RangeDay
Privacy Policy
Last updated: 10 September 2026
1. About this policy
RangeDay is operated by Temperis Pty Ltd (ACN 701 968 229, ABN 30 701 968 229), trading as RangeDay, of Karratha, Western Australia. In this policy, "we" and "us" mean Temperis Pty Ltd.
This policy explains how personal information is handled across the RangeDay platform. It applies to everyone whose information passes through it — club members and membership applicants, visitors and guests at a range, character referees, club administrators and committee members, the people who deal with us on a club's behalf, and visitors to rangeday.com.au.
This is our policy, about our platform. It is not your club's privacy policy. Your club may have its own policy covering how it handles information generally, including records it keeps outside RangeDay — on paper, in its own email, or in its own filing systems. Where your club has one, it applies alongside this policy and we do not speak for it.
2. Who is responsible for what
Two organisations are involved, and it matters which one is responsible for a given record.
Your club decides what information it collects about its members and visitors, why it collects it, how long it keeps it, and who within the club may see it. In privacy terms the club is the controller of those records, and it is the club you deal with about them.
We hold and process those records on the club's behalf, under a written agreement that limits what we may do with them. In privacy terms we are the club's processor. We do not use member or visitor information for our own purposes — not for marketing, not for profiling, and not for any commercial purpose other than running the service.
We are responsible in our own right for a narrower set of information: the details of the people who administer a club or deal with us about it (names, work contact details, correspondence), account and billing records for the club's subscription, support requests you send us, and technical records from rangeday.com.au. For that information, we are the controller and you deal with us directly.
3. What the platform collects
The platform collects only what is reasonably necessary for club administration, range safety, and the legal and regulatory obligations that apply to clubs (consistent with APP 3).
Members and membership applicants
- Full name, preferred name, and date of birth
- Contact details: phone number, email address, and postal address
- Membership number and expiry date
- Firearm Licence (FAL) details and number
- Working with Children check details
- Credentials and certifications (Range Officer, First Aid, etc.)
- Attendance records at club events and matches
- Payment records (membership fees, range fees, equipment purchases)
- Photographs (member ID photos, document scans) — used for identification and administrative purposes
- Club membership status, join date, and end date
- Firearm support records (where the club supports a member's firearm licence)
- Administrative notes and tags recorded by club staff, and each member's communication preferences
- Electronic signatures on declarations and forms
Visitors, guests, and other people at the range
- Visitor declarations required by firearms law — name, date of birth, gender, contact details, residential address, firearm licence details, driver's licence / passport or other identification numbers, the self-declarations the prescribed form requires (including declarations relating to disqualification, prohibition, and mental health), and an electronic signature
- Young persons (12–17) — the parent or guardian's name, date of birth, licence and identification details, and consent signature
- Spectators and guests signed in at the range — name and contact details
- Range-booking enquiries — organisation, contact person, email, and phone number
Character referees
- Referee name, contact details, firearm authority number, and typed signature, together with the internet (IP) address and browser details of the submission
Safety and regulatory records
- Incident reports, including the members involved, witness details, and any police report numbers
- Reports about a person's fitness to hold a firearms licence — see section 7, which explains these in full because of what they contain and who receives them
Club administrators and the people we deal with
- Name, role or office held, and work contact details for the club's administrators, committee members, and billing contact
- Correspondence with us, including support requests and their attachments
- Records of the club's subscription, invoices, and payments
- Acceptance records for the club's legal agreements — the accepting person's name, office, email address, IP address, browser details, and the time of acceptance
Account and technical data
- Sign-in sessions, including IP address and browser/device information
- Device quick-unlock data — a securely hashed PIN, device label, and device characteristics
- Multi-factor authentication enrolment details, including a phone number where SMS codes are used
- Social sign-in identity details (name, email, profile photo) where someone chooses to sign in with an external account
- Push-notification subscriptions for devices that opt in to notifications
- In-app messages and notifications (for example, committee chat)
- Copies of emails and SMS messages a club sends through the platform, including the recipient address and message content
- Audit records of who accessed or changed member information
Some of this is sensitive information under the Privacy Act 1988 (Cth) — in particular health and mental-health declarations on prescribed firearms forms, and the reports described in section 7. It is collected only where a prescribed form or legal obligation requires it, with the individual's consent at the point of collection where consent is the basis, and access to it is restricted to authorised club officers.
