Book a demo

Privacy Policy

EventCheck - Operations Control Board
Effective 11 July 2026 · Last updated 11 July 2026

1. Who we are

EventCheck is operated by RANDAZZO, BAILEY FITZGERALD as a sole trader, trading as "EventCheck" (ABN 29 982 442 983) ("EventCheck", "we", "us", "our"). We are based in Western Australia.

This Privacy Policy explains how we collect, use, hold, disclose and protect personal information in connection with the Operations Control Board platform and related websites, mobile/SMS interfaces and services (together, the "Platform"). We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Contact:bailey@eventcheck.io · https://eventcheck.io

2. What the Platform does (so you know what we handle)

The Operations Control Board is a real-time operations and incident-management platform used by organisers of live events (such as marathons, triathlons, cycling and running events) to run their event-day "control room". The Platform's features may be added to, changed, removed or configured differently over time, but they are broadly designed to help authorised operators coordinate event-day operations - for example, without limitation, logging and tracking incidents, managing schedules, resources and field communications (including operational SMS), generating AI-assisted summaries, and publishing limited public information such as a road-closure map or schedule. This policy covers how we handle personal information across the Platform's features generally, not only the examples given here.

Because of what the Platform does, the information handled through it can include details about real incidents, the locations of incidents and people, and - in free-text incident notes - information about a person's health, safety or welfare.

3. Our two roles: "for the organiser" vs "our own"

The Platform is provided to event organisers (our "Customers"). We handle information in two capacities:

4. Whose information we handle

Account holders and operators (the organiser's admins/operators); staff, crew and volunteers; members of the public and participants who text an event's SMS line or whose details are recorded (for example a participant name and race number in a withdrawal, or a person referred to in an incident note); third-party contacts an organiser records; and visitors to public schedule or closure pages.

5. Information we collect

Not every item applies to every person.

5.1 Account and identity - first and last name (or display name); mobile number (E.164) and/or email; a one-time passcode (OTP) sent by SMS or email to verify you; for email accounts, a password (we never see it in readable form - it is hashed by our authentication provider, Supabase Auth); your role and permissions, the events/organisations you belong to, invitation status/PIN, who invited you, and the dates you were added, accepted or deactivated.

5.2 Profile and personnel - display name, contact phone/email and role; for people recorded as event personnel, operational details such as team or assignment, status and notes, and (where used) shift or presence information, including clock-on/clock-off times that can indicate presence and approximate location during an event.

5.3 Event operational content (organiser-controlled) - operational event records created and managed for the event, such as incidents and incident logs (including an incident reference, category, priority, status, who reported or is handling it, a short summary and free-text notes, and a timestamped history of updates, actions, escalations, handovers and resolutions). Free-text incident summaries, notes and logs may contain information about a person's health, injury, medical treatment, welfare or safety, and may identify individuals. Other operational records include schedules, contacts, personnel, resources and vehicles, and related event configuration.

5.4 Location - location data, including GPS coordinates associated with incidents and other operational records, geolocation (EXIF) metadata extracted from uploaded photos where present, map and route data, and approximate staff presence inferred from activity during an event.

5.5 Communications (SMS) - inbound and outbound SMS handled for an event, including phone numbers, the full message body and any media (MMS images); the name, role and participant type a person provides when joining an event's SMS line; AI-generated classifications or metadata attached to messages (such as a severity, a short summary or a suggested action); and broadcast messages and delivery-status information from our SMS provider.

5.6 Uploaded files and media - files and images uploaded to or generated in the Platform (for example incident photos, documents and reports) and stored in our cloud storage, which is private by default, with a limited area intentionally public for event branding.

5.7 AI assistant interactions - where AI features are used, the conversation history and the record of any tool actions the assistant proposed or performed, with the relevant event data those features drew upon.

5.8 Technical, security and usage - technical data such as authentication and session tokens and small functional settings stored in your browser to keep you signed in and remember preferences; notification subscriptions where you enable them; identifiers for connected or paired display devices; and, for public pages, a hashed (not plain-text) IP address, browser/device type, the page and time, used for security, rate-limiting and basic usage measurement; and audit/access logs of significant actions (who did what and when) plus operational logs used to diagnose and secure the Platform.

We do not use third-party advertising, analytics or tracking SDKs (such as Google Analytics or Meta pixels), and the Platform does not use cookies for tracking or advertising. See section 12.

