Privacy

Privacy

Plain English. We collect what we need to run the service, nothing more, and we never sell it.

Who we are

Garden Buddy AU is operated by HELP4BIS (ABN 86 081 237 087), based in Dayboro, Queensland, Australia. We are the entity responsible for your personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). If you have any privacy question, email support@gardenbuddy.au.

What we collect

If you sign up for an account: your email address, the password you choose (stored hashed, not in plain text), your postcode (used to determine your climate zone), the crops you add to your garden journal, and any photos you upload for pest identification.

If you ask to see a vegetable’s growing guide on the price tracker: we ask for your email address once (a one-time gate). We store that email along with the date, your IP address and browser type, so we can recognise you next time and send the free digest you opted into.

If you subscribe to a price report: your email address, your display name, the vegetables you select to follow, and your send schedule. Pro members choose their own list; Starter members get the weekly top-movers alert.

If you pay us: Stripe handles the payment and we never see your card number. We see the transaction status (paid/failed/refunded) and the amount, managed through Paid Memberships Pro.

If we email you: we record whether the email was delivered and whether it was opened (a tracking pixel logs the open time, IP and browser). You can ignore the pixel by viewing email with images turned off.

If you visit any page: standard server logs (IP address, browser, page requested, timestamp) and the privacy-first analytics described below.

Analytics we use

Koko Analytics, our primary analytics tool. Privacy-first: no tracking cookies, no cross-site tracking, stores only aggregate counts (page views, referrers). Data stays on our Australian server.

help4bis-siteanalytics, our own first-party analytics platform. Tracks page views and session journeys to help us understand which features are useful. No third-party data sharing. IP addresses are hashed before storage.

Google Analytics 4 (via Google Site Kit), aggregate traffic insights with IP anonymisation enabled. Google processes data on US servers under the Australian Privacy Principles. You can opt out via the Google Analytics opt-out.

We do not use Facebook Pixel, advertising networks, or any retargeting cookies.

What we do with it

We use your postcode/zone and active crops to personalise advice. We use your email to send the digests, price reports and alerts you signed up for, and to recover your account if you forget your password. We use your selected vegetables to build your personalised price report. We use email open-tracking and server logs to fix bugs, measure whether reports are useful, and detect abuse.

That is it. We never sell your data. We never share it with third-party advertisers. Logged-in members never see ads. If we add affiliate links to seed or garden suppliers in the future, we will label them clearly as affiliate links, they do not change what we collect about you.

How long we keep it

While your account is active, we keep your garden journal, photos, history and report preferences. If you delete your account, we delete all your personal data within 30 days. Email subscribers who unsubscribe are removed from active sending immediately and purged within 30 days. Server logs are kept for 90 days then automatically rotated out. Email open/delivery logs are kept for up to 12 months for deliverability troubleshooting, then removed.

Where it lives

Our database and the site run on Australian infrastructure. Any AI processing happens on hardware we own, located in Australia, your photos are not sent to OpenAI, Google Vision, or any other third-party AI vendor.

Stripe (which handles payments) is a US company and complies with the Australian Privacy Principles. Their privacy policy is at stripe.com/au/privacy. Outbound email is delivered through our own mail server.

Your rights

Under the Australian Privacy Act, you can:

  • Ask us what data we hold about you (we will export it within 30 days)
  • Ask us to correct anything that is wrong
  • Ask us to delete everything (full account deletion, 30-day SLA)
  • Unsubscribe from any email at any time using the link in every email
  • Complain to the Office of the Australian Information Commissioner (oaic.gov.au) if you think we have done the wrong thing

For any of the above, email support@gardenbuddy.au.

Cookies

We use the minimum number of cookies needed to make the site work: a session cookie (PHPSESSID), a logged-in cookie for members, and a one-time cookie that remembers you have given your email on the price tracker so we do not ask again. Koko Analytics and help4bis-siteanalytics do not set tracking cookies. Google Analytics 4 sets first-party cookies for session counting (not used for advertising).

Last updated: 21 May 2026.