Privacy Policy

Effective 8 September 2026 · Version 2026-09-08

Out West AI Pty Ltd (ABN 84 695 421 615) ("we", "us") operates CommitteeHQ. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why, and the choices you have.

1. Two kinds of personal information

CommitteeHQ holds personal information in two distinct capacities:

  • Account information we collect for ourselves — the name, email address, mobile number and login records of people who create CommitteeHQ accounts. We decide how this is used (to operate accounts, billing and support), and this policy governs it directly.
  • Committee records stored by your Organisation — member directories, volunteer rosters, contact details, compliance documents and similar records that a committee stores about its own people. The committee controls this information; we process it only on the committee's behalf to provide the service. Questions about how a committee uses its records should go to that committee first.

2. What committee records can include

Committees commonly store contact details, committee positions, membership status and event participation. Some records are more sensitive, and we design for them accordingly:

  • Information about minors. Junior members and young volunteers may appear in member registers and event rosters. The committee is responsible for having a parent or guardian's consent to record information about a person under 18. We never use minors' information for anything beyond providing the service, and it is never used for marketing.
  • Volunteer forms (health information). Before an event a volunteer may be asked to give an emergency contact, their date of birth (only so we know whether a parent or guardian's details are needed), and, optionally, anything the coordinator or a first-aider should know — which may include medical conditions or allergies — and to sign a safety brief. Where that note contains medical details it is health information under the Privacy Act. It is entered by the volunteer themselves, used only so the committee can look after them on the day, shown only to the committee and the event-day coordinator, printed only on the coordinator's station sheet (which the committee is told to destroy after the event), and never used for anything else. The note is optional. The signature image is kept with the signed brief as the record that it was read.
  • Compliance documents. RSA certificates, blue cards, insurance policies and licences may contain identifying details. These are visible only to the Organisation's authorised members, and access to documents is logged.

Some committee records are created as you use CommitteeHQ rather than typed in: your RSVP to a meeting and how you attended it (in person, by phone or by video), motions you moved or seconded and how the votes were counted, action items assigned to you, and receipts you photograph for a bill. Attendance and motions become the minutes of the meeting, which is a record an incorporated association is required to keep.

3. The mobile app

The CommitteeHQ app for phones and tablets is a window onto the same committee records. Accounts are not created in the app: your committee gives you access, and the app signs you in to it. In addition to the records above, the app collects:

  • A device notification token, issued by Google's Firebase Cloud Messaging, so we can send you push notifications about meetings, bill approvals and event days. You can turn these off in the app or on your device.
  • Basic device and app-version information, sent when the device registers, so support can tell which build you are on.

The app does not collect your location, does not use advertising identifiers, and contains no analytics or crash-reporting tools.

So that the app works without mobile coverage, a copy of some of your committee's information is kept on your own device: meeting papers, the directory, documents you have opened, and anything you have entered that has not yet been sent. That copy is held in an encrypted database, sign-in tokens are kept in the device's secure keystore (iOS Keychain or Android Keystore), and logging out erases the local copy entirely, which matters for a committee tablet that is passed around. Anything entered on the device and not yet sent is not part of your committee's records until it reaches us; the app shows plainly when that is the case.

Working-with-children (blue card) details are visible on the website only to committee members whose role requires them. The app shows counts and expiry status only, never the card details.

4. What happens when office bearers change

Committee records belong to the Organisation, not to the individual office bearer who entered them. When a committee's office bearers turn over, the Organisation's administrators can transfer access to the incoming committee; the outgoing office bearer's access ends but the records remain with the Organisation. This is how incorporated associations are expected to maintain continuity of their registers.

5. How long we keep information

  • Active accounts: for as long as the Organisation subscribes or a trial is active.
  • After a trial ends without subscribing, or after cancellation: the Organisation's data is locked and retained for 3 months, then may be permanently deleted. During the retention window the committee can reactivate or export its data.
  • Earlier deletion: an Organisation's administrators can request earlier permanent deletion in writing.
  • Financial records we must keep: our own invoicing and tax records are retained as required by Australian law.

6. Who we share information with

We do not sell personal information. We share it only with service providers needed to run CommitteeHQ:

  • Stripe — payment processing. Card details go directly to Stripe; we never hold them.
  • Xero — only when your committee connects its own Xero account, and only the accounting data that integration needs.
  • Email delivery provider — to send the notices, digests and reminders your committee configures.
  • Google (Firebase Cloud Messaging) — to deliver push notifications to the mobile app. Firebase receives your device token and the text of each notification (for example a meeting title or a supplier name on a bill to approve). It does not receive your committee's records.
  • Out West AI analytics — our public marketing pages send anonymous usage analytics (page URL, referrer, screen size, language) to our own analytics service at outwest.ai. This does not include names, emails or committee records.

Our services are hosted in Australia. Some providers process data overseas: in particular, Firebase processes push-notification data outside Australia, and Stripe and Xero operate globally. Where that happens we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles, and we limit what those providers receive to what their function needs.

7. Security

Access to committee records is restricted to the Organisation's own authorised members and scoped by role. Everything travels over HTTPS. Passwords are hashed, sessions are protected, two-factor authentication is required before anyone can reach financial records, sensitive tokens are hashed at rest, and administrative access is logged. Changing your password or your two-factor setting signs out every mobile device. No system is perfectly secure; if a data breach is likely to cause serious harm we will notify affected people and the OAIC as required by the Notifiable Data Breaches scheme.

8. Access, correction and closing an account

You can access and update your own account information from your profile. For committee records about you, ask your committee first — its secretary or administrator controls those records and can usually act immediately. If you believe we hold information about you that is inaccurate and your committee cannot help, contact us and we will assist.

You can ask us to delete information about you, subject to the records your committee is legally required to keep and to the fact that the information may belong to your committee rather than to you. Because accounts are created by committees rather than in the app, closing your access is something your committee does; if you would rather deal with us directly, contact us and we will arrange it with them.

9. Cookies

We use cookies for login sessions and security (including CSRF protection), and browser storage to remember preferences such as your theme. We do not use third-party advertising cookies.

10. Complaints

Privacy questions or complaints: privacy@outwestai.com.au. We respond within 30 days. If you are unsatisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

11. Changes to this policy

Material changes will be notified to Organisation administrators by email before they take effect, and each version is identified by the date at the top of this page.