Privacy Policy - Everflame Fundraising
Version: 1.0 · Effective date: on publication at www.everflamefundraising.com.au/privacy · Last updated: 2026-07-11 · Operator: VirgoLabs (ABN 62 345 335 476)
This policy takes effect on the date of its publication at www.everflamefundraising.com.au/privacy and remains in force until replaced by a later version.
This is general information for your own decision or for review with a registered tax adviser. The platform records, computes and assembles; it does not advise, and it does not prepare or lodge any return, statement or distribution for a fee.
Part A - The operator, this policy, and the Privacy Act
A.1 The platform and the operator. Everflame Fundraising is a fundraising platform for the Australian organisational recipient spectrum, from non-charitable not-for-profits through registered charities and deductible-gift-endorsed entities to multi-entity administering bodies, offered as a website at www.everflamefundraising.com.au. Donors give to a Recipient's campaign by card, the Recipient's registered position determines the receipt that issues, and each Recipient maintains its own supporter relationships through the platform. Until Everflame Fundraising Pty Ltd is incorporated, the platform is operated by VirgoLabs, ABN 62 345 335 476, based in New South Wales, Australia. On its incorporation the operator will be Everflame Fundraising Pty Ltd (ACN [to be inserted on incorporation], ABN [to be inserted on incorporation]), an Australian company registered under the Corporations Act 2001 (Cth) — a national scheme administered Commonwealth-wide by the Australian Securities and Investments Commission — with its registered office in New South Wales; the operator's rights and obligations under this policy and the Terms of Service will be assigned or novated to that company under the Terms' assignment clause, and this policy will be updated to name it. References in this policy to "we", "us" and "the operator" are references to the operator so identified, references to "the platform" mean the Everflame software and service, and the capitalised terms Recipient, Donor and Gift carry the meanings in the Operator and shared facts section at the foot of this page. The operator's public identifiers for privacy purposes are the ABN above and the privacy contact in Part L.
A.2 Definitions. This policy uses the following terms in the meanings the Privacy Act 1988 (Cth) (the Privacy Act) gives them, quoted from the current compilation of the Act.
- Personal information means "information or an opinion about an identified individual, or an individual who is reasonably identifiable: (a) whether the information or opinion is true or not; and (b) whether the information or opinion is recorded in a material form or not" (Privacy Act s 6(1)).
- Sensitive information means, relevantly, "information or an opinion (that is also personal information) about an individual's racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, or criminal record", together with health, genetic and certain biometric information (Privacy Act s 6(1)). The relevance of this definition to a giving platform is addressed in Part C.
- Consent means "express consent or implied consent" (Privacy Act s 6(1)).
- An entity holds personal information "if the entity has possession or control of a record that contains the personal information" (Privacy Act s 6(1)).
- Collection, use and disclosure carry their ordinary meanings under the Act: collection is obtaining personal information for inclusion in a record, use is handling within the entity, disclosure is making information accessible to others outside it.
- APP entity means an agency or organisation to which the Australian Privacy Principles (the APPs, Schedule 1 to the Privacy Act) apply. OAIC means the Office of the Australian Information Commissioner.
A.3 The operator and the Privacy Act. The Act binds APP entities. An "organisation" is "an individual, a body corporate, a partnership, an unincorporated association, or a trust", excluding among others a "small business operator" (Privacy Act s 6C(1)). Section 6D(1) provides that "a business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less", and s 6D(3) provides that a small business operator is a person or entity that "(a) carries on one or more small businesses; and (b) does not carry on a business that is not a small business". The operator has confirmed that the aggregate annual turnover of all businesses it carries on is $3,000,000 or less, it does not disclose personal information about anyone for a benefit, service or advantage, and it does not provide a benefit, service or advantage to collect personal information about anyone. On those facts the operator is a small business operator and the Privacy Act does not apply to the platform automatically. The operator has chosen not to rest anything on that exemption, for the reasons in A.4.
A.4 The posture this policy adopts. This policy applies the Australian Privacy Principles as binding practice from the date it takes effect: that is the operator's ratified position, not an aspiration. The operator has further chosen to be treated as an organisation under s 6EA of the Act, under which a small business operator may elect, by notice to the Information Commissioner in the approved form, to have the Act apply to it as law rather than as practice; the operator's ratified position is that this election will be in force at or before the platform's live launch, and because the election attaches to the legal person rather than to a product, once in force it binds the operator's handling of personal information on this platform as well. The reasons are structural rather than cosmetic: the platform handles money given to causes, giving histories reveal what people care about, receipts are regulated artifacts kept for years, and a Recipient entrusts its whole supporter relationship to the platform's custody. A privacy posture that turned on a turnover threshold would not be a defensible one for a platform holding that data.
