
Sports Where I Am Privacy Policy
Details of our Privacy Policy can be read here.
1. PURPOSE OF OUR POLICY
(a) Providing the system and services that we offer; and
(b) The normal day-to-day operations of our business.
(a) The Australian Privacy Principles set by the Australian Government for the handling of Personal Information under the Privacy Act 1988 (Cth) (Privacy Act);
(b) The regulations and principles set by the European Unionʼs General Data Protection Regulation (Regulation 2016/679) (GDPR) for the handling of Personal Data;
(c) The UK General Data Protection Regulation and the Data Protection Act 2018; and
(d) State privacy laws in the United States, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, 'CCPA').
(collectively, “Applicable Privacy Laws”)2. WHO AND WHAT THIS POLICY APPLIES TO
3. THE INFORMATION WE COLLECT
(a) Identifiers. We may collect personal details such as an individual’s name, location, date of birth, nationality, family details and other information defined as “Personal Information” in the Applicable Privacy Laws that allows us to identify who the individual is;
(b) Contact Information. We may collect information such as an individual’s email address, telephone & fax number, third-party usernames, residential, business and postal address and other information that allows us to contact the individual;
(c) Profile Information. Including when you create an account with us, or when you connect or provide us with your third-party profile details (e.g. Facebook). In these circumstances we may collect information specified on those profiles, as well as any content like messages, posts or photos you post or make available;
(d) Financial and Transactional Information. We may collect financial information related to an individual such as any bank or credit card details used to transact with us; billing address, transaction history, and purchase details and other information that allows us to transact with the individual and/or provide them with our services;
(e) Technical Information. We may collect the IP Addresses of users accessing our systems, the actions of users on our website and other digital information created by an individualʼs use of our online systems, including browser type, operating system, network activity, clickstream data, and interactions with pixels/cookies;
(f) Booking Information: We may collect information specific to bookings that are made or facilitated through us, which may include information regarding your planned itinerary, as well as other types of information such as event preferences, itinerary details, seating preferences, delivery instructions ;
(g) Statistical Information. We may collect, create, and process de-identified, aggregated, or anonymised statistical data derived from your interactions with our Services (such as general event attendance trends, platform usage patterns, purchase histories, and venue popularity). This aggregated data does not directly or indirectly reveal your identity and is used solely to analyse platform performance, improve customer experience, and optimise our ticket distribution services; and
(h) Information an individual sends us. We may collect any personal correspondence that an individual sends us, or that is sent to us by others about the individual’s activities. This includes, without limitation, information or feedback contained in communications between you and our customer support teams, which from time to time might take place over third party platforms (e.g. Facebook).
4. HOW INFORMATION IS COLLECTED
(a) Registrations/Subscriptions. When an individual registers or subscribes for a service, account, connection or other process whereby they enter Personal Information details in order to receive or access something, including a transaction;
(b) Purchases/Bookings. When an individual purchases tickets, or makes bookings with our assistance, or when we are engaged to make such purchases or bookings on behalf of individuals;
(c) Sharing with other Users. When an individual provides Personal Information to other users of the website or service;
(d) Supply. When an individual supplies us with goods or services;
(e) Contact. When an individual contacts us in any way, including without limitation through our customer service channels, by completing user surveys, leaving feedback, or participating in promotional contests;
(f) Access. When an individual accesses us physically we may require them to provide us with details for us to permit them such access. When an individual accesses us through the internet we may collect information using cookies (if relevant – an individual can adjust their browserʼs setting to accept or reject cookies) or analytical services; and/or
(g) Pixel Tags. Pixel tags enable us to send email messages in a format customers can read and they tell us whether mail has been opened. Third-party tools (e.g., Meta Pixel, Google Tag Manager) measure conversion rates and serve targeted advertisements based on your browsing habits. Our systems automatically detect and honour Global Privacy Control browser signals as valid opt-out requests under applicable US state laws.
5. WHEN PERSONAL INFORMATION IS USED & DISCLOSED
(a) Consent: we will only rely upon express, clear and informed consent. Any consent provided may specify and/or restrict the purpose, and can be withdrawn at any time without penalty. We will keep a record of when and how we got consent from an individual;
(b) Legitimate interests: we will only rely upon an identifiable legitimate interest where we can demonstrate that the processing of Personal Information is necessary to achieve it by balancing it against the individualʼs interests, rights and freedoms. We will keep a record of our legitimate interests assessments; and
(c) Contract Performance: Processing necessary to fulfill ticket orders, manage accounts, and deliver requested services.
