Privacy Policy
- Controller:
- Solteq Pty Ltd (ABN 91 697 347 907)
- Registered office:
- 97 Creek St, Brisbane City QLD 4000, Australia
- Effective date:
- 20 June 2026
Who we are
DynaPlay is a registered business name of Solteq Pty Ltd (ABN 91 697 347 907), the entity responsible for the personal information described in this policy. Our registered office is 97 Creek St, Brisbane City QLD 4000, Australia.
When this policy says "DynaPlay", "we", "us", or "our", it refers to Solteq Pty Ltd trading as DynaPlay. In line with our open and transparent management obligations (Australian Privacy Principle 1.4), you can reach us about any privacy matter at privacy@dynaplay.app.
Scope of this policy
This policy applies to the DynaPlay consumer mobile app (iOS and Android) and the dynaplay.app website. It covers the personal information you provide and that we collect as you discover venues, make and coordinate bookings, pay, and chat with other participants.
Our business-facing surfaces — the venue marketing site and the operator dashboard — operate under their own terms and are not covered here.
Information we collect
We collect only the personal information reasonably needed to provide and improve DynaPlay, consistent with Australian Privacy Principle 5. The categories below mirror our published data-safety disclosures.
- Name: your name, used for your account, personalisation, and booking confirmations sent to venue operators. Required to create an account.
- Email address: used for your account, authentication, and transactional email. Required.
- User ID: an account identifier used to operate your account and, where you make a payment, shared with Stripe for payment processing. Required.
- Payment methods: payment method details handled through Stripe (our payment processor) for processing payments. Optional, but required for paid bookings.
- Purchase history: records of your bookings and payments, kept for your account and to meet tax-compliance obligations. Required when a purchase is made.
- Chat messages: messages you send to other participants of a shared booking. Optional — collected only when you send a message.
- Profile avatar: a profile photo you may add for personalisation. Optional.
- Precise location: precise device geolocation used to discover venues near you. Optional, and used only to serve your request — we keep no server-side location trail beyond it.
- App-interaction analytics: in-app activity used to understand and improve the product, processed through Firebase Analytics. Optional, controlled by an in-app analytics toggle.
- Push token: a device identifier used to deliver push notifications through Firebase Cloud Messaging. Optional.
- Crash logs: diagnostic crash reports — stack traces and device state when the app crashes — processed through Firebase Crashlytics to keep the app stable. Collected automatically in release builds; records auto-expire after about 90 days.
How and why we use your information
We use your information for the purposes below.
- Providing the service: to create and operate your account, run venue discovery, process bookings and payments, and enable chat between participants. This is necessary to provide the service you sign up for.
- Optional features: to deliver push notifications and use your precise location for proximity discovery. We use these only with your consent, which you can withdraw at any time.
- Legal and tax obligations: to retain financial records as required by Australian tax law.
- Securing and improving DynaPlay: to keep the service secure, prevent abuse, troubleshoot, and measure app-usage analytics to improve our products. App-usage analytics is on by default; you can turn it off at any time in Settings → Privacy & data.
Sharing and disclosure
We do not sell personal information. We share personal information only with the service providers needed to operate DynaPlay, and only as described below.
- Stripe: payment processing. We share your customer ID, payment method tokens, transaction amounts, and booking identifiers so payments can be processed. Stripe also collects device signals to prevent payment fraud.
- Firebase Cloud Messaging: push notification delivery. We share your push notification token.
- Firebase Analytics: product analytics. We share app events and non-identifying user properties, subject to your in-app analytics toggle.
- Firebase Crashlytics: crash diagnostics. We share crash stack traces and device state at the time of a crash to keep the app stable; these are keyed to a Crashlytics installation identifier, not your account.
- Stadia Maps: map rendering. When you browse the venue map, your device's IP address and the map area you are viewing are sent to Stadia Maps to load map tiles. This is not linked to your account.
- Google Maps Platform: address lookup and venue-location search. If you add a venue, your precise location and the address text you type are sent to Google's Places and Geocoding services to find and confirm the address. This is not linked to your account.
- Resend: transactional email. We share your email address to send account and notification emails.
Location information
We use precise device geolocation to help you discover venues near you, and — if you add a venue — to look up and confirm the venue's address, in each case only when you grant the permission. For address lookup, your coordinates and the address text you type are sent to Google Maps Platform. We do not build or retain a server-side location history of our own — your location is used to serve the request and not stored as an ongoing trail. You can revoke location access at any time in your device settings.
How long we keep your information
We keep personal information only as long as needed for the purpose it was collected, and no longer, consistent with Australian Privacy Principle 11.2.
Financial records (bookings and payments) are retained for five years to meet the Australian Taxation Office's record-keeping obligation; on account deletion these are anonymised rather than removed. Messages you sent are retained so other participants' conversation histories remain intact, with your attribution anonymised to a "Deleted user" sentinel. Everything else tied to your account is hard-deleted or anonymised once the deletion grace period ends.
Your privacy rights
You have rights over your personal information under the Australian Privacy Principles — notably the right to access your information (APP 12) and to ask us to correct it (APP 13). You can also delete your account and the information tied to it, request a copy of your data, and withdraw consent for uses that rely on it (such as analytics and precise location).
- Deletion: you can delete your account, and the personal information tied to it, from the in-app deletion flow or at dynaplay.app/delete-account.
- Data export: you can request a copy of your data by emailing support@dynaplay.app; we reply within 30 days.
- All other requests: to access, correct, object to, or restrict processing, or to withdraw consent, contact us at privacy@dynaplay.app. We may need to verify your identity before responding.
Children
DynaPlay is not directed to children under 16, and we do not knowingly collect personal information from children (consistent with the Google Play Families policy). If you believe a child has provided us personal information, contact us and we will take reasonable steps to delete it.
How we protect your information
We take reasonable steps to protect personal information. All traffic is encrypted in transit using HTTPS, and data is encrypted at rest using managed key encryption. Apple Sign-In refresh tokens are additionally encrypted with AES-256-GCM. No internet service can be guaranteed completely secure, but we work to protect your information from misuse, loss, and unauthorised access.
International data transfers
Some of our service providers store or process information outside Australia. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles (Australian Privacy Principle 8.1). Because provider infrastructure changes over time, it may not be practicable to list every country at all times.
Changes to this policy
We may update this policy as DynaPlay, privacy laws, or our data practices change. The effective date shown above tells you when the current version took effect. For material changes we will take reasonable steps to notify you, consistent with keeping this policy current (Australian Privacy Principles 1.3–1.5).
Contact and complaints
For any privacy question, request, or complaint, contact us at privacy@dynaplay.app. We will review the matter and respond within a reasonable time (Australian Privacy Principle 1.2).
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).