A.5 Our two roles. The data a fundraising campaign generates belongs to the Recipient that earned it and the Donor who gave it, never to the platform. For giving data the platform therefore acts largely as a custodian handling records on behalf of each Recipient, while for its own accounts, bookings and site operation it collects personal information in its own right. This policy covers both roles, and the commitments in D.2 bind both. Where a Recipient uses giving data outside the platform, for example by emailing its supporters from its own systems, the Recipient handles that data under its own obligations; the platform's contribution is to record each Donor's per-channel consents so the Recipient can honour them.
A.6 The demonstration / live toggle, stated first. The website offers a per-visitor demonstration / live toggle. In the default demonstration view it shows worked-example campaigns, takes no payment, sends no email, and stores nothing you type: a contact message you ask us to send is relayed to our mailbox by the transactional email provider and is not stored by the platform; if you enter a name or an email address into a demonstration form, that input is processed transiently to render the demonstration and is neither saved nor sent; the demonstration sign-in screens keep what you type in your own browser's storage and transmit it to no one. In the live view, campaigns are real, Gifts are charged through the real payment provider, and real receipts and account emails are sent. Every part of this policy that describes collection and disclosure speaks to the live view, and the parts that are not yet running (recurring giving) are named honestly where they appear. This paragraph is the truth owed to every visitor, whichever view they are in.
Part B - What we collect
B.1 Information you give us directly. The live platform collects the following categories of personal information directly from you. Each exists in the code as at the census date in L.5, none is speculative, and no category has been omitted.
When you give: (1) your name; (2) your email address; (3) your donor-wall display preference (not listed, first name only, full name, or anonymous); (4) the Gift amount and the campaign it supports; (5) whether you chose to cover the card-processing fee.
When a campaign offers a dedication: (6) a dedication ("in memory of" or "in honour of"), a dedicatee's name and an optional short message. The data model supports this category and the current public donation form does not collect it; it is listed so the policy does not fall silent the day a campaign enables it.
When you book a call: (7) your name; (8) your email address; (9) your chosen date and time; (10) an optional note; (11) the page the booking came from; and, only if you choose to complete the optional follow-up form, (12) your organisation, your role, the number of entities you administer, and what you would like to discuss.
When you send us a message through the contact page: (13) your email address and (14) the message you write. The message is relayed to the operator's mailbox by the transactional email provider and is not stored in the platform's database.
When you request early access as an Organisation not yet on the invited-access list: (15) your name; (16) your organisation's name; (17) what you would like to fundraise for; (18) your email address; and, optionally, (19) your phone number, (20) your ABN or ACN, and (21) your website. This is relayed to the operator's mailbox in the same way as a contact-page message and is not stored in the platform's database.
When you hold an Organisation account: (15) your email address; (16) your full name; (17) your role within the Organisation (board, administration or oversight); (18) the backup-recovery email addresses you add for account security; (19) a record of the account actions the audit record in G.2 requires.
When a Recipient maintains its supporter records: (20) the consents you gave or withheld per channel (email, post, SMS), when, and from where they were captured.
B.2 Information about you that others provide. It would be false to state that all personal information on the platform is collected directly from the person it concerns, and this policy does not state it. The platform also collects information indirectly, in the following measured ways: an account holder may add a backup-recovery email address that belongs to you, held for account security, and you may receive an account-recovery or account-takeover confirmation email even though you never signed up; a Recipient may enter your contact details (name, email, phone, postal address) into its own supporter records held on the platform; for payout onboarding, an Organisation's official contact address is taken from a public register (the ABR or the ACNC register), not typed by a campaign creator, and the onboarding link is sent to that register-sourced address; and a peer-to-peer fundraising page, where a campaign enables one, carries the name of the individual fundraiser who fronts it. Where the platform holds information about a person collected in these ways, this policy applies to it, and this policy together with the confirmation email that the recovery and onboarding flows send is the practicable notice of that collection.
