Effective date: 1 March 2025 · MysteryBoxAU Pty Ltd (ABN XX XXX XXX XXX)
MysteryBoxAU Pty Ltd (“we”, “us”, “our”) is bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth). We are committed to protecting the personal information we hold about you and to handling it responsibly.
This Policy explains how we collect, hold, use, and disclose personal information in connection with MysteryBoxAU. By using our platform you agree to the practices described in this Policy.
We collect personal information that is necessary for the provision of our services. This may include:
Account Information
Transaction Information
Technical Information
We only collect personal information that is reasonably necessary for our business functions. We do not collect sensitive information (as defined in the Privacy Act) unless you have consented and it is reasonably necessary.
We collect personal information:
We use your personal information to:
We will not use your information for a secondary purpose unless that purpose is related to the primary purpose of collection and you would reasonably expect such use, or you have consented.
We may disclose personal information to the following third parties who assist us in operating the Platform:
| Party | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | USA (Privacy Shield) |
| Supabase, Inc. | Database hosting & auth | USA / AWS |
| Vercel, Inc. | Web hosting & CDN | USA / Global |
| Shipping carriers | Prize delivery | Australia |
| Analytics providers | Usage analytics | Varies |
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may also disclose information where required by law, court order, or to protect our legal rights.
Some third parties are located overseas (primarily USA). By using our Platform, you consent to the transfer of your information to overseas recipients who are bound by comparable privacy protections.
We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access. Our security measures include:
If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
We may send you promotional emails about new boxes, prizes, and platform updates if you have opted in at registration or at any time in your account settings.
You may opt out of marketing communications at any time by clicking the “unsubscribe” link in any marketing email or by updating your preferences in your account settings. Opting out does not affect transactional communications required for account operation.
We use cookies and similar technologies to operate the Platform, remember your preferences, and analyse usage. Types of cookies used:
You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the Platform. We do not use advertising or tracking cookies from social media networks.
We retain personal information for as long as necessary to provide our services and comply with our legal obligations:
When personal information is no longer required, we will securely destroy or de-identify it.
Under the Australian Privacy Principles, you have the right to:
To exercise any of these rights, contact us at privacy@mysteryboxau.com.au. We will respond within 30 days. We will not charge a fee for access requests unless the request is complex or requires significant resources, in which case we will notify you in advance.
If you believe we have mishandled your personal information, please contact us first at privacy@mysteryboxau.com.au. We take all privacy complaints seriously and will investigate and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
We may update this Privacy Policy from time to time. Where changes are material, we will notify registered users by email at least 14 days before the changes take effect. The current version will always be available at mysteryboxau.com.au/privacy.
Contact our Privacy Officer
Email: privacy@mysteryboxau.com.au
MysteryBoxAU Pty Ltd · ABN XX XXX XXX XXX