Privacy Policy

Last updated: 22 April 2026

Who we are

Train Wizard is based in Queensland, Australia ("Train Wizard", "we", "us", "our"). This Privacy Policy explains how we collect, use, store, and disclose personal information when you use our website at trainwizard.com.au and our strength-and-conditioning services for junior rugby league athletes (the "Service").

By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

Who this policy covers

Train Wizard is built for junior rugby league athletes aged 11 to 18. Because our users are minors, all accounts must be created and managed by a parent or legal guardian ("Parent"). When we refer to "you" in this policy, we mean the Parent who holds the account. We also refer to the minor athlete as the "Player".

What information we collect

Information the Parent gives us when creating an account

  • Parent's full name and email address
  • Password (stored in hashed form — we never see your actual password)
  • Billing name, address, and payment method (handled by our payment processor — see "Payments" below)

Information about the Player

  • Player's first name (or nickname), age or date of birth, playing position, and current training level
  • Optional: height, weight, relevant injury history, goals

Information generated through use of the Service

  • Which training sessions were completed, when, and how they were marked off
  • Progress metrics and streaks
  • Messages sent to us or to coaches through the app

Technical information collected automatically

  • Device type, operating system, browser type
  • IP address, approximate location (city-level, derived from IP)
  • Log data (timestamps, pages visited, error reports)
  • Cookies and similar technologies — see "Cookies" below

Information from third parties

  • If you sign in with Google, Apple, or similar: basic profile information they provide
  • Payment confirmation from our payment processor

We do not collect more than we need to provide the Service.

How we use your information

We use personal information for the following purposes:

  • To provide the Service — creating accounts, tailoring programs to the Player's age, position, and level, tracking progress, serving video content.
  • Safety and age-appropriateness — age and level inputs let us avoid programming that isn't appropriate for a younger Player (for example, not prescribing maximal loading to a 12-year-old).
  • Communication — sending service-related emails (account confirmations, billing, program updates, security notices). With your consent, we may also send newsletters or product updates; you can opt out at any time.
  • Customer support — responding to questions and requests.
  • Service improvement — analysing usage to understand which features are helpful, find and fix bugs, and improve the product.
  • Legal and safety compliance — meeting legal obligations and protecting our rights and the rights of our users.
  • Fraud prevention and security — detecting and preventing misuse of the Service.

We do not sell your personal information. We do not use your information for automated decisions that have legal or similarly significant effects.

Payments

Payments are processed by Stripe, Inc. ("Stripe"). When you enter card details, they are collected directly by Stripe's secure payment form — we never see or store your full card number or CVV. Stripe's handling of this information is governed by Stripe's privacy policy, available at https://stripe.com/au/privacy. We receive only a tokenised reference, the last four digits of your card, the brand, and the result of each transaction.

Who we share information with

We share information only with parties that help us run the Service, and only with the information they need:

  • Hosting and infrastructure providers — for storing data and delivering the Service.
  • Payment processor — Stripe (see above).
  • Email delivery — our email service providers for sending transactional and, where you consent, marketing emails.
  • Analytics — aggregated, usually-pseudonymous product analytics to understand how the Service is used.
  • Customer support tools — the software we use to reply to your messages.
  • Professional advisors — our lawyers and accountants, where required.

We require each of these providers to handle your information consistently with this policy and with Australian privacy law.

We may also disclose information where required by law, to respond to a valid legal process, to protect the rights and safety of our users, or in connection with a business transfer (such as a sale of the company), in which case we will notify you beforehand.

Where your information is stored

We primarily host data in Australia where available. Some of our service providers (including Stripe and our analytics and email providers) store and process data overseas, including in the United States and the European Union. Where personal information is transferred overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.

How long we keep information

We keep personal information only for as long as we need it:

  • Account data — while your account is active, plus up to 24 months after closure, after which we delete or irreversibly anonymise it. Some records (for example, tax invoices) are kept for 7 years as required by Australian law.
  • Support conversations — up to 3 years after the last contact.
  • Technical logs — up to 12 months.

Security

We use reasonable technical and organisational measures to protect personal information, including encryption in transit, encrypted storage, access controls, and regular reviews. No online service can guarantee absolute security, so we encourage you to use a strong, unique password and keep your account details private.

If we become aware of a data breach that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.

Your rights

Under the Privacy Act 1988 (Cth) you have the right to:

  • Access the personal information we hold about you and your Player
  • Correct information that is inaccurate, incomplete, or out of date
  • Delete your account and the information we hold, subject to legal or legitimate business retention requirements
  • Withdraw consent to marketing communications at any time
  • Complain about how we have handled your information

To exercise any of these rights, email hello@trainwizard.com.au. We will respond within 30 days.

If you are not satisfied with our response, you can make a complaint to the Office of the Australian Information Commissioner:

Cookies

We use a small number of cookies and similar technologies:

  • Essential cookies — required for the Service to work (for example, keeping you signed in).
  • Analytics cookies — help us understand how the Service is used so we can improve it.

You can disable non-essential cookies in your browser or on first visit via our cookie banner.

Children's privacy

Our Service is designed for use by Players aged 11 to 18, and accounts are held by a Parent. We do not knowingly allow minors to create their own accounts. If you become aware that a minor has created an account without a Parent's involvement, please contact us at hello@trainwizard.com.au and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the "Last updated" date. If the changes are material, we will also notify account holders by email before the changes take effect.

Contact

For any questions about this Privacy Policy, or to exercise any of the rights set out above:

Train Wizard
Email: hello@trainwizard.com.au