Privacy Policy

Last updated: 30 August 2026

Ian Blaney ABN 63916898422 ("we", "us", "our") operates the Spesh platform. We are committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs). This policy explains what information we collect, why we collect it, how we use it, and your rights in relation to it.

1. What Personal Information We Collect

Depending on how you use Spesh, we may collect:

Members (consumers)

  • Name and email address (collected at registration)
  • Password (stored as a one-way cryptographic hash — we cannot read it)
  • Wishlist items and saved specials — when you add one and have granted location permission, we also record the suburb and postcode your device was in at the time, so we can tell businesses what is being asked for in their area (see section 5)
  • Location information, in the circumstances described in section 5
  • Activation records — where you scan a venue's activation code to unlock an offer, we record which special and business it was, the time, and how far your device reported being from the venue (see section 6)
  • Push notification subscriptions, including the notification address issued by your browser and, if you enable nearby alerts, the location associated with that device (see section 7)
  • Which specials you view and how often (stored as anonymous view counts — no device or browser data is retained by us)
  • IP address — recorded against a short-lived counter when you perform an action we rate-limit, such as logging in, requesting a password reset, looking up an ABN, scanning an activation code, or submitting a review, so that we can limit how often those requests can be made. Where the limit applies to an email address rather than a device, the email address is recorded in the same way. These counters are stored in our database and are deleted automatically within a few hours (see section 12)

Business owners

  • Business name, address, suburb, state, and postcode
  • Business phone number, and your ABN, your ACN, or both
  • Owner name and email address
  • Special/promotion details and uploaded images
  • Geographic coordinates derived from your business address (for mapping)
  • Your subscription plan and, where you subscribe to a paid plan, the customer identifier issued to us by our payment processor (see section 10)
  • Aggregate activation and scan reporting for your own specials (see section 6)
  • Verification records — the outcome of checking your ABN against the Australian Business Register or, for a registered company that holds no ABN, a record that one of our administrators checked your ACN against the ASIC register by hand, the company name shown there, and who approved it
  • Where you use Spesh Reviews, your review settings — including the Google Business Profile you have confirmed as yours and the address you want reply notifications sent to (see section 8)

People leaving a review

  • The rating you gave, any tags you chose, and anything you wrote (see section 8)
  • Your email address — only if you choose to supply one so the business can reply to you

We do not collect payment card details. Card payments are handled entirely by Stripe and never pass through our systems.

2. How We Collect Information

We collect information:

  • Directly from you — when you register, update your profile, list a business or special, scan an activation code, or answer a review request.
  • Automatically — Google Analytics 4 and Google Tag Manager collect device type, browser, and session data on our behalf when you use the platform. We do not collect this data directly into our own systems.
  • From your device — location data, when you grant browser permission, and a push notification address, when you enable notifications.
  • From third parties — address geocoding via Geoapify to convert a business address into map coordinates; reverse geocoding via OpenStreetMap's Nominatim service to convert a member's coordinates into a suburb and postcode; ABN verification via the Australian Business Register; for a registered company that holds no ABN, a manual check of the public ASIC company register; subscription status from Stripe.

3. Why We Collect and Use Your Information

We collect and use personal information to:

  • create and manage your account;
  • display relevant local specials based on your location;
  • allow business owners to list, manage, and promote their specials;
  • unlock offers that require an in-venue scan, and confirm to the business that an activation was genuine;
  • send you notifications you have asked for, including alerts when you are near a participating venue;
  • provide businesses with reporting about their own specials;
  • pass your feedback to the business it is about, and carry its reply back to you;
  • confirm that a business is the legal entity it claims to be;
  • administer paid subscriptions and process payments through our payment provider;
  • send transactional emails (e.g. password reset and email verification links) via our email provider, Resend;
  • analyse platform usage and improve our service;
  • detect and prevent fraud, abuse, and security incidents; and
  • comply with our legal obligations.

We will not use your personal information for a purpose other than those listed above without your consent, unless required or authorised by law (APP 6).

4. Cookies and Analytics

Spesh uses cookies and similar technologies for session management and analytics. Specifically:

  • Session cookie — a secure, HTTP-only JWT cookie used to keep you logged in.
  • CSRF token — a security cookie that protects against cross-site request forgery.
  • Google Analytics 4 (GA4) — we use GA4 to understand how users interact with the platform. GA4 may set its own cookies. Data is processed by Google in accordance with their privacy policy. You can opt out via Google's opt-out tool.
  • Google Tag Manager — used to manage analytics and tracking tags.

