Privacy Policy
How we collect, use, and protect your information within the AMARI community.
AMARI Group (“we”, “us”, “our”) operates the AMARI mobile application (the “App”), an invite-only community serving Australia’s Black Diaspora. We are committed to protecting your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it.
Information We Collect
Information You Provide
When you join the AMARI community and create an account, we collect the following personal information directly from you:
- Full name — used to identify you within the community
- Email address — used for authentication, account recovery, and essential communications
- Password — encrypted and used solely for account authentication (we never store plaintext passwords)
We do not collect sensitive personal information such as gender, racial or ethnic origin beyond what is implicit in the community’s purpose, religious beliefs, political opinions, health information, or biometric data.
Information Generated Through Use
As you interact with the App, we automatically collect certain information related to your membership and engagement:
- Membership tier — your current tier level (Member, Silver, Platinum, or Laureate) within the AMARI community
- Event attendance — records of community events you register for or attend
- Engagement metrics — basic usage data such as feature interactions and session activity, used to improve the App experience
- Push notification tokens — device tokens required to deliver push notifications you have opted into
Information We Do Not Collect
We want to be transparent about what we do not collect:
- We do not collect precise geolocation data
- We do not access your device contacts, camera, or microphone
- We do not collect gender or demographic fields beyond your name and email
- We do not use third-party analytics or advertising SDKs
- We do not collect financial or payment information within the App
How We Use Your Information
We use the personal information we collect for the following purposes:
- Account management — to create and maintain your AMARI account, authenticate your identity, and manage your membership tier
- Community experience — to provide you with access to community features, content, and events appropriate to your membership level
- Communications — to send you essential account-related notifications, event updates, and community announcements via push notifications and email
- App improvement — to analyse aggregate engagement metrics and improve the App’s features, performance, and user experience
- Event coordination — to manage event registrations, attendance tracking, and related community logistics
- Security — to detect, prevent, and address technical issues, abuse, or unauthorised access to the App
We do not sell, rent, or trade your personal information to any third party. Your data is used exclusively to operate and improve the AMARI community experience.
Data Storage & Security
Cloud Infrastructure
Your data is stored and processed using Supabase, a secure, open-source backend. Supabase provides:
- Encrypted database storage with PostgreSQL
- Row-Level Security (RLS) policies ensuring users can only access their own data
- Secure authentication via Supabase Auth with bcrypt password hashing
- Data transmission encrypted via TLS/SSL
- Infrastructure hosted on enterprise-grade cloud providers
Local Device Storage
On your device, we use expo-secure-store to store sensitive data such as authentication tokens. Expo SecureStore uses:
- iOS Keychain Services on Apple devices
- Android Keystore system on Android devices
These are hardware-backed security modules provided by the operating system, ensuring your local data is encrypted and protected from other applications.
Security Measures
We implement a multi-layer security architecture:
- Database layer — PostgreSQL Row-Level Security policies restrict data access at the database level
- Application layer — server-side Postgres functions enforce business logic and tier-based access controls
- Interface layer — client-side tier gating ensures users only see features and content appropriate to their membership level
While we take reasonable steps to protect your information using industry-standard security practices, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.
Third-Party Services
The App integrates with a limited number of third-party services, each serving a specific function:
Supabase
Provides our backend infrastructure including authentication, database, and real-time features. Supabase processes your account data (name, email, encrypted password) and stores your membership and engagement data. Supabase’s privacy practices are governed by their own privacy policy.
Expo / Expo Push Notifications
We use Expo’s push notification service to deliver notifications to your device. Expo receives your device’s push notification token to route notifications. Expo does not receive your personal information such as your name or email address.
Google Play Store
The App is distributed through the Google Play Store (package name: com.amari.mobile). Your interaction with the Google Play Store is governed by Google’s Privacy Policy. We receive limited analytics from Google Play Console regarding app installs and crashes, which do not contain personally identifiable information.
We do not integrate any third-party advertising networks, social media tracking pixels, or analytics platforms (such as Google Analytics, Facebook SDK, or similar services).
Your Rights
Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you have the following rights regarding your personal information:
- Right to access — you may request a copy of the personal information we hold about you
- Right to correction — you may request that we correct any inaccurate, incomplete, or out-of-date personal information
- Right to deletion — you may request that we delete your account and associated personal data, subject to any legal obligations we may have to retain certain records
- Right to complain — if you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us or with the Office of the Australian Information Commissioner (OAIC)
- Right to opt out of communications — you may disable push notifications through your device settings at any time
To exercise any of these rights, please contact us at the email address provided in the Contact section below. We will respond to your request within 30 days.
If you are not satisfied with our response to a privacy complaint, you may escalate the matter to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
Data Retention
We retain your personal information for as long as your AMARI account remains active and you continue to be a member of the community.
If you request account deletion, we will:
- Delete your personal profile data (name, email) within 30 days of the request
- Remove your authentication credentials immediately
- Anonymise or delete engagement metrics and event attendance records within 30 days
- Retain anonymised, aggregate data that cannot be linked back to you for the purpose of improving the App
We may retain certain information where required by law or for legitimate business purposes such as resolving disputes or enforcing our community guidelines.
Children’s Privacy
The AMARI App is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at the email address below, and we will take steps to delete that information.
As an invite-only community, all members must be approved before gaining access, which provides an additional safeguard against underage use.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last Updated” date at the top of this policy
- Notify you via push notification or email where the changes are significant
- Where required by law, seek your consent before applying changes that materially affect how your personal information is used
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to reach out.