B.3 Cookies and device storage. The website sets one cookie for ordinary visitors: ef-view, which records whether you have switched the site between its demonstration view and its live view; it holds that single word and nothing about you. When an authorised administrator signs in to the account-administration area, the site sets everflame_admin, an HttpOnly, signed, strictly-necessary session cookie that keeps that administrator signed in; it is never set for an ordinary visitor. When real accounts ship, an essential authentication session cookie (set through the database provider's client) will keep account holders signed in. The website also stores a small number of values in your browser's localStorage and sessionStorage, where they stay on your device and are transmitted to no one: your theme preference (ws-theme), the previous-page markers that power the Back button (ws-prev-path, ws-current-path), a once-per-session marker so a support prompt is not shown twice, whether you have seen or dismissed the install-as-app hint (everflame_install_dismissed, everflame_ios_install_dismissed, everflame_ios_visit_count), and, on the demonstration account-preview screens, the name and email you type into the demonstration sign-in (ef_donor_session, ef_org_session), which exist only in your browser. If you install the website as an app, a service worker keeps copies of the site's static interface files in your browser's cache so pages can load offline; it caches only files on an explicit static allowlist, never a signed-in page, never a payment path, and never anything from the platform's data service. No analytics, advertising or tracking cookie, and no third-party tracking script, exists on the site.
B.4 What we do not collect. The platform holds no card numbers and no sensitive cardholder data of any kind: card details are entered with and held by the payment provider (Stripe), and the platform keeps only the gift record, the provider's charge identifier and, for a recurring gift, the provider's instrument token, which is not a card number. The platform holds no full bank credentials for a Recipient: for payout display it keeps only the last three digits of a BSB and the last four digits of an account number, plus the payment provider's connected-account identifier. It collects no date of birth, no government identifiers of individuals (an Organisation's ABN is an identifier of the organisation), no location telemetry, and no behavioural-tracking data. If any of these positions changes, this policy will be revised before the change ships.
B.5 Data sources that are not about you. Organisation registration facts (ABN status, charity registration, deductible-gift endorsement) are read from the Australian Business Register and the ACNC register. Those lookups carry the Organisation's identifiers, never a Donor's personal information.
Part C - Sensitive information
C.1 The honest position. The Privacy Act names "religious beliefs or affiliations", "philosophical beliefs" and health information among the protected limbs of sensitive information (s 6(1), quoted in A.2). The platform does not ask for sensitive information and no field exists to collect it. A giving record can nonetheless support an inference: a Gift to a religious charity, a health-condition foundation or an advocacy body may suggest something about your beliefs, your health or your affiliations. The platform's posture is to treat the giving history it holds with the care that possibility demands rather than to argue about which gifts qualify: giving data is used only for the purposes in Part D, is never sold, mined or profiled, and is displayed publicly only where you chose that at gift time.
C.2 The collection standard. APP 3.3 provides that an APP entity "must not collect sensitive information about an individual unless the individual consents to the collection of the information and the information is reasonably necessary" for one or more of the entity's functions or activities. To the extent a Gift you choose to make carries such an implication, the collection rests on your express choice to make that Gift to that Recipient, recorded with the receipt the law requires; the platform adds no belief, health or affiliation labels to anyone's data of its own motion.
C.3 The consequence of public display. The one public display of a Donor's identity is the donor wall, and it is opt-in with a default of not listed (Part E.1). Where you choose to appear on the wall of a campaign, you are choosing to associate your name publicly with that cause, and anyone on the internet can read that association. You control this entirely through the display choice you make at gift time, and you can change or remove it later (Part I).
Part D - Why we collect it and how we use it
D.1 Purposes of collection. The platform collects the categories in Part B for the following primary purposes: processing and recording each Gift and issuing the correct receipt for the Recipient's registered position; delivering the Recipient's acknowledgement of a Gift; maintaining each Recipient's supporter records and per-channel consents; operating Organisation accounts, including security, recovery and role-based access; responding to a book-a-call enquiry; responding to a contact enquiry; responding to an early-access request; maintaining the integrity of the service, including the append-only audit record of money-bearing and compliance-bearing actions; and meeting legal record-keeping duties.
D.2 The use and disclosure discipline. APP 6.1 provides that where an entity "holds personal information about an individual that was collected for a particular purpose (the primary purpose), the entity must not use or disclose the information for another purpose" without consent or another permitted basis. The operator's commitments under that discipline are these: your personal information is not sold, rented or traded to anyone; giving data is not used for the platform's own marketing, and the platform sends no marketing email of its own to Donors; your data is not used for profiling or advertising; it is not disclosed for any benefit, service or advantage to the operator; and any new purpose will be put to you for consent, or notified through a revision of this policy, before it begins. The platform's messages are transactional only: receipts, booking confirmations, account-recovery links and onboarding links. A Recipient may communicate with its own Donors under the consents each Donor has given, which are recorded per channel and can be withdrawn at any time; a commercial electronic message must carry accurate sender identification and a functional unsubscribe and be sent with consent, as the Spam Act 2003 (Cth) requires.
