your account or personal information promptly to privacy@flowfetti.com.

11. Australian privacy rights and complaints

11.1Subject to applicable law, you may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

11.2You may also ask us to:

·explain how we collected, used or disclosed your personal information;

·stop sending direct marketing communications;

·correct your marketing preferences;

·delete or anonymise information where we are not legally or operationally required to retain it; or

·address a concern about how we have handled your personal information.

11.3Some rights depend on the law that applies to you. We may decline or limit a request where permitted or required by law. If we do so, we will generally provide our reasons and explain any available complaint process.

11.4To make a request or complaint, contact Flowfetti Pty Ltd at privacy@flowfetti.com or via www.flowfetti.com.

11.5Please provide enough information for us to identify you, understand your request and locate the relevant information. We may take reasonable steps to verify your identity before granting access or making a change. We will not normally require copies of identity documents unless they are reasonably necessary, and we will handle any verification information only for verification, security and legal compliance purposes.

11.6We will acknowledge a privacy complaint and aim to provide a substantive response within 30 days. If we require more time because of the complexity of the matter, we will tell you why and provide an updated timeframe.

11.7If you are not satisfied with our response to an Australian privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner through www.oaic.gov.au.

12. Your rights under the EU GDPR and UK GDPR

12.1Where the EU GDPR or UK GDPR applies to our processing of your personal information, you may have the following rights:

·Right to access: the right to be provided with a copy of your personal information.

·Right to rectification: the right to require us to correct any mistakes in your personal information.

·Right to erasure: the right to require us to delete your personal information in certain situations.

·Right to restriction of processing: the right to require us to restrict processing of your personal information in certain circumstances, for example if you contest the accuracy of the data.

·Right to data portability: the right to receive the personal information you provided to us in a structured, commonly used and machine-readable format and to transmit that data to a third party in certain situations.

·Right to object: the right to object at any time to your personal information being processed for direct marketing (including profiling), and in certain other situations to our continued processing of your personal information.

·Right not to be subject to automated individual decision-making: the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.

12.2For further information on each of those rights, including the circumstances in which they apply, see the guidance from the UK Information Commissioner's Office on individual rights under the General Data Protection Regulation.

12.3To exercise any of these rights, contact privacy@flowfetti.com.

13. GDPR and UK GDPR representatives

13.1Flowfetti is established in Australia and does not currently have an establishment in the European Economic Area or the United Kingdom.

13.2We periodically assess whether our activities are subject to the EU GDPR or UK GDPR, including whether we offer goods or services to individuals in those locations or monitor their behaviour there.

13.3If applicable law requires us to appoint a representative in the European Economic Area or the United Kingdom, we will make that appointment and publish the representative's name and contact details in this Privacy Policy.

13.4Until representative details are published, questions concerning the EU GDPR or UK GDPR may be directed to privacy@flowfetti.com. This contact arrangement does not replace a representative where appointment is legally required.

14. California privacy disclosures

14.1We do not sell personal information for monetary consideration.

14.2We may disclose personal information to service providers and contractors for business purposes, including hosting, authentication, payment processing, analytics, security, error monitoring, communications and customer support.

14.3Some United States privacy laws define "sale", "sharing" or similar terms more broadly than a transfer for money. If our use of advertising, analytics or other technologies constitutes a sale or sharing under applicable law, eligible users may exercise an opt-out right by contacting privacy@flowfetti.com.

14.4The categories of personal information disclosed for business purposes are limited to the categories reasonably required for the applicable service. We do not knowingly sell or share the personal information of persons under 16 years of age.

14.5You have the right under the CCPA and certain other privacy and data protection laws, as applicable, to exercise free of charge:

·Disclosure: the right to know the categories of personal information we have collected about you, the categories of sources from which it was collected, our business or commercial purpose for collecting it, the categories of third parties with whom we share it, and the specific pieces of personal information we have collected about you.

·Deletion: the right to request deletion of your personal information from our records and to direct our service providers to delete it from their records, subject to certain exceptions permitted by law.

·Opt-out of sale or sharing: the right to opt out of the sale or disclosure of your personal information.

·Non-discrimination: the right not to be discriminated against because you exercised any of your rights under the CCPA.

14.6To exercise your CCPA rights, contact privacy@flowfetti.com. Please note that you may only make a data access or data portability disclosure request twice within a 12-month period. We are not obligated to make a disclosure if we cannot verify that the person making the request is the person about whom we collected information, or is someone authorised to act on that person's behalf.

14.7Any personal information we collect from you to verify your identity in connection with your request will be used solely for the purposes of verification.

15. Automated decisions

15.1We use automated systems to support functions such as generating class plans, identifying subscription or feature eligibility, identifying possible duplicate trials or referrals, scheduling reminders and producing platform statistics.

15.2Unless expressly stated at the point of use, we do not use personal information in a solely automated decision that produces legal effects or similarly significant effects concerning an individual.

15.3If we introduce automated decision-making that has legal or similarly significant effects, we will update this Privacy Policy and provide any information, safeguards and rights required by applicable law.

16. Keeping your personal information secure

16.1We have appropriate security measures in place to prevent personal information from being accidentally lost or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

16.2We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

17. How to exercise your rights

17.1If you would like to exercise any of your rights as described in this Privacy Policy, please email us at privacy@flowfetti.com.

17.2If you choose to contact us by email, please provide:

·enough information to identify you, such as your full name, address and account or reference number;

·proof of your identity and address if reasonably required; and

·a description of the right you want to exercise and the information to which your request relates.

17.3We are not obligated to make a data access or data portability disclosure if we cannot verify that the person making the request is the person about whom we collected information, or is someone authorised to act on that person's behalf.

17.4Any personal information we collect from you to verify your identity in connection with your request will be used solely for the purposes of verification.

18. How to file a GDPR complaint

18.1We hope that our Privacy Officer can resolve any query or concern you raise about our use of your information.

18.2The EU GDPR and UK GDPR also give you the right to lodge a complaint with a supervisory authority in the European Union or European Economic Area state where you work, normally live, or where any alleged infringement of data protection laws occurred.

19. Changes to this Privacy Policy

19.1This Privacy Policy was last updated on 19 September 2026.

19.2We may change this Privacy Policy from time to time. When we do, we will inform you by posting an updated version on the Flowfetti website with a revised "last updated" date. Where changes are material, we will provide notice via email or a prominent notice on the platform.

20. How to contact us

20.1Please contact us or our Privacy Officer if you have any questions about this Privacy Policy or the information we hold about you.

20.2We may be contacted at privacy@flowfetti.com. Our Privacy Officer may also be contacted at the same address.

Flowfetti Pty Ltd · ACN 701 735 597 · ABN 83 701 735 597