Revilob Pty Ltd trading as Sweepa Sports · ABN 94 629 582 430 · Last updated 24 August 2026 · v95c26303
Revilob Pty Ltd trading as Sweepa Sports (ABN 94 629 582 430) ("Sweepa", "we", "us") provides a sports venue management platform. This policy explains how we handle personal information, and how we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Please read section 1 first. Sweepa handles personal information in two very different roles, and which role applies changes who you should contact about your information.
We are responsible for personal information ("we decide what happens to it") when you visit sweepa.io, submit an enquiry or proposal request, apply for a Sweepa account, are named as a contact at one of our tenant venues, use our demo environment, or contact our support team. For that information, we are the APP entity responsible and this policy governs how we handle it.
We handle personal information on behalf of a venue ("the venue decides what happens to it") when a sports venue, club or operator uses Sweepa to run its bookings, registrations, competitions, programs, payments and communications. The personal information of that venue's own customers — players, parents, guardians, team members, hirers and enquirers — is collected and controlled by the venue, under the venue's own privacy policy and privacy collection notice. We hold and process it on the venue's instructions, as its service provider, and we do not use it for our own purposes.
If you are a customer of a venue that uses Sweepa and you want to access, correct or delete your information, or make a complaint about how it is used, contact the venue first. We will assist the venue to respond. If you cannot identify or reach the venue, use our contact form and we will try to direct you.
Prospective and current tenant venues, and their people: name, role or title, work email address, phone number, the venue or organisation name, legal entity name and ABN, the content of enquiry, demo-request and proposal forms, plan and billing metadata, and correspondence with our team.
Contract and acceptance records: when someone accepts an agreement with us electronically, we record the typed full name, the role or title typed by the signer, the email address the agreement was sent to, the acceptance timestamp, the IP address and browser user agent of the device used, and a checksum of the exact document text accepted. These records are proof of a contract and are retained as described in section 10.
Website visitors: information collected through cookies and similar technologies, described in section 6.
Demo environment users: the activity you carry out inside the shared demo tenant. Demo data is fictional and is reset on a schedule. Do not enter real personal information into the demo.
Support and administration: support conversations, and logs of privileged administrative access to tenant environments (see section 8).
We do not seek sensitive information (as defined in the Privacy Act) about tenant contacts in the ordinary course. We do not collect government identifiers from tenant contacts. Payment card numbers never reach our systems — they are collected directly by Stripe.
When a venue uses Sweepa, the information it collects from its own customers may include names, contact details, addresses, dates of birth, participant and team details, emergency contact details, booking, registration and attendance records, payment records and refund history, communications history (email and SMS), and — where the venue uses our phone features — call logs and recordings of calls made to or from the venue's Sweepa phone number.
It may also include information the venue chooses to collect about children and young people, including participant details supplied by a parent or guardian, and information relating to working with children checks for that venue's staff and volunteers.
We hold this information on the venue's behalf. The venue is responsible for having a lawful basis to collect it, for giving its own customers a privacy collection notice and privacy policy, for obtaining any consents required (including consents relating to children, photographs and call recording), and for meeting its own obligations under the Privacy Act and any state or territory laws that apply to it.
Directly from you, when you complete a form on sweepa.io, request a demo or a proposal, email or call us, or use the platform.
From your organisation, when a venue names you as a contact, an owner, a manager or a staff user of its Sweepa account.
Automatically, through cookies and similar technologies on sweepa.io (section 6) and through security and reliability logging on our platform.
Through our service providers, listed in section 7.
Our public forms are protected by Cloudflare Turnstile, which analyses signals from your browser to distinguish humans from automated traffic.
To provide, operate, secure and improve the Sweepa platform.
To respond to enquiries, prepare proposals, and assess account applications.
To administer contracts, including generating agreements, recording acceptance and issuing executed copies.
To bill subscriptions and administer payments, and to provide support.
To send service, account, security and billing messages, and — where permitted — product and marketing messages you can opt out of at any time.
