Privacy Policy

Last updated: 24 December 2025

1. Introduction

BIG TOYS CLUB Pty Ltd (ABN to be registered) ("BIG TOYS CLUB", "we", "us", or "our") operates the website bigtoysclub.com and associated mobile applications (collectively, the "Platform").

We are committed to protecting your privacy and handling your personal information in an open and transparent manner. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using our Platform, you consent to the collection and use of your personal information as described in this Privacy Policy. If you do not agree with this policy, please do not use our Platform.

2. Information We Collect

2.1 Information You Provide

We collect personal information that you voluntarily provide when you:

  • Create an Account: Name, email address, phone number, password, and profile photo.
  • Register as a Yacht Owner or Host: Business name, ABN/ACN, bank account details for payments, yacht specifications, and licensing information.
  • Register as Crew: Professional qualifications, certificates of competency (COC), experience history, availability, and home location.
  • Make a Booking: Guest names, contact details, special requests, dietary requirements, and event details.
  • Complete Identity Verification: Government-issued identification documents processed through our secure third-party provider (Stripe Identity) for KYC compliance.
  • Process Payments: Payment card details (processed securely by Stripe), billing address, and transaction history.
  • Join Our Waitlist: Email address, name, phone number, user segment preferences, yacht details (for owners), and referral information.
  • Participate in Referral Program: Unique referral codes, referee names and email addresses, charter completion verification data, referral bonus payment records, and waitlist position tracking information.
  • Contact Us: Name, email address, phone number, and message content.
  • Leave Reviews: Written feedback, ratings, and any photos you upload.

2.2 Information Collected Automatically

When you use our Platform, we automatically collect:

  • Device Information: IP address, browser type and version, operating system, device type, and unique device identifiers.
  • Usage Data: Pages visited, features used, search queries, time spent on pages, and interaction patterns.
  • Location Data: Approximate location based on IP address. We only collect precise location data with your explicit consent for features like yacht search.
  • Referral Data: Marketing campaign identifiers (UTM parameters), referral codes, and referring websites.

2.3 Information from Third Parties

We may receive information about you from:

  • Social Login Providers: If you sign in using Google or other OAuth providers, we receive your name, email, and profile photo.
  • Payment Processors: Transaction status and fraud prevention data from Stripe.
  • Identity Verification Services: Verification results from Stripe Identity (we do not store copies of your ID documents).

3. How We Use Your Information

We use your personal information for the following purposes:

3.1 Providing Our Services

  • Creating and managing your account
  • Processing yacht charter bookings and payments
  • Facilitating communication between guests and yacht owners/crew
  • Verifying user identities for safety and compliance
  • Managing waitlist registrations and early access

3.2 Improving Our Platform

  • Analysing usage patterns to improve user experience
  • Developing new features and services
  • Conducting research and analytics
  • Training and improving our AI-powered search and recommendations

3.3 Communication

  • Sending booking confirmations and updates
  • Responding to enquiries and support requests
  • Sending marketing communications (with your consent, which you can withdraw at any time)
  • Providing important service announcements

3.4 Safety and Security

  • Preventing fraud, abuse, and unauthorised access
  • Enforcing our Terms of Service
  • Complying with legal obligations
  • Protecting the rights and safety of users

4. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

4.1 Essential Cookies

Required for the Platform to function properly, including authentication, security, and session management. These cannot be disabled.

4.2 Analytics Cookies

We use analytics services to understand how visitors use our Platform:

  • Plausible Analytics: A privacy-focused analytics service that does not use cookies or collect personal data.
  • Google Analytics 4: Used for detailed analytics with IP anonymisation enabled. You can opt out using browser settings or the Google Analytics Opt-out Browser Add-on.

4.3 Your Cookie Choices

You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect Platform functionality. We honour "Do Not Track" browser signals.

5. How We Share Your Information

We do not sell, trade, or rent your personal information to third parties for marketing purposes. We may share your information in the following circumstances:

5.1 With Other Users

  • Guests: Yacht owners and crew can see guest names and contact details for confirmed bookings.
  • Yacht Owners/Hosts: Guests can see host profiles, yacht details, and reviews.
  • Public Profiles: Your display name, profile photo, and reviews may be visible to other users.

5.2 With Service Providers

We share information with trusted third-party service providers who assist us in operating our Platform:

  • Stripe: Payment processing and identity verification (USA-based with Australian data processing)
  • Amazon Web Services: Cloud hosting and email delivery (with Australian region options)
  • Neon: Database hosting (with Australian region options)
  • Sentry: Error monitoring and performance tracking
  • Voyage AI / OpenAI: AI-powered search and recommendations

5.3 For Legal Reasons

We may disclose your information when required to:

  • Comply with applicable laws, regulations, or legal processes
  • Respond to lawful requests from government authorities
  • Protect our rights, privacy, safety, or property
  • Investigate potential violations of our Terms of Service

5.4 Business Transfers

If BIG TOYS CLUB is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

6. Cross-Border Data Transfers

Some of our service providers are located outside Australia, including in the United States. When we transfer your personal information overseas, we take reasonable steps to ensure that the recipient handles your information in accordance with the APPs and this Privacy Policy.

By using our Platform, you consent to the transfer of your personal information to countries outside Australia where our service providers are located.

7. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication with password hashing
  • Regular security assessments and monitoring
  • Access controls limiting data access to authorised personnel
  • Secure payment processing through PCI-DSS compliant providers

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

8. Data Retention

We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, including:

  • Active Accounts: While your account remains active and for a reasonable period afterward.
  • Transaction Records: Seven (7) years for tax and accounting compliance.
  • Legal Compliance: As required by applicable laws or to resolve disputes.
  • Anonymised Data: We may retain anonymised, aggregated data indefinitely for analytics purposes.

When your information is no longer needed, we securely delete or anonymise it.

9. Your Rights

Under the Privacy Act 1988 and the APPs, you have the following rights regarding your personal information:

9.1 Access

You have the right to request access to the personal information we hold about you. We will respond to your request within a reasonable timeframe.

9.2 Correction

You can request that we correct any inaccurate or incomplete personal information. You can also update your account information directly through your profile settings.

9.3 Deletion

You can request that we delete your personal information, subject to legal retention requirements. Account deletion can be initiated through your account settings or by contacting us.

9.4 Marketing Opt-Out

You can opt out of marketing communications at any time using either method:

  • Click the "Unsubscribe" link at the bottom of any marketing email we send you
  • Log in to your account and update your communication preferences in Account Settings

Please note that even if you opt out of marketing communications, we will still send you essential service-related emails (booking confirmations, account notifications, legal updates) as these are necessary for operating your account.

9.5 Complaints

If you believe we have breached the APPs, you can lodge a complaint with us. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

10. Children's Privacy

Our Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.

11. Third-Party Links

Our Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by:

  • Posting the updated policy on our Platform
  • Updating the "Last updated" date at the top of this page
  • Sending you an email notification (for material changes)

Your continued use of the Platform after any changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

BIG TOYS CLUB Pty Ltd

Email: privacy@bigtoysclub.com

We aim to respond to all enquiries within 30 days.