Legal
This Privacy Policy explains how Match Well (ABN 62 397 979 132), operating as Merydia ('we', 'us', 'our'), collects, uses, stores, and discloses your personal information when you use the Merydia application and related services ('the Service').
We are bound by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). This policy is written to satisfy our APP 1 transparency obligation.
If you have questions about this policy or your personal information, contact our Privacy Officer at privacy@merydia.app.
When you register, we collect your name, email address, and professional information via LinkedIn OAuth. We receive only the information you authorise LinkedIn to share. We do not receive or store your LinkedIn password.
We collect the information you provide during onboarding, including your age, suburb, relationship goals, lifestyle preferences, and profile photographs. We also collect your responses to preference and compatibility questions.
We use your profile data to generate a compatibility score and select introduction candidates. We do not disclose the specific weighting applied to individual preference dimensions — this is proprietary — but we disclose that a weighted compatibility scoring model is used. Your preference data is not used for any purpose other than generating introductions within the Service.
Where you complete an attractiveness rating exercise during onboarding, those ratings are used solely to calibrate aesthetic compatibility matching and are not disclosed to other users or used for any other purpose. You have consented to this collection separately at the point of collection.
When you exchange messages with an introduction, message content is stored in our database and is retained for the period set out in Section 6 below. Messages are subject to automated content moderation for safety purposes.
We maintain an immutable ledger of credit transactions associated with your account, including credits purchased, credits consumed, and credits returned. Payment processing is handled by Apple (App Store) or Google (Google Play) and by RevenueCat as our subscription management intermediary. We do not hold your payment card data at any point.
We maintain an immutable record of every consent you have granted within the Service, including the consent type, the exact text displayed to you at the time of consent, a cryptographic hash of that text, and the timestamp. This record is retained for 7 years. You may withdraw consent at any time via Profile Settings > Manage Consents.
Our system maintains an immutable audit log of significant events associated with your account for compliance and safety purposes. Audit log records are retained for 7 years and are not disclosed to you as part of a Data Subject Access Request except to the extent required by law.
We use PostHog for product analytics. PostHog is configured without personally identifiable information — we do not transmit your name, email, or profile data to PostHog. Analytics data is used to improve the Service and is not used for targeted advertising.
We use Sentry for application error monitoring. Sentry is configured with personal information scrubbing: profile fields, message content, matching scores, photo data, and user identifiers are excluded from all error payloads before transmission to Sentry.
We use Expo Push Notification Service to deliver push notifications to your device. We transmit your device push token to Expo for this purpose only. We do not transmit profile content or matching data to Expo.
We use Postmark to deliver transactional and lifecycle emails. We transmit your email address and relevant account data to Postmark for delivery purposes only.
See Section 3 below.
This section is effective from [INSERT DOCV_GOLIVE_DATE].
Australian law requires us to confirm that you are 18 or older before you can access Merydia. To do this, we use a secure identity verification service provided by Veriff OÜ (Estonia).
You will be asked to photograph your government-issued ID document and take a selfie. Veriff compares these to confirm your identity and age. This process takes approximately 2 minutes.
Veriff processes verification data on servers located in Australia (AWS ap-southeast-2, Sydney). Some ancillary fraud-model processing may occur on servers located in the European Union. This cross-border disclosure is governed by Standard Contractual Clauses that provide protections equivalent to the Australian Privacy Principles. Veriff retains captured ID images and facial images for up to 6 months for operational and fraud-prevention purposes, after which they are permanently deleted. Veriff retains the verification reference and outcome for audit purposes.
We retain the verification reference number and outcome (pass/fail) in our records for 7 years, consistent with our legal record-keeping obligations. This reference number is used solely to confirm that age verification was completed. It is not used in matching, recommendations, or any other computation, and is not disclosed to any third party other than as required by law.
Age verification requires your consent. Your consent is recorded when you tick the checkbox on the age verification screen. You may withdraw this consent at any time via Settings > Privacy & Data. If you withdraw consent, you will be removed from the matching pool and will not receive introductions. Withdrawal of consent does not result in deletion of the verification reference number already held, as that record is required for our legal compliance obligations under the Online Safety Act 2021 (Cth). Requests for deletion of ID images and facial images held by Veriff should be directed to privacy@veriff.com.
