Harrison Riedel Foundation Limited Privacy Policy

Harrison Riedel Foundation Privacy Policy
Revised May 2025

The Harrison Riedel Foundation Limited (HRF) is committed to protecting your privacy and the confidentiality of any personal information you provide to us. This Privacy Policy outlines HRF’s practices regarding the collection, use, storage, and disclosure of personal information in connection with our services (Services).

By accessing HRF’s Services, website, and applications—including the YourCrew mobile and web apps—or providing information to HRF, you agree to this Privacy Policy, which may be updated periodically.

1. Collection of Personal Information

HRF may collect personal information to provide services, process donations, or facilitate your participation in our programs and events. The extent and nature of the information collected depend on your interactions with HRF and may include:

Reasons for Collection:

  • To receive information or participate in HRF initiatives
  • To join HRF promotions or campaigns
  • To receive updates about fundraising outcomes
  • To purchase HRF/YourCrew merchandise
  • To make or process a donation (anonymity may limit our ability to send receipts or provide support)
  • To share your story or motivation with HRF
  • To attend HRF events
  • To register for the YourCrew mobile application

Types of Personal Information Collected:

  • Name, photograph, age, date of birth, address, postcode, phone number, email, employer, donation history, donation amount
  • Credit card details (collected for donations but not stored by HRF)

Note: Providing personal information is voluntary, but it may impact HRF’s ability to deliver specific services if insufficient information is provided.

Sensitive Information: Users may choose to store sensitive information, such as health details, in features like the digital journal or safety plan within YourCrew. This data is encrypted at rest and in transit, is accessible only by the user, and is not viewable by HRF.

2. Use of Personal Information

Personal information provided to HRF will only be used as permitted by the Privacy Act 1988 (Cth) and the Australian Privacy Principles, including:

  • Sending updates about HRF and our programs
  • Processing and acknowledging donations, including issuing receipts
  • Facilitating involvement in HRF events, promotions, or campaigns
  • Delivering merchandise
  • Marketing HRF’s initiatives, campaigns, and events (see Section 8 below for details on opting out)
  • Analysing community statistics to improve services
  • Addressing legal or safety concerns as required

3. Phone Data Access

When using the YourCrew app, users may grant permission to access their phone contacts for the following purposes:

  • To identify which of their existing contacts are already using YourCrew
  • To invite known contacts who do not yet use the app to join YourCrew

Contacts Data Handling:

  • Accessed only during the “Add New Contacts” function
  • Not stored or retained on YourCrew servers—processed in real-time only  
  • Encrypted in transit and at rest
  • Not shared with any third parties
  • Access requires user opt-in and can be revoked at any time through device settings

User Discovery via Contacts: YourCrew does not include a user search function or directory. Users cannot be found or contacted by people they do not know. With permission, the app may access a user’s personal phone contact list locally to identify which of those contacts already have YourCrew accounts. This is solely to assist users in building a trusted Crew composed of people they already know. This process does not expose user information to individuals outside the user’s contact list.

4. Google API Services

The YourCrew app adheres to the Google API Services User Data Policy, including its Limited Use requirements. For full policy details, visit: Google API Services User Data Policy.

5. Use and Disclosure of Personal Information

HRF will use and disclose your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles:

  • As required by law
  • Where you have provided consent
  • For the purpose for which it was collected, or for related, reasonable purposes

Program Evaluation: HRF may engage reputable third-party researchers (e.g., 5D Market Research & Consulting) to collect and evaluate data for YourCrew and YourCrew Classroom. These firms follow strict security and compliance protocols. Data collection for evaluation always requires user consent.

Overseas Disclosure: HRF does not currently disclose personal information overseas. If this changes, the policy will be updated with details.

6. Security & Storage of Information

HRF ensures information security through:

  • Secure Australian-based servers
  • Firewalls and modern encryption protocols
  • Restricted, logged access for authorised staff only
  • Regular penetration testing and risk assessments
  • Data encryption at rest and in transit
  • Comprehensive incident response protocols

7. Marketing Communications and Opting Out 

Marketing communications (e.g., newsletters, campaign updates) are only sent to individuals who:

  • Opt-in via our website,
  • Provide contact details during events or enquiries,
  • Specifically request updates from HRF.

HRF does not send commercial, promotional, or marketing messages to YourCrew app users unless they have separately opted in. App users are not automatically added to marketing lists through app use.

Opting Out: Anyone who has opted in may unsubscribe at any time by:

  • Clicking the “unsubscribe” link in emails
  • Emailing info@harrisonriedelfoundation.com
  • Using the HRF website contact form

This opt-out process applies to HRF communications only. It does not apply to in-app notifications, which are part of the YourCrew service and may include essential information such as crisis support during emergencies (e.g. floods), wellbeing prompts, or encouragement messages during times like school exams. These notifications are designed to support users’ mental health and safety and are a core part of the YourCrew experience.

8. Parental Consent

For children under 13, HRF requires parental or guardian consent before collecting any personal information. For children 13 and older, HRF works with schools to determine the child’s ability to provide informed consent. Parental involvement may still be requested for sensitive information.

9. Anonymisation and De-Identification

Where possible, HRF will anonymise or de-identify personal information used for evaluation of our programs or analytical purposes to safeguard privacy.

10. Access, Correction, and Complaints

  • Access: Email info@harrisonriedelfoundation.com or write to 6 Borambil Place, Longueville NSW 2066. to request the personal information HRF holds about you.
  • Correction: Contact the same address to update your details
  • Complaints: Email or write to HRF; we will respond within 30 days

11. Changes to this Privacy Policy

This policy may be updated from time to time to reflect changes in law or HRF operations. When significant updates are made, users will be notified via an in-app announcement or platform notification. The current version of these Terms will always be available in the ‘About’ section of the YourCrew app and on the HRF website. We encourage users to review them periodically to stay informed.

 12. Third-Party Platforms and Sub-Processors

HRF and YourCrew app use secure platforms like Raisely, Firebase, SendGrid, and others. These services handle data transiently and adhere to high standards:

  • Strict access controls
  • Encrypted communication and storage
  • Compliance with Australian and international standards

Refer to HRF’s Sub-Processors Table for detailed roles and links to each provider’s privacy policy.

Sub-Processor

Data types

Roles & Data Handling

Location(s)

Privacy Policy Link

Twilio

Name and phone number

Cloud communications platform for sending system SMS (eg. Distress alerts, verification) and invites to both users and potential users

United States

Twilio Privacy Policy

Twilio SendGrid

Name and email

Email delivery services for sending system emails (eg. Distress alerts, verification) and invites to both users and potential users

United States

SendGrid Privacy Policy

Google Analytics

User IPs and geographic information

Website traffic analysis and reporting of page views and visits

United States

Google Privacy Policy

Google Places

User IPs and geographic information

Website traffic analysis and reporting of page views and visits

United States

Google Privacy Policy

Cloudinary

User uploaded images

Storage and delivery of uploaded images for profile, check-ins and journal entries

United States

Cloudinary Privacy Policy

Hyperspike

All user uploaded data

Application and database Hosting and security

Australia

Hyperspike Privacy Policy

Google Vision

User uploaded images

Image analysis for automated moderation to ensure images meet designated standards as per our terms and conditions

United States

Google Cloud Privacy Notice

Firebase

Mobile number

 

Push notification service and mobile and web application traffic analysis and reporting

United States

Firebase Privacy and Security

Notes:

  • Google Services (Analytics, Vision, Firebase): While these services are primarily based in the United States, certain features may store data in various global locations. It’s advisable to review their respective privacy policies for detailed information.​