Privacy Policy
Last updated: 15 April 2026
Grass Roots Company Pty Ltd ABN 38 610 840 376 ("Grassrootz", "we", "our" or "us") is committed to the protection of your personal information. This Privacy Policy covers how we collect, use, disclose and protect the personal information we hold.
We may update this Privacy Policy from time to time. The most current version will be located on our website, and is also available by contacting us at the details provided below.
By using our website or platform, or by providing any personal information to us, you consent to the collection, use and disclosure of your personal information as set out in this Privacy Policy.
You may access other websites through links on our website. We are not responsible for the privacy practices of other sites, and recommend that you review the privacy policy of each site you visit.
Types of Information Collected
The types of personal information we collect and hold will vary depending on your dealings with us and may include:
your name, email address, telephone or mobile number, and physical address;
payment information (last four digits of your card number and expiry date — full card details are collected and processed entirely by our payment provider, Stripe, and never enter our systems);
donation and transaction details, including amounts, dates, and pledge status;
fundraising page content and campaign activity;
activity data from connected fitness platforms (such as Strava or Fitbit), where you choose to link your account, including activity type, distance, duration, and steps;
information you provide when contacting us for support;
where required in relation to your participation in a particular event, additional information such as dietary requirements or emergency contact details.
You do not have to provide us with any personal information, however if you do not do so you may not be able to make a donation or participate in a particular event, and we may not be able to provide you with the services you have requested.
Where you choose to connect a third-party account (such as Facebook, Strava, or Fitbit), we collect only the information necessary to provide the relevant platform functionality. You can disconnect a linked account at any time through the third-party platform's settings or by contacting support@grassrootz.com.
How We Collect Personal Information
Generally, we collect personal information directly from you, such as when you:
make a donation;
create a fundraising page using the Grassrootz platform;
register for or participate in an event;
purchase a ticket (including free tickets) or associated merchandise in a campaign or event;
connect a third-party account such as Facebook, Strava, or Fitbit;
contact us for support; or
otherwise interact with us or our platform.
We may also collect personal information from:
organisations or individuals who fundraise through Grassrootz;
charity partners on whose behalf fundraising is conducted;
event registration platforms, where you register for an event and choose to donate or create a fundraising page as part of that process;
third-party platforms you have chosen to connect to your account;
our service providers, such as our payment processor.
From time to time, another person may provide us with your personal information — for example, where someone registers family members or a team for a fundraising event. Where you provide us with personal information about someone else, it is your responsibility to ensure that those persons are aware of this Privacy Policy, consent to you providing information on their behalf and understand how their information will be handled.
Our Use and Disclosure of Personal Information
We will use the personal information we collect for the purpose disclosed at the time of collection, or otherwise as set out in this Privacy Policy. We will not use your personal information for any other purpose without first seeking your consent, or where authorised or required by law.
We use your personal information for the following purposes:
to allow you to fundraise for your selected organisation or cause;
to collect and process your donation and provide it to your selected organisation;
to provide the services you have requested from us;
to establish and maintain your relationship with us;
to communicate with you about your account, campaigns, and platform activity;
for internal analysis, reporting, and platform improvement;
to monitor and improve the quality of our services and user experience, including through session recording and analytics tools such as Microsoft Clarity;
to protect our platform and users from fraud, spam, and automated abuse
to answer any enquiry you make; or
to comply with our legal and regulatory obligations.
Grassrootz does not sell, rent, or trade your personal information.
Disclosure to Charity Partners
We will disclose your personal information to the organisations that you have donated to or fundraised for. This is a core function of the platform — when you donate or fundraise, the relevant charity receives your information so that it can manage its fundraising activities and communicate with you.
Once your personal information has been provided to a charity partner, that organisation is responsible for handling it under its own privacy obligations and privacy policy. We are not responsible for a charity's use of your personal information after it has been disclosed to them. If you have any concerns about a charity's handling of your information, please contact them directly.
Disclosure to Service Providers
We use third-party service providers to help us deliver our platform and services, including for payment processing, email communications, cloud hosting, and analytics. These providers are contractually required to protect your information and may only use it for the purpose of providing services to us.
Other Disclosures
We may also disclose your personal information where required or authorised by law, regulation, or legal process, or if we are involved in a merger, acquisition, or sale of all or part of our assets.
When you make a donation, you can choose how your name is displayed publicly, or for the donation to appear as anonymous. If you create a fundraising page, you can choose to customise your page name. These display choices do not affect the personal information we collect and hold as described in this policy.
Direct Marketing
We may use your personal information to send communications to you from us and from the organisation or individual you have donated to or fundraised for.
You may opt out of receiving marketing communications at any time through the unsubscribe function included in each communication, or by contacting support@grassrootz.com. Please note that even if you opt out of marketing communications, we may still send you transactional or service-related messages (such as donation receipts, campaign updates, and system notifications) where these are necessary to provide our services.
How We Store and Protect Personal Information
We store personal information in secure cloud-hosted environments and take reasonable steps to protect your personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
Our security measures are designed in alignment with recognised information security standards and include access controls, encryption, and regular review of our security practices.
We take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed for the purposes described in this policy or as required by applicable legal and regulatory obligations.
We cannot and do not accept responsibility for the security of information you send to or receive from us over the internet, or for any unauthorised access or use of that information.
Do We Send Personal Information Overseas?
Some of the service providers we use to deliver our platform are located overseas, including in the United States. We are also likely to disclose personal information to organisations you have donated to or fundraised for who may be located outside Australia.
Where we disclose personal information to overseas recipients, we take reasonable steps to ensure that the recipient handles your information in accordance with the Australian Privacy Principles, including through contractual obligations and the use of service providers with recognised security certifications.
Accessing and Correcting Your Personal Information
You may request access to the personal information we hold about you, or ask us to correct information that is inaccurate, incomplete, or out of date. We will respond to your request within 30 calendar days.
We may need to verify your identity before providing access or making corrections. In some circumstances, we may decline a request for access in accordance with the Privacy Act 1988, in which case we will provide you with reasons.
If your personal details change, you may also need to update your information with us in order to continue accessing our services.
Can I Request My Data Be Deleted?
You may request that we delete your personal information. We will take reasonable steps to do so, unless we are required to retain it to comply with our legal or regulatory obligations. To make a deletion request, please contact support@grassrootz.com.
If you are located in the European Union, United Kingdom, United States or New Zealand, you may have additional rights under applicable local privacy laws. Please contact us to discuss how these may apply to your request.
Data Breach Notification
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988.
Cookies and Analytics
Our website and platform use cookies and similar technologies to improve your experience and help us understand how our services are used. Cookies are small data files stored on your device when you visit a website.
We also use analytics and session recording, and security tools to monitor site performance, understand usage patterns, and improve our services. These tools may record interactions such as page visits, clicks, and scrolling behaviour.
You can disable cookies through your browser settings, however some features of our platform may not function properly without them.
Complaints
You may send a complaint to us at support@grassrootz.com. We will promptly acknowledge and investigate any complaint about the way we manage personal information. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (www.oaic.gov.au).
How to Contact Us
If you have any questions about this Privacy Policy, or if you wish to make a request or complaint regarding your personal information, please contact us:
Privacy Officer
Email: privacy@grassrootz.com
You may also contact us at any time about any aspect of the Grassrootz service at support@grassrootz.com.