top of page

Privacy Policy

1. Privacy Policy


This Privacy Policy explains how the Australian Newsagents’ Federation (trading as the Australian Lottery and Newsagents Association – “ALNA”, and Local Retailers Australia (LRA) “we”, “us”, “our”) collects, holds, uses, and discloses personal information. It applies to all personal information we handle in connection with:


  • Our public websites (www.alna.net.au and www.localretailers.au)

  • The Local Retailers Hub – our Wix-based member portal (www.localretailershub.com.au)

  • Our VTiger CRM member database, which holds comprehensive member account and relationship records

  • Microsoft 365 and OneDrive for Business, used for document storage, internal file management, and staff collaboration

  • Email communications, event registrations, and other direct interactions


We are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth). We are committed to handling personal information in accordance with those principles and this Policy.


By using our services, you agree to the collection and use of your personal information as described in this Policy.



2. What Information Do We Collect?


2.1 Information You Provide Directly

The personal information we collect depends on your relationship with us and the context in which you provide it. Categories of information we may collect include:


  • Identification details: full name, business name, trading name, ABN

  • Contact details: postal address, email address, telephone and mobile numbers

  • Business details: store type, location, licensed products held (e.g. lottery agent, Western Union sub-agent), membership tier

  • Payment information: bank account or card details for membership fees or supplier transactions (processed via secure third-party payment processors)

  • Employment-related information: provided when using our Employment Advisory Service

  • Correspondence and communications: emails, enquiries, complaints, and other communications you send to us

  • Survey and feedback responses


2.2 Local Retailers Hub

The Local Retailers Hub is our member-facing portal. Through this portal, we collect and hold a more limited set of data, which may include:


  • Member login credentials (email address and password)

  • Profile information you complete within the Hub (store name, contact details)

  • Content you post in discussion forums or community features

  • Your activity within the Hub (pages visited, resources downloaded, event registrations)


2.3 CRM – Member Database
Our primary member database is a cloud-based customer relationship management platform. It holds comprehensive records about our members, including:


  • All identification and contact information listed in section 2.1

  • Membership status, tier, and history

  • Records of communications and correspondence with us

  • Notes and activity logs maintained by our staff

  • Subscription and service preferences

  • Financial transaction records related to membership and services


Note: Our CRM is hosted on cloud infrastructure. Data stored may be held on servers located in Australia or overseas depending on infrastructure configuration. See section 6 (International Transfers) for further detail.


2.4 Information Collected Automatically

When you visit our website or the Local Retailers Hub, we and our third-party service providers automatically collect certain technical information, including:


  • IP address and approximate geographic location

  • Browser type, version, and operating system

  • Pages visited, links clicked, and time spent on pages

  • Referring website or search terms used to reach our site

  • Device type and screen resolution


This information is used for security, platform performance monitoring, and internal analytics. It does not, on its own, identify you personally.


2.5 Cookies and Tracking Technologies

We use cookies and similar technologies (including web beacons and pixels) on our website’s and the Local Retailers Hub. Cookies serve a number of purposes, including:


  • Keeping you logged in to the Hub

  • Remembering your preferences

  • Analysing site usage to improve our services (via analytics tools such as Google Analytics)

  • Supporting third-party advertising functionality


You can control or disable cookies through your browser settings. Disabling some cookies may affect the functionality of the Hub or website. Our Cookie Policy provides more detail on the specific cookies we use and how to opt out.



3. Why Do We Collect and Use Personal Information?


We collect and use personal information for the following primary purposes:


  • Administering your membership, including processing applications, renewals, and cancellations

  • Providing member services including newsletters, The magazine, industry updates, employment advice, and supplier programs

  • Operating the Local Retailers Hub and providing access to member-only resources and community features

  • Processing payments for membership fees, events, and other services

  • Communicating with you about industry news, advocacy activities, regulatory changes, and matters affecting your business

  • Conducting advocacy on behalf of members, including preparing regulatory submissions and representations to government

  • Organising and managing member events, roadshows, and training programs

  • Managing our commercial relationships with suppliers and business partners

  • Complying with our legal obligations, including obligations under the Anti-Money

  • Laundering and Counter-Terrorism Financing Act 2006 (where applicable to sub-agency arrangements)

  • Enforcing our Terms of Use and resolving disputes

  • Improving our services and understanding the needs of our membership base


We will only use your personal information for the purpose for which it was collected, or for a related purpose you would reasonably expect, unless you have consented to another use, or we are permitted or required by law to use it for another purpose.



