Privacy Policy

Last updated: 24th Aug 2026

1. Who this policy covers

This Privacy Policy explains how we collect, use, hold and disclose personal information across the following websites and the Lori application (together, our Services):

ServiceOperated by
betteracts.comBetterActs Pty Ltd (ABN 82 692 853 544, ACN 692 853 544)
betteractscollective.orgBetterActs Collective Inc. (ABN 90 406 224 512)
lorivolunteer.org (the Lori app)BetterActs Collective Inc. (ABN 90 406 224 512)

We also currently operate getlori.tech, which will be retired and redirected to lorivolunteer.org. This policy applies to it in the meantime.

In this policy, 'BetterActs', 'we', 'us' and 'our' refer to whichever of BetterActs Pty Ltd or BetterActs Collective Inc. operates the Service you are using. Lori is operated exclusively by BetterActs Collective Inc.. The two are separate legal entities, and each is responsible only for the personal information it holds.

Our information handling practices are set out in this policy and are based on the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). We will handle personal information in accordance with them, and we will review and update them as our Services develop. The APPs are available from the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

2. Important note for Lori: two different roles we play

Lori is used by organisations (Customers) to manage their own volunteers (End Users). We handle personal information in two different capacities.

(a) Information we collect and control ourselves — Expressions of Interest submitted through our websites, a Customer's account and billing details, support and bug-report correspondence, technical logs, and marketing subscriptions where someone has opted in. We are directly responsible for this, and the rest of this policy explains how we handle it.

(b) Information Customers or their volunteers enter into Lori — a volunteer's name, contact details, availability, roles or checks (Customer Data). This is collected and controlled by the Customer organisation, not by BetterActs. We process it only as a service provider, on the Customer's instructions, to run Lori.

If you are a volunteer with questions about how your information is used, contact the organisation that invited you to Lori first. They control that information and are responsible for explaining how they use it.

Our undertakings to Customers

In respect of Customer Data we will:

  • process it only to provide, maintain, secure and support Lori, on the Customer's instructions or as required by law;
  • not use it for our own purposes, and not use it to train or evaluate machine learning or AI models;
  • not disclose one Customer's data to any other Customer;
  • not send marketing to your volunteers. We do not currently add volunteers to any mailing list, and volunteers only hear from us about the operation of their own account. If this ever changes it will be opt-in only, and we will update this policy and notify you before it takes effect;
  • impose confidentiality and security obligations on any service provider we engage (section 8);
  • assist the Customer to respond to access, correction and deletion requests from their volunteers; and
  • on request, or on account closure, delete Customer Data in line with section 11.

3. What personal information we collect

3.1 Website contact forms (Expressions of Interest) — we control this

When you submit an Expression of Interest through a contact form on any of our websites, we collect your name, email address, organisation and role, and the content of your message.

3.2 Lori Customer accounts and billing — we control this

When an organisation creates a Customer account, or upgrades to a paid plan, we collect:

  • the name, email address and role of the person setting up or administering the account;
  • the organisation's name and contact details;
  • authentication data — a hashed password and session identifiers. We never store your password in readable form;
  • selected plan, billing cycle and subscription status; and
  • transaction records (amounts, dates, invoice history).

Payments are processed by Stripe. We do not collect or store full card numbers, expiry dates or CVCs — these go directly into Stripe's PCI-DSS compliant payment form and are handled under Stripe's privacy policy. We receive only limited metadata (transaction status, amount, masked card reference) to reconcile subscriptions.

3.3 Technical and log information — we control this

Our systems automatically record IP address, browser and device type, request timestamps, actions taken in the app, and error logs. We use this only for security, fraud prevention, fault diagnosis and service reliability.

3.4 Volunteer (End User) information entered into Lori — the Customer controls this

When a Customer invites a volunteer, or enters volunteer details into Lori, the Customer may collect:

  • name and email address;
  • phone number and postal address;
  • emergency contact details (which are the personal information of a third party);
  • availability, shift and attendance records, roles, skills and training records;
  • notes recorded by the Customer's coordinators; and
  • any other fields the Customer chooses to add.

Sensitive information and government identifiers. Customers may choose to record sensitive information or government-related identifiers — for example Working with Children Check (WWCC) numbers, police check outcomes, driver licence details, RSA certificates, or health, dietary and accessibility information.

As set out in section 2, this is the Customer's information to control. It is the Customer's responsibility to:

  • obtain the volunteer's consent before collecting sensitive information;
  • comply with APP 9 and with State and Territory laws governing the use and disclosure of working-with-children and police check information — including the Worker Screening Act 2020 (Vic) and the Child Protection (Working with Children) Act 2012 (NSW), which restrict how check information may be used and shared; and
  • collect only what is reasonably necessary.

Recommended practice.Where a Customer's purpose is limited to verifying that a check is current, we recommend that the Customer record only the verification status, the expiry date, and the identity of the person who conducted the verification, rather than the identifier itself or an image of the underlying document. Lori is designed to support this approach. Minimising the identifiers held materially reduces the likelihood that an unauthorised disclosure would result in serious harm.

