Privacy Policy
We run Slate to answer one question — what’s on this weekend — and we collect as little about you as possible while doing it. No accounts, no profiles, no ad tracking, no selling data. This policy explains what we do collect, why, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. What we collect and why
| Data | When | Why | Kept |
|---|---|---|---|
| Email address, chosen city, frequency preference | You subscribe to the newsletter | To send you the weekly email you asked for | Until you unsubscribe, + 30 days |
| Newsletter link tokens | You click a link in our email | To know which listings subscribers find useful (aggregate) | Tokens expire; click data 12 months |
| Contact email (optional) | You submit an event | To ask follow-up questions about the submission | 12 months |
| Hashed device identifier | You report a listing issue | To detect duplicate or abusive reports; the hash is salted and cannot be reversed to identify you | 30 days |
| Standard server logs (IP, browser, pages) | You visit the site | Security, rate limiting, and keeping the site up | 30 days |
| Approximate (city-level) location from your IP | Your first visit | To suggest your nearest city, once | Not stored |
Your saved city and dark-mode preference are stored on your device, not our servers.
We do not collect sensitive information, and we ask you not to include personal information about other people in submissions or reports.
2. What we don’t do
- No advertising or tracking cookies, and no third-party ad networks
- No selling, renting, or trading personal information — to anyone, ever
- No profiling, and no combining your data with outside sources
3. Who we share with (service providers)
We use a small number of processors to run Slate: hosting and database (Vercel, Supabase) and email delivery (Resend). They process data only to provide those services to us. Some are located overseas (primarily the United States); by using Slate you consent to that disclosure, and we take reasonable steps to ensure they handle data consistently with the APPs.
We may disclose information if required by law.
4. Security
Data is encrypted in transit, access is restricted, and we keep only what the table above says, for as long as it says. If a data breach is likely to result in serious harm, we will assess and notify affected people and the OAIC as required by the Notifiable Data Breaches scheme.
5. Your rights
- Unsubscribe — one click in any email, honoured immediately
- Access or correct your information — email hello@ontheslate.au and we’ll respond within 30 days
- Delete — ask and we’ll erase your email and related records within 30 days
6. Complaints
Contact hello@ontheslate.au first and we’ll do our best to resolve it. If you’re not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992).
7. Visitors from outside Australia
Slate currently serves Australian cities. If we launch in regions with additional privacy laws (such as the EU/UK GDPR), this policy will be updated with the rights and lawful bases that apply there before we collect anything.
8. Changes
We’ll post any changes here with a new “last updated” date. If a change meaningfully affects how your email address is used, we’ll tell you by email before it takes effect.