Privacy Policy
This policy explains how Next Break ("we", "us", "our"), operated from nextbreak.com.au, collects, holds, uses and discloses personal information when you use the Service. It's written to be consistent with the Australian Privacy Principles (APPs), even though Next Break, as a small operation, may currently fall under the Privacy Act's small business exemption. We've chosen to follow the APPs as good practice regardless.
1. What personal information we collect
We only collect what's needed to run the Service:
- Roster and trip planning details: your hometown, home airport, and either your repeating roster pattern (days on/off and next break start) or manually entered break dates. Your hometown is also converted to an approximate latitude/longitude (via a free geocoding lookup) so we can search for nearby events for your break dates.
- Account details, if you create an account: your email address and a securely hashed password (we never store or see your password in plain text), or, if you sign in with Google, the basic profile fields Google shares at sign-in (name, email, profile photo).
- Profile extras, entirely optional: a display name and a profile photo, if you choose to add them, stored on our server and served back only to you.
- Personalisation signals: which trip interests you've selected (e.g. beach, food, adventure) and which destinations you've clicked through to book, used only to lean future suggestions toward what you actually like, never to charge you a higher price.
- Feedback you submit: the reaction, topic tags, and any optional free-text comment you choose to leave through the in-app feedback widget, plus your email address if you're logged in when you send it.
- Marketing preference: whether you've opted in to occasional break-reminder emails, and which reminders you've already been sent (so we don't send the same one twice).
- Payment details, only if a paid feature is used: card details are entered directly into Stripe's own hosted checkout page and processed by Stripe; we never receive or store your full card number.
- Technical information: standard web request data (like IP address and browser type) that's generated automatically by any web request, and used only for security and troubleshooting, not tracking.
We don't ask for or knowingly collect sensitive information (health, government ID numbers, etc.), and there's nothing in the Service that requires it.
2. How we collect it
Directly from you, when you fill in the Setup form, create an account, sign in with Google, or make a payment. We don't buy personal information from third parties or scrape it from elsewhere.
3. Why we collect, use and disclose it
Solely to provide and improve the Service: projecting your upcoming breaks, looking up real flight prices and nearby events and activities for those dates, identifying your account so your setup is saved across devices, personalising which options we show based on your stated interests and past clicks, sending an optional break-reminder email if you've opted in, understanding feedback you choose to submit, and processing any payment you choose to make. We do not sell your personal information, and we do not use it for advertising or share it with data brokers.
4. Cookies and local storage
If you're logged in, we set one strictly-necessary session cookie so the Service knows it's you. This isn't a tracking or advertising cookie and isn't shared with any third party. If you use the Service without an account, your setup is instead kept in your browser's local storage (never sent to any server other than ours) so it's there next time you visit. We don't run any third-party analytics or advertising trackers on the Service. We do keep a simple internal count of page loads per day (e.g. "142 visits on 14 July") to understand overall traffic. Nothing about that count can be tied to you individually: no cookies, no IP logging, no device or browser identifiers, and no way to tell separate visits on the same day apart from each other. Once you click through to book a flight, activity, or event ticket, that third-party site (Aviasales/Travelpayouts, Viator, Ticketmaster) may set its own cookies under its own privacy policy, which is outside our control.
A couple of features work via a unique, hard-to-guess link rather than a login: your calendar subscribe link, and the unsubscribe link in any break-reminder email. Treat these like a password — anyone with the link can use that specific feature (see your upcoming breaks, or unsubscribe you from reminder emails) — and let us know if you think either has leaked so we can issue you a fresh one.
5. Who we disclose information to, and overseas recipients
We share only what's needed to make a specific feature work, with these service providers, several of whom are based overseas. Under Australian Privacy Principle 8, we're required to name them and note where they're located:
| Provider | What for | Roughly where |
|---|---|---|
| Travelpayouts / Aviasales | Real flight price lookups and booking links | Cyprus / EU |
| Viator (TripAdvisor) | Real, bookable local activities and booking links near your hometown, shown when there's nothing better to offer for a break | United States |
| Ticketmaster | Real event listings and booking links near your hometown, via their public Discovery API | United States |
| OpenStreetMap (Nominatim) | Converting your hometown into an approximate latitude/longitude, so we can search for nearby events and activities | Germany / EU (community-run) |
| OpenStreetMap (Overpass API) | Finding free public spots (beaches, parks, lookouts) near your hometown when there's nothing bookable available | Germany / EU (community-run) |
| Open-Meteo | Weather forecasts for your destination and travel dates — only a location and date are sent, no personal information | Germany / EU |
| exchangerate-api.com | Currency conversion rates for international destinations — only a currency code is sent, no personal information | United States |
| Stripe | Payment processing, if you use a paid feature | United States |
| Google Sign-In, if you choose to use it | United States | |
| Resend | Sending password-reset emails, and break-reminder emails if you've opted in | United States |
Each of these is a well-established provider with its own privacy and security commitments, and we only send them the minimum information each needs to do its job (e.g. Aviasales gets your home airport and travel dates, Ticketmaster and Viator get an approximate location and date range, not your email or password in either case). We haven't audited each provider's internal infrastructure in detail, but we choose providers with credible, published privacy practices. Once you click a booking link and leave Next Break, you're dealing directly with that provider under its own privacy policy.
6. Data security
We use industry-standard practices: passwords are hashed (never stored or logged in plain text), traffic to the Service is encrypted (HTTPS), and we don't ask for or store full payment card numbers ourselves. That said, no online service can guarantee absolute security; use a password you don't reuse elsewhere, and let us know straight away if you suspect unauthorised access to your account.
7. How long we keep it
We keep your account and roster information for as long as your account is active, so the Service keeps working the way you'd expect. Feedback you submit and your click history are kept in a capped internal log, used only in aggregate to understand how the Service is used, not for anything else. If you ask us to delete your account, we'll delete the personal information associated with it, other than anything we're legally required to retain (for example, payment records for tax purposes).
8. Access, correction and complaints
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, at any time. Email mark.volley@gmail.com and we'll respond as quickly as we reasonably can. If you're unhappy with how we've handled a privacy concern, please raise it with us first so we can try to fix it directly; if you're still not satisfied, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Automated decision-making
The Service surfaces flight, event, and activity suggestions using rule-based logic (matching real cached fares, nearby events and activities to your break dates and route, with a light personalisation nudge toward your stated interests and past clicks when prices are close). It doesn't use your personal information to make any automated decision that significantly affects your legal rights or similar interests (for example, we don't do automated pricing decisions about you, credit checks, or eligibility assessments). If that ever changes, we'll update this section, consistent with the Privacy Act's transparency requirements for automated decision-making that commence in December 2026.
10. Children
The Service isn't directed at, or intended for use by, children. Creating an account requires the legal capacity to agree to our Terms and Conditions, which assumes you're at least 18.
11. Changes to this policy
We may update this policy from time to time, including as privacy law changes. We'll update the "Last updated" date above whenever we do.
12. Contact us
Questions about this policy, or a privacy request? Email mark.volley@gmail.com.