Last updated: 29 April 2026
Data Handling Policy
A plain-language explanation of exactly what data we collect, where it goes, and how long we keep it. Read alongside our Privacy Policy for full detail.
Data we collect and where it lives
| Data type | Where stored | Retention |
|---|---|---|
| Email address | Supabase (auth) + Brevo (email) | 7 years from account creation (Supabase); until unsubscribe (Brevo) |
| Name | Supabase profile table + Brevo contact | 7 years; until unsubscribe |
| Hashed password | Supabase (auth) — bcrypt | While account active + 7 years |
| Purchase record (amount, date, product) | Supabase — product_purchases table | 7 years (legal/tax requirement) |
| Access entitlement (product, expiry) | Supabase — product_entitlements table | Duration of access + 7 years |
| Stripe session ID | Supabase — product_purchases table | 7 years |
| Card details / banking data | NOT stored by Mindspan — Stripe only | Stripe retains per their policy |
| Program usage / page views | Supabase (session logs) | 12 months rolling |
| Email open/click data | Brevo | 2 years |
| IP address (login events) | Supabase auth logs | 90 days |
| Support emails | Gmail (info@mindspan.com.au) | 7 years |
Data flows — what happens when you purchase
- You click purchase → redirected to Stripe-hosted checkout
- Stripe processes payment → sends
checkout.session.completedevent to our webhook - Our Supabase edge function receives the event, verifies the Stripe signature, and records the purchase in
product_purchases - If you were logged in at checkout, your access entitlement is granted immediately in
product_entitlements - Your name and email are added to the relevant Brevo list → triggers the email onboarding sequence
- A tax invoice is generated by Stripe and emailed to you automatically
Guest purchases (checkout without being logged in) are recorded in product_purchases. Access entitlement requires an account. Log in with the email used at checkout to link your access.
Third-party services and data processing
Supabase
All account, purchase, and entitlement data. Hosted in AWS ap-southeast-2 (Sydney). Row-level security enabled. Data does not leave Australia for primary storage. Supabase Privacy Policy →
Stripe
All payment processing. Stripe stores payment card details — we do not. Data processed in the USA under standard contractual clauses. Stripe is PCI-DSS Level 1 certified. Stripe Privacy Policy →
Brevo (Sendinblue)
Email delivery and automation. Stores your name, email, and program attributes. Data processed in the EU under GDPR with standard contractual clauses applying to Australian users. Unsubscribe at any time via any email footer link. Brevo Privacy Policy →
Vercel
Platform hosting and edge delivery. May process request metadata (IP address, headers) in the USA. No personal data is stored at the Vercel layer beyond standard web server logs. Vercel Privacy Policy →
What we do not do
- We do not sell personal data to any third party
- We do not use behavioural advertising or cross-site tracking
- We do not use advertising or social-media tracking pixels
- We do not collect health information through this platform
- We do not use personal data to train AI models
- We do not profile users for targeted advertising
Your rights
To access, correct, or delete your data, email info@mindspan.com.au. We will respond within 30 days. Some data may be retained after deletion requests where required by law (e.g., financial records for 7 years).
To unsubscribe from emails: use the unsubscribe link in any email, or email us and we will remove you from all lists within 48 hours.
Questions: info@mindspan.com.au | Mindspan Pty Ltd | Melbourne, Victoria, Australia