To detect, investigate and prevent fraud, abuse, security incidents and misuse of the platform.
To comply with our legal obligations and to establish, exercise or defend legal claims.
Some Sweepa features use AI models supplied by Anthropic to draft or summarise content for venue staff. Where we send content to that service we minimise the personal information included, and the provider does not use that content to train its models. We do not use AI to make decisions that have a legal or similarly significant effect on an individual.
We do not sell personal information.
Our marketing website uses cookies and similar technologies to understand how the site is used and to measure our advertising.
These load through Google Tag Manager and include Google Analytics 4 (pages viewed, referring site, approximate location, device and browser, and the links you click) and the Meta pixel (which records that a visit or enquiry came from a Facebook or Instagram advertisement). Both set identifiers in your browser so we can count returning visits and attribute enquiries to a campaign. We also use Cloudflare Web Analytics, which is cookieless and does not identify individual visitors.
If you reach us through an advertisement or a campaign link, the campaign parameters carried in that link (for example utm_source, utm_campaign, and click identifiers such as gclid or fbclid) are stored alongside your enquiry so we know which campaign it came from.
You can opt out at any time using your browser's cookie controls or a tracking blocker, or by setting your preferences directly with the providers through Google Ads Settings, Google Analytics Opt-out and Meta Ad Preferences. Opting out does not limit any part of sweepa.io.
The Sweepa platform itself (the venue-facing application) uses cookies only for authentication, security and essential functionality.
We disclose personal information to the service providers that help us run Sweepa. Each provider only receives the information necessary to perform its function, and is bound by contractual confidentiality and security obligations.
Supabase — database, authentication and file storage; our primary data store — Sydney, Australia
Stripe — subscription billing, and venue payment processing through Stripe Connect — Australia and United States
Vercel — application hosting and serverless compute — United States, with global edge delivery
Cloudflare — marketing site hosting, DNS, bot protection (Turnstile) and cookieless web analytics — United States, with global edge delivery
Resend — outbound transactional email and inbound email processing — United States
Twilio — SMS delivery, venue telephone numbers, voice calls and call recordings — United States
Expo — mobile push notification delivery — United States
Anthropic — AI-assisted features, with personal information minimised — United States
Upstash — rate limiting, queues and caching (technical metadata) — Australia
Sentry — application error monitoring and diagnostics — United States
Google — website analytics and advertising measurement (marketing site only) — United States
Meta Platforms — advertising measurement (marketing site only) — United States
Microsoft — email hosting and Graph API access for Sweepa's own HQ, support and founder mailboxes — United States / Global
We also disclose personal information to our professional advisers, and where we are required or authorised to do so by law, or where it is reasonably necessary to protect the safety, rights or property of any person.
If Sweepa is acquired, merged or restructured, personal information may be disclosed to the acquirer, subject to the acquirer's continued compliance with this policy or a materially equivalent one.
This list is current as at the version date shown on this page. We review it whenever we change providers, and we update this policy when we add or remove one. Tenant venues on agreements that include change notification will be notified separately as required by their agreement.
Each venue's data is logically separated from every other venue's data, and enforced at the database layer by row level security. Some plans offer a dedicated environment; where that applies it is described in the venue's agreement with us.
Members of the Sweepa team can access a tenant environment to provide support, investigate faults, and meet legal obligations. That access is restricted to authorised personnel, and administrative access to a tenant environment is logged. Privileged administrative actions require an additional authentication step.
Our demo environment contains fictional data and is reset on a schedule. Anything you enter into the demo may be visible to other demo users and will be deleted at the next reset. Do not enter real personal information into the demo.
Our primary database and file storage are hosted in Sydney, Australia.
Some of the providers listed in section 7 store or process personal information outside Australia, principally in the United States, and some deliver content through global edge networks in other countries. Before disclosing personal information to an overseas recipient we take steps that are reasonable in the circumstances to ensure the recipient handles it in a way consistent with the APPs, including entering into contractual data protection terms with that provider.
