moveera

Privacy Policy

Effective date: 15 August 2026 Last updated: 21 September 2026

This Privacy Policy explains how your personal information is collected, used, stored, and shared when you use the Moveera mobile app, the website at moveera.com.au, and any related services (together, the "Service"). The Service is operated by Moveera Pty Ltd ACN 698 848 341, ABN 73 698 848 341, a company incorporated in Australia and based in Queensland ("Moveera", "we", "us", "our").

We are committed to protecting your privacy and complying with the Australian Privacy Principles under the Privacy Act 1988 (Cth). This Policy forms part of our Terms and Conditions.

By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.


1. Who this policy applies to

This Policy applies to all users of Moveera, including:

  • People who create an account to discover, book, and attend fitness events ("Attendees")
  • People and organisations who create communities and host events ("Hosts")
  • People who buy or reserve a ticket through our website. You sign in with your mobile number and a code we text you, and that makes you a Moveera account.
  • Visitors to moveera.com.au

Moveera is intended for users aged 16 and over. We do not knowingly collect personal information from anyone under 16. If you believe a person under 16 has provided us with personal information, please contact us and we will take reasonable steps to delete it.


2. Information we collect

2.1 Information you provide

  • Account information: your mobile number (checked with a code we text you when you sign up and, on our website, each time you sign in), email address, username or display name, and a password if you set one (stored hashed, never in plain text)
  • Profile information: profile photo, bio, location (suburb or city level), social media handles
  • Community information (Hosts): community name, description, logo, gallery images, contact details, event categories
  • Event information: event titles, descriptions, dates, times, locations, pricing, capacity, refund settings
  • Booking information: events you save, reserve, book, or join a waitlist for, attendee details, check-in status
  • Communications: messages you send to other users and communities through the app, support enquiries, feedback, reports you make about content or users

2.2 Payments

If you buy a ticket to a paid event:

  • Your card or Apple Pay details go directly from your device to Stripe, our payment processor. We never receive or store your full card number.
  • We keep a record of the transaction: what you bought, the amounts, fees, GST where applicable, the payment status, and any refund. We use this to run the Service, issue your receipt, and meet our tax and record-keeping obligations.

If you are a Host receiving payouts:

  • Identity documents and bank account details are provided by you directly to Stripe during payout setup. We do not store them.
  • We store your ABN, your GST registration status, and the status of your Stripe account (for example whether charges and payouts are enabled), along with records of your sales, fees, refunds, and payouts.

2.3 Waivers and health information

Some Hosts require you to sign a waiver before attending. When you sign one, we record the waiver text you agreed to, its version, the name you signed with, and when you signed. If a Host's waiver or event asks about health conditions, injuries, or similar matters, that is sensitive information under the Privacy Act: we collect it only with your consent, store it securely, and share it only with the Host whose event it relates to. Hosts are required to handle it in line with the Privacy Act and to collect no more than they reasonably need (see our Terms).

2.4 Buying on our website

When you get a ticket on our website we ask for your mobile number, your name and your email. We text a code to your mobile to confirm it is yours. If the host asks questions or needs a waiver signed, we keep your answers against your account while you finish, and attach them to your ticket once it is booked.

To stop our texts being abused, we count code requests for each mobile number and each internet address. We do not store the number or the address for this: we store a scrambled version that cannot be turned back without a key we keep secret, and we delete it within a day.

If you reserved a spot on our website before we introduced sign-in by text, we made a basic account for you with only what you gave us. You can ask us to delete it at any time.

2.5 Information collected automatically

  • Device information: device type, operating system, app version
  • Usage analytics: the screens you view and actions you take in the app (for example viewing an event, booking, or checking out), collected through PostHog and linked to your account so the Service can be improved. See section 9.
  • Location data: approximate location to show events near you, only with your permission. You can withdraw it at any time in your device settings.
  • Log and error data: IP address, access times, error reports, and crash logs, collected through Sentry. On our website this includes session replays for visits where an error occurs, which are recordings of page interactions used to diagnose the problem. See section 9.
  • Checkout analytics: on our website's checkout we set a first-party cookie with a random id, so we can see how many people reach each step and where they stop. Once you sign in, these events are linked to your account. They never include your mobile number, your email or your card details.
  • Push notification tokens: to deliver notifications about events, bookings, messages, and waitlist offers
  • SMS delivery records: when we send you an SMS (such as a verification code or a waitlist offer), we keep a record of whether it was delivered

3. How we use your information

We use your information to:

  • Provide, operate, and maintain the Service
  • Create and manage your account
  • Process ticket purchases, refunds, and Host payouts, and issue receipts
  • Help you discover, book, and attend events
  • Enable communication between Hosts, Attendees, and communities
  • Send booking confirmations, reminders, waitlist offers, receipts, and important service updates by push notification, email, and SMS
  • Send email about a ticket you hold: the ticket itself, changes to the time or place, cancellations, and a reminder the day before. We send these because you hold the ticket, so they have no unsubscribe link.
  • Show you events relevant to your location and interests
  • Respond to support requests, reports, and feedback
  • Detect, prevent, and address fraud, abuse, chargebacks, and security issues
  • Measure the effectiveness of our advertising (see section 9)
  • Comply with our legal obligations, including tax and anti-money-laundering requirements that apply to payments
  • Improve the Service through analytics and user research

