LÜP Reuse Network — Privacy Policy
Effective date: 15 September 2026 · Version: 1.3
Langlee Trading Pty Ltd (ABN 93 687 333 811) trading as LÜP Reuse Network (“LÜP”, “we”, “us”) respects your privacy. This policy explains how we handle your personal information. We handle it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we hold ourselves to those standards as a matter of policy — including where a particular obligation might not strictly apply to a business of our size.
1. What personal information we collect
- Email address — to create your account, sign you in, and send you service messages. You can sign in either with your email address and a one-time code, or with Apple Pay or Google Pay — in which case the wallet passes us (via Stripe) the email address linked to it, and that address becomes your LÜP account. If you’d rather your account used a different address, sign in with your email and a one-time code instead.
- Payment method — when you save a card, you enter it directly with Stripe. To help verify the card and reduce fraud, Stripe also collects your card’s billing postcode, and may record the country. We never see or store your full card number. Your postcode isn’t stored in our systems either — it sits on the record Stripe keeps for us, which we can access but don’t use. Through Stripe we hold a payment token, a record of your payment authorisation, and your payment status. Your card brand and last 4 digits are shown to us by Stripe when we need them, rather than stored by us. We don’t ask for your name or phone number. If you use Apple Pay or Google Pay, no postcode is collected — though your card provider may attach the cardholder name to the Stripe record, which we also don’t use.
- Borrow and return activity — which Bowls you borrow and return, when, and at which Partner Venues; any Bowls you keep and the $5 Keep Price charged. These records are generated by the Service as you use it.
- Approximate location (we don’t store it) — to show nearby venues and sort them by distance, the app uses either the postcode you type or, only if you allow it, your device’s location. Either way, we never send your postcode or location to, or store it on, LÜP’s servers. To draw the map itself, your browser connects directly to Google Maps Platform, which receives the map area being displayed and (as with any web request) your IP address, and handles that under Google’s own privacy terms. See clause 4.
- Device and usage information — technical data your browser sends when you use the app, such as your IP address, browser and device type, and app request and error logs.
- Support information — anything you send us when you contact support.
- Records of your consent — a record of your acceptance of our Terms of Use and of your authorisation for the $5 Keep Price charge, including the date, time and version you accepted, and the IP address and browser details captured at that moment.
We don’t intentionally collect sensitive information (e.g. health, racial, political information).
1.1 Cookies and tracking technologies
We keep this simple. LÜP uses the essential cookies your browser needs to sign you in and run the app — for example, keeping you logged in and remembering a borrow or return you’ve started. Our payment provider (Stripe) may also set its own strictly necessary cookies on payment screens to help detect fraud. When the venue-finder map loads, your browser connects directly to Google (see clause 1). We use Google’s mapping code directly rather than an embedded Google Maps page, so it doesn’t set Google’s advertising or preference cookies.
Finding and fixing problems. We use an error-monitoring tool (Sentry) that records technical details when something goes wrong in the app — what the error was, and basic information about your browser and device — so we can diagnose and fix it. Before an error report leaves the app we strip out the things that could identify you, including your account details, IP address, cookies and the query part of the web address. Sentry doesn’t record your screen or your session, and we don’t use it for advertising.
Stopping automated abuse of sign-in. When you ask for a sign-in code, an invisible check from Cloudflare Turnstile runs in your browser to confirm the request is coming from a real browser rather than an automated script. You won’t see anything, and it doesn’t run while you borrow, return or swap. To make that check, your browser sends Cloudflare technical signals — your IP address and details about your browser and connection (its user-agent and TLS fingerprint). Cloudflare uses them to detect and block bots for us, and also uses them to improve its bot detection, as described in Cloudflare’s Turnstile Privacy Addendum. We don’t receive those signals. Instead your browser gives us a one-time pass, and our server sends that pass, together with your IP address, to Cloudflare to confirm it is genuine; Cloudflare tells us only whether it passed. When you sign in, we also pass your IP address to Supabase, our sign-in provider, so it can limit repeated sign-in attempts from the same place.
