Privacy Policy
Effective date: [DATE OF PUBLICATION] Last updated: [DATE OF PUBLICATION]
1. Who we are
Cheatcode Playground is operated by Cheatcode Playground Fortitude Valley Pty Ltd (ABN 46 686 592 978), of Unit 1, 27 Ballow Street, Fortitude Valley QLD 4006. In this policy, "we", "us" and "our" refer to that company.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Why the Privacy Act applies to us in full
Some small businesses are exempt from the Privacy Act. We are not.
Because our sessions are directed at improving psychological wellbeing, and because we screen clients for health conditions before they use our equipment, we treat ourselves as a health service provider for the purposes of the Act. The small business exemption does not apply to health service providers, so the Australian Privacy Principles apply to everything we do.
This also means that most of the information we hold about you is health information, which carries stronger protections than ordinary personal information. That includes your name, contact details and booking history, because the fact that you are our client is itself health information.
3. What we collect
Information you give us when you register or book
Name, email address, mobile number, date of birth, emergency contact details where provided, and your booking and attendance history.
Screening and clearance information
Before you use our equipment we ask you to complete a screening form. This form asks about conditions that the manufacturers of our devices exclude, including epilepsy and seizure history, pregnancy, heart conditions, eye conditions, implanted medical devices, recent surgery, medications, and psychological or psychiatric conditions. Some answers require you to provide written detail. Some require written clearance from your doctor before we can proceed, in which case we record your doctor's name, contact details and the advice they give.
We also ask, before each session, about sleep in the previous 24 hours and about alcohol or recreational drug use in the previous 24 hours.
Session information
Session type, devices used, protocol selections, physiological measurements recorded by the equipment during your session such as heart rate variability, any rating or feedback you give, and notes made by our staff about your session and your care.
Payment information
Transaction records, amounts, dates and payment method. Card numbers are handled by our payment processor and are not stored by us. Where you choose to save a card for future use, it is stored by our payment processor and we hold only a reference to it.
Camera footage
Our five session rooms are fitted with cameras. Session rooms are private, enclosed spaces in which you are reclining and alone, using equipment that carries a photosensitive seizure risk, so we monitor them for your safety. There are no cameras in the toilets. Our cameras do not record audio.
Footage of you in a session room is health information and we treat it as such.
Website information
When you visit our marketing website we collect standard technical information such as IP address, browser type, pages viewed and referring site, through cookies and similar technologies. See section 10.
4. How we collect it
We collect most information directly from you, through our online registration and screening flow, at our front desk, or in conversation with our staff.
Where you have given us written clearance from a doctor, we may collect information from that doctor.
Where someone books a session on your behalf, we collect your name, email address and mobile number from them, and we collect everything else from you directly when you arrive.
5. Why we collect it
We collect and use your information to:
determine whether it is safe for you to use each device, and to identify when it is not
deliver your sessions and tailor them to your goals
keep accurate records of your participation and of decisions made about your care
process bookings, payments, refunds and gift cards
communicate with you about your bookings, including confirmations, reminders and receipts
maintain the safety and security of our premises
respond to enquiries, complaints and incidents
meet our legal, regulatory, insurance, accounting and record keeping obligations
We do not use your health information to decide what marketing to send you. Not as a segment, not as a filter, and not to personalise anything. This is a standing rule and no consent setting changes it.
6. Consent, and what happens if you do not give it
We collect health information with your consent and only where it is reasonably necessary for our services.
Screening. If you do not answer the screening questions we cannot assess whether our equipment is safe for you, and we cannot provide sessions on the affected devices.
Camera recording in session rooms. We ask for your explicit consent to being recorded in a session room. That consent is asked for separately from our general terms and separately from your screening consent, so you can see exactly what you are agreeing to. If you do not consent to recording, we are not able to offer you sessions in our rooms, because we are not willing to place a client alone in an enclosed room with this equipment without the ability to monitor for safety.
You can withdraw consent at any time by contacting us, though doing so will usually mean we can no longer provide the affected service.
7. Who we disclose it to
We do not sell personal information and we do not disclose it to third parties for their own marketing purposes.
We disclose personal information to:
Service providers who operate our systems on our behalf, including hosting, database, email, SMS, payment processing and website providers. These providers act on our instructions and are bound by contract to handle the information only for the purposes of delivering their services to us. Section 8 sets out where they are located.
Software development tooling, including AI-assisted development tools used by our developers when building and maintaining our booking platform. Client information may be visible to these tools in the course of that work.
Your doctor or other treating practitioner, where you have asked us to seek clearance or where you have consented.
Emergency services and medical responders, where necessary to respond to a medical emergency or to lessen a serious threat to your life, health or safety.
Our professional advisers, including lawyers, accountants and insurers, where necessary.
