1. About This Policy
This Privacy Policy explains how Resunday Pty Ltd (ACN 698 158 744) ("Resunday", "we", "us", "our") collects, uses, discloses, and protects your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy applies to all personal information collected through our website at resunday.app, our application at try.resunday.app, and any related services we provide, including bill auditing, provider negotiation, and provider switching conducted under a Service Authorisation Agreement.
By using our website for general browsing, you consent to the collection of non-sensitive information as described in this policy (such as essential and analytics cookies and usage data; advertising cookies require your separate opt-in, see Section 10). For sensitive information, including identity documents and billing data, we obtain your explicit consent at the point of collection.
We are committed to collecting only the personal information that is reasonably necessary to provide our services. If you choose not to provide certain information, we may not be able to deliver some or all of our services to you.
2. Information We Collect
We collect the following categories of personal information:
- Contact details:
- name, email address, phone number
- Billing documents:
- copies of your household bills (energy, internet, insurance) uploaded for analysis, including provider names, account numbers, plan details, usage data, and charges
- Identity verification:
- government-issued identification (such as a driver's licence or passport) and a selfie, captured at the point of Deal Card approval to verify your identity before we act with a provider under your Service Authorisation. Identity verification is performed by Stripe Identity (our KYC sub-processor): Stripe captures and holds the document, and we retain only the verification outcome (that your identity was confirmed), not the document itself. This is classified as sensitive information under APP 3.3 and requires your explicit consent before collection
- Service Authorisation records:
- when you accept a Service Authorisation Agreement at Deal Card approval, we record your consent timestamp (in AEST), your IP address at the time of consent, the service type the authorisation covers (e.g., electricity), and the agreement version you consented to. This data is collected to maintain a verifiable audit trail of your authorisation
- Account information:
- provider account numbers, plan details, contract terms, and provider correspondence received in the course of negotiations conducted on your behalf
- Payment information:
- billing details processed through our payment provider (Stripe) for success-fee charges. We do not store your full card details on our servers
- Usage data:
- device information, browser type, IP address, pages visited, and interaction data collected automatically when you use our website or application
3. How We Collect Information
We collect personal information through the following methods:
- Directly from you:
- when you create an account, upload bills, approve Deal Cards, submit identity documents, or contact us
- From your service providers:
- when we contact providers on your behalf under your Service Authorisation to negotiate rates, request plan details, or execute approved switches
- Through automated processing:
- uploaded bill documents are processed using artificial intelligence (specifically, Anthropic's Claude API) to extract billing data such as rates, charges, and plan details. See Section 5 for details on how AI is used in our service
- Automatically via our website:
- through cookies, server logs, and analytics tools when you interact with our website or application
4. How We Use Your Information
We use your personal information for the following purposes:
- Audit and benchmark your current household bills against market rates
- Generate Deal Cards presenting savings opportunities for your review and approval
- Act on your behalf under your Service Authorisation to negotiate retention offers, request plan changes, or execute provider switches that you have explicitly approved
- Verify your identity with providers during negotiations or switches
- Communicate with you about savings opportunities, service updates, and account activity
- Process success-fee payments in accordance with our pricing model
- Maintain an audit trail of all actions taken on your behalf
- Improve our rate comparison engine and service quality using de-identified data
- Comply with legal and regulatory obligations
5. Automated Processing & Artificial Intelligence
Resunday uses artificial intelligence to process your uploaded bill documents. Specifically:
- Bill extraction:
- uploaded PDF bills are processed by Anthropic's Claude API to extract structured data including rates, charges, plan names, and account details. The extracted data is used to benchmark your bills against current market rates
- What our AI-assisted tools don't do:
- No switching decision is automated. All switching and negotiation actions require your explicit approval via Deal Card acceptance before any action is taken
- Human oversight:
- AI-extracted data is used to generate savings estimates which are reviewed as part of our quality assurance process. You can review all extracted data in your dashboard before approving any action
Processing your documents through AI involves transmitting document data to Anthropic's servers in the United States. See Section 7 for details on cross-border data transfers.
