How SlateGrid handles your information
We are committed to protecting the personal information of the clubs and members who trust SlateGrid. This Privacy Policy explains how we collect, use, and safeguard data in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Who we are
SlateGrid (ABN coming soon) is operated from Adelaide, South Australia. We build membership and payments software for Australian university clubs and community organisations. You can contact us athello@slategrid.app.
2. The information we collect
We collect information so clubs can manage members and fulfil payments. This may include:
- Identification: first name, last name, email address, phone number, student number and any custom fields your club requests.
- Authentication: login email, hashed passwords, WebAuthn credentials (public key identifiers), and active session tokens.
- Membership activity: club memberships you join, forms you submit, ticket purchases, and responses to membership questions.
- Payment information: Stripe checkout identifiers, payment intent IDs, currency and amounts paid. Credit card numbers are never stored by SlateGrid.
- Technical data: device type, browser, IP address and usage timestamps captured in server logs for security and troubleshooting.
Clubs may add their own questions to membership forms. These answers are stored as part of your profile and are only visible to the club administrators who manage that membership.
3. How we collect information
We collect personal information directly from you when you:
- Create a SlateGrid account or sign in via webauthn.
- Complete a membership or event form hosted on SlateGrid.
- Purchase a membership or ticket using our Stripe-powered checkout.
- Interact with SlateGrid support, submit feedback, or respond to surveys.
We may also receive information from your club administrators, such as membership lists imported when they set up SlateGrid.
4. Why we process personal information
We use personal information to:
- Provide and maintain the SlateGrid platform, including authentication and session management.
- Facilitate membership purchases, ticketing, and digital membership passes.
- Send transactional emails and notifications related to your memberships.
- Support clubs with administration, reporting, and compliance obligations.
- Monitor for fraud, misuse, or security threats.
- Develop new features and improve the product experience.
We do not sell personal information or use it for third-party advertising. Any optional marketing communication from SlateGrid is sent on an opt-in basis and can be unsubscribed at any time.
5. Where information is stored
Data is hosted in Australia where available or in enterprise-grade data centres in the Asia Pacific region. SlateGrid uses MongoDB Atlas and other infrastructure providers located primarily in Sydney (ap-southeast-2) and Singapore (ap-southeast-1). We rely on Stripe, headquartered in the United States, to process card payments. Stripe complies with PCI DSS and maintains its own privacy program.
When information is stored or processed overseas, we take reasonable steps to ensure those providers comply with obligations equivalent to the Australian Privacy Principles.
6. Disclosure to third parties
We share personal information with:
- Club administrators and authorised committee members who manage your membership.
- Stripe, for secure payment processing.
- Email delivery partners (currently Postmark or SES) for transactional communications.
- Service providers assisting with infrastructure, logging, and error monitoring.
We may also disclose information if required by Australian law, a court order, or to prevent serious harm.
7. Security
We use encryption in transit, least-privilege access controls, audit logging, and regular security reviews. Administrators are required to use strong authentication. While no system is perfectly secure, we work continuously to mitigate risk and respond promptly to incidents.
8. Access, correction, and deletion
You can request access to the personal information we hold about you or ask for corrections if it is inaccurate, out-of-date, or incomplete. You may also request deletion of your SlateGrid account, subject to legal and contractual obligations your club may have (for example, financial record keeping).
To make a request, contact us atprivacy@slategrid.app. We aim to respond within 30 days.
9. Cookies and analytics
SlateGrid uses strictly necessary cookies to maintain authenticated sessions and protect against abuse. Optional analytics may be added in future; if we introduce analytics or marketing cookies, we will update the Cookie Policy and obtain appropriate consent.
10. Complaints
If you have concerns about how we handle your personal information, please contact us first so we can work towards a resolution. If you are not satisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
- Mail: GPO Box 5218, Sydney NSW 2001
11. Changes to this policy
We may update this Privacy Policy to reflect product changes or legal requirements. When we do, we will post the revised policy on this page and update the “Last updated” date. Significant changes will be communicated to registered users via email or in-app notice.
Last updated: 19 September 2025