Legal
Privacy Policy
How Blue Planet Expedition collects, uses, discloses, stores and protects personal information.
1. Who we are and scope
Blue Planet Expedition is the trading name of Blue Planet Expedition Pty Ltd (ABN 50 659 577 876), of 2 Verco Ct, Campbelltown SA 5074, Australia. In this policy, “we”, “us” and “our” refer to Blue Planet Expedition Pty Ltd.
This policy applies when you use our website, create an account, make or manage a booking request, buy from our shop, apply to become a merchant, contact us, or participate in the Marine Logbook. We are committed to handling personal information in line with the principles of the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Information we collect
Depending on how you use our services, we may collect:
- account and identity information, including first and last name, email, phone number, date of birth, gender, nationality, account credentials and account identifiers;
- dive profile information, including certification level and documents, logged-dive count and most recent dive date;
- booking and traveller information, including packages and add-ons, contact details, passport number and documents, insurance documents, emergency contacts, traveller details, booking status, cancellation information and communications;
- health information that you submit where a traveller has a serious medical history or had surgery within the previous 12 months, including supporting medical documents;
- payment and transaction information, although complete payment-card details are handled by Stripe and are not stored by Blue Planet Expedition;
- merchant information, including business name, applicant contact details and phone number, qualification notes, application status, reviewer records and business relationship records;
- shop order, delivery or pickup information;
- contact, quote, support, complaint, refund and dispute communications;
- Marine Logbook activity, including comments, replies, submitted images, candidate-image title and location, likes, unlocks, moderation records and the account connected to that activity; and
- technical information needed to operate and secure the service, such as IP address, device and browser information, session cookies, timestamps and security logs.
3. Sources of information
We receive information directly from you, from a person authorised to book for another traveller, from a selected merchant or operator, and from service providers that return authentication, email-delivery, payment, refund, fraud-prevention or transaction status information.
If you provide another traveller's information, you must have their authority and give them access to this Privacy Policy before submitting their passport, insurance, certification, emergency-contact or health information. We do not buy personal information from data brokers, and we do not sell or rent personal information.
4. How we use information
We use personal information to create and protect accounts; maintain dive profiles; process booking requests; assess certification and dive-safety suitability; obtain operator decisions; provide confirmed travel services; process payments and refunds; send transactional communications; manage merchant applications; fulfil shop orders; moderate Marine Logbook content; provide support; prevent fraud and misuse; keep business and security records; resolve disputes; and comply with legal obligations.
5. Health and sensitive information
Our website does not routinely request health information. A traveller with a serious medical history or who had surgery within the previous 12 months must disclose that fact and may upload relevant supporting documents with the booking request.
We collect health information with the required declaration in booking Step 4, or where otherwise permitted by law. We use it only for dive-safety and booking assessment, do not use it for marketing, and disclose it only to authorised personnel of the selected operator who need it for that assessment.
For an unsuccessful booking, we delete health documents 30 days after the booking is rejected, withdrawn or otherwise ends. For a successful booking, we delete them 30 days after the trip is completed. If an accident, refund, complaint or legal dispute occurs, relevant information may be kept only as long as needed to resolve the matter and complete the applicable limitation period.
6. Disclosure to selected operators
Before an operator approves a booking request, we disclose only the traveller's name, certification level, logged-dive count, most recent dive date and certification document needed to assess the request.
After approval, the operator may receive additional information reasonably needed to provide the trip, including phone number, date of birth, emergency contacts, passport details and documents, and insurance documents. Health documents remain restricted to authorised safety-review personnel.
7. Service providers and overseas processing
We use the following providers to operate the service:
- Supabase provides authentication, database and private file storage. Our primary database and storage region is Sydney, Australia. Limited support, security or subprocessor activity may occur in the United States, Singapore or other locations identified by Supabase. See Supabase privacy information and Supabase subprocessors.
- Stripe processes payments and refunds. Data may be processed in Australia, the United States, India, and countries where payment methods, banks, card networks, financial partners or Stripe providers operate. See the Stripe Privacy Policy.