6. Sensitive information (including health)

Some information handled through the Platform is "sensitive information" under the Privacy Act - in particular health information that may appear in incident summaries, notes, logs and medical-related fields. We collect, hold and disclose it only to provide the Platform to the event organiser and at the organiser's direction. Where consent is required to collect sensitive information, the event organiser is responsible for ensuring an appropriate basis or consent exists. We restrict access to such information within an event to authorised members of that event and apply the security measures in section 11.

7. How and why we use information

To create, authenticate and secure accounts and verify identity; to provide the Platform's features (such as incident management, scheduling, operational records, mapping, reporting and public information pages); to send and receive operational SMS for an event and triage inbound messages; to generate AI-assisted classifications, analysis and incident summaries (section 8); to resolve coordinates to map locations and show weather and maps; to deliver notifications you enable; to maintain audit trails, ensure security, prevent and investigate misuse and enforce our terms; to provide support, operate, improve and meter usage of the Platform (for example SMS and AI usage); and to comply with legal obligations. Under the APPs we generally collect personal information because it is reasonably necessary to provide the Platform.

8. Artificial intelligence (AI) features and our AI provider

The Platform offers AI features: automatic classification and summarisation of inbound SMS, an operator assistant, periodic "ops analysis" of incident data, and AI-generated incident summary reports. To provide them, relevant text - which can include incident summaries and notes, incident logs, SMS content, operator notes and, for certain features, uploaded photos - is sent to our AI provider, Anthropic (the "Claude" API), for processing. Important points:

How Anthropic handles this data (commercial API): Anthropic processes the data as our sub-processor under a Data Processing Addendum that is incorporated into its Commercial Terms. Anthropic does not use data submitted through its API to train its models, and for standard API calls retains API inputs and outputs for up to 30 days for trust-and-safety purposes and then deletes them (limited exceptions apply, for example content flagged for policy/safety reasons may be retained for up to two years, or where law requires). We make these AI calls from our secure backend, not from your browser.

9. When we disclose information, and our sub-processors

We do not sell personal information. We disclose it: within an event (to the authorised members of that event and the organiser's admins, subject to role and per-page access controls); to service providers (sub-processors) who help us run the Platform (they may process information outside Australia - see section 14); for public features the organiser enables (a public schedule or road-closure map shows only the limited information published, not incident details or operator PII, and may be PIN-gated); to comply with law or protect rights, property or safety; and in a business transfer (subject to this policy).

The Platform relies on a small number of trusted service providers (sub-processors) to deliver specific functions - for example cloud hosting, database, authentication and file storage (provided through Supabase, with our primary database and file storage held on Amazon Web Services in Sydney, Australia); content delivery and network security; SMS/MMS messaging (for example via Twilio); AI processing (via Anthropic's "Claude" API); transactional and invitation email; mapping, geocoding and location services; and weather data. We share with each provider only the information it needs for its function, and some providers process data outside Australia (see section 14). For security and commercial reasons we do not publish a full itemised vendor list here; a current, detailed list of our sub-processors, including their roles and processing locations, is maintained in Annex B of our Data Processing Addendum and is available to business customers on request.

10. How long we keep information

We retain personal information for as long as needed to provide the Platform to the relevant organiser and to meet that organiser's operational, audit, insurance and legal needs, and as required by law.

Because the Platform is an incident-management and audit system, event records (incidents, logs, SMS, AI outputs, audit logs and uploaded files) are retained to preserve their integrity and are not deleted automatically on a short cycle; when a person's membership of an event is removed, the record is generally deactivated rather than permanently deleted, so the audit trail is preserved.

We retain event data for the period the organiser requires for those purposes, and we delete or de-identify it on the organiser's instruction, or within 7 years after the relevant event or the closure of the organiser's account, whichever the organiser specifies - unless a longer period is required by law. Account and profile information is retained while an account is active and for a reasonable period afterwards. You may make the requests in section 13; where information is not part of an incident/audit record, we will delete or de-identify it on request (see section 13).

