Onside Consulting Pty Ltd (ABN 41 693 900 695) runs this website, and runs an app on the Meta platform called Onside AI, App ID 1420405316796685. In this policy, "we", "us" and "our" mean Onside Consulting Pty Ltd. This policy explains what we collect, why, who we share it with, and how to get it deleted.
We handle personal information in two very different roles.
When you deal with Onside directly by visiting this website, booking a call, or becoming our client, we decide how your information is used. We are the controller of that information and this policy governs it.
When we run advertising for a soccer coaching business that hired us, the parents and players who respond to those ads are that business's customers, not ours. That business decides what happens to their information. We act on its instructions, as its service provider. In UK and EU terms, the coaching business is the controller and we are its processor.
You can still come straight to us to have your information deleted, and we will act on it without making you go to the coaching business first.
Our app on the Meta platform is called Onside AI, App ID 1420405316796685. Nobody logs into it. No member of the public ever signs into it with Facebook or Instagram. Our clients give our Business Manager partner access to their advertising assets inside Meta Business Manager, and our software then works on those assets.
Here is everything the app reads from Meta, and it is a short list.
Advertising structure. The names, settings, schedules and status of campaigns, ad sets, ads and ad creatives inside our clients' ad accounts.
Advertising performance. Spend, impressions, reach, clicks, cost per result, and how many enquiries or bookings each ad produced. These are counts and totals. They do not name anyone.
Identifiers. The ad account, Facebook Page, Instagram account and advertising pixel our client tells us to work on, so that ads and tracking are attached to the right place.
Asset lists. Which of a client's accounts, Pages and pixels have been shared with our Business Manager, so we know what we are allowed to touch.
What it does not do, and this is deliberate. It does not download enquiry form submissions. It does not read, send or store Facebook or Instagram messages. It does not read or reply to comments. It does not post to Instagram or to any Page. It does not read anyone's profile, friend list, photos or timeline. We hold none of that, because we never ask for it.
When a parent responds to one of our clients' ads and fills in an enquiry form, their details go into that coaching business's own customer relationship management account, so the coach can contact them about a session. That is the point of the form, and the form says so at the time.
Those details do not pass through our Meta app. They arrive in the coaching business's own account through its own connection to Meta. We administer that account for our client as their agency, so we can see and work with those details on the client's behalf, and we handle them only to run the follow up we were hired to run.
A form typically collects the parent's name, email address and phone number, and the answers to the coach's own questions, which usually include a child's first name and age.
We never use those details to reach anyone outside the campaign they responded to. We never build profiles of individual people. We never sell, license or trade them, and we never give them to a data broker.
Our clients' websites and booking pages carry a Meta pixel. When a parent visits one of those pages or completes a booking, the pixel tells Meta the event happened. We also send the same events to Meta from our own servers using the Meta Conversions API, which is a more reliable copy of the same information, not extra information.
An event sent from our servers can include the parent's email address, phone number, name, city, state, postcode and country, along with the browser identifiers Meta itself set on that website. Contact details are hashed with SHA-256 before they leave our systems, so Meta receives a scrambled string rather than the plain email address or phone number, and uses it to match the event to an account it already has.
We never send Meta health information, financial information, government identifiers, card numbers, or anything about a person's race, religion, politics, sexual orientation or union membership. We never knowingly send Meta information about a child.
Where we build and run a client's website, we put the tracking notice on it. Where the client runs their own website, that notice is the client's responsibility.
If you contact us or book a call: your name, email address, phone number, business name, and whatever you tell us about your coaching business.
If you become our client: the above, plus your advertising account details, your billing details (handled by our payment processor, never stored by us), and our working notes about your account.
If you consent to SMS: your mobile number, for the program described below.
If you visit this website: standard analytics about pages viewed, collected in aggregate.
We collect this because you gave it to us, to deliver a service you asked about or bought.
Onside Consulting operates one SMS text messaging program, named Onside Consulting. It covers appointment confirmations and reminders for a consultation call you have booked, customer care messages, and follow-up messages about our services for youth soccer coaching businesses. You join it by ticking the SMS consent checkbox on our opt-in page or on any Onside Consulting web form carrying the same checkbox. The checkbox is never pre-ticked, and consent is never required to use our website or services.
Message frequency may vary. Message and data rates may apply. Reply STOP to opt out at any time, or reply HELP for help. Full program details are in our SMS Terms.
SMS opt-in data and consent are never shared with anyone, for any purpose. Not with affiliates, not with partners, not for marketing, not for anything else. This is an absolute exclusion from every sharing category below.
We do not sell personal information. We never have and we will not.
