Privacy policy
Last updated 17 September 2026.
The Council is a private membership operated by Meson Agency in Australia. This policy explains what we collect through The Council website and iOS app, who can see it, and what you can ask us to do with it. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
What we collect
Only what the membership needs to work:
- When you request an invitation: your name, work email, company and role, who referred you, and what you write about what you run.
- Your profile: name, photograph, company, role, city, a short bio and a LinkedIn URL. You choose what to put here and can edit or clear it at any time.
- Your contact details: email address and mobile number. These are stored separately from your profile and are never part of the directory.
- Events: which events you RSVP to, your place on a waitlist, the first name of a guest if you bring one, and whether a seat has been paid for.
- Introductions: who asked to be introduced to whom, the note sent with the request, and whether it was accepted or declined.
- Your device: a push notification token, if you turn notifications on.
- Billing: a Stripe customer reference and the status of your membership. Card numbers go directly to Stripe and never reach our servers.
We do not run advertising, we do not use third-party analytics or tracking pixels, and we do not sell or rent personal information to anyone.
Who can see it
This is enforced in the database itself, not only in the app:
- Your profile is visible to other members whose own membership is current — and only while you have "show me in the directory" switched on.
- Your mobile number and email are shared with another member only when an introduction between you is accepted, and only if you have allowed that in your settings. They are never visible in the directory.
- Attendee lists for an event are visible to current members who can see that event.
- Administrators (the membership committee) can see all member records, requests and attendee lists in order to run the group.
- People who request an invitation and are not approved are never visible to members.
Where it is stored
Member data is held in a Supabase Postgres database hosted in Sydney, Australia (AWS ap-southeast-2). Photographs are stored in the same project. Backups stay within that infrastructure.
Who we share it with
Service providers only, each for a single purpose:
- Supabase — database, authentication, file storage and email sign-in links.
- Stripe — membership and event payments. Stripe is the controller of your card data under its own policy.
- Expo — delivery of push notifications to your device, if you enable them.
- Netlify — hosting of this website.
- Google Places — venue lookup used by administrators when creating an event. No member information is sent to Google.
We will also disclose information where the law requires it. We do not otherwise send personal information overseas, beyond the providers listed above operating their own global infrastructure.
How long we keep it
- Member records are kept while your membership is current, and for seven years afterwards where we need them for tax and financial records.
- Unsuccessful requests are kept for twelve months, then deleted.
- Push tokens are deleted as soon as they stop working or you turn notifications off.
Your choices
- Hide yourself from the directory, or stop sharing your mobile or email on introductions, in Me → Edit profile.
- Turn notifications off, individually or entirely, in Me → Notifications.
- Correct anything in your profile yourself, at any time.
Access, correction and deletion
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account and its data. Email members@mesonagency.com and we will respond within 30 days. Deleting your account removes your profile, contact details, RSVPs and introductions; we may retain financial records where the law requires it.
Security
Access to data is restricted row by row in the database, so one member's record cannot be read by another except through the rules described above. Sign-in uses one-time email links rather than passwords. Administrative access is limited to the membership committee. No system is perfectly secure, and if a breach ever affects you we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
Children
The Council is for adults in professional practice. It is not directed at anyone under 18 and we do not knowingly collect their information.
Changes
If this policy changes materially we will tell members in the app before the change takes effect. The date at the top always reflects the current version.
Complaints
If you think we have mishandled your information, write to members@mesonagency.com and we will investigate. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.