Back to home

Privacy Policy

Version: 5.2 - 17 September 2026

Alice and Bear Holdings Pty Ltd (ACN 701 192 896, ABN 84 701 192 896) trading as With A Bow

1. General

Alice and Bear Holdings Pty Ltd (ACN 701 192 896, ABN 84 701 192 896) trading as With A Bow ("With A Bow", "we", "us" or "our") operates a digital wishing well and gift registry platform that allows event organisers to create event pages through which guests can make cash gifts, select gift items, leave messages and receive related communications ("Platform"). We provide registry creation, payment facilitation, payout coordination, messaging, reporting, moderation and related support tools ("Services"). This Privacy Policy explains how we collect, hold, use and disclose Personal Information in connection with the Platform and Services, and how we follow the Australian Privacy Principles. In this Privacy Policy, "Privacy Act" means the Privacy Act 1988 (Cth).

Capitalised terms used but not defined have the meaning given in our Terms and Conditions, available at withabow.com.au/terms.

2. Scope and who this policy applies to

This Privacy Policy applies to all individuals whose Personal Information we collect in connection with the Platform and Services, including event organisers, hosts, guests, contributors, prospective users, individuals who report an event or content, individuals who interact with us through With A Bow or related business channels, and other visitors to our website and Platform.

It also applies to Personal Information collected through our website, event pages, account registration flows, payment flows, communications, support interactions, reporting tools, referrals, partner or supplier interactions, and other online and offline channels related to the Platform and Services.

We are committed to handling Personal Information in a lawful, fair and transparent way, and to making this policy clear for everyone who uses the Platform, whether you are creating an event, giving a gift, receiving a message, reporting a concern or visiting our website.

3. The information we collect

We collect information that is reasonably necessary for our functions and activities, including to operate, secure, administer, support and improve the Platform and Services. The types of Personal Information we collect may include:

  • Identity and contact information, including your name, email address, phone number, postal address and account identifiers. If we need to look into a concern about an account or event, we may also ask for information that confirms who you are.
  • Payment account information. For event organisers, this includes the information needed to connect and administer a Payment Processor connected account, and the verification status the Payment Processor gives us. Event organisers give their identity documents and bank details to the Payment Processor, not to us.
  • Event and profile information, including event titles, event dates, event descriptions, gift items, wishing well details, pricing tier selections, event photos, hero images, cover photos, public messages, account profile information and other information you choose to include on or through an event page.
  • Contribution and payment-related information, including contribution amounts, selected gift items, fee allocation choices, refund and chargeback records, dispute records, payout status, Payment Processor account identifiers, fraud or risk flags and related transaction metadata. Card details are collected and tokenised by the Payment Processor and are not seen by With A Bow.
  • Account, consent and usage information, including account registration data, user preferences, consent records, terms and policy acceptance records, marketing preferences, hashed IP addresses, access times, event management activity, feature use, support interactions, audit logs and technical logs.
  • Communications and content, including messages, enquiries, contribution messages, thank-you messages sent through the Sending Gratitude feature, photos attached to those messages, reports about events or content, privacy requests, support requests, feedback and other communications you send or receive through the Platform or with us.
  • Technical and device information, including IP address or hashed IP address, device and browser type, operating system, language settings, referrer URLs, session identifiers, diagnostic data, error reports, cookie and analytics identifiers and similar technical data.

Sensitive Information. We do not ask for Sensitive Information (as defined in the Privacy Act), such as information about health, racial or ethnic origin, religion, sexual orientation or criminal record, and we ask you not to include it in event pages, messages, photos or reports. This matters most when the information is about someone else. If you include Sensitive Information about another person, you must have their agreement first.

If Sensitive Information is included anyway, we handle it only to provide the feature you used (for example, showing your event page or delivering your message), to moderate content, to keep the Platform safe, or where the law requires or allows it. By choosing to include Sensitive Information about yourself, you agree to us handling it for those limited purposes. You can ask us to remove it at any time, and we may remove it ourselves.

