Legal & Privacy

Privacy Policy

Effective date: 12 September 2026

Introduction and Scope

This Privacy Policy explains how Cardclub Boomerang collects, uses, discloses, and protects personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). The policy applies to all visitors, members, guests, and event participants at our exclusive offline poker venue and upscale restaurant/bar in Surry Hills, Sydney.

It covers information collected through our website, booking systems, in-person interactions, and any other channels. By using our services, you consent to the practices described in this policy.

Who We Are: Cardclub Boomerang operates a dedicated card room, poker tables, and a card lounge at Level 1, 123 Crown Street, Surry Hills NSW 2010, Australia. Our services include poker tournaments, private events, and dining. This policy is governed by Australian privacy law.

Information We Collect

Personal Information You Provide

We collect personal information that you voluntarily provide when you interact with us, such as when you book a poker table, register for a tournament, or contact us. This may include:

  • Contact details: name, email address, and phone number.
  • Booking details: preferred dates, times, and table preferences.
  • Payment information: processed securely by third-party providers; we do not store full card details.
  • Identification details: age verification (21+) may require date of birth or ID check.

Information Collected Automatically

When you visit our website, we may automatically collect certain technical information to improve your experience and ensure security. This includes device information such as IP address, browser type, and operating system; usage data such as pages visited, time spent, and referring URLs; and cookies and similar technologies as described in our Cookie Policy.

Information from Third Parties

We may receive personal information about you from third parties, such as event organisers or booking platforms, to facilitate your participation in our services. Corporate event organisers may provide attendee lists, and booking platforms may share reservation details. We only use such information for the purposes for which it was provided.

How We Use Your Information

Primary Purposes

We use your personal information to provide and improve our services, including managing bookings, facilitating poker games and tournaments, and ensuring a safe environment. Specifically, we use your information for:

  • Processing table reservations and event registrations.
  • Communicating with you about your bookings and enquiries.
  • Verifying age (21+) and identity where required.
  • Providing customer support and responding to feedback.
  • Complying with legal and regulatory obligations.

Marketing and Communications

With your consent, we may use your contact details to send you information about upcoming poker tournaments, special events, and venue news. You can opt out of marketing communications at any time. We do not sell your personal information to third parties, and marketing emails include an unsubscribe link.

Disclosure of Personal Information

Third-Party Service Providers

We may disclose personal information to trusted third-party service providers who assist us in operating our business, such as payment processors, IT support, and booking platforms. These providers are contractually obligated to protect your information and may only use it for the specific services they provide to us.

Legal and Safety Disclosures

We may disclose personal information if required by law, or if we believe in good faith that such disclosure is necessary to protect our rights, your safety, or the safety of others. This includes compliance with court orders or legal processes, prevention of fraud or illegal activities, and protection of venue security and integrity.

Business Transfers

In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of the transaction, subject to confidentiality obligations. You will be notified of any such transfer and any changes to this policy.

Data Security and Retention

Security Measures

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. These measures include:

  • Use of encryption for data transmission.
  • Restricted access to personal information on a need-to-know basis.
  • Regular review of security practices.
  • Secure storage of physical records where applicable.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law. Booking records are typically retained for 12 months after the event. Marketing consent records are retained until you withdraw consent. Legal obligations may require longer retention.

Your Rights and Choices

Access and Correction

You have the right to request access to the personal information we hold about you and to ask for corrections if it is inaccurate, incomplete, or out-of-date. Contact us using the details below to make a request. We will respond within a reasonable timeframe, usually 30 days, and may need to verify your identity before processing your request.

Opt-Out and Withdrawal of Consent

You may opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us directly. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal. You may also request deletion of your personal information where applicable.

Complaints

If you have a complaint about how we handle your personal information, please contact us first. We take privacy complaints seriously and will investigate promptly. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

International Data Transfers

We do not typically disclose personal information to overseas recipients. However, some of our third-party service providers may store data on servers located outside Australia, such as in the United States or European Union. Where this occurs, we take reasonable steps to ensure the recipient complies with the APPs or equivalent protections. By providing your information, you acknowledge that it may be transferred overseas in these circumstances.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated version will be posted on this page with a new effective date. We encourage you to review this policy periodically. Material changes may be notified via email or a notice on our website.

Current effective date: 12 September 2026

Contact Us

If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us using the details below.