Regulators, courts and government authorities, where required or authorised by law. This includes Workplace Health and Safety Queensland where a notifiable incident occurs on our premises, and the Office of the Australian Information Commissioner in the event of an eligible data breach.
8. Overseas storage and disclosure
Most of our systems are provided by companies based overseas, which means your personal information, including your health information, is stored and processed outside Australia.
We think you should know specifically where, rather than being told "Australia or overseas". As at the date of this policy:
What Provider function Country Client records, screening answers, session notes, booking history Database and authentication India Booking platform application Application hosting and processing United States Payment processing Payments United States Booking confirmations, reminders and receipts sent by email Email delivery United States Text messages SMS delivery United States Marketing website Website hosting United States Website analytics and advertising tools Analytics and advertising United States AI-assisted development tooling Software development United States
Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, principally through contractual terms and data processing agreements with each provider. Under section 16C of the Privacy Act we generally remain accountable to you for how these providers handle your information.
Camera footage. [CHOOSE ONE AND DELETE THE OTHER BEFORE PUBLISHING]
Option A, if footage is held only on the recorder at our premises: Camera footage is recorded and stored on equipment located at our premises. It is not stored overseas and is not held by any cloud provider.
Option B, if the camera provider stores footage or clips in the cloud: Camera footage is stored by our camera system provider on servers located in [COUNTRY].
9. How long we keep it
Record Retention Camera footage from session rooms Approximately 3 months, then automatically overwritten Client records, including screening answers, clearances and session notes 7 years from your last interaction with us. For clients who were under 18, until they turn 25, whichever is later Financial and transaction records 7 years, as required by tax and corporations law Incident records At least 5 years where the incident was notifiable to the work health and safety regulator Enquiries and complaints 7 years
Accounts that are created but never used may be deleted after a period of inactivity. Signing in stops that clock.
When we no longer need information and are not required to keep it, we destroy it or de-identify it.
10. Cookies, analytics and advertising
Our marketing website at cheatcodeplayground.com uses cookies and similar technologies, including Google Tag Manager, Google Analytics and the Meta pixel. These help us understand how people find and use our site, and allow us to measure advertising.
These tools are provided by Google and Meta, who may use the information they collect for their own purposes in accordance with their own privacy policies.
You can control cookies through your browser settings, and you can opt out of Google Analytics using Google's browser add-on. Blocking cookies may affect how parts of our website work.
11. Direct marketing
We only send marketing messages to people who have given us consent to receive them, and we ask for that consent separately for email and for SMS. Consent is off by default and we never bundle it into a waiver or a terms acceptance.
Booking confirmations, reminders, receipts and similar operational messages are not marketing and are sent to all clients, because they are part of delivering the service you have asked for.
Every marketing message includes an unsubscribe option. If you opt out, we apply that across all channels, and we will not contact you again to ask you to reconsider.
12. Dealing with us anonymously
You can browse our website, make general enquiries and buy a gift card without identifying yourself.
You cannot book or attend a session anonymously or under a pseudonym. We need to know who you are in order to screen you safely, to keep an accurate record of decisions made about your care, and to contact you if something goes wrong during or after a session.
13. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include access controls on our systems, restricting who can view camera footage to a limited number of authorised people, encryption of information in transit, and contractual protections with our service providers.
No system is completely secure. If we become aware of a data breach that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
14. Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, and you can ask us to correct it if it is wrong, out of date, incomplete or misleading.
Contact us using the details in section 16. We will usually respond within 30 days. We do not charge a fee for making a request, though we may charge a reasonable fee for the cost of providing access to a large volume of material, and we will tell you before we do.
There are limited circumstances in which we may refuse access or correction, for example where giving access would have an unreasonable impact on someone else's privacy. If we refuse, we will tell you why in writing and explain how to complain.
15. Complaints
If you think we have mishandled your personal information, please tell us first. Contact our Privacy Contact using the details below, setting out what happened. We will acknowledge your complaint and aim to respond within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
Website: oaic.gov.au Phone: 1300 363 992 Post: GPO Box 5288, Sydney NSW 2001
16. Contact us
Please direct privacy questions, access and correction requests, and complaints to our Privacy Contact:
Privacy Contact Cheatcode Playground Fortitude Valley Pty Ltd Unit 1, 27 Ballow Street, Fortitude Valley QLD 4006 Email: info@cheatcodeplayground.com
17. Changes to this policy
We may update this policy from time to time. The current version is always available on our website, and the effective date at the top tells you when it last changed. If we make a significant change to how we handle your information, we will take reasonable steps to tell you.
Your nervous system is your greatest asset.
Treat it like one.
If your work, relationships, and decisions depend on clarity and emotional steadiness, a regulated nervous system isn’t a nice-to-have — it’s infrastructure. You don’t need to wait for a crash to address it. Give your body and brain a structured way to restore regulation, build resilience, and maximise performance.