Draft for legal review. These data processing terms are a draft. They have not yet been reviewed by a lawyer and may change before they take effect.
Last updated: 4 October 2026 (draft)
1. What these terms cover
These terms explain how ZenByte Australia Pty Ltd (ABN 38 698 761 956) (“ZenByte”, “we”, “us”) handles the personal information a club keeps in MemberCrew about its members and others (“member data”). They form part of our terms of service with each club.
2. Who controls the data
- The club decides what member data it collects and why, and controls it.
- ZenByte stores and processes member data on the club’s behalf, only to provide MemberCrew.
3. How we process member data
- We process member data only to provide MemberCrew to the club, and as the club asks through the way it uses MemberCrew, unless the law requires otherwise.
- We do not sell member data or use it for our own marketing.
- Our staff access a club’s member data only to give the club support.
4. Where member data is held
The main MemberCrew database is in Sydney (Supabase, Australia region ap-southeast-2), and the service’s server functions run in Sydney (Vercel). Our providers may also process information in other countries, as set out below. Our privacy policy has more detail.
5. Providers we use
| Provider | What it does | Where it may process information |
|---|---|---|
| Supabase | The main MemberCrew database | Stored and primarily processed in Sydney; its terms allow processing wherever Supabase or its providers have facilities, including the United States |
| Vercel | Hosting, page delivery and server functions | Server functions in Sydney; page delivery through a worldwide network; primary processing facilities in the United States |
| Stripe | Payments into each club’s own Stripe account, and our billing of clubs | Australia, the United States, India and other countries where Stripe operates |
| Resend | Sending email from MemberCrew, once email is switched on | Account data, email details and logs in the United States; sending from the United States, Ireland, Brazil or Japan |
| Cloudflare | Turnstile spam checks on forms | Primarily the United States and the European Economic Area |
| Vercel Web Analytics | Cookieless visitor statistics for the website (not member data) | As for Vercel |
Placeholder: how and when clubs will be told about a new or changed provider
6. Security
- Role-based access. Each person who logs in for the club sees only what their role allows.
- An activity log. Every change to the club’s records is recorded, showing who made it and when.
- Export. The club can export all of its records at any time.
7. Data breaches
If we become aware of a data breach affecting the club’s member data, we will tell the club promptly. We follow the Notifiable Data Breaches scheme and work with the club on any notices that need to be given to members or to the Office of the Australian Information Commissioner.
8. Members’ requests
Members with questions or requests about their information should go to their club first. If a member contacts us, we will refer them to the club. We help the club respond, for example by helping it find, export or correct a member’s records.
9. Keeping and deleting member data
- Clubs on the SA Conditional Registration Scheme must keep records for five years, so activity and compliance records are kept at least that long.
- When a club leaves MemberCrew, it gets a full export of its records. Its data is then deleted on request, once the club confirms it has the export.
10. Contact
Questions about these terms: support@membercrew.au.
ZenByte Australia Pty Ltd, ABN 38 698 761 956, Adelaide, South Australia.