Effective from 30 September 2026.
Operator: Solway Web Consulting, trading as Pride Compass Australia ABN: 16 750 149 558.
1. About this policy
Pride Compass Australia (“we”, “us” and “our”) operates an Australian directory connecting people with LGBTQ+ friendly businesses, services and community organisations.
We respect your privacy and are committed to handling personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth). We comply with Australian privacy and data protection laws that apply to our activities, including applicable state and territory requirements and the Spam Act 2003 (Cth).
This policy explains how we handle information about visitors, subscribers, account holders, people making enquiries, sole traders, and individuals who own, represent or work for businesses and organisations. A person's work email address, direct phone number or business role can be personal information even when used for business purposes.
Contact our Privacy Officer at privacy@pridecompass.com.au for privacy enquiries, requests or complaints, or to request a copy of this policy in another accessible format.
2. Information we collect
We collect personal information reasonably necessary to operate the directory and manage our relationships with you. Depending on your interaction with us, this may include:
- Your name, email address, telephone number and communication preferences.
- Your business or organisation, role, business contact details and authority to manage a listing.
- Account details, password hashes, verification records and account status.
- Listing submissions, claim requests, supporting information, photographs and other material you provide.
- Enquiries, feedback, complaints, correspondence and relevant contact or follow-up notes.
- Subscription preferences and records of consent, confirmation and unsubscribe requests.
- Technical information needed to deliver and secure the service, such as IP addresses, request times, requested pages, browser information and security or error logs.
- Information collected automatically by our own application analytics, including page and listing views, selected link clicks, page and destination URLs, event times, a browser-session identifier, referring domain, IP address and a hashed version of it, browser and operating system details, device type and, where available, approximate country and city derived from the IP address. Section 9 explains this collection and its purposes.
Please provide only information relevant to your request. Do not send identity documents or sensitive information unless we specifically request it and explain why it is needed and how it will be handled.
3. How we collect information and your choices
We generally collect information directly from you through forms, account registration, listing submissions, mailing-list registration, email and other correspondence.
We may also receive business contact or listing information from an authorised representative of your organisation, a person suggesting a listing, or public sources such as business websites and directories. We check that collection is appropriate and, where required, take reasonable steps to tell you about the collection, its source and purpose as soon as practicable. Public availability does not remove an individual's privacy protections.
If you provide information about another person, you must have authority to do so and make them aware of this policy. Do not provide another person's sensitive information without their express consent.
You can browse the public directory without an account. Where lawful and practicable, you can make a general enquiry anonymously or using a pseudonym. We may need your identity or contact details to verify a listing claim, provide an account, respond to a particular request or investigate a complaint. If you choose not to provide necessary information, we may be unable to provide that service.
If we receive unsolicited personal information we could not lawfully have collected, we will destroy or de-identify it where lawful and reasonable.
4. Sensitive information
Some information can reveal or imply sensitive matters, including sexual orientation, racial or ethnic origin, religious beliefs or health information. An ownership description, photograph or listing label may reveal information about an identifiable person.
You do not need to disclose your sexual orientation or other sensitive information to browse the directory or join our mailing list. We do not infer a person's sexual orientation from their use of the site, subscription or association with a listed business.
We collect sensitive information only with your express, informed consent and where reasonably necessary for our activities, unless Australian law permits or requires otherwise. Consent to collect information does not automatically authorise its publication. We seek specific consent before publishing sensitive information about an identifiable person, including an ownership label that reveals their sexual orientation.
You can withdraw consent for future optional handling by contacting us. We will explain any effect on the relevant feature and arrange removal from our own public listing where appropriate. We cannot guarantee removal of copies already made by others.
5. How we use information
We use personal information to operate accounts; assess, verify, publish and maintain listings; process claims; respond to enquiries; manage business relationships; send requested updates; understand site usage and listing engagement through our own application analytics; improve the directory; maintain security; prevent misuse; resolve complaints; and meet legal obligations.