By using Sweepa, or by a venue using Sweepa, you acknowledge that personal information may be disclosed to recipients in those countries. Where APP 8.2 does not apply, we remain accountable for those disclosures under APP 8.1.
We protect personal information with encryption in transit and at rest, database level access controls including row level security, access limited to personnel who need it, and an additional authentication step for privileged administrative actions. No system is completely secure, and we cannot guarantee absolute security.
We keep personal information for as long as we need it for the purposes described in this policy, or for as long as the law requires.
Financial and tax records are retained for at least seven years, as required by Australian law.
Contract and acceptance records — including the typed name, role, timestamp, IP address, user agent and document checksum described in section 2 — are retained indefinitely by design. They are the evidence that a contract was formed, and deleting them would destroy that evidence. We retain them even after an account closes.
Deletion on request is available today, and is described in section 12. Automatic time-based deletion is not. We have defined retention periods for the categories of information we hold, but we do not yet run a process that deletes or de-identifies records once a period passes. Other personal information therefore remains until it is deleted on request, or until a venue's account closes and its data is removed on the timetable in that venue's agreement. We are building that enforcement and will update this section when it is in place.
Voicemail recordings made through venue phone features are stored by Twilio (United States) on Sweepa's behalf. Sweepa stores the recording reference and duration in our database in Sydney; we do not copy the audio into Supabase. Recordings remain on Twilio until deleted from the Twilio account. Sweepa does not currently enforce an automatic deletion schedule for voicemail recordings.
Where we hold information on behalf of a venue, retention is governed by that venue's agreement with us and its own retention obligations. On termination, data export and deletion follow the timetable in that venue's agreement.
We may send you marketing communications about Sweepa where we are permitted to do so. Every marketing email contains an unsubscribe link, and we act on unsubscribe requests promptly, consistent with the Spam Act 2003 (Cth).
Service, account, billing, security and transactional messages are not marketing, and you cannot opt out of them while you hold an account, because we need them to operate the service and meet our obligations.
We do not use or disclose personal information for the direct marketing purposes of third parties.
You can ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Use our contact form.
We will respond within a reasonable period, and within 30 days where practicable. There is no charge to make a request. If we refuse access or correction, we will tell you why in writing and how to complain.
If you use the Sweepa mobile app as a customer of a venue, you can request deletion of your account from within the app. Otherwise, use our contact form and we will handle your request.
If your request concerns information that a venue collected about you — bookings, registrations, competition entries, payments or communications with a venue — contact the venue. The venue decides what happens to that information; we can only act on the venue's instructions, though we will assist the venue to respond to you.
We may need to verify your identity before acting on a request, and we may refuse a request where the Privacy Act permits us to.
If you think we have breached the Australian Privacy Principles, or mishandled your personal information, use our contact form with the details. We will acknowledge your complaint, investigate it, and respond in writing, usually within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, telephone 1300 363 992, or GPO Box 5218, Sydney NSW 2001.
We maintain measures to detect, contain and assess suspected data breaches. If a data breach involving personal information we hold is likely to result in serious harm to any individual, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
Where a breach affects information we hold on behalf of a venue, we will notify the venue without undue delay and cooperate with it so that the applicable notification obligations are met. Agreements with venues set out how that assessment and notification is coordinated.
Sweepa is a business tool for venue operators. We do not market to children, and we do not knowingly collect personal information directly from children in our own right.
Venues collect participant information, including information about children, under their own privacy policies and consent processes. Sweepa stores and processes that information on the venue's behalf, with the safeguards described in this policy. Questions about a child's information held by a venue should go to that venue.
We may update this policy. The version number and the date it was last updated are shown on this page.
If we make a change that materially affects how we handle personal information, we will take reasonable steps to notify affected individuals and tenant venues in advance, for example by email or by a notice in the platform, before the change takes effect. Continuing to use Sweepa after a change takes effect means the updated policy applies.
Privacy enquiries, access and correction requests, and complaints: contact form
Revilob Pty Ltd trading as Sweepa Sports, ABN 94 629 582 430