Privacy Policy
This Privacy Policy explains how Joga Bonito Tour (“JBT”, “we”, “us”), operated by INCASA.DM PTY LTD, collects, uses, stores and discloses your personal information when you use the JBT Inner Circle app (the “App”), our website at jogabonitotour.com and related services. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
If you are in the European Union or the United Kingdom, the General Data Protection Regulation also applies to us, and section 14 sets out the additional rights you have and how we meet them.
1. Who we are
Joga Bonito Tour is a trading name of INCASA.DM PTY LTD (ABN 91 502 658 580), based in New South Wales, Australia. INCASA.DM PTY LTD is the data controller for the information described in this policy. For any privacy question or request, contact goncalo@incasadm.com.
2. The information we collect
- Account details — your email address, and optionally your first name, when you join or create an account.
- Sign-in credentials — a password you set, stored securely (hashed) by our authentication provider. We never see your password in plain text.
- Visit activity — when you scan a partner venue’s QR code, we record the venue and the date/time of your visit. A scan logs a visit only — never a payment, bill total or anything you purchased.
- Table bookings — if you request a table at a partner venue, the venue, date, time, party size, a contact phone number and any note you add. The phone number is held against that booking so the venue can confirm it; it is not added to your member profile.
- League activity — if you take part in the JBT foot-tennis league, the scores and results you and your opponent submit.
- Where you’re based — your country and, in Australia, your postcode and suburb, which you give us when you join. You may also tell us a junior club and whether there’s a junior player in the family; both are optional. We do not collect your street address, and we do not track your device’s GPS location.
- Preferences — your notification settings and similar choices.
- Device/technical data — basic information your browser provides (e.g. general location by region, device type) and local storage used to keep you signed in.
We do not collect payment card details, and we have no access to your spending, bills or transactions at any venue.
3. How we use your information
- To create and manage your membership and account.
- To record your visits and show you your own visit history and recognition (streaks, standing).
- To give you members-first access to partner deals, events, giveaways and the league.
- To match you to partners near you, and — in aggregate only — to understand where our members are as a whole, so we can bring on venues and partners in the areas members actually live. Any location figure we share with a partner or prospective partner is a count, never a list: no names, no email addresses, no member-level rows. Where a count is small enough that it could identify someone, we withhold it.
- To send you communications you’ve chosen to receive (see “Your choices” below).
- To operate, secure, improve and understand use of the App.
4. What partners can and cannot see
Partner venues can see that a JBT member visited their venue, and when. They do not see your other visits, your account details, or any spending information — and we will never sell your personal information. Aggregated, non-identifying visit counts may be shown to a partner for their own venues.
Table bookings are the exception, because you are asking the venue to contact you. When you request a table through the App, we pass that venue your name, JBT member number, the date, time and party size, the contact number you enter on the booking form and any note you add. The venue needs these to confirm your table. Only the venue you booked receives them — no other partner does. We tell you this on the booking form itself, before you submit it. The number you give is stored against that booking only; it is not added to your member profile and it is not used for marketing.
5. Who we share information with
We share personal information only with service providers who help us run the App, under obligations to protect it:
- Supabase — database and authentication (member data is stored in a Sydney, Australia region).
- Vercel — application hosting.
- Resend — sending our emails.
- Google — website analytics only, and only on jogabonitotour.com. See section 6.
Some of these providers may process data on servers outside Australia. We take reasonable steps to ensure your information is handled securely wherever it is processed. We may also disclose information where required by law.
6. Cookies and analytics
The App itself does not run analytics. It uses local storage on your device to keep you signed in and to remember your preferences — that stays on your device and is not used to track you.
Our website, jogabonitotour.com, uses Google Analytics 4 so we can see how many people visit, which pages they open and whether they go on to the App. Google Analytics sets cookies on your device and collects: a randomly generated identifier, the pages you view, links you click away to, your approximate location (country and city, worked out from your IP address), and your device and browser type. We have configured it so that it is never used for advertising — advertising and personalisation signals are switched off permanently — and Google is not permitted to use this data for its own products. We do not sell it, and we cannot identify you personally from it.
If you are in the EU, the UK or Switzerland, we ask you first. No analytics cookie is set until you choose “Accept analytics” on the banner. If you decline, or simply ignore the banner, no analytics cookie is set and the site works exactly the same. You can change your mind at any time by clearing your browser’s site data for jogabonitotour.com, which removes the choice we stored and brings the banner back. Outside those regions we measure visits without a banner, which Australian privacy law permits; you can still opt out using your browser’s cookie controls or Google’s opt-out add-on.
Google’s own handling of this data is described in its Privacy Policy.