We use or disclose information for the purpose for which it was collected, another purpose you consent to, or another purpose permitted or required by Australian law. We do not sell personal information, rent mailing lists or disclose private contact details to advertisers for their own marketing.
6. Mailing lists and marketing
For mailing-list registration, we collect your email address, whether you register as an individual or business, any name or business name you supply, and records of your consent and subscription status. We confirm your email before adding you to the mailing list. When you opt in to ongoing updates, we use these details to send Pride Compass news, new blog content and venue-specific special offers. Earlier Sydney launch-only subscriptions remain limited to that purpose unless you explicitly confirm the wider subscription. Venue offers are sent by Pride Compass; signing up does not share your email address with venues. Registration does not create an account or publish a listing, and subscriber details are not displayed in the directory.
We send marketing communications only with consent as required by law. A public business email address alone is not blanket permission to send marketing. Marketing messages identify us and provide a simple unsubscribe option. You can also unsubscribe by contacting us. We action requests within five working days without charging a fee or requiring you to log in or provide extra personal information.
Unsubscribing from marketing does not stop necessary service messages, such as account security or a response to your enquiry. We may retain a minimal suppression record to ensure we respect your choice.
7. Public listings and disclosures
Information intended for a public listing may include business names, descriptions, addresses, public contact details, websites, photographs and approved labels. Please avoid supplying a home address or personal contact details for publication unless you intend them to be public. Private account information, administrative business contacts, claim evidence and internal correspondence are not published as listing content.
Public listings can be viewed worldwide, indexed by search engines and copied by third parties. Australian hosting cannot prevent this. Our Australia-only commitment for information we hold does not mean public listing content can be kept within Australia after publication.
We may disclose personal information to authorised personnel and service providers who need it to operate hosting, email, backups, security or support; professional advisers where necessary; and regulators, courts or other recipients where Australian law permits or requires disclosure. Service providers must handle information only for authorised purposes and protect it appropriately. We limit disclosures to what is necessary.
8. Australian storage and processing
Personal information held by us is stored and processed in Australia, including databases, uploaded files, email records, logs and backups. We do not transfer that information to overseas service providers or allow overseas access by support personnel. We require providers handling this information on our behalf to meet these Australian storage, processing and access requirements.
Public directory content is subject to the worldwide-access limitation explained above. If you choose to follow an external link, such as a business website, social network or map service, that service handles information under its own privacy policy and may operate overseas. Your own email provider may also process communications outside Australia. These independent services are outside our control.
9. Cookies, advertising and analytics
We use our own first-party application analytics to understand how people use the directory, measure listing visibility and engagement, produce internal reports and improve the service. Our site records page and listing views and selected interactions, including clicks on website, social media, telephone, email and directions links. Some outbound clicks are recorded by our server when it redirects you to the selected website.
These events are sent to our own application and stored and processed in Australia under the commitments in section 8. The information collected is described in section 2. Approximate location is derived using a locally held IP-location database where available; we do not request your device's precise GPS location for analytics. Because analytics records include IP addresses and session identifiers, we do not describe them as anonymous.
Our analytics uses a randomly generated identifier (qc_analytics_session_id) in your browser's session storage to associate events within a browser-tab session. This is separate from cookies and is normally cleared when that tab or window is closed. Closing the session does not delete events already recorded on our server; those records are subject to section 10.
We do not use Google Ads, Google Analytics or external cookie-based analytics services. We do not send our application analytics records to third-party analytics or advertising platforms, use advertising cookies or tracking pixels, or use browser fingerprinting or email-open tracking. Our analytics is used to measure activity on our own service, not to track your browsing across other websites or build advertising profiles. It starts on pages where the analytics script is included; we do not currently provide an analytics consent or opt-out switch. A browser Do Not Track signal is not currently used to disable collection.
Our Cookie Policy identifies our first-party cookies and browser storage, their purposes and their lifetimes. We use a session cookie for form security and administrator sign-in, and an optional trusted-browser cookie when an administrator chooses to trust a browser for 30 days. Public user and business accounts are not currently available; mailing-list signup does not create an account. You can manage cookies and site storage through your browser, although restricting them may affect site functions. Blocking cookies alone does not stop our application analytics: page and click events can still be recorded without a session-storage identifier, and outbound redirects can still be recorded by our server.