Part E - Who can see your information
E.1 Disclosure to the public. The website has no login wall, campaign pages are readable by anyone on the internet, and search engines can index them. Exactly one class of Donor personal information is disclosed to the public, and only on your explicit choice: where you opted onto a campaign's donor wall at gift time, your chosen display appears on that campaign's public page, as your first name only, your full name as you gave it, or an anonymous acknowledgement, according to your selection. If you make no choice you are not listed; the default is not listed. A peer-to-peer fundraising page, where a campaign enables one, also displays the individual fundraiser's name, placed there by the fundraiser who created the page. No other Donor personal information, no email address, no amount attributed to a named person unless you chose a named display, and no giving history, is ever shown publicly.
E.2 Disclosure to the Recipient. A Recipient sees the giving data for Gifts made to it, which is the purpose of the product: the donor record, the Gift, the receipt, the consents, and the acknowledgement's delivery state. One Recipient never sees another Recipient's donors, and the separation holds between entities under one administering body exactly as between unrelated Recipients.
E.3 Disclosure to the operator's administrators. The operator's administrators see the records needed to operate the platform, onboard Organisations and support account holders, under the role-based access in G.2, and their compliance-bearing actions are written to the same append-only audit record as everyone else's.
E.4 Disclosure to service providers. The live platform runs on the following providers, each processing data so the platform can operate and none receiving it for its own purposes: Supabase (database, authentication and storage; production data in the Sydney region, ap-southeast-2, so the primary copy remains in Australia); Stripe (the payment provider: card entry, charging, and settlement to each Recipient's own account); Resend (transactional email delivery); and Vercel (web hosting and server functions). Mail you send to the platform's contact address is received into a mailbox hosted by Proton AG in Switzerland. Organisation verification lookups go to the ABR and ACNC registers with Organisation identifiers only. Beyond the providers named in this clause no third party receives personal information, and this policy will be revised before any new provider is added.
E.5 Disclosure required or authorised by law. The operator will disclose personal information where required or authorised by Australian law, including to courts, regulators and law enforcement with lawful authority, and to the Australian Taxation Office or the ACNC where a receipt or fundraising record is lawfully required.
E.6 No sale. The operator does not sell, rent or trade personal information, and does not disclose it to any person for a benefit, service or advantage.
E.7 Links that leave the platform. Some pages link to external destinations, including a fundraisers page whose Donate buttons open another provider's secure payment page in a new tab. What you enter there is collected by that provider under its own privacy policy, not this one, and the platform receives none of it.
Part F - Overseas disclosure
F.1 The rule. APP 8.1 provides that before an APP entity discloses personal information to a person "who is not in Australia or an external Territory", the entity "must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles". Under s 16C of the Act, an entity that discloses personal information to an overseas recipient is, in certain circumstances, accountable for the recipient's acts, which are "taken to have been done by the APP entity".
F.2 Where your data lives. Production data is hosted in Supabase's Sydney region (ap-southeast-2), so the primary copy of platform data remains in Australia. Supabase is operated by a corporate group headquartered in the United States, so even with Australian-region hosting, technical support access, sub-processing and backup arrangements may involve access from outside Australia; the operator treats that possibility as overseas handling and discloses it here. Stripe, Resend and Vercel process data in the United States and elsewhere in their networks; a payment necessarily involves Stripe's processing wherever its network performs it.
F.3 Countries. APP 1.4 asks a privacy policy to state the countries in which overseas recipients are likely to be located, if practicable. They are: Australia, for primary hosting (Supabase, Sydney region); the United States, for Supabase's corporate group, Stripe, Resend and Vercel; and Switzerland, for Proton AG, which hosts the operator's contact mailbox.
Part G - Security
G.1 The standard. APP 11.1 provides that an entity holding personal information "must take such steps as are reasonable in the circumstances to protect the information: (a) from misuse, interference and loss; and (b) from unauthorised access, modification or disclosure".
G.2 Measures in place. The platform's design carries its protections in the structure rather than in promises. Card data never touches the platform: card entry, storage and charging live with the payment provider alone, and no code path may hold cardholder data or take custody of donor funds. Funds settle directly to each Recipient's own payment-provider account and are never pooled on a platform balance. Every money-bearing or compliance-bearing action is written to an append-only, hash-chained audit record that is never rewritten and that no role may alter. Access rules are enforced in the database itself, per Organisation and per role (board, administration, oversight), rather than only in the user interface. Account-recovery and takeover-confirmation tokens fail closed: where a signing secret or a delivery channel is not configured, no token issues. Administrator sign-in uses a signed, HttpOnly session cookie.