4. How we collect Personal Information

We collect Personal Information:

  • directly from you when you register an account, create or update an event page, connect or administer a Payment Processor account, contribute to an event, send or receive messages, upload photos or other content, submit a report, make an enquiry or privacy request, opt in or out of communications, communicate with us or otherwise use the Platform;
  • automatically through your use of the Platform, including through cookies, analytics tools, error monitoring, security tools, technical logs and session records, as described in section 10;
  • from other users of the Platform, for example where an event organiser uploads content relating to an event, where a guest contributes to an event or leaves a message, or where a person reports an event or content to us;
  • from third parties, including the Payment Processor, authentication providers, analytics providers, email service providers, security and fraud-prevention providers, support providers, professional advisers, referral partners who introduced you to us, or publicly available sources, where permitted by law.

5. Purposes for which we collect, use and disclose Personal Information

We collect, use and disclose Personal Information for purposes reasonably necessary for, or directly related to, our functions and activities, including to:

  • provide, operate, host, secure, administer and support the Platform and Services;
  • create and manage accounts, record acceptance of our terms and policies, authenticate access and administer user preferences;
  • enable event organisers to create, publish, manage and share event pages, wishing wells, gift items and related event content;
  • enable guests to make contributions, choose gift items, leave messages, receive receipts and otherwise interact with event pages;
  • process contributions, service fees, refunds, chargebacks, disputes and payouts through or via the Payment Processor, and manage related fraud, risk, operational and compliance controls;
  • deliver transactional communications, receipts, security notices, support responses, Platform updates, policy notices and permitted thank-you communications;
  • investigate reports, suspected impersonation, fake events, unlawful activity, chargeback abuse, fraud, suspicious activity, security incidents, abusive content or breaches of our Terms and Conditions;
  • moderate, suspend, remove or restrict event pages, content, accounts, contributions or payouts where permitted by our Terms and Conditions or where reasonably necessary to protect users, guests, event organisers, With A Bow, the Payment Processor or the Platform;
  • calculate and pay referral fees to partners who introduced an event organiser to us, as described in section 8;
  • develop, maintain and improve the Platform and Services, including through analytics, testing, quality assurance, troubleshooting, product research, security monitoring and de-identified or aggregated reporting;
  • comply with legal and regulatory obligations, respond to lawful requests from authorities, maintain required records, resolve disputes, enforce our agreements and protect our rights and the rights of users and third parties; and
  • send marketing emails about With A Bow to account holders who have asked for them, as described in section 17.

We do not use or disclose Personal Information for other purposes unless you have agreed, you would reasonably expect it and it is related to a purpose above, or the law requires or allows it.

6. Platform visibility and user disclosures

The Platform is designed to allow event organisers to publish event pages and allow guests to contribute to those events. As part of this functionality, certain Personal Information may be visible to, or shared with, other users and recipients.

An event organiser's event title, event date, names, descriptions, gift items, event photos, cover images and public messages may be visible to anyone who can access the event page.

Unless a guest chooses to contribute anonymously, the guest's name, the gift item or cash fund they contributed towards, and the date of the contribution may be displayed on the event page and visible to anyone who can access that page. Contribution amounts, email addresses and contribution messages are not displayed on the event page. Where a guest has not chosen to contribute anonymously, the guest's name, email address, contribution details, selected gift item and message are also made available to the relevant event organiser so they can manage the event, reconcile contributions and send permitted thank-you communications.

Where a guest chooses to contribute anonymously, the guest's name and email address are not displayed on the event page and are not shown to the event organiser. The event organiser can see the contribution amount, the gift item or cash fund, the date and any message the guest has written, shown under a generic label.

Choosing anonymity changes how the contribution is displayed. With A Bow still collects and retains the guest's name, email address and contribution details, and may use and disclose that information for payment processing, receipts, record-keeping, fraud prevention, dispute handling and the other purposes described in this Privacy Policy.