Your facial image, as processed by Veriff, constitutes biometric information under the Privacy Act 1988 (Cth). We collect this information with your explicit consent for the sole purpose of age verification.
We use your personal information for the following purposes:
We do not use your personal information for targeted advertising. We do not sell, rent, or lease your personal information to any third party.
We disclose personal information to the following third-party service providers for the purposes described in Section 2: Veriff OÜ (age verification), RevenueCat (subscription management), Postmark (email delivery), Expo (push notifications), PostHog (analytics — no PII), Sentry (error monitoring — PII scrubbed), AWS via Supabase (database and storage hosting, Sydney).
When a mutual introduction is made, each party receives the other's profile information including their name, photographs, professional headline, and About me text. This disclosure is the core function of the Service and is consented to when you register.
We may disclose personal information to law enforcement agencies, the eSafety Commissioner, the OAIC, or other regulatory authorities where required or authorised by law, including mandatory reporting obligations under the Online Safety Act 2021 (Cth) with respect to child sexual abuse material.
We do not sell, rent, or lease your personal information to any third party for marketing purposes.
We retain personal information for the following periods:
Backups: Our infrastructure provider maintains rolling point-in-time recovery backups. Personal information deleted from our active database may remain in backup snapshots for up to 28 additional days before the backup rolls off. Backup access is restricted to our Technical Lead and is subject to documented access controls.
We implement the following security measures to protect your personal information:
No security system is impenetrable. In the event of a data breach likely to result in serious harm, we will notify you and the OAIC as required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
8.1 Access You may request access to the personal information we hold about you by contacting privacy@merydia.app. We will respond within 30 days.
8.2 Correction You may update most of your profile information directly within the app. For other corrections, contact privacy@merydia.app.
8.3 Deletion You may delete your account at any time from Profile Settings > Account > Delete Account. Profile data and photographs are purged within 30 days. Certain records (consent log, audit log, credit transactions, document verification reference) are retained for the periods set out in Section 6 due to legal obligations.
8.4 Withdrawal of Consent You may withdraw consent for specific processing activities via Profile Settings > Manage Consents. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.
8.5 Data Subject Access Request (DSAR) You may request a copy of your personal data in a portable format. DSARs are processed within 30 days. Note that system-generated compatibility scores may be excluded from DSAR exports subject to legal advice regarding proprietary methodology.
8.6 Complaints If you believe we have handled your personal information in a way that does not comply with the Australian Privacy Principles, you may lodge a complaint with us at privacy@merydia.app. We will respond within 30 days. If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
We disclose personal information to overseas recipients as described in Sections 2 and 5. All cross-border disclosures are governed by contractual arrangements that require overseas recipients to handle personal information consistently with the Australian Privacy Principles (APP 8).
Merydia's matching and delivery process is fully automated. Our algorithm generates compatibility scores and selects introduction pairs automatically. Introductions are delivered to users at 12:00pm AEST every Monday without individual human review or approval of any pair. A Product Owner hold mechanism exists: before 11:30am AEST on delivery day, the Product Owner may place a hold on the entire cycle's delivery if a systemic batch-level issue is identified. This is an exceptional intervention applied to the cycle as a whole and does not constitute individual human review of any introduction pair.
Because Merydia already uses fully automated decision-making in its current form, the disclosure obligation under the Privacy and Other Legislation Amendment Act 2024 (Cth) applies now and is satisfied by this section. We will update this section if the nature of the automated decision-making changes materially, including if algorithmic training methodology changes in a way that affects the basis on which decisions about individuals are made.
Merydia is intended exclusively for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. Age assurance (Section 3) is implemented to prevent under-18 access. If you believe we hold personal information about a minor, please contact us immediately at privacy@merydia.app.
We may update this Privacy Policy from time to time. Material changes will be notified to you by in-app notice at least 14 days before the change takes effect. The effective date at the top of this policy will be updated. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
Privacy Officer: privacy@merydia.app
Match Well, Sydney NSW Australia
ABN: 62 397 979 132
For document verification enquiries relating to data held by Veriff OÜ: privacy@veriff.com