Legal

Privacy Policy

Last updated: 31 March 2026

1. Who we are

Sherwood ("we", "us", "our") is based in Victoria, Australia. This policy explains how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. Information we collect

We may collect the following categories of personal information:

  • Account information: email address, name, and password when you create an account or subscribe.
  • Google account data: if you sign in with Google, we receive your name, email address, and profile picture from Google. We do not access your Google password, contacts, or any other Google account data.
  • Quiz responses: answers you provide in the account-health quiz, used to generate your personalised assessment.
  • Usage data: pages visited, features used, calculator inputs, and interaction patterns collected via analytics tools.
  • Payment information: billing details processed by our third-party payment provider. We do not store full card numbers.
  • Communications: emails or messages you send to us.

3. How we use your information

We use personal information to:

  • Provide, operate, and improve Sherwood's features and services.
  • Process subscriptions and payments.
  • Send account-related communications (e.g. receipts, service updates).
  • Send marketing communications where you have opted in. You can unsubscribe at any time via the link in each email.
  • Generate aggregated, anonymised insights to improve the platform.
  • Comply with legal obligations.

4. Legal basis for processing

We process personal information on the following grounds:

  • Consent: where you have given clear consent (e.g. subscribing to marketing emails).
  • Contract: where processing is necessary to fulfil your subscription or provide the service.
  • Legal obligation: where we are required to process data under Australian law.

5. Disclosure to third parties

We do not sell your personal information. We may share information with:

  • Service providers: hosting, analytics, email delivery, and payment processing providers who act on our behalf under contractual obligations. These include Google (authentication) and Stripe (payment processing — Stripe may collect and process payment information under their own privacy policy).
  • Legal requirements: where disclosure is required by law, regulation, or court order.

Some service providers may be located outside Australia. Where this occurs, we take reasonable steps to ensure they comply with the APPs or equivalent standards.

6. Cookies and analytics

Sherwood uses cookies and similar technologies to remember preferences, analyse usage, and improve the service. We also use authentication cookies and tokens to maintain your signed-in session. You can manage cookie preferences through your browser settings. Disabling cookies may affect functionality.

7. Data retention

We retain personal information for as long as your account is active or as needed to provide services. If you delete your account, we will remove your personal information within 30 days, except where retention is required by law.

8. Data security

We implement reasonable technical and organisational measures to protect your personal information from unauthorised access, loss, or misuse. However, no method of electronic transmission or storage is completely secure.

9. Your rights

Under the Privacy Act 1988 and the APPs, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or outdated information.
  • Request deletion of your personal information (subject to legal obligations).
  • Opt out of marketing communications at any time.
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached.

10. Children

Sherwood is not intended for anyone under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a user is under 18, we will promptly delete their account and associated data.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. The "last updated" date at the top reflects the most recent revision.

12. Contact

For privacy-related enquiries, to exercise your rights, or to lodge a complaint, contact us at privacy@sherwood.bet.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.