What we don’t do. We don’t use advertising cookies or cross-site trackers, we don’t build advertising or behavioural profiles of you, we don’t sell your personal information, and we don’t share it with advertising networks or data brokers.
Because the cookies we use are strictly necessary to provide the Service you’ve asked for, we don’t ask you to accept a cookie banner. You can still clear or block cookies in your browser, but sign-in and core features won’t work without the essential ones.
2. How we collect it
- Directly from you — when you sign up, set up a Saved Payment Method, borrow or return Bowls, search venues, or contact us.
- From your digital wallet — if you sign in using Apple Pay or Google Pay, we receive the email address linked to that wallet, passed to us through Stripe. Apple and Google aren’t our service providers — they run your wallet under their own terms, and (as with any card payment) your wallet and card provider will see the merchant name and amount of any Keep Price charge.
- Generated as you use the Service — your borrow and return records, and the technical and log data created automatically when you use the app.
- From our service providers — e.g. Stripe (payment status), and standard technical data from hosting and email providers.
- From Partner Venues — where a venue confirms a borrow or return.
3. Why we collect, hold, use and disclose it
- To provide the Service — creating your account and signing you in (email address), recording what you borrow and return and where (borrow and return activity), and showing you nearby venues (the postcode you type or your device location).
- To charge the $5 Keep Price if a Bowl isn’t returned in time — using your borrow and return records to work out whether the 7-day window has passed, and your Saved Payment Method to take the payment (clause 5).
- To communicate with you — service messages (sign-in codes, receipts, return reminders, charge notices) and, only with your consent, marketing.
- To run, secure and improve the Service and prevent fraud or misuse — mainly using device and usage information, including the automated-abuse check on sign-in (clause 1.1).
- To meet legal obligations (e.g. tax and financial record-keeping) and to handle disputes and complaints.
- To produce aggregated, de-identified statistics about the network’s environmental impact — for example Bowls reused and single-use containers avoided. These are built from borrow and return records, don’t identify you, and may be shared with Partner Venues, councils and other organisations, or published.
We only use or disclose your information for these purposes, a directly related purpose you’d reasonably expect, or as required or authorised by law.
4. Who we share it with
We share personal information with the service providers below, who help us run LÜP and are required by contract to protect it and use it only for us. Where noted, your browser connects directly to a provider and that provider also handles the information under its own privacy terms.
| Provider | Purpose | Data |
|---|---|---|
| Stripe | Payments / card storage | Email address, card details and billing postcode (entered directly with Stripe), payment token, charge details |
| Supabase | Database + sign-in (hosted in Sydney, Australia) | Account + activity data, and your IP address each time you sign in — used to limit repeated sign-in attempts, and kept in short-lived sign-in security logs |
| Resend | Sending transactional email | Email address, message content |
| Google Maps Platform | Venue-finder map | The map area you view, and your IP address, sent directly from your browser to Google. Your postcode or location is not sent to LÜP or stored by us. Google handles this under its own privacy terms. |
| Vercel | App hosting | Technical request data |
| Sentry | Error monitoring — catching and diagnosing crashes and faults | Crash reports — the error, and basic browser and device details. Identifying data (account details, IP address, cookies, query strings) is removed before sending. No session recording. |
| Cloudflare Turnstile | Blocking automated abuse of sign-in | Your IP address and technical browser and connection details, sent directly from your browser to Cloudflare when you request a sign-in code, and your IP address again from our server when we confirm the check passed. Cloudflare also uses these to improve its bot detection, under its Turnstile Privacy Addendum. |
We don’t sell your personal information. We may disclose information where required or authorised by law, to enforce our Terms, or as part of a proposed or completed sale, merger, restructure or transfer of all or part of our business — in which case we will require the recipient to handle your personal information consistently with this policy.
5. Automated charging (automated decision-making)
If a borrowed Bowl isn’t returned within 7 days, you keep it and the $5 Keep Price applies per Bowl (see our Terms of Use). Because this has a financial consequence for you, here’s how that decision is made:
- What information is used — your borrow and return records (which Bowls, when, and at which Partner Venue), the 7-day window that applies to each borrow, and your Saved Payment Method.
