Privacy
Nexply Order is an Australian ordering platform: venues use it to take orders from their own guests, on pages we host for them. This notice explains what personal information moves through the platform — whether you are a guest ordering at a table or an operator running a venue — and how it is handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Last updated 1 September 2026.
The short version
- Guests order without an account. There is no sign-up and no password.
- An order carries what fulfilment needs: the items, any notes you add, the pickup time you choose, and the email address (and usually the name) entered on the payment page.
- Card details go to Stripe. They never touch our servers.
- Guest details are not used for marketing and are never sold.
What we collect from guests
- Order details — the items and options you chose, the total paid, the pickup time you chose, and the table or area encoded in the QR code you scanned.
- Order notes — anything you type in an item note is stored with your order, shown to the venue’s staff, and included in your confirmation email. Add only what the kitchen needs; for allergies, speak with staff.
- Contact details from payment — the email address you enter on Stripe’s payment page (used for your order confirmation) and, for most card payments, the cardholder name.
- Payment — processed entirely by Stripe on the venue’s own Stripe account. We record that an order was paid, never your card number.
- On your device — your cart (the items, options and any notes you’ve typed) is kept in your browser’s local storage so it survives a page reload. It never leaves your browser until you order.
- Technical logs — standard request logs, and short-lived, hashed rate-limit counters that protect the ordering endpoint from abuse.
What we collect from venue operators
- Account details: name, email address, and a securely hashed password.
- Venue details: name, address, contact details, menu, opening hours, and any images you upload (logo, menu photos, profile photo).
- Team membership, invitations, an audit trail of account actions, and sign-in session records (IP address and browser details).
- Stripe account identifiers for payouts and billing. Identity verification for payments is performed by Stripe, not by us.
Why we use it
To take and fulfil orders, send order confirmations, run the operator dashboard, provide support, protect the platform against fraud and abuse, and meet legal obligations such as tax record-keeping. Guest details collected at payment are used for that order — not for marketing.
Who sees your information
When you order at a venue, that venue is the merchant: its staff see your order, the table or area it belongs to, and the name and email from payment, so they can fulfil the order and handle any issue or refund. We do not share guest information with other venues, and we do not sell personal information to anyone.
Service providers
The platform runs on a small set of processors:
- Stripe — payment processing and payouts. Card data is held by Stripe under its own PCI-DSS obligations.
- Supabase — database and file storage, hosted in Sydney, Australia.
- Vercel — application hosting and delivery.
- Resend — transactional email (order confirmations, sign-in and team emails).
Primary data storage is in Australia. Some providers (including Stripe, Vercel and Resend) process data outside Australia as part of operating their services; we rely on their contractual and security commitments when they do.
How long we keep it
Order and payment records are kept for at least five years to meet Australian tax record-keeping requirements. Rate-limit counters are hashed and swept minutes after their window passes. If you ask us to delete your personal information, we remove or anonymise the personal fields — including any order notes — while keeping the financial record the law requires.
Access, correction and deletion
You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it — write to hello@nexply.com.au from the address involved (or with enough detail for us to find the record, such as the order number and venue). We respond within 30 days.
Cookies and local storage
Operators get sign-in cookies: a session cookie, and a trusted-device cookie if they choose it. Guests get no cookies at all, no advertising trackers and no analytics pixels — the only thing stored on a guest’s device is the cart described above.
Security
Everything is served over HTTPS. Venue data is isolated per tenant at the database layer, card data never reaches our infrastructure, and access to production systems is limited to the people who operate the platform.
Data breaches
If a data breach is likely to result in serious harm, we assess and notify affected people and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.
Complaints
If you think we have mishandled your information, contact us first at hello@nexply.com.au and we will look into it. You can also complain to the OAIC at oaic.gov.au.
Changes
When this notice changes, the date above changes with it. Material changes are announced to operators in the dashboard or by email.