← frienemi.com

Privacy Policy

Updated 24 August 2026 · This describes what Frienemi actually does with your data today. Formal legal review is in progress.

1. Who we are

Frienemi is operated by Short Technology Pty Ltd ("Short Tec", "we", "us"), a company registered in Western Australia. We are the data controller for personal information processed through Frienemi. One thing to be clear about up front, because it decides who you should talk to. Frienemi is software that clubs use to run themselves. When a club puts its member list into Frienemi, the club decided to collect that information and the club decides what to do with it. We hold it for them. Where this policy says "your club", it means an organisation making its own decisions about your data, not us. Contact for privacy matters: privacy@frienemi.com.

2. What we collect

Account. Email address, display name, username, a password hash (bcrypt — we never store the password itself), profile photo, and an optional short bio. Third-party sign-in. If you sign in with Google, Apple or Facebook, we receive your email address, name and profile photo from that service, and a stable identifier it uses for you. That is all we ask for, and it is used only to create or recognise your Frienemi account. We do not request — and cannot see — your friends, contacts, posts, photos or anything else held by that service. Profile and play. Your rating, playing preferences, and a location you type in yourself (a suburb or city, as free text — not coordinates). Matches and sessions you played, scores, opponents, partners, rating history, and friends. Club membership. Which clubs you belong to, your role in each, when you joined, when you left, and whether your membership is currently active. You can belong to several clubs at once. Each club sees its own relationship with you and not the others. Payments. Amount, currency, what it was for, status, dates, any refund, and the Stripe reference numbers for the transaction. We do not hold your card. See section 4. Member and student verification. If a club offers a member or student price, we hold the record that proves you qualify. See section 5. Device and technical. Device model, OS version, app version, push notification token, and IP address for security and fraud prevention. Diagnostics and analytics. The mobile app includes Firebase Crashlytics (crash reports) and Firebase Analytics (aggregated usage). This website loads Google Tag Manager.

3. Why we use it

(a) To run Frienemi: sessions, ladders, scoring, notifications, memberships and access. (b) To take and record payments a club is owed, and to bill clubs our own commission. (c) To communicate with you: account email, support replies, important service notices. (d) To improve Frienemi: aggregated analytics on feature use and performance, and crash reports. (e) To prevent abuse: rate limits, fraud detection, ban enforcement. (f) To meet legal obligations, including keeping financial records.

4. Payments, and what Stripe does

We do not see, receive or store your card number. Paying inside Frienemi sends you to a payment page hosted by Stripe. You type your card details into Stripe's page, not ours. Our database has no column that could hold a card number, and never has. What we send Stripe when you pay: your email address, your display name, a description of what you are buying (the item, the club and your name), and four internal reference ids — for the payment, the club, the item and your account. Nothing else about you goes with it. What we keep afterwards: the amount, the currency, what it was for, whether it succeeded, the date, any refund and when it landed, our commission, Stripe's processing fee, and Stripe's own reference numbers for the charge. Those reference numbers are the only way a disputed payment can later be answered, which is why we keep them. Stripe is a payment processor and handles your card data as its own controller under its own terms and privacy policy. See stripe.com/privacy. For clubs: when your club connects its Stripe account, we store the Stripe account id and a few status flags — whether it can take charges, whether payouts are enabled, whether the connection is still live. Bank account details and identity documents go from the club straight to Stripe and never touch our database. We also store, if the club enters them, the club's ABN, legal name and the email address its commission statements go to.

5. Member and student verification

Some clubs price a membership differently for students, life members, juniors, or anyone else they define. To do that, they need a record that you qualify. There are two kinds. Verified email address. You type in your institutional email address — a university address, say. We email a six-digit code to it and you type the code back. We store only a hash of that code, never the code itself; it expires after one hour, and five wrong attempts destroys it and makes you start again. The code arriving is the proof: it shows the address is yours. Granted by the club. A club admin ticks you off against a category the club itself created. Nothing is emailed and no address is stored. What we store on a verification: the address you proved (for the email kind), the date, who verified it, and whether it is still current. If the institution's rule includes a member or student number, we store that number too — either read out of your address, or typed in by you at the time. Who can see it. Owners and admins of the club whose pricing depends on it. They can see that you hold the credential, when, and your member or student number. They cannot see the verified email address itself — nothing in the product ever shows it to them. Other members see none of it. Kept separate between clubs. A credential one club granted you never appears in another club's list, even if you belong to both. A verified-email credential is shared across clubs that rely on the same institution — that is the point, so you only prove it once — but it shows up in a club's list only while you are a current member there. A club cannot revoke it either; only you can remove it, from your own account. How long. The stored email address is cleared 24 months after the verification that produced it, automatically. The credential itself stands until you remove it or the club revokes a credential it granted. A member or student number is kept for as long as the credential record exists, including after it lapses — clubs and institutions count their members at year end, and someone whose verification went stale in March is part of that count. Everything in this section is deleted outright when you delete your account.