G.3 Honest limitations. The following limitations exist as at this policy's date, and none is concealed by this policy. An independent penetration test has not yet been run, and this policy says "reasonable steps" rather than promising that data is safe in absolute terms. In the live view, real donor data and payments are held on a real, live database — the measures above describe a system that presently holds real donor records, not only the built product. Organisation accounts are self-created by invitation: the operator pre-approves an email address, and the organisation creates its own account under it. A security posture that described none of this would misdescribe the platform.
Part H - Retention and deletion
H.1 The rule the money records live under. Receipts, Gift records, ledger entries and the audit record are records the law requires to be kept: tax record-keeping, charity record-keeping and, where relevant, ancillary-fund administration each impose retention periods. The operator has adopted a single retention floor of seven years for these records, measured from the later of the record's making or the end of the obligation it supports, which is at or above each regime's requirement; the specific statutory minima are confirmed with the operator's registered adviser and the floor is re-examined whenever this policy is revised. An erasure request cannot override a retention duty, and the append-only audit record is never rewritten.
H.2 What you can have erased. You can ask the operator to erase your contact data, and the platform is built to honour it: erasure removes your name, email, phone and address from the donor record while the underlying financial records (receipt, Gift, ledger entry, audit entry) are retained as the law requires, no longer connected to a usable contact identity. Consents are yours to withdraw at any time, per channel, which stops the communications they covered without touching the financial records.
H.3 The donor wall. Removing your name from a campaign's public donor wall is a display change, available on request at any time, and it does not delete the receipt or the financial records behind the Gift. The live product must carry a working wall-removal mechanism before any wall ships publicly; that build requirement is recorded in this policy's register rather than hidden.
H.4 The destruction standard. APP 11.2 requires an entity to take reasonable steps "to destroy the information or to ensure that the information is de-identified" once it is no longer needed for a permitted purpose. The positions above, contact data erased on request, financial records retained for the adopted floor and then destroyed or de-identified, are the operator's implementation of that standard.
Part I - Access, correction and portability
I.1 Access. APP 12.1 provides that if an entity "holds personal information about an individual, the entity must, on request by the individual, give the individual access to the information", and for organisations the response is due "within a reasonable period after the request is made". Requests go to the privacy contact in Part L. Every access request is acknowledged within 7 days and answered within 30 days.
I.2 Correction. APP 13.1 requires an entity to take reasonable steps to correct personal information that is "inaccurate, out of date, incomplete, irrelevant or misleading", on its own satisfaction or on request. Account holders can correct their account details directly; anything else, including information about you supplied by others under B.2, can be raised through the privacy contact, and the operator will correct or annotate it within the same 30-day period.
I.3 Portability, which is a design commitment here. The data a campaign generates belongs to the Recipient that earned it and the Donor who gave it. A Recipient's full contact and giving record is exportable to it, on request, in an ordinary portable form, and that export right survives the end of the Recipient's relationship with the platform. A Donor's own giving record is likewise available in a portable form on request. Portability is built into the product rather than granted as a favour, and no export is withheld to hold a Recipient's data hostage to the platform.
Part J - Data breaches
J.1 The scheme. Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. An eligible data breach arises where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and a reasonable person would conclude that it is likely to result in serious harm to any individual to whom the information relates (s 26WE(2)). An entity aware of reasonable grounds to suspect an eligible breach must assess it, taking "all reasonable steps" to complete the assessment within 30 days (s 26WH(2)). Where an eligible breach is confirmed, the entity must prepare a statement and give a copy to the Commissioner as soon as practicable (s 26WK(2)), and must notify affected individuals of its contents as soon as practicable (s 26WL(3)).
J.2 Applicability and commitment. The scheme binds APP entities, so once the s 6EA election described in A.4 takes effect it applies to the operator as law. The operator applies its discipline from adoption in any event: contain the incident, assess within 30 days, notify the OAIC and affected individuals as soon as practicable where serious harm is likely, and record the incident and the decisions taken in the audit record. Giving histories and contact data are the working assumption's starting point: a breach of donor records is treated as capable of serious harm rather than assessed neutrally.
