Terms of Use
Last updated: January 19, 2026
This Privacy Policy explains how OneSurf ("we", "us", or "our") collects, uses, stores, and discloses personal information when you visit onesurf.com, purchase or access our programs, or use service delivered through third-party platforms such as Everfit.
We aim to manage personal information in line with applicable privacy laws, including the Australian
Privacy Principles under the Privacy Act 1988 (Cth) where they apply, and other data protection laws that may apply depending on your location.
Quick reference
Business OneSurf
Website onesurf.com
Privacy contact info@onesurf.com
Program platform Everfit (client accounts and program delivery)
1. Scope and key definitions
In this Policy:
- Personal information means information about an identified individual, or an individual who is reasonably identifiable (and includes "personal data" as defined in the GDPR where applicable).
- Sensitive information includes certain categories such as health information (and "special category data" under GDPR). category data" under GDPR).
Services means our digital training programs, coaching resources, education products, and related services we offer via our website and third-party platforms. services we offer via our website and third-party platforms.
This Policy should be read alongside any terms and conditions that apply to your purchase or use of our Services.
2. What information we collect
We collect personal information that is reasonably necessary for our business functions and to provide our Services. The types of information we collect depend on how you interact with us.
2.1 Information you provide
- Name, email address, and contact details.
- Account details and program enrolment information.
- Payment and transaction details (note: card details are typically handled by payment processors,not stored by us).
- Messages you send us (e.g., support requests or enquiries).
2.2 Program and training data
When you access programs, we and/or our program platform may process information about your participation and progress, such as program check-ins, completions, milestones, and responses you submit.
2.3 Sensitive information (health-related data)
Depending on the features you use, we may process health or fitness-related information (for example, injury notes, training limitations, goals, measurements, or similar information). Where required by law, we will collect and use this information only with your consent, and only for the purpose of delivering the Services and supporting your training outcomes.
2.4 Automatically collected information
- Device and browser information.
- IP address and approximate location (derived from IP).Website usage data such as pages visited and actions taken.
- Cookies and similar tracking technologies (see Section 6).
3. How we collect personal information
- Directly from you when you fill out forms, purchase, create an account, or contact us.
- Via platforms that help deliver our Services (for example, Everfit).
- From service providers that assist with payments, analytics, marketing, customer support, and website hosting.
- From third parties where you have consented or where permitted by law (for example, if you connect a third-party service to your program account).
3.1 Dealing with us anonymously or using a pseudonym
Where lawful and practicable, we will provide you with the option to deal with us anonymously or using a pseudonym (for example, for a general enquiry). If we do not collect certain personal information, you may be unable to access some features or Services.
You can decline to provide requested information, but this may limit our ability to provide some or all Services.
4. Why we collect and use personal information
We use personal information to:
- Provide, administer, and improve our Services (including program delivery, coaching support, and account management).
- Process payments and manage orders, subscriptions, or access entitlements.
- Communicate with you about your account, purchases, support requests, and important service updates.
- Send marketing communications where permitted (you can opt out at any time).
- Monitor, protect, and maintain the security and integrity of our systems, website, and Services.
- Comply with legal obligations, resolve disputes, and enforce our terms.
5. Data sharing, third-party platforms, and processors
We do not sell your personal information. We may share personal information with trusted third parties where it is necessary to operate our business and deliver the Services.
5.1 Everfit (program platform)
We use Everfit as our primary platform to host and deliver training programs and manage client accounts. When you use our Services, certain personal information is processed and stored on Everfit’s platform.
- Controller/processor roles: OneSurf generally acts as the controller for customer data we collect and manage. Everfit acts as a processor and/or an independent controller for certain data it collects and processes to provide its services, in line with its own terms and policies.
- Sub-processors: Everfit may use sub-processors to provide its services.
- More information: You can review Everfit’s privacy and data processing documentation for detailson its handling of data.
5.2 Other service providers
We may use providers for functions such as website hosting, payment processing, analytics, customer support, email delivery, and advertising. These providers are permitted to process personal information only for the services they provide to us, subject to appropriate safeguards.
6. Cookies and tracking technologies
We use cookies and similar technologies to operate our website, understand traffic and usage, improve performance, and support marketing. You can manage cookies through your browser settings. If you disable cookies, some site features may not work properly.
7. Marketing communications
If you opt in to marketing communications, we may send you updates, offers, and announcements. You can opt out at any time by using the unsubscribe link in our emails or contacting us at info@onesurf.com. Even if you opt out of marketing, we may still contact you about service-related matters (such as receipts, account notices, or important updates).
8. Overseas disclosures and international transfers
Some of our service providers (including Everfit and its sub-processors) may store or process data outside Australia, including in the United States or other countries. Where required, we take reasonable steps to ensure appropriate safeguards are in place for international transfers (for example, contractual protections such as Standard Contractual Clauses for GDPR-regulated transfers).
9. Security and retention
We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We retain personal information only for as long as necessary to provide the Services, meet our legal obligations, resolve disputes, and enforce our agreements. When information is no longer required, we take reasonable steps to delete or de-identify it.
10. Access, correction, deletion, and other rights
You may request access to, or correction of, personal information we hold about you. Depending on your location, you may also have rights to request deletion, restrict processing, object to processing (including direct marketing), or request a portable copy of certain data. To make a request, contact us at info@onesurf.com. We may need to verify your identity before completing certain requests.
11. Complaints (Australia)
If you have a complaint about how we handle personal information, please contact us first so we can try to resolve it.
- Email: info@onesurf.com
- Subject line suggestion: "Privacy Complaint"
If you are not satisfied with our response, you may be able to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
12. Data breaches
Where applicable, we will comply with legal requirements relating to notifiable (eligible) data breaches, including notifying affected individuals and relevant regulators where required.
13. European and UK residents (GDPR/UK GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the GDPR/UK GDPR may apply to our processing of your personal data.
Our legal bases may include:
- Contract: to provide the Services you request.
- Legitimate interests: to operate and improve our business (balanced against your rights).
- Consent: for certain marketing activities and for processing certain sensitive information where required.
- Legal obligation: to meet applicable laws.
You may have rights to access, correct, delete, restrict, object, and data portability, and the right to lodge a complaint with your local supervisory authority.
14. Children
Our Services are not directed to children and we do not knowingly collect personal information from children where prohibited by law. If you believe a child has provided us personal information, please contact us and we will take reasonable steps to delete it.
15. Changes to this Policy
We may update this Policy from time to time. The latest version will be posted on onesurf.com with an updated "Last updated" date.
16. Contact us
Email: info@onesurf.com
Website: onesurf.com