- Resend sends account, booking, payment, refund and support email. Email addresses, message content, delivery logs and account metadata are stored or processed in the United States. See the Resend Privacy Policy and Resend subprocessors.
- Website hosting provider hosts and delivers the website and related operational data.
Provider locations and subprocessors may change. Their linked policies and subprocessor lists contain current information about their handling practices.
8. Cookies and local storage
We currently use only cookies or browser storage needed for authentication, security, language preferences, booking drafts and cart operation. Disabling essential storage may prevent account, cart or booking functions from working.
We do not currently use advertising cookies, cross-site tracking, Google Analytics, Meta Pixel, PostHog, Sentry, Mailchimp or other analytics or marketing trackers. We therefore do not currently show a marketing-cookie consent banner. We will update this policy and introduce an appropriate consent mechanism before adding analytics or advertising tools that require one.
9. Communications
Resend is used for transactional account, booking, payment, refund and support messages. Acceptance of this Privacy Policy does not include marketing consent. If we introduce promotional email in future, we will request a separate opt-in and provide a working unsubscribe method.
10. Marine Logbook
The public Marine Logbook may display an account name, comments, replies, submitted images, candidate-image title and location, and public like counts. It does not publicly identify the users behind likes. Administrators may view a contributor's email address for moderation.
Community content remains public until you delete it, an administrator removes it under the community rules, you request removal through our privacy email, or your account is deleted or anonymised.
11. Security and data breaches
We use reasonable safeguards including account and role-based access restrictions, non-public storage for certification, passport, insurance and health documents, need-to-know access, controlled server credentials, secure transmission, periodic access review, and deletion or anonymisation when information is no longer required. No internet or storage system can be guaranteed completely secure.
If we suspect a data breach, we investigate and contain the risk, assess the likelihood of serious harm, notify affected individuals and the OAIC where legally required, record the response and improve safeguards.
12. Retention
| Information | Retention period |
|---|---|
| Active account information | For the life of the account. |
| Closed-account information | Deleted or anonymised within 1 year after account closure. |
| Security backups after account closure | Up to 2 years. |
| Unsuccessful booking records and related documents | 30 days after rejection, withdrawal, or other conclusion. |
| Completed or paid booking records | 5 years. |
| Certification stored in a profile | Until you delete or replace it, or close your account, subject to the closed-account period above. |
| Security and login logs | 12 months. |
| Rejected or withdrawn merchant applications | 6 months after the decision. |
| Approved merchant and member information | For the business relationship and 5 years after it ends. |
| Shop orders and payment or refund records | 5 years. |
| Contact, quote and support communications | 2 years after the matter ends. |
| Marine Logbook content | Until deletion, moderation removal, a privacy removal request, or account deletion or anonymisation. |
| Health documents | The shorter periods described in Health and sensitive information below. |
Information connected with an accident, refund, complaint, fraud review or legal dispute may be kept until the matter is resolved and the applicable limitation period ends. A legal recordkeeping duty overrides a shorter period only to the extent required.
13. Access, correction and complaints
You may request access to, correction of, or deletion of your personal information, or make a privacy complaint, by emailing info@blueplanetexpedition.com.au. We may verify your identity before disclosing or changing information. We normally respond within 30 days. If we need more time, we will explain why and provide a new expected response date.
If you are dissatisfied with our response, you may complain to the Office of the Australian Information Commissioner.
14. Minors
A person under 18 cannot independently create an account or submit a booking request. A parent or legal guardian must make the booking and provide the necessary authority. Our service is not directed to children under 16, and we do not intentionally collect their information directly.
15. Automated decisions
Booking and certification decisions are made by authorised operator personnel. Blue Planet Expedition does not use AI, automated scoring or solely automated processing to make decisions that significantly affect a user. Stripe may conduct its own payment fraud prevention under its privacy policy.
16. Changes and contact
We may update this policy as our services or practices change. We will publish the revised policy with a new last-updated date and may also communicate material changes through the website or email.
Blue Planet Expedition Pty LtdTrading as Blue Planet Expedition
ABN 50 659 577 876
2 Verco Ct, Campbelltown SA 5074, Australia
info@blueplanetexpedition.com.au
