Legal
Privacy Policy
Last updated: 31 March 2026
1. Who we are
Sherwood ("we", "us", "our") is based in Victoria, Australia. This policy explains how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. Information we collect
We may collect the following categories of personal information:
- Account information: email address, name, and password when you create an account or subscribe.
- Google account data: if you sign in with Google, we receive your name, email address, and profile picture from Google. We do not access your Google password, contacts, or any other Google account data.
- Quiz responses: answers you provide in the account-health quiz, used to generate your personalised assessment.
- Usage data: pages visited, features used, calculator inputs, and interaction patterns collected via analytics tools.
- Payment information: billing details processed by our third-party payment provider. We do not store full card numbers.
- Communications: emails or messages you send to us.
3. How we use your information
We use personal information to:
- Provide, operate, and improve Sherwood's features and services.
- Process subscriptions and payments.
- Send account-related communications (e.g. receipts, service updates).
- Send marketing communications where you have opted in. You can unsubscribe at any time via the link in each email.
- Generate aggregated, anonymised insights to improve the platform.
- Comply with legal obligations.
4. Legal basis for processing
We process personal information on the following grounds:
- Consent: where you have given clear consent (e.g. subscribing to marketing emails).
- Contract: where processing is necessary to fulfil your subscription or provide the service.
- Legal obligation: where we are required to process data under Australian law.
5. Disclosure to third parties
We do not sell your personal information. We may share information with:
- Service providers: hosting, analytics, email delivery, and payment processing providers who act on our behalf under contractual obligations. These include Google (authentication) and Stripe (payment processing — Stripe may collect and process payment information under their own privacy policy).
- Legal requirements: where disclosure is required by law, regulation, or court order.
Some service providers may be located outside Australia. Where this occurs, we take reasonable steps to ensure they comply with the APPs or equivalent standards.
6. Cookies and analytics
Sherwood uses cookies and similar technologies to remember preferences, analyse usage, and improve the service. We also use authentication cookies and tokens to maintain your signed-in session. You can manage cookie preferences through your browser settings. Disabling cookies may affect functionality.
7. Data retention
We retain personal information for as long as your account is active or as needed to provide services. If you delete your account, we will remove your personal information within 30 days, except where retention is required by law.
8. Data security
We implement reasonable technical and organisational measures to protect your personal information from unauthorised access, loss, or misuse. However, no method of electronic transmission or storage is completely secure.
9. Your rights
Under the Privacy Act 1988 and the APPs, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or outdated information.
- Request deletion of your personal information (subject to legal obligations).
- Opt out of marketing communications at any time.
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached.
10. Children
Sherwood is not intended for anyone under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a user is under 18, we will promptly delete their account and associated data.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. The "last updated" date at the top reflects the most recent revision.
12. Contact
For privacy-related enquiries, to exercise your rights, or to lodge a complaint, contact us at privacy@sherwood.bet.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.