Privacy Policy

Effective date: 18 March 2026

PlaceLocal (“PlaceLocal”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use our website at https://placelocal.com.au, our application at https://app.placelocal.com.au, and any associated services (collectively, the “Services”).

This policy should be read alongside our Terms of Service. By using the Services, you consent to the practices described in this Privacy Policy.

Our core commitment: We do not sell your personal information to third parties. We collect only what we need to provide and improve our Services, and we handle your data with care. For any privacy questions, contact admin@placelocal.com.au.

1. Who We Are

PlaceLocal operates the PlaceLocal local business growth network — a platform connecting consumers with trusted local service providers, and providing business owners with tools to manage their online presence, reputation, and customer relationships.

For the purposes of applicable privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), PlaceLocal is the entity responsible for handling the personal information described in this policy.

2. Information We Collect

We collect personal information that you provide to us, that is generated by your use of the Services, and that we receive from third parties (such as Google). The categories of information we may collect include:

2.1 Account and Profile Information

  • Name and email address
  • Password (stored in hashed/encrypted form — we never store plaintext passwords)
  • Profile photo
  • Phone number (optional)
  • Business name, ABN/ACN, business address, service area, trading hours, and business category
  • Profile bio, service descriptions, portfolio images, and any other content you add to your profile
  • Account preferences and settings

2.2 Google Account Data (when you connect Google services)

  • Name, email address, and profile picture from your Google account (via Google Sign-In)
  • Google Calendar event data (when you connect Google Calendar integration)
  • Gmail data as needed for email integration features (when you connect Gmail)
  • Google Business Profile data (when you connect the Google Business Profile integration)
  • OAuth tokens (stored securely to maintain your connected integrations)

2.3 Billing and Payment Information

  • Billing name and address
  • Payment card type and last four digits (full card details are handled by our payment processor and never stored by us)
  • Transaction history and subscription status

2.4 Communications Data

  • Messages you send via in-platform contact forms or enquiry tools
  • Support communications (emails, tickets)
  • Notification preferences

2.5 Usage and Technical Data

  • IP address
  • Browser type and version
  • Operating system
  • Device type and identifiers
  • Pages visited, time spent, and actions taken within the Services
  • Referring URLs
  • Session identifiers and cookie data
  • Error logs and crash reports
  • API usage data

2.6 Reviews, Ratings, and User-Generated Content

  • Reviews and ratings you submit about businesses
  • Photos, comments, or other content you contribute to the platform

2.7 Partner and Referral Data

  • Contact details and business information of referral partners
  • Referral activity and commission data
  • Partner portal access logs

3. How We Collect Information

We collect information through the following means:

  • Directly from you — when you register an account, complete your profile, submit forms, make purchases, or contact us
  • Automatically — through cookies, session tracking, server logs, and similar technologies when you browse or use our Services (see Section 6)
  • From Google — when you sign in with Google or connect a Google service integration, with your explicit authorisation
  • From third-party analytics and advertising tools — such as Vercel Analytics, Google Analytics, or Facebook Pixel (see Section 7)
  • From other users — for example, when a business receives a review from a customer
  • From referral partners — when a partner submits a referral on your behalf
  • From payment processors — transaction confirmation and billing data

4. How We Use Your Information

We use the information we collect for the following purposes:

4.1 Providing and Operating the Services

  • Creating and managing your account
  • Displaying your business profile and listings on the platform
  • Processing transactions and managing subscriptions
  • Sending service-related notifications, invoices, and transactional emails
  • Facilitating communications between businesses and customers
  • Enabling connected Google integrations (Calendar, Gmail, Business Profile)
  • Running the partner and referral portal

4.2 Improving the Services

  • Analysing usage patterns to improve features and user experience
  • Debugging, testing, and fixing issues
  • Developing new features and services
  • Conducting internal research and analytics

4.3 Communications and Marketing

  • Sending service announcements, updates, and security alerts
  • Sending marketing communications about our Services (where you have opted in or where permitted by law)
  • Responding to your enquiries and support requests

4.4 Safety, Security, and Compliance

  • Detecting, preventing, and responding to fraud, abuse, and security incidents
  • Enforcing our Terms of Service and acceptable use policies
  • Complying with applicable legal obligations
  • Resolving disputes

4.5 Analytics and Advertising

  • Measuring the performance of our marketing campaigns
  • Building advertising audiences and enabling retargeting (where permitted)
  • Tracking conversions and return on ad spend

We process your personal information on the legal bases of contract performance (to deliver the Services you have requested), legitimate interests (to improve and secure our Services), your consent (for marketing and non-essential tracking), and legal obligation (where required by law).

5. Google Services Data

5.1 Scope of Google Data Collection

When you connect a Google service to PlaceLocal, we collect only the data required for the specific feature you are using. We do not request access to Google data beyond what is necessary.

5.2 Google Sign-In

When you use Google Sign-In, we receive your name, email address, and profile picture. We use this solely to create and manage your PlaceLocal account. We do not access any other Google account data via Sign-In.

