Privacy Policy
Last updated: 30 August 2026
Ian Blaney ABN 63916898422 ("we", "us", "our") operates the Spesh platform. We are
committed to protecting your privacy and handling your personal information in accordance with
the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs).
This policy explains what information we collect, why we collect it, how we use it, and your
rights in relation to it.
1. What Personal Information We Collect
Depending on how you use Spesh, we may collect:
Members (consumers)
- Name and email address (collected at registration)
- Password (stored as a one-way cryptographic hash — we cannot read it)
- Wishlist items and saved specials — when you add one and have granted location permission, we also record the suburb and postcode your device was in at the time, so we can tell businesses what is being asked for in their area (see section 5)
- Location information, in the circumstances described in section 5
- Activation records — where you scan a venue's activation code to unlock an offer, we record which special and business it was, the time, and how far your device reported being from the venue (see section 6)
- Push notification subscriptions, including the notification address issued by your browser and, if you enable nearby alerts, the location associated with that device (see section 7)
- Which specials you view and how often (stored as anonymous view counts — no device or browser data is retained by us)
- IP address — recorded against a short-lived counter when you perform an action we rate-limit, such as logging in, requesting a password reset, looking up an ABN, scanning an activation code, or submitting a review, so that we can limit how often those requests can be made. Where the limit applies to an email address rather than a device, the email address is recorded in the same way. These counters are stored in our database and are deleted automatically within a few hours (see section 12)
Business owners
- Business name, address, suburb, state, and postcode
- Business phone number, and your ABN, your ACN, or both
- Owner name and email address
- Special/promotion details and uploaded images
- Geographic coordinates derived from your business address (for mapping)
- Your subscription plan and, where you subscribe to a paid plan, the customer identifier issued to us by our payment processor (see section 10)
- Aggregate activation and scan reporting for your own specials (see section 6)
- Verification records — the outcome of checking your ABN against the Australian Business Register or, for a registered company that holds no ABN, a record that one of our administrators checked your ACN against the ASIC register by hand, the company name shown there, and who approved it
- Where you use Spesh Reviews, your review settings — including the Google Business Profile you have confirmed as yours and the address you want reply notifications sent to (see section 8)
People leaving a review
- The rating you gave, any tags you chose, and anything you wrote (see section 8)
- Your email address — only if you choose to supply one so the business can reply to you
We do not collect payment card details. Card payments are handled entirely by Stripe and
never pass through our systems.
2. How We Collect Information
We collect information:
- Directly from you — when you register, update your profile, list a business or special, scan an activation code, or answer a review request.
- Automatically — Google Analytics 4 and Google Tag Manager collect device type, browser, and session data on our behalf when you use the platform. We do not collect this data directly into our own systems.
- From your device — location data, when you grant browser permission, and a push notification address, when you enable notifications.
- From third parties — address geocoding via Geoapify to convert a business address into map coordinates; reverse geocoding via OpenStreetMap's Nominatim service to convert a member's coordinates into a suburb and postcode; ABN verification via the Australian Business Register; for a registered company that holds no ABN, a manual check of the public ASIC company register; subscription status from Stripe.
3. Why We Collect and Use Your Information
We collect and use personal information to:
- create and manage your account;
- display relevant local specials based on your location;
- allow business owners to list, manage, and promote their specials;
- unlock offers that require an in-venue scan, and confirm to the business that an activation was genuine;
- send you notifications you have asked for, including alerts when you are near a participating venue;
- provide businesses with reporting about their own specials;
- pass your feedback to the business it is about, and carry its reply back to you;
- confirm that a business is the legal entity it claims to be;
- administer paid subscriptions and process payments through our payment provider;
- send transactional emails (e.g. password reset and email verification links) via our email provider, Resend;
- analyse platform usage and improve our service;
- detect and prevent fraud, abuse, and security incidents; and
- comply with our legal obligations.
We will not use your personal information for a purpose other than those listed above without
your consent, unless required or authorised by law (APP 6).
4. Cookies and Analytics
Spesh uses cookies and similar technologies for session management and analytics. Specifically:
- Session cookie — a secure, HTTP-only JWT cookie used to keep you logged in.
- CSRF token — a security cookie that protects against cross-site request forgery.
- Google Analytics 4 (GA4) — we use GA4 to understand how users interact with the platform. GA4 may set its own cookies. Data is processed by Google in accordance with their privacy policy. You can opt out via Google's opt-out tool.