With the coaching business you responded to. If you filled in a form on a soccer coaching ad we run, your details go to that coaching business, because that is what the form was for.
With the companies whose software we run the business on. Each may only use information to do the job we hired it for, and each is bound to keep it confidential. The ones that can handle personal information are: GoHighLevel (United States), the customer relationship system that holds contact details and sends our email, SMS and WhatsApp messages; Google (United States), which hosts our email and files; Railway (United States), which runs the scheduled software that talks to Meta; Meta Platforms (United States and Ireland), which receives the advertising events described above; and Stripe (United States), which processes client payments.
We also use software that handles our own business records rather than yours, including accounting, internal documentation and website hosting. Those hold company records and our own notes, not the enquiry details described above.
When the law requires it, or to protect someone's safety or our legal rights.
We are in Sydney, Australia. Most of the companies listed above are in the United States, and Meta may also process information in Ireland. That means your information will be sent outside Australia.
Before we do that, we take reasonable steps to satisfy ourselves that the company receiving it will protect it to the standard the Australian Privacy Principles require.
We keep information only while we have a reason to, and we judge that by what it is for rather than by a fixed calendar.
Enquiry and contact details are kept while we are running that client's campaigns and for a reasonable period afterwards, so the client can still see where their players came from. After that they are deleted.
Advertising performance records are spend and result totals that do not name anyone, and we keep those as our own business history.
Records that Australian tax and company law require us to hold are kept for as long as that law requires, because we are not permitted to delete them sooner.
Separately from all of that, we delete information we obtained from Meta as soon as we no longer need it for the reason we got it, when the person asks us to, when Meta asks us to, when a client stops working with us, or if we stop trading. We do that whether or not anyone asks.
If you want to know what we currently hold about you and for how long, ask us at info@onside.consulting and we will tell you.
Anyone can ask us to delete their information. You do not need an account with us. You do not need to be a client. It does not matter what country you are in. It costs nothing, and we do not ask you to explain why.
Email info@onside.consulting with the subject line Delete my data. Tell us the email address or phone number you gave us so we can find you. That is all we need. Do not send identity documents. We will not ask for them.
We confirm we have received your request within 5 business days and complete the deletion within 30 days. If Australian law makes us keep a particular record, we will tell you exactly which record and why, and we will not use it for anything else.
Full step-by-step instructions, including how to cut off our access yourself, are on our data deletion page.
You can ask us for a copy of the personal information we hold about you. You can ask us to correct it if it is wrong. You can ask us to delete it. You can tell us to stop sending you messages, by replying STOP to any SMS or using the unsubscribe link in any email.
For anything else, email info@onside.consulting. We answer within 30 days and we do not charge.
If you are unhappy with how we handled your information, tell us first and we will try to put it right. If you are still unhappy you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
UK and EU data protection law gives you additional rights. You can ask us for your information in a portable form, ask us to restrict how we use it, and object to us using it.
Who is responsible. When we run ads for a UK or EU coaching business, that business is the controller of the parent and player information and we are its processor, acting on its instructions. When you deal with Onside directly about our own services, we are the controller.
Our lawful bases are consent, where you ticked a box to hear from us or submitted an enquiry form; contract, where we need the information to deliver a service you or your business bought; and legitimate interests, where we measure how advertising performs.
You can complain to the UK Information Commissioner's Office at ico.org.uk, or to the supervisory authority in your own country.
We want to be precise about this, because a vague answer here is worse than none.
We sell our services to adults who run soccer coaching businesses. We do not market to children, and a child cannot set anything up with us.
Our clients coach children, so when a parent responds to an ad the form usually asks for the child's first name and age. The parent provides that, not the child. It is held so the coach knows who is attending and which age group to place them in.
We never use a child's information for advertising. We never build a profile of a child. We never send a child's information to Meta.
If you are a parent and you want your child's details removed, email info@onside.consulting and we will delete them.
We take reasonable measures to protect personal information from unauthorised access, disclosure, alteration and destruction. Information is encrypted in transit, credentials are held in a password manager rather than in our code, and access is limited to the people who need it.
No method of transmission over the internet or electronic storage is entirely secure, and we cannot guarantee absolute security.
We may update this policy to reflect changes in what we do, or for legal or operational reasons. The effective date at the top of this page tells you when it last changed. If we change it in a way that matters, we will say so on this page.
Questions, access requests, correction requests and deletion requests all go to info@onside.consulting.
Onside Consulting Pty Ltd
ABN 41 693 900 695
Sydney, NSW, Australia
We are also the privacy contact for the Onside AI app on the Meta platform, App ID 1420405316796685.