You are responsible for the information you choose to share on or through the Platform, including in an event page, gift item, contribution message, thank-you message, photo, report or communication with us. Once information is shared with another user or recipient through the Platform, With A Bow may not be able to control how that person uses, stores or further discloses that information. Please do not share sensitive personal details, yours or anyone else's, unless you are comfortable doing so and have any agreement you need.

We may provide tools and settings to help you manage your privacy on the Platform, including controls relating to event pages, account details, notifications, communications, reporting and moderation. We may also implement verification, moderation, reporting and safety features to help protect users, guests, event organisers and the Platform.

7. Payments, identity verification and risk review

We use the Payment Processor to process contributions, service fees, refunds, chargebacks, disputes, connected accounts, identity verification and payouts. The Payment Processor collects and processes payment card details, identity verification information and bank account details directly from event organisers and guests. With A Bow receives limited information from the Payment Processor, such as account identifiers, verification status, transaction metadata, refund status, dispute status and payout status, to operate the Platform, manage risk and comply with our obligations.

We use automated and manual tools to support fraud prevention, platform security, risk review, dispute handling and operational monitoring. Our tools flag activity for a person on our team to look at. Some safeguards act automatically. They pause payouts when a guest disputes a payment with their bank, when a gift or a guest's recent giving goes above our review settings, when an event date is moved earlier after gifts have been received, when an event organiser changes their bank details, or when a bank returns a payment. A person on our team reviews each of these, and a person decides whether to suspend an account or event, remove content, or keep a payout on hold. If a decision like this affects you, you can ask us to explain it and to review it by contacting us using the details in section 22.

Where a contribution, account, payout, event page or other activity is subject to review, we may collect and use related Personal Information to investigate the issue, contact relevant users, liaise with the Payment Processor or other service providers, comply with applicable laws, and take action permitted by our Terms and Conditions.

8. Service providers and other disclosures

In addition to the user disclosures described above, we may disclose Personal Information to:

  • service providers and contractors who assist us in operating the Platform, including payment processors and connected-account providers (the Payment Processor), database, hosting and authentication providers (Supabase), transactional email providers (Resend), analytics providers (PostHog), error-monitoring providers (Sentry), security and fraud-prevention providers, customer support providers and other technology suppliers;
  • professional advisers, including lawyers, accountants, insurers, auditors and consultants;
  • law enforcement, regulators, government agencies, courts or dispute resolution bodies where required or authorised by law;
  • the Payment Processor, financial institutions, payment networks, card issuers or other payments participants in connection with payment processing, refunds, chargebacks, disputes, fraud prevention, risk review and payouts;
  • a referral partner who introduced an event organiser to us. We tell the partner only what we need to calculate and pay their referral fee, such as whether a paid plan was bought and the fee amounts involved. We do not give referral partners guests' names, contact details or messages. Because a referral fee can be worked out from the service fees on an event, a partner may be able to estimate the value of gifts given through an event they referred;
  • another person with your consent, or where you have directed us to make the disclosure; and
  • a third party in connection with any merger, acquisition, financing, corporate restructure, sale of all or part of our business or assets, or similar transaction, provided we take reasonable steps to ensure the recipient handles Personal Information consistently with this Privacy Policy and applicable privacy law.

We do not sell your Personal Information to third parties or disclose it to third parties for their own unrelated marketing purposes.

9. Data hosting and cross-border disclosure

The Platform uses Supabase infrastructure, and core production account data is stored in Sydney, Australia.

Some of our service providers store, process or access Personal Information outside Australia. Based on our current service stack:

  • the Payment Processor processes payment and connected-account data in the United States and Ireland, and may process it in other countries where it or its service providers operate, as listed in its privacy policy;
  • Resend sends our emails through Japan, and stores email data, including message content and delivery records, in the United States;
  • PostHog processes product analytics data in the European Union (Germany);
  • Sentry processes website error reports in the European Union (Germany); and
  • these providers may also access information from other countries, including the United States, for support and security purposes.

