Legal
Privacy Policy
Last updated: 20 July 2026
Members Request Desk is operated by NEMO Australia Pty Ltd (ABN 60 631 429 055), 39 River Oak Circuit, Kellyville NSW 2155, Australia (“we”, “us”). We automate membership freezes for fitness studios that use Mindbody. This policy explains how we handle personal information, in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and — where it applies — the EU/UK GDPR.
Our two roles
For member freeze data, the studio is the data controller and we act as its processor — we process member information on the studio's instructions to carry out the freeze. Please also read your studio's own privacy policy. For studio staff accounts and website visitors, we are the controller.
What we collect
We deliberately keep our data footprint minimal. From a member submitting a freeze request:
- Name, email, phone and (optionally) date of birth — used only to match the member to their Mindbody record.
- The Mindbody client and contract IDs we match to.
- Freeze details: requested start, duration, and a reason category only (non-medical / medical / staff).
- A record that consent was given (timestamp + policy version), and technical data (IP, device) for security.
We do not collect health or medical information (medical freezes are directed to your studio directly) and we neverhandle payment card details (any freeze fee is processed by the studio's own Mindbody merchant account).
Why we use it
- To verify a member's identity and carry out the freeze they requested.
- To send transactional notifications (verification codes, confirmations) by email/SMS.
- To keep an audit log for reliability, dispute resolution and security.
- We currently use no analytics or marketing cookies; if we ever introduce them, they will be consent-based (see our Cookie Policy).
Who we share it with
We use trusted providers to run the service and do not sell personal information:
- Supabase — database & authentication (Sydney, Australia)
- Vercel — website & application hosting
- Twilio — SMS delivery; Resend — email; Stripe — studio billing
- Mindbody — the studio's own system we integrate with
This list matches the subprocessors published in our Trust Center; we will update both before adding a new provider.
Cross-border disclosure
Our primary database is hosted in Australia (Sydney). Some providers are overseas (mainly the United States); where information is disclosed overseas we take reasonable steps to ensure it is handled consistently with the APPs, and rely on appropriate safeguards (such as Standard Contractual Clauses) for GDPR transfers.
Storage & security
Studio Mindbody credentials are AES-256-GCM encrypted at rest and only decryptable server-side. Data is isolated per studio with row-level security. Secrets are never committed to source control or written to logs, and access is limited to authorised personnel. No system is perfectly secure, but we take reasonable steps to protect personal information.
Retention
We keep personal information only as long as it is needed, and enforce that automatically rather than by promise alone:
- Verification codes are stored only as one-way hashes and expire within minutes of being issued.
- Closed freeze requests past their retention window are automatically de-identified by a scheduled retention job — the personal fields are removed while non-identifying operational records are kept for audit integrity.
- On account closure, studios can request export or deletion of their data, which we honour subject to any legal retention obligations.
Data breach notification
If a data breach occurs that is likely to result in serious harm, we will notify affected studios and the Office of the Australian Information Commissioner in accordance with Australia's Notifiable Data Breaches scheme, and — where the GDPR applies — the relevant supervisory authority and affected individuals without undue delay. As a processor, we will notify the affected studio (the controller) promptly so it can meet its own obligations.
Children
The Service is intended for studio staff and adult members. We do not knowingly collect information from children; memberships for minors are managed by the studio and the member's parent or guardian under the studio's own terms.
Your rights
You may access the personal information we hold and ask us to correct it (APPs 12–13). Under the GDPR you may also request erasure, restriction or portability, or object to processing and withdraw consent. Because we act as a processor for member freeze data, such requests may be directed to your studio; we will assist. For data we control, contact us below.
Complaints
In Australia, if you are unhappy with how we have handled your information, contact us first; you may then complain to the Office of the Australian Information Commissioner (oaic.gov.au). In the EU/UK you may lodge a complaint with your local supervisory authority.
Contact
NEMO Australia Pty Ltd — privacy@membersrequestdesk.com — 39 River Oak Circuit, Kellyville NSW 2155, Australia.