- Google Tag Manager — used to manage analytics and tracking tags.
You can control cookies through your browser settings. Disabling cookies may affect the
functionality of Spesh.
5. Location Data
Spesh uses your device's location in five distinct ways. All of them depend on the permission
you grant through your browser, which you can deny or revoke at any time.
- Browsing nearby specials — your position is used to sort and filter what you see. It is used for that request and is not written to our database.
- Nearby alerts — if you turn on push notifications, the location of that device is stored on our servers, linked to your account, so we can send you specials near you. It is updated when your device re-registers. Turning notifications off removes it (see section 7).
- Arrival reminders — while the Spesh app is open in the foreground, your device may check its position against a list of nearby participating venues so it can remind you about an offer when you arrive. The reminder is decided on your device; we receive your approximate position when the surrounding list of venues is refreshed.
- Activating an offer — when you activate a special by scanning a code in-venue, your position at that moment is compared with the venue's location. We do not store your coordinates; we store the resulting distance (see section 6).
- Adding to your wishlist — when you add an item, your coordinates are sent to OpenStreetMap's Nominatim service, which returns the suburb and postcode. That suburb and postcode are stored on our servers against your account identifier, alongside the item, so we can show businesses what shoppers in their area are looking for. Your coordinates themselves are not stored.
If you decline location access you can still browse Spesh and still activate offers by
scanning a code — some features will simply be less useful.
For business listings, we convert the business street address into geographic coordinates
using Geoapify. These coordinates are stored to enable location-based search.
6. Activation Records
Some specials only become available when you scan a code displayed inside the venue. When you
activate one, we create a record containing:
- the special and the business it belongs to;
- your account identifier, if you were signed in;
- the date and time of activation;
- whether a location check was performed and, if so, the distance in metres between your device and the venue — not your coordinates;
- which printed item the code was scanned from;
- a randomly generated visit identifier, which groups the offers you activate during a single visit to one venue so that the business can tell repeat orders from repeat customers. It is created on your device, is not linked to your account or to any other venue, and is discarded when you leave or close the page; and
- whether staff marked the code as handed over, and when.
Because these records show that a particular account was at a particular venue at a particular
time, we treat them as sensitive in practice. They are used to make the offer work, to give
the business accurate reporting about its own specials, and to detect codes that have been
copied or shared outside the venue. They are not used to build a profile of your movements,
and we do not disclose individual activation records to businesses in a form that identifies
you by name or email — a business sees counts, times, and redemption codes for its own
specials.
You can activate an offer without being signed in, in which case no account identifier is
recorded.
7. Push Notifications
If you opt in to notifications, your browser issues us a unique notification address for that
device. We store it together with your account identifier and, where you have granted location
permission, the device's location, so that alerts can be limited to specials near you.
Delivering a notification necessarily involves the push service operated by your browser or
device vendor — for example Google, Apple, or Mozilla. The notification content passes through
that service, which is generally located overseas (see section 10).
You can withdraw consent at any time. Turning notifications off in Spesh deletes the stored
subscription for that device immediately, including any location held with it. Revoking
notification permission in your browser or device settings instead stops delivery at once, and
we delete the stored subscription when the push service next tells us it is no longer valid.
If you re-enable notifications without granting location permission, any location previously
held with that subscription is cleared.
8. Reviews and Private Threads
A business using Spesh Reviews can display a code or link inviting the people it serves to
rate their visit. You do not need a Spesh account to answer one, and we do not ask you to
identify yourself. When you answer, we record:
- the rating you gave, any tags you selected, and anything you wrote;
- which business it was about, which printed card or link you answered from, and the date and time;
- whether you went on to leave a public review on Google — we record that you were handed over, never what you wrote there; and
- your email address, only where you choose to give one so the business can reply. It is optional, and everything else works without it.
Where you write something, your words open a private thread between you and that business.
The business reads and answers it in its own inbox on Spesh. We do not show the
business your email address — it sees only that a reply is possible. We pass each
reply to you by email through Resend, and that email carries the only link back to the
thread. Anyone who holds that link can read the thread, so treat it as private and do not
forward it.
Both routes are offered at every rating: we do not filter who is invited to review, or hide
the public option from anyone based on what they told us.
If you choose the Google option you leave Spesh at that point, and what you post on Google
Maps is public and governed by Google's terms and privacy policy rather than ours. We cannot
see, edit, or remove it.
To have a review or a message you sent deleted, email support@speshoffers.com and tell us which business it concerned and roughly when. You do not need an account for us
to act on that.
