Privacy Policy
Last updated: 24 April 2025
Paddock ("we", "us", "our") operates the Paddock platform at getpaddock.com.au. We are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data. By using Paddock you agree to the practices described here.
1. Information we collect
Account information: When you create an account we collect your email address, display name, and optionally a profile photo and bio. Sellers also provide stall details (name, location, description, product listings).
Transaction data: We record orders placed on the platform including items purchased, quantities, prices, timestamps, and order status.
Payment information: Card details are handled entirely by Stripe and are never stored on our servers. We retain payment references (PaymentIntent IDs, Stripe account IDs) for order reconciliation.
Location data: With your permission, we access your device's location to show nearby stalls. Location is not stored beyond your session unless you save an address yourself.
Communications: Messages sent between buyers and sellers on the platform are stored to provide the messaging service and resolve disputes.
Usage data: We collect standard server logs (IP address, browser, pages visited, referring URLs) for security and performance purposes.
2. How we use your information
- To operate and provide the Paddock marketplace
- To process payments and send order confirmations
- To send transactional emails (order updates, new-order alerts) via Resend
- To calculate and collect the platform commission (4%, capped at $20 per order)
- To show stalls on the map in proximity to your location
- To allow buyers and sellers to message each other
- To detect and prevent fraud, abuse, and unauthorised access
- To improve the platform based on usage patterns (aggregated, de-identified)
- To comply with legal obligations under Australian law
We do not sell your personal information to third parties.
3. Third-party services
We share information with the following providers solely to operate the service:
Supabase
Database, authentication, file storage
Stripe
Payment processing, seller payouts (Connect Express)
Mapbox
Map rendering, geocoding, address search
Resend
Transactional email delivery
Vercel
Web hosting and edge functions
Each provider processes your data only as necessary for the service they perform and is bound by their own privacy policies.
4. Data retention
We retain your account information for as long as your account is active. Order records are retained for 7 years to satisfy Australian tax and accounting requirements. You may request deletion of your account at any time (see Section 7); transaction records required by law will be retained for the statutory period.
5. Security
We implement industry-standard security measures including TLS encryption in transit, row-level security policies in the database, and limited staff access to production data. No system is completely secure — if you believe your account has been compromised, contact us immediately at hello@getpaddock.com.au.
6. Cookies and local storage
We use browser local storage (not tracking cookies) to persist your cart, map preferences, and dismissed UI elements between sessions. We do not use third-party advertising cookies. If you add analytics in future, this policy will be updated and a consent banner will be added.
7. Your rights
Under the Australian Privacy Principles you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information (via your profile settings or by contacting us)
- Delete your account and associated personal data (excluding records required by law)
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your information — oaic.gov.au
To exercise any of these rights, email us at hello@getpaddock.com.au. We will respond within 30 days.
8. Children
Paddock is not directed at children under 13. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it promptly.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to registered users at least 14 days before they take effect. Continued use of Paddock after that date constitutes acceptance of the updated policy.
10. Contact
For privacy-related questions or complaints:
PaddockEmail: hello@getpaddock.com.au
Website: getpaddock.com.au
Australia