Where a form collects information from you directly, it tells you at that point what is being collected and why. Unsolicited personal information that is not reasonably necessary is destroyed or de-identified.
4. Why it is collected
The platform exists to let a club administer its membership, run its range safely, and meet the obligations firearms law places on it. Information is collected to:
- process and maintain memberships, and verify licences and credentials
- record attendance, bookings, and who is present at a range
- administer payments and club accounts
- communicate with members and visitors about club matters they have asked to hear about or that the club must tell them
- record incidents and make the reports firearms law requires
- keep the platform secure, and keep an audit trail of who did what
Information is not sold, traded, or disclosed for marketing or commercial purposes.
5. Cookies
The platform uses a small number of strictly necessary cookies: a session cookie that keeps you signed in, an optional trusted-device cookie that enables PIN quick-unlock on devices you choose, and short-lived security cookies used during sign-in flows. The edge-security provider that protects public forms may also set its own cookies when presenting an anti-bot challenge. No advertising or cross-site tracking cookies are used.
Our public website at rangeday.com.au sets no cookies of its own. It does load web fonts from Google's font service, which means your browser contacts Google directly and Google receives your IP address and browser details as part of that request.
6. Who else handles the information
To deliver the service we engage a small number of service providers — an Australian server host and backup provider, an edge network, transactional email and SMS providers, and supporting infrastructure. Each is engaged under its own terms of service and published privacy and security commitments, which we review before engaging them and which we take into account in deciding what information each one receives. Some of these services — address autocomplete on public forms, and delivery of push notifications to your device — are contacted by your browser directly rather than by us. A current list of these providers, naming each one and what it handles, is published as an annex to our Data Processing Agreement and is available to any member on request.
Where a club configures its own email or SMS provider for its communications, contact details and message content are disclosed to that provider, which the club chooses and which may be located overseas.
Our own personnel may access club data where necessary to operate, support, or troubleshoot the service. That access uses the same permission controls as club staff access and is recorded in the audit log.
Information may also be disclosed to law enforcement, courts, or regulators where the law requires it — including the reports described next.
7. Reports to WA Police about a person's fitness to hold a firearms licence
This section describes the most sensitive disclosure the platform supports, and we set it out in full so nobody is surprised by it.
Under the Firearms Regulations 2024 (WA), a club officer who forms the opinion that a person may not be a fit and proper person to hold a firearms authority is required to report that opinion to the Commissioner of Police within 7 days. This is a legal obligation on the club officer, not a choice made by us, and a failure to report carries a penalty.
Where a club makes such a report using RangeDay, the report is prepared and stored in the platform and may include:
- the person's full name and residential address
- whether the concern relates to criminal matters, medical matters, or mental health, to threats, or to the person's retention of a firearm
- a written description of the concern and when the opinion was formed
- whether the person has been suspended by the club or from holding firearms
- whether CCTV or other footage is available
The report is disclosed to Western Australia Police. The club decides whether to make a report and is responsible for its contents; we provide the means to prepare, store, and submit it, and we retain a record of it.
Because these reports concern health and mental health, they are sensitive information. Access within the platform is restricted to authorised club officers and every access is recorded in the audit log.
8. Where information is held
Club data is stored on a server located in Perth, Western Australia, in a certified Australian datacentre, and encrypted backups are retained within Australia.
