Privacy & data

Small data footprint.
Clear family control.

Vuni is a family activity directory for web and mobile. Child profiles use a nickname and age only, account data is protected by signed-in access controls, and referral reporting records only the source of an outbound provider link.

Current privacy levelEnhanced child-safe · account deletion in app and web
PRIVACY POLICY · PROTOTYPE

Effective 7 August 2026

1. Who this policy covers

This policy describes the Vuni Northern Rivers prototype and applies to families, adult parents or carers, and activity providers who use it. Vuni’s legal operator name, ABN (if applicable), street address and monitored privacy email have not yet been established.

Launch requirement

The legal operator and monitored privacy contact must be published before broader production promotion or provider outreach.

2. What data is handled now

Family profile information

On the web, child profiles and planning preferences may be stored in the browser. In the mobile app, a signed-in adult may synchronise a child nickname, age, interests and availability through Vuni’s protected database. Vuni does not require a child account, full legal name, exact birth date, home address or school.

Provider workspace information

A provider claim may include a business name, adult contact name and work email, role, activity details, location, age range, schedule, website and practical booking information. Submitted claims are stored in the secure provider workspace so the provider can return to them and Vuni can review changes before publication.

Stripe Connect information

If an approved provider chooses to connect payouts, Stripe collects and verifies its identity, business and bank-account information on Stripe’s hosted pages. Vuni stores the connected Stripe account identifier, onboarding and payout status, outstanding requirement labels, and update times. Vuni does not receive or store the provider’s bank account number, BSB, identity documents or Stripe password.

Referral source records

When someone follows a provider booking link, Vuni records a random event number, the relevant provider or claim, whether the link began in the Vuni directory or one of the provider’s own tracked links, the provider-selected channel, destination and time. The referral record does not contain the family’s name, email, child profile or payment information, and no analytics cookie is set.

Directory and technical information

The prototype displays provider information sourced from public provider or government websites. Like most websites, the hosting platform may also process request data needed to deliver and protect the site, such as IP address, browser information, requested page, timestamps, security events and short-lived operational logs. Vuni does not use that data for advertising or behavioural profiles.

3. Why data is used

Device-only information is used to rank directory activities for a family. Provider workspace data is used to verify ownership, review requested changes and publish confirmed information. Stripe Connect status is used to show whether an approved provider can accept payments and receive payouts. Minimal referral records let providers see whether an outbound journey began in the directory or through their own promotion and provide evidence for any future attribution-based fee. Technical data is processed to deliver, secure, troubleshoot and prevent misuse of the site.

4. Children’s privacy

Vuni applies an enhanced child-safe standard because the service concerns children’s activities. Child profiles are for an adult parent or carer to create. Use a nickname only. Do not enter a full legal name, address, school, exact date of birth, contact details, health or disability information, photographs, precise location, or anything else sensitive or identifying.

Profiles are not shared with providers, used for targeted advertising, sold, or sent to an AI service. Mobile profile data is stored only to synchronise the adult’s family planner and is isolated to that signed-in account. Any future expansion of child data requires a privacy impact assessment and appropriate adult authority before release.

5. Sharing and overseas processing

Vuni does not sell personal information. Provider claim information and referral counts are visible only to the relevant signed-in provider and authorised operators, except for provider details approved for public publication. When a provider voluntarily connects payouts, Stripe processes its onboarding and payment-account information under Stripe’s terms and privacy policy. Technical delivery data may be processed by the managed site-hosting platform and its infrastructure providers, including OpenAI and Cloudflare, in Australia, the United States and other countries where their networks and support operations are located.

6. Retention, security and deletion

Device-only data remains until you remove it, clear it on this page or reset the browser. Signed-in family and provider data is protected by account-based row-level access controls. You can request deletion from Account in the mobile app or the web account deletion page. Submitted provider claims, connected-account status and minimal referral records remain until deletion or Vuni’s documented retention period requires removal. Closing a Vuni provider record does not necessarily remove records Stripe must retain by law.

7. Access, correction and complaints

You can view, change or remove device-only child profiles on the My kids page and manage submitted provider details in the provider dashboard. A monitored privacy contact must be published before broader production promotion so people can request access, correction or deletion of server-held information, seek removal of a directory listing, dispute a referral source or make a privacy complaint.

8. Marketing

The prototype does not send emails. Before any provider outreach, Vuni must have express or valid inferred consent, identify the real sender and provide accurate contact details and a working unsubscribe method. Unsubscribe requests must be honoured within five working days and suppression records retained so the person is not contacted again.

9. Laws and standards

Vuni is designed against the Australian Privacy Principles as a voluntary baseline. The Privacy Act 1988 (Cth), including the APPs and Notifiable Data Breaches scheme, becomes mandatory if the operator has annual turnover above $3 million or falls within a statutory exception, including trading in personal information. Vuni must not trade in personal information.

The Spam Act 2003 (Cth) applies to commercial provider email or messaging. The Online Safety Act 2021 (Cth) and applicable industry codes or standards must be reviewed before adding user uploads, messaging or other interactive content. The Children’s Online Privacy Code is due to be registered by 10 December 2026 and is expected to apply to covered APP entities whose online services are likely to be accessed by children or primarily concern children’s activities; scope and the final text must be reassessed at registration.

10. Changes

This policy will be reviewed before customer payment collection, advertising, messaging, upload, AI or additional analytics is enabled, and at least annually after launch. The effective date will change when material updates are published.