CrowdSpot Privacy Policy
Effective 8 Aug 2026 · Draft for legal review · CrowdSpot Pty Ltd (a CrowdLab product)
This Privacy Policy explains how CrowdSpot Pty Ltd (trading as CrowdSpot) handles personal information on the CrowdSpot v2 platform and marketing site. Campaign maps also publish a project-specific Privacy Collection Statement at the point you submit.
1. Contact
Privacy requests: crowdspot.com.au/contact or hello@crowdlab.com.au.
2. What we collect
Participants: depending on the project, location, survey answers, narrative, photos, optional name, optional email and opt-in, anonymous engagement tokens, and technical security data such as a hashed IP address for rate limiting and abuse prevention.
Organisation admins: account and organisation membership data from our authentication provider (Clerk), plus admin actions needed to moderate and configure projects.
Marketing site: contact form details, optional newsletter fields where offered, and standard analytics.
Public map participation does not require creating an account.
3. Why we collect it
- Run campaign maps and publish approved contributions
- Support organisation partners to report on campaign outcomes
- Moderate content and prevent abuse
- Contact you about a campaign only if you opt in
- Secure, operate, and improve the platform
- Meet legal obligations
4. Who we share with
We may share information with the campaign organisation partner for that project, with service providers who host CrowdSpot, with CrowdLab operators for support and incidents, and with authorities where required by law. We do not sell personal information. Approved map content is visible to anyone who visits the public map.
5. Processors (CrowdSpot v2)
We use managed providers to operate the platform. Some processing may occur outside Australia.
- Vercel — app hosting and CDN
- Supabase — primary database and submission media storage (database region
ap-southeast-2) - Clerk — organisation admin authentication
- Mapbox — maps and geocoding
- Resend — transactional email when configured
- Sentry — error monitoring
- Google Analytics (GA4) — optional analytics
- Logo.dev — optional marketing logos
6. Retention, export, and deletion
Campaign submissions are generally kept for the life of the campaign and a reasonable archive period afterwards, unless the organisation or CrowdLab removes or anonymises them earlier. Hashed IP and similar security fields are used for abuse prevention, not marketing.
Organisation admins can export submissions available in admin tools (for example CSV or GeoJSON). To request access, correction, or deletion of personal information that identifies you, contact us using the details above. We will respond in line with the Australian Privacy Principles and explain what we can change (including where content is already public).
Formal self-serve retention schedules will be published when that product launches. See also Terms of Service.
7. Security and rights
We use HTTPS, access-controlled admin areas, database controls, and monitoring. You may request access or correction, and lodge a complaint with us. If unresolved, you may contact the Office of the Australian Information Commissioner.
8. Previous PDF
The March 2021 PDF remains available for reference. CrowdSpot v2 platform operations are described by this 8 Aug 2026 draft until counsel locks a single instrument.