Legal
How we collect, use, hold and disclose personal information across our websites and the Lori app.
Last updated: 24th Aug 2026Contents
Section 01
This Privacy Policy explains how we collect, use, hold and disclose personal information across the following websites and the Lori application (together, our Services):
| Service | Operated by |
|---|---|
| betteracts.com | BetterActs Pty Ltd (ABN 82 692 853 544, ACN 692 853 544) |
| betteractscollective.org | BetterActs Collective Inc. (ABN 90 406 224 512) |
| lorivolunteer.org (the Lori app) | BetterActs Collective Inc. (ABN 90 406 224 512) |
We also currently operate getlori.tech, which will be retired and redirected to lorivolunteer.org. This policy applies to it in the meantime.
In this policy, 'BetterActs', 'we', 'us' and 'our' refer to whichever of BetterActs Pty Ltd or BetterActs Collective Inc. operates the Service you are using. Lori is operated exclusively by BetterActs Collective Inc. The two are separate legal entities, and each is responsible only for the personal information it holds.
Our information handling practices are set out in this policy and are based on the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). We will handle personal information in accordance with them, and we will review and update them as our Services develop. The APPs are available from the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Section 02
Lori is used by organisations (Customers) to manage their own volunteers (End Users). We handle personal information in two different capacities.
Expressions of Interest submitted through our websites, a Customer's account and billing details, support and bug-report correspondence, technical logs, and marketing subscriptions where someone has opted in. We are directly responsible for this, and the rest of this policy explains how we handle it.
A volunteer's name, contact details, availability, roles or checks (Customer Data). This is collected and controlled by the Customer organisation, not by BetterActs. We process it only as a service provider, on the Customer's instructions, to run Lori.
If you are a volunteer with questions about how your information is used, contact the organisation that invited you to Lori first. They control that information and are responsible for explaining how they use it.
In respect of Customer Data we will:
Section 03
When you submit an Expression of Interest through a contact form on any of our websites, we collect your name, email address, organisation and role, and the content of your message.
When an organisation creates a Customer account, or upgrades to a paid plan, we collect:
Payments are processed by Stripe. We do not collect or store full card numbers, expiry dates or CVCs — these go directly into Stripe's PCI-DSS compliant payment form and are handled under Stripe's privacy policy. We receive only limited metadata (transaction status, amount, masked card reference) to reconcile subscriptions.
Our systems automatically record IP address, browser and device type, request timestamps, actions taken in the app, and error logs. We use this only for security, fraud prevention, fault diagnosis and service reliability.
When a Customer invites a volunteer, or enters volunteer details into Lori, the Customer may collect:
Customers may choose to record sensitive information or government-related identifiers — for example Working with Children Check (WWCC) numbers, police check outcomes, driver licence details, RSA certificates, or health, dietary and accessibility information. As set out in section 2, this is the Customer's information to control. It is the Customer's responsibility to:
Where a Customer's purpose is limited to verifying that a check is current, we recommend that the Customer record only the verification status, the expiry date, and the identity of the person who conducted the verification, rather than the identifier itself or an image of the underlying document. Lori is designed to support this approach. Minimising the identifiers held materially reduces the likelihood that an unauthorised disclosure would result in serious harm.
Lori does not currently support uploading images or scans of licences, WWCCs or other credentials. We are developing this feature. Before it is released we will update this policy, tell Customers where those files will be stored, and give Customers the choice of whether to use it.
Some Customers engage volunteers under 18. Where a volunteer is under 18, the Customer is responsible for deciding whether that person can consent to the collection of their information, and for obtaining parental or guardian consent where they cannot. We do not knowingly collect information directly from children other than through a Customer's use of Lori. If you believe a child's information has been provided to us in another way, contact us and we will delete it.
Lori is in beta. If you report a bug, we collect your name, email address, screenshots and your description of the issue, to investigate and respond. Please avoid including volunteer personal information in a bug report unless it is necessary to diagnose the problem.
Where lawful and practicable you may deal with us anonymously or under a pseudonym — for example, a general enquiry. This is not practicable where we need to identify you to provide an account, process a payment, or respond to an access request.
Section 04
Wherever practical, we (or, for volunteer information, the Customer) collect personal information directly from the individual — when someone submits a contact form, sets up or manages a Customer account, registers as an invited volunteer, or contacts us for support.
We also collect indirectly in two situations:
Section 05
Lori uses only strictly necessary cookies and browser storage — to keep you signed in and to keep your session secure. Lori does not use advertising cookies, cross-site tracking, or third-party marketing pixels.
We use Vercel Web Analytics on our marketing sites to understand aggregate traffic — page views, referrers, country, device type. Vercel Web Analytics does not set cookies and does not track visitors across websites; it derives an anonymous, rotating identifier from request data and discards it. We cannot identify individual visitors from it. Vercel processes this data on infrastructure outside Australia (see section 8).
If we introduce any additional analytics or tracking, we will update this section before doing so. We do not respond to browser "Do Not Track" signals, as there is no agreed standard for interpreting them.
Section 06
We use the information described in sections 3.1, 3.2, 3.3 and 3.6 to:
When someone sets up an organiser account on Lori, we offer an optional, unticked checkbox inviting them to receive occasional emails from BetterActs about Lori, our roadmap and our work. It is off by default, separate from accepting our terms, and declining it does not affect your use of Lori. If you tick it, we hold your name, email address and the date and source of your consent as a record.