You can control cookies through your browser settings. Disabling cookies may affect the functionality of Spesh.

5. Location Data

Spesh uses your device's location in five distinct ways. All of them depend on the permission you grant through your browser, which you can deny or revoke at any time.

  • Browsing nearby specials — your position is used to sort and filter what you see. It is used for that request and is not written to our database.
  • Nearby alerts — if you turn on push notifications, the location of that device is stored on our servers, linked to your account, so we can send you specials near you. It is updated when your device re-registers. Turning notifications off removes it (see section 7).
  • Arrival reminders — while the Spesh app is open in the foreground, your device may check its position against a list of nearby participating venues so it can remind you about an offer when you arrive. The reminder is decided on your device; we receive your approximate position when the surrounding list of venues is refreshed.
  • Activating an offer — when you activate a special by scanning a code in-venue, your position at that moment is compared with the venue's location. We do not store your coordinates; we store the resulting distance (see section 6).
  • Adding to your wishlist — when you add an item, your coordinates are sent to OpenStreetMap's Nominatim service, which returns the suburb and postcode. That suburb and postcode are stored on our servers against your account identifier, alongside the item, so we can show businesses what shoppers in their area are looking for. Your coordinates themselves are not stored.

If you decline location access you can still browse Spesh and still activate offers by scanning a code — some features will simply be less useful.

For business listings, we convert the business street address into geographic coordinates using Geoapify. These coordinates are stored to enable location-based search.

6. Activation Records

Some specials only become available when you scan a code displayed inside the venue. When you activate one, we create a record containing:

  • the special and the business it belongs to;
  • your account identifier, if you were signed in;
  • the date and time of activation;
  • whether a location check was performed and, if so, the distance in metres between your device and the venue — not your coordinates;
  • which printed item the code was scanned from;
  • a randomly generated visit identifier, which groups the offers you activate during a single visit to one venue so that the business can tell repeat orders from repeat customers. It is created on your device, is not linked to your account or to any other venue, and is discarded when you leave or close the page; and
  • whether staff marked the code as handed over, and when.

Because these records show that a particular account was at a particular venue at a particular time, we treat them as sensitive in practice. They are used to make the offer work, to give the business accurate reporting about its own specials, and to detect codes that have been copied or shared outside the venue. They are not used to build a profile of your movements, and we do not disclose individual activation records to businesses in a form that identifies you by name or email — a business sees counts, times, and redemption codes for its own specials.

You can activate an offer without being signed in, in which case no account identifier is recorded.

7. Push Notifications

If you opt in to notifications, your browser issues us a unique notification address for that device. We store it together with your account identifier and, where you have granted location permission, the device's location, so that alerts can be limited to specials near you.

Delivering a notification necessarily involves the push service operated by your browser or device vendor — for example Google, Apple, or Mozilla. The notification content passes through that service, which is generally located overseas (see section 10).

You can withdraw consent at any time. Turning notifications off in Spesh deletes the stored subscription for that device immediately, including any location held with it. Revoking notification permission in your browser or device settings instead stops delivery at once, and we delete the stored subscription when the push service next tells us it is no longer valid. If you re-enable notifications without granting location permission, any location previously held with that subscription is cleared.

8. Reviews and Private Threads

A business using Spesh Reviews can display a code or link inviting the people it serves to rate their visit. You do not need a Spesh account to answer one, and we do not ask you to identify yourself. When you answer, we record:

  • the rating you gave, any tags you selected, and anything you wrote;
  • which business it was about, which printed card or link you answered from, and the date and time;
  • whether you went on to leave a public review on Google — we record that you were handed over, never what you wrote there; and
  • your email address, only where you choose to give one so the business can reply. It is optional, and everything else works without it.

Where you write something, your words open a private thread between you and that business. The business reads and answers it in its own inbox on Spesh. We do not show the business your email address — it sees only that a reply is possible. We pass each reply to you by email through Resend, and that email carries the only link back to the thread. Anyone who holds that link can read the thread, so treat it as private and do not forward it.

Both routes are offered at every rating: we do not filter who is invited to review, or hide the public option from anyone based on what they told us.