Part K - Children
K.1 The honest position. The platform is not directed at children, Organisation accounts are held by adults acting for their organisations, and the donation flow collects no date of birth and performs no age verification; the practical control on giving is that a card payment requires a cardholder. This policy does not claim an age gate that does not exist. If the operator learns that it holds personal information collected from a child, it will delete it unless a retention duty attaches to a completed Gift, in which case the record is retained as the law requires and used for nothing else.
Part L - General provisions
This Part applies to every reader of this policy, whether a Donor, a Recipient's account holder, a visitor, or a person who holds no account and appears in records under B.2.
L.1 Contact. Privacy enquiries, access requests, correction requests, consent withdrawals, donor-wall changes and complaints all go to the operator's contact address: virgolabs@proton.me. This document is self-contained, and every route appears here rather than by reference elsewhere.
L.2 Complaints. A complaint about the handling of your personal information should be made to the contact address first; the operator will acknowledge it within 7 days and respond substantively within 30 days. If you are not satisfied with the response you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au, which accepts complaints online. The s 6EA election described in A.4 places the operator within the Act's complaint machinery, and the operator's own commitment above applies regardless.
L.3 Changes to this policy. This policy carries a version number and a date, material changes will be notified on the platform before they take effect, and the current version will remain available on the website at all times. No change operates retrospectively to authorise a use or disclosure this policy did not permit when the information was collected.
L.4 Collection notice. APP 5.1 requires an entity, at or before the time of collection or as soon as practicable after, to take reasonable steps to notify the matters in APP 5.2, including the entity's identity, the purposes of collection, usual disclosures, access and correction, complaint routes, and the likelihood of overseas disclosure. This policy is the platform's standing notice of those matters: identity in A.1, purposes in D.1, disclosures in Part E, overseas position in Part F, access and correction in Part I, complaints in L.2. For information collected indirectly under B.2, the practicable notice is this policy together with the confirmation emails the recovery and onboarding flows send to the person concerned.
L.5 Interpretation. Headings organise, they do not limit. Factual statements about the platform's behaviour derive from a code-level census of the platform's repository dated 11 July 2026, and they speak as at that date. The Schedule and the Adoption Record below form part of this policy.
Schedule - Legislative sources
Each provision quoted in this policy was verified against the source shown on 10 July 2026, in the operator's documented verification exercise for its platforms (the Federal Register of Legislation text read from the current compilation of the Privacy Act 1988, compilation in force 4 June 2026), and the quoted words were checked against the fetched text. On 11 July 2026, the date of publication, the quoted words of APP 3.3, APP 6.1, APP 8.1, APP 11.1, APP 11.2, APP 12.1 and APP 13.1 were re-verified against the OAIC's published text of the Australian Privacy Principles, and the s 6EA opt-in mechanics (notice in the approved form; the public opt-in register; revocability) were re-verified against the OAIC's opting-in guidance. The Privacy Act definitional quotes (s 6(1), s 6C, s 6D) stand on the 10 July 2026 exercise, one day before publication.
| # | Provision | Words verified | Source |
|---|---|---|---|
| 1 | Privacy Act s 6(1) "personal information" | "information or an opinion about an identified individual, or an individual who is reasonably identifiable" plus limbs (a)-(b) | OAIC APP Guidelines ch B, cross-checked against legislation.gov.au C2004A03712 |
| 2 | Privacy Act s 6(1) "sensitive information" | full limb list including "religious beliefs or affiliations" and "philosophical beliefs" | OAIC APP Guidelines ch B, cross-checked as above |
| 3 | Privacy Act s 6(1) "consent" | "express consent or implied consent" | OAIC APP Guidelines ch B |
| 4 | Privacy Act s 6(1) "holds" | "possession or control of a record that contains the personal information" | OAIC APP Guidelines ch B |
| 5 | Privacy Act s 6C(1) "organisation" | individual, body corporate, partnership, unincorporated association, trust, excluding a small business operator | legislation.gov.au C2004A03712 |
| 6 | Privacy Act s 6D(1) | "A business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less." | legislation.gov.au C2004A03712 |
| 7 | Privacy Act s 6D(3) | "(a) carries on one or more small businesses; and (b) does not carry on a business that is not a small business" | legislation.gov.au C2004A03712 |