4. How we share your information

We do not sell your personal information. We share it only in the following circumstances:

4.1 With other users

  • Public profile information (username, display name, profile photo, bio) is visible to other users.
  • Attendee lists are visible by design. When you book or RSVP to an event, other users viewing that event can see that you are going, shown with your public profile. Hosts can choose to hide the attendee list on their events.
  • Booking details are shared with the Host of the event: your name, username, check-in status, your answers to the host's questions, and any waiver you signed for it. A Host can also ask us for the email addresses of their attendees, which we give only after the Host confirms a code sent to their own email. We do not give your mobile number to the Host. From the point a Host receives your details, the Host is independently responsible for them under the Privacy Act, as set out in our Terms.
  • Host information (community name, logo, public profile) is visible to Attendees browsing events.

4.2 With service providers

We share information with third-party providers who help us operate the Service:

ProviderPurposeData location
SupabaseDatabase, authentication, and file storageSydney, Australia
StripePayment processing, Host identity verification, and payoutsUnited States and global
TwilioSMS delivery (verification codes and event texts such as waitlist offers)United States
ResendTransactional email delivery (welcome emails, receipts, refund notices, waitlist offers, weekly digests)United States
PostHogProduct analytics (app usage events)United States
SentryError and crash monitoring, including website session replaysGermany (EU)
ExpoRelay service that delivers push notifications to Apple and GoogleUnited States
Apple / GoogleFinal delivery of push notifications to your device (APNs and FCM)United States
MapboxMap rendering and geolocation servicesUnited States
VercelWebsite hosting and analyticsGlobal
MetaAdvertising measurement on our website (see section 9)United States

Each of these providers processes data only for the purpose described and is bound by its own privacy obligations.

4.3 Legal disclosures

We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4.4 Business transfers

If we sell or transfer the Service or its assets in the future, your information may be transferred as part of that transaction. We will notify you of any such change.


5. International data transfers

Some of our service providers are located outside Australia: most (including Stripe, Twilio, Resend, PostHog, Expo, Mapbox, and Meta) in the United States, and Sentry in the European Union. When we share your information with these providers, we take reasonable steps to ensure it remains protected to a standard consistent with Australian law.


6. Data retention

We retain your personal information for as long as your account is active or as needed to provide the Service.

When you delete your account, your profile is removed immediately and your personal information is permanently deleted, normally within days and at most within 30 days, except where:

  • Financial records must be kept. Records of ticket purchases, receipts, refunds, and payouts are retained for as long as Australian tax and corporations law requires, even after your account is deleted.
  • Retention is required by other law, or information is needed to resolve disputes, handle chargebacks, enforce our agreements, or prevent fraud.
  • Information has already been shared with a Host as part of an event you attended or booked. That copy remains with the Host, subject to the Host's own obligations.
  • A minimal audit record of the deletion itself is kept, so we can show the deletion happened.

You can delete your account in the app under Profile → Settings → Delete account, or see moveera.com.au/delete-account.


7. Your rights and choices

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and associated personal information
  • Object to or restrict certain uses of your information
  • Withdraw consent for optional processing, such as push notifications or location access, in your device or app settings
  • Request a copy of your information in a portable format
  • Choose what else we send you. If you signed up by buying a ticket on our website, we only email you about your tickets unless you choose to hear news from Moveera. You can turn news on or off in your settings on the website or the app, or with the unsubscribe link in any such email.

To exercise any of these rights, email us at support@moveera.com.au. We will respond within 30 days. You can also manage many of these settings directly in the app under Profile → Settings.


8. Security

We use industry-standard security measures to protect your information, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Hashed password storage
  • Row-level security on our database, so users can only read what they are permitted to see
  • Access controls limiting who can view your information
  • Payment credentials handled solely by Stripe, never stored by us

No system is perfectly secure. If we become aware of a data breach that affects your personal information, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.


9. Analytics, advertising, and tracking

We want to be specific about what runs where.

On the website (moveera.com.au):

  • Vercel Analytics collects aggregated visit statistics.
  • Sentry collects errors and, for any visit where an error occurs, a session replay: a recording of page interactions used to diagnose the problem.
  • The Meta Pixel measures the effectiveness of our advertising on Meta platforms (Facebook and Instagram). It sets cookies and may associate your visit with your Meta account. You can control this through your browser's cookie settings and through Meta's ad preferences.

In the app:

  • PostHog records product analytics events (for example that an event was viewed or a booking made), linked to your account, so we can understand and improve how the Service is used.
  • Sentry records crashes and errors.
  • The app contains no advertising SDKs and does not track you across other apps or websites.

We do not use your data for third-party advertising networks beyond the website measurement described above, and we do not sell it.


10. Third-party links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.


11. Children's privacy

Moveera is not intended for users under 16. We do not knowingly collect personal information from anyone under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@moveera.com.au and we will take reasonable steps to delete it.


12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If the changes are significant, we will notify you through the app or by email.


13. Contact us

If you have questions, concerns, or requests about your privacy, contact us at:

Email: support@moveera.com.au Postal: Moveera Pty Ltd, c/- Poole Group, Level 1, 8 Innovation Parkway, Birtinya QLD 4575, Australia

If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):