Vantage Software Pty Ltd · Sydney · Global
Privacy
Policy
Effective 27.06.2026 — Version 1.0
The short version
What we collect
- Your name and email, if you make an account.
- What you read and how — scrolls, taps, dwell time, heatmaps.
- Your approximate location, from your IP address.
- The articles & images you save into Folios.
- Push tokens & device info, if you turn on notifications.
What we’ll never do
- Store your raw IP address (we hash it, one-way).
- Sell or rent your personal information.
- Use advertising or cross-site tracking cookies.
- Ignore your browser’s “Do Not Track” signal.
- Follow you around the rest of the internet.
This panel is a plain-language summary for convenience only. It is not a substitute for, and does not vary, the binding terms set out in the numbered clauses below, which prevail in the event of any inconsistency.
Preamble & scope
This Privacy Policy (the “Policy”) governs the manner in which Vantage Software Pty Ltd (ACN 695 152 231) (the “Company”, “we”, “us” or “our”) collects, holds, uses, discloses and otherwise processes Personal Information in connection with RIGHTEOUS in each of its forms — the website, the iPhone and iPad applications, and the Apple TV application (collectively, the “Services”). It applies to all users of the Services worldwide (“you”).
We are committed to handling Personal Information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (the “APPs”) and, to the extent applicable to you, the EU and UK General Data Protection Regulations (“GDPR” and “UK GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other applicable data-protection laws (together, “Data Protection Laws”).
Who we are & how to reach us
The Company is the data controller (and, for the purposes of the CCPA/CPRA, the “business”) responsible for your Personal Information. We are incorporated in Australia and based in Sydney, New South Wales. All privacy enquiries, requests and complaints may be directed to our standards desk at [email protected].
The information we collect
“Personal Information” means information or an opinion about an identified, or reasonably identifiable, individual. We collect only such Personal Information as is reasonably necessary for, or directly related to, the functions and activities described in this Policy.
(a) Information you provide
- Account data: your name, email address, and a cryptographically hashed password (we do not retain your password in plain text).
- Preferences: the settings you elect, including email digest and notification preferences.
- Saved content (Folios): the articles and images you save, the folios you create, any notes you attach, and your chosen visibility for each folio.
- Correspondence: the contents of communications you send to us.
(b) Information collected automatically (analytics)
To understand readership, we record interaction telemetry across the Services, namely:
- Activity events: pages and articles viewed, scroll depth, reading duration, time spent on individual article sections, links followed, navigation sequence (preceding and subsequent pages), images viewed and zoomed, and items saved.
- Interaction coordinates (heatmaps): the on-screen position of taps, clicks and (on the web) cursor movement, recorded as a proportion of page width and scroll depth rather than to the pixel, and thereafter aggregated.
- Technical data: device and browser type (user-agent), platform (web, iOS, tvOS), referring source, and the content version viewed.
- Identifiers: a randomly-generated visitor identifier and session identifier (stored in browser local storage on the web, or generated on-device in the apps), linked to your account where you are signed in.
- Approximate location: your country and, where enabled, region, city and approximate coordinates, derived from your IP address. We do not retain your raw IP address in our analytics; it is irreversibly hashed and used solely for rate-limiting and abuse prevention.
(c) Email & notifications
- Email engagement: our emails may contain a tracking pixel and instrumented links enabling us to measure opens and click-throughs.
- Push notifications: where you enable them, we store the push token, platform and device label so that Apple’s Push Notification service may deliver alerts to your device.
Cookies, local storage & Do Not Track
We do not use cookies for advertising, profiling or cross-site tracking. The only cookie we set is a strictly-necessary session cookie required to maintain your authenticated session. Our analytics identifiers are stored in local storage, which you may clear at any time. We honour the browser “Do Not Track” signal: where it is enabled, our web analytics do not operate.
Purposes & lawful bases
We process Personal Information to: (i) provide and operate the Services, including accounts, saving and folios; (ii) send verification, security, password-reset and (where you opt in) digest communications; (iii) understand and improve readership and our editorial and product, including aggregated analytics and heatmaps; (iv) secure the Services through rate-limiting, CAPTCHA and new-device alerts; and (v) comply with our legal obligations.