Document uploads. Lori does not currently support uploading images or scans of licences, WWCCs or other credentials. We are developing this feature. Before it is released we will update this policy, tell Customers where those files will be stored, and give Customers the choice of whether to use it.

3.5 Volunteers who are minors

Some Customers engage volunteers under 18. Where a volunteer is under 18, the Customer is responsible for deciding whether that person can consent to the collection of their information, and for obtaining parental or guardian consent where they cannot. We do not knowingly collect information directly from children other than through a Customer's use of Lori. If you believe a child's information has been provided to us in another way, contact us and we will delete it.

3.6 Bug reports and support — we control this

Lori is in beta. If you report a bug, we collect your name, email address, screenshots and your description of the issue, to investigate and respond. Please avoid including volunteer personal information in a bug report unless it is necessary to diagnose the problem.

3.7 Anonymity and pseudonymity

Where lawful and practicable you may deal with us anonymously or under a pseudonym — for example, a general enquiry. This is not practicable where we need to identify you to provide an account, process a payment, or respond to an access request.

4. How we collect personal information

Wherever practical, we (or, for volunteer information, the Customer) collect personal information directly from the individual — when someone submits a contact form, sets up or manages a Customer account, registers as an invited volunteer, or contacts us for support.

We also collect indirectly in two situations:

  • From Stripe — limited transaction metadata when a Customer pays.
  • From Customers — volunteer details a Customer enters into Lori before inviting that volunteer. Where this happens, the Customer is responsible for telling the volunteer. Lori's invitation email identifies which organisation invited them.

5. Cookies, analytics and tracking

Lori app. Lori uses only strictly necessary cookies and browser storage — to keep you signed in and to keep your session secure. Lori does not use advertising cookies, cross-site tracking, or third-party marketing pixels.

Marketing websites. We use Vercel Web Analytics on our marketing sites to understand aggregate traffic — page views, referrers, country, device type. Vercel Web Analytics does not set cookies and does not track visitors across websites; it derives an anonymous, rotating identifier from request data and discards it. We cannot identify individual visitors from it. Vercel processes this data on infrastructure outside Australia (see section 8).

If we introduce any additional analytics or tracking, we will update this section before doing so.

We do not respond to browser "Do Not Track" signals, as there is no agreed standard for interpreting them.

6. Why we collect, hold, use and disclose personal information

We use the information described in sections 3.1, 3.2, 3.3 and 3.6 to:

  • respond to Expressions of Interest;
  • set up, bill and manage Customer accounts and subscriptions, including processing payments through Stripe;
  • authenticate users and secure accounts;
  • investigate and resolve bugs and support requests, particularly during beta;
  • monitor and improve the security, reliability and performance of our Services, using aggregated or de-identified data wherever possible;
  • meet legal, insurance, tax and reporting obligations, including obligations as an incorporated association; and
  • send updates or newsletters, only to people who have opted in.

Direct marketing

When someone sets up an organiser account on Lori, we offer an optional, unticked checkbox inviting them to receive occasional emails from BetterActs about Lori, our roadmap and our work. It is off by default, separate from accepting our terms, and declining it does not affect your use of Lori. If you tick it, we hold your name, email address and the date and source of your consent as a record.

We do not currently send marketing to volunteers. Volunteers are not added to any mailing list, and we use volunteer contact details only to operate Lori on their organisation's behalf. If we introduce a marketing opt-in for volunteers in future, it will be opt-in only, we will update this policy, and we will notify Customers before it takes effect.

We comply with the Spam Act 2003 (Cth). Every commercial message identifies BetterActs as the sender and contains a working unsubscribe link, which we action within 5 business days.

Everything else

For volunteer information described in section 3.4, we use it only to provide, maintain, secure and support Lori on the Customer's behalf.

We will not use personal information we control for a purpose other than the one it was collected for, unless you would reasonably expect that use, you consent to it, or we are required or authorised by law.

Artificial intelligence. We do not use personal information, including Customer Data, to train, fine-tune or evaluate machine learning or AI models, and we do not permit our service providers to do so. If we build any AI-assisted feature into Lori, we will update this policy and notify Customers before enabling it.

7. Disclosure of personal information

We may disclose personal information to:

  • our people and contractors who need it to run our Services or support Customers, under confidentiality obligations;
  • the service providers listed in section 8, under contractual obligations to protect it and use it only for the purpose we engage them for;
  • our professional advisers — accountants, auditors, insurers, lawyers;
  • regulators or authorities where required or authorised by law, or to establish, exercise or defend a legal claim; and
  • an acquirer or successor entity if the Lori platform is transferred, merged or restructured — in which case we will notify affected Customers in advance and require the recipient to be bound by protections no weaker than this policy.

Within Lori, a Customer's administrators can access the volunteer information that Customer has collected — that is the purpose of the app.

We do not disclose one Customer's volunteer information to another Customer. We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.

8. Service providers and where information is stored

We use a small number of service providers. This table sets out what each handles and where. It is included so Customers can assess their own cross-border disclosure obligations under APP 8.

