Privacy Policy
Away is operated by Secret Agency Pty Ltd ABN 35 613 451 371. We take your privacy seriously. This policy explains what we collect, why we collect it, and how we use it. It is intended to satisfy our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
What we collect
When you use Away, we may collect:
- Account information — name, email, password hash
- Booking details — dates, experience, guest count, payment references
- Application data — guide and host applications you submit
- Halo sensor data — if you use an Away Halo wearable, we collect EEG (brainwave) and HRV (heart rate variability) readings during wear. This is sensitive health information under the Privacy Act and is collected only with your explicit consent.
- Third-party wellbeing signals — biometric data you voluntarily connect (Apple Health, Oura, Garmin etc). Collection requires your explicit authorisation within each platform.
- Communications — messages you send to Away or hosts via the platform
- Usage data — pages visited, actions taken, device type, browser
Sensitive information
EEG and HRV data collected by the Away Halo constitutes sensitive health information under the Privacy Act 1988. We collect it only with your explicit consent, use it solely for the purposes described below, and apply additional security measures appropriate to its sensitivity.
How we use it
- To operate the platform and process bookings
- To match guests with appropriate experiences and guides
- To generate your personal Presence score and Away Signal wellbeing data
- To personalise experience recommendations — your biometric data is used to calibrate the guidance algorithm to your own patterns. Aggregated and de-identified data may be used to improve the algorithm's general accuracy. Individual-level biometric data is never shared with other users.
- To send transactional emails (booking confirmation, receipts)
- To improve the platform and experience quality
- To comply with legal obligations
What we don't do
- We do not sell your data to third parties
- We do not share biometric or health data with employers, guides, hosts or any other party
- We do not use your data for advertising networks
- We do not send marketing without your consent
- We do not use your individual biometric data to train models for third parties
Data storage and infrastructure
Away data is stored on servers in Australia and the United States. Our primary database is hosted on Neon (a PostgreSQL cloud provider) using infrastructure in the United States. We use industry-standard encryption in transit and at rest. Biometric and health data is encrypted and associated only with your account identifier — not your name or email. By using Away, you consent to this cross-border transfer of your data, including any sensitive health information, to the United States for the purposes described in this policy.
Your rights
You have the right to access, correct or delete your personal data at any time. You can export your Away Signal data from account settings. To request full data deletion, email legal@away.au.
Cookies
Away uses essential cookies for authentication and session management. We do not use third-party tracking cookies. You can disable cookies in your browser, but some features may not function correctly.
Changes to this policy
We may update this policy as the platform evolves. Material changes will be communicated by email to registered users. Continued use of Away after a policy update constitutes acceptance of the updated terms.