DRAFT — PENDING LEGAL REVIEW. This version has not yet been reviewed by Dansoria's Australian commercial lawyer. It was prepared by auditing what the platform actually does. It is not final and is not legal advice. (To publish: delete this paragraph.)
Dansoria Privacy Policy (AU)
Last updated: August 2, 2026
1. Purpose
This Privacy Policy explains how Dansoria collects, holds, uses, and discloses personal information when users access or use the platform.
It is intended to support Australian privacy expectations and should be read together with the platform Terms and Conditions.
2. Who We Collect Information About
We may collect personal information about:
- Students
- Choreographers
- Studios
- prospective users
- support contacts
- website visitors
3. What We Collect
Depending on how the platform is used, we may collect:
Identity and account data:
- full name
- email address
- phone number
- login identifiers
- role selection
- account status
Profile and listing data:
- display name
- biography
- profile image
- business or trading name
- studio details
- location and address details
- specialties, rates, availability, and listing content
Compliance and provider data:
- legal name
- entity type, meaning the business structure a provider operates under
- country of tax residency
- ABN
- foreign tax identifier
- GST registration status
- date of birth, for providers only — see section 7, Tax Reporting
- given name and family name recorded as separate fields, for providers only — see section 7
- child-related class self-declarations, including a Working With Children Check reference number where a provider lists a class as child-related
Booking and payments data:
- booking history
- payment status
- payout status
- receipts and transaction records
- Stripe account identifiers
- refund and cancellation records
Class attendance data:
- a record that a student checked in to a class they booked, or was marked present by the class host, and the time this occurred
- where a host reverses a check-in, a record that they did so
Community feed data:
- posts, comments, likes, and any image attached to a post
- the display name, role, and profile image shown alongside a post or comment
- reports made about a post or comment, including the identity of the person who made the report
Communications and support data:
- support requests
- notification records
- email delivery logs
- marketing consent status and timestamps
- where a promotional campaign is sent, a record of the recipients it was sent to
Technical and usage data:
- first-party analytics events describing how the platform is used, for example a class page being viewed, a booking button being tapped, or a signup step being completed. Each event records the event name, the page path, a random per-session identifier, and, for signed-in users, the account identifier. These events are collected for signed-in users and for visitors who are not signed in.
- server and infrastructure logs generated by our hosting, database, and authentication providers. These are created and held by those providers rather than by the Dansoria application, and can include IP addresses and device or browser information.
- local storage and session storage in your browser, used to keep you signed in and to remember interface preferences. Dansoria does not use advertising or cross-site tracking cookies.
4. How We Collect Information
We collect personal information when users:
- sign up or log in;
- complete profiles or onboarding forms;
- complete the provider business details step;
- create or update listings;
- make or receive bookings;
- check in to a class, or are checked in by a class host;
- post or comment in the community feed;
- connect payout accounts;
- contact support;
- submit forms, messages, declarations, appeals, or reports; or
- use the website and app.
We may also receive information from:
- Stripe and other payment or infrastructure providers;
- Firebase and authentication systems;
- users who submit booking, dispute, or moderation information about another user; and
- legal or regulatory requests.
5. Why We Collect, Use, and Hold Information
We use personal information to:
- create and manage user accounts;
- operate listings, bookings, payments, payouts, and receipts;
- record class attendance;
- operate the community feed and moderate reported content;
- provide support and platform communications;
- verify eligibility, provider status, or compliance information;
- meet tax reporting obligations, as described in section 7;
- investigate fraud, safety concerns, disputes, and misuse;
- improve platform features and reliability;
- maintain records, logs, and audit trails;
- comply with legal and regulatory obligations; and
- send marketing communications where permitted.
6. Payment and Payout Processing
Payments and payout onboarding are processed through Stripe.
When a provider sets up payouts, they complete Stripe's own onboarding, which is hosted by Stripe. Identity documents and bank account details entered there are provided directly to Stripe. Dansoria does not receive or store provider bank account numbers.
