Privacy Policy

Last updated: 2 April 2026  ·  Effective: 2 April 2026

This Privacy Policy describes how CostMyRecipe.app ("we", "us", or "our"), operated by Website Wizard of Oz (ABN 22 551 534 961), collects, uses, discloses, and protects your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using CostMyRecipe.app, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the service.


1. Who We Are

Business name: Website Wizard of Oz

ABN: 22 551 534 961

Website: costmyrecipe.app

Privacy contact: [email protected]

2. What Information We Collect

We collect personal information only to the extent necessary to provide our services (APP 3 — Collection of solicited personal information).

2.1 Information You Provide Directly

  • Account registration: name, email address, login method (email/password, Google, or Apple)
  • Recipe data: recipe names, ingredient lists, quantities, and costs you create and save
  • Feature suggestions: ideas and feedback you submit on our Suggestions page
  • Referral codes: your unique referral code and any codes you redeem
  • Communications: emails or messages you send to us

2.2 Payment Information

We use Stripe to process all payments. We do not store your credit card number, CVV, or full card details on our servers. Stripe stores and processes payment information under their own privacy policy and PCI-DSS compliance. We retain only:

  • Your Stripe Customer ID (to manage your subscription)
  • Your Stripe Subscription ID (to track your plan status)
  • Your subscription plan name and status

2.3 Information Collected Automatically

  • Usage data: pages visited, features used, clicks, and session duration (via Google Analytics 4)
  • Device information: browser type, operating system, screen size, and IP address
  • Cookies and similar technologies: session cookies for authentication, analytics cookies (see Section 7)
  • Log data: server logs including IP address, request timestamps, and error reports

3. How We Use Your Information

We use your personal information only for the primary purpose for which it was collected, or a directly related secondary purpose (APP 6 — Use or disclosure of personal information). Specifically:

PurposeLegal Basis
Provide and operate the CostMyRecipe serviceContract performance
Process subscription payments via StripeContract performance
Send account-related emails (receipts, plan changes)Contract performance
Authenticate and secure your accountLegitimate interest / contract
Respond to your enquiries and support requestsLegitimate interest
Improve and develop new featuresLegitimate interest
Analyse usage patterns via Google AnalyticsLegitimate interest (anonymised)
Send marketing emails (only with your consent)Consent
Comply with legal obligationsLegal obligation

4. Disclosure of Your Information

We do not sell, rent, or trade your personal information. We may disclose it to trusted third parties only as necessary to operate our service (APP 6):

Stripe Inc.

Payment processing and subscription management

Location: USA (Privacy Shield / Standard Contractual Clauses)

View their privacy policy →

Google LLC (Analytics & Tag Manager)

Website analytics and conversion tracking

Location: USA (Standard Contractual Clauses)

View their privacy policy →

Manus AI Platform

Application hosting, database, and OAuth authentication

Location: USA

View their privacy policy →

We may also disclose your information where required by Australian law, a court order, or to protect the rights, property, or safety of our users or the public.

5. Overseas Disclosure (APP 8)

Some of our third-party service providers are located overseas (primarily the United States). Before disclosing your personal information to an overseas recipient, we take reasonable steps to ensure they handle your information in a manner consistent with the Australian Privacy Principles. By using our service, you consent to this overseas disclosure. We remain accountable for how those recipients handle your information.

6. Data Security (APP 11)

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:

  • HTTPS encryption for all data in transit (TLS 1.2+)
  • Encrypted session tokens (JWT) with secure, HTTP-only cookies
  • Passwords hashed using industry-standard algorithms (never stored in plain text)
  • Database access restricted to application servers only
  • Stripe handles all payment card data under PCI-DSS Level 1 compliance
  • Regular security reviews and dependency updates

No method of internet transmission is 100% secure. If you believe your account has been compromised, please contact us immediately at [email protected].

7. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our service:

Cookie / TechnologyPurposeType
Session cookieKeeps you logged in securelyEssential
Google Analytics (_ga, _gid)Anonymous usage analyticsAnalytics
Google Tag ManagerManages analytics and marketing tagsAnalytics

You can disable cookies in your browser settings. Note that disabling essential cookies will prevent you from logging in. Google Analytics can be opted out via the Google Analytics Opt-out Browser Add-on.

8. Data Retention (APP 11.2)

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected:

  • Account data: retained while your account is active; deleted within 30 days of a verified account deletion request
  • Recipe data: retained while your account is active; deleted upon account deletion
  • Payment records: retained for 7 years to comply with Australian tax law (ATO requirements)
  • Analytics data: retained for 26 months in Google Analytics (Google's default)
  • Server logs: retained for 90 days for security and debugging purposes

9. Your Rights Under the Australian Privacy Act

Under the Privacy Act 1988 and the Australian Privacy Principles, you have the following rights:

APP 12

Access

You have the right to request access to the personal information we hold about you. We will respond within 30 days.

APP 13

Correction

If you believe information we hold is inaccurate, out of date, or incomplete, you can request we correct it. You can update most information directly in your account settings.

APP 3

Deletion

You can request deletion of your account and personal data. We will action this within 30 days, subject to legal retention obligations (e.g. tax records).

APP 7

Opt-out of direct marketing

You can opt out of marketing emails at any time by clicking 'Unsubscribe' in any email or contacting us directly.

APP 1

Complaint

If you believe we have breached the APPs, you can lodge a complaint with us first. If unresolved, you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before processing your request.

10. Children's Privacy

CostMyRecipe.app is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

11. Third-Party Links

Our website may contain links to third-party websites (such as Stripe's checkout page). We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before providing any personal information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email. We encourage you to review this policy periodically. Continued use of CostMyRecipe.app after changes constitutes your acceptance of the updated policy.

13. Contact Us

For any privacy-related questions, requests, or complaints, please contact our Privacy Officer:

Privacy Officer

Website Wizard of Oz

ABN 22 551 534 961

Email: [email protected]

Website: websitewizardofoz.com.au

Office of the Australian Information Commissioner (OAIC)

If you are not satisfied with our response to a privacy complaint, you may contact the OAIC:

www.oaic.gov.au →

This Privacy Policy was last updated on 2 April 2026 and is effective from 2 April 2026.
© 2026 Website Wizard of Oz (ABN 22 551 534 961). All rights reserved.