Privacy Policy
Last updated: 21 July 2026
1. Who we are
This Privacy Policy explains how Rain Day Spa Indooroopilly Pty Ltd (ACN 700511324), trading as Rain Day Spa ("Rain Day Spa", "we", "us", "our"), collects, uses, discloses and protects your personal information.
We are committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because we collect health information and provide health‑related services, we treat ourselves as bound by the Privacy Act and this policy applies regardless of our size.
2. What personal information we collect
- Identity and contact details: your name, email address, phone number, and any postal address you provide. Where we serve alcohol, we may also sight proof of age.
- Account information: your login credentials (stored securely) and account preferences.
- Booking and transaction history: the sessions and treatments you book, booking type, attendance, tokens, subscriptions, gift cards and extras.
- Payment information: payments are processed by Stripe. We do not store your full card number; we receive limited transaction information from Stripe.
- Health information (sensitive information): when you accept our Health Waiver, and when you disclose relevant conditions to a practitioner for a treatment, you provide health‑related information (for example, confirming you have no condition that makes the facilities or a treatment unsafe for you). This is "sensitive information" and we handle it with extra care (see clause 4).
- Communications: records of your enquiries, feedback and correspondence with us.
- Technical information: limited technical data (such as IP address and device/browser information) generated when you use the Website, collected by our hosting and security providers, and information from essential cookies (see clause 9).
3. How we collect it
We collect personal information directly from you — when you create an account, make a booking or purchase, accept the Waiver, disclose information to a practitioner, contact us, or otherwise use the Website. Some information (such as payment confirmations) we receive from our service providers acting on your instructions.
4. Sensitive information and consent
We only collect health information that is reasonably necessary for your safety and our functions, and only with your consent. By accepting our Health Waiver and providing health information, you consent to us collecting and handling that information for the purpose of assessing your eligibility to use the Facility safely, enabling a practitioner to provide a treatment safely, and managing health and safety. You can decline — but if you do, we may not be able to allow you to use the Facility or receive a treatment.
5. Why we use your personal information
We use your personal information to:
- create and manage your account;
- take and manage bookings, treatments, tokens, subscriptions, gift cards and extras;
- process payments and refunds;
- protect the health and safety of guests and manage risk and incidents;
- communicate with you about your bookings and account (service messages);
- send you marketing communications where permitted (see clause 7);
- improve and secure our Website and services; and
- comply with our legal obligations and protect our legal rights.
We will only use your information for a purpose you would reasonably expect, or a directly related purpose, unless you consent otherwise or the law permits or requires it.
6. Who we share it with, and overseas disclosure
We disclose personal information to service providers and others who help us run our business, including:
- Stripe — payment processing;
- Resend — sending transactional and (where permitted) marketing emails;
- Render — website and database hosting;
- independent practitioners — limited to the information needed to provide your treatment safely;
- our IT and professional advisers as needed; and
- others where you consent, or where required or authorised by law.
Some of these providers store or process data overseas, including in the United States. Where we disclose your information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
7. Direct marketing
We may send you marketing communications (for example, about offers or new services). Where we do:
- every message will identify us as the sender and include a simple unsubscribe option;
- you can opt out at any time using the unsubscribe link or by contacting us, and we will action your request promptly; and
- we will only send marketing where we are permitted to under the Spam Act 2003 (Cth) and the Privacy Act — which generally means where you have consented, or to existing customers about related services where consent can be inferred.
We do not sell your personal information.
8. Automated decision‑making
We do not currently use automated systems to make, or substantially assist in making, decisions that have a significant effect on you. If we introduce such systems, we will update this policy to explain how they are used, consistent with the automated‑decision‑making transparency requirements that take effect on 10 December 2026.
9. Cookies and analytics
Our Website uses essential cookies that are necessary for it to work — for example, to keep you securely logged in and to support secure payments (via Stripe). These are required for the Website to function and cannot be switched off.
We do not currently use third‑party advertising or analytics cookies. If we add analytics (such as Google Analytics) in future, we will update this policy and, where required, ask for your consent.
10. How we protect your information
We take reasonable steps — including appropriate technical and organisational measures — to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include secure hosting, access controls, encryption in transit, and storing credentials and payment data with reputable providers. No system is completely secure, but we work to keep your information safe.
11. Data breaches
If we suspect a data breach, we will assess it (generally within 30 days). If a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
12. How long we keep it
We keep personal information only for as long as we need it for the purposes described in this policy, or as required by law (for example, financial and tax records), after which we take reasonable steps to destroy or de‑identify it.
13. Accessing and correcting your information
You can ask us to access the personal information we hold about you, or to correct it if it is inaccurate, out of date or incomplete. Contact us using the details below. We will respond within a reasonable time and may need to verify your identity. If we cannot give access or make a correction, we will explain why.
14. CCTV
We do not currently operate CCTV at the Facility. If we introduce CCTV for security in future, we will display clear signage and update this policy to explain how any footage is handled. CCTV would not be used in change areas, treatment rooms, or other private spaces.
15. Children
Our services are for adults (18+). We do not knowingly collect personal information from anyone under 18.
16. Complaints
If you have a privacy concern or complaint, please contact us first using the details below and we will try to resolve it. If you are not satisfied, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
17. Changes to this policy
We may update this policy from time to time. The current version will always be available on the Website, with the "last updated" date shown above.
18. Contact us
For privacy questions, access/correction requests, or complaints:
Privacy Contact — Rain Day Spa
Attention: Nicolle Toohey
Email: info@raindayspa.com.au
Phone: 0432 908 081
Post: 9 Ormond Terrace, Indooroopilly QLD 4068
