Privacy Policy

Last updated: 27 August 2026

1. Who we are

This Privacy Policy explains how StampRise Pty Ltd (ABN 88 701 811 690) ("StampRise", "we", "us", "our") handles personal information.

We are an Australian company. We provide a browser-based event gamification platform used by event organisers to run Digital Event Passports, check-ins, prize draws, leaderboards, and scavenger hunts.

Contact: privacy@stamprise.com
Postal: Level 1, 63-73 Ann Street, Surry Hills, NSW 2010, Australia

2. Our role depends on whose data it is

This is the most important section of this policy, because StampRise handles two different categories of personal information in two different capacities.

Organiser account information: we are the controller. When you create an Organiser account, contact us, or pay for the Service, we decide how that information is used. We are the data controller (and an "APP entity" under the Australian Privacy Act). This policy governs that handling.

Participant information: we are the processor. When a Participant scans a QR code, collects a stamp, checks in, or enters a prize draw at an event, the information collected belongs to the Organiser's programme. The Organiser decides what is collected, why, and what happens to it afterwards. The Organiser is the data controller. StampRise processes that information on the Organiser's behalf and in accordance with their instructions.

What this means if you are a Participant. If you took part in an event and want to know how your information is being used, request a copy, or ask for it to be deleted, the event organiser is the right party to contact. They chose what to collect and they control it. You can contact us at privacy@stamprise.com and we will pass your request to the relevant organiser, but we cannot decide the outcome on their behalf.

3. Information we collect

From Organisers

  • Account information: name, email address, password (stored hashed), company name, role
  • Billing information: billing name, billing address, and the last four digits and type of payment card. Full payment card details are collected and stored by Stripe, not by us
  • Campaign configuration: event details, agenda, exhibitor and sponsor listings, prize descriptions, branding assets, and copy you upload
  • Communications: messages you send us by email, through our support chat, or through our contact forms
  • Usage information: pages accessed, features used, actions taken in the dashboard, timestamps

From Participants, on behalf of Organisers

What is collected depends entirely on what the Organiser configures. It may include:

  • Identifiers: name, email address, phone number, or a session identifier only, where the Organiser has chosen an anonymous mode
  • Custom fields the Organiser has configured, such as company, job title, or dietary requirements
  • Participation data: stamps collected, stations or booths visited, check-ins, quiz and survey responses, prize draw entries, prizes won, leaderboard position
  • Timestamps and the sequence of interactions

Collected automatically from all users

  • IP address, browser type and version, device type, operating system
  • Referring URL and pages viewed
  • Cookie and session identifiers (see section 10)

We do not intentionally collect sensitive information as defined by the Australian Privacy Act, or special category data as defined by the GDPR. Organisers must not configure Campaigns to collect such information without an appropriate lawful basis and their own compliance measures in place.

4. How we use information

Organiser information. To create and administer accounts, provide and support the Service, process payments, send transactional and service messages, respond to enquiries, produce internal analytics on how the Service is used, improve the Service, prevent fraud and abuse, and comply with legal obligations.

Participant information. Only to provide the Service to the Organiser. This includes maintaining Digital Event Passport state, delivering passport recovery and prize notification emails configured by the Organiser, generating the Organiser's event analytics, and making the data available to the Organiser.

We do not sell personal information. We do not use Participant information for our own marketing, and we do not use it to train machine learning models.

We may use aggregated and de-identified information, from which no individual can reasonably be identified, for benchmarking, research, and improving the Service.

5. Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on the following bases:

  • Contract: to provide the Service to Organisers and administer their account
  • Legitimate interests: to secure and improve the Service, prevent fraud, and communicate about the Service, where those interests are not overridden by your rights
  • Legal obligation: to comply with tax, accounting, and other legal requirements
  • Consent: for optional marketing communications, which you may withdraw at any time

For Participant information, the Organiser is responsible for establishing the lawful basis.