Where the GDPR or UK GDPR applies, we rely on the following lawful bases: performance of a contract (to provide accounts and features you request); your consent (for optional notifications and digest emails, and city-level geolocation, which you may withdraw at any time); our legitimate interests (to secure, measure and improve the Services, balanced against your rights); and compliance with legal obligations. We do not sell your Personal Information and we do not use it for third-party advertising.
Disclosure & service providers
We disclose Personal Information only to service providers (processors) engaged to perform functions on our behalf, and only to the extent necessary, including: Cloudflare (content delivery, security and bot protection, which also supplies the originating country of a request); ip-api.com (approximate IP-based geolocation, where city-level lookup is enabled); Apple Push Notification service (delivery of notifications); our email delivery provider; and our hosting provider. We require such providers to protect Personal Information consistently with this Policy. We may also disclose Personal Information where required or authorised by law, to protect our rights or the safety of any person, or in connection with a corporate transaction.
International transfers
The Services are operated from, and your Personal Information may be processed in, jurisdictions other than your own, including Australia, the United States and the European Union. Where we transfer Personal Information across borders, we take reasonable steps to ensure an adequate level of protection, including (as applicable) compliance with APP 8 and, for transfers subject to the GDPR or UK GDPR, reliance on adequacy decisions or the European Commission’s / UK’s Standard Contractual Clauses. You may request further information about these safeguards using the contact details below.
Retention
We retain account information for as long as your account remains active and thereafter only as required to meet our legal, accounting or reporting obligations. Raw analytics events are retained for a limited period (by default, approximately thirteen months) and are then deleted; only de-identified, aggregated trend data is retained beyond that period. Deleting your account removes your account, saved items, folios and notes.
Security
We implement reasonable technical and organisational measures appropriate to the risk, including password hashing, one-way hashing of IP addresses, access rate-limiting, new-device sign-in alerts and automated bot protection. No method of transmission or storage is wholly secure; however, we maintain procedures designed to protect Personal Information and to respond promptly to any data breach in accordance with applicable law (including the Notifiable Data Breaches scheme and, where relevant, GDPR breach-notification requirements).
Your rights
Subject to applicable law and verification of your identity, you may exercise the rights set out below by contacting [email protected]. We will respond within the timeframe required by the applicable Data Protection Law. We will not discriminate against you for exercising any right.
(a) All users
You may access and correct your information (your name, email and preferences are editable in your account settings), delete your account and associated data, and opt out of digest emails and notifications, and of web analytics via Do Not Track. Accounts that are also RIGHTEOUS staff (Studio) accounts are administered through Studio.
(b) Australia
You have the rights of access and correction under the APPs, and the right to complain to the Office of the Australian Information Commissioner (OAIC).
(c) European Economic Area & United Kingdom
Where the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing (including profiling based on legitimate interests), and the right to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).
(d) California
Under the CCPA/CPRA you have the rights to know, access, correct and delete the Personal Information we collect, and to opt out of any “sale” or “sharing” of Personal Information. We do not and have not sold or shared Personal Information as those terms are defined, nor do we process sensitive Personal Information for the purpose of inferring characteristics. You may use an authorised agent to submit requests.
(e) Other jurisdictions
If your local law grants you additional or equivalent rights, we will honour them to the extent they apply to you.
Children
The Services are intended for a general adult audience and are not directed at children under the age of 16. We do not knowingly collect Personal Information from children under 16 (or such higher age as your local law may require for consent). If you believe a child has provided us Personal Information, please contact us and we will delete it.
Changes to this Policy
We may amend this Policy from time to time. Material changes will be indicated by the “Effective” date and version above and, where required by law, notified to you. Your continued use of the Services following the effective date of any amendment constitutes acceptance of the amended Policy to the extent permitted by law.
Contact & representatives
Vantage Software Pty Ltd
Sydney, New South Wales, Australia
[email protected]
For the purposes of Article 27 of the GDPR, our representative in the European Union is Europa Privacy Services Ltd, 14 Merrion Square North, Dublin D02 XR63, Ireland ([email protected]). For the purposes of Article 27 of the UK GDPR, our representative in the United Kingdom is Albion Data Representation Ltd, 71–75 Shelton Street, London WC2H 9JQ, United Kingdom ([email protected]). Complaints may also be made to the OAIC (Australia), your EEA supervisory authority, or the UK ICO, as applicable.