If you choose the Google option you leave Spesh at that point, and what you post on Google Maps is public and governed by Google's terms and privacy policy rather than ours. We cannot see, edit, or remove it.

To have a review or a message you sent deleted, email support@speshoffers.com and tell us which business it concerned and roughly when. You do not need an account for us to act on that.

9. Business Content and Social Publishing

Spesh promotes listed specials on its own social media accounts. Where a business's special is selected, the product name, price, description, image, and business name and suburb may be published to Facebook and Instagram by us. This is business listing content, not the personal information of members, and it is content the business has already published on Spesh.

Once published to a third-party platform, that content is subject to that platform's own terms and privacy practices and may remain visible there after it is removed from Spesh.

10. Disclosure of Personal Information

We do not sell your personal information. We may disclose it to:

  • Service providers — including MongoDB Atlas (database hosting), Cloudflare R2 (image storage), Resend (transactional email), Geoapify (geocoding), and Stripe (payment processing for paid business plans), each engaged under contractual obligations to protect your data;
  • OpenStreetMap Foundation — your coordinates are sent to its Nominatim service to be converted into a suburb and postcode when you add a wishlist item, as described in section 5. Nominatim is a public service and is not engaged by us under contract;
  • Push services — the notification service operated by your browser or device vendor (such as Google, Apple, or Mozilla), only where you have enabled notifications;
  • Meta Platforms — where a business listing is promoted on our Facebook or Instagram accounts, as described in section 9;
  • Google — for analytics via GA4 and Google Tag Manager, and, where you choose to leave a public review, Google Maps, which you visit directly and post to yourself;
  • Law enforcement or regulators — where required or authorised by Australian law; and
  • Successors — in the event of a merger, acquisition, or sale of the business, subject to equivalent privacy protections.

Some of these third-party providers may be located outside Australia (including the United States and the European Union). Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it in a manner consistent with the APPs (APP 8).

11. Data Security

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11), including:

  • encrypted HTTPS connections across the platform;
  • passwords stored using bcrypt hashing — never in plain text;
  • HTTP-only, same-site cookies for authentication tokens;
  • rate limiting and account lockout on login to prevent brute-force attacks;
  • cryptographically signed activation codes, which a business can retire and reissue at any time;
  • CSRF token validation on all form submissions; and
  • access controls limiting database access to authorised services only.

No method of transmission over the internet is completely secure. If you become aware of a security issue, please contact us immediately at support@speshoffers.com.

12. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the service. More specifically:

  • Account details — kept while your account is open.
  • Activation records — kept for up to 24 months so that businesses can report on their specials, after which they are deleted or de-identified. If you close your account sooner, the link to your account identifier is removed and only anonymous counts remain.
  • Push subscriptions — kept until you disable notifications, the subscription expires, or your browser reports it as no longer valid.
  • Business listings and images — kept while the listing is live and for a reasonable period afterwards.
  • Reviews and thread messages — kept while the business's account is open, so that it can go back to what a customer told it. Ask us and we will delete your review, your messages, and any email address held with them.
  • Rate-limiting counters — the IP address or email address recorded against a request counter is deleted automatically within a few hours of the window it belongs to.

If you close your account, we will delete or de-identify your personal information within a reasonable time, unless we are required to retain it by law (for example, for taxation or regulatory purposes).

13. Your Rights

Under the Australian Privacy Principles, you have the right to:

  • Access — request a copy of the personal information we hold about you, including your activation history and any review you have left (APP 12);
  • Correction — request that we correct inaccurate, out-of-date, or incomplete information (APP 13);
  • Anonymity — where lawful and practicable, interact with us without identifying yourself; and
  • Complaint — lodge a complaint with us or with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.

To exercise any of these rights, contact us at support@speshoffers.com. We will respond within 30 days.

14. Children's Privacy

Spesh is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or via an in-app notification. The updated policy will take effect from the date shown at the top of this page. We encourage you to review this policy periodically.

16. Complaints

If you have a complaint about how we have handled your personal information, please contact us first at support@speshoffers.com. We will acknowledge your complaint within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):

Website: www.oaic.gov.au
Phone: 1300 363 992
GPO Box 5218, Sydney NSW 2001

17. Contact Us

Ian Blaney
Email: support@speshoffers.com

This Privacy Policy has been prepared with reference to the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It does not constitute legal advice. You should seek independent legal advice if you require it.