When a payout account is created, we provide Stripe with the provider's email address, their account type and country, and an internal reference to their Dansoria account.
We may receive information from Stripe such as:
- payment intent identifiers;
- account status fields;
- connected account identifiers;
- payout readiness status;
- charge and refund events;
- the account holder's first and last name; and
- limited billing or verification information relevant to the transaction.
We do not store full card numbers in our application database.
7. Tax Reporting (Sharing Economy Reporting Regime)
Australian law requires operators of electronic distribution platforms to report information about sellers who earn income through the platform to the Australian Taxation Office. This is the Sharing Economy Reporting Regime, under Subdivision 396-B of Schedule 1 to the Taxation Administration Act 1953.
This section applies to providers only, meaning choreographers and studios who earn income through Dansoria. It does not apply to students.
What we collect for this purpose. In addition to the compliance details listed in section 3, we collect from Australian providers:
- the business structure they operate under, for example sole trader, company, partnership, or trust;
- their legal given name and family name, recorded as separate fields; and
- their date of birth, where the reporting rules treat them as an individual seller. Stripe collects a date of birth separately for its own purposes and does not make it available to us, so we must collect it directly.
When we collect it. At the provider business details step, before a provider account is activated to accept bookings or publish classes.
Who can see it. Access to these records is restricted to Dansoria platform administrators. The record is stored separately from the provider's profile, and a provider cannot read the stored date of birth back through the platform. The platform will confirm that a date of birth is held, but will not display it. Students and other providers cannot access it.
Who we disclose it to. We disclose this information, together with the income, fee, and transaction totals for each reporting period, to:
- the Australian Taxation Office; and
- Dansoria's registered tax agent, where they prepare or lodge the report on our behalf.
How long we keep it. Australian taxation law requires reporters to keep this information for 5 years, and to be able to reproduce a lodged report on request. We therefore retain these records, and the reports we lodge, for at least 5 years from the date of lodgment, including where an account is otherwise closed or deleted.
Access and correction. A provider can ask us what we hold for this purpose, and can correct it, either by updating their business details in their dashboard or by contacting us at hilton@dansoria.au. Section 15 sets out how access and correction requests are handled.
8. Information That Is Published Publicly
Some information is published on the public parts of the platform and can be viewed by anyone, including people who are not signed in, and may be indexed by search engines.
This includes:
- choreographer and studio public profiles, including display name, biography, specialties, rates, and profile or banner images;
- studio location details, including the street address published on a studio's profile, so that people can find the venue;
- class listings, including title, description, date and time, price, and images;
- choreography listings offered for licensing; and
- community feed posts and comments, including the poster's display name, role, profile image, and any attached image. Students appear under a plain name that does not link to a profile page. Choreographers and studios appear under a name that links to their public profile.
Images and files uploaded to the platform, including profile pictures, studio banners, class images, and community post images, are stored with our hosting provider and are publicly accessible to anyone who has the file's link, whether or not they are signed in.
Please do not post anything to a public area of the platform that you do not want to be public.
9. Disclosure of Personal Information
We may disclose personal information to:
- other users where needed to complete a booking or provide a service. For example, a provider sees the name and booking details of a person who books with them, and a class host sees the names of students booked into their class;
- service providers and infrastructure vendors;
- payment processors such as Stripe;
- cloud hosting, storage, communications, and support providers;
- the Australian Taxation Office and our tax agent, as described in section 7;
- professional advisers;
- regulators, law enforcement, courts, or government agencies where required or authorised; and
- a purchaser or successor in connection with a sale, merger, restructure, or transfer of the business.
We do not sell personal information as a standalone data product.
10. Third Parties We Use
The third parties that currently receive or process personal information for Dansoria are:
- Google Firebase and Google Cloud, used to run the platform, including hosting, authentication, the database, file storage, and server functions. They hold account, profile, booking, payment, messaging, and uploaded file data.
