Clause 1Who we are
This policy applies to GRIPSWICH PTY LTD (ABN 88 692 673 751 , ACN 692 673 751), trading as GRIPswich Bouldering at 17a Thorn St, Ipswich, QLD, 4306, and to this website, gripswich.au.
Our Privacy Officer is the person to talk to about anything on this page. Email info@gripswich.au with "Privacy" in the subject line, or write to Privacy Officer, GRIPswich Bouldering, 17a Thorn St, Ipswich, QLD, 4306.
Clause 2Our commitment
We handle your personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles.
Some small businesses are exempt from the Privacy Act. We don't rely on that exemption. Because we collect health information — the medical declarations on our waiver, and our injury and first-aid records — and because coaching and induction are aimed at helping people participate safely, we treat ourselves as fully covered, and this policy is written to the standard the Act sets.
Plainly: we do not sell, rent or trade your personal information, to anyone, for any reason. Nothing you give us gets monetised.
Clause 3What we collect
| Category | What's in it |
|---|---|
| Enquiries | Your name, email address and whatever you write in the message when you use our contact form. |
| Gift card purchases | When you buy a gift card on our site: your name and email address, the first name of whoever it's for if you give us one, and the message you write on the card. Your card details go straight to our payment provider and never reach our systems. We don't ask for the recipient's email address, so we never hold it. |
| Waiver & sign-up details | Your first and last name, date of birth, gender, email, phone number and postcode; the affirmation you agreed to, which version of the waiver it was, the date and time you signed, and the IP address and browser you signed from. |
| Emergency contact | The name and phone number of the person you'd like us to call if something happens to you here. |
| Health information | Medical conditions, injuries or fitness matters you tell us about, and any first-aid we give you or incident we record. See clause 6. |
| Marketing preference | Whether you ticked "keep me up to date" when you signed up, and your answer to "how did you hear about us" — which helps us understand what's working. |
| Membership and account | Contact details, your membership type and status, your member code and wallet pass, induction status, and your login credentials (your password is stored hashed — we can't read it). |
| Your photo (optional) | A photo of your face, if you choose to add one, so our reception staff can match your name to your face when you check in. It is entirely optional — nothing is refused to you for not having one, and you can remove it yourself at any time from your member portal. It is shown only to our staff and to you; it is never published, never used in marketing, and never used for automated face recognition — a human at the desk looks at it, and that is all. For members under 18, a photo can only be added by our staff at reception with a parent or guardian present, and we record which staff member added it. Photos are deleted when your membership record is deleted. |
| Visit history | Every check-in: when you scanned in, whether entry was allowed, and why not if it wasn't. |
| Bookings | Classes and inductions you've booked, attended, or cancelled — including late cancellations and no-shows, and whether either attracted the $10 fee. |
| Payments | What you bought, when, how much, and whether it succeeded. Your card numbers and bank account details are handled by our payment providers and never stored on our systems — we only see the last few digits and the result. |
| Concessions | That we sighted a valid student or essential-services ID, and when. We record that we checked; we don't keep a copy of the card. |
| Children's information | For each under-18 you sign the waiver for: their first and last name, date of birth, gender, and your yes/no answer to us using photos they appear in. Plus their health declaration, program attendance, and your own details as their parent or guardian. See clause 7. |
Health information, and anything you tell us about a disability, is sensitive information under the Privacy Act and gets the extra protections in clause 6.
Clause 4How we collect it
Almost always directly from you: on the waiver form, at the front desk, when you join, when you book a class, when you scan in, or when you email us.
Sometimes we collect it from someone else — a parent enrolling a child, one adult signing up a family membership, or a school or group organiser making a booking. If you've been signed up by someone else, this policy still applies to you, and you can still exercise every right in it.
We'll always tell you, at the point of collection, why we're asking. To climb, we need a signed waiver, a completed induction, and an emergency contact — without those we can't let you on the wall, and we'll tell you that up front rather than after you've paid. The rest is optional: your phone number, your postcode, whether you want our emails, and (for gender) a "prefer not to say" is always there. Telling us about a medical condition is your choice too — see clause 6 for what we can and can't do if you leave it out.
Clause 5Why we collect it
- To let you climb safely — checking you have a current waiver and completed induction, knowing about a condition that affects your safety, and knowing who to call if something goes wrong.
- To run your membership — billing you, applying your discounts, managing freezes and cancellations, and showing you your own history in the member portal.
- To run classes and programs — rosters, attendance, coach-to-climber ratios, and marking inductions complete.