6. Disclosure of Information
We may disclose your personal information to the following categories of recipients:
- Your service providers:
- energy retailers, internet providers, and insurance companies, in the course of negotiating or executing switches on your behalf under your Service Authorisation
- Cloud infrastructure:
- our platform is hosted on Supabase (powered by Amazon Web Services) which stores your account data, bill records, and application data
- Payment processing:
- Stripe processes all payment transactions. Stripe receives only the information necessary to process your payments
- Identity verification:
- Stripe Identity verifies your government-issued ID and selfie at Deal Card approval. Stripe captures and stores the identity document; we receive only the verification result and the matched name and date of birth needed to confirm you are the account holder
- AI processing:
- Anthropic (Claude API) processes uploaded bill documents for data extraction as described in Section 5
- Email services:
- Loops.so handles product and transactional email delivery; Resend handles authentication emails
- Advertising and conversion measurement:
- Meta Platforms, Inc. (Facebook and Instagram), only where you have opted in via our cookie banner. When enabled, the Meta pixel receives limited event data (such as that you viewed a page, completed a free audit, or reserved a seat, together with your IP address and browser information) so we can measure how our advertising performs. It is off by default and you can decline or withdraw at any time. See Section 10
- Government authorities:
- where required by law, regulation, or court order
We do not sell, rent, or trade your personal information to third parties, for any purpose. We may use your information for our own direct marketing, with your consent and with an opt-out in every message, as described in Section 12. Where you opt in via our cookie banner, we share limited event data with Meta Platforms to measure our advertising, as described in Section 10. This is not a sale of your personal information, it is off by default, and you can withdraw your consent at any time.
All third-party service providers are contractually required to handle your personal information in accordance with this policy and applicable Australian privacy law.
7. Cross-Border Data Transfers
Some of the third-party services we use to operate our platform are based outside Australia. In accordance with APP 8, we disclose that your personal information may be transferred to the following countries:
- United States:
- Supabase (cloud hosting via AWS), Stripe (payment processing and identity verification), Anthropic (AI bill extraction), Loops.so (email delivery), Resend (authentication emails), and, where you have opted in, Meta Platforms (advertising and conversion measurement)
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information. These steps include reviewing the recipient's privacy and security practices and entering into contractual arrangements that require compliance with equivalent privacy protections.
8. Data Security
We take the security of your personal information seriously and implement measures consistent with APP 11. Our security controls include:
- Encryption in transit (TLS) for all data transmitted between your device and our servers
- AES-256 encryption at rest for stored data, including billing records and account data
- Role-based access controls limiting internal access to personal information on a need-to-know basis
- Row Level Security (RLS) policies enforced at the database layer to ensure users can only access their own data
- Regular review of security practices and access controls
No method of electronic storage or transmission is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
9. Data Retention & Purging
We retain your personal information only for as long as necessary to fulfil the purposes described in this policy:
- Identity verification:
- we do not store your identity document. It is held by Stripe Identity for the verification; we instruct Stripe to redact it within 30 days of a completed switch or negotiation, or immediately when you delete your account. We retain only the verification outcome (that your identity was confirmed)
- Bill data:
- retained while your account is active to support ongoing benchmarking and savings tracking
- Free audit bills:
- source files uploaded to the free audit (no account required) are automatically purged within 90 days of upload. Before purging, de-identified data extracted from these bills may be retained in aggregated form to improve our bill analysis and rate comparison services
- De-identified data:
- bill data may be retained in de-identified and aggregated form (where it can no longer be linked to you as an individual) to improve our rate comparison engine. De-identification is performed by removing all personal identifiers and aggregating data across multiple users
- Account and transaction data:
- retained for the period required by applicable tax and financial record-keeping obligations
You may request deletion of your personal information at any time by contacting [email protected]. We will action your request within 30 days, subject to any legal obligations that require us to retain certain records.