| 8 | Privacy Act s 6EA | small business operator may elect by written notice to the Commissioner to be treated as an organisation | legislation.gov.au C2004A03712; OAIC small-business guidance (Privacy Opt-In Register) |
| 9 | Privacy Act s 16C | overseas recipient's act "taken to have been done by the APP entity" in certain circumstances | OAIC APP Guidelines ch 8, paragraph 8.60 |
| 10 | Privacy Act Part IIIC, s 26WE(2) | eligible data breach: unauthorised access, unauthorised disclosure, or loss, likely to result in serious harm, reasonable-person standard | OAIC, Data breach preparation and response, Part 4 |
| 11 | Privacy Act s 26WH(2) | "all reasonable steps" to complete the assessment within 30 days of becoming aware | OAIC, Data breach preparation and response, Part 4 |
| 12 | Privacy Act s 26WK(2) | prepare a statement and give a copy to the Commissioner as soon as practicable | OAIC, Data breach preparation and response, Part 4 |
| 13 | Privacy Act s 26WL(3) | notify affected individuals as soon as practicable | OAIC, Data breach preparation and response, Part 4 |
| 14 | APP 1.3, APP 1.4 (the APPs are Schedule 1 to the Privacy Act) | duty to have a clearly expressed, up-to-date privacy policy, and its required contents | OAIC, Read the Australian Privacy Principles |
| 15 | APP 3.3 | "must not collect sensitive information about an individual unless the individual consents ... and the information is reasonably necessary" | OAIC, Read the Australian Privacy Principles |
| 16 | APP 5.1, APP 5.2 | notification at or before collection or as soon as practicable after; matters list | OAIC, Read the Australian Privacy Principles |
| 17 | APP 6.1 | primary purpose rule, "must not use or disclose the information for another purpose" | OAIC, Read the Australian Privacy Principles |
| 18 | APP 8.1 | "take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles" | OAIC, Read the Australian Privacy Principles; APP Guidelines ch 8 |
| 19 | APP 11.1 | "protect the information: (a) from misuse, interference and loss; and (b) from unauthorised access, modification or disclosure" | OAIC, Read the Australian Privacy Principles |
| 20 | APP 11.2 | "destroy the information or to ensure that the information is de-identified" | OAIC, Read the Australian Privacy Principles |
| 21 | APP 12.1 and response period | "must, on request by the individual, give the individual access to the information"; organisations respond "within a reasonable period after the request is made" | OAIC, Read the Australian Privacy Principles |
| 22 | APP 13.1 | correction where "inaccurate, out of date, incomplete, irrelevant or misleading" | OAIC, Read the Australian Privacy Principles |
| 23 | Spam Act 2003 (Cth) | commercial electronic messages require consent, accurate sender identification and a functional unsubscribe | ACMA, Avoid sending spam (general description; no day-count asserted) |
Adoption Record
The operator's standing decisions under this policy, ratified by the operator on 11 July 2026 and recorded so that the policy's commitments can be checked against them.
- Operator. Until Everflame Fundraising Pty Ltd is incorporated: VirgoLabs, ABN 62 345 335 476, New South Wales, Australia. On incorporation, Everflame Fundraising Pty Ltd (ACN and ABN to be inserted on incorporation), per A.1.
- Posture. Voluntary compliance with the Australian Privacy Principles from adoption; the s 6EA election described in A.4 to be in force at or before this platform's live launch.
- Contact. All routes: virgolabs@proton.me. Contact mailbox hosted by Proton AG, Switzerland.
- Hosting and providers. Database, authentication and storage: Supabase, Sydney region (ap-southeast-2), primary data in Australia. Payments: Stripe. Transactional email: Resend. Hosting: Vercel. Register lookups: ABR and ACNC, Organisation identifiers only.
- The card boundary. No card number or sensitive cardholder data is ever held by the platform; no code path, even disabled, may hold cardholder data or take custody of donor funds.
- Donor wall. Opt-in at gift time; default not listed; display change or removal on request at any time; a working wall-removal mechanism is a prerequisite of any public wall.
- Retention floor. Seven years for receipts, Gift records, ledger entries and the audit record, measured from the later of the record's making or the end of the obligation it supports; contact data erasable on request.
- Response periods. Acknowledgement within 7 days; substantive response within 30 days.
- Marketing. The platform sends no marketing email of its own to Donors; Recipient communications run only under recorded, withdrawable per-channel consents.
Version 1.0. Published by VirgoLabs (ABN 62 345 335 476) at www.everflamefundraising.com.au/privacy.
Operator and shared facts
The facts referenced above — the Operator, the governing-law state, the defined terms, the third-party recipients of data, and the retention periods — are set out here so this page is self-contained.
