← BACK TO HOME

PRIVACY POLICY

Effective date: 24 March 2026

We treat your data like a rare orchid — we keep it safe, we give it only what it needs, and we definitely don't sell it to strangers. This policy explains what we collect, why, and what you can do about it.

1. WHO WE ARE

Roots and Rants is operated by Neon Dirt Pty Ltd (ACN 696 030 510), an Australian company. Throughout this policy, "we", "us", and "our" refers to Neon Dirt Pty Ltd.

This policy covers the Roots and Rants mobile application (the "App") and the website at rootsandrants.com (the "Website"). Together we call these the "Services".

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also respect the privacy rights of users in other jurisdictions.

2. WHAT PERSONAL INFORMATION WE COLLECT

We only collect information that is reasonably necessary to provide you with the Services. Here's the full picture:

2.1 Information you provide directly

Data When & why
Email address and password When you create an account or sign up to the waitlist. Used for authentication and to send you transactional emails (e.g. welcome email).
Username and display name When you create or edit your profile. Your username and display name are visible to other users in social features (the Deck).
Profile photo and bio Optional. If provided, these are visible to other users.
Climate zone Derived from your postcode during profile setup. We store only the climate zone code (e.g. "AU_SUBTROPICAL"), not your postcode.
Garden content Section names, descriptions, plant details, photos, captions, and assessment notes you add to your garden.
Deck posts, comments, and reactions Content you share on the Deck (our community feed). Posts and photos on the Deck are visible to all authenticated users.
Plant problem cases (ER) Descriptions, symptoms, and photos you submit when diagnosing plant issues.
Special babies Names, descriptions, personality notes, and photos of your favourite plants.
Design projects Garden design preferences, briefs, and photos submitted to our AI garden designer (Digby).
Feedback Bug reports, feature requests, and messages you submit through the in-app feedback form.
Merch votes and ideas Votes on merchandise ideas and any custom merch ideas you submit.

2.2 Information collected automatically

Data Purpose
Device platform and OS version Collected with feedback submissions and analytics events to help us fix bugs and improve the App across devices.
App version Included in feedback and error reports so we can identify version-specific issues.
Analytics events We use PostHog to understand how people use the App (e.g. which features are popular, where users drop off). Events include actions like signing up, submitting feedback, and navigating between screens. Your email and username may be associated with these events.
Crash and error reports We use Sentry to capture application errors and crash data. These reports may include technical context such as device type and OS but do not intentionally include personal content.

2.3 Information we do NOT collect

3. HOW WE USE YOUR INFORMATION

We use your personal information for the following purposes:

We will not use your personal information for purposes unrelated to the Services without your consent, except where required or authorised by law.

4. HOW WE SHARE YOUR INFORMATION

We do not sell, rent, or trade your personal information. We share data with third-party service providers only as necessary to operate the Services:

Service provider What they receive Why
Supabase (USA) All account and app data Database hosting, authentication, file storage, and server-side functions.
PostHog (USA/EU) Usage events, email, username, platform Product analytics to understand how the App is used.
Sentry (USA) Error data, device/OS context Crash and error monitoring.
Google (Gemini AI) (USA) Photos and text from AI features AI-powered plant identification and garden design. Data is sent server-side; Google processes it under their API terms.
Stripe (USA) Payment data (collected by Stripe directly) Processing donations. We do not receive or store card details.
Resend (USA) Email address Sending transactional emails (welcome emails, moderation alerts).
Cloudflare (USA) Standard web request data Website hosting and content delivery.

We may also disclose personal information where required by Australian law, court order, or to protect the safety of our users.

5. CROSS-BORDER DATA TRANSFERS

In accordance with APP 8, we want to be upfront: most of our service providers are based in the United States. This means your personal information may be transferred to, stored in, and processed in the US and other countries where our providers operate.

Before engaging these providers, we take reasonable steps to ensure they handle personal information in a manner consistent with the Australian Privacy Principles. This includes reviewing their privacy and security practices and relying on their published data processing terms.

By using the Services, you acknowledge that your data may be processed overseas as described above.

6. PUBLICLY VISIBLE INFORMATION

Some information you provide is visible to other authenticated users of the App:

Your garden sections, plants, ER cases, special babies, and design projects are private to your account and are not shared with other users.

7. DATA SECURITY

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our measures include:

No system is perfectly secure. While we do our best, we cannot guarantee absolute security of your data.

8. DATA RETENTION

We retain your personal information for as long as your account is active or as needed to provide the Services. Specifically:

9. DELETING YOUR ACCOUNT

You can delete your account at any time from within the App:

  1. Go to Settings.
  2. Tap Delete Account.
  3. Confirm the deletion.

When you delete your account, we permanently delete:

Account deletion is permanent and irreversible. Some data may persist in encrypted backups for a limited period, and data already shared with third-party analytics or error reporting services may be retained according to their respective policies.

If you cannot access the App or need assistance deleting your account, email us at support@rootsandrants.com and we will process your request within 30 days.

10. YOUR RIGHTS UNDER AUSTRALIAN PRIVACY LAW

Under the Australian Privacy Principles, you have the right to:

To exercise any of these rights, contact us at support@rootsandrants.com. We will respond to access and correction requests within 30 days. We may need to verify your identity before processing your request.

We will not charge you for making a request or for giving you access to your personal information, unless the request is manifestly unfounded or excessive.

11. CHILDREN'S PRIVACY

The Services are not directed at children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.

If you believe a child under 16 has provided us with personal information, please contact us at support@rootsandrants.com.

12. COOKIES AND WEBSITE TRACKING

The rootsandrants.com website is a simple static site. We do not use cookies, tracking pixels, or advertising trackers on the Website. The waitlist signup form sends your email directly to our server — no third-party marketing tools are involved.

Our hosting provider (Cloudflare) may collect standard web server logs (IP addresses, browser type, pages visited) for security and performance purposes under their own privacy policy.

13. DIRECT MARKETING

We do not engage in direct marketing. We will only send you emails that are transactional in nature (e.g. welcome emails, password resets) or directly related to your use of the Services.

If we ever introduce marketing communications in the future, we will obtain your opt-in consent and provide a clear unsubscribe option in every message, in accordance with the Spam Act 2003 (Cth).

14. COMPLAINTS

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you can lodge a complaint with us:

We will acknowledge your complaint within 7 days and aim to resolve it within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

15. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. When we make material changes, we will:

We encourage you to review this page periodically. Your continued use of the Services after changes are posted constitutes acceptance of the updated policy.

16. CONTACT US

If you have any questions about this Privacy Policy or how we handle your personal information, get in touch:

Neon Dirt Pty Ltd (ACN 696 030 510)
Email: support@rootsandrants.com
Website: rootsandrants.com