10. Cookies & Analytics
We use cookies and similar technologies on our website. These fall into the following categories:
- Essential cookies:
- required for core site functionality, including authentication and session management. These cannot be disabled without affecting your use of the site
- Analytics cookies:
- used to understand how visitors interact with our website, including pages visited and navigation patterns. This data is collected in aggregate form
- Advertising cookies:
- set by the Meta pixel (Facebook and Instagram) to measure how our advertising performs and attribute audits and seat reservations back to the ads that drove them. These are off by default and load only after you accept them on the consent banner shown on your first visit. We do not load any advertising cookies unless you opt in
Advertising cookies stay off until you opt in, and load only after you accept them on the consent banner shown on your first visit. You can change your choice at any time using the Cookie preferences link in the footer, or through your browser settings. Declining advertising cookies will not affect core site functionality, and we never sell your personal information.
11. Your Rights
Under the Australian Privacy Principles, you have the following rights:
- Access (APP 12):
- you may request access to the personal information we hold about you. We will respond to your request within 30 days
- Correction (APP 13):
- you may request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading
- Deletion:
- while the APPs do not provide an absolute right to deletion, we will honour requests to delete your personal information where we are not required by law to retain it. Contact us to request deletion
- Withdraw consent:
- where we rely on your consent to process information (such as identity documents), you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal
- Complaint:
- you may lodge a complaint about our handling of your personal information (see Section 15)
To exercise any of these rights, contact us at [email protected].
12. Direct Marketing
We may use your contact details to send you communications about savings opportunities, service updates, and product features. In accordance with APP 7:
- You can opt out of direct marketing communications at any time by clicking the unsubscribe link in any email, or by contacting us at [email protected]
- We will action opt-out requests within 5 business days
- Opting out of marketing communications will not affect transactional messages related to your account activity (such as Deal Card notifications, switch confirmations, and billing receipts)
13. Children's Privacy
Our services are intended for individuals aged 18 years and over who are the legal account holders of household services. We do not knowingly collect personal information from individuals under 18. If we become aware that we have collected information from a minor, we will take steps to delete that information promptly.
14. Notifiable Data Breaches
In accordance with Part IIIC of the Privacy Act 1988 (Cth), if we become aware of an eligible data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- Notify affected individuals, including a description of the breach, the types of information involved, and recommended steps to mitigate potential harm
15. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by emailing [email protected]. Your complaint will be acknowledged within 7 days. Our privacy officer will investigate the matter, which may include consulting with relevant team members and reviewing our data handling practices. We will provide a written response within 30 days, including any remedial action we propose to take. If you are unsatisfied with our response, you may escalate the matter to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
16. Consumer Data Right (CDR)
The Consumer Data Right framework under Part IVD of the Competition and Consumer Act 2010 (Cth) applies to designated sectors including energy. Resunday does not currently operate as an Accredited Data Recipient under the CDR framework. We collect your energy billing data directly from documents you upload to our platform, not through CDR data-sharing arrangements.
If our participation in the CDR framework changes in the future, we will update this policy and notify you accordingly.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Where we make material changes (such as changes to the types of information we collect, how we use your information, or new categories of third-party recipients), we will notify you via email to the address associated with your account and update the "Last updated" date on this page.
Non-material changes (such as formatting or clarifications) will be posted on this page without individual notification. We encourage you to review this policy periodically.
18. Governing Law
This Privacy Policy is governed by the laws of Australia, with the laws of Victoria applying where state law is relevant. You submit to the exclusive jurisdiction of the courts of Victoria for any disputes arising under this policy.
19. Contact Us
For any questions or concerns about this Privacy Policy or our data practices, contact:
Resunday Pty Ltd
ACN 698 158 744
Privacy enquiries: [email protected]
General enquiries: [email protected]
This document was prepared by an AI-assisted legal research team for review purposes only. It does not constitute legal advice. Review and sign-off by a qualified Australian lawyer is required before use or execution.