- To meet our legal obligations — work health and safety records, incident reporting, tax and accounting records, and responding to lawful requests.
- To respond to you — answering enquiries and complaints.
- To make the gym better — understanding how busy we get and when, so the "busy right now" gauge on this site is honest and we staff the floor properly. This uses check-in counts, not who you are.
- To understand our community — we collect gender to track and encourage gender-diversity in climbing, your postcode to understand where our climbers come from and tailor what we offer, and how you heard about us so we know what's working. None of this is ever sold or used to single you out.
- To tell you about things, if you've said we can. See clause 12.
We don't use your information for anything else without asking you first, unless the law requires it.
Clause 6Health information
Health information is the most sensitive thing we hold, and we treat it that way.
- We collect it only with your consent, and only what we actually need to keep you safe — a condition that affects how you should climb, or an injury we should know about. (Your emergency contact is different: we do ask everyone for one, because it's who we'd call if you couldn't. It's listed on its own in clause 3.)
- You can decline to tell us about a condition. If you do, we'll still let you climb; we just won't be able to make allowances we don't know about, and our staff will have less to hand a paramedic.
- It's used for safety, supervision, first aid, incident management, insurance and legal claims — and nothing else.
- We never use health information for marketing. Not ever, not in aggregate, not to decide who to send an offer to.
- Access is limited to authorised staff, under named logins, and we only open a health record when there's an actual reason to.
- For a climber under 18, their parent or guardian gives this consent, and can withdraw it.
Want something removed from your health record with us? Email info@gripswich.au and we'll remove it, unless it forms part of an incident record we're required to keep.
Clause 7Children and young people
- Under 18s can't sign our waiver themselves — a parent or legal guardian completes it for them, and gives consent for their information to be collected.
- We generally treat climbers aged 15 and over as able to make their own decisions about their own account and the messages we send them. For under-15s, we deal with a parent or guardian.
- A parent or guardian can ask to see, correct, or have us delete their child's information at any time.
- We never send marketing to under-18s. Anything promotional goes to the parent or guardian on the account.
- We don't build profiles of children, and we don't use anything about a child for anything beyond running their climbing, their program and their safety.
How we keep children safe more broadly — coach screening and Blue Cards, supervision, and how to raise a concern — is set out in our Child Safety policy.
Clause 8Photos and video
We take photos and video in the gym for our website and social media, because a climbing gym that looks empty in every picture looks like a bad climbing gym.
- For under-18s, we ask for a clear yes or no. When a parent or guardian signs the waiver, they answer — separately for each child — whether we may use images the child appears in. We record that answer against the child and honour it. The default is no: if it isn't ticked yes, we treat it as no.
- For adults, general photos and video of the gym in action may include you. If you'd rather not appear in anything we publish, tell us and we won't use it.
- We don't publish anyone's full name or identifying details alongside a photo without asking that person (or their parent) specifically.
- You can change your mind at any time. Email info@gripswich.au and we'll stop using your image and take down what we reasonably can. Once something's been shared onward by someone else we can't always claw it back, but we'll do what we can.
- When we're shooting deliberately, we'll say so — signage at the desk and a heads-up on the floor. If you'd rather not be in it, tell whoever's holding the camera and that's completely fine.
If you're filming your own climbing, that's your business — but please read the "ask before you film" rule in our Gym Rules. Plenty of people don't want to be in the background of someone else's video.
Clause 9CCTV
- We operate security cameras in public areas only — entry, reception, retail and the climbing floor.
- There are no cameras in change rooms, toilets or any other private area. Not now, not ever.
- Footage is used for safety, security, and working out what actually happened after an incident. It's not used to monitor how often you come in or how you're climbing.
- It's kept for a limited period and then overwritten, unless it's been retained for a specific incident or a lawful request.
- Access is limited to management. We'll release footage to police or an insurer where the law allows or requires it.
- Signage at the entrance tells you the cameras are there.
Clause 11Overseas storage
Your membership record is stored in Singapore. That's where your details, your waiver and health declarations, your bookings, your check-ins and your payment history sit. This changed on 21 September 2026 — the database used to be in Sydney, and we moved it to sit alongside the website so the front desk isn't waiting on a round trip to another country every time it looks you up. The company that provides that database service, Neon, is based in the United States.
So none of your membership information is held in Australia any more. Our website hosting is in Singapore too — our hosting provider has no Australian region — and that's where every page you load and every form you send us is handled, and where our server logs are kept. Our transactional email, and card processing through Square and Stripe, are in the United States.