(a) Service Providers: Cloud hostings, payment processors (e.g., Stripe, PayPal), and email delivery tools (e.g., Mailchimp, Google Workspace) located in the US and Australia.
(b) Primary Venues & Primary Brokers: Venues, teams, or primary ticketing partners strictly necessary to facilitate your physical entry into an event.
(c) Corporate Restructuring: Potential buyers or corporate successors in the event of a merger, acquisition, or asset sale.
(d) Law Enforcement and Regulatory Bodies: Where required by legal process or to investigate suspected fraud or breach of terms.
(a) The provision of goods and services between an individual and us;
(b) Verifying an individualʼs identity;
(c) Communicating with an individual about: i Their relationship with us; ii Our goods and Services; iii Our own marketing and promotions to customers and prospects; iv Offers from our partners to our customers; v Competitions, surveys and questionnaires
(d) Investigating any complaints about or made by an individual, or if we have reason to suspect that an individual is in breach of any of our terms and conditions or that an individual is or has been otherwise engaged in any unlawful activity; and/or
(e) As required or permitted by Applicable Privacy Laws.
(a) Where the disclosure is necessary to provide you with services that you have requested, and we have agreed to provide;
(b) Where the disclosure is necessary to improve our service delivery and business practices, though in these circumstances we will endeavour to de-identify any personal information before disclosing it;
(c) Where we reasonably believe that an individual may be engaged in fraudulent, deceptive or unlawful activity that a governmental authority should be made aware of;
(d) As required by Applicable Privacy Laws including in compliance with court orders, statutory tax reporting, or government mandates; and/or
(e) In order to sell our business (in that we may need to transfer Personal Information to a new owner).
6. OPTING “IN” OR “OUT”
(a) Opt In. Where relevant, the individual will have the right to choose to have information collected and/or receive information from us; or
(b) Opt Out. Where relevant, the individual will have the right to choose to exclude himself or herself from some or all collection of information and/or receiving information from us.
7. THE SAFETY & SECURITY OF PERSONAL INFORMATION
(a) We will immediately establish the likelihood and severity of the resulting risk to wider rights and freedoms of natural persons;
(b) If we determine there is a risk from the security breach, then we will immediately notify the relevant supervisory authority and provide all relevant information on the particular breach, and by no later than 72 hours after having first become aware of the breach;
(c) If we determine there is a high risk from the security breach (a higher threshold than set for notifying supervisory authorities), we will immediately notify the affected individuals and provide all relevant information on the particular breach without undue delay.
8. YOUR DATA RIGHTS AND REMEDIES
(a) Where the Personal Information is no longer necessary in relation to the purpose for which it was originally collected and/or processed;
(b) When the individual withdraws consent;
(c) When the individual objects to the processing and there is no overriding legitimate interest for continuing the processing;
(d) The processing of the Personal Information was otherwise in breach of Applicable Privacy Laws;
(e) The Personal Information has to be erased in order to comply with a legal obligation; and/or
(f) The Personal Information is in relation to a child.
(a) To exercise the right of freedom of expression and information;
(b) To comply with a legal obligation for the performance of a public interest task or exercise of official authority.
(c) For public health purposes in the public interest;
(d) Archiving purposes in the public interest, scientific research historical research or statistical purposes; or
(e) The exercise or defence of legal claims.
9. COMPLAINTS AND DISPUTES
(a) Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
(b) United Kingdom: Information Commissioner’s Office (ICO) — www.ico.org.uk
(c) European Union: Your national Data Protection Authority (DPA)
(d) United States: The Federal Trade Commission (FTC) or your State Attorney General.
10. CONTACTING INDIVIDUALS
11. CONTACTING US
Global Data Protection Officer WhereIAm Group Pty Ltd PO Box 1200
Windsor VIC 3141 privacy@sportswhereiam.com
You may contact the Data Protection Officer by email in the first instance.
12. ADDITIONS TO THIS POLICY

Sports Where I Am is a registered trademark of Where I Am Group © 2025 WhereIam Group Pty Ltd.