Privacy Policy

Frontage Systems ("Frontage", "we", "us", "our") Effective date: 21 June 2026 Contact: privacy@frontage.net.au

1. Who we are

Frontage is a multi-tenant community platform that allows organisations ("communities" or "tenants") to operate private digital communities for their members ("patrons"). You may interact with Frontage through a Frontage-branded app, a community-branded app, or a community's website.


2. What data we collect

2.1 Account data

When you create a patron account we collect:

2.2 Community activity

2.3 Device and usage data

2.4 Location data (on-device only)

Some tools (Prayer Times, Qibla Compass) request your device location solely to compute a local result. This data is processed on your device and in memory on our servers for the duration of the request. We do not store your GPS coordinates. We pass coordinates to aladhan.com (a third-party prayer-time API) in real time for calculation; aladhan.com does not store coordinates per their published policy.

2.5 Payment data

Payment card data is handled entirely by Stripe or PayPal. We never see or store full card numbers. We store transaction IDs and amounts as an immutable ledger.

2.6 Uploaded media

Photos and files you upload are stored on our server. Videos are transcoded and delivered via Bunny.net (CDN, Sydney region by default). See §6 for sub-processors.

2.7 AI assistant queries (where enabled)

Where a community enables the in-app AI assistant, the questions you type are sent to a third-party AI provider (Hyder AI) to generate a response. Do not include sensitive personal information in AI questions. See §6 for sub-processors.


3. How we use your data

PurposeLegal basis (AU Privacy Act / GDPR)

Delivering the community platformContract performance
Sending notifications you requestedConsent (you opt in per community)
Security — detecting fraud and abuseLegitimate interest
Crash reporting and bug fixesLegitimate interest
Compliance with legal obligationsLegal obligation

We do not sell your data. We do not use your data for advertising.


4. Data sharing

We share data only:


5. Push notifications

We use your device push token to deliver notifications for communities you have joined. You can disable notifications per-community inside the app, or revoke push permission at the OS level at any time. We use Firebase Cloud Messaging (Google) for push notification delivery (see §6).


6. Sub-processors

ProcessorPurposeLocation

Contabo GmbHVPS server hosting (app, database, file storage)Germany / EU
Bunny.netVideo transcoding and CDN deliveryNetherlands / Global CDN
Brevo (Sendinblue)Transactional emailEU
StripePayment processingUSA (PCI-DSS compliant)
PayPalPayment processingUSA
aladhan.comPrayer time calculation APIUSA (request only, no storage)
CloudflareDDoS protection, edge networkUSA / Global
SentryError and crash reportingUSA
Google (Firebase Cloud Messaging)Push notification deliveryUSA / Global
Hyder AIIn-app AI assistant (processes questions you type, where a community enables it)See provider policy

Transfers to processors outside Australia are protected by standard contractual clauses or equivalent safeguards.


7. Data retention

Data typeRetention

Active patron accountUntil deletion request + 60-day grace
Deleted accountPII anonymised immediately; activity logs retained 7 years for legal compliance
Transaction ledger7 years (tax / financial regulation)
Consent recordsIndefinitely (legal obligation)
Crash reports90 days
Push tokensUntil account deletion or token refresh


8. Your rights

Under the Australian Privacy Act 1988 and, where applicable, the EU GDPR, you have the right to:

We respond to requests within 30 days.


9. Children

The platform is intended for users aged 13 and over. Users under 13 may only access the platform through a guardian account. If we become aware of a patron under 13 without guardian access, we will suspend the account and contact the community administrator.


10. Security

We use AES-256-GCM encryption for sensitive data at rest, TLS 1.2+ for all data in transit, and bcrypt for passwords. Access to production data is restricted to authorised personnel only. We maintain audit logs of administrative access.


11. Changes to this policy

We will notify you of material changes via email and an in-app notice at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.


12. Contact

Frontage Systems

privacy@frontage.net.au

Governing law: New South Wales, Australia.

For GDPR complaints: you may also contact your local supervisory authority.