Privacy Policy
Frontage Systems ("Frontage", "we", "us", "our") Effective date: 21 June 2026 Contact: privacy@frontage.net.au1. Who we are
Frontage is a multi-tenant community platform that allows organisations ("communities" or "tenants") to operate private digital communities for their members ("patrons"). You may interact with Frontage through a Frontage-branded app, a community-branded app, or a community's website.
2. What data we collect
2.1 Account data
When you create a patron account we collect:
- Display name
- Email address
- Password (stored as a bcrypt hash — never in plaintext)
- Optional profile photo (stored on our server)
- Optional date of birth (if provided)
- Account creation timestamp and last-seen timestamp
2.2 Community activity
- Posts, comments, and reactions you create
- Content you bookmark or mark as read
- Notification preferences you set
2.3 Device and usage data
- Device type, OS version, and app version (for crash reporting and compatibility)
- IP address at login (stored for security audit purposes, not shared with tenants)
- Push notification token (for delivering notifications you request — see §5)
2.4 Location data (on-device only)
Some tools (Prayer Times, Qibla Compass) request your device location solely to compute a local result. This data is processed on your device and in memory on our servers for the duration of the request. We do not store your GPS coordinates. We pass coordinates to aladhan.com (a third-party prayer-time API) in real time for calculation; aladhan.com does not store coordinates per their published policy.
2.5 Payment data
Payment card data is handled entirely by Stripe or PayPal. We never see or store full card numbers. We store transaction IDs and amounts as an immutable ledger.
2.6 Uploaded media
Photos and files you upload are stored on our server. Videos are transcoded and delivered via Bunny.net (CDN, Sydney region by default). See §6 for sub-processors.
2.7 AI assistant queries (where enabled)
Where a community enables the in-app AI assistant, the questions you type are sent to a third-party AI provider (Hyder AI) to generate a response. Do not include sensitive personal information in AI questions. See §6 for sub-processors.
3. How we use your data
| Purpose | Legal basis (AU Privacy Act / GDPR) |
| Delivering the community platform | Contract performance |
| Sending notifications you requested | Consent (you opt in per community) |
| Security — detecting fraud and abuse | Legitimate interest |
| Crash reporting and bug fixes | Legitimate interest |
| Compliance with legal obligations | Legal obligation |
We do not sell your data. We do not use your data for advertising.
4. Data sharing
We share data only:
- With the community you joined — community administrators can see member lists, activity counts, and moderation flags. They cannot see your password, payment card data, or cross-community activity.
- With sub-processors listed in §6, under data processing agreements.
- If required by law — court order, regulator demand, or to prevent serious harm.
5. Push notifications
We use your device push token to deliver notifications for communities you have joined. You can disable notifications per-community inside the app, or revoke push permission at the OS level at any time. We use Firebase Cloud Messaging (Google) for push notification delivery (see §6).
6. Sub-processors
| Processor | Purpose | Location |
| Contabo GmbH | VPS server hosting (app, database, file storage) | Germany / EU |
| Bunny.net | Video transcoding and CDN delivery | Netherlands / Global CDN |
| Brevo (Sendinblue) | Transactional email | EU |
| Stripe | Payment processing | USA (PCI-DSS compliant) |
| PayPal | Payment processing | USA |
| aladhan.com | Prayer time calculation API | USA (request only, no storage) |
| Cloudflare | DDoS protection, edge network | USA / Global |
| Sentry | Error and crash reporting | USA |
| Google (Firebase Cloud Messaging) | Push notification delivery | USA / Global |
| Hyder AI | In-app AI assistant (processes questions you type, where a community enables it) | See provider policy |
Transfers to processors outside Australia are protected by standard contractual clauses or equivalent safeguards.
7. Data retention
| Data type | Retention |
| Active patron account | Until deletion request + 60-day grace |
| Deleted account | PII anonymised immediately; activity logs retained 7 years for legal compliance |
| Transaction ledger | 7 years (tax / financial regulation) |
| Consent records | Indefinitely (legal obligation) |
| Crash reports | 90 days |
| Push tokens | Until account deletion or token refresh |
8. Your rights
Under the Australian Privacy Act 1988 and, where applicable, the EU GDPR, you have the right to:
- Access your personal data (request a copy via privacy@frontage.net.au)
- Correct inaccurate data (edit in-app or contact us)
- Delete your account and data (Settings → Account → Delete account, or email us)
- Port your data (request a JSON export via privacy@frontage.net.au)
- Object to processing based on legitimate interest
- Withdraw consent for notifications at any time via OS settings
We respond to requests within 30 days.
9. Children
The platform is intended for users aged 13 and over. Users under 13 may only access the platform through a guardian account. If we become aware of a patron under 13 without guardian access, we will suspend the account and contact the community administrator.
10. Security
We use AES-256-GCM encryption for sensitive data at rest, TLS 1.2+ for all data in transit, and bcrypt for passwords. Access to production data is restricted to authorised personnel only. We maintain audit logs of administrative access.
11. Changes to this policy
We will notify you of material changes via email and an in-app notice at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.
12. Contact
Frontage Systemsprivacy@frontage.net.au
Governing law: New South Wales, Australia.
For GDPR complaints: you may also contact your local supervisory authority.