Skip to main content

Privacy policy

Last reviewed: 2026-04-20

Spitfire Association Website

Privacy Policy

This page informs website visitors of our policies regarding the collection, use and disclosure of Personal Information provided to the Spitfire Association website, known here as the “Service”.

If you choose to use our Service, then you agree to the collection and use of information in relation to this policy. The Personal Information that we collect is used only for providing and improving the Service. We do not share your information with anyone except as described in this Privacy Policy.

The Spitfire Association complies with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth).

Information Collection and Use

Where you contact us or join the Association, we may collect personally identifiable information, including your name, email address, phone number and postal address. This information is used only to contact or identify you.

Biographical content (names, ranks, service numbers, dates) published about historical crew members is drawn from public-domain sources including the Australian War Memorial and the National Archives of Australia, and from materials provided with consent by families and contributing authors.

Log Data

When you visit our Service, standard server logs record information such as your computer’s IP address, browser version, pages visited, and the time and date of your visit. This log data is used for operational and security purposes only.

In addition, when you sign in as a member (or attempt to), our application records your IP address and the timestamp of that attempt, for the sole purpose of detecting and blocking brute-force login attempts. These records are retained for no longer than 30 days.

Committee administration

When a committee member signs in with administrator privileges and edits content (an article, a biography, a shop product, a member record), we record the action, the admin’s member ID and email, the IP address, and a field-level summary of what changed. This is an internal accountability log — viewable only by administrators — used to reconstruct the history of a page if a question arises about an edit. We retain these records for 3 years, after which they are automatically deleted.

Individual audit entries cannot be erased on request (they exist so the Association can answer “who changed this article and when” accurately). If a committee member leaves and their underlying member record is anonymised, the display of their email in audit entries is replaced automatically.

Short-link click counters

The Association operates a URL shortener at spitfr.au so articles can be shared with shorter URLs. We count aggregate clicks per short link (“humans” and “bots” separately, based on the User-Agent header) so administrators can see which content is getting attention. We do not record your IP address, browser User-Agent, referring page, or any information that could identify an individual visitor. The counters are aggregate only.

Cookies

We use a small number of first-party cookies that are strictly necessary for the site to function: your session cookie, and a cookie recording your cookie-consent choice (valid for 180 days, after which we ask again). These are set on our own domain and are not shared with any third party.

On the first visit you will see a banner asking for consent. Choosing Reject non-essential means we set only the strictly necessary cookies described above. Choosing Accept all additionally enables hCaptcha (which protects our forms from spam). Your browser also provides options to accept or refuse cookies at any time.

What we do NOT use

This site does not use any of the following, on any page:

  • Google Analytics or any behavioural analytics platform
  • Facebook Pixel, Facebook SDK, or any social-media tracking
  • LinkedIn, Twitter/X, TikTok or other platform trackers
  • Third-party advertising networks or remarketing
  • Third-party live-chat widgets
  • CDN-hosted fonts (our typefaces are self-hosted)

Service Providers

We use a small, named set of third-party services in specific, limited ways:

  • Our hosting provider hosts the website and its database.
  • Stripe processes payments. Stripe is loaded only on pages where a payment can occur (shop, membership and renewal pages) and is not present on biographical, news or informational pages. Stripe's own privacy policy applies to transactions it handles.
  • MailChimp (Intuit Mailchimp, United States) holds the Association's membership mailing list. Three separate flows send Personal Information to MailChimp:
    • Creating a website login: we pass your email address to MailChimp to verify that you are a current member before we create a login record.
    • Ordering through the online shop: we pass your name, email, phone, postal address and any honorifics you provided at checkout to MailChimp, and add you to the Association's mailing list. We do this because people who buy tickets, merchandise or membership are generally the people who want to hear what the Association is doing. We also record what kind of purchase you made — an event ticket, merchandise, or a ticket to a particular occasion — so we can write to you about arrangements for an event you are attending without emailing everyone. You can unsubscribe from any email we send or from your member dashboard; this is a single list, so unsubscribing ends all Association mail, including renewal reminders, notices of meetings and event invitations. Your membership itself continues to the end of the financial year, but email is our only means of contacting members, so we would have no way to remind you to renew. Order receipts are sent by the website itself and are unaffected.
    • Subscribing from our homepage: we pass your email address to MailChimp and add you to the Association's mailing list. You may receive event invitations, notices of meetings and occasional Association news. This is a single list, so unsubscribing ends all Association mail. Subscribers are retained in MailChimp until they unsubscribe, request deletion, or the Association archives the audience; you can unsubscribe from any email we send or by contacting the address below.
    You can change your marketing preference at any time from your member dashboard, via the unsubscribe link in any email we send, or by contacting privacy@spitfireassociation.com. MailChimp's own privacy policy applies to that exchange.
  • hCaptcha (provided by Intuition Machines, Inc.) protects our contact and registration forms from automated spam. It is loaded only after you have given cookie consent.
  • Microsoft 365 (Microsoft Corporation, United States) delivers outbound email from the site (password-reset links, membership-renewal confirmations, and webhook audit alerts) via the Microsoft Graph API. Only the recipient address, subject line and message body transit Microsoft's infrastructure. Microsoft's own privacy practices apply to that transit.

These providers are given access to Personal Information only where required to perform the specific task assigned, and are obligated not to disclose or use the information for any other purpose.

Overseas disclosure

Stripe, MailChimp, hCaptcha and Microsoft are United States-based providers. Where Personal Information is disclosed to them in the course of the specific tasks above, it is subject to their own privacy practices. We do not otherwise disclose Personal Information outside Australia.

Security

We value your trust in providing us with Personal Information and use commercially acceptable means to protect it: HTTPS site-wide, session cookies with Secure and HttpOnly flags, server-side input validation, prepared database statements, and a Content Security Policy that restricts what code can execute on the site. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Links to Other Sites

Our Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. These external sites are not operated by us. We strongly advise you to review the privacy policy of any website you visit. We have no control over, and assume no responsibility for, the content or privacy practices of third-party sites.

Children’s Privacy

Our Services do not address anyone under the age of 18. We do not knowingly collect personal identifiable information from children under 18. If we discover that a child under 18 has provided us with personal information, we will delete it from our systems. If you are a parent or guardian and are aware that your child has provided us with personal information, please contact us and we will take appropriate action.

Access, correction and complaints

Under APP 12 and APP 13 you may request access to, or correction of, the Personal Information we hold about you. Requests should be made to our privacy contact below. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We advise you to review this page periodically for any changes. Updates take effect immediately on posting.

Contact Us

If you have any questions or suggestions about our Privacy Policy, please contact the Spitfire Association:

Spitfire Association
12 Gerald Ave
Roseville NSW 2069
privacy@spitfireassociation.com