Privacy Policy
Last updated: 24 December 2025
1. Introduction
BIG TOYS CLUB Pty Ltd (ABN to be registered) ("BIG TOYS CLUB", "we", "us", or "our") operates the website bigtoysclub.com and associated mobile applications (collectively, the "Platform").
We are committed to protecting your privacy and handling your personal information in an open and transparent manner. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using our Platform, you consent to the collection and use of your personal information as described in this Privacy Policy. If you do not agree with this policy, please do not use our Platform.
2. Information We Collect
2.1 Information You Provide
We collect personal information that you voluntarily provide when you:
- Create an Account: Name, email address, phone number, password, and profile photo.
- Register as a Yacht Owner or Host: Business name, ABN/ACN, bank account details for payments, yacht specifications, and licensing information.
- Register as Crew: Professional qualifications, certificates of competency (COC), experience history, availability, and home location.
- Make a Booking: Guest names, contact details, special requests, dietary requirements, and event details.
- Complete Identity Verification: Government-issued identification documents processed through our secure third-party provider (Stripe Identity) for KYC compliance.
- Process Payments: Payment card details (processed securely by Stripe), billing address, and transaction history.
- Join Our Waitlist: Email address, name, phone number, user segment preferences, yacht details (for owners), and referral information.
- Participate in Referral Program: Unique referral codes, referee names and email addresses, charter completion verification data, referral bonus payment records, and waitlist position tracking information.
- Contact Us: Name, email address, phone number, and message content.
- Leave Reviews: Written feedback, ratings, and any photos you upload.
2.2 Information Collected Automatically
When you use our Platform, we automatically collect:
- Device Information: IP address, browser type and version, operating system, device type, and unique device identifiers.
- Usage Data: Pages visited, features used, search queries, time spent on pages, and interaction patterns.
- Location Data: Approximate location based on IP address. We only collect precise location data with your explicit consent for features like yacht search.
- Referral Data: Marketing campaign identifiers (UTM parameters), referral codes, and referring websites.
2.3 Information from Third Parties
We may receive information about you from:
- Social Login Providers: If you sign in using Google or other OAuth providers, we receive your name, email, and profile photo.
- Payment Processors: Transaction status and fraud prevention data from Stripe.
- Identity Verification Services: Verification results from Stripe Identity (we do not store copies of your ID documents).
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Providing Our Services
- Creating and managing your account
- Processing yacht charter bookings and payments
- Facilitating communication between guests and yacht owners/crew
- Verifying user identities for safety and compliance
- Managing waitlist registrations and early access
3.2 Improving Our Platform
- Analysing usage patterns to improve user experience
- Developing new features and services
- Conducting research and analytics
- Training and improving our AI-powered search and recommendations
3.3 Communication
- Sending booking confirmations and updates
- Responding to enquiries and support requests
- Sending marketing communications (with your consent, which you can withdraw at any time)
- Providing important service announcements
3.4 Safety and Security
- Preventing fraud, abuse, and unauthorised access
- Enforcing our Terms of Service
- Complying with legal obligations
- Protecting the rights and safety of users
4. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
4.1 Essential Cookies
Required for the Platform to function properly, including authentication, security, and session management. These cannot be disabled.
4.2 Analytics Cookies
We use analytics services to understand how visitors use our Platform:
- Plausible Analytics: A privacy-focused analytics service that does not use cookies or collect personal data.
- Google Analytics 4: Used for detailed analytics with IP anonymisation enabled. You can opt out using browser settings or the Google Analytics Opt-out Browser Add-on.
4.3 Your Cookie Choices
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect Platform functionality. We honour "Do Not Track" browser signals.
5. How We Share Your Information
We do not sell, trade, or rent your personal information to third parties for marketing purposes. We may share your information in the following circumstances:
5.1 With Other Users
- Guests: Yacht owners and crew can see guest names and contact details for confirmed bookings.
- Yacht Owners/Hosts: Guests can see host profiles, yacht details, and reviews.
- Public Profiles: Your display name, profile photo, and reviews may be visible to other users.
5.2 With Service Providers
We share information with trusted third-party service providers who assist us in operating our Platform:
- Stripe: Payment processing and identity verification (USA-based with Australian data processing)
- Amazon Web Services: Cloud hosting and email delivery (with Australian region options)
- Neon: Database hosting (with Australian region options)
- Sentry: Error monitoring and performance tracking
- Voyage AI / OpenAI: AI-powered search and recommendations
5.3 For Legal Reasons
We may disclose your information when required to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from government authorities
- Protect our rights, privacy, safety, or property
- Investigate potential violations of our Terms of Service
5.4 Business Transfers
If BIG TOYS CLUB is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
6. Cross-Border Data Transfers
Some of our service providers are located outside Australia, including in the United States. When we transfer your personal information overseas, we take reasonable steps to ensure that the recipient handles your information in accordance with the APPs and this Privacy Policy.
By using our Platform, you consent to the transfer of your personal information to countries outside Australia where our service providers are located.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication with password hashing
- Regular security assessments and monitoring
- Access controls limiting data access to authorised personnel
- Secure payment processing through PCI-DSS compliant providers
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
8. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, including:
- Active Accounts: While your account remains active and for a reasonable period afterward.
- Transaction Records: Seven (7) years for tax and accounting compliance.
- Legal Compliance: As required by applicable laws or to resolve disputes.
- Anonymised Data: We may retain anonymised, aggregated data indefinitely for analytics purposes.
When your information is no longer needed, we securely delete or anonymise it.
9. Your Rights
Under the Privacy Act 1988 and the APPs, you have the following rights regarding your personal information:
9.1 Access
You have the right to request access to the personal information we hold about you. We will respond to your request within a reasonable timeframe.
9.2 Correction
You can request that we correct any inaccurate or incomplete personal information. You can also update your account information directly through your profile settings.
9.3 Deletion
You can request that we delete your personal information, subject to legal retention requirements. Account deletion can be initiated through your account settings or by contacting us.
9.4 Marketing Opt-Out
You can opt out of marketing communications at any time using either method:
- Click the "Unsubscribe" link at the bottom of any marketing email we send you
- Log in to your account and update your communication preferences in Account Settings
Please note that even if you opt out of marketing communications, we will still send you essential service-related emails (booking confirmations, account notifications, legal updates) as these are necessary for operating your account.
9.5 Complaints
If you believe we have breached the APPs, you can lodge a complaint with us. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
10. Children's Privacy
Our Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
11. Third-Party Links
Our Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by:
- Posting the updated policy on our Platform
- Updating the "Last updated" date at the top of this page
- Sending you an email notification (for material changes)
Your continued use of the Platform after any changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
BIG TOYS CLUB Pty Ltd
Email: privacy@bigtoysclub.com
We aim to respond to all enquiries within 30 days.