5.3 Google Calendar

When you connect Google Calendar, we may read, create, update, and delete calendar events to support scheduling and appointment features. We do not use your calendar data for any purpose other than providing these features.

5.4 Gmail

When you connect Gmail, we may access your Gmail account to send emails on your behalf (e.g., client communications, invoices) and, where applicable, to read relevant email threads for integrated workflows. Gmail data is used solely for the email features you activate and is never used for advertising or profiling.

5.5 Google Business Profile

When you connect the Google Business Profile integration, we may access and update your business information, respond to reviews, and manage profile data on your behalf. This is done only within the permissions you grant and for the purpose of delivering this feature.

5.6 Google API Limited Use Policy

Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google data to provide or improve the user-facing features of PlaceLocal
  • We do not use Google data to serve advertisements
  • We do not allow humans to read your Google data unless you explicitly request support that requires it, it is necessary for security purposes, or we are required to by law
  • We do not sell, transfer, or use Google data for purposes unrelated to the features you have enabled

5.7 Revoking Google Access

You can revoke PlaceLocal’s access to your Google account at any time through your Google Account Permissions page or within your PlaceLocal account settings. After revocation, we will delete or cease using the associated Google data within a reasonable time, except as required by law.

6. Cookies and Tracking Technologies

6.1 What We Use

We use cookies, web beacons, pixel tags, local storage, and similar technologies to operate and improve the Services, remember your preferences, and understand how you interact with our platform.

6.2 Strictly Necessary Cookies

These cookies are essential for the Services to function. By using the Services, you agree to their use:

  • Authentication and session management cookies — maintain your logged-in state securely across the App
  • Security cookies — protect against CSRF and session hijacking attacks
  • Preference cookies — remember your language, theme, and configuration settings
  • Infrastructure cookies — used by our hosting and CDN providers (including Vercel and Supabase) for routing and performance

6.3 Analytics Cookies

We use analytics cookies to understand how visitors use the Services. Where required by law, we obtain your consent before placing analytics cookies.

6.4 Marketing and Advertising Cookies

We may deploy third-party advertising cookies, including those from Meta (Facebook Pixel) and Google (Google Ads conversion tracking and remarketing tags). Where required, these are only placed with your consent.

6.5 Session vs. Persistent Cookies

Session cookies expire when you close your browser. Persistent cookies remain on your device for a set period or until you delete them.

6.6 Managing Cookies

You can manage or delete cookies through your browser settings. Disabling strictly necessary cookies will impair the functionality of the Services.

7. Analytics and Advertising Technologies

We use the following analytics and advertising services, which may process your personal information according to their own privacy policies:

7.1 Vercel Analytics

We use Vercel Analytics on our marketing website (https://placelocal.com.au) to collect privacy-focused analytics data, including page views, referral sources, and browser types. For more information, see Vercel’s Privacy Policy.

7.2 Google Analytics

We may use Google Analytics to collect detailed usage data about visitors to our marketing site. You can opt out using the Google Analytics Opt-out Browser Add-on.

7.3 Facebook Pixel (Meta Pixel)

We may deploy the Facebook Pixel on our marketing website. You can manage Meta’s use of your data via Meta Ad Settings.

7.4 Google Ads Conversion Tracking

We may use Google’s conversion tracking tag to measure actions (such as sign-ups or purchases) that occur after a user clicks on one of our Google Ads. This data is used only for campaign optimisation.

7.5 Session Recording Tools

We may use session recording tools (such as Hotjar or similar) to record anonymised replays of user sessions to understand usability issues. These tools are configured to automatically mask sensitive fields such as passwords and payment data.

7.6 Future Tools

We may introduce additional analytics or advertising technologies in the future. We will update this policy accordingly and, where required, obtain your consent before deployment.

8. How We Share Your Information

We do not sell your personal information. We share your information only in the following limited circumstances:

8.1 Service Providers

We share information with trusted third-party service providers who assist us in operating the Services:

  • Supabase — database, authentication, and backend infrastructure
  • Vercel — hosting and edge delivery
  • Payment processors — for billing and transaction processing
  • Email delivery providers — for transactional and marketing emails
  • SMS providers — for notifications and communications features
  • Cloud storage providers — for file and media storage
  • Analytics providers — as described in Section 7
  • Customer support platforms — for managing support tickets

8.2 Google Services

Where you have authorised a Google integration, we share the minimum necessary data with Google APIs to enable that integration. This is subject to Google’s own privacy policies and terms.

8.3 Public Profile Data

Business profile information you choose to make public — including your business name, contact details, location, services, reviews, and photos — will be visible to all visitors of placelocal.com.au and may be indexed by search engines.

8.4 Referral Partners

If you were referred to PlaceLocal by a referral partner, we may share information about your account status with that partner for the purpose of validating and paying referral commissions. We share only the minimum information necessary for this purpose.

8.5 Legal and Safety Disclosures

We may disclose your information where required by law, regulation, or legal process, or where we believe in good faith that disclosure is necessary to protect the safety of our users, third parties, or the public, or to protect our rights and property.

