Privacy Policy — SkillStake

Last updated: 2026-04-15

Who We Are

SkillStake is operated by SeaQae Group (40 300 987 116), a sole trader based in Perth, Western Australia. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use SkillStake at https://skillstake.com.

Information We Collect

**Account Information:** Name, Email address, Password (hashed) - Purpose: Account creation and authentication - Retention: Until account deletion **Payment Information:** Stripe customer ID, Subscription status, Transaction history - Purpose: Payment processing and billing - Retention: 7 years (tax compliance) **Challenge Data:** Challenge type, Pricing configuration, Participant counts, Results and outcomes, Location metadata - Purpose: Service delivery and analytics - Retention: Until account deletion **Participant Data:** Participant name, Email (if provided), Payment confirmation, Waiver signatures, Challenge results - Purpose: Challenge participation and legal compliance - Retention: 3 years after challenge date **Usage Data:** Pages visited, Features used, Device and browser information, IP address - Purpose: Service improvement and security - Retention: 12 months

Information You Provide

When you create an account, make a purchase, or contact us, you may provide your name, email address, and payment information. Payment details are processed directly by Stripe and never stored on our servers.

Information Collected Automatically

When you visit our site, we automatically collect certain information including your IP address (anonymised), browser type, device information, pages visited, and referring URL. This is collected through our analytics provider (PostHog) and hosting platform (Vercel).

Cookies and Tracking

We use essential cookies for authentication and session management. We use analytics cookies (PostHog) to understand how our service is used. You can disable non-essential cookies through your browser settings. We do not use third-party advertising cookies.

How We Use Your Information

We use your personal information to: - Provide and maintain the SkillStake service - Process payments and manage your subscription - Send transactional emails (account confirmation, password resets, receipts) - Send product updates and marketing communications (only with your consent, and you can unsubscribe at any time) - Analyse usage patterns to improve our service (anonymised data) - Respond to your enquiries and support requests - Comply with legal obligations

Third-Party Service Providers

We share your information with the following third-party service providers who assist us in operating SkillStake: **Stripe** — Payment processing - Data shared: Name, email, payment details (card processed by Stripe, never stored by us) - Location: United States (with AU data processing) - Privacy policy: https://stripe.com/au/privacy **Vercel** — Website hosting and edge delivery - Data shared: IP address, page views, device info (anonymised analytics) - Location: Global edge network - Privacy policy: https://vercel.com/legal/privacy-policy **Railway** — Backend infrastructure and database hosting - Data shared: Application data stored in PostgreSQL (encrypted at rest) - Location: United States - Privacy policy: https://railway.app/legal/privacy **Resend** — Transactional and marketing email delivery - Data shared: Email address, name, email interaction data - Location: United States - Privacy policy: https://resend.com/legal/privacy-policy **PostHog** — Product analytics and feature flags - Data shared: Anonymised usage events, device info, session replays (if enabled) - Location: EU (PostHog Cloud EU) - Privacy policy: https://posthog.com/privacy **Sentry** — Error monitoring and performance tracking - Data shared: Error stack traces, device info, IP address (anonymised) - Location: United States - Privacy policy: https://sentry.io/privacy/ **Stripe** — Payment processing - Data shared: Payment method details, transaction amounts - Location: United States - Privacy policy: https://stripe.com/privacy **Neon (PostgreSQL)** — Database hosting - Data shared: All application data (encrypted at rest) - Location: United States - Privacy policy: https://neon.tech/privacy **Vercel** — Application hosting and CDN - Data shared: Request logs, IP addresses - Location: United States - Privacy policy: https://vercel.com/legal/privacy-policy **Resend** — Transactional email delivery - Data shared: Email addresses, email content - Location: United States - Privacy policy: https://resend.com/legal/privacy-policy We only share the minimum information necessary for each provider to perform their function. We do not sell your personal information to any third party.

Data Security

We implement appropriate technical and organisational measures to protect your personal information, including: - All data transmitted over HTTPS (TLS 1.3) - Passwords hashed using Argon2id - Database encrypted at rest - Regular security reviews - Access controls and audit logging No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Your Rights

You have the right to: - **Access** your personal information we hold - **Correct** inaccurate information - **Delete** your account and associated data - **Export** your data in a portable format - **Withdraw consent** for marketing communications at any time - **Lodge a complaint** with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy

Additional Rights for EU/UK Users (GDPR)

If you are located in the European Union or United Kingdom, you also have the right to: restrict processing, object to processing, and data portability. Our lawful basis for processing is consent (for marketing) and legitimate interest (for service provision and analytics). To exercise these rights, contact us at the email below.

Additional Rights for California Users (CCPA)

If you are a California resident, you have the right to: know what personal information we collect, request deletion, and opt out of the "sale" of personal information. We do not sell your personal information. To exercise these rights, contact us at the email below.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with our service. After account deletion, we retain anonymised analytics data and may retain certain records as required by law (e.g., financial records for 7 years per ATO requirements). You can request deletion of your account and associated personal data at any time by contacting support@skillstake.com.

Children's Privacy

SkillStake is intended for users aged 18 and over. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on https://skillstake.com. Your continued use of SkillStake after changes are posted constitutes your acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, contact us: - Email: support@skillstake.com - Business: SeaQae Group (ABN 40 300 987 116) - Location: Perth, Western Australia