ZAP
Effective 3 July 2026
Zap is the internal team-communication platform operated by Third Wave BBQ (“we”, “us”) for staff and managers across our venues. It is a workplace tool available by invitation only — it is not a public service. This policy explains what personal information we collect through Zap’s web, desktop, and mobile apps, how we use it, and the choices you have. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Account and profile. Your name, work email address, phone number (if provided), venue and position, display name, profile photo, bio, and timezone.
Sign-in information. One-time login codes sent to your email, and — if you choose “Continue with Google” — your basic Google account profile (name, email, avatar). We never see or store your Google password.
Content you create. Messages, thread replies, reactions, polls and votes, uploaded files and photos, collaborative canvases, custom statuses, scheduled messages, shift and swap information, maintenance requests, and announcement acknowledgements.
Technical information. Device push-notification tokens, IP address, browser or device identifiers, and security audit logs (for example sign-in events and session activity). We use these to keep accounts secure and the service reliable.
We do not sell personal information, and we do not use your content for advertising.
Zap is provided for work purposes. Content you post (including direct messages) is stored on company systems and may be accessed by authorised administrators where reasonably necessary — for example to investigate misconduct, comply with legal obligations, moderate content, or export records. Deleted messages may be retained in edit-history and backups for a period. Please treat Zap like any workplace system rather than a private messaging service.
We share personal information only with service providers who help us run the platform:
Some of these providers process data outside Australia. Where that happens, we take reasonable steps to ensure your information is handled consistently with the Australian Privacy Principles. We may also disclose information where required by law.
Connections are encrypted in transit (HTTPS). Login tokens are stored hashed on our servers and in secure storage on your device, sessions are bound to your device and expire automatically, and administrative actions are audit-logged. No system is perfectly secure, but if we become aware of a data breach likely to result in serious harm we will notify affected people and the OAIC as required by the Notifiable Data Breaches scheme.
We keep your information while you work with Third Wave BBQ and for a reasonable period afterwards to meet record-keeping and legal obligations. When your account is deactivated, your sign-in access is revoked immediately; content you contributed to shared conversations may be retained as part of the team’s records. You can request deletion of your account and personal data at any time — see Delete your account.
You can view and update most of your profile information in the app. To request access to, or correction of, other personal information we hold about you — or to make a privacy complaint — contact us at privacy@thirdwavebbq.com.au. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
We may update this policy from time to time. Material changes will be announced in the app, and the effective date above will always reflect the current version.