Privacy Policy
1. Who we are
Back2Back Australia ("Back2Back", "the app", "we", "us", "our") is a free mobile application that helps backpackers and working holiday travellers find sharehouses and rooms, rent or share cars, match for road trips, message each other directly, and access practical guides (such as the 88-day regional work requirement, tax, and ABN information).
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, who we share it with, and the rights you have over it. It applies to everyone who uses the app, wherever you are in the world.
We operate the app from Australia and comply with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). Because our users come from many countries — including Europe, the United Kingdom, South America, India, and Nepal — we have also built this policy around the standards of the EU General Data Protection Regulation (GDPR) and the UK GDPR. Where those laws give you stronger rights than your local law, we extend those rights to you regardless of where you live.
Contact: support@back2backaustralia.com
2. The information we collect
We follow a simple rule, also required by law in Australia and Europe: we only collect what we actually need to run the service. We do not collect personal information we have no use for.
Information you give us directly
- Account details — your email address, a password (stored only in encrypted/hashed form, never in plain text), and a username. We deliberately use a username rather than your full legal name to reduce the personal information attached to your public profile.
- Profile information — anything you choose to add, such as a profile photo, nationality, or a short bio. This is optional.
- Listings you post — the content of any room, car, or road trip listing you create, including text, photos, locations, dates, and prices.
- Messages — the content of messages you send to other users through the app.
- Reports and blocks — if you report a listing or user, or block someone, we record that action so we can act on it and keep the community safe.
Information we collect automatically
- Device and technical data — device type, operating system version, app version, and basic diagnostic data, used to keep the app stable and fix crashes.
- Usage data — how you interact with the app (for example, which screens you open), used to improve the service.
- Advertising identifiers — where ads are shown, our advertising provider (Google AdMob) may access a device advertising identifier and related data (see Section 7).
- Push notification token — if you enable push notifications, we store the token your device needs to receive them. Push notifications may be temporarily unavailable depending on the app version; when they are off, no token is collected.
What we do NOT collect
We do not run payments inside the app. We do not take a deposit, hold money, or process card details — when you arrange a room, a car, or a trip, you deal with the other person directly and outside the app. We do not ask for your passport, visa number, or government ID. We do not knowingly collect information from anyone under the age required to use the app (see Section 11).
3. How we use your information
We use your information only for clear, stated purposes:
- To create and manage your account and let you sign in.
- To display your listings and profile to other users so the service works.
- To deliver messages between users.
- To operate our anti-scam and safety systems — automatically blocking phone numbers, emails, and links inside listing text, and requiring at least one genuine photo per listing.
- To respond to reports, enforce our rules, and remove harmful content.
- To send you essential service emails (such as email verification, password reset, and important changes to the service or this policy).
- To keep the app secure, stable, and free of fraud and abuse.
- To show advertising that keeps the app free (see Section 7).
- To comply with our legal obligations.
Our legal bases (for users in Europe, the UK, and similar regimes)
Where the GDPR or UK GDPR applies to you, we rely on these legal bases:
- Performance of a contract — to provide the core service you signed up for (account, listings, messaging).
- Consent — for optional things like marketing emails, push notifications, and personalised ads. You can withdraw consent at any time.
- Legitimate interests — to keep the service safe, prevent fraud and scams, and improve the app, balanced against your rights.
- Legal obligation — where we must process data to comply with the law.
We do not use your personal information to make solely automated decisions that produce legal or similarly significant effects about you. Our anti-scam filters screen listing content, not people, and a human reviews reports and account actions.
4. Direct marketing and the right to unsubscribe
We mostly send only essential service emails. If we ever send promotional or marketing messages, we will clearly identify ourselves as the sender and include a working, easy unsubscribe link or instruction in every message. This meets the requirements of the Australian Spam Act 2003 and equivalent rules in Europe and the UK. You can opt out of marketing at any time without affecting your ability to use the app. Essential service messages (such as a password reset you requested) are not marketing and cannot be unsubscribed from while you hold an account.
5. Where your data is stored and international transfers
This is important, and we want to be transparent about it.
Our backend and database are hosted by Supabase, running on Amazon Web Services infrastructure in the ap-northeast-1 region (Tokyo, Japan). This means that wherever you are — Australia, Europe, the UK, South America, India, or Nepal — your personal information is stored on servers located in Japan, and supporting providers we use may process limited data in other countries (see Section 7).
