Privacy policy.
Last updated: 6 June 2026
1. Who we are
This platform (“Now What”, “we”, “us”, “our”) is operated by [BUSINESS ENTITY NAME — TODO: Rachel] (ABN [ABN — TODO: Rachel]), the publisher of the Now What Podcast, based in [CITY, STATE — TODO: Rachel], Australia.
We take your privacy seriously, particularly because much of our content concerns sensitive personal experiences: separation, divorce, family safety, financial wellbeing. This policy explains what personal information we collect, why we collect it, who we share it with, and what choices you have. It is written to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
If you have any questions about this policy or how we handle your data, contact us at hello@nowwhatpodcast.com.au.
2. What we collect
We collect the following categories of personal information.
2.1 Information you give us
- Account details: your name and email address when you sign up. Your password is set with our authentication provider (Supabase) and is never stored or visible to us in readable form.
- Profile information: any information you choose to add to your profile, including your stage of the separation journey (selected on the onboarding quiz or in your profile).
- Quiz responses: answers you give to the onboarding quiz, used to tailor the content you see.
- Mailing-list signups: if you submit your email address to be notified about new content, courses, or platform updates, we store that email address with the source of the signup (e.g. home page, pricing page).
- Contact requests: if you contact us through the contact form or by email, we store the message and any details you provide so we can respond.
- Course content you write (browser-local): when you complete journal prompts or worksheets inside a paid course, your answers are saved in your web browser only (using localStorage). This information is not transmitted to our servers and we cannot read it. Clearing your browser data, switching device, or using a private window will erase these entries.
2.2 Information collected automatically
- Session cookies: required to keep you signed in. Set by our authentication provider.
- Technical data: IP address, approximate location (derived from IP), browser type, device type, operating system, referring URL, and pages visited.
- Usage analytics: aggregate, de-identified data about how the site is used, served via our analytics providers (see §4).
2.3 Information from third parties
- Payment information (when paid courses become available): collected and processed entirely by our payment provider (Stripe). We receive a confirmation that a payment succeeded plus minimal metadata (e.g. plan type, last four digits of card). We do not see or store full card numbers or CVV codes.
2.4 Sensitive information
Some of the information we collect, or that you may provide, could be considered sensitive information under the Privacy Act (for example, signalling that you have experienced family violence by viewing certain checklists). We treat this information with extra care and only use it to operate the platform and tailor the content you see. We do not share it with the partner directory, advertisers, or any third party for marketing.
3. How we use your information
We use the information we collect to:
- Create and manage your account, including signing you in and out.
- Provide free checklists, paid courses, and the partner directory.
- Personalise the content surface (e.g. ordering sections based on your journey stage).
- Process payments and grant access to paid courses you purchase or subscribe to.
- Send you transactional emails (sign-up confirmation, password resets, payment receipts).
- Send you marketing emails about new content, courses, and platform updates, but only if you have opted in, and with an unsubscribe link on every email per the Spam Act 2003 (Cth).
- Respond to your support requests or contact-form messages.
- Improve the platform by analysing aggregate usage patterns.
- Detect and prevent abuse, fraud, and security incidents, and enforce our Terms of Service.
- Comply with our legal obligations (for example, responding to a valid subpoena or law-enforcement request).
4. Who we share your information with
We do not sell your personal information. We share it only with the service providers we need to operate the platform, and only the information they need to do their job.
- Supabase (Sydney, Australia region): hosting, database, authentication, and file storage.
- Vercel (Sydney edge): web hosting and content delivery.
- Stripe (Australia, with global infrastructure): payment processing for paid courses and subscriptions, when those go live.
- Email / CRM provider [VENDOR TBD — TODO: Rachel]: sending transactional and marketing email; receives your email address and name only.
- Vercel Analytics and Plausible: aggregate, de-identified analytics on page views and traffic.
- Error monitoring [VENDOR TBD — TODO: Rachel]: if we use a service like Sentry, it may collect technical data about errors that occur while you use the site.
- Legal authorities: where we are required to disclose information by Australian law (for example, a court order or police warrant).
- Professional advisers (lawyers, accountants, insurers) where reasonably necessary, under confidentiality.
The partner directory on this platform lists independent professionals (lawyers, brokers, advisers) and businesses. We do not pass your personal information to anyone in the directory. If you contact a directory listing, you are communicating with them directly. Their own privacy practices apply.
5. Overseas storage and transfers
Our primary data is stored in Australia (Supabase Sydney). Some of our service providers may store or process limited information outside Australia. For example, Stripe processes payments through infrastructure that may be located in the United States, and email delivery providers may operate globally. Where we send personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
6. How long we keep your information
We keep your account and personal information for as long as your account is active, and for a reasonable period afterwards to comply with our legal and accounting obligations. Specifically:
- Account data: kept while your account is active. On deletion, we remove or de-identify personal data within 30 days, except where we are required to retain it by law (e.g. tax records for 7 years).
- Mailing-list signups: kept until you unsubscribe, after which we either delete the record or retain only the fact-of-unsubscribe to honour your preference.
- Payment records: retained for the period required by Australian taxation law (typically 7 years).
- Backups: deleted data may persist in encrypted backups for up to 30 days before rotation removes it.
7. Cookies and tracking
The site uses a small number of cookies and similar technologies:
- Essential cookies: set by Supabase to keep you signed in. The site does not work without these.
- Analytics: Vercel Analytics and Plausible. Both are configured to be privacy-preserving and do not use cross-site tracking cookies.
- Browser localStorage: used to remember your selected Australian state on state-specific checklists, and to save the journal-prompt and worksheet entries you write inside paid courses. This data lives on your device only.
We do not use advertising cookies, retargeting pixels, or social-media tracking.
8. Your rights
Under the Privacy Act, you have the right to:
- Access the personal information we hold about you.
- Ask us to correct information that is inaccurate.
- Ask us to delete your account and the personal information associated with it, subject to legal retention obligations.
- Withdraw consent at any time, for example, by unsubscribing from marketing emails (every email includes an unsubscribe link).
- Make a complaint about how we have handled your data (see §11).
To exercise any of these rights, email hello@nowwhatpodcast.com.au. We will respond within a reasonable timeframe and at most within 30 days.
9. Security
We use industry-standard security measures to protect your information, including encryption in transit (HTTPS) and at rest, access controls on our database, and reputable service providers (Supabase, Vercel, Stripe).
No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
10. Children
This platform is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
11. Complaints
If you have a complaint about how we have handled your personal information, contact us first at hello@nowwhatpodcast.com.au and we will try to resolve it. If you are not satisfied with our response, you can make a complaint to the Office of the Australian Information Commissioner (OAIC).
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of the page reflects the most recent version. For material changes (for example, a new category of data collection or a new disclosure recipient), we will notify account holders by email and post a notice on the site before the change takes effect.
13. Contact us
For any privacy question, complaint, or request, email hello@nowwhatpodcast.com.au, or write to [POSTAL ADDRESS — TODO: Rachel].