- Stripe, used for payments, refunds, and provider payouts. Stripe receives payer and provider details relevant to a transaction, and receives provider identity and bank details directly through its own onboarding.
- Google Maps Platform, used to convert a studio's address into its correct timezone so that class and booking times are displayed correctly. It receives the studio's address. We use the result only to determine the timezone, and we do not store the coordinates it returns.
- Resend, used to send transactional and promotional email. It receives the recipient's email address and the content of the message.
- Vercel, used to host and deliver the website. Its infrastructure handles web request data, including IP addresses.
We also send operational alerts about payment and payout problems to a Dansoria administrator's email address. These alerts can contain booking and payment details.
11. Overseas Disclosure
Some service providers used by Dansoria store or process information outside Australia. These currently include:
- Google Firebase and Google Cloud services, which may process data in the United States and other regions;
- Google Maps Platform, which may process address lookups outside Australia;
- Stripe, which may process data in the United States;
- Resend, our email delivery provider, which may process data in the United States; and
- Vercel, our website hosting provider, which operates a global network.
By using the platform, you acknowledge that personal information may be processed in these locations.
12. Marketing and Transactional Communications
Dansoria sends transactional emails and notices necessary to operate the platform, including:
- welcome emails;
- booking notices;
- payment receipts;
- cancellation notices;
- payout-related alerts; and
- security or account notices.
Promotional emails are sent only to users who chose to receive them when signing up. Every promotional email includes a one-click unsubscribe link that does not require signing in.
Unsubscribing from promotional email does not stop the operational messages listed above, which are necessary to run the platform.
13. Security
Dansoria takes reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
These steps include:
- database access rules that restrict each record to the users entitled to see it, with tax reporting records described in section 7 restricted to platform administrators;
- server-side controls over financial and identity records, so that they cannot be created or altered directly from a user's browser;
- authentication safeguards provided by Firebase Authentication;
- audit records for administrator actions in areas including licensing and community moderation; and
- encryption and infrastructure protections managed by the providers listed in section 10.
No platform can guarantee absolute security.
14. Retention
We keep information for as long as reasonably necessary to:
- operate the platform;
- maintain booking, payment, payout, and audit records;
- resolve disputes;
- enforce terms;
- respond to legal claims; and
- comply with legal, tax, accounting, and regulatory obligations.
One period is fixed by law: tax reporting records described in section 7 are kept for at least 5 years from the date the relevant report is lodged with the Australian Taxation Office, including after an account is closed.
Other categories do not currently have a fixed deletion schedule. Records are retained while they remain necessary for the purposes listed above, and we do not currently operate automated deletion of historical booking, payment, or account records.
If you ask us to delete your information, we will do so unless we are required or entitled to keep it, for example records covered by the tax reporting obligation above, or records needed for an unresolved dispute.
15. Access and Correction
Users may request access to, or correction of, personal information held by Dansoria, subject to lawful exceptions.
Much of this information can be viewed and corrected directly in the platform, through profile, listing, and business details settings.
Privacy requests can be sent to hilton@dansoria.au.
16. Complaints
Users may contact Dansoria with privacy complaints at hilton@dansoria.au.
We will acknowledge a privacy complaint and respond within a reasonable time.
If a user is dissatisfied with our response, they may complain to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992.
17. Children
Dansoria is not intended for unsupervised use by children where that would be unlawful or inappropriate.
Providers who list a class as child-related are asked to confirm their Working With Children Check status and to provide a reference number. Dansoria records this declaration but does not independently verify it with the issuing authority.
18. Changes to This Policy
Dansoria may update this Privacy Policy from time to time.
The current version is always published at /legal/privacy with the date it was last updated. Where a change materially affects how we handle personal information, we will take reasonable steps to notify affected users, which may include emailing them or showing a notice in the platform.
19. Contact
- Business name: Dansoria
- Privacy and support contact: hilton@dansoria.au
- Phone: 0484 554 927
- Address: 1 Nalya Ave, Patonga NSW 2256, Australia