Skip to content
PIAGO

Legal

Privacy policy

Last updated 19 May 2025

1. Introduction

This policy explains how Project Is A Go Pty Ltd (“we”, “us”, “our”) collects, uses, discloses and safeguards information when you use our websites and the GO! Site Approved and GO! Site Ready platforms.

We comply with the Australian Privacy Principles, and with the GDPR, PIPEDA, and CCPA/CPRA where those apply. Please read this policy carefully — using the service implies agreement with it. We may modify this policy, and any update is indicated by the “Last updated” date above.

2. Definitions

“Personal Data” means any information relating to an identified or identifiable natural person. “Processing” means any operation performed on Personal Data, such as collection, recording, organisation, storage, use, disclosure or deletion.

“Data Controller” means the entity determining the purposes and means of processing. “Data Processor” means an entity processing data on the controller’s behalf. “Service” means our platforms and websites. “User” means anyone who accesses or uses the Service.

3. Information we collect

Identity data — full name, username or similar identifiers. Contact data — email address, telephone number, and billing or physical address.

Financial data — we use third-party payment processors (Paddle and Stripe) and do not directly store full credit card numbers. Transaction data received from those processors may include payment confirmations, subscription details, partial payment information and billing addresses.

Technical data — collected automatically, including IP address, browser type, operating system, access times, device information, and the pages viewed directly before and after accessing the Service. Usage data — how platform features are used, actions taken, and time spent.

User-generated content — content you create, upload or store, which may contain personal data for which you are the controller. Marketing and communications data — your marketing and communication preferences.

We collect information directly from you at registration or purchase, automatically as you use the Service, and from our third-party payment processors.

4. How we use your information

Service provision — account creation and management, customer support, and operating the platform. Transaction processing — facilitating payment through Paddle and Stripe, managing subscriptions, and preventing fraud.

Communications — responding to enquiries and sending administrative information and security alerts. Service improvement — analysing usage trends, monitoring feature effectiveness, troubleshooting, and improving the experience.

Security — monitoring and preventing fraudulent or unauthorised activity, and maintaining the security and integrity of the Service. Marketing — sending newsletters, promotions and product information, subject to your consent and opt-out rights.

Legal compliance — meeting legal requirements, responding to lawful requests from authorities, and enforcing our agreements.

5. Legal basis for processing (GDPR)

For users in the EU and UK, we rely on the following lawful bases. Performance of a contract — processing necessary to provide the Service under our terms.

Legitimate interests — including service improvement, fraud prevention, security and, where permitted, direct marketing, provided those interests do not override your data protection rights. Receiving data from Paddle for fulfilment or support relies on legitimate interest.

Consent — required for certain activities such as specific marketing communications or non-essential cookies, and able to be withdrawn at any time. Legal obligation — where processing is necessary to comply with law, such as tax obligations or responses to legal process.

6. Data sharing and disclosure

With service providers — third parties who perform services on our behalf, including hosting, analytics, customer service and email delivery. They have access only to the personal data necessary to perform those services and are obliged not to disclose or use it for any other purpose.

With payment processors — Paddle acts as Merchant of Record and processes payments and compliance; we receive the buyer information necessary for fulfilment, support and fraud prevention, and use it only for those purposes unless Paddle has obtained your explicit consent for another use. Payment details provided to Stripe go directly to Stripe; we receive transaction confirmations and related data. Each processor’s own privacy policy governs their use of your data.

For legal reasons — where required by law, subpoena or other legal process, or where we believe in good faith it is necessary to protect rights or safety, investigate fraud, or respond to a government request.

Business transfers — in a merger, asset sale, financing or acquisition, personal data may be transferred. With consent — we may disclose personal data for any other purpose with your consent.

We do not “sell” personal data as that term is traditionally understood. The CCPA/CPRA definitions of “sale” and “sharing” are broad; if our use of third-party analytics or advertising tools constitutes a sale or sharing under those definitions, California residents may opt out under section 12.

7. International data transfers

Your information may be transferred to, and maintained on, computers located outside your jurisdiction, where data protection laws may differ. If you are outside Australia and provide us with information, you acknowledge that it may be transferred to Australia and to the locations of our service providers.

For transfers from the EEA, UK or Switzerland we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions. For transfers out of Australia we take reasonable steps to ensure the overseas recipient handles the information in accordance with the Australian Privacy Principles, generally through contractual arrangements.

8. Data security

We implement reasonable technical and organisational security measures designed to protect the personal data we process, including encryption, access controls and regular security assessments.

No method of transmission over the internet or method of electronic storage is completely secure. While we use commercially acceptable means to protect your personal data, absolute security cannot be guaranteed. You remain responsible for keeping your account credentials secure.

9. Data retention

We retain personal data only for as long as necessary for the purposes set out in this policy, unless a longer retention period is required by law for tax, accounting or other reasons.

Where there is no ongoing legitimate business need, we either delete or anonymise the data. Where that is not possible — for example, because it is held in backup archives — we store it securely and isolate it from further processing until deletion is possible.

10. Cookies and tracking technologies

We use cookies and similar technologies such as web beacons and pixels to access or store information. These support essential operations necessary for the Service to function, performance and analytics, functionality such as remembering your preferences, and marketing where you have consented.

You can manage your cookie preferences through your browser settings. The Service does not currently respond to Do-Not-Track signals.

11. Children’s privacy

The Service is not directed to individuals under 16, and we do not knowingly collect personal data from children under that age. If we discover that we have collected such data without verified parental consent, we will remove it from our servers.

12. Your data protection rights

Depending on where you are, you may have the right to access the personal data we hold about you; to have inaccurate or incomplete data corrected; to request deletion, subject to exceptions such as legal obligations; to restrict processing in certain circumstances; to receive your personal data in a structured, machine-readable format; to object to processing based on legitimate interests or to direct marketing; and to withdraw consent where consent is the basis for processing.

California residents may additionally direct us not to “sell” or “share” personal data for cross-context behavioural advertising. You have the right not to be discriminated against for exercising any of these rights, and the right to lodge a complaint with a data protection authority.

To exercise any of these rights, contact us using the details in section 14. We may need to verify your identity. We respond within the applicable timeframes, typically within 30 to 45 days.

13. Changes to this policy

We may update this policy from time to time. Any update is indicated by a revised “Last updated” date and takes effect once published. We encourage you to review this page periodically. Where changes are significant we may notify you directly or by a prominent notice on the Service.

14. Contact us

For questions or comments about this policy, or to exercise any of your data protection rights, contact us at:

Project Is A Go Pty Ltd
PO Box 2468
Redcliffe North QLD 4020
[email protected]
(07) 3251 2468

Australian users may also contact the Office of the Australian Information Commissioner. Users in the EU or UK may lodge a complaint with their local data protection authority, and Canadian users may contact the Office of the Privacy Commissioner of Canada.