4. Who Do We Share Personal Information With?


We may share your personal information with third parties in the following circumstances:


4.1 Service Providers and Technology Platforms
We share personal information with third-party vendors, technology providers, and contractors who perform services on our behalf and require access to that information to do so. These include:


  • CRM – our member database and relationship management platform

  • Wix.com Ltd – the platform hosting the Local Retailers Hub

  • Microsoft Corporation – Microsoft 365 and OneDrive for Business, used for document storage, internal communications, and staff file management

  • Email delivery and marketing platforms (e.g. for sending newsletters and member communications)

  • Other cloud based automations

  • Payment processors and financial institutions

  • Event management platforms

  • IT support and cybersecurity service providers

  • Professional advisers including legal, accounting, and insurance professionals


We require all service providers to handle your personal information in accordance with the Australian Privacy Principles and, where applicable, to maintain appropriate data security measures.


4.2 Business Partners
We may share relevant member information with our commercial partners where this is necessary to facilitate a product or service you have opted into, or where you have otherwise consented.


4.3 Industry and Government Bodies
We may disclose personal information to industry associations, government agencies, regulators, or law enforcement where required or permitted by law, or where necessary to protect the rights, property, or safety of our members or the public.


4.4 Legal Requirements
We may disclose your personal information where required by law, including in response to a court order, subpoena, or other legal process, or to comply with our obligations under applicable legislation.


4.5 Business Transfers
In the event of a merger, acquisition, restructure, or sale of ANF or its assets, personal information held by us may be disclosed to the acquiring entity as part of that transaction.

We will take reasonable steps to ensure any acquiring party continues to protect your personal information in accordance with this Policy.


4.6 With Your Consent

We may share your personal information with other third parties where you have provided your consent to that sharing.


We do not sell, rent, or trade your personal information to third parties for their own independent marketing or commercial purposes.



5. How Do We Protect Personal Information?


We take the security of your personal information seriously and implement reasonable technical and organisational measures to protect it from misuse, loss, unauthorised access, modification, or disclosure. Our security measures include:


  • Access controls: access to personal information held in our CRM and the Local Retailers Hub is restricted to authorised staff and contractors on a need-to-know basis, using role-based access permissions

  • Authentication: staff access to member systems requires authentication credentials; administrative access uses enhanced authentication measures

  • Encryption: data transmitted to and from our website and the Local Retailers Hub is encrypted in transit using TLS/SSL protocols

  • Platform security: we rely on the security infrastructure of our platform providers and require them to maintain appropriate security standards

  • Staff training: Our staff are trained on privacy obligations and data handling practices

  • Incident response: we maintain procedures for identifying, assessing, and responding to data security incidents, including our obligations under the Notifiable Data Breaches scheme


No method of electronic transmission or storage is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security.



6. International Transfers of Personal Information


Some of the third-party platforms and service providers we use may store or process personal information on servers located outside Australia. In particular:


  • VTiger CRM – depending on infrastructure configuration, member data may be hosted on servers located in other jurisdictions in which our CRM operates

  • Wix.com Ltd – based in Israel, with data centres located in the United States and other regions

  • Microsoft 365 and OneDrive for Business – operated by Microsoft Corporation (United States), with data centres located in Australia and other regions globally depending on service configuration and data residency settings

  • Other cloud-based tools used for email delivery, analytics, or communications may process data in overseas jurisdictions


Where we disclose personal information to overseas recipients, we take reasonable steps to ensure those recipients handle your information in a manner consistent with the Australian Privacy Principles, including through contractual protections. In some cases, the recipient country may not have privacy laws that are equivalent to those in Australia.


By providing us with your personal information and using our services, you acknowledge that we may transfer your information to overseas recipients as described above. If you have concerns about international transfers of your data, please contact us using the details in section 13.


As the Australian Government develops a “whitelist” of approved overseas jurisdictions under the Privacy and Other Legislation Amendment Act 2024 (Cth), we will update our practices accordingly.



7. Notifiable Data Breaches


ALNA is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we have reasonable grounds to believe there has been an eligible data breach (that is, a breach that is likely to result in serious harm to any individual whose personal information is involved), we will:


  • Conduct a prompt assessment of the breach

  • Notify affected individuals as soon as practicable, where required under the NDB scheme

  • Notify the Office of the Australian Information Commissioner (OAIC) as required

  • Take immediate steps to contain the breach and prevent further harm


If you believe your personal information held by ALNA may have been subject to a breach, please contact us immediately using the details in section 13.



8. Automated Decision-Making


From 10 December 2026, the Privacy and Other Legislation Amendment Act 2024 (Cth) will require entities to disclose in their privacy policy whether they use automated decision-making processes that could significantly affect the rights or interests of individuals.


Currently, we do not use some automated decision-making systems to make decisions that significantly affect the rights or interests of members or individuals without human review. Routine automated processes we use (such as email delivery scheduling, website analytics, and membership onboarding and reminders) do not make decisions that significantly affect individual rights.


