Privacy
Privacy Policy
How we collect, use and protect personal information. Last updated 10 July 2026.
Glenorchy City Brass Inc. (“the band”, “we”, “us”) is a community brass band association based in Tasmania, Australia. This policy explains how we handle personal information across our website (including the member portal) and the Chordinate mobile app when it is connected to our site. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What we collect
For band members and people who register interest in joining:
- Identity and contact details: name, email address, phone numbers, postal address and date of birth (required at registration; we use it to apply the extra protections for members under 18 described below).
- Membership details: the ensembles and sections you play in, your instrument or part, band roles (for example committee positions), membership status, whether you consent to photos of you being used for band promotion and, where you provide one, a profile photo.
- Participation records: your responses to events (yes / no / maybe and any note you add), attendance history, announcements you post and replies you make.
- Care and compliance details: emergency contact name and phone number, any medical needs you choose to tell us about, uniform size, and where a role requires it, compliance information such as Working with Vulnerable People registration status.
- Parent / guardian details (under-18s): a parent or guardian’s name and email address, and a record of their decisions (whether they approve the membership, who band correspondence should go to, and whether the member may use the Chordinate app).
- Billing records: invoices we issue you (for example membership fees or instrument hire) and their payment status. Card payments are processed by Square; your card details never touch our systems.
- App and device information: if you use the Chordinate app and enable notifications: a push notification token, your device’s name and platform, and your per-device notification preferences (including quiet hours).
For visitors to the public website: only what you submit (for example the contact form or mailing-list subscription). We do not run advertising or third-party analytics trackers.
How we use it
- Running the band: scheduling rehearsals and performances, collecting RSVPs, taking attendance, and communicating with members by email and push notification.
- Publishing announcements and news to the right audience (everyone, an ensemble, a section, or the committee).
- Issuing and tracking invoices, and sending renewal or compliance reminders.
- Maintaining the member directory (see “What other members can see” below).
- Keeping members safe: any member can report an announcement or reply as inappropriate. A copy of the reported content, its author and the reporter’s name goes to the band committee so they can act on it.
- Meeting our legal and association-governance obligations.
We do not sell personal information, and we do not use it for third-party advertising.
What other members can see
- Everything in the member area is scoped to your own band(s): you see the events, announcements and directory of the ensembles you belong to, plus public concerts. Committee members and administrators see the whole organisation so they can run it.
- The directory shows names, sections and parts. Your phone number and email are shown to other members only if you opt in (“share contact details” in your profile). Authorised office-bearers can see contact details regardless, so the band can reach you.
- Members under 18 never have their contact details shown to other members in the directory or the app, even if the opt-in is ticked.
- Event responses (who answered yes / no / maybe, with any note) are visible to members of the invited band(s) to the extent each event’s settings allow. An event can show all responses, counts only, or only your own.
- Committee-only events and announcements are visible only to committee members.
- Sensitive details (for example date of birth, medical needs, emergency contacts, guardian details and compliance records) are restricted to authorised office-bearers.
The Chordinate app
Chordinate is the band’s companion mobile app (currently in pre-release testing with band members). It signs in to the same member account and shows the same band-scoped information as the member portal. When you use it:
- Your sign-in token is stored in your device’s secure storage.
- Members under 18 can sign in to the app only if a parent or guardian has given permission (see “Young members” below). The app has no private member-to-member messaging; communication is limited to announcements posted by band leaders and replies that leaders can see.
- The schedule and announcements are cached on your device so the app works offline; read/unread state is kept on the device.
- If you turn on biometric lock, the fingerprint / face check happens entirely on your device using the operating system’s own mechanism. Biometric data is never sent to us and we cannot access it.
- Calendar access is used only when you tap “Add to calendar”, and only to add that event.
- The app contains no ads and no third-party analytics or tracking SDKs.
- Signing out removes your sign-in token and unregisters the device from push notifications.
Who we share information with
We use a small number of service providers to run our systems. They process data on our behalf and are not permitted to use it for their own purposes:
- Railway hosts our website and database.
- Cloud file storage stores uploaded photos and documents.
- Square processes invoice payments (card details are handled entirely by Square).
- Resend and Microsoft 365 deliver our emails.
- Expo, Apple and Google deliver push notifications to your device.
Some providers store data outside Australia. We only share what each service needs to do its job. Beyond these providers, we disclose personal information only with your consent or where the law requires it.
Young members
We apply extra protections to members under 18 (identified by date of birth):
- When someone under 18 registers, we collect a parent or guardian’s name and email address and the membership does not begin until the guardian approves it via an emailed link. The guardian also tells us who band correspondence should go to.
- The guardian decides whether the member may use the Chordinate app, after being shown how the app works. Without that permission the member cannot sign in to the app. The guardian can change this decision at any time by contacting us.
- Their contact details are never shared. An under-18 member’s phone number, email and address are never shown to other members in the directory, on the website or in the app, even if the sharing opt-in is ticked. Only authorised office-bearers can see them, for band administration.
- No one can privately message them. It isn’t possible. Under-18 members can read their band’s announcements and post replies, but our website and app have no direct-messaging feature at all, for anyone. All communication happens in group announcements and their replies.
- Every post is seen and moderated by checked adults. Announcements and replies are visible to the band leaders and committee members who run the band. They are multiple adults holding Working with Vulnerable People registrations, and they moderate what’s posted. Any member can also report any post or reply with one tap, and the report goes straight to the committee.
- A parent or guardian consents to this policy on the member’s behalf and can exercise all of the rights below for them.
Security and retention
All traffic to our website and app is encrypted (HTTPS). Access to member information is role-based: ordinary members, committee members and administrators each see only what their role permits. We keep membership records while you are a member and for a reasonable period afterwards for association and financial record-keeping (financial records are kept as required by Australian law), after which they are deleted.
Your rights
- You can view and update most of your details yourself in the member portal or the app.
- You can ask us for a copy of the personal information we hold about you, or ask us to correct or delete it.
- You can request deletion of your account and associated data at any time via our account deletion page.
- You can turn notifications off per category and per device at any time, and unsubscribe from the mailing list via the link in any email.
To make a request or a complaint, email secretary@gccb.org.au. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
Changes to this policy
If we change how we handle personal information, we will update this page and the “last updated” date above, and flag significant changes to members directly.