- What the system does — our system works out automatically whether the 7-day window has passed without a matching return, and flags the borrow for charging.
- Who decides — the outcome follows from your borrow and return records. At launch, a member of the LÜP team checks each flagged borrow before a charge is made and can charge it or waive it. As the Service grows, that check may be replaced by the system making the charge automatically. Either way, you can ask us to review a charge — see below.
- The outcome — a $5 Keep Price per Bowl is charged to your Saved Payment Method off-session, and the Bowl becomes yours — and if we waive the charge, the Bowl is still yours.
- Before and after — we send you reminders before the window closes, and a receipt after any charge.
- If you think a charge is wrong — email support@lupit.com.au. We’ll review it, tell you what records we relied on, and refund the charge if it shouldn’t have been made. You can also ask us to correct your information (clause 10) or make a privacy complaint (clause 11).
6. Direct marketing
We send service messages as a necessary part of the Service — these aren’t marketing. They include sign-in and email-verification codes, a welcome message when you set up your Saved Payment Method, borrow, return and swap confirmations, return reminders, and notices about charges, waivers and refunds. We send marketing to customers only if you’ve opted in. You can turn some confirmations off in the app; messages we must send to operate the Service or to tell you about a charge are still sent. Every marketing message identifies us as the sender and includes a simple unsubscribe, which stays working for at least 30 days after the message is sent. We action unsubscribe requests as quickly as we can, and in any case within 5 business days (the maximum allowed under the *Spam Act 2003* (Cth)). You can opt out any time (unsubscribe link, or email privacy@lupit.com.au).
7. How we keep it secure
We take reasonable technical and organisational steps to protect your information — including encryption in transit, restricting access to personal information to the people who need it, and using a PCI-compliant payment processor (Stripe) so we never hold raw card numbers. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident (see clause 12).
8. How long we keep it (and deletion)
We keep personal information only as long as we need it for the purposes above, except where the law requires us to keep it. How long depends on the type of record:
- Transaction, payment and tax records — at least 5 years after the relevant transaction, as required by Australian tax law, and up to 7 years where company financial-record requirements apply.
- Technical logs — the device and usage data described in clause 1, kept for a short period (up to 90 days) for security, troubleshooting and abuse-prevention, then deleted or de-identified.
- Account and activity records — kept while your account is open, and afterwards only for as long as we need them to resolve anything outstanding, then deleted or de-identified.
You can ask us to delete your account and personal information (email privacy@lupit.com.au). We handle these requests by hand, so please allow us a little time — we’ll confirm when it’s done. Closing your account under our Terms of Use and deleting your personal information are related but separate — you can close your account once you have no Bowls outstanding and nothing left to pay, and you can ask us separately to delete your information. If you’ve been charged or saved a payment method, we may need to keep the transaction record for the period described above; in that case we de-identify your account so the record no longer identifies you. We’ll delete or de-identify everything else, hold anything we do keep securely and use it only for the purpose that requires us to keep it, and delete it when that period ends. Copies may remain in our secure backups for a short time before being overwritten.
9. Overseas disclosure
Some of our providers are overseas companies, and some store or process information outside Australia. Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, and we remain responsible to you for how your information is handled — if something goes wrong with one of our overseas providers, raise it with us (clause 11) and we’ll deal with it.
Where each provider stores or processes information, as at the effective date of this policy:
- Supabase (database + sign-in — where your account and activity data live) — Sydney, Australia. Supabase is a US company.
- Stripe (payments) — United States and other Stripe locations. We send only a payment token and limited metadata; raw card numbers are handled by Stripe, not LÜP.
- Resend (transactional email) — Japan (Tokyo sending region); Resend is a US company.
- Google Maps Platform (venue-finder map) — United States / global.
- Vercel (app hosting) — primarily Sydney (syd1) compute; Vercel is a US company and some control-plane functions may involve the United States.
