← Home

LÜP Reuse Network — Privacy Policy

Draft — pending legal review. This document is a working draft and is not yet final or legally binding. It will be replaced with the reviewed version before LÜP launches.

Effective date: 15 September 2026 · Version: 1.3

Langlee Trading Pty Ltd (ABN 93 687 333 811) trading as LÜP Reuse Network (“LÜP”, “we”, “us”) respects your privacy. This policy explains how we handle your personal information. We handle it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we hold ourselves to those standards as a matter of policy — including where a particular obligation might not strictly apply to a business of our size.

1. What personal information we collect

We don’t intentionally collect sensitive information (e.g. health, racial, political information).

1.1 Cookies and tracking technologies

We keep this simple. LÜP uses the essential cookies your browser needs to sign you in and run the app — for example, keeping you logged in and remembering a borrow or return you’ve started. Our payment provider (Stripe) may also set its own strictly necessary cookies on payment screens to help detect fraud. When the venue-finder map loads, your browser connects directly to Google (see clause 1). We use Google’s mapping code directly rather than an embedded Google Maps page, so it doesn’t set Google’s advertising or preference cookies.

Finding and fixing problems. We use an error-monitoring tool (Sentry) that records technical details when something goes wrong in the app — what the error was, and basic information about your browser and device — so we can diagnose and fix it. Before an error report leaves the app we strip out the things that could identify you, including your account details, IP address, cookies and the query part of the web address. Sentry doesn’t record your screen or your session, and we don’t use it for advertising.

Stopping automated abuse of sign-in. When you ask for a sign-in code, an invisible check from Cloudflare Turnstile runs in your browser to confirm the request is coming from a real browser rather than an automated script. You won’t see anything, and it doesn’t run while you borrow, return or swap. To make that check, your browser sends Cloudflare technical signals — your IP address and details about your browser and connection (its user-agent and TLS fingerprint). Cloudflare uses them to detect and block bots for us, and also uses them to improve its bot detection, as described in Cloudflare’s Turnstile Privacy Addendum. We don’t receive those signals. Instead your browser gives us a one-time pass, and our server sends that pass, together with your IP address, to Cloudflare to confirm it is genuine; Cloudflare tells us only whether it passed. When you sign in, we also pass your IP address to Supabase, our sign-in provider, so it can limit repeated sign-in attempts from the same place.

What we don’t do. We don’t use advertising cookies or cross-site trackers, we don’t build advertising or behavioural profiles of you, we don’t sell your personal information, and we don’t share it with advertising networks or data brokers.

Because the cookies we use are strictly necessary to provide the Service you’ve asked for, we don’t ask you to accept a cookie banner. You can still clear or block cookies in your browser, but sign-in and core features won’t work without the essential ones.

2. How we collect it

3. Why we collect, hold, use and disclose it

We only use or disclose your information for these purposes, a directly related purpose you’d reasonably expect, or as required or authorised by law.

4. Who we share it with

We share personal information with the service providers below, who help us run LÜP and are required by contract to protect it and use it only for us. Where noted, your browser connects directly to a provider and that provider also handles the information under its own privacy terms.

Provider Purpose Data
Stripe Payments / card storage Email address, card details and billing postcode (entered directly with Stripe), payment token, charge details
Supabase Database + sign-in (hosted in Sydney, Australia) Account + activity data, and your IP address each time you sign in — used to limit repeated sign-in attempts, and kept in short-lived sign-in security logs
Resend Sending transactional email Email address, message content
Google Maps Platform Venue-finder map The map area you view, and your IP address, sent directly from your browser to Google. Your postcode or location is not sent to LÜP or stored by us. Google handles this under its own privacy terms.
Vercel App hosting Technical request data
Sentry Error monitoring — catching and diagnosing crashes and faults Crash reports — the error, and basic browser and device details. Identifying data (account details, IP address, cookies, query strings) is removed before sending. No session recording.
Cloudflare Turnstile Blocking automated abuse of sign-in Your IP address and technical browser and connection details, sent directly from your browser to Cloudflare when you request a sign-in code, and your IP address again from our server when we confirm the check passed. Cloudflare also uses these to improve its bot detection, under its Turnstile Privacy Addendum.

We don’t sell your personal information. We may disclose information where required or authorised by law, to enforce our Terms, or as part of a proposed or completed sale, merger, restructure or transfer of all or part of our business — in which case we will require the recipient to handle your personal information consistently with this policy.

