In effect from 2 August 2026
This policy explains how zzippr.audiencedirect.com.au handles personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It covers both the people who hold accounts with us and the people whose details appear in our marketing database.
We handle two quite different sets of personal information, and your rights depend on which one you are in:
| If you are… | See |
|---|---|
| A customer — you have an account, or you have used the audience builder on our website | Sections 3, 5 and 7 |
| An individual in our marketing database — your name, address or contact details may be held by us even though you have never used this service | Sections 4, 6 and 7 |
If you are not sure which applies to you, section 7 works either way: you can ask us what we hold about you, and you can ask us to stop.
zzippr.audiencedirect.com.au is offered in Australia only. Our services are directed at Australian businesses, our marketing data relates to individuals in Australia, and this policy is written to Australian law. We do not offer the service in the European Union or the United Kingdom and do not hold ourselves out as complying with the GDPR. If you are outside Australia, this service is not directed at you.
This does not mean your information never leaves the country — see section 8 on overseas disclosure, which is a real and routine part of how the product works.
When you create an account or use the service, we collect:
We collect this to provide the service, take payment, keep the platform secure, meet our record keeping obligations, and support you. We collect it from you directly, except for the Meta sign-in and advertising details described above.
This is the part of our handling most likely to concern you if you have never heard of us before today.
We maintain a database of individuals in Australia for the purpose of audience building and direct marketing by our customers. It may include your name, residential or postal address, email address, telephone number, and attributes used for segmentation such as approximate location and general demographic or interest categories.
We did not collect this information from you directly, and you will not usually have had any dealing with us. That is precisely why the rights in section 7 exist and why we do not require you to prove an account with us in order to use them.
If you want to know how we obtained your information, ask us and we will tell you. Write to privacy@audiencedirect.com.au and we will respond with the source of your details, ordinarily within 30 days. You do not need to give a reason, and asking does not put you on any list. Your details must match what we hold in order for us to answer, and we may need to verify your identity first.
We do not knowingly collect or hold sensitive information as defined in the Privacy Act — including health information, or information about race, political opinions, religious beliefs, sexual orientation or criminal record, and we do not permit (or provide the capability for) our customers to build audiences on that basis.
We do not knowingly hold information about children in the marketing database, and the service is not directed at or for use by anyone under 18.
We use it to run the service, and we disclose it to:
We do not sell customer account information, and we do not disclose it for another organisation's marketing.
Our customers use the platform to describe an audience — for example, an age range in a particular set of postcodes — and the platform counts and assembles the matching records. The customer does not browse or download the underlying list of individuals through the audience builder.
Where the customer delivers that audience to Meta as a Custom Audience, the matching contact details are hashed before they leave our systems and are transmitted in that form. Meta matches the hashes against its own users and discards those that do not match. This is Meta's standard Custom Audiences mechanism.
Our customers are separately responsible for how they market to an audience once it is built, including their obligations under the Spam Act 2003 (Cth) for email and SMS, and the Do Not Call Register Act 2006 (Cth) for telephone marketing. Our terms require them to comply with those laws. That does not displace your rights against us in section 7.
You can ask us to remove you from the marketing database, and to stop your details being included in any future audience. You do not need an account, and you do not need to give a reason. See our opt-out page for the form and what happens next. We will confirm when it is done.
We keep the minimum information needed to make an opt-out stick — a record that you asked not to be included — because discarding it entirely would mean re-adding you at the next data update.
Under APPs 12 and 13 you may ask us for the personal information we hold about you, and ask us to correct it if it is wrong, out of date, incomplete or misleading. Write to privacy@audiencedirect.com.au. We will ordinarily respond within 30 days. We may need to verify your identity first, and we will only ask for what is necessary to do that.
Access is free. If a request is unusually complex we may charge a reasonable cost-based fee, and we will tell you what it is before we do any work. If we refuse access or correction we will tell you why in writing and how to complain.
If you hold an account, see our data deletion page.
Delivering an audience to Meta discloses information to a recipient outside Australia. Meta Platforms operates from the United States and processes data in that and other countries. Once information is disclosed to Meta it is handled under Meta's own terms and privacy policy rather than ours.
Our payment, email and infrastructure providers may also store or process data outside Australia, including in the United States. Where a provider holds our primary databases we use Australian regions where that option is offered.
This means an overseas recipient may not be bound by the Privacy Act, and you may not be able to seek redress under that Act against them.
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption in transit, hashed passwords, access controls that scope staff and customers to their own records, second-factor authentication, and audit logging of administrative actions.
No system is perfectly secure. We are covered by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If a data breach involving your personal information is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as the scheme requires.
We destroy or de-identify personal information when it is no longer needed for a purpose permitted under the APPs and we are not required to retain it — for example, tax records, which we keep for five years.
Our website uses cookies and similar technologies to keep you signed in, remember your preferences, and understand how the site is used. You can block or delete cookies in your browser, though parts of the service will not work without the ones that maintain your session.
If you think we have breached the Australian Privacy Principles, please tell us first. Write to privacy@audiencedirect.com.au with the details. We will acknowledge your complaint and respond in writing, ordinarily within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
We may update this policy. The date at the top shows when the current version took effect. Where a change materially affects how we handle your personal information we will take reasonable steps to tell you, rather than relying on you to notice the date.
zzippr.audiencedirect.com.au
Privacy enquiries: privacy@audiencedirect.com.au
General enquiries: support@audiencedirect.com.au