Privacy Policy

How Member Hub handles your personal information

Last updated:

Member Hub is operated by Daniel Draper, sole trader ("Member Hub", "we", "us" or "our"). This policy explains how we collect, hold, use and disclose personal information across our website, web application, mobile app, kiosks and support services. It covers members, organisation administrators, visitors, people submitting forms and people contacting us.

Personal information is information or an opinion about an identified person, or someone who can reasonably be identified. This can include technical information linked to an account or device. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth), where applicable. This policy explains our practices; using Member Hub does not, by itself, give consent to every collection or use of personal or sensitive information.

1. Member Hub and your organisation

Your organisation chooses how it uses Member Hub, which membership and operational records it maintains, and who is authorised to access them. We store and process those records to provide the service to your organisation. We also handle information for our own account administration, billing, support and security purposes.

Your organisation is responsible for explaining its own collection and use of information, providing appropriate notices and obtaining any necessary consent, including when it adds or imports records about you. Its privacy policy and recordkeeping obligations may also apply. These responsibilities do not remove our own obligations under applicable privacy law. Contact your organisation about its records or decisions, or contact us if you need help identifying the appropriate person.

2. Information we collect

The information handled depends on the features you and your organisation use. It can include:

  • Identity and contact details: names, preferred names, member numbers, email and postal addresses, phone numbers, date of birth, gender, photographs, organisation, position and emergency contact details.
  • Membership and operational records: membership status, roles, qualifications, training and competency evidence, attendance, availability, leave, time logs, event responses, bookings, equipment loans, orders and approvals.
  • Content you or others submit: forms, custom fields, comments, messages, documents, photographs, signatures and other attachments.
  • Sensitive information: medical conditions, dietary information that reveals health or religious information, or other sensitive details included in profiles, forms or supporting documents. We collect sensitive information only where reasonably necessary for the relevant service and with consent where required, or where collection is otherwise permitted or required by law. Only provide sensitive information relevant to the activity, and only provide another person's information if you are authorised to do so.
  • Account and technical information: login and authentication records, IP addresses, browser and operating system details, device and app identifiers, push notification tokens, session information, activity and audit logs, and diagnostic information about errors and performance.
  • Location information: locations entered in forms, device coordinates you choose to supply, and approximate locations derived from IP addresses.
  • Payments and enquiries: billing contacts, purchases, transaction references, payment status, support correspondence and newsletter subscriptions. Stripe processes card payments. We retain limited payment details, such as the cardholder name, card brand, last four digits, expiry and payment token; we do not store the full card number or card security code.

3. How we collect information

We collect information directly when you register, sign in, update a profile, complete a form, record an activity, send a message, upload a file, make a payment or contact us. We also receive information from your organisation, authorised members and administrators, imports, and services connected by your organisation. A record about you may therefore exist before you first sign in.

Some information is generated automatically when you use the service, including security logs, device details and message delivery or engagement records. You may contact us with a general enquiry anonymously or using a pseudonym where practicable. An identifiable account is normally needed for membership, training, attendance and other operational functions. If necessary information is not supplied, we or your organisation may be unable to provide the related feature or respond to a request.

4. How we use information

  • Provide and administer Member Hub and your organisation's membership and operational workflows.
  • Authenticate users, manage permissions, maintain audit records, prevent misuse and investigate security issues.
  • Deliver invitations, alerts, messages, reminders and other communications requested by you or your organisation.
  • Process payments, maintain billing records and respond to enquiries and support requests.
  • Diagnose faults, understand service use and improve reliability and functionality.
  • Meet legal obligations and establish, exercise or defend legal claims.

We may use aggregated or de-identified information for service reporting and planning where it does not reasonably identify you. Any direct marketing is subject to applicable consent requirements and your communication choices. We do not sell personal information.

5. Who can receive information

We disclose information as reasonably needed for the purposes described in this policy, including to:

  • Your organisation and authorised users: administrators, managers, assessors, approvers and other members according to their permissions and the relevant feature. Authorised managers in a parent or related account may have access where the organisation's account structure and permissions allow it. Directory visibility and sharing preferences affect what other members can see, but do not remove authorised administrative access.
  • Selected recipients: people your organisation sends messages, notifications, reports or exports to, including external recipients where the feature allows this. An organisation may publish selected content to an audience or share a public form link; this does not make all of its underlying member records public.
  • Service providers: providers of hosting, storage, messaging, payment processing, security, monitoring and location lookup services. These include Amazon Web Services (AWS), Postmark for email, ClickSend and telecommunications carriers for SMS, Apple for push notifications, Stripe for payments, AppSignal for diagnostics, Cloudflare for web security, IPinfo for IP-based location, and OpenStreetMap's Nominatim service for location searches. Providers receive the information needed for their function, which can include contact details, message content, attachments or technical information. Google services may also receive website technical information as described below.
  • People supporting our business: authorised personnel, contractors and professional advisers where access is needed to operate, support or protect the service.
  • Other lawful recipients: where required or authorised by law, to respond to a valid legal process, or in connection with a business transfer subject to applicable privacy obligations and appropriate confidentiality arrangements.

Your organisation may use its own provider accounts or integrations. Information exported or received by your organisation or other recipients is also subject to their handling practices. External websites and services have their own privacy policies.