Before we hand anything to an overseas provider we take reasonable steps to satisfy ourselves they'll handle it consistently with the Australian Privacy Principles. Under section 16C of the Privacy Act we remain accountable to you for what they do with it — if an overseas provider mishandles your information, that's on us, not on you to chase.
If you'd like to know exactly where your information sits at any given time, ask us and we'll tell you.
Clause 12Marketing and your choices
- We'll only send you marketing — new problems, comps, class blocks, member offers — if you've opted in. It's the "keep me up to date with deals and events" box on the waiver, and it starts unticked: we don't sign you up by default.
- Every marketing message has a working unsubscribe link, and we action it promptly.
- Unsubscribing from marketing doesn't stop the messages you actually need: booking confirmations, a failed payment, a class cancellation, a safety notice or an incident follow-up. Those aren't marketing and you can't opt out of them while you're a member.
- We don't send marketing to under-18s, and we never use health information to decide who gets what.
Want out of everything? Email info@gripswich.au and we'll take you off the list.
Clause 14How we keep it safe
- The whole site runs over an encrypted connection, and we enforce it.
- Passwords are stored hashed, not in readable form. Nobody here can look up your password.
- Card and bank details are handled by our payment providers and never touch our database.
- Only staff we've authorised can get into member records at all, each under their own named login, so every look-up is attributable to a person.
- We're building finer-grained access than that — so that health and incident detail is visible only to whoever is handling the incident — and we'll update this page when it's in place.
- Our systems are backed up, and access to those backups is restricted.
- Paper waivers and forms, where we use them, are kept secured and out of public view.
No system is perfectly secure, and we won't pretend otherwise. If something goes wrong, clause 17 says what we'll do.
Clause 15How long we keep it
| What | How long |
|---|---|
| Signed waivers and incident/injury records | Long enough to defend a potential injury claim. For someone who was under 18 when it happened, the clock only starts when they turn 18, so these are kept for many years. |
| Membership, payment and transaction records | At least 7 years, as our tax obligations require. |
| Check-in and booking history | While you're a member, and for a reasonable period after. |
| Contact-form enquiries | 12 months, unless it turned into something we need to keep. |
| Marketing contact details | Until you unsubscribe, then removed from the list. |
| CCTV footage | A short rolling period, then overwritten — unless retained for an incident. |
When we no longer need something for any of the purposes in this policy, and no law requires us to keep it, we destroy it or strip out anything that identifies you.
Clause 16Getting access, or fixing it
You can ask for a copy of everything we hold about you, and you can ask us to correct anything that's wrong. Both are free.
Email info@gripswich.au with "Privacy request" in the subject, or write to Privacy Officer, GRIPswich Bouldering, 17a Thorn St, Ipswich, QLD, 4306. We'll respond within 30 days.
- Some of it you can see yourself right now — your details, visit history, bookings and payments are all in your member portal.
- We may need to confirm it's really you before we hand anything over.
- If we can't give you something — because it would reveal someone else's personal information, or the law prevents it — we'll tell you which part and why.
- If we disagree that something is wrong, we'll note your disagreement on the record.
- You can ask us to delete information too. We'll do it where we're able; where a law requires us to keep something (an incident record, a tax record), we'll explain that.
Clause 17If there's a data breach
We're covered by the Notifiable Data Breaches scheme, and we take it seriously.
- If we suspect a breach, we'll investigate straight away and finish that assessment within 30 days.
- If personal information has been lost or accessed in a way that's likely to cause you serious harm, we'll tell you directly — by email to the address on your account — and we'll tell the Office of the Australian Information Commissioner.
- We'll tell you what happened, what information was involved, and what you should do about it.
We won't quietly sit on it. Health information and children's details are the kinds of data where a breach matters most, and those are exactly the kinds we hold.
Clause 18Complaints
Think we've mishandled your information? Tell us and we'll fix it.
- Write to us first. Email info@gripswich.au, marked "Privacy complaint". We'll acknowledge it within 2 business days and give you a full response within 30 days.
- Still not happy? Take it to the Office of the Australian Information Commissioner — the national privacy regulator. They'll generally want you to have come to us first.
Online: oaic.gov.au/privacy/privacy-complaints
Phone: 1300 363 992
Post: GPO Box 5288, Sydney NSW 2001
Complaining costs you nothing and won't affect your membership or how you're treated here.
Clause 19Changes to this policy
We'll update this page when what we do changes, with a new "last updated" date at the top. If a change materially affects how we handle your information, we'll tell members directly rather than relying on you to check.
Want a copy of this policy in another format? Ask and we'll send you one.