Privacy policy

Last updated 12 April 2026. Written by humans, for humans.

Defaiflo Lotteries Pty Ltd (ABN 00 000 000 000) handles your personal information in line with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth). This policy explains what we collect, why we collect it, where we store it and the choices you have over your data.

1. Information we collect

When you browse our website, create an account, or buy a ticket, we collect the following:

  • Identity details: full name, date of birth and Australian address to confirm eligibility.
  • Contact details: email address and mobile number so we can reach you with draw results or support.
  • Payment metadata: the last four digits of the card used, the billing postcode and the transaction ID returned by our payment provider. We do not store the full card number.
  • Technical data: your IP address, browser type, device category and the pages visited on defaiflo.com.

2. How we use your information

We use the information you provide to:

  1. Confirm you are 18+ and an Australian resident.
  2. Sell tickets, issue receipts and notify winners.
  3. Run the Defaiflo Lotteries membership program and your preferred auto-entry tier.
  4. Respond to support requests and comply with applicable regulator reporting obligations.
  5. Improve the defaiflo.com experience through aggregated, de-identified analytics.

3. Who we share it with

Personal information is shared only with the parties required to run the lottery: our licensed drawing agent, our Australian payment processor, our email delivery partner and our regulated document storage provider. All partners are bound by confidentiality agreements. We do not sell personal information to third parties for marketing.

4. Cookies and analytics

We use a small set of first-party cookies to keep you signed in, remember your ticket bundle, and honour your cookie preferences. You can decline non-essential cookies via the cookie banner and clear them in your browser at any time. Our analytics tooling is configured to strip IP addresses before storage.

5. Storage and security

Your data is stored on Australian-hosted servers in Sydney and Melbourne with encryption at rest and in transit. Access is restricted to trained Defaiflo Lotteries team members via multi-factor authentication. We keep account data for the length of your membership plus seven years to meet tax and regulatory obligations, after which it is securely destroyed.

6. Your choices

  • Request a copy of the data we hold about you.
  • Ask us to correct anything that's out of date.
  • Close your account and request deletion of records not required by law.
  • Opt out of any marketing email — our draw-result emails are not marketing and will continue while your account remains open.

7. Complaints

If you're unhappy with how we've handled your information, please email privacy@defaiflo.com. If we can't resolve it together, you're welcome to escalate to the Office of the Australian Information Commissioner at oaic.gov.au.

8. Updates

We'll update this policy if we change how we handle information. Substantive changes trigger an email to active account holders at least 14 days before the new policy takes effect.