Privacy

Nexply Order is an Australian ordering platform: venues use it to take orders from their own guests, on pages we host for them. This notice explains what personal information moves through the platform — whether you are a guest ordering at a table or an operator running a venue — and how it is handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Last updated 2 August 2026.

The short version

  • Guests order without an account. There is no sign-up and no password.
  • An order carries what fulfilment needs: the items, the table or area from the QR code, and the email address (and usually the name) entered on the payment page.
  • Card details go to Stripe. They never touch our servers.
  • Guest details are not used for marketing and are never sold.

What we collect from guests

  • Order details — the items and options you chose, the total paid, and the table or area encoded in the QR code you scanned.
  • Contact details from payment — the email address you enter on Stripe’s payment page (used for your order confirmation) and, for most card payments, the cardholder name.
  • Payment — processed entirely by Stripe on the venue’s own Stripe account. We record that an order was paid, never your card number.
  • On your device — your cart (item ids and quantities only) is kept in your browser’s local storage so it survives a page reload. It holds no personal details.
  • Technical logs — standard request logs, and short-lived, hashed rate-limit counters that protect the ordering endpoint from abuse.

What we collect from venue operators

  • Account details — name, email address, and a securely hashed password.
  • Venue details — name, address, contact details, menu, opening hours.
  • Team membership, invitations, and an audit trail of account actions.
  • Stripe account identifiers for payouts and billing. Identity verification for payments is performed by Stripe, not by us.

Why we use it

To take and fulfil orders, send order confirmations, run the operator dashboard, provide support, protect the platform against fraud and abuse, and meet legal obligations such as tax record-keeping. Guest details collected at payment are used for that order — not for marketing.

Who sees your information

When you order at a venue, that venue is the merchant: its staff see your order, the table or area it belongs to, and the name and email from payment, so they can fulfil the order and handle any issue or refund. We do not share guest information with other venues, and we do not sell personal information to anyone.

Service providers

The platform runs on a small set of processors:

  • Stripe — payment processing and payouts. Card data is held by Stripe under its own PCI-DSS obligations.
  • Supabase — database and file storage, hosted in Sydney, Australia.
  • Vercel — application hosting and delivery.
  • Resend — transactional email (order confirmations, sign-in and team emails).

Primary data storage is in Australia. Some providers (including Stripe, Vercel and Resend) process data outside Australia as part of operating their services; we rely on their contractual and security commitments when they do.

How long we keep it

Order and payment records are kept for at least five years to meet Australian tax record-keeping requirements. Rate-limit counters are deleted within minutes. If you ask us to delete your personal information, we remove or anonymise the personal fields while keeping the financial record the law requires.

Access, correction and deletion

You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it — write to hello@nexply.com.au from the address involved (or with enough detail for us to find the record, such as the order number and venue). We respond within 30 days.

Cookies and local storage

Operators get a session cookie to stay signed in. Guests get no advertising cookies and no analytics pixels — the only thing stored on a guest’s device is the cart described above.

Security

Everything is served over HTTPS. Venue data is isolated per tenant at the database layer, card data never reaches our infrastructure, and access to production systems is limited to the people who operate the platform.

Data breaches

If a data breach is likely to result in serious harm, we assess and notify affected people and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.

Complaints

If you think we have mishandled your information, contact us first at hello@nexply.com.au and we will look into it. You can also complain to the OAIC at oaic.gov.au.

Changes

When this notice changes, the date above changes with it. Material changes are announced to operators in the dashboard or by email.