We do not currently send marketing to volunteers. Volunteers are not added to any mailing list, and we use volunteer contact details only to operate Lori on their organisation's behalf. If we introduce a marketing opt-in for volunteers in future, it will be opt-in only, we will update this policy, and we will notify Customers before it takes effect.
We comply with the Spam Act 2003 (Cth). Every commercial message identifies BetterActs as the sender and contains a working unsubscribe link, which we action within 5 business days.
For volunteer information described in section 3.4, we use it only to provide, maintain, secure and support Lori on the Customer's behalf. We will not use personal information we control for a purpose other than the one it was collected for, unless you would reasonably expect that use, you consent to it, or we are required or authorised by law.
We do not use personal information, including Customer Data, to train, fine-tune or evaluate machine learning or AI models, and we do not permit our service providers to do so. If we build any AI-assisted feature into Lori, we will update this policy and notify Customers before enabling it.
Section 07
We may disclose personal information to:
Within Lori, a Customer's administrators can access the volunteer information that Customer has collected — that is the purpose of the app. We do not disclose one Customer's volunteer information to another Customer.
We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.
Section 08
We use a small number of service providers. This table sets out what each handles and where. It is included so Customers can assess their own cross-border disclosure obligations under APP 8.
| Provider | What it handles | Where it is stored |
|---|---|---|
| Supabase | Authentication for Lori — email addresses, hashed passwords, session tokens | Sydney, Australia (ap-southeast-2) |
| Neon (via Replit) | The main Lori database, including all Customer Data — volunteer names, contact details, availability, roles and any other fields Customers add | United States |
| Stripe | Payment processing and billing records for paid plans | United States and other countries in Stripe's global infrastructure |
| Resend | Transactional and notification email — recipient name, email address, message content | United States |
| Vercel | Marketing website hosting and aggregate website analytics | United States and global edge network |
Notice to Customers. Volunteer information entered into Lori is stored on servers located in the United States. This disclosure is made so that Customers may assess their own obligations, including any obligation to notify their volunteers of overseas disclosure. Overseas recipients are subject to the laws of the jurisdictions in which they operate, and Australian law may not be enforceable against them.
We contract with each provider on its standard data processing terms, including standard contractual clauses where the provider offers them. We are actively working toward Australian data residency for the main database, and will notify Customers before any change to where their data is stored — in either direction.
Section 09
We take reasonable steps to protect personal information, including Customer Data, from misuse, interference, loss, and unauthorised access, modification or disclosure. What we do:
No method of electronic storage or transmission is entirely secure, and we do not warrant that personal information will remain free from unauthorised access in all circumstances. Lori remains in beta and under active development, and Customers should have regard to that when determining what information to enter into the platform.
Customers are responsible for maintaining strong, unique account credentials and for revoking administrator access promptly when a person ceases to require it.
Section 10
If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information:
Customers must tell us as soon as practicable if they become aware of unauthorised access to their Lori account.
Section 11
| Information | Retention |
|---|---|
| Expression of Interest / contact form submissions | 24 months from last contact, then deleted — unless you become a Customer or opt in to updates |
| Customer account, billing and transaction records | At least 5 years after account closure, as required by Australian tax and record-keeping law |
| Marketing subscription records | Until you unsubscribe, plus 2 years to evidence consent under the Spam Act |
| Support and bug-report correspondence | 24 months from resolution |
| Technical and security logs | 90 days |
| Volunteer information in Lori | While the Customer's account is active, or as the Customer instructs |
| Customer Data after account closure | 30 days to allow recovery, then permanently deleted; backups purged within a further 30 days |
Customers can request deletion of their organisation's data at any time. We will action verified deletion requests within 30 days and confirm in writing. When information is no longer needed, we take reasonable steps to securely destroy or de-identify it.
Section 12
If you submitted an Expression of Interest, hold a Customer account, or are on our marketing list, you can ask us for access to the personal information we hold about you, or ask us to correct it, at any time.
No fee to make a request. We may charge a reasonable administrative fee for providing copies. We may need to verify your identity first. We will respond within 30 days. If we refuse, we will tell you why in writing and how to complain.
If you are a volunteer and want to access or correct information a Customer holds about you in Lori, contact that organisation directly — they control it. If you can't resolve it with them, contact us and we will help where we reasonably can, including by raising it with that Customer.
Data export. Customers can export their organisation's data from Lori at any time. Contact us if you need help.
Section 13
If you have a concern about how we have handled information we control (see section 2), email us using the details in section 15. We will acknowledge within 5 business days and respond substantively within 30 days.
If your concern is about a Customer's handling of your volunteer information, raise it with that organisation first.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner:
Section 14
We may update this policy from time to time, including as Lori's features and beta status change. The current version is always available on our websites and inside Lori, with the 'last updated' date at the top.
Where a change materially affects how we handle personal information — including any change to where data is stored, or the introduction of document uploads or additional tracking — we will email Customers at least 14 days before it takes effect.
Section 15
For privacy questions, access or correction requests, or complaints:
| Entity | Contact |
|---|---|
| Lori and BetterActs Collective Inc. | info@betteractscollective.org |
| BetterActs Pty Ltd | info@betteracts.com |
| Registered office | Melbourne VIC 3003, Australia |
We are an incorporated association registered in Victoria. Our registered address is available through the Australian Business Register at abr.business.gov.au using ABN 90 406 224 512.
We'd rather you asked than wondered. Get in touch and a real person will answer.
Get in Touch