← Home

Privacy Policy

Last updated: 2 April 2026

1. Overview

Let's Siesta (“the Tool”), operated by Alpine Code (ABN 83 774 179 276) (“we”, “us”), is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

In accordance with Australian Privacy Principle 2, you can use Let's Siesta without identifying yourself. No account, identification, or contact details are required to use the free calculators.

2. What we collect

Data stored on your device only (anonymous users)

If you use the Tool without signing in, your financial details — including salary, super balance, assets, income, retirement age, and spending targets — are stored exclusively in your browser's local storage. This data never leaves your device and is never transmitted to our servers.

You can delete this data at any time by clearing your browser's local storage or site data for this website.

Data collected when you sign in (authenticated users)

If you choose to sign in via Google, Apple, or Facebook, we collect and store the following in our secure database:

  • Your name and email address (as provided by your sign-in provider)
  • Your OAuth provider identifier (e.g. Google account ID)
  • Your financial profile details, if you choose to save your profile (salary, super balance, assets, retirement age, spending targets, and related inputs)

This data is stored to allow you to save your profile and scenarios and return to them later. Your sign-in provider may share additional profile information with us (such as a profile photo); we do not use or store this beyond what is necessary for authentication.

Anonymous analytics

We collect anonymous usage data to understand how people use the Tool and improve it. This includes:

  • Device type (mobile, tablet, or desktop)
  • Pages visited and time spent on each section
  • Interactions with controls (e.g. which sliders were adjusted, which toggles were used) — including which controls were interacted with, how many times, and whether toggles were turned on or off. We do not record the specific financial values you enter.
  • Onboarding progress (which steps were completed or skipped)
  • Referrer type (direct, search, social, or other)

Demographic brackets (optional)

If you complete the onboarding wizard, we may store broad demographic brackets alongside your analytics session — for example, an age range (e.g. 55–59) or a super balance range (e.g. $300K–$500K). These are deliberately coarse categories that cannot identify you individually. We use them to understand which user segments find the Tool most useful.

For anonymous users, exact financial figures are never sent to our servers. Only the broad brackets are transmitted.

Feedback

If you choose to submit feedback through the Tool, we collect the star rating you provide, any optional free-text comment you write, the page you were viewing, and the demographic brackets described above. Feedback is stored in our database alongside an anonymous session identifier. Please avoid including personal information (such as your name, email, or specific financial details) in free-text feedback comments, as we have no way to link feedback back to you for correction or deletion.

Cookies and client-side storage

The Tool uses your browser's local storage to save your financial profile, onboarding preferences, and a feedback cooldown timestamp. For anonymous users, this data stays on your device and is not transmitted to our servers (except for the demographic brackets described above).

If you sign in, a session cookie is set to maintain your authenticated session. This is a functional cookie required for the sign-in feature to work and is not used for tracking or advertising purposes.

We use Google Analytics 4 for anonymised usage analytics and Meta Pixel for advertising conversion tracking. These services use cookies for session management and measurement. You can opt out of Google Analytics via Google's opt-out browser add-on, and manage other cookie preferences through your browser settings. You can clear all locally stored data at any time through your browser's settings.

3. What we do NOT collect

  • IP addresses for analytics or tracking purposes. Standard web server logs (which may include IP addresses) are retained for up to 14 days for security and debugging purposes, then automatically deleted.
  • Cookies for advertising or third-party tracking
  • Financial data from anonymous users (exact figures remain on your device only)

If we introduce features that collect additional personal information in the future, we will update this policy and notify you before any collection begins.

4. How we use your data

We use the data we collect for the following purposes:

  • To provide and maintain the Tool, including saving your profile and scenarios (authenticated users)
  • To understand which features are most used and where users drop off
  • To improve the accuracy and usability of the Tool
  • To identify which user segments the Tool serves well and where gaps exist
  • To respond to user feedback and prioritise improvements
  • To send you occasional product updates, new feature announcements, or retirement planning content — only if you have opted in to marketing communications. You can unsubscribe at any time.

We do not sell your personal data. We may share anonymised, aggregated data with advertising partners. We will not share your personal information with third parties for their own marketing purposes without your explicit consent.

5. Data storage and security

Authenticated user profiles, anonymous analytics, and feedback data are stored in a secure PostgreSQL database hosted on Amazon Web Services (AWS) in the Sydney (ap-southeast-2) region. Access to this data is restricted to authorised personnel only and is protected by encryption in transit (TLS) and at rest.

For anonymous users, your financial details remain in your browser's local storage and are subject to the security of your device and browser. We recommend keeping your browser up to date and not using the Tool on shared or public computers.