- Sentry (error monitoring) — Frankfurt, Germany (Sentry’s EU data region), with backups in the EU. Sentry is a US company, and some account and organisation details are held in the United States so the account can be signed into and managed.
- Cloudflare Turnstile (sign-in bot protection) — Cloudflare’s global network, generally at a data centre near you; Cloudflare is a US company. See Cloudflare’s Turnstile Privacy Addendum.
- Xero (accounting and venue invoicing) — Australia, New Zealand and the United States, as stated in Xero’s privacy notice. Xero is a New Zealand company. Xero holds Partner Venue billing contacts (clause 14), not customer information.
Providers can change where they operate. We check these locations whenever we update this policy.
10. Accessing and correcting your information
You can ask to access the personal information we hold about you, or to correct it if it’s wrong, by emailing privacy@lupit.com.au. We don’t charge you for making a request. We’ll ask you to confirm your identity first — usually just by replying from the email address on your account — and we’ll respond within a reasonable time, usually within 30 days. If we can’t give you access or make a correction, we’ll explain why in writing and tell you how to complain (clause 11). If we don’t make a correction you’ve asked for, you can ask us to attach a note to the information recording that you think it’s wrong.
11. Complaints
If you think we’ve mishandled your personal information or breached the APPs, contact our privacy contact (privacy@lupit.com.au). We’ll acknowledge your complaint promptly and aim to resolve it within 30 days. If you’re not satisfied with our response, or we haven’t responded within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au, 1300 363 992.
12. Data breaches
If personal information we hold is lost, or accessed or disclosed without authorisation, and that’s likely to result in serious harm to you, we’ll act under the Notifiable Data Breaches scheme. We’ll assess any suspected breach promptly (within 30 days), take action to reduce the risk of harm, and where serious harm is still likely we’ll notify you and the OAIC with the information and recommended steps you need. Not every incident is notifiable — if we can contain it so serious harm is no longer likely, notification isn’t required, but we’ll still deal with it.
13. Changes to this policy
We may update this policy. We’ll post the new version at app.lupit.com.au/privacy with an updated effective date and version number. If a change is material — for example, collecting a new kind of personal information, using it for a new purpose, adding a new service provider, or disclosing information to a new overseas recipient — we’ll take reasonable steps to tell you before it takes effect, for example by email or a notice in the app. Where the law requires your consent to a change, we’ll ask for it.
14. If you work at a venue
This clause covers people at Partner Venues — the owners, managers and staff who use the LÜP venue dashboard or deal with us — and people at venues we’re approaching about partnering.
- What we collect — your name, work email address and phone number, your role at the venue, your dashboard sign-in details, the venue’s business details (ABN, address, website and social media handles), the venue’s billing contact details, and records of our dealings with you, including notes we keep about conversations, applications and decisions.
- Where we get it — from you when you deal with us, and, for venues we’re approaching, from public and third-party sources such as business directories, venue websites and social media.
- Why — to give you access to the venue dashboard, run the venue’s LÜP account, invoice the venue and take payment, provide support and service messages, contact venues about partnering with us, and meet our legal and record-keeping obligations.
- Who we share it with — the providers listed in clause 4 (Supabase, Resend, Vercel and Sentry, and Cloudflare Turnstile when you request a dashboard sign-in code), our accounting software (Xero) for invoicing, and Google Maps Platform, which receives your venue’s address so we can place it on the map and find it in address search.
- If you’d rather we didn’t hold your details — email privacy@lupit.com.au and we’ll remove you from our outreach records.
- The rest of this policy applies to you too — including cookies (clause 1.1), security (clause 7), how long we keep information and deletion (clause 8), overseas disclosure (clause 9), access and correction (clause 10), complaints (clause 11) and data breaches (clause 12).
15. Contact us
Privacy contact: privacy@lupit.com.au
Support: support@lupit.com.au
Entity: Langlee Trading Pty Ltd (ABN 93 687 333 811) t/as LÜP Reuse Network
Postal address: 26 Langlee Ave, Waverley NSW 2024, Australia