Privacy Policy
Last updated: 14 May 2026
GroupToIt ("we", "us") is operated from Australia and is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
What we collect
- Account data: name, email, password hash.
- Event data: trips, members, dates, accommodation, budgets and itineraries you create.
- Payment data: processed by Stripe. We store transaction metadata (amount, status, payment intent) but never your full card details.
- Usage data: standard server logs (IP, user agent, timestamps) for security and debugging.
How we use it
- To run the service: organise events, split costs, send invites and reminders.
- To process payments via Stripe Connect and remit funds to organisers.
- To contact you about your account, transactional emails, and (if opted in) product updates.
Sharing
We share data only with sub-processors required to run the service: Stripe (payments), Supabase (database and auth), Cloudflare (hosting), and our transactional email provider. We do not sell your data.
Your rights
You can access, correct, export, or delete your data by emailing hello@grouptoit.com.au. You can also unsubscribe from non-transactional emails at any time via the link in the footer of those emails.
Retention
We keep account and event data while your account is active. Payment records are retained for 7 years to meet Australian tax and accounting obligations.
Contact
Questions or complaints? Email hello@grouptoit.com.au. If unresolved, you can contact the Office of the Australian Information Commissioner (OAIC).