Privacy Policy
Last updated 18 June 2026
Spotbagger is operated by Heysailor Pty Ltd (ACN 698138162, ABN 35698138162), based in Tasmania, Australia ("we", "us", "our"). This policy explains what personal information we collect when you use Spotbagger, how we use and protect it, and the choices you have. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By creating an account or using Spotbagger you agree to the handling of your personal information as described here.
Information we collect
We only collect what we need to run the service:
- Account details — your email address. We use magic-link sign-in, so we never collect or store a password.
- Notification details — if you opt in to SMS alerts, the mobile number you provide.
- Watch settings — the locations, dates and preferences for the bookings you ask us to watch.
- Billing records — credit balance and transaction history. Card details are entered directly with our payment processor (Stripe); we never see or store your full card number.
- Technical data — basic log information such as IP address, browser type and timestamps, used to keep the service secure and working.
How we use your information
We use personal information to:
- create and authenticate your account;
- check the booking sites you've asked us to watch and notify you when a spot opens;
- send you transactional email and, where you've opted in, SMS alerts;
- process top-ups, maintain your credit balance and keep billing records;
- protect the service against abuse, fraud and security threats; and
- respond to your enquiries and meet our legal obligations.
We do not sell your personal information, and we do not use it for advertising or send you marketing you didn't ask for.
Service providers we share data with
We share limited personal information with trusted providers only so they can perform a service for us. Each handles your data under its own privacy terms:
- Stripe — payment processing and card handling for top-ups.
- Postmark — delivery of sign-in and notification emails.
- Twilio — delivery of SMS alerts (only if you opt in).
- Cloudflare — bot protection (Turnstile) and network security on our public forms.
- Our hosting provider — secure infrastructure on which Spotbagger runs.
Some of these providers may store or process data outside Australia (for example, in the United States or the European Union). Where that happens we take reasonable steps to ensure your information is handled consistently with the APPs.
Cookies
We use a small number of strictly necessary cookies to keep you signed in and to protect our sign-in form. We do not use third-party advertising or cross-site tracking cookies.
How long we keep it
We keep your personal information for as long as your account is active and for as long as we need it to provide the service, meet our legal and financial-record obligations, and resolve disputes. When you close your account we delete or de-identify your personal information, except where we are required to retain certain records (such as billing records) by law.
How we protect it
We take reasonable technical and organisational steps to protect your information against loss, misuse and unauthorised access — including encrypted connections, passwordless sign-in, and limiting access to the people and systems that need it. No method of transmission or storage is completely secure, but we work to keep your data safe and to respond promptly to any incident.
Your rights
Under the Australian Privacy Principles you can:
- request access to the personal information we hold about you;
- ask us to correct information that is inaccurate or out of date;
- opt out of SMS alerts at any time from your account settings; and
- ask us to delete your account and associated personal information.
To make a request, email us at hello@heysailor.nz. We'll respond within a reasonable time and may need to verify your identity first.
Complaints
If you believe we've mishandled your personal information, please contact us first at hello@heysailor.nz so we can try to put it right. If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes to this policy
We may update this policy from time to time. When we do, we'll change the "Last updated" date above. Material changes will be communicated through the service or by email.
Contact us
Heysailor Pty Ltd
ACN 698138162 · ABN 35698138162
Tasmania, Australia
hello@heysailor.nz