Privacy Policy
Version 1.0 · Last updated: 2 July 2026
Nextround is a workplace recognition platform. This Privacy Policy explains what personal information we collect, why we collect it, how we keep it safe, and what choices you have.
We comply with the Australian Privacy Act 1988 and the 13 Australian Privacy Principles (APPs). If you are reading this from elsewhere, your local laws may also apply.
What we collect. Your mobile number (so you can sign in by one-time code), your full name, your work email (when supplied by you or your employer for invite matching), your organisation and team affiliation, the recognition activity you take part in (recognitions you send and receive, vouchers you send and redeem), and any messages you write in the product. For users migrated from the prior Snobbi platform, we also hold the equivalent records from that system so your history transfers.
What we do NOT collect. Government identifiers. Payment card data — Nextround does not store, process, or transmit card data; when paid plans are added, payment is handled by an external PCI-compliant provider so card data never reaches us. Health data. Location data beyond your team's city. Behavioural data for advertising.
Why we collect it. To run the service: authenticate you, route recognition to the right colleagues, allocate and redeem voucher value. We do not sell personal information. We do not use your data for marketing without your separate opt-in.
Where it is stored. Our primary database is hosted in Sydney, Australia (Amazon Web Services ap-southeast-2 region, via Supabase). Data does not leave Australia for storage. Some sub-processors handle data in transit only — see "Sub-processors" below.
How we keep it safe. We use encryption at rest (AES-256) and in transit (TLS 1.2+). Access to your data is restricted to authorised personnel using multi-factor authentication. We log access to personal information for audit. We have an incident response plan and notify affected individuals and the Office of the Australian Information Commissioner when required under the Notifiable Data Breaches scheme.
Sub-processors. We use the following sub-processors. Each is bound by a Data Processing Agreement. Supabase (database and authentication, Sydney). Vercel (web hosting and CDN, United States — request transit only, no PII storage). Twilio (one-time-code SMS delivery, United States — mobile number only). Resend, when wired (transactional email, United States — email address and email body only). Stripe, when wired (subscription billing — handles payment information directly via hosted checkout; we do not see card details).
Your rights. You may request a copy of the personal information we hold about you (right of access). You may ask us to correct inaccurate information (right of correction). You may ask us to delete your personal information (right of erasure), subject to limited exceptions — for example, where we are required to retain transaction records for tax or audit purposes. To exercise these rights, contact privacy@nextround.live. We respond within 30 days.
Retention. We keep your personal information for as long as your account is active and for a reasonable period afterwards (30 days from account closure) to handle any final reconciliation. Aggregated, non-identifiable statistics may be retained longer. Audit records of access to personal information are retained for 7 years.
Children. Nextround is a workplace tool and is not intended for users under 18.
Changes to this policy. We will notify you of material changes by in-product banner or email. The "Last updated" date at the top of this page tells you when the current version took effect.
Contact. privacy@nextround.live for privacy enquiries and data-subject requests. security@nextround.live for security reports. hello@nextround.live for general support.
Complaints. If you are not satisfied with our handling of a privacy issue, you may complain to the Office of the Australian Information Commissioner: www.oaic.gov.au.
See also: Data Processing Addendum · Cookies · Terms