8.6 Business Transfers

In the event of a merger, acquisition, restructure, or sale of all or part of our business, your personal information may be transferred to the successor entity. We will notify you of any such transfer.

8.7 With Your Consent

We may share your information with third parties where you have given us explicit consent to do so.

9. We Do Not Sell Your Data

PlaceLocal does not sell, rent, trade, or otherwise transfer your personal information to third parties for their own marketing or commercial purposes. We are not in the business of selling user data.

Where we use third-party analytics or advertising tools (such as the Facebook Pixel or Google Analytics), data flows to those providers are governed by your consent settings and the respective providers’ data use policies.

10. Referral Partners

All referral partners who access the PlaceLocal Partner Portal must agree to our Terms of Service and this Privacy Policy as a condition of participation. Partners are required to:

  • Handle any personal information they encounter in connection with the Services in accordance with applicable privacy laws
  • Not use customer or user data obtained through the Services for their own marketing or commercial purposes
  • Maintain confidentiality of non-public information accessed through the Partner Portal
  • Comply with all applicable data protection obligations

Partners who violate these requirements may have their access terminated and may be held liable for any resulting harm.

11. Security Measures

We take the security of your personal information seriously and implement a range of technical and organisational measures to protect it.

11.1 Technical Controls

  • Encryption in transit — all data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
  • Encryption at rest — sensitive data stored in our databases is encrypted at rest
  • Password hashing — passwords are never stored in plaintext; we use industry-standard hashing algorithms
  • Secure authentication — we support Google OAuth 2.0 and email-based authentication with email verification
  • Access controls — access to production systems and customer data is restricted to authorised personnel on a need-to-know basis
  • Infrastructure security — we rely on enterprise-grade cloud infrastructure (Supabase, Vercel)
  • Regular security updates — we keep our software dependencies and infrastructure patched and up to date
  • Session management — sessions are securely managed with appropriate expiry and revocation capabilities

11.2 Organisational Controls

  • Staff training on data handling and security practices
  • Vendor due diligence for third-party service providers
  • Incident response procedures for potential data breaches

11.3 Limitations

No method of transmission over the internet or method of electronic storage is 100% secure. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Privacy Act 1988 (Cth) Notifiable Data Breaches scheme.

11.4 Your Responsibilities

You are responsible for maintaining the security of your account credentials and for promptly notifying us of any suspected unauthorised access to your account.

12. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Services.

  • Account data — retained for the duration of your account and for a reasonable period following closure
  • Billing and transaction records — retained for at least 7 years as required by Australian tax and accounting law
  • Communication records — retained for a reasonable period to support customer service and dispute resolution
  • Usage and analytics data — retained in aggregated or anonymised form indefinitely; identifiable usage logs are retained for a shorter period
  • Google OAuth tokens — deleted or invalidated promptly upon revocation of access or account closure
  • Backup data — retained for a limited period in accordance with our backup and disaster recovery schedule

When data is no longer required, we delete or anonymise it in a secure manner.

13. Your Rights and Choices

You have the following rights in relation to your personal information, subject to applicable law:

13.1 Access

You have the right to request a copy of the personal information we hold about you.

13.2 Correction

You have the right to request that we correct any inaccurate or incomplete personal information we hold about you.

13.3 Deletion

You may request that we delete your personal information. We will honour such requests where we are not required by law to retain the information and where deletion is technically feasible.

13.4 Restriction and Objection

In certain circumstances, you may have the right to restrict how we process your personal information or to object to certain processing activities.

13.5 Withdrawal of Consent

Where we rely on your consent to process personal information, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

13.6 Opt-Out of Marketing Communications

You may opt out of marketing communications at any time by clicking the “unsubscribe” link in any marketing email we send, or by contacting us at admin@placelocal.com.au.

13.7 Google Integration Control

You can revoke PlaceLocal’s access to your Google account at any time via your Google Account Permissions page.

13.8 How to Exercise Your Rights

To exercise any of the above rights, please contact us at admin@placelocal.com.au. We will respond to your request within 30 days.

13.9 Complaints

If you are not satisfied with how we have handled your personal information, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

14. Children's Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we may have collected information from a child, please contact us at admin@placelocal.com.au.

15. International Data Transfers

PlaceLocal is based in Australia, and our Services are primarily intended for Australian users. However, some of our third-party service providers may process and store your data in countries outside Australia, including the United States and other jurisdictions. These providers are required to uphold appropriate data protection standards.

By using the Services, you acknowledge that your information may be transferred to, stored in, and processed in countries other than Australia.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the effective date at the top of this page and, where appropriate, by sending you an email notification or displaying a prominent notice within the Services.

Your continued use of the Services following the posting of changes constitutes your acceptance of the revised Privacy Policy.

18. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:

PlaceLocal — Privacy Enquiries

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner (OAIC)
Phone: 1300 363 992
This Privacy Policy was last updated on 18 March 2026. © 2026 PlaceLocal. All rights reserved.
Privacy Policy — PlaceLocal | PlaceLocal