Privacy policy
This policy covers fullhall.au and the fullhall product, operated by Outback Yak Pty Ltd (ABN 11 672 730 773). It's written to be read, not to cover anyone's backside. Last updated 18 July 2026.
The short version
We hold two kinds of personal information: accounts for the admins who sign in, and the records their organisations keep (contacts, RSVPs). The second kind belongs to the organisation, not to us. We don't sell personal information and we never use your members' details for our own marketing. The database runs in Australia.
What we collect and why
Admin accounts: your name and email address, collected when you sign up, used to sign you in and to send you messages about the service. Sign-in is handled by Clerk, our authentication provider; we never see or store your password.
Organisation records: the contacts, teams, events, RSVPs and files your organisation puts into fullhall. We store and process these only to run the service for your organisation. What goes in is your organisation's decision, and its responsibility to have the right to record.
RSVPs from supporters: a name, an email address and a guest count, given on a public event page. They're used to confirm the RSVP, manage the waitlist, and keep the organisation's attendance list true. Supporters don't get accounts and are never emailed for marketing.
Ticket buyers: a name, an email address and the order itself (which tickets, for how much, and any refund), given when someone buys a ticket on a public event page. Card details are entered on Stripe's payment page and go straight to Stripe; they never reach our servers, and we couldn't see them if we wanted to. The order record is used to send tickets, run the door list, and let the organisation issue refunds.
Members: a name, an email address and, where the organisation records it, a postal address, given when someone joins on a public membership page or when the organisation adds them. These make up the organisation's membership records and its register of members; we store and process them only for that purpose. Membership payments work like ticket payments: card details go straight to Stripe and never reach our servers.
Usage analytics: we use PostHog, hosted in the European Union, to understand how the product is used. Visitors who aren't signed in are not profiled; analytics are tied to a person only after sign-in. We don't run advertising trackers.
We may also use data in aggregated or de-identified form, where no person or organisation is identifiable, to operate, secure and improve the service. Once de-identified it's no longer personal information, and we keep it that way.
Where your data lives
The fullhall database runs on infrastructure in Australia. Uploaded files are stored with Cloudflare. A few services we build on process limited data overseas: Clerk (authentication, United States), Stripe (ticket payments, United States), PostHog (analytics, European Union) and Cloudflare (file storage and network). Each receives only what its job requires. Ticket payments settle in the organisation's own Stripe account, and Stripe acts under its own privacy policy for the payment itself.
Who can see it
The admins of your organisation see your organisation's records; nobody from another organisation can. Our own access is limited to what operating the service requires (debugging a fault you've reported, for instance), and we don't browse customer data.
We disclose personal information outside the company only to the service providers above, or where the law requires it.
How long we keep it
We keep your organisation's records while its account is active, because that's the service. After an organisation is closed, we delete or de-identify its data within 90 days, keeping only what the law requires us to keep (and for only as long as it requires).
Cookies
fullhall sets the cookies needed to keep admins signed in, and an analytics cookie as described above. There are no third-party advertising cookies.
Access, correction and deletion
Email [email protected] to see what we hold about you, have it corrected, or have it deleted. If you're a supporter whose details sit in an organisation's list, we'll also point you to that organisation, since the list is theirs; but we'll help either way. Organisations can export their contacts as CSV at any time and can ask us to delete everything.
If something goes wrong
If a data breach is likely to cause serious harm, we'll notify the affected organisations and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme, and we'll tell you what happened in plain language.
Complaints
If you think we've mishandled your personal information, email us first and we'll try to put it right. If you're not satisfied with our answer, you can complain to the OAIC.
Changes
When this policy changes, the date at the top changes with it, and material changes get an email to admins. The current version always lives at this address.
Questions about any of this: [email protected]. The security page covers how the data is protected.