Privacy Policy
Last updated: 16 June 2026
1. Introduction
Venture Fit Pty Ltd (“Venture Fit”, “we”, “us”) is committed to protecting your privacy. This policy explains how we collect, use, disclose, store and protect your personal information, and how we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
It applies to everyone who uses the Venture Fit platform, including Customers and Trainers.
2. Information we collect
Information you give us:
- Account details — name, email, password, and optionally date of birth and mobile number.
- Booking details — sessions you book, the city and location, and your messages.
- Health information — your responses to the pre-exercise screening questionnaire and any medical clearance documents you upload. This is “sensitive information” under the Privacy Act and we collect it only with your consent.
- Trainer details — for Trainers, your qualifications, vetting documents, and profile content.
Information collected automatically:
- Device and usage data, log data, and analytics about how you use the Platform.
- Approximate location to show sessions near you (you can decline precise location).
3. Why we collect and use it
- To create and manage your account and bookings.
- To assess fitness-to-exercise and keep you safe (health information).
- To process payments and refunds.
- To enable Trainers to safely deliver a session you have booked.
- To send service communications such as confirmations and reminders.
- To operate, secure, debug and improve the Platform.
- To meet legal, tax and regulatory obligations.
We do not use your health information for marketing, and we do not send it to analytics or advertising tools.
4. How health information is protected
Your health questionnaire responses and screening records are encrypted at rest. Access is tightly restricted: a Trainer can only see a point-in-time health summary for a Customer who has an active, confirmed booking with them, and only for as long as that access is needed. Access to sensitive records is logged in an audit trail.
5. Who we share it with
We do not sell your personal information. We share it only as needed to run the Platform, with service providers acting on our instructions, including:
- Supabase — database, authentication and file storage (hosted in Australia).
- Vercel — application hosting (functions handling health data run in Australia).
- Stripe — payment processing.
- Resend — transactional email delivery.
- Sentry — error monitoring (personal information is scrubbed before it is sent).
- PostHog — product analytics (Australian region; no health information).
- Google Maps and, for Trainers who connect it, Google Calendar.
We also share information where required by law, to protect safety, or with your consent. Trainers receive the limited Customer information needed to deliver a booked session.
6. Where your data is stored (data residency)
Personal and health information is stored in Australian data centres (the Supabase Sydney region), and application functions that handle health information run in Sydney. Some service providers (for example, payment processing) may process limited data overseas; where this happens we take reasonable steps to ensure it is handled consistently with the APPs.
7. Retention
We keep personal information only as long as needed for the purposes above or as required by law. Financial records are retained for the period required by Australian tax law. Health information is retained for a limited period and then deleted or de-identified. Audit logs are retained for a minimum of seven years.
8. Your rights
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct information that is inaccurate or out of date.
- Deletion — ask us to delete your account and personal information, subject to records we must keep by law.
- Withdraw consent — withdraw consent to health-data processing, noting some bookings cannot proceed without it.
To exercise these rights, contact us using the details below. You can view and update much of your information directly in your account.
9. Data breaches
We maintain safeguards to protect your information and have an incident response process. If an eligible data breach occurs, we will comply with the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.
10. Cookies and analytics
We use cookies and similar technologies to keep you signed in, remember preferences, and understand usage so we can improve the Platform. You can control cookies through your browser settings, though some features may not work without them.
11. Changes and contact
We may update this policy from time to time and will publish the current version here with a revised date. For privacy enquiries, access or correction requests, or to make a complaint, contact us via our Contact page. If you are not satisfied with our response, you may contact the OAIC at oaic.gov.au.