5. Automated charging (automated decision-making)

If a borrowed Bowl isn’t returned within 7 days, you keep it and the $5 Keep Price applies per Bowl (see our Terms of Use). Because this has a financial consequence for you, here’s how that decision is made:

6. Direct marketing

We send service messages as a necessary part of the Service — these aren’t marketing. They include sign-in and email-verification codes, a welcome message when you set up your Saved Payment Method, borrow, return and swap confirmations, return reminders, and notices about charges, waivers and refunds. We send marketing to customers only if you’ve opted in. You can turn some confirmations off in the app; messages we must send to operate the Service or to tell you about a charge are still sent. Every marketing message identifies us as the sender and includes a simple unsubscribe, which stays working for at least 30 days after the message is sent. We action unsubscribe requests as quickly as we can, and in any case within 5 business days (the maximum allowed under the *Spam Act 2003* (Cth)). You can opt out any time (unsubscribe link, or email privacy@lupit.com.au).

7. How we keep it secure

We take reasonable technical and organisational steps to protect your information — including encryption in transit, restricting access to personal information to the people who need it, and using a PCI-compliant payment processor (Stripe) so we never hold raw card numbers. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident (see clause 12).

8. How long we keep it (and deletion)

We keep personal information only as long as we need it for the purposes above, except where the law requires us to keep it. How long depends on the type of record:

You can ask us to delete your account and personal information (email privacy@lupit.com.au). We handle these requests by hand, so please allow us a little time — we’ll confirm when it’s done. Closing your account under our Terms of Use and deleting your personal information are related but separate — you can close your account once you have no Bowls outstanding and nothing left to pay, and you can ask us separately to delete your information. If you’ve been charged or saved a payment method, we may need to keep the transaction record for the period described above; in that case we de-identify your account so the record no longer identifies you. We’ll delete or de-identify everything else, hold anything we do keep securely and use it only for the purpose that requires us to keep it, and delete it when that period ends. Copies may remain in our secure backups for a short time before being overwritten.

9. Overseas disclosure

Some of our providers are overseas companies, and some store or process information outside Australia. Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, and we remain responsible to you for how your information is handled — if something goes wrong with one of our overseas providers, raise it with us (clause 11) and we’ll deal with it.

Where each provider stores or processes information, as at the effective date of this policy:

Providers can change where they operate. We check these locations whenever we update this policy.

10. Accessing and correcting your information

You can ask to access the personal information we hold about you, or to correct it if it’s wrong, by emailing privacy@lupit.com.au. We don’t charge you for making a request. We’ll ask you to confirm your identity first — usually just by replying from the email address on your account — and we’ll respond within a reasonable time, usually within 30 days. If we can’t give you access or make a correction, we’ll explain why in writing and tell you how to complain (clause 11). If we don’t make a correction you’ve asked for, you can ask us to attach a note to the information recording that you think it’s wrong.

11. Complaints

If you think we’ve mishandled your personal information or breached the APPs, contact our privacy contact (privacy@lupit.com.au). We’ll acknowledge your complaint promptly and aim to resolve it within 30 days. If you’re not satisfied with our response, or we haven’t responded within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au, 1300 363 992.

12. Data breaches

If personal information we hold is lost, or accessed or disclosed without authorisation, and that’s likely to result in serious harm to you, we’ll act under the Notifiable Data Breaches scheme. We’ll assess any suspected breach promptly (within 30 days), take action to reduce the risk of harm, and where serious harm is still likely we’ll notify you and the OAIC with the information and recommended steps you need. Not every incident is notifiable — if we can contain it so serious harm is no longer likely, notification isn’t required, but we’ll still deal with it.

13. Changes to this policy

We may update this policy. We’ll post the new version at app.lupit.com.au/privacy with an updated effective date and version number. If a change is material — for example, collecting a new kind of personal information, using it for a new purpose, adding a new service provider, or disclosing information to a new overseas recipient — we’ll take reasonable steps to tell you before it takes effect, for example by email or a notice in the app. Where the law requires your consent to a change, we’ll ask for it.

14. If you work at a venue

This clause covers people at Partner Venues — the owners, managers and staff who use the LÜP venue dashboard or deal with us — and people at venues we’re approaching about partnering.

15. Contact us

Privacy contact: privacy@lupit.com.au

Support: support@lupit.com.au

Entity: Langlee Trading Pty Ltd (ABN 93 687 333 811) t/as LÜP Reuse Network

Postal address: 26 Langlee Ave, Waverley NSW 2024, Australia