Where Singapore's PDPA applies, we rely on consent obtained by the Organiser, or on an applicable exception under that Act.

6. Who we share information with

Event Organisers

Where you participate in an event as a Participant, the information collected through that Campaign is made available to the event Organiser. This is the purpose of the Service.

Once an Organiser accesses or exports that information, it is under their control. Their own privacy policy governs what they do with it, including whether they add you to a mailing list or share it with their sponsors and exhibitors. We are not responsible for their handling of it.

Others

We may disclose information where required by law, court order, or a regulator, where necessary to establish or defend a legal claim, to protect the rights or safety of any person, or in connection with a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different policy.

7. International transfers

We are based in Australia and our service providers operate in a number of countries, including the United States and the European Union. Personal information may therefore be transferred to, stored in, and processed in countries other than your own, which may have different data protection laws.

Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

Where we disclose personal information overseas as an Australian Privacy Principle entity, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.

8. How long we keep information

Organiser account information: for as long as your account is active, and for 7 years after closure where required for tax and accounting purposes. Other account information is deleted within 90 days of account closure.

Participant information: retained for the period specified by the Organiser in their Campaign settings, or otherwise for 12 months after the event ends, after which it is deleted. Organisers may request earlier deletion at any time, and we will action it within 30 days.

We do not retain Participant information indefinitely.

Billing records: 7 years, as required by Australian tax law.

Support communications: 3 years from the date of last contact.

Backups: deleted information may persist in encrypted backups for up to 35 days before being overwritten.

9. Your rights

Depending on where you are located, you may have the right to:

  • access the personal information we hold about you
  • request correction of inaccurate or incomplete information
  • request deletion of your information
  • object to or restrict certain processing
  • receive your information in a portable format
  • withdraw consent, where processing is based on consent
  • lodge a complaint with a supervisory authority

To exercise any of these rights in relation to your Organiser account, email privacy@stamprise.com. We will respond within 30 days.

If your request relates to information collected at an event you attended, please contact the event organiser directly, as they control that information. If you are not sure who that is, contact us and we will identify them and forward your request.

Complaints. If you are not satisfied with our response, you may complain to:

  • Australia: Office of the Australian Information Commissioner, oaic.gov.au
  • EU/EEA: your local data protection authority
  • UK: Information Commissioner's Office, ico.org.uk
  • Singapore: Personal Data Protection Commission, pdpc.gov.sg

10. Cookies and similar technologies

We use the following:

Strictly necessary cookies. httpOnly session cookies that maintain Participant Digital Event Passport sessions and Organiser login sessions. The Service cannot function without these.

Support and messaging cookies. Intercom sets cookies to operate our in-product support messenger and help centre, including recognising returning users and maintaining conversation history.

Analytics cookies. Used to understand how the Service is used so we can improve it.

You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent the Service from working.

We do not use advertising or cross-site tracking cookies.

11. Children

The Service is not directed to children. Organiser accounts may only be created by individuals aged 18 or over.

Some events may be attended by children. Where an Organiser configures a Campaign that may collect information from a child, it is the Organiser's responsibility to obtain any parental consent required by law, including under the GDPR and the US Children's Online Privacy Protection Act, and to comply with any applicable restrictions.

If you believe we hold information about a child that was collected without a lawful basis, contact us at privacy@stamprise.com and we will work with the relevant Organiser to have it deleted.

12. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, hashed password storage, access controls, and restricted administrative access.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the relevant regulator as required by law, and will notify affected Organisers without undue delay.

13. Changes to this policy

We may update this policy from time to time. Where a change is material, we will notify Organisers by email or in-product notice before it takes effect. The date at the top of this policy shows when it was last updated.

14. Contact

StampRise Pty Ltd (ABN 88 701 811 690)
Level 1, 63-73 Ann Street,
Surry Hills, NSW 2010,
Australia

Privacy enquiries: privacy@stamprise.com