A. The Operator
Until Everflame Fundraising Pty Ltd is incorporated, the Operator is VirgoLabs (ABN 62 345 335 476), of New South Wales, Australia. On its incorporation the Operator will be Everflame Fundraising Pty Ltd (ACN [to be inserted on incorporation], ABN [to be inserted on incorporation]), an Australian company registered under the Corporations Act 2001 (Cth) — a national scheme administered Commonwealth-wide by the Australian Securities and Investments Commission — with its registered office in New South Wales. On that incorporation the Operator's rights and obligations under these documents will be assigned or novated to that company under the Terms' assignment clause (clause 20.3), notice will be published on the platform, and these documents will be updated to name it.
"Everflame" and "Everflame Fundraising" name the software and service (the product brand); the Operator identified above is the legal person behind it. The platform's website is www.everflamefundraising.com.au.
Contact for everything — privacy requests, gift corrections, donor-wall changes, account security, complaints, and general enquiries: virgolabs@proton.me. The contact mailbox is hosted by Proton AG in Switzerland.
B. Governing law and jurisdiction
The governing law is that of New South Wales, Australia, following from the Operator's principal place of business, and the courts of New South Wales and of the Commonwealth of Australia have non-exclusive jurisdiction. Nothing in either document excludes a protection given by the mandatory consumer laws of the place where you live.
C. Defined terms (authored once; used by both documents)
- the Platform / Everflame — the Everflame fundraising software and service at
www.everflamefundraising.com.au.
- the Operator — the legal person identified in §A that runs the Platform: VirgoLabs
(ABN 62 345 335 476) until Everflame Fundraising Pty Ltd is incorporated, and that company after.
- Recipient / Organisation — an entity that receives Gifts through the Platform (a non-charitable
not-for-profit, a registered charity, a deductible-gift-endorsed entity, or an administering body).
- Donor / Supporter / "you" — a person who gives, pledges, enquires, books a call, or holds an
account.
- Gift — a voluntary payment made to a Recipient through the Platform.
- Pledge — an all-or-nothing giving commitment, live in the live view (Terms clause 3A): a Donor's
card is tokenised at commitment and charged only by the Recipient's own deliberate act if the campaign's goal is reached; charging and release are not currently automated.
- Payment Provider — the compliant third-party payment processor that holds card data and moves
funds (Stripe; §D).
- Personal Information — has the meaning given by the Privacy Act 1988 (Cth), quoted in the
Privacy Policy, Part A.
D. Third-party recipients of data (service providers)
These are the third parties that process data so the Platform can operate. The Platform does not sell, rent, or mine Personal Information; these are service providers under the Platform's instructions.
| Service provider | Role | Data-region note |
|---|---|---|
| Supabase (database, authentication, storage) | Stores the Platform's records | Sydney region (ap-southeast-2); the primary copy of platform data remains in Australia. The provider's corporate group is US-headquartered, so support and backup arrangements may involve overseas access, disclosed in the Privacy Policy, Part F. |
| Stripe (Payment Provider) | Card entry, charging, settlement to each Recipient's own account | Processes in the United States and elsewhere in its network. Card data lives with Stripe alone; the Platform holds none. |
| Resend (email delivery) | Sends transactional email (receipts, confirmations, recovery links) | Processes in the United States. |
| Vercel (web hosting) | Serves the website and server functions | Processes in the United States and on its global edge network. |
| Proton AG (contact mailbox) | Receives mail sent to the contact address | Switzerland. |
| ABR — ABN Lookup | Verifies an Organisation's ABN | Receives Organisation identifiers only, never Donor Personal Information. |
| ACNC register | Verifies an Organisation's charity / deductible-gift status | Receives Organisation identifiers only, never Donor Personal Information. |
E. Retention positions
Receipts, Gift records, ledger entries and the append-only audit record are records the law requires to be kept. The Operator's adopted positions:
| Record kind | Position |
|---|---|
| Receipts, Gift, ledger and audit records | Retained for at least seven years, measured from the later of the record's making or the end of the obligation it supports (an adopted floor at or above the tax and charity record-keeping regimes; confirmed with the Operator's registered adviser). |
| The append-only audit record | Never rewritten; no role may alter it. |
| Donor contact data | Erasable on request at any time; erasure removes name, email, phone and address while the financial records above are retained as the law requires. |
| Per-channel consents | Withdrawable at any time; withdrawal stops the communications the consent covered. |
| Donor-wall display | Changeable or removable on request at any time; a display change never deletes a financial record. |
An erasure request never overrides a retention duty, and no retention duty is ever used as a reason to keep contact data that can lawfully be erased.