Legal
Privacy Policy
How Player Bash Pty Ltd handles your personal information — what we collect, why, who else sees it, and how to get it back or have it deleted.
Last updated 31 July 2026
01About this policy
This policy explains how Player Bash Pty Ltd handles personal information. It applies to the Player Bash app, the Player Bash website, the centre portal and everything we do with information about you.
“Personal information” means information or an opinion about an identified individual, or one who is reasonably identifiable — the definition used in the Privacy Act 1988 (Cth).
We handle personal information in accordance with the Australian Privacy Principles (APPs) in that Act. We do this as a matter of policy, and we hold ourselves to it regardless of whether a turnover threshold would otherwise exempt a business of our size.
02What we collect
Information you give us
- Account details — your name, email address, phone number, date of birth and gender. Date of birth is used to confirm you are 18 or over and, where you choose, for age-based competition grading.
- Profile — your photo, the sports you play, your skill level, and whether you appear on public leaderboards.
- Bookings and activities — the centres and courts you book, when you play, who you play with, and the matches and tournaments you enter.
- Messages — chat you send to other players and to centres through the app.
- Support and feedback — what you tell us when you contact us, report another player, or give a reason when closing your account.
Information we generate or collect automatically
- Results and ratings — scores you or your opponents report, and the ratings and leaderboard positions calculated from them.
- Location — if you allow it, your device’s location, so we can show courts near you. You can refuse or withdraw this in your device settings and still use Player Bash by searching for a suburb instead.
- Device and app data — device type, operating system and version, app version, and a push notification token for each device you enable notifications on.
- Crash reports — when the app fails, the error and where in the app it happened, so we can fix it.
- Technical logs — request records needed to run and secure the service. IP addresses are used for security and fraud prevention and are not retained in an identifiable form beyond that purpose.
Information from others
- If you sign in with Google or Apple, we receive your name, email address and, from Google, your profile picture. We never receive your password. If you use Apple’s Hide My Email, we only ever see the relay address.
- Our payment provider tells us whether a payment succeeded, the type of card used and the country it was issued in. We do not receive your card number.
- Centres may tell us about an incident at their venue involving a booking made through us.
Sensitive information
We don’t seek health information, and you shouldn’t send it to us through chat. If you tell a centre about an injury or a medical condition so they can support you safely, that is between you and the centre. If sensitive information reaches us in a support request, we use it only to deal with that request.
03How we collect it
We collect personal information directly from you wherever we can — when you create an account, complete your profile, make a booking, message someone or contact support.
We collect it from others only where it is unreasonable or impracticable to collect it from you: from Google or Apple when you choose to sign in that way, from Stripe when a payment is processed, and from a centre reporting something that happened at their venue.
04Why we use it
We use personal information to:
- create and run your account, and confirm you are eligible to use Player Bash;
- take bookings, process payments and refunds, and issue receipts and credit notes;
- tell the centre who is coming, and tell you about your booking — confirmations, reminders, changes and cancellations;
- let you find and play with other players, and run matches, tournaments, ratings and leaderboards;
- provide support, investigate reports and complaints, and resolve disputes;
- keep the platform safe and secure — detecting fraud, abuse and unauthorised access;
- understand how the product is used so we can improve it, and fix crashes;
- send you service messages, and marketing where you have opted in;
- meet our legal obligations, including tax and financial record keeping.
If we ever want to use your information for something materially different from these purposes, we will ask you first.
05Who we share it with
We do not sell personal information, and we do not disclose it for other organisations’ marketing. We share it only as described here.
Sports centres
When you book, the centre receives your name, the booking details, and contact details where they need them to run the booking. If you play regularly at a centre or hold a membership with them, they will see your booking history with them. Centres are required by their agreement with us to use that information only to provide the booking and to comply with privacy law.
Other players
Your profile — name, photo, sports, skill level and public ratings — is visible to other players. Players in the same activity as you can see that you are taking part and can message you in that activity’s chat. You can hide yourself from global leaderboards in your settings, and you can block another player at any time.
Service providers
| Provider | What they do for us | What they receive |
|---|---|---|
| Stripe | Payments, refunds, payouts to centres, fraud screening | Your name, email, payment details and transaction data |
| MongoDB Atlas | Our main database | Your account and booking data, hosted in Sydney |
| Cloudflare | Website delivery and security, and file storage for photos and receipt PDFs | Technical request data; uploaded files and documents |
| Resend | Sending transactional email | Your email address and the content of that email |
| Apple and Google | Sign-in, push notifications, app distribution, maps | Sign-in identifiers, device push tokens, map queries |
| Geoapify and OpenStreetMap | Address lookup and venue locations | The address text you type into a search |
These providers may only use your information to provide their service to us.
Others
- Professional advisers — lawyers, accountants and auditors — under confidentiality.
- Law enforcement, regulators or courts, where we are required or authorised by law, or where we reasonably believe it is necessary to prevent a serious threat to someone’s life, health or safety.
- A buyer, if our business is sold or restructured. We would tell you first, and the buyer would be bound by this policy.
06Where your information is held
Our database is hosted in Sydney, Australia.