9. Business Content and Social Publishing
Spesh promotes listed specials on its own social media accounts. Where a business's special is
selected, the product name, price, description, image, and business name and suburb may be
published to Facebook and Instagram by us. This is business listing content, not the personal
information of members, and it is content the business has already published on Spesh.
Once published to a third-party platform, that content is subject to that platform's own terms
and privacy practices and may remain visible there after it is removed from Spesh.
10. Disclosure of Personal Information
We do not sell your personal information. We may disclose it to:
- Service providers — including MongoDB Atlas (database hosting), Cloudflare R2 (image storage), Resend (transactional email), Geoapify (geocoding), and Stripe (payment processing for paid business plans), each engaged under contractual obligations to protect your data;
- OpenStreetMap Foundation — your coordinates are sent to its Nominatim service to be converted into a suburb and postcode when you add a wishlist item, as described in section 5. Nominatim is a public service and is not engaged by us under contract;
- Push services — the notification service operated by your browser or device vendor (such as Google, Apple, or Mozilla), only where you have enabled notifications;
- Meta Platforms — where a business listing is promoted on our Facebook or Instagram accounts, as described in section 9;
- Google — for analytics via GA4 and Google Tag Manager, and, where you choose to leave a public review, Google Maps, which you visit directly and post to yourself;
- Law enforcement or regulators — where required or authorised by Australian law; and
- Successors — in the event of a merger, acquisition, or sale of the business, subject to equivalent privacy protections.
Some of these third-party providers may be located outside Australia (including the United
States and the European Union). Where we disclose personal information overseas, we take
reasonable steps to ensure the recipient handles it in a manner consistent with the APPs
(APP 8).
11. Data Security
We take reasonable steps to protect your personal information from misuse, interference,
loss, and unauthorised access, modification, or disclosure (APP 11), including:
- encrypted HTTPS connections across the platform;
- passwords stored using bcrypt hashing — never in plain text;
- HTTP-only, same-site cookies for authentication tokens;
- rate limiting and account lockout on login to prevent brute-force attacks;
- cryptographically signed activation codes, which a business can retire and reissue at any time;
- CSRF token validation on all form submissions; and
- access controls limiting database access to authorised services only.
No method of transmission over the internet is completely secure. If you become aware of a
security issue, please contact us immediately at support@speshoffers.com.
12. Data Retention
We retain your personal information for as long as your account is active or as needed to
provide the service. More specifically:
- Account details — kept while your account is open.
- Activation records — kept for up to 24 months so that businesses can report on their specials, after which they are deleted or de-identified. If you close your account sooner, the link to your account identifier is removed and only anonymous counts remain.
- Push subscriptions — kept until you disable notifications, the subscription expires, or your browser reports it as no longer valid.
- Business listings and images — kept while the listing is live and for a reasonable period afterwards.
- Reviews and thread messages — kept while the business's account is open, so that it can go back to what a customer told it. Ask us and we will delete your review, your messages, and any email address held with them.
- Rate-limiting counters — the IP address or email address recorded against a request counter is deleted automatically within a few hours of the window it belongs to.
If you close your account, we will delete or de-identify your personal information within a
reasonable time, unless we are required to retain it by law (for example, for taxation or
regulatory purposes).
13. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access — request a copy of the personal information we hold about you, including your activation history and any review you have left (APP 12);
- Correction — request that we correct inaccurate, out-of-date, or incomplete information (APP 13);
- Anonymity — where lawful and practicable, interact with us without identifying yourself; and
- Complaint — lodge a complaint with us or with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.
To exercise any of these rights, contact us at support@speshoffers.com.
We will respond within 30 days.
14. Children's Privacy
Spesh is not directed at children under the age of 18. We do not knowingly collect personal
information from anyone under 18. If you believe a child has provided us with personal
information, please contact us and we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of
material changes by email or via an in-app notification. The updated policy will take effect
from the date shown at the top of this page. We encourage you to review this policy
periodically.
16. Complaints
If you have a complaint about how we have handled your personal information, please contact
us first at support@speshoffers.com.
We will acknowledge your complaint within 5 business days and respond substantively within 30
days.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992
GPO Box 5218, Sydney NSW 2001 This Privacy Policy has been prepared with reference to the Privacy Act 1988 (Cth)
and the Australian Privacy Principles. It does not constitute legal advice. You should seek
independent legal advice if you require it.