Effective date: 25 August 2026
Privacy contact: [email protected]
Organisation: St. Mary of Egypt Coptic Orthodox Church, ABN 69 239 477 321, trading as St Mary’s Orthodox Church
This policy explains how we collect, hold, use and disclose personal information through the St Mary of Egypt Events website and the fundraising events it supports. We handle personal information in accordance with applicable Australian privacy law, including the Australian Privacy Principles where they apply.
Event-specific collection details are also provided in the Event Privacy Collection Notice shown before a ticket purchase.
1. Information we collect
Depending on how you use the website or attend an event, we may collect:
- your name, email address and telephone number;
- purchaser, booking, ticket and attendee details;
- dietary requirements, allergies, accessibility requirements and other important notes you choose to provide;
- answers to event registration questions;
- payment status, Stripe transaction references and limited billing details made available to us;
- event check-in and seating information;
- raffle entries, merchandise orders, auction bids, results and transaction status;
- communications you send to us;
- operational email delivery information;
- private-reference access, security and audit records;
- browser, device and network information used to operate and secure the service;
- photographs or video recordings made at an event; and
- other information you voluntarily provide.
We do not store complete payment-card numbers or card security codes.
2. How we collect information
We usually collect information directly from you when you make a booking, use a booking or attendee portal, purchase an item, enter a raffle, place an auction bid, check in or contact us.
A purchaser may also provide information about other attendees in their order. The purchaser must tell those attendees that their information is being provided and obtain consent before entering another person's sensitive or health-related information.
We may receive transaction and fraud-prevention information from Stripe, delivery information from Microsoft 365, and information from authorised church staff or volunteers who operate an event.
3. Sensitive information
Dietary requirements, allergies, disabilities and accessibility needs may be sensitive or health-related information. Providing this information is optional.
We collect and use it with consent to support catering, accessibility, attendee safety and event operations. Access is limited to people who reasonably need it, such as authorised event staff, volunteers, caterers or venue personnel.
4. Why we use information
We use personal information to:
- process bookings and transactions;
- create and manage tickets, attendees and private access references;
- manage capacity, seating and check-in;
- provide dietary, accessibility and safety arrangements;
- deliver operational event communications and reminders;
- operate raffles, merchandise sales and silent auctions;
- determine and contact winners and fulfil purchases;
- process refunds and reconcile payments;
- prevent fraud, misuse and unauthorised access;
- maintain financial, regulatory, security and audit records;
- respond to enquiries, access requests and complaints;
- meet legal, insurance and regulatory obligations; and
- protect attendees, volunteers, staff and the church.
Event registration does not add you to an unrelated promotional mailing list. We do not sell personal information.
5. Private references and account security
Booking and attendee references provide access without a conventional password. Anyone with a valid reference may be able to open the associated portal. Keep references private and contact us promptly if one is lost, disclosed or misused.
Purchasers can view and manage the attendees in their booking. An attendee using their individual reference can view and edit only their own attendee details and activity. A separate QR token is used for check-in so scanning a ticket does not reveal the portal reference.
6. Communications
We use purchaser and attendee contact details to send messages needed to provide an event, such as confirmations, receipts, tickets, reminders, attendee-information requests, changes, cancellations, refunds and relevant transaction outcomes.
These messages are operational, not unrelated marketing. Where multiple people in an order use the same email address, we may combine or deduplicate operational messages.
7. Payments
Stripe processes online payments and may collect payment-card information, billing details, transaction information, and device or fraud-prevention information under its own privacy terms.
We generally receive transaction status, references, limited customer details and information needed for reconciliation. Payment data may also be handled by card networks, banks and other payment-system participants.
8. Disclosures and service providers
We may disclose relevant information to:
- Stripe for payment processing and fraud prevention;
- Microsoft 365 and Microsoft Graph for transactional and operational email delivery;
- Oracle Cloud Infrastructure in Australia for application hosting, database storage and backups;
- venues, caterers and event suppliers where needed to deliver an event;
- authorised church staff and volunteers;
- professional advisers, auditors and insurers;
- raffle or other regulatory authorities where required;
- emergency services where necessary for health or safety; and
- government, law-enforcement or regulatory bodies where required or authorised by law.
We limit access to the information reasonably required for each person's or provider's responsibilities.
9. Storage and overseas processing
The event application, database and backups are hosted on Oracle Cloud Infrastructure in Australia. Microsoft 365 mailbox content for our Australian tenant is ordinarily stored at rest in Australia, subject to Microsoft's applicable service terms.
Stripe and other payment-system participants may process information overseas and may use several locations to provide payment, security and support services.
Confirmed overseas processing locations: United States, Ireland and India. Microsoft 365 email content for our Australian tenant is ordinarily stored in Australia. Our payment and technology providers may use authorised global infrastructure and support operations. The event website is hosted in Australia.
Where information is disclosed overseas, we take reasonable steps appropriate to our obligations and the nature of the information.
10. Website operation and security logs
The website uses essential cookies or similar storage where needed for secure sessions and service operation. We may record reference access, administrative activity, network information and errors to protect the platform and investigate problems.
We do not use this event registration information for unrelated advertising profiling.
11. Photography and video
Photography and video recording may occur at events. Images may be used on church websites, newsletters and social-media channels to communicate parish and fundraising activities.
You may contact us before an event or speak with staff on arrival if you do not wish to appear in identifiable promotional material. We will take reasonable steps to respect notified preferences.
An attendee may appear incidentally in crowd, background, foreground or wide-event imagery. We seek appropriate permission before deliberately featuring an identifiable child and before deliberately selecting an identifiable person as the featured subject of promotional material.
You may ask us not to publish, or to remove where reasonably practicable, an identifiable image of you or a child in your care.
12. Security
We use measures designed to protect information, including restricted administrative access, role-based permissions, encrypted network connections, protected references, security logging, rate limiting and backups.
No online service can be guaranteed completely secure. Please contact us promptly if you suspect unauthorised access to a reference or personal information.
13. Retention
We retain information only for as long as it is reasonably needed for event delivery, security, legal obligations and church record keeping. Our intended approach includes:
- deleting or anonymising dietary, allergy and accessibility information approximately 30 days after the event;
- disabling active booking and attendee reference access approximately 90 days after the event unless needed for an unresolved matter;
- retaining security, session and email-delivery records only as operationally necessary; and
- retaining financial, refund, raffle, auction and regulatory records for the period required by law and applicable record-keeping policies.
Information no longer required is deleted or de-identified where reasonably practicable.
14. Access and correction
You may ask to access or correct personal information we hold about you. We may need to verify your identity and may refuse or limit access where permitted by law.
Some attendee information can be viewed or updated directly through the booking or attendee portal while event editing remains open.
15. Questions and complaints
Contact us if you have a privacy question, want to make an access or correction request, or believe your information has not been handled appropriately:
Email: [email protected]
Postal address: St Mary of Egypt Coptic Orthodox Church
55 Mona Vale Road
Pymble NSW 2073
Australia
Please provide enough information for us to understand and investigate the matter. We will respond within a reasonable period.
Information about privacy complaints is also available from the Office of the Australian Information Commissioner at oaic.gov.au.
16. Changes to this policy
We may update this policy when our practices, providers or legal obligations change. The effective date at the top identifies the current version. Material changes will be communicated where reasonably necessary.