Ulloora Privacy Policy
Version 1 · effective 5 October 2026
Ulloora Privacy Policy
Ulloora Pty Ltd | ABN 40 699 387 221
Version 1.0 | Prepared 4 October 2026 | Draft for operational confirmation
This policy explains how Ulloora handles personal information when you browse our marketplace, create an account, buy goods, book services, onboard as a vendor or contact us. It covers food and beverage, tutoring and child-related services, beauty and personal care, home and property services, and agriculture and general products.
1 Who we are and how to contact us
Ulloora Pty Ltd operates the Ulloora website, applications and related marketplace systems. Vendors are independent sellers and service providers. Our role as a marketplace does not remove our responsibility for personal information we collect or control.
For privacy enquiries, access or correction requests, consent withdrawal or complaints, contact the Privacy Officer at admin@ulloora.com.au, use the Platform help function, or write to Ulloora Pty Ltd, 153 Beauchamp Drive, The Ponds NSW 2769. Please mark your message Privacy. Do not send identity documents or detailed health information by ordinary email unless we have arranged a suitable secure process.
We handle personal information in accordance with applicable Australian privacy laws. Where the Privacy Act 1988 (Cth), the Australian Privacy Principles or a binding privacy code applies to us, we comply with it. This policy does not waive any statutory right or create blanket consent to collect, use or disclose information.
2 Information we collect and hold
Account and contact information includes your name, email address, telephone number, account credentials, confirmation that you are at least 18, and relevant billing, delivery or service addresses. We collect identity evidence only where proportionately needed for security, compliance or verification.
Transaction information includes orders, bookings, selected vendors, items or service scope, dates, delivery and pickup instructions, pricing, payment status, refunds, recurring arrangements, consent records, and the version of terms and transaction policies you accepted. Payment information available to us may include payment tokens, transaction identifiers and limited card details supplied by the payment provider.
Communications and support information includes messages, reviews, enquiries, complaints, photographs or documents you submit, and relevant dispute or incident evidence. Delivery or collection records may include tracking events, timestamps, photographs and PIN or QR confirmations.
Technical information may include IP address, browser and device type, operating system, access times, session identifiers, pages or functions used, error logs and security events. Section 8 explains cookies and location permissions.
For vendor onboarding, we collect business and contact details, ABN and registration information, qualifications, licences, insurance evidence, connected-account references and relevant compliance declarations. For child-facing providers, we collect the identity and working-with-children clearance information needed for the required checks, including verification results and expiry dates. These records may contain sensitive information and receive additional protection.
Food allergy information, relevant child support or health needs and information in safety reports can be sensitive information. We collect only the information reasonably necessary for the particular purpose. Beauty customers should provide detailed health and treatment suitability information directly and securely to their vendor. We do not require general medical histories, store home keys or alarm codes, or request unrelated sensitive information.
3 How we collect information and your choices
We generally collect information from you through registration, checkout, booking forms, vendor onboarding, messages, support interactions and device interactions with the Platform. We may also receive relevant information from a person authorised to book for you, your vendor, Stripe, an integrated delivery provider such as DoorDash, authorised verification sources, or authorities where lawful. We give a collection notice where required, including when information comes from another source.
You may browse public pages or make a general enquiry anonymously or using a pseudonym where lawful and practicable. Purchases and bookings require an adult account and sufficient accurate information to process and fulfil the transaction. You do not need to publish your full legal name in a public review.
If necessary information is not provided, we may be unable to create an account, process a payment, complete a check, deliver an order or arrange a suitable service. We explain the relevant consequence. Optional information and marketing choices are identified separately. We do not obtain consent by preselected boxes or by assuming that acceptance of customer terms authorises unrelated data use.
Before collecting sensitive information, we explain why it is needed, who needs it and what happens if it is not supplied, and obtain express consent where required. An exception is used only where law permits it. If unsolicited information is not information we could lawfully collect, we securely destroy or de-identify it where lawful and reasonable.
4 Children and information about other people
Account holders must be at least 18. A parent, guardian or authorised adult can book permitted services for a child. We collect only relevant booking details, age or age range where needed, emergency contact details, required permissions and information necessary for safe service delivery.
An adult providing another person’s information must have lawful authority to do so. We consider a child’s capacity to understand and consent to information handling in the circumstances and obtain the appropriate individual or parent or guardian consent where required. Adult booking authority does not automatically permit access to every private record about a child.
Booking consent, specific consent for an in-person session without parental attendance, and permission for photography, audio, video or publication are separate decisions. General acceptance of terms does not authorise recording. Approved child-service communication channels provide parent or guardian visibility as described at booking; do not treat those channels as private from the authorised supervising adult.