If ALNA introduces automated decision-making processes of the kind contemplated by the Act, we will update this section to provide the required transparency information, including the kinds of decisions made, the types of personal information used, and how individuals can seek review of an automated decision.



9. How Long Do We Keep Your Information?


We retain personal information for as long as it is necessary to fulfil the purposes for which it was collected, or as required or permitted by law (including tax, accounting, and regulatory record-keeping obligations).


For current members, we retain your information for the duration of your membership and for a reasonable period after membership ends, to allow for account reactivation, dispute resolution, and compliance with applicable legal obligations.


When personal information is no longer required, we will securely delete or de-identify it. Where immediate deletion is not possible (for example, in the case of backup archives), we will securely isolate the information from further active processing until deletion is possible.


If you request deletion of your personal information, we will assess your request and, subject to any legal obligations that require retention, comply as promptly as practicable. See section 11 for further information on your rights.



10. Third-Party Websites and Platforms


Our websites, the Local Retailers Hub, and our communications may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party services you access through links we provide.


In particular, the Local Retailers Hub is hosted on the Wix platform. Wix’s own data collection and processing is governed by the Wix Privacy Policy, available at wix.com/about/privacy. VTiger’s data practices are governed by its own Privacy Policy at vtiger.com/privacy-policy. Microsoft’s handling of data in Microsoft 365 and OneDrive for Business is governed by the Microsoft Privacy Statement and the Microsoft Product Terms, available at microsoft.com/en-au/privacy.



11. Your Privacy Rights and Choices


11.1 Access and Correction
You have the right to request access to the personal information we hold about you, and to request correction of information that is inaccurate, out of date, incomplete, or misleading. To make an access or correction request, please contact us using the details in section 13. We will respond to your request within 30 days and will not charge you for making an access request (though we may charge a reasonable fee for providing access in certain circumstances).


11.2 Deletion and Account Termination
You may request the deletion of your personal information or the termination of your ALNA account. Where we are not legally required to retain your information, we will action such requests promptly. Some information may be retained in our systems to prevent fraud, resolve disputes, comply with legal obligations, or enforce our terms of service.


11.3 Marketing and Communications
You may opt out of receiving ALNA marketing or promotional communications at any time by:


  • Clicking the “unsubscribe” link in any marketing email we send

  • Contacting us directly using the details in section 13


Please note that even if you opt out of marketing communications, we may still need to send you service-related communications that are necessary for the administration of your membership or our legal obligations.


11.4 Do Not Track
Most web browsers and some mobile operating systems include a Do-Not-Track (DNT) feature. Currently, no uniform technology standard exists for recognising and implementing DNT signals. We do not respond to DNT browser signals at this time. If a recognised standard is adopted in the future, we will update our practices and this Policy accordingly.


11.5 Statutory Tort for Serious Invasions of Privacy

As of 11 June 2025, individuals have a right under the Privacy and Other Legislation Amendment Act 2024 (Cth) to bring a legal action for serious invasions of privacy, including unauthorised misuse of personal information. Nothing in this Policy limits any rights you may have under that legislation.



12. Children’s Privacy


Our services are directed at business operators and are not intended for use by children under the age of 18. We do not knowingly collect personal information from children. The Office of the Australian Information Commissioner is developing a Children’s Online Privacy Code under the Privacy and Other Legislation Amendment Act 2024 (Cth). We will update our practices and this Policy as that Code is finalised.



13. Contact Us


For questions, concerns, or requests relating to this Privacy Policy or the handling of your personal information, please contact us:


  • Phone: +61 2 9978 3400

  • Email: membership@alna.net.au

  • Post: Australian Newsagents’ Federation T/as Australian Lottery and Newsagents’ Association and Local Retailers Australia,  Level 1, Suite 1.9, 56 Delhi Road, North Ryde NSW 2113

  • Legal notices: Level 1, Suite 1.9, 56 Delhi Road, North Ryde NSW 2113


Response time: We will respond to privacy requests within 30 days of receipt. If you are not satisfied with our response to a privacy concern, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):


  • Website: oaic.gov.au

  • Phone: 1300 363 992

  • Post: GPO Box 5288, Sydney NSW 2001



14. Updates to This Policy


We may update this Privacy Policy from time to time to reflect changes in our practices, the services we provide, or applicable law (including the ongoing implementation of the Privacy and Other Legislation Amendment Act 2024 (Cth) and any subsequent tranches of privacy reform). The updated version will be available on our website and will take effect from the date it is published.


We encourage you to review this Policy periodically. Where we make material changes, we will notify members via the Local Retailers Hub or by email.

Australian Lottery and Newsagents Association

61 2 9978 3400

​media@alna.net.au

​

Level 1, Suite 1.9,
56 Delhi Road,
North Ryde NSW 2113

© Copyright 2026 Australian Newsagents Federation t/a Australian Lottery and Newsagents Association.

bottom of page