ProviderWhat it handlesWhere it is stored
SupabaseAuthentication for Lori — email addresses, hashed passwords, session tokensSydney, Australia (ap-southeast-2)
Neon (via Replit)The main Lori database, including all Customer Data — volunteer names, contact details, availability, roles and any other fields Customers addUnited States
StripePayment processing and billing records for paid plansUnited States and other countries in Stripe's global infrastructure
ResendTransactional and notification email — recipient name, email address, message contentUnited States
VercelMarketing website hosting and aggregate website analyticsUnited States and global edge network

Notice to Customers. Volunteer information entered into Lori is stored on servers located in the United States. This disclosure is made so that Customers may assess their own obligations, including any obligation to notify their volunteers of overseas disclosure. Overseas recipients are subject to the laws of the jurisdictions in which they operate, and Australian law may not be enforceable against them. We contract with each provider on its standard data processing terms, including standard contractual clauses where the provider offers them.

We are actively working toward Australian data residency for the main database, and will notify Customers before any change to where their data is stored — in either direction.

9. Data security

We take reasonable steps to protect personal information, including Customer Data, from misuse, interference, loss, and unauthorised access, modification or disclosure. What we do:

  • encrypt data in transit using TLS, and rely on our infrastructure providers' encryption at rest;
  • store passwords only as salted hashes, never in readable form;
  • apply role-based access controls, so each Customer's data is logically separated and reachable only by that Customer's authorised administrators;
  • limit our own team's access to production data to those who need it for support, and only for as long as needed;
  • keep all card data with Stripe — it never touches our systems;
  • keep development and production environments separate, and do not use production data for testing; and
  • apply security updates to our software dependencies.

No method of electronic storage or transmission is entirely secure, and we do not warrant that personal information will remain free from unauthorised access in all circumstances. Lori remains in beta and under active development, and Customers should have regard to that when determining what information to enter into the platform. Customers are responsible for maintaining strong, unique account credentials and for revoking administrator access promptly when a person ceases to require it.

10. Data breaches

If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information:

  • we will contain and assess the incident promptly;
  • where Customer Data is affected, we will notify the affected Customer(s) without undue delay and in any event within 72 hours of becoming aware, with the information they need to meet their own notification obligations;
  • where information we control is affected and serious harm is likely, we will notify the OAIC and affected individuals in line with the Notifiable Data Breaches scheme; and
  • we will cooperate with the Customer's own investigation and notification process.

Customers must tell us as soon as practicable if they become aware of unauthorised access to their Lori account.

11. How long we keep information

InformationRetention
Expression of Interest / contact form submissions24 months from last contact, then deleted - unless you become a Customer or opt in to updates
Customer account, billing and transaction recordsAt least 5 years after account closure, as required by Australian tax and record-keeping law
Marketing subscription recordsUntil you unsubscribe, plus 2 years to evidence consent under the Spam Act
Support and bug-report correspondence24 months from resolution
Technical and security logs90 days
Volunteer information in LoriWhile the Customer's account is active, or as the Customer instructs
Customer Data after account closure30 days to allow recovery, then permanently deleted; backups purged within a further 30 days

Customers can request deletion of their organisation's data at any time. We will action verified deletion requests within 30 days and confirm in writing.

When information is no longer needed, we take reasonable steps to securely destroy or de-identify it.

12. Access to and correction of your personal information

If you submitted an Expression of Interest, hold a Customer account, or are on our marketing list, you can ask us for access to the personal information we hold about you, or ask us to correct it, at any time.

  • No fee to make a request. We may charge a reasonable administrative fee for providing copies.
  • We may need to verify your identity first.
  • We will respond within 30 days. If we refuse, we will tell you why in writing and how to complain.

If you are a volunteer and want to access or correct information a Customer holds about you in Lori, contact that organisation directly - they control it. If you can't resolve it with them, contact us and we will help where we reasonably can, including by raising it with that Customer.

Data export.Customers can export their organisation's data from Lori at any time. Contact us if you need help.

13. How to make a complaint

If you have a concern about how we have handled information we control (see section 2), email us using the details in section 15. We will acknowledge within 5 business days and respond substantively within 30 days.

If your concern is about a Customer's handling of your volunteer information, raise it with that organisation first.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner:

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001

14. Changes to this policy

We may update this policy from time to time, including as Lori's features and beta status change. The current version is always available on our websites and inside Lori, with the 'last updated' date at the top.

Where a change materially affects how we handle personal information — including any change to where data is stored, or the introduction of document uploads or additional tracking — we will email Customers at least 14 days before it takes effect.

15. Contact us

For privacy questions, access or correction requests, or complaints:

Lori and BetterActs Collective Inc.info@betteractscollective.org
BetterActs Pty Ltdinfo@betteracts.com
Registered officeMelbourne VIC 3003, Australia

We are an incorporated association registered in Victoria. Our registered address is available through the Australian Business Register at abr.business.gov.au using ABN 90 406 224 512.