Some of our service providers are overseas, so your information may be disclosed to recipients in the United States, Ireland and other countries where those providers operate infrastructure, including Stripe, Cloudflare, Resend, Apple and Google.
Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through our contracts with them. We choose established providers with published privacy and security commitments.
07Payment information
Card payments are processed by Stripe. Your full card number never reaches Player Bash’s systems. It is captured by Stripe’s software on your device and sent directly to them.
What we hold against a booking is:
- the amount, currency, date and status of the payment;
- the type of payment method used and the country the card was issued in;
- Stripe’s references for the payment, so we can match a refund or a dispute to the right booking;
- the receipts and credit notes we issue you.
If you save a card for next time, it is stored by Stripe against a customer record, not by us.
Stripe also handles its own fraud screening and may use device and transaction signals for that purpose, under Stripe’s privacy policy.
08Marketing and notifications
Service messages — booking confirmations, reminders, cancellations, receipts, security alerts — are part of the service and are sent whenever they are relevant. They are not marketing and can’t be switched off while you hold an account, though you can control which of them arrive as push notifications.
Marketing — news, offers and suggestions — is only sent where you have opted in. Every marketing email has an unsubscribe link, and you can change your preferences in the app at any time. We honour opt-outs promptly, as required by the Spam Act 2003 (Cth).
Push notifications can be turned off per category in the app, or entirely in your device settings.
09Data security
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include:
- encryption of data in transit, and at rest at our providers;
- passwordless or provider-backed sign-in, with one-time codes for administrative access;
- role-based access, so staff only reach the data their job needs;
- an audit trail over sensitive changes such as business and bank details;
- rate limiting, bot protection and monitoring against automated abuse.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will assess it promptly and notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
10Data retention
| Information | Kept for |
|---|---|
| Account and profile | While your account is open. De-identified immediately when you close it. |
| Bookings, payments, receipts | 7 years from the transaction — the period the Corporations Act 2001 requires a company to keep its financial records. Then permanently deleted. |
| Chat messages | While the activity exists. Your name and photo come off your messages the moment you close your account; the message text goes at the 7-year mark with everything else. |
| Support tickets | 2 years after the matter is closed |
| Safety reports and blocks | As long as needed to keep the platform safe, and to defend a legal claim |
| Crash reports and technical logs | 12 months |
What happens when you delete your account
You can delete your account from the app (More → Profile → Delete account) or at playerbash.com/delete-account. It takes effect straight away and cannot be undone. There is no waiting period and no way for us to restore it.
Immediately:
- your name, email address, phone number, date of birth, gender and profile photo are removed or replaced;
- your name and photo are stripped from every message you have sent;
- your followers, the people you follow, and your blocks are deleted;
- push notification tokens are deleted, so no device receives anything further;
- you are removed from public leaderboards, and appear as “Deleted User” in past games;
- every session and every login method — password, Google, Apple — is destroyed, so the account can never be signed into again;
- your email address is released, so you can start a fresh account with it whenever you like.
Kept, and only this: the record of your bookings, payments, refunds and receipts, for the 7 years the Corporations Act 2001 requires. Those records are no longer connected to a usable profile, and are permanently destroyed at the end of that period.
Australian privacy law expressly allows an organisation to de-identify personal information as an alternative to destroying it (APP 11.2), and does not require destruction where another Australian law compels the record to be kept. That is the basis on which we do this.
Before you delete
If you have a booking you have paid for that hasn’t happened yet, cancel it or play it first. We will ask you to do that before we can delete the account — once it is gone there is no one left for us to refund.
Deleting your Player Bash account doesn’t delete records held by our payment provider. Stripe keeps its own transaction records under its legal obligations and its privacy policy.
11Accessing and correcting your information
You can ask us to:
- give you a copy of the personal information we hold about you;
- correct anything that is wrong, out of date, incomplete or misleading — most of it you can edit yourself in the app;
- delete your account and the information we don’t have to keep. You can start this yourself at playerbash.com/delete-account or in the app;
- stop marketing at any time.
Email privacy@playerbash.com. We will verify who you are, respond within 30 days, and there is no charge. If we refuse access or a correction — which the Privacy Act permits in limited circumstances — we will tell you why in writing and how to complain.
12Children
Player Bash accounts are for people aged 18 and over, and we do not knowingly collect personal information from anyone under 18. A parent or guardian may add a child as a participant on their own booking; in that case we hold only the child’s first name for the centre’s attendance record.
If you believe a child has given us personal information, contact privacy@playerbash.com and we will delete it.
14Complaints
If you think we have mishandled your personal information, tell us first. Email privacy@playerbash.com with what happened and what you would like us to do. We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, or 1300 363 992.
15Changes to this policy
We’ll update this policy as the product and the law change. The “last updated” date at the top always reflects the current version. Where a change materially affects how we handle your personal information, we’ll tell you in the app or by email before it takes effect.
16Contact us
For anything about privacy or your personal information:
- Player Bash Pty Ltd (trading as Player Bash)
- Unit 3/11 Lambert Avenue, Sandy Bay TAS 7005, Australia
- support@playerbash.com
Privacy enquiries: privacy@playerbash.com
