Green Week Club

Privacy Policy

Effective 16 September 2026

These policies apply to Green Week Club accounts and use of this website.

1. Who handles your information

This policy covers Green Week Club’s website, accounts, membership billing, referrals and optional notifications. Green Week Club is operated by Unified Shores IT Services Pty LTD (ABN 35 603 926 656), of Level 5, 140E Cronulla Street, Cronulla NSW 2230. Send privacy enquiries, access requests and complaints to support_team@greenweekclub.com.

2. Information collected

Account information includes email, name, optional display name, country/jurisdiction, time zone, confirmation that you are 18 or older, accepted terms/disclaimer versions and timestamps, notification choices and account status. Authentication is handled by Supabase. Passwords are submitted for authentication; they are not included in experiment analytics.

Membership records include plan, payment-provider references, invoice amounts and status, payment failures and referral relationships. Stripe collects card details in its payment setup pages; the application uses Stripe references instead of storing full card details. If you choose Telegram notifications, the linked chat/account identifier and delivery settings are used for that service. Information you send to support is also processed.

Hosting, security and error-monitoring providers process technical request information, which may include IP address, browser/device information, timestamps, page requests and error details. Avoid sending passwords or card details to support. We do not obtain your bookmaker account balance or personal bets through the website.

3. Why information is used

We use information to create and secure accounts, check stated eligibility, supply member content, send requested notifications, administer billing and referrals, respond to support, investigate errors or misuse, and improve the website. Age and terms confirmations record the signup declarations; they are not independent identity verification. Marketing preferences are separate from necessary account and billing communications.

4. Cookies, analytics and website experiments

PostHog automatically measures page visits and signup and checkout steps to help us improve the website. You can turn this optional analytics off using the control below, and we honour previously saved opt-outs. It receives only selected page paths, step numbers, traffic-source categories, approved X campaign and content labels, and technical browser/device categories. Campaign labels from tagged links are kept in page memory to connect the arrival with subsequent signup or checkout steps during that visit. We do not send form contents, email addresses, account IDs, payment details, full URL query strings or fragments, and do not enable session replay or automatic interaction capture. A random identifier exists only in page memory and is not linked to your account. If you change your analytics preference, that choice is stored in this browser’s local storage; analytics identifiers and these campaign labels are not persisted across page reloads or stored in cookies. Global Privacy Control and Do Not Track disable this optional collection. These choices apply to PostHog; essential services and error monitoring below are separate.

Optional PostHog analytics are off for this browser.

Authentication cookies support sign-in and session security. The manual design-preview cookie remembers a preview choice for up to 30 days. Website analytics use PostHog, and error monitoring uses Sentry. Session replay is disabled for this launch. Error monitoring may still process technical diagnostics and request metadata; it is separate from optional analytics and the signup experiment.

For permitted visits arriving through campaign or referral links, a separate first-party campaign cookie lasts up to 90 days and remembers selected campaign tags and referral information across navigation. This collection can operate when no design experiment is enrolling. Global Privacy Control and Do Not Track disable it; known automated traffic, signed-in arrivals and staff preview browsers are excluded. At signup, campaign information is linked privately to the new account for acquisition reporting and is scheduled for removal after 180 days by daily maintenance.

When website experiments are enabled, a first-party cookie lasting up to 90 days keeps a browser in the same design group. Experiment records include a random browser identifier, design and experiment version, entry page, coarse device category, campaign tags and referral information, along with signup-step, rendering and performance events. At account creation, a private link connects that identifier to the account to measure email verification, profile completion, activation and return visits. These linked records are pseudonymous, not anonymous.

Experiment events do not include passwords, email addresses, form contents or full URLs containing authentication tokens. The experiment implementation respects Global Privacy Control and Do Not Track signals by skipping participation and event collection. This setting does not disable essential authentication or necessarily control other providers. Blocking or deleting cookies can affect sign-in and design persistence. The site does not use fingerprinting for experiment assignment.

5. Service providers and overseas processing

The service uses Supabase for accounts and database storage, Stripe for payments, Resend for outbound email, Microsoft 365 for support email, Netlify for hosting, Sentry for error monitoring and PostHog for optional website and product analytics. PostHog uses its United States cloud region for this site. Operational automation helps deliver the service; Telegram receives delivery information if you link it. Providers receive information needed for their function under their terms and our configuration. Public results describe the model’s published selections, not members’ private betting accounts.

Information may be stored or processed outside Australia. Our operational Supabase database is hosted in Japan. Other providers and their suppliers may process information in the United States and other countries in which they operate. A provider’s registered address is not necessarily the location of its data storage. Contact us for the current provider and overseas-processing information relevant to your account. We may also disclose information when required by law or reasonably necessary to investigate misuse and protect lawful rights.

6. Retention and security

We retain information needed to run accounts, resolve disputes, maintain required records and meet legal obligations, then delete or de-identify it where appropriate. Experiment retention is 180 days from assignment, after which experiment events and account links are removed by the daily maintenance job. The 90-day browser cookie lifetime is separate from database retention. If you request account deletion, we aim to remove or de-identify account information no longer needed within 30 days after verifying the request. We retain required company financial records for at least seven years and longer where a legal hold or other requirement applies. Routine support correspondence is reviewed for deletion 24 months after the issue closes. We target no more than 90 days for application diagnostic records under our control. Providers maintain separate retention and backup cycles; deletion from active records may precede expiry from backups. Retained records are restricted to the purpose that requires retention.

To preserve signup attribution through temporary failures, a private pending signup record holds a one-way email digest and a random request identifier. The digest is removed when the account is linked; pending request records are scheduled for deletion after one day by daily maintenance. Delayed or failed maintenance can delay scheduled removal. Membership activation history records the first observed access transition.

Access controls limit private records to authorised systems and people. Payment processing is delegated to Stripe, and experiment data is unavailable through public database access. No internet service can promise absolute security. Contact support if you suspect unauthorised account access.

7. Access, corrections, choices and complaints

You can edit available profile and notification settings in your account. Contact support to request access to or correction of other personal information, account deletion, or to raise a privacy complaint. We may need to verify your identity. Some records may need to be retained for legal, security or billing reasons; any applicable restrictions will be explained.

We acknowledge privacy requests and complaints within five business days and aim to provide a substantive response within 30 days, explaining any delay. If unresolved, you may contact the Office of the Australian Information Commissioner where it has jurisdiction, or the relevant privacy authority in your location. We do not limit any right you have under applicable privacy law.

8. Updates

We will display the effective date of this policy and notify account holders of material changes through the website or account communications before they take effect where practicable.

Contact Green Week Club