6. Data retention

Anonymous analytics data is collected in de-identified form (broad demographic brackets such as “salary $80K–$100K”, device type, and page interactions). Because this data cannot reasonably be linked back to an individual, it is retained indefinitely for product improvement and aggregate statistical purposes.

Session identifiers (such as device IDs and session IDs used to group page views) are stripped or deleted after 24 months. After this point, only fully de-identified bracket and interaction data remains.

Server logs: Standard web server logs (which may include IP addresses, request URLs, and timestamps) are retained for up to 14 days, then automatically deleted.

Authenticated user profile data is retained for as long as your account exists. You may request deletion of your account and all associated data at any time by contacting us (see Section 16).

Data stored in your browser's local storage persists until you clear it manually or your browser removes it automatically.

7. Third-party services

The Tool uses the following third-party services:

  • Amazon Web Services (AWS) — hosting (via AWS Amplify), database (RDS PostgreSQL), email delivery (SES), and content delivery (CloudFront). Our primary infrastructure is in the Sydney (ap-southeast-2) region. AWS is US-headquartered; infrastructure runs in Sydney but is subject to US law. CloudFront may deliver content via edge locations outside Australia.
  • Google Analytics 4 (GA4) — anonymised usage analytics including page views, device type, and interactions. GA4 uses cookies for session management. You can opt out via browser settings or Google's opt-out add-on. Google is US-headquartered and data may be processed outside Australia per Google's privacy policies.
  • Google Ads — conversion tracking to measure the effectiveness of our advertising. Does not collect or transmit your financial data.
  • Meta (Facebook) Pixel — conversion tracking for advertising campaigns. Tracks page views and registration events only. Does not collect or transmit your financial data. Meta is US-headquartered and data may be processed outside Australia per Meta's privacy policies.
  • Google, Apple, Facebook — OAuth sign-in providers. When you sign in, your authentication is handled by the provider you choose. Each provider is US-headquartered and has its own privacy policy governing the data they collect during sign-in.

We may introduce additional third-party services (such as payment processors, AI service providers, email marketing platforms, or advertising networks) as the Tool evolves. This policy will be updated before any new service receives your personal data.

8. International data transfers

Our servers are located in AWS's Sydney region and authenticated user data (profiles and scenarios) is stored exclusively in Australia. However, several of our service providers are headquartered overseas:

  • AWS — US-headquartered; infrastructure runs in Sydney but is subject to US law. CloudFront may deliver content via locations outside Australia.
  • Google (Analytics, Ads & OAuth) — data may be processed outside Australia per Google's privacy policies.
  • Meta (Pixel & OAuth) — data may be processed outside Australia per Meta's privacy policies.
  • Apple (OAuth) — authentication data transits through Apple's US-based services.

In accordance with APP 8, we take reasonable steps to ensure overseas recipients handle your information in accordance with the Australian Privacy Principles.

9. Marketing communications

If you opt in to marketing communications during registration, we may send you emails about product updates, new features, and retirement planning content. Every marketing email includes a one-click unsubscribe link. You can also manage your preferences by contacting us at contact us via our website.

We will never send marketing emails without your consent. Opting out of marketing communications does not affect transactional emails (such as password reset emails) or your access to the Tool.

10. Your rights

Under the Australian Privacy Principles, you have the right to:

  • Know what personal information we hold about you
  • Request access to your personal information
  • Request correction of any inaccurate information
  • Request deletion of your account and associated data
  • Complain about a breach of the APPs

For anonymous users, because we do not collect personally identifiable information, we cannot link analytics data back to you as an individual. Your financial data is stored only on your device and can be deleted at any time by clearing your browser data.

For authenticated users, you can request access to, correction of, or deletion of your personal information by contacting us at contact us via our website. We will respond to your request within 30 days.

11. Data breach notification

In the unlikely event of a data breach that is likely to result in serious harm, we will comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). This includes notifying the Office of the Australian Information Commissioner (OAIC) and taking reasonable steps to notify affected individuals as soon as practicable.

12. Children

The Tool is designed for Australian adults approaching retirement. It is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children. If a parent or guardian believes their child has provided personal information to us, please contact us at contact us via our website and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page indicates when the most recent changes were made. If we make material changes that affect how we handle your personal information, we will notify authenticated users via the Tool before the changes take effect. Privacy protections will not be reduced without clear notice.

14. Complaints

If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us using the process below:

  1. Contact us at contact us via our website with details of your complaint.
  2. We will acknowledge your complaint within 7 days and investigate.
  3. We will respond with the outcome within 30 days of receiving your complaint.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

15. Third-party links

The Tool may contain links to third-party websites, including sign-in providers and external resources. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policies of any third-party sites you visit.

16. Contact

If you have questions about this Privacy Policy, wish to exercise your rights, or want to request deletion of your data, contact us at contact us via our website.

Modelled outcomes only. Not financial advice.