This Privacy Policy explains what personal information Glacier collects, how we use it, who else receives it, and the choices you have. It applies to the Glacier app and website (together, "Glacier", the "platform", or the "Service"), which are operated by the entity named in the header of this document (referred to here as "we", "us", or "our"). By using the Service you agree to the handling of your information as described here.
We collect the information we need to run a marketplace that introduces people, arranges events and bookings, and takes payment. This includes:
- Identity: your display name, your handle, and your email address. - Profile content: the things you choose to add to your profile, such as your bio, the roles you take on the platform, your specialties, any certifications, social links, and photos. - Coarse location: your suburb, city, state, country, and timezone, derived as described in the next section. - Gender, where you provide it. - Payment identifiers: the references our payment and subscription providers give us so we can link a payment or a subscription to your account. We do not store your full card number. - Device push tokens, so we can send you notifications you have asked for. - Usage counters that record how often you use certain features, which help us apply limits and keep the Service working fairly. - Reputation figures, such as attendance and no-show records, as described in our Terms of Service.
Your email address is kept private from other people on the platform. Other users never see it.
Location on Glacier works in three tiers, and it is worth being precise about each, because a flat "we never share your address" would not be true. Addresses are shared, but only in defined circumstances.
Always visible to signed-in users. Your suburb, city, state, and country are shown to other signed-in people so they can find events and services near them. A street address is never part of this.
How your location is captured. When you give permission, your device location is sampled once, at low accuracy, during onboarding. We do not track your position and we do not store it. We store only the centroid of your suburb. To turn the sampled coordinates into a suburb name, they are sent to Nominatim, a third-party geocoding service described under "Who else receives your data".
The exact address, disclosed conditionally. The precise address of an event, or a Pro's service address, is never placed on the public listing. It is released only to a defined group, at a defined moment, and the governing principle is that the exact location is disclosed only once the disclosure has been earned:
- For events, the exact address is served only to registered attendees, and only from the point the host's chosen reveal window opens. That window is at least 24 hours before the event starts, and a host may set it to 36 or 48 hours. For a short-notice event that begins sooner than its window, the address is available as soon as you register. - For a paid event, the exact location is released only after your payment has been taken. - For an online event, the passcode follows the same timing as a physical address would. The meeting link, however, is shown to an attendee once they have registered, and for a paid event once they have paid, which may be earlier than the address window. In other words, registering (and paying, where the event is paid) is what reveals the meeting link. - For a booking, the counterparty sees the exact address once the booking is confirmed, and for a paid booking that confirmation follows payment.
Never disclosed otherwise. Addresses that are stored but not attached to a confirmed booking or an imminent event are not shared with anyone else. A Pro's saved service addresses are held privately to that Pro.
An honest limit. Once an address has been disclosed to another person, it cannot be un-disclosed. If a registration is cancelled or a payment is refunded, we withdraw that person's access to the address inside the app, but we cannot retract what they have already seen.
Some of your information is visible to other signed-in users so the marketplace can work: your name, your bio and professional details, your suburb, your photos, your social links, your premium tier, any verification marker, and your reputation counters.
Other information is never shown to other users. This includes your email address, any saved addresses, your notification preferences, your gender, any moderation state on your account, and your internal usage counters.
Registrations for an event are private. A registration is visible only to the person who made it, the host of the event, and our administrators. Our administrators can access private records where it is necessary to operate the Service, resolve a dispute, or meet a legal obligation.
We do not monitor or routinely read the private messages you exchange with other people on Glacier. We access private communications only where it is necessary to investigate a safety concern, prevent abuse, resolve a dispute, or meet a legal obligation.
We share personal information with a small number of service providers who process it on our behalf so the Service can function. We do not sell your personal information.
- Google. We use Google's Firebase platform for Authentication, Firestore, Storage, Cloud Messaging, Cloud Functions, Analytics, and App Check. Google Sign-In is offered as a way to log in. - Stripe and Stripe Connect. Card payments, and payouts to Pros, are processed here. - RevenueCat. Subscriptions and in-app purchases are managed through this provider. - Nominatim, operated by the OpenStreetMap project. Sampled coordinates are sent to this geocoding service to resolve a suburb name, as described under "Location and addresses".
We do not use advertising networks, and we do not embed third-party tracking software in the Service.
We use the Google analytics service listed under "Who else receives your data" to understand how the Service is used. We record usage events grouped by category, such as opening a screen or completing an action, so we can improve the platform. This analytics does not use an advertising identifier and is not used to track you across other apps or websites.
Our primary processing takes place in Australia, in the Google Cloud region australia-southeast1. The service providers named under "Who else receives your data" process some information in their own regions and countries. Where information is handled outside Australia, it remains subject to this policy and to the providers' own obligations to protect it.
We keep your information for as long as you have an account, and then only as long as we need to.
- Notifications are deleted automatically 14 days after they are created. - Account deletion is available to you at any time from within the app. When you ask us to delete your account, there is a 30-day grace period during which you can cancel the request. After that period, we permanently erase your profile, your posts, your attendance records, your follows, your blocks, your conversations, and your profile photo. - Financial records are kept in anonymised form for 7 years, because tax law and the need to prevent fraud require us to retain them. In that form they are no longer linked to your identity.
You have rights over your personal information, including the right to access it, to have it corrected, to have it erased, to restrict or object to how we use it, to receive a copy of it in a portable form, and to make a complaint.
You can delete your account yourself, at any time, using the account deletion tools in the app, as described under "How long we keep it".
For a copy of your data in a portable form, please email our support team, whose address is in the Contact section below. We will respond within 30 days. We are building a self-serve export tool, and we will update this policy when it is available.
If you have a concern about how we handle your information, we would like the chance to put it right, so please contact us first. You may also complain to the data protection authority where you live, such as the Office of the Australian Information Commissioner.
Glacier is intended only for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected information from a person under 18, we will delete it. If you believe a child has given us their information, please contact us.
We may update this policy from time to time, for example to reflect changes to the Service, to our service providers, or to the law. When we make a material change, we will take reasonable steps to let you know, such as by notice in the app or by updating the version and date shown at the top of this document. Continuing to use Glacier after a change takes effect means you accept the updated policy.
You can reach us about this policy, about your information, or to exercise any of your rights, at support@getglacier.app. This is our single monitored contact address for these matters.