Privacy Policy

Last updated: 9 May 2025

Who we are

KidFriendlyEats is a community directory of cafes and venues in Melbourne where kids can play. It is operated by an individual based in Australia. When this policy says “we”, “us” or “KidFriendlyEats”, that’s who it means.

This policy explains what personal information we collect, how we use it, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

What we collect

We collect the following personal information:

  • Account information. Your email address and display name, collected when you create an account via Google OAuth or email magic link.
  • Photos you upload. Images you submit alongside a place listing. You represent that you took these photos and have the right to share them.
  • Place listings and reviews. Descriptions, tips, ratings and other content you submit about venues. This is associated with your account.
  • Location data. If you use the "Near me" feature, your device's approximate GPS coordinates are used to find nearby venues. This is processed in your browser and is not stored on our servers.
  • IP addresses. Collected automatically for rate-limiting and security purposes. Not linked to your account and not retained beyond 24 hours.
  • Usage data. Standard server logs (pages visited, browser type). No third-party analytics or tracking cookies are used.

How we use your information

We use personal information only to operate and improve the service:

  • To authenticate you and manage your account
  • To display your submitted listings and reviews on the site
  • To send transactional emails (sign-in magic links and account notifications) — no marketing emails
  • To enforce our community guidelines and respond to reports
  • To detect and prevent abuse (rate limiting by IP)

We do not sell, rent or trade your personal information. We do not use it for advertising.

Third parties we share data with

Running the service requires a small number of third-party providers. Each receives only the data they need to do their job.

  • Supabase. Our database, authentication and file storage provider. Your account data and uploaded photos are stored on Supabase infrastructure hosted on AWS in the United States. Supabase is SOC 2 Type II certified. Under APP 8, we remain responsible for ensuring your data is handled consistently with the APPs.
  • Resend. Email delivery provider used to send sign-in magic links. Receives your email address for the purpose of sending the email. US-based.
  • Mapbox. Used for the map and address search. When you search for an address or use the map, your search query is sent to Mapbox. No account data is sent. Subject to Mapbox's own privacy policy.
  • Cloudflare Turnstile. Bot-protection challenge shown during sign-up. Cloudflare receives your IP address and browser signals. No cookies are set.

We do not share data with any other third parties. We will disclose personal information if required to do so by Australian law or a valid court order.

Photos and children

Because this site is about family venues, photos of play areas may incidentally include children. We take this seriously.

  • We require users to confirm that photos are their own and do not contain identifiable people.
  • If you believe a photo on this site contains an identifiable person (including a child) who has not consented to being photographed and published, please use the Report button on the listing and select "Contains identifiable person in photo." We will remove the photo promptly.
  • Our target response time for photo removal requests of this nature is within 24 hours.

Data retention and deletion

We retain your account information and content for as long as your account is active. If you want your account and associated data deleted, email us at support@kidfriendlyeats.spacewith the subject line “Delete my account”. We will delete your account and personal information within 30 days, except where retention is required by law.

Listings and reviews you have submitted may remain on the site in anonymised form after your account is deleted, as they form part of the community database. If you want specific content removed along with your account, please say so in your deletion request.

Your rights

Under the Privacy Act 1988 (Cth) you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or out-of-date information
  • Request deletion of your personal information
  • Complain about a breach of the Australian Privacy Principles

To exercise any of these rights, contact us at support@kidfriendlyeats.space. We will respond within 30 days. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

Security

We use industry-standard measures to protect your personal information: HTTPS throughout, Supabase row-level security policies so users can only access their own data, and no storage of passwords (authentication is passwordless via magic links or Google OAuth).

No method of internet transmission is 100% secure. If you become aware of a security issue, please contact us immediately at support@kidfriendlyeats.space.

Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new “Last updated” date. For significant changes, we will notify registered users by email.

Contact

Questions or concerns about this privacy policy or how we handle your data:

support@kidfriendlyeats.space

Governing law: this policy is governed by the laws of Victoria, Australia.

Note: This policy was drafted to be accurate and honest. It has not been reviewed by a solicitor. If you are a legal professional and notice an issue, please get in touch.