10. Security, retention and data breaches
We take the protection of information that identifies, or could reasonably identify, an individual seriously. We exercise care in how we collect, use, store and disclose it, and take reasonable technical and organisational measures to protect it against misuse, interference, loss and unauthorised access, modification or disclosure.
Australian Privacy Principle 11 (APP 11) under the Privacy Act 1988 requires entities covered by it to take reasonable steps to secure personal information, including technical and organisational measures, and to destroy or de-identify information no longer needed, subject to legal exceptions. We use these requirements as the basis for our personal-information security practices and comply with the legal obligations applicable to our activities. The sensitivity of information, the potential harm from its misuse and the circumstances in which we hold it inform the measures we take.
Our security programme implements the Australian Signals Directorate's Essential Eight mitigation strategies: application control, application patching, restrictions on Microsoft Office macros, user application hardening, restricted administrative privileges, operating-system patching, multi-factor authentication and regular backups. These practices address the systems and administrative environments used to operate the service, with controls appropriate to those environments. This statement does not claim an independently certified or assessed maturity level, or Australian Government endorsement.
Our application protections include restricted administrator access, multi-factor authentication, limited-duration sessions, revocable trusted-browser credentials, password hashing, protection of authentication secrets, and controls intended to prevent unauthorised form submissions and abusive requests. We use HTTPS for the public service. Access to personal information is limited to authorised people and service providers who need it for their work. We maintain security and backup practices and review risks as the service changes.
No website, transmission method or security framework can guarantee absolute protection. This does not reduce our responsibility to take reasonable protective measures, maintain them and respond appropriately to incidents. Please report a suspected security or privacy issue to privacy@pridecompass.com.au, without including unnecessary personal data or attempting to access someone else's information.
We retain information only for as long as needed for its permitted purpose or a legal retention requirement. This includes maintaining an active account or listing, resolving an enquiry or dispute, demonstrating consent, respecting an unsubscribe request and measuring site and listing usage for as long as reasonably needed. We review retained information and securely destroy or de-identify it when no longer needed, unless Australian law or a court or tribunal order requires retention. Backup copies are restricted from ordinary use and removed through the backup retention cycle.
If a data breach occurs, we take steps to contain it, assess the risks and reduce harm. We promptly assess suspected breaches, including whether unauthorised access, disclosure or loss is likely to cause serious harm and whether remedial action can prevent that harm. Where the Notifiable Data Breaches scheme applies, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required, including as soon as practicable after identifying an eligible data breach.
11. Access, correction and removal
You can ask us to give you access to personal information we hold about you, correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, or consider a request to delete information or remove it from a public listing. Contact our Privacy Officer using the email above.
We may take proportionate steps to verify your identity and clarify the request. We aim to respond within 30 days and will explain if more time is needed. We do not charge to make a request or correct information. If providing access would involve a reasonable charge, we will explain it beforehand.
Deletion is not an unconditional right under Australian privacy law. We may need to retain some information for legal obligations or another permitted purpose. If we refuse access or correction, we will give written reasons where required and explain complaint options. If a correction is disputed, you may ask us to associate a statement with the information. Where required, we will take reasonable steps to notify previous recipients of a correction if you ask us to do so.
12. Privacy complaints
Please email our Privacy Officer with details of your concern and the outcome you seek. We will acknowledge your complaint, investigate it and aim to provide a written response within 30 days. If we need more time, we will explain why and keep you informed.
If you are dissatisfied with our response or have not received a response within 30 days, you can contact the OAIC to ask about your options or lodge a complaint within its jurisdiction. Visit OAIC privacy complaints or call 1300 363 992. Marketing complaints can also be made to the Australian Communications and Media Authority.
13. Changes to this policy
We publish updates on this page and change the effective date. For material changes, we take reasonable steps to bring them to your attention. Updating this policy does not itself give us consent for new uses of personal information.