Privacy Policy · v2026-09-04-v1
Your information, respected.
Gear Envy Pty Ltd (ACN 701 832 171, ABN 54 701 832 171) — “Gear Envy”, “we”, “us” — runs a peer-to-peer marketplace for hiring creator and adventure equipment in Australia. This policy explains what personal information we collect, why, who we share it with, where it goes, and how you can access, correct or complain about it. It is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. What we collect
When you join the waitlist: your email address, your referral code if you arrived through one, and how you arrived — the campaign parameters and advertising click identifier in the link you followed, and the page you landed on.
When you create an account: your name, email address and the suburb you are in.
When you use the marketplace: your listings, bookings and booking history; messages you send to other members through the platform; and the handover photographs you and the other party take at the start and end of a hire.
When you verify your identity: an identity document and a photograph, which you provide so other members can trust who they are dealing with. Section 4 sets out how these are handled differently from everything else.
When you pay or get paid: payment is processed by Stripe. Gear Envy does not receive or store your full card number. We hold a record of the transaction and, for owners, the connected payment account identifier Stripe issues.
Automatically: basic usage and device information for analytics, error monitoring and advertising measurement, and information needed to protect the site from automated abuse. Section 6 sets out what advertising measurement involves, because it is the part that shares information with a third party.
We do not buy personal information about you from anyone else, and we do not sell yours.
2. Why we collect it
To operate the marketplace: to let you list and hire equipment, to process payments and bonds, to let the two sides of a hire communicate, to resolve disputes and damage claims using the photo record, to verify identity so members can trust each other, to keep the platform safe and free of fraud, and to meet our legal and tax obligations. We also use it to understand whether our advertising works, which is covered in section 6.
We use your email to send you what you need — booking confirmations, messages, the waitlist confirmation you asked for. Marketing email is separate: you opt in, and every message carries an unsubscribe link.
3. Who we share it with
Other members, but only what the hire requires. An owner sees a renter's display name, suburb and booking details. A renter sees the same about an owner. Your identity documents are never shown to another member. Your full address is shared only where a hire requires it.
Service providers who run parts of the platform for us. These are listed in section 5, with the countries they operate in.
Meta, for advertising measurement only, as described in section 6.
Where the law requires it — a court order, a regulator, or where necessary to prevent a serious threat to someone's life, health or safety.
We do not sell your personal information, and we do not disclose it for another organisation's marketing.
4. Identity documents
Identity verification is carried out by Stripe Identity. You upload your identity document to Stripe directly.
Gear Envy never receives, holds or stores your identity document. What we receive back from Stripe is the outcome — whether verification succeeded or failed — and a reference that lets us ask Stripe about it if there is a dispute. Stripe's handling of your document is governed by Stripe's own privacy policy.
Your identity document is never visible to another member and is never attached to a listing or a booking. We keep the verification outcome and its date for as long as you have an account, because other members rely on it when deciding whether to hire to or from you.
5. Where your information goes, including overseas
Our database, file storage and the handover photographs are hosted in Australia, in Amazon Web Services' Sydney region (ap-southeast-2), through Supabase.
Some services we rely on operate outside Australia. Under APP 8 we are required to tell you which, and in which countries they are likely to handle your information:
| Provider | What it handles | Countries |
|---|---|---|
| Resend | Waitlist and transactional email — your name and email address | Japan (our sending region is Tokyo) and the United States |
| Stripe | Payments, payouts, connected accounts and identity verification | United States, and the European Union and India through Stripe's own service providers |
| Meta | Advertising measurement — see “Analytics and advertising” below | United States, and other countries where Meta operates its advertising infrastructure |
| PostHog | Product analytics | United States (we use PostHog's US cloud) |
| Sentry | Error monitoring | United States (our Sentry organisation is in the US region) |
| Vercel | Website hosting and delivery | United States, and other countries where Vercel's global edge network serves our site |
| Cloudflare | Bot protection on our forms | United States, and other countries where Cloudflare's global network operates |
By using Gear Envy you agree that we may disclose your personal information to these providers in these countries. We take reasonable steps to ensure they handle it consistently with the APPs, but we cannot guarantee that the law of every country offers the same protection as Australian law, and you may not be able to seek redress under the Privacy Act against an overseas recipient.
6. Analytics and advertising
Two different things happen here, and they are worth separating because only one of them shares information outside Gear Envy.
Product analytics and error monitoring. We use PostHog to understand how people move through the site, and Sentry to catch errors. These record events such as pages viewed, a waitlist signup, or an identity verification completing, along with basic device and browser information. We use this to fix what is broken and improve what is confusing. It is not used to target advertising at you.
Advertising measurement. We advertise on Facebook and Instagram, which are run by Meta. To know which advertisements actually bring people to us rather than guessing, we use two of Meta's measurement tools.
The Meta Pixel. A small piece of Meta's code runs in your browser on our website and records that a page was viewed, together with the identifiers Meta's own cookies set in your browser. This tells Meta that a visit happened.
The Conversions API. When you confirm your waitlist signup, our server sends Meta a single “Lead” event. That event contains an irreversibly scrambled (SHA-256 hashed) version of your email address — Meta receives the scrambled value, not the address itself, and matches it against its own equally scrambled records — together with the Meta advertising click identifier and browser identifier that came with your visit, if any, your IP address, and your browser's user agent string. It also carries a reference to your waitlist record, which exists so the same signup is never counted twice.
We use these only to measure our own advertising. We do not sell your information to Meta, we do not upload customer lists to Meta or anyone else for advertising, and we do not use these tools to advertise to you on behalf of another business.
Your choices. Browser tracking protection, ad blockers, and Meta's own ad preference settings all limit or stop the pixel. The Conversions API event is tied to the waitlist confirmation itself and is sent once; if you unsubscribe or ask us to delete your record, nothing further is sent about you.
7. Keeping it secure
Access to member data is restricted by row-level database policies, so a member's own records are the only ones their session can read. Administrative access is limited to the people who need it. Identity documents are held by Stripe, not by us.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
8. Your rights
Access. You can ask for a copy of the personal information we hold about you. That includes your legal acceptance record — which documents you agreed to, which version, and when.
Correction. You can ask us to correct anything inaccurate, out of date or incomplete.
Deletion. You can ask us to delete your account and your information. Some records must be kept — transaction and tax records in particular — and we will tell you what we have to retain and for how long.
Marketing. You can unsubscribe at any time. This does not stop the operational emails a booking requires.
We will respond to an access or correction request within a reasonable period. If we refuse, we will tell you why in writing.
9. Complaints
If you think we have mishandled your personal information, contact us at privacy@gearenvy.com.au. We will acknowledge your complaint within 5 business days and respond within 30 calendar days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992. The Commissioner generally expects you to raise the complaint with us first and allow us a reasonable period, usually 30 days, to respond. See the contact & support page for the full process (APP 1.4).
10. Changes
If we change this policy we will publish the new version here with a new version number. Where the change is material we will ask you to accept the new version rather than swapping it silently. Your acceptance of each version is recorded with a timestamp.
Version 2026-09-04-v1 · Acceptance of this version is logged with timestamp and IP at signup. Terms of Service →