Privacy Policy
This policy explains how [Business Name] collects, uses, discloses and protects your personal information when you use Pigrids, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Last updated: August 2026. This document is provided for general information and does not constitute legal advice to you.
What this means
- We collect only what we need to run your account, save your progress, and deliver tutoring.
- Your card details never touch our servers — Stripe handles payments directly.
- We use session cookies to keep you signed in — no advertising trackers, ever.
- We never sell your personal information.
- Parents and guardians can access or delete their child's data any time.
- Requests, corrections or complaints — email [email protected].
Document version: 2.0
1. Who we are & scope
Pigrids is operated by [Business Name] (ABN [ABN]) ("we", "us" or "our") at pigrids.com. This policy covers the personal information we collect through the Pigrids website, learning platform, and tutoring services, and applies wherever you interact with us. We are committed to handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You can browse our public pages without identifying yourself; an account (and therefore the personal information described below) is needed only to use the learning platform, because progress tracking is inherently tied to an identified account.
2. What we collect
We collect only what we need to run the Service:
- Account information — your name, email address, password (stored securely by our authentication provider), and year level.
- Learning data — units you complete, questions you attempt, your results, bookmarks, and where you left off, so we can save and show your progress.
- Tutoring details — contact details, preferred session times, and, for students under 18, the contact details of a parent or guardian.
- Billing metadata — your subscription tier and status, as provided to us by Stripe. Your card number and other payment card details never touch our servers — they are collected and processed directly by Stripe.
- Technical data — authentication session cookies needed to keep you signed in. We do not use advertising trackers or third-party marketing cookies of any kind.
3. Why we collect it
We use personal information to:
- provide and improve the Service, including your account and learning progress;
- process subscription billing and tutoring invoices through Stripe;
- arrange, confirm and support tutoring bookings;
- respond to your enquiries and provide support; and
- meet our legal obligations.
4. Children's data
Pigrids is directed at school-age users, some of whom are under 18. We apply data minimisation for children's information, collecting only what is needed to provide the learning experience, and we do not use children's information for advertising. Any use of the Service by a person under 18 — including creating an account — requires the knowledge and consent of a parent or legal guardian, as set out in our Terms of Service; this consent is collected as a declaration at sign-up. Tutoring for a student under 18 additionally requires the parent or guardian to make the booking and provide their own contact details for that purpose. A parent or guardian may contact us at any time to request access to, or deletion of, their child's information.
5. Disclosure
We never sell your personal information. We share personal information only with the service providers below, and only to the extent each needs it to perform its function for us:
- Stripe — processes subscription and tutoring payments (United States).
- Supabase — hosts our database and handles authentication (United States).
- Vercel — hosts the website and content delivery network (United States).
- Resend — sends transactional emails (for example, receipts and booking confirmations) (United States).
- Google — provides video-call links for online tutoring sessions (United States).
We may also disclose information where required by law.
6. Overseas disclosure
Each of the providers listed above stores or processes data on servers located outside Australia, principally in the United States. Where this happens, we take reasonable steps to ensure your information receives protection comparable to the APPs, consistent with our obligations under Australian Privacy Principle 8.
7. Marketing
We send only service emails — receipts, booking confirmations, security notices, and notices about your account or material changes to our terms. We do not send marketing email unless you have expressly opted in, and any marketing email we ever send will include a working unsubscribe link. We do not use your information for direct marketing by any other channel, and we never provide it to third parties for their marketing.
8. Security
We protect personal information using row-level security so database access is scoped to each user, encryption in transit, least-privilege service credentials, and reputable infrastructure providers. Payment card data is held and protected by Stripe under the Payment Card Industry Data Security Standard (PCI-DSS) — we never hold it ourselves. No online service can be completely secure, so we also ask you to keep your login details confidential.
9. Retention
We keep your information for as long as your account is active, and for a limited period afterwards to meet legal and operational needs, before deleting or de-identifying it. Your learning progress is deleted when you delete your account. Records we are legally required to keep — such as tax and payment transaction records — are retained for up to seven years as required by Australian law, even after account deletion.
10. Access, correction & deletion
You may request access to, correction of, or deletion of the personal information we hold about you by emailing [email protected]. We will respond within 30 days. Deletion requests are honoured except for records we are legally required to retain (see section 9); those are deleted when the retention period ends.
11. Complaints
If you have a privacy concern, contact us first at [email protected] and we will try to resolve it. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
12. Data breaches
We maintain practices to detect and respond to data breaches, and if an eligible data breach occurs we will act in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), including notifying affected individuals and the OAIC where required.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "last updated" date and, where changes are material, take reasonable steps to let you know.
14. Contact
For any privacy question or request, contact our privacy officer at [Business Name] (ABN [ABN]) via [email protected].