6. What your club can see

An owner or admin of a club you belong to can see: your name, your email address, your role, when you joined, whether your membership is active, which plan you are on, what you have paid through to, how that membership was funded (card, paid outside the app, or comped), any credentials you hold in that club and the member number attached, and your ratings and results within that club. They can export all of that as a spreadsheet. Ordinary members of the club see what the app shows on a roster or a ladder — names, ratings, results — and not the money or the verification records. Revenue and financial reporting is narrower still: some of it is limited to the club's owner rather than every admin. Only what happens in that club. A club's export contains its own club's data. It does not reveal your other clubs, your matches elsewhere, or your private messages.

7. Member lists a club uploads

A club can import its existing membership list as a spreadsheet. That list is the club's own record, gathered by the club, and the club is responsible for having been allowed to gather it. What an import reads: email address, name, and — for the club's own preview only — the plan name and paid-through date its spreadsheet claims. Importing a list does not create a payment, charge anyone, or change anyone's membership dates. It creates an invitation, which becomes a membership when the person signs up or signs in with that address. What an import ignores: everything else in the file. If the spreadsheet carries a phone number, that column is read and then discarded with the request — we have no field to put it in and nothing downstream can reach it. Columns like addresses and notes are dropped without being read at all. A role column is deliberately not read, so an uploaded file can never make someone an admin.

8. Who we share with

Other Frienemi users. Your display name, photo, rating and results are visible inside the app according to the visibility you set. We never show other users your email address or contact details. Your clubs. As described in section 6. Service providers, who process data on our behalf under contract: Amazon Web Services (hosting, database, file storage and outbound email via SES), Stripe (payments — see section 4), Google Firebase (push notifications, crash reporting and analytics), and Google Tag Manager on this website. Legal. Where required by law, court order, or to protect Frienemi or its users. Sign-in providers (Google, Apple, Facebook). The flow is one-way. They tell us who you are when you choose to sign in; we send them nothing about your Frienemi activity, matches or friends, and we do not post anything on your behalf. You can revoke Frienemi's access at any time in your Google, Apple or Facebook account settings — your Frienemi account survives, and you can set a password with "Forgot password" to keep signing in by email. We do not sell your personal information.

9. Where your data is held

Our servers, database and file storage run in Amazon Web Services' Sydney region (ap-southeast-2), and our outbound email is sent from there. Some service providers process data outside Australia. Stripe, Firebase and Google Tag Manager all operate internationally, including in the United States, under standard contractual clauses or equivalent safeguards.

10. How long we keep things

While your account is open, we keep your account data. When you delete your account, most personal information is removed immediately and the rest is anonymised. The full list is on our delete-account page, and it is worth reading before you delete: some things survive, and there are reasons. Two durations are enforced automatically. A verified email address stored against a credential is cleared 24 months after the verification that produced it. Expired sign-in tokens are deleted nightly. Payment records are kept. A record that money moved — the amount, the date, our commission and the Stripe reference numbers — is a financial record, and we keep it even after the account is deleted and even after the club it belonged to is deleted. It no longer names you: it points at an anonymised account. Backups are kept on a rolling schedule. A backup taken before you deleted your account still contains what it contained at the time, until it rolls off. We do not restore a backup to undo a deletion. You can ask us about anything held about you, or ask for earlier deletion, at privacy@frienemi.com.

11. Your rights

Under the Australian Privacy Act 1988 you can: - ask what personal information we hold about you and get a copy - ask us to correct anything wrong - ask us to delete your account and personal data - withdraw consent for optional processing - complain to us, and complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au Email privacy@frienemi.com to do any of these. We aim to respond within 30 days. If your request is about something your club holds — a club's member list, a club's record of what you paid it — tell us anyway. We will either handle it or tell you plainly that it is the club's decision and who to ask.

12. Security

TLS in transit, encrypted storage at rest, passwords hashed with bcrypt, verification codes stored only as hashes and destroyed after five wrong attempts, least-privilege access controls, and routine security review. Card data never enters our systems, so a breach of Frienemi cannot expose a card number. No system is perfectly secure. If we learn of a breach affecting your data we will notify you in line with Australian breach-notification law.

13. Children

Frienemi is not directed to children under 16. If we learn we have collected information from a child under 16 without verifiable parental consent we will delete it. Clubs run junior programs. If your club has put a junior's details into Frienemi, the club is responsible for having the parent's consent to do so.

14. Changes

We will revise this policy from time to time. Material changes will be communicated by email or in-app notice 30 days before they take effect.

15. Contact and complaints

Privacy questions or requests: privacy@frienemi.com. If you are unhappy with how we handled something, say so in that email and we will look at it again. If you are still unhappy, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. Postal: Short Technology Pty Ltd, Western Australia, Australia (full address on request).

See also our Terms of Service and how to delete your account. Frienemi is operated by Short Technology Pty Ltd, a company registered in Western Australia, Australia.