Allergy and child-service information is available only to Ulloora personnel and the relevant vendor who need it for the order or booking, subject to necessary lawful safety reporting. It is not used for advertising, unrelated profiling or marketing. We do not activate collection of this information until the required collection notices, consent, access restrictions, retention controls and incident procedures are operating.
5 Why we use personal information
We use information to operate accounts; identify the supplier; process and confirm orders, bookings and payments; communicate delivery or service instructions; administer recurring arrangements, cancellations and refunds; provide support; and keep appropriate transaction and acceptance records.
We also use necessary information to onboard and monitor vendors, perform required clearance checks, manage fraud and security risks, investigate disputes, moderate reviews, respond to safety incidents or recalls, and meet legal, accounting and reporting obligations. Verification information is used for its stated verification or safety purpose, rather than unrelated profiling. We may use ordinary technical and service information to identify errors and improve Platform usability and performance. We use de-identified or aggregated information where practical and do not describe information as anonymous if an individual can reasonably be identified.
Optional Ulloora marketing is covered by section 9. A materially different use requires an appropriate notice and any consent or other lawful basis required. We do not sell personal information or authorise vendors to use Ulloora customer details for their own marketing during the pilot.
6 Who receives information
We share information reasonably needed for the relevant transaction with the selected vendor, such as customer contact details, delivery or service location, order or booking requirements and necessary allergy or child-service information. Vendors do not receive unrelated account activity or other vendors’ customer records.
Stripe processes payments through vendor connected accounts. Payment details are entered through the payment provider’s secure facilities. Ulloora does not store full card numbers or card security codes. Stripe and the vendor receive information needed to process payment, verify transactions and manage authorised recurring charges, refunds or disputes.
Integrated delivery providers such as DoorDash, or the vendor’s own delivery workers, receive necessary delivery details, such as recipient contact details, address, delivery instructions and appropriate order references. We do not routinely send detailed health or child-service information to delivery providers.
Microsoft Azure provides our cloud hosting infrastructure. Other service providers may supply communications, security, technical support or analytics where enabled and disclosed. Access is limited to the service they provide and subject to appropriate safeguards. Section 7 addresses overseas handling.
We may disclose necessary information to professional advisers, insurers, banks or payment-dispute participants; to authorities where required or authorised by law; or to respond lawfully to serious safety concerns. A genuine business transfer may involve limited information disclosure under confidentiality and privacy safeguards, with notice where appropriate. We do not authorise a purchaser to disregard existing privacy obligations.
Public reviews and vendor profiles are visible to others. Public vendor profiles contain relevant business information, not private identity documents, clearance documents or bank details. Do not post health information, children’s identifying details, private contact information or payment information publicly. We may remove material that breaches privacy.
Independent vendors and third parties may have their own privacy obligations and policies for information they collect or control. Ask them about their practices when dealing with them directly. Their separate responsibilities do not exclude Ulloora’s obligations for its own handling or disclosures.
7 Storage and overseas handling
We use Microsoft Azure for Platform hosting. Cloud storage, backups, payment processing, communications and authorised support can involve different locations. Choosing an Australian hosting region does not by itself establish that every provider, backup or support activity stays in Australia.
Personal information may be disclosed to the following providers in the countries listed: Microsoft Azure — [INSERT COUNTRY/COUNTRIES]; Stripe — [INSERT COUNTRY/COUNTRIES]; DoorDash — [INSERT COUNTRY/COUNTRIES]; and other enabled email, SMS, analytics or support providers — [INSERT COUNTRY/COUNTRIES]. Where personal information is disclosed overseas, we take reasonable steps to ensure the recipient provides a standard of protection comparable to the Australian Privacy Principles and we comply with applicable cross-border disclosure requirements. You can contact us for details of the countries in which your information may be stored, processed or accessed. Where we disclose personal information overseas, we take reasonable steps to ensure appropriate protection and comply with applicable cross-border disclosure requirements. We do not rely on general acceptance of this policy as consent to waive protections or accountability. You can contact us about overseas handling.
8 Cookies device permissions and automation
We use necessary cookies or comparable technologies for account sessions, security, preferences and checkout. Technical logs assist troubleshooting and abuse prevention. Browser controls can restrict cookies, but essential account or checkout functions may then be unavailable.
Any optional analytics, advertising trackers or third-party pixels must be identified in the applicable cookie notice or settings before activation, with consent where required. DRAFT COMPLETION REQUIRED: confirm the actual technologies, providers, purposes, duration and available controls. Until confirmed, this draft does not authorise installation of optional trackers or describe them as already deployed.
