Privacy policy
What information is collected, why it is used, who receives it and how to exercise your privacy rights.
Version 1.1 · Updated 7 September 2026. Published by Glu IO Pty. Ltd., the owner and operator accountable for Helper Shifts. Committee-specific agreements take effect when signed.
Who handles your information
Helper Shifts provides volunteer scheduling for independent parent committees, parents’ associations, clubs and community groups. The group organiser decides why to run an event, who may administer it and how to use its volunteer list. Committee use does not create a relationship with any school or give a school access to volunteer records. Contact the committee organiser about bookings and Glu IO Pty. Ltd. about service privacy or security.
Glu IO Pty. Ltd. owns and operates Helper Shifts and is ultimately accountable for the service, including personal information handling, service security and the providers it engages. It handles account administration and hosts group records to provide the service. The organiser’s own privacy notices also apply.
Service operator: Glu IO Pty. Ltd. — owner and operator of Helper Shifts, ultimately accountable for the service.
Privacy, security and committee enquiries: A monitored service contact is awaiting confirmation. Existing users can contact their group organiser through their usual committee communication channel.
Include your group address, the nature of your request and a safe way to reply. Do not send passwords, sign-in links, student records or identity documents in an initial message.
Information we collect
- Volunteer bookings: name, email address, phone number, selected shifts, group association, consent flag and registration time.
- Organiser accounts: name, email, password hash, group memberships and owner/admin role. Verification, invitation and password-reset records support account access.
- Event information: group name and address, event title, description, location, dates, shift times and capacity. Published event information is public.
- Technical information: request metadata such as IP address, browser information, timestamps and errors may be processed by hosting infrastructure. Helper access-email abuse controls store keyed digests of email and IP identifiers; these are pseudonymous, not anonymous.
- Correspondence: information you choose to provide when requesting support or making a privacy enquiry.
Information comes directly from you, an authorised group organiser, or your browser when you use the service. The booking form requires contact details to coordinate volunteers. If you do not want to provide them online, ask the organiser for an alternative arrangement; online booking cannot proceed without required fields. General information pages can be read without an account or identifying yourself by name.
Uses and disclosures
Information is used to register volunteers, show their own shifts, let authorised organisers coordinate events and export attendance lists, verify account access, send service emails, prevent abuse, resolve support requests and meet applicable legal obligations.
Group owners and co-admins can access helpers’ names, email addresses, phone numbers and scheduled shifts, and export CSV files. Their permitted use under the terms is limited to administering those shifts and contacting helpers about reminders, instructions, changes or cancellations. They must not sell, rent, publish or share these details outside authorised shift administration, or use them for unrelated marketing, fundraising, mailing lists or recruitment for other events. Legally required disclosures are addressed in the terms.
Volunteers do not receive the organiser’s volunteer list through the public booking pages. Administrators must protect downloaded copies and avoid exposing helpers’ contact details to other recipients when sending group messages. See the administrator contact rules. Booking consent is not consent to unrelated communications.
Infrastructure and email providers process data to operate the service. Service personnel may require access for support, maintenance, security or lawful requests. Access should be limited to authorised personnel with a need to know; a reviewed personnel-access process is still required. Information may also be disclosed where law requires or authorises it.
The policy prohibits selling personal information, targeted advertising, unrelated marketing and training AI models on group or volunteer information. No advertising, analytics SDK or AI integration was identified in the reviewed application. This is not an audit of providers’ independent operations.
Data location and overseas handling
Helper Shifts data is stored within Australia. Application records, database backups and operational logs are hosted in AWS Sydney. Application processing and automated service-email submission also take place in Sydney. External email delivery, support access and global DNS can involve overseas handling.
See the data residency and subprocessor register. A committee needing all handling, including external providers and remote access, restricted to Australia must agree that scope in writing before use. A local database alone would not establish that all processing, backups or remote access stay in Australia.
Cookies and browser storage
The organiser session cookie, helpershifts_session, expires after eight hours. The helper portal cookie, helpershifts_helper, expires after 30 days. They are signed, HTTP-only session tokens; they are not encrypted containers. Production configuration enables Secure cookies. They may be shared across Helper Shifts subdomains, while server-side authorisation checks restrict group access.
The optional “Remember my details on this device” setting saves your name, email and phone in browser local storage for the current site. It has no automatic expiry. Leave it off on shared devices. Untick it or use “Not you? Clear” to remove remembered information; clearing site data in browser settings also removes it. Existing remembered details from earlier versions may still be present. Consent is requested again for each new booking.
Organiser event-editor drafts also use local storage until cleared. Signing out removes the relevant session cookie but does not erase all local storage or downloaded files. No advertising cookies or third-party font requests are included in this version. Your email provider independently handles emails delivered to your inbox.
Retention and protection
Booking records currently remain until deleted through supported functionality or an authorised administrative process. Deleting an event removes its associated registrations in the application database. Cancelling an eligible shift removes that registration; it does not erase other bookings, accounts, emails, exports or backup copies.
There is no verified automatic whole-account retention or backup-erasure schedule. Infrastructure code configures application logs for 14 days, subject to deployment settings. See the retention and deletion schedule for limitations and committee recordkeeping responsibilities.
Reviewed controls include password hashing, signed sessions, group-scoped queries, input validation and HTTPS infrastructure configuration. Production database role restrictions, backup recovery, staff access and security operations still need evidence. No system can eliminate every security risk.
Access, correction and complaints
Contact your group organiser to request a copy of your volunteer records, correct contact details, withdraw booking consent or request deletion. Use the service contact for account information, service security concerns, complaints about the operator, or unresolved organiser requests. Identify your group and the affected information without sending unnecessary identity documents.
The procedure is to verify identity proportionately, locate the information, consult the organiser where appropriate, and explain the outcome, any lawful refusal or retention requirement and available complaint options. Withdrawing consent stops future consent-based use; it does not undo lawful past processing or override required record retention. Applicable legal deadlines and any agreed committee response periods apply.
You can complain to the OAIC where it has jurisdiction, or another relevant regulator where it has jurisdiction. The operator’s coverage under the Privacy Act, including any small-business exception or contractual obligations, needs legal confirmation. This policy does not limit rights you have under applicable law.
Children and policy changes
The intended use is adult volunteer coordination. Do not put student names, health information, learning records, identity documents or working-with-children check documents into event titles, descriptions or contact fields. Organisers must arrange any safeguarding permissions and volunteer screening required for their activities; Helper Shifts does not perform those checks. There is no age-verification mechanism; an adult-use statement alone does not prevent children accessing the service.
If children’s information is entered accidentally, contact the organiser and service operator to arrange assessment and appropriate removal. Any proposed student-facing use requires a separate privacy, safety and legal assessment.
Material policy changes should be notified to affected organisers before taking effect, with a dated version retained. This policy takes effect on 7 September 2026. Its structure follows the Australian Privacy Principles; this is not a claim that every applicable obligation has been satisfied.
Document history: version 1.1 — clarified independent committee use and contact responsibilities, 7 September 2026; version 1.0 — published documents, Australian data storage and Glu IO Pty. Ltd. operator identity, 7 September 2026; version 0.2 — clarified administrator contact-use restrictions, 7 September 2026; version 0.1 — initial publication, 6 September 2026. Print or save this page as PDF to retain this version. Committee agreements and applicable law take priority over general guidance.