Before we disclose Personal Information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including by using providers bound by data protection terms. We do not ask you to consent to overseas disclosure in place of taking those steps.

We may also disclose Personal Information to law enforcement, regulators, courts or other authorities in Australia or overseas where required or authorised by law.

10. Cookies, analytics, session recording and error monitoring

We use cookies and similar technologies to operate the Platform, authenticate sessions, keep you signed in, support payment processing and fraud prevention, remember your settings and monitor security. These are essential for the Platform to function and cannot be switched off through our systems.

We also use PostHog, a product analytics service, to understand how the Platform is used and to improve it. Where you have not accepted analytics, PostHog is not loaded in your browser: no cookie is set, no analytics identifier is created, and your browser makes no request to PostHog. Separately, our own servers record a small number of operational events about contributions and payments, identified only by internal account and contribution references, so that we can trace and correct faults on the payment path. If you accepted previously and later decline, we remove PostHog cookies and stored identifiers from your browser.

Where you accept, PostHog collects information about how you use the Platform, including pages viewed, features used, clicks and similar interactions, and heatmaps showing where visitors click and scroll. For account holders this is linked to your account identifier. Guests are not identified. Your IP address is anonymised before it is stored.

We also record browsing sessions where you have accepted analytics. A session recording is a replay of the pages you saw and the actions you took, which we use to diagnose faults and improve the Platform. Text you type into forms is masked before it leaves your browser, so we do not receive passwords, card details or the contents of messages you write. We do not record browser console output. Session recordings are kept for 30 days and then deleted.

PostHog processes this information in the European Union.

We also use Sentry, an error-monitoring service, to detect and fix faults in the Platform. This runs separately from your analytics choice and does not depend on it, because its purpose is to keep the Platform working rather than to analyse how you use it. Sentry sets no cookies and stores nothing in your browser. Your browser sends Sentry a report only when an error occurs. A report contains the error message, the place in our code where it happened, your browser and operating system, your language and time zone, and the version of the Platform you were using. We configure Sentry not to collect your account identity, cookies, the page address, form contents or the sequence of actions you took, and it does not record browsing sessions. Sentry does not store your IP address, but it may record an approximate location at country level derived from your connection. Error messages are written by us and are not intended to contain Personal Information. Sentry processes these reports in the European Union (Germany) and deletes them after 30 days.

You may adjust your browser settings to refuse some or all cookies. This may affect authentication, payments and fraud-prevention features. If you want to change your analytics choice after making it, or ask us to delete analytics data associated with you, contact us using the details in section 22.

11. Sending Gratitude and photos

The Sending Gratitude feature allows event organisers to send thank-you communications to guests or contributors who have contributed to their event. To deliver those communications, we may use the contributor's name, email address, contribution details, message content and any photo or message the event organiser chooses to include.

Photos uploaded through the Sending Gratitude feature are stored securely and may be made available to the intended recipient through a time-limited signed link. Hero images and event cover photos may be stored in a separate public location because they are designed to be visible on event pages. Signed links, photos and related content may remain available for the periods notified to the user or recipient, unless deleted or expired earlier in accordance with our retention practices.

When you make a contribution to an event, you acknowledge that the relevant event organiser may use your contact details to send you permitted thank-you communications through the Platform. We do not use contributor contact details for With A Bow marketing unless the contributor has asked us to.

12. Reports about events or content

If a person submits a report about an event, user, contribution, message or other content on the Platform, we may collect the reporter's name and contact details, the details of the report, supporting information and related technical information. We use this information to assess the report, contact the reporter for clarification, investigate the issue, contact relevant users, moderate content, suspend accounts or events, liaise with the Payment Processor or other providers, and take any other action we consider appropriate under our Terms and Conditions or applicable law.