If a feature requests location, camera or notification access, we explain the purpose and use the device permission controls. A manually entered address can be used where available. We do not require continuous background location tracking to browse or make an ordinary booking.
Automation may send confirmations, reminders and status messages, release expired payment holds, route complaints, process approved refunds or flag possible security issues using relevant account, transaction and technical information. Vendor acceptance remains necessary for relevant bookings. A fraud flag or automated status is not conclusive proof of misconduct or fulfilment. Contact support to request review of an adverse outcome or incorrect information.
Before introducing computer-assisted decisions that could significantly affect an individual’s rights or interests, we assess privacy risks and update this policy with the relevant decision types and personal information used where required by law. DRAFT COMPLETION REQUIRED: confirm any existing automated fraud, account suspension, verification, eligibility or refund decisions and describe their actual operation before publication.
9 Marketing and communications
Order confirmations, receipts, reminders, refund updates and essential security, safety or contract notices may be sent by email, SMS or through the Platform. These messages are connected to providing the service and are separate from optional marketing.
Ulloora promotional messages require a separate optional unticked opt-in with appropriate channel choices. You may unsubscribe using the message instructions, account settings where available, or admin@ulloora.com.au. We action unsubscribe requests within the period required by law. Withdrawing marketing consent does not stop essential transaction or safety messages.
Vendors must not add customers obtained through Ulloora to marketing lists or use their information for vendor promotions during the pilot. Referral features must not upload another person’s address book or send marketing to a referred person without an appropriate lawful basis. Allergy, child-service and other sensitive information is not used to target advertising.
10 Security retention and data breaches
We take reasonable technical and organisational steps to protect information from misuse, interference, loss, unauthorised access, modification and disclosure. Controls are proportionate to the information and include restricted access, secure transmission, appropriate authentication, provider safeguards and incident management. Internet services cannot be guaranteed completely secure.
We retain information only while reasonably needed for the purpose collected or an applicable legal, accounting, safety, dispute or recordkeeping requirement. Account closure does not require immediate destruction of records we must lawfully retain. Different record types have different retention needs; we periodically review them and securely destroy or de-identify information when no longer required.
Allergy and child-service records have restricted access and purpose-specific retention. Backup copies are protected and removed through managed backup cycles; retained copies are not made available for ordinary use.
The following retention periods apply to each record type:
If we suspect a data breach, we take steps to contain it, assess the information and likely harm, remediate and prevent recurrence. Where the Notifiable Data Breaches scheme applies, we conduct required assessments within the statutory timeframe and notify the OAIC and affected individuals as required. Report suspected exposure or account compromise promptly through our privacy contact.
11 Access correction deletion and consent withdrawal
You may request access to personal information we hold about you and correction of inaccurate, out-of-date, incomplete, irrelevant or misleading information. Account settings may allow some changes directly. Contact the Privacy Officer for other requests. We may verify identity and authority using proportionate measures and provide access securely.
We aim to respond to access and correction requests within 30 days. If more time is reasonably needed, we explain why and provide an update. We do not charge for making a request or for correction. Any permitted access charge must be reasonable, explained beforehand and must not discourage access.
If a lawful exception prevents access or correction, we give written reasons to the extent required and explain complaint options. Where appropriate, we provide partial access or an alternative. If a correction is disputed, you may request a statement of disagreement to be associated with the record. We notify other recipients of a correction where required or requested and reasonable.
You may request account closure or deletion, or withdraw consent for future optional or sensitive information handling. We explain any legal retention obligation or effect on an unfulfilled booking. Withdrawal does not undo lawful prior handling or remove legal reporting requirements. Australian privacy law does not provide an unrestricted right to erase every record. Vendor-controlled records may require a separate request to the vendor; we can help identify the relevant contact.
12 Privacy complaints and policy updates
Contact the Privacy Officer with the relevant facts, dates, transaction reference and outcome sought. We acknowledge complaints within two business days and aim to provide a substantive response within 30 days, giving progress updates if the matter takes longer. Urgent safety or security concerns are assessed promptly.
We review relevant records and staff or provider responses, assess the complaint fairly, explain our findings and any corrective action, and provide escalation options. You may complain without losing access to genuine refunds or other statutory remedies.
If you are dissatisfied with our response, or we have not responded within a reasonable period, you may contact the Office of the Australian Information Commissioner where it has jurisdiction: www.oaic.gov.au/privacy/privacy-complaints or 1300 363 992. Other applicable regulators or remedies remain available.
We review this policy when services, providers, data flows or law change and publish the current version and date free of charge. We notify material changes through appropriate channels where required. Updating a policy does not itself obtain consent for a new sensitive-information use. You can request a copy in another reasonably accessible form.