Some service components process limited data outside Australia — transactional email and SMS delivery, edge-network delivery and anti-bot protection on public forms, browser push-notification services, address autocomplete on public forms, source-code and deployment infrastructure, and (where a club enables it) social sign-in providers. The annex referred to in section 6 identifies which providers these are and where each operates.
Using an overseas provider does not shift responsibility away from us: under APP 8 we remain accountable for personal information we send overseas. The steps we take are to keep the primary data store and its backups in Australia, to limit overseas processing to the narrow functions listed above, to choose providers on the basis of their published privacy and security commitments, and to use encrypted connections (TLS 1.2 or higher) for all transfers.
Two of the services above — address autocomplete on public forms, and delivery of push notifications to your device — are contacted by your browser directly. We do not send your information to them; your browser does, and they receive your IP address as part of that.
9. How long information is kept
Retention of member and visitor records is set by each club, because the club decides how long it needs to keep them and what its own legal obligations require. We provide the controls and apply whatever the club sets. To find out what your club has chosen, ask your club.
The platform's defaults, which apply until a club changes them, are:
- Past member records — 5 years from the membership end date, then permanently deleted or de-identified
- Audit records — 7 years
- Committee chat — 24 months
- Range presence records — a configurable period set by the club
A longer period applies where law or a regulator requires records to be kept. Records held for a club's active membership are retained while the membership remains current.
Information we hold in our own right — administrator contacts, billing records, support correspondence, and agreement acceptance records — is kept while the club is a customer and for as long afterwards as we need it for tax, accounting, and legal purposes.
10. Security
We implement security measures aligned with the Australian Signals Directorate's Essential Eight framework and the Information Security Manual:
- Full-disk encryption at rest — the server's data volume is encrypted at rest with full-disk encryption (LUKS, AES-256); the club databases and uploaded documents and photos reside on this encrypted volume
- Encryption in transit — all connections use TLS 1.2+ (HTTPS)
- Tenant isolation — each club's data is held in a separate, dedicated database so one club's records cannot be reached from another
- Restricted access to sensitive fields — access is governed by role permissions, and all sensitive data changes are recorded in an immutable audit log
- Multi-factor authentication — available to all accounts. Each club decides whether to turn it on; where a club does, the administrator role always requires it and the club may require it for other roles as well
No system is perfectly secure. We describe here the controls we actually operate, and we do not claim protections the software does not provide.
11. Data breaches
If a security incident affects club data at the platform level, we notify the affected club without undue delay, targeting notification within 24 hours of becoming aware of it, and we assist the club in responding.
Because the club is the controller of member and visitor records, the club assesses whether the incident is an eligible data breach and makes any notification required to affected individuals and to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. We do not make that assessment on a club's behalf.
For information we hold in our own right, we make that assessment and any required notification ourselves.
12. Access, correction, and deletion
You may ask to see the personal information held about you, ask for it to be corrected, or ask for it to be deleted.
For member, visitor, or referee records, contact your club. The club decides those requests because it is the controller, and it holds context we do not. If a club asks us to help with a request, we do.
For information we hold in our own right — administrator and billing contacts, correspondence with us, agreement acceptance records — contact us at stu@temperis.com.au.
Your club sets the period in which it aims to respond to a request; the platform's default is 30 days. Ask your club what it has set. Some information cannot be deleted on request where the law requires it to be kept — records made under firearms law are the main example.
13. Complaints
If you are concerned about how your club has handled your information, raise it with the club first. If you are concerned about how we have handled information, contact us at stu@temperis.com.au and we will respond.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
14. Changes to this policy
The current version of this policy is always published at rangeday.com.au and within the platform. Where a change is material, we will notify club administrators before it takes effect.
15. Contact
Temperis Pty Ltd (ACN 701 968 229, ABN 30 701 968 229), trading as RangeDay
Karratha, Western Australia
stu@temperis.com.au
Questions about your own membership records, your attendance, or your declarations should go to your club — they hold the answers and they decide those requests. Questions about the platform itself, or about information we hold about you as a club administrator or contact, come to us.