6. Location and device permissions

Where a feature offers your device's current location, it requests browser or device permission. You can decline or revoke that permission in your settings. Choosing a location search or address lookup sends the search text or coordinates to our location provider to return a result. A location submitted with a form becomes part of that organisation's record and is available to users authorised to access it.

Separately, we use IP addresses to estimate location for activities such as sign-ins and time logging. This does not rely on GPS permission and may be inaccurate. Turning off device location permission does not prevent IP-based location lookup or delete previously submitted locations.

Camera or file-selection features let you scan codes or provide attachments. Push notifications use a device token and notification preferences; notification content passes through Apple's push service and may appear on your lock screen according to your device settings. You can change these permissions in your browser or device settings, although related features may then be unavailable. If you enable Face ID or Touch ID for mobile sign-in, your device performs the biometric check; Member Hub does not receive your facial or fingerprint data.

7. Cookies and communications

We use cookies and similar storage for sign-in sessions, security, preferences and remembering newsletter subscriptions. Our public website may load Google Analytics scripts, and Cloudflare security checks may process IP addresses, browser details and interaction information. Third-party scripts can receive technical information when your browser connects to them. You can manage cookies through your browser, but blocking necessary cookies may prevent sign-in or other functions.

Our public website embeds a Better Uptime status badge, and our uptime page embeds its full status page. Loading either connects your browser directly to that provider, which receives your IP address and browser request information.

Emails sent through Member Hub's messaging feature use open and link tracking. This can record whether and when an email was opened or a link was followed, alongside delivery, bounce and unsubscribe information, and make those records available to authorised message managers. Email privacy settings can affect the accuracy of this information. Blocking remote images may limit open tracking, but does not prevent link tracking.

Use the unsubscribe link where provided, adjust available notification preferences, or contact us to stop marketing from Member Hub. Contact your organisation about messages it sends. Unsubscribing from marketing does not necessarily stop essential account, security or service communications.

8. Storage and overseas processing

Our primary application hosting and storage use AWS in Sydney, Australia. This does not mean that all information remains in Australia: messaging, payments, diagnostics, security, location lookup and other providers may process information overseas.

Relevant overseas locations include the United States (including Postmark email processing), the Netherlands (AppSignal diagnostics), and the United Kingdom and the Netherlands (OpenStreetMap services). ClickSend identifies potential overseas recipients in the United States, United Kingdom, New Zealand, Brazil, Vietnam and the Philippines. International SMS delivery may also involve the recipient's country. Provider networks and support operations may involve other locations depending on the service used; contact us for information about a particular transfer.

We take reasonable steps required by applicable law to protect information disclosed overseas, including considering provider safeguards and contractual protections. Overseas processing does not remove our obligations under Australian privacy law.

9. Security and data breaches

We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include encrypted web connections, access permissions, authentication controls, logging and backups. No online service can guarantee absolute security.

If we become aware of a suspected data breach, we will investigate and take appropriate containment and response steps. We will notify affected organisations, individuals and regulators where required by applicable law, including the Notifiable Data Breaches scheme where it applies. Report a privacy concern using the contact details below; technical vulnerabilities can be reported through our Responsible Disclosure process.

10. Retention and deletion

Retention depends on the type of record, the purpose for which it is held, your organisation's recordkeeping needs, applicable service arrangements and legal obligations. Operational, training, attendance, audit and billing records may need to remain after you leave an organisation or stop using Member Hub.

Deactivating or archiving a membership, deleting an app, or removing a record from an active screen does not necessarily erase the underlying information. Some records are retained in an archived state, and copies may remain in backups, logs or exports held by your organisation. Contact us or your organisation to request deletion and to understand which records can be removed and which must be retained.

We take reasonable steps to destroy or de-identify personal information when it is no longer needed for a permitted purpose, unless retention is required by law. We assess deletion requests against these requirements rather than promising immediate removal of every copy.

11. Access, correction and choices

You can view or update some information and preferences in Member Hub. For other information, request access or correction from your organisation or from us using the contact details below. We may need to verify your identity and clarify the records requested. We will respond within a reasonable period and explain any lawful refusal and the available complaint options. There is no charge to make a request or to correct information. If a permitted charge applies to providing access, we will explain it in advance.

You can also ask about deletion, directory visibility or withdrawing consent to an optional use. Withdrawing consent does not undo earlier lawful handling, and some records may still be needed or required by law. For organisation-controlled records, we may need to coordinate with your organisation; you can still contact us directly about our handling of your information.

12. Contact and complaints

For privacy questions, access or correction requests, deletion requests, complaints, or a copy of this policy in another accessible format, contact:

Privacy contact — Daniel Draper, Member Hub
Email: privacy@memberhub.com.au
Alternatively, use our contact form.

Describe your concern, the relevant organisation or account, and how we can contact you. Please do not send passwords or unnecessary sensitive documents. We will review your complaint, seek any information needed to investigate, and explain the outcome and any proposed resolution. We aim to respond within 30 days and will let you know if more time is needed.

If you are dissatisfied with our response or have not received one within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), where the matter falls within its jurisdiction. The OAIC can also be contacted on 1300 363 992.

13. Changes to this policy

We may update this policy as the service or our practices change. The current version will be available on this page with its update date. For material changes, we will provide an appropriate notice, such as an in-service notice or email. If a new use requires consent, we will seek that consent separately.

Friendly support

We care about security & privacy