We may share the substance of a report with the relevant event organiser, user, service provider, adviser or authority where reasonably necessary to investigate or respond to the issue. We will not share a reporter's identity more broadly than necessary unless the reporter consents, the disclosure is required or authorised by law, or we consider disclosure reasonably necessary to protect users, guests, event organisers, With A Bow, the Payment Processor or the Platform.

13. Security

We implement reasonable technical and organisational measures designed to protect Personal Information against unauthorised access, modification or disclosure, and against misuse, interference and loss. These measures may include access controls, encryption in transit and at rest where appropriate, secure hosting, Row Level Security, administrative multi-factor authentication, secret management, logging, monitoring, operational security reviews and incident response processes.

No method of transmission or storage is completely secure. You are responsible for maintaining the security of your account credentials. We recommend using a strong, unique password and enabling any additional security features we make available.

14. Data retention

We retain Personal Information for as long as reasonably necessary to provide the Services, fulfil the purposes described in this Privacy Policy, comply with legal and regulatory obligations, resolve disputes, manage fraud and security risks, and enforce our agreements. Our Records Management Policy, at withabow.com.au/records-management-policy, explains how we apply these periods.

Event records. We keep the financial and transaction records for each event, including contribution records, payment records, fee records, refund and dispute records and related transaction details, for seven years after that event closes to contributions. We then delete them. Each event is counted on its own, so creating a new event does not extend how long we keep the records of an earlier one.

Your account. We keep your account for seven years after your most recent event closes to contributions. If you have not created another event in that time, we delete your account and the personal information held in it. Creating a new event starts that seven years again from the date the new event closes. If you create an account and never create an event, we keep your account for two years and then delete it.

Session recordings and error reports. Session recordings in PostHog and error reports in Sentry (see section 10) are deleted after 30 days.

We keep these records because we are required to keep records that record and explain our transactions, and because they may be needed for tax, dispute, fraud prevention or audit purposes.

When you close your account or ask us to delete your information, we will delete or de-identify your Personal Information within a reasonable period, except for records we must keep for the periods above or while a dispute, investigation or legal requirement is open. Some information may remain in backups for a limited period as part of our ordinary backup and disaster recovery processes, and is deleted when those backups expire.

15. Access, correction and deletion

You can ask us for access to the Personal Information we hold about you, ask us to correct it, or ask us to delete it. You can do this in any of these ways:

  • using the "Request my data" option on this page;
  • updating your details in your account settings, for information shown there; or
  • emailing hello@withabow.com.au.

You do not need to use a particular form or give a reason, and we do not charge you to make a request, to correct your information or to give you access.

Confirming who you are. We need to be satisfied a request comes from you, or from someone authorised to act for you, before we act on it. For requests made using "Request my data", we send a one-time link to the email address named in the request. The link is valid for 24 hours. Requests not confirmed within 7 days are deleted, and you are welcome to make a new one.

If you cannot use the email link, for example because you no longer have access to that email address, your account may have been compromised, you are acting for someone else, or you never had an account, email us and we will agree another way to confirm who you are. We will ask for no more information than we need, and where possible we will look at a document rather than keep a copy.

Our response. We will respond within 30 days. We may redact or withhold information where necessary to protect another person's privacy or where the law permits or requires it.

If we refuse a request, or cannot give access in the way you asked, we will tell you in writing why (unless it would be unreasonable to do so) and how you can complain.

If we refuse to correct information, you can ask us to attach a statement to it saying you believe it is inaccurate, out of date, incomplete, irrelevant or misleading, and we will take reasonable steps to do so so that anyone using the information can see it.

If we correct information that we previously gave to another organisation covered by the Privacy Act, we will tell that organisation if you ask us to, unless that is impracticable or unlawful.