We remain fully responsible for your information even when it is handled by these providers overseas.
- For Australian users: under Australian Privacy Principle 8, we take reasonable steps to ensure overseas recipients handle your information consistently with the APPs, through our contracts with these providers and their own security and compliance commitments.
- For users in Europe and the UK: transfers of your data outside the EEA/UK are protected by appropriate safeguards, such as the European Commission's Standard Contractual Clauses incorporated into our providers' data processing terms, together with the technical and organisational measures described in Section 8.
If you would like more detail about a specific transfer or safeguard, email us.
6. Who can see your information
Other users: your username, profile photo, bio, and the content of any listing you post are visible to other people using the app — that is the point of the service. Your email address and password are never shown to other users.
No selling of data: we do not sell your personal information to anyone, and we never will.
We only share your information with the service providers in Section 7, and only as far as needed for them to do their job, and where we are legally required to.
7. Service providers and third parties
We use a small number of trusted providers to run the app. Each only receives the data it needs:
- Supabase (database, authentication, storage) — stores your account, listings, messages, and related data, on AWS in Tokyo, Japan.
- Expo / Expo Application Services (app build and delivery, push notification token handling) — may process device and push-token data.
- Google AdMob (advertising) — where ads are shown, AdMob's SDK may collect a device advertising identifier, IP-derived approximate location, and ad-interaction data to serve and measure ads. You can limit ad tracking through your device settings. Google's own handling of this data is governed by Google's privacy policy.
- Sentry (error and crash monitoring, hosted in the EU region) — receives technical diagnostic data to help us find and fix bugs. We configure it to avoid collecting unnecessary personal information.
We may add or change providers as the app evolves. If we make a change that materially affects how your information is handled, we will update this policy and, where required, notify you.
8. How we keep your information secure
- Passwords are stored hashed, never in plain text.
- Connections to our servers are encrypted in transit (HTTPS/TLS).
- Database access is controlled by row-level security rules so users can only reach data they are entitled to.
- Anti-scam filters block contact details and external links inside listing text.
- We restrict internal access to personal information to what is necessary to operate and support the service.
No system is ever perfectly secure. While we work hard to protect your information, we cannot guarantee absolute security — keep your password private and be cautious about what you share with other users.
9. Data breaches
If a data breach occurs that is likely to result in serious harm (Australia) or a risk to your rights and freedoms (Europe/UK), we will act quickly to contain it and notify the people affected and the relevant regulator as required by law — in Australia under the Notifiable Data Breaches (NDB) scheme, and in Europe/UK in line with GDPR/UK GDPR breach-notification rules (generally within 72 hours).
10. How long we keep your information
- Account, profile, and listings — for as long as your account is active.
- After you delete your account — we delete or anonymise your personal information within a reasonable period, except for limited data we must keep to meet legal obligations, resolve disputes, or enforce our terms.
- Messages — retained so conversations remain available to both participants; deleting your account removes your personal data from them as above.
You can delete your account at any time from within the app or by emailing us.
11. Children and young people
The app is intended for adults (and, where local law sets a higher minimum age, that higher age applies). We ask users to confirm they meet the minimum age at sign-up. We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe someone underage has created an account, contact us and we will remove it.
12. Your privacy rights
Depending on where you live, your rights include:
- Access — ask for a copy of the personal information we hold about you.
- Correction — ask us to fix information that is wrong or out of date.
- Deletion / erasure — ask us to delete your account and personal information.
- Objection and restriction — ask us to stop or limit certain processing.
- Withdraw consent — for anything based on consent (marketing, push notifications, personalised ads).
- Data portability (Europe/UK) — ask for your data in a portable format.
- Complain — to us first, then to your privacy regulator.
To exercise any of these, email support@back2backaustralia.com. We will not charge you or treat you unfairly for making a request.
How to complain
- Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
- Europe: your national Data Protection Authority
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- Other countries: your local data protection or privacy authority
13. Changes to this policy
We may update this Privacy Policy as the app grows or the law changes. When we do, we will update the "Last updated" date above, and for significant changes we will give you notice within the app or by email.
Back2Back Australia is an independent app built by a backpacker, for backpackers. We collect as little as possible, we don't sell your data, and we try to be straight with you about everything we do with it.