Legal

Privacy Policy

Last updated: 18 July 2026

Miss Mystery (ABN 91 153 062 332) is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what personal information we collect and how we handle it.

1. Information we collect

  • Account information — name, email, and (if you set one) password when you sign in to the client portal.
  • Venue information — business name, address, phone, website, primary goals, provided during onboarding.
  • Visit & scorecard data — notes, ratings, and photos captured by our assessors during mystery guest visits.
  • Payment metadata — Stripe customer and subscription IDs, plan, and status. We do not receive or store full card numbers.
  • Communications — emails you send us and emails we send via Brevo (including open, click, and bounce events for our own outreach).
  • Technical data — cookies, IP address, browser, and pages viewed, for security and analytics.

2. How we use it

To deliver the Services, generate reports, process payments, send transactional emails (receipts, digests, password resets), respond to enquiries, prevent fraud, and improve our methodology. We use publicly available review data (e.g. Google Reviews) as inputs to AI-generated summaries; we do not scrape private data.

3. Third parties we share with

  • Lovable Cloud / Supabase — database, authentication, and file storage (hosted in the region configured for our project).
  • Stripe — payment processing and billing portal.
  • Brevo — transactional and outreach email delivery and analytics.
  • Google — sign-in (OAuth) and Places API for venue metadata.
  • Google Gemini via Lovable AI — generating insight summaries from review text.
  • Cloudflare — content delivery and DDoS protection for our website.

We do not sell personal information.

4. Data retention

We retain client account and visit data for the duration of your engagement plus seven years for tax and record-keeping obligations. You can request earlier deletion where legally permitted.

5. Security

Data is transmitted over TLS. Row-level security is enforced on all client-facing tables so that clients can only access their own venue's data. Access to production data is limited to Miss Mystery principals.

6. Your rights

You may request access to, correction of, or deletion of your personal information by emailing hello@miss-mystery.com.au. If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

7. Cookies

We use strictly necessary cookies for authentication and session management, and — where you consent — analytics cookies. You can manage this via the cookie banner shown on your first visit.

8. Changes

We may update this policy from time to time. Material changes will be signalled on the website. This version supersedes any prior version.

Miss Mystery · ABN 91 153 062 332 · Sydney, Australia · hello@miss-mystery.com.au