7. Where your information is stored, and how it is protected
Your information is stored in a database hosted in Sydney, Australia. It is protected by access controls and database row-level security, so members can only access their own data and partners only their own venue’s activity. Changes to member records, partner access and referral status are written to an audit log. Backups are taken daily and retained for seven days. No method of storage or transmission is completely secure, but we take reasonable steps to protect your information from misuse, loss and unauthorised access.
8. Marketing and your choices
Marketing is off unless you switch it on. We only send marketing communications — such as deal alerts, partner offers and event invitations — if you have opted in, and we record when you did so and the exact wording you agreed to. You must be 16 or over to opt in.
You can withdraw your consent at any time, and it is as easy as giving it: use Settings → Notifications in the App, or the one-tap link at the bottom of any marketing email. Withdrawing does not affect anything we sent beforehand, and it does not affect essential account messages such as sign-in or security notices, which are part of providing the service rather than marketing.
9. Accessing, correcting or deleting your information
You can request access to the personal information we hold about you, ask us to correct it, or ask us to delete your account and associated data, by emailing goncalo@incasadm.com. For step-by-step instructions on deleting your account, see Delete Your Account. We respond within one month.
10. Data retention
We keep information only as long as we need it:
- Member account data — while your account is active, and for up to 24 months after your last activity, after which we delete or de-identify it.
- Security and audit logs — up to 7 years, so we can evidence who changed what if a dispute arises. These record actions taken, not the content of your data.
- Backups — daily, retained for 7 days. If you delete your account, your data may persist in a backup for up to that period before it ages out.
If you delete your account we delete or de-identify your personal information, except where we are required to keep it by law.
11. Children and young players
Membership is intended for adults. You must be 16 or over to opt in to marketing emails, and we do not knowingly send marketing to anyone younger.
Some JBT services involve young players — in particular registrations for a partner academy’s player pathway. Where a player is under 18, the registration must be made by a parent or guardian, who confirms their consent as part of it, and we record who gave that consent. If you believe a child has given us information without a parent or guardian’s involvement, contact goncalo@incasadm.com and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We’ll post the updated version here and change the “Last updated” date above. Significant changes will be communicated in the App.
13. Contact and complaints
For any privacy question, request or complaint, contact goncalo@incasadm.com. If you’re not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
14. Members in the European Union and United Kingdom
If you are in the EU or the UK, the General Data Protection Regulation gives you specific rights. INCASA.DM PTY LTD is the data controller, and you can reach us at goncalo@incasadm.com.
Why we use your data, and on what legal basis
- Creating and running your membership — so we can provide the service you asked for. Basis: performance of a contract (Article 6(1)(b)). We do not ask for your consent to this, because you have asked us for the membership itself.
- Sending you offers, partner deals and event invitations — Basis: your consent (Article 6(1)(a)). You opt in, and you can withdraw at any time.
- Passing your details to a partner when you ask to be introduced — for example a player-pathway registration or a viewing booking. Basis: performance of a contract (Article 6(1)(b)).
- Keeping security and audit records — Basis: our legitimate interests (Article 6(1)(f)) in protecting the platform, detecting misuse and being able to evidence who changed what.
- Measuring visits to jogabonitotour.com — Basis: your consent (Article 6(1)(a)), and Article 5(3) of the ePrivacy Directive for storing the cookie itself. Nothing is stored or read on your device until you accept, and you can withdraw as easily as you gave it. See section 6.
Where your data goes
The information you give us is sent directly to our systems, which are hosted in Sydney, Australia. Australia has not received an adequacy decision from the European Commission, which means Australian law does not give your data the same protection as EU law, and you may have fewer avenues of redress against an Australian company than against an EU one.
Three service providers process personal data on our behalf: Supabase (database hosting, in Sydney), Resend (email delivery) and — for website analytics only, and only if you accepted the cookie banner — Google, which processes analytics data in the United States. Our agreements with all three incorporate the European Commission’s Standard Contractual Clauses, which is the safeguard Chapter V of the GDPR requires for transfers of this kind; for Google this is the Google Analytics Data Processing Terms, which we accepted on 19 September 2026. We do not sell your personal data, and we do not transfer it to anyone else outside the EEA or UK.
Your rights
You can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct it if it is wrong (rectification);
- delete it (erasure);
- restrict or object to how we use it;
- send it to you or another provider in a portable format;
- withdraw your consent to marketing at any time, without affecting what we did beforehand.
Email goncalo@incasadm.com and we will respond within one month. There is no charge, and we will not treat you differently for asking.
Complaints
Please tell us first so we can put it right. You also have the right to complain to the data protection authority in your country, or to the UK Information Commissioner’s Office at ico.org.uk.
Data breaches
If a breach happens that is likely to put your rights and freedoms at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell affected members without undue delay.