11. How we protect information

We take reasonable steps to protect personal information, including: encryption in transit (HTTPS/TLS with HSTS enforced); Row-Level Security in our database so users only access data for events they belong to; authentication and access control via signed tokens (JWT) from Supabase Auth, role-based permissions and per-page restrictions, with sensitive admin functions restricted to privileged roles; password security handled by Supabase Auth using industry-standard salted hashing (we never store passwords in readable form); private storage with file-type and size limits; secrets management using a per-environment vault (third-party keys are never exposed to the browser or committed to source code); hardened web security headers, rate limiting on public endpoints, signature verification on inbound SMS webhooks, validation of media URLs, sanitisation of text before AI processing, and tamper-resistant audit logs; encryption at rest of the database and file storage (AES-256, provided by our AWS cloud infrastructure); and automated daily backups of the database with restricted, controlled access. While we are not yet independently certified, we design and operate the Platform consistent with the control practices behind recognised standards such as SOC 2 and ISO/IEC 27001, and intend to pursue formal certification as we grow. No method of transmission or storage is completely secure; you are responsible for keeping your login credentials and devices secure. If you believe your account has been compromised, contact bailey@eventcheck.io.

12. Cookies and local storage

The Platform uses your browser's local storage and similar technologies for essential and functional purposes only - keeping you signed in (a session token via local storage), remembering your preferences, caching data so the app works with poor connectivity, delivering notifications you enable, and pairing connected display devices. It does not use tracking or advertising cookies and does not use third-party analytics SDKs. Some embedded third-party resources (such as map tiles, web fonts, and location and QR-code services) may set their own cookies or receive your IP address as a normal part of delivering that content, under their own policies. You can clear cookies/local storage and unregister service workers in your browser settings; doing so will sign you out, clear offline caches and reset preferences. Because this storage is essential, disabling it may prevent you using the Platform.

13. Your privacy rights and choices

Subject to applicable law, you may access the personal information we hold about you and request a copy; correct information that is inaccurate or out of date; request deletion of your information; object to or restrict certain processing; withdraw consent where we rely on it; and opt out of non-essential communications.

Because much of the information in the Platform is controlled by the event organiser, we may refer your request to the relevant organiser or ask you to contact them, and we will help them respond. We verify identity before actioning a request and respond within the timeframes required by law.

How deletion works here. The Platform deliberately does not offer self-service deletion, because it is an incident, audit and compliance log where record integrity matters. We distinguish: Account/profile information not tied to an incident record (for example your contact details) - we will delete or de-identify it on request. Operational incident, log and audit records - we may decline or limit deletion where retention is needed for the integrity of the records, the organiser's legal/insurance/record-keeping obligations, or the establishment, exercise or defence of legal claims; where we decline, we will tell you why. We can usually de-identify or restrict access instead.

To exercise any right, contact bailey@eventcheck.io. If you have a privacy concern, contact us first; if you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

14. Overseas disclosure

Several sub-processors (section 9) are located in or process data in countries outside Australia, including the United States, the United Kingdom and other locations via global cloud and content-delivery networks. By using the Platform you acknowledge your information may be processed in these countries. We take reasonable steps so that overseas recipients handle personal information consistently with the APPs and, where the GDPR applies, rely on appropriate transfer mechanisms (such as Standard Contractual Clauses). Your core event data - our primary database and file storage - is hosted on Amazon Web Services (AWS) in the Sydney region (ap-southeast-2) via our managed database provider, Supabase, so it is stored onshore in Australia. The overseas disclosures above are limited to the specific sub-processors described in section 9 (for example AI processing, SMS, email and mapping).

15. Children and minors

The Platform is a business tool for organisers and their authorised personnel and is not directed to children. However, event data (for example a participant record or incident note at a community or youth event) may include information about a minor; where this occurs, that information is provided and controlled by the event organiser, who is responsible for having an appropriate basis (including any necessary parental/guardian consent).

16. Third-party links and changes

The Platform may link to or embed third-party services (such as maps or an organiser's chosen integrations), which have their own privacy policies. We may update this policy from time to time and will post the updated version with a new date; where changes are material we will take reasonable steps to notify Customers.

17. Contact

EventCheck - operated by RANDAZZO, BAILEY FITZGERALD (sole trader), ABN 29 982 442 983 · Email: bailey@eventcheck.io · Web: https://eventcheck.io

EventCheck
EventCheck
×

Get EventCheck for your event

Leave your details and we'll reach out. Takes 20 seconds.

* Required. We'll only use your details to get in touch.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
EventCheck live operations board