16. Notifiable data breaches

If we become aware of a data breach involving Personal Information that is likely to result in serious harm, we will assess the incident promptly and, where required under the Notifiable Data Breaches scheme in the Privacy Act, notify affected individuals and the Office of the Australian Information Commissioner (OAIC). We will also take reasonable steps to contain, investigate and address the incident.

17. Direct marketing

We send marketing emails about With A Bow, such as new features and offers, only to account holders who have asked for them. You can ask for them by ticking the box when you sign up or by turning them on in your account settings. We do not send marketing emails to guests who have not asked for them.

You can stop marketing emails at any time by turning them off in your account settings, by using the unsubscribe link included in every marketing email we send, or by contacting us. We will act on your request promptly, and within 5 business days.

Service emails are part of providing the Platform and do not carry an unsubscribe link. They include receipts, payment updates, security alerts, policy notices, support messages, account notices, dispute notices and thank-you communications sent by an event organiser through the Platform. Stopping marketing emails does not stop service emails.

18. De-identified and aggregated information

We may de-identify Personal Information and create aggregated datasets, statistics and insights for purposes including service improvement, product analytics, research, reporting, fraud-risk assessment, operational monitoring and platform performance analysis. De-identified information does not identify you as an individual. We may use and disclose de-identified or aggregated information for any lawful purpose, provided we take reasonable steps to ensure it is not re-identified.

19. Third-party links and services

The Platform may contain links to third-party websites or services, including Payment Processor-hosted payment flows, Payment Processor dashboards, email links, event-related links provided by users and other third-party services. We are not responsible for the privacy practices, content or security of those third parties. We encourage you to review their privacy policies before providing Personal Information to them.

20. Children

Only people aged 18 or over can create an account. Guests do not need an account to give a gift, and we do not knowingly collect Personal Information from guests under 18.

Event pages, photos and messages can include information about children, for example on a baby shower page or in a family photo. The event organiser is responsible for having the right to share it. A parent or guardian can ask us to remove information about their child by contacting us.

If you believe a person under 18 has given us Personal Information, please contact us so we can take appropriate steps.

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on our website with a new version number and date.

If we make a significant change, we will tell account holders by email or when they next sign in, before the change takes effect where we reasonably can. If a change would involve a new use of your Personal Information that needs your consent, we will ask for it. We will not treat your continued use of the Platform as that consent.

22. How to contact us and complaints

If you have questions about this Privacy Policy, wish to make a privacy request, or have a complaint about how we have handled your Personal Information, please contact:

Privacy Officer
Alice and Bear Holdings Pty Ltd (ABN 84 701 192 896)
Email: hello@withabow.com.au

Please make your complaint in writing, including by email. We will acknowledge it promptly, investigate it, and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au or by calling 1300 363 992.

23. Definitions

For the purposes of this Privacy Policy:

  • Contribution means a cash gift or payment toward a gift item made through the Platform.
  • Event Organiser or Host means a person who creates, administers or is authorised to administer an event on the Platform and receives, or is authorised to receive, contributions for that event.
  • Guest or Contributor means a person who visits an event page, interacts with an event page, or makes or attempts to make a contribution to an event through the Platform.
  • Payment Processor means the nominated payment processor procured by us, which, as at the date of this policy is Stripe Payments Australia Pty Ltd and/or its affiliates, but includes any replacement or additional payment processor procured by With A Bow from time to time.
  • Personal Information has the meaning given in the Privacy Act and includes information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether recorded in a material form or not.
  • Platform means the With A Bow website at withabow.com.au, any related online services, event pages, payment flows, messaging tools, reporting tools, account features and other functionality provided by or through With A Bow.
  • Sensitive Information has the meaning given in the Privacy Act and includes, among other categories, information about health, racial or ethnic origin, political opinions, membership of a political association, religious beliefs, sexual orientation and criminal record.
  • Services means the registry creation, payment facilitation, payout coordination, messaging, reporting, moderation, support, risk review and related services provided through the Platform.