Tocca App — Privacy Policy
Effective date: September 15, 2026
Status: Revision 2 - live
This Privacy Policy explains how Tocca App (“Tocca”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use our mobile applications, websites, and related services (collectively, the “Services”). This Policy should be read together with our Terms of Service, which govern your use of the Services and set out the full liability framework, governing law, and dispute resolution process. By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
4.1 Who We Are
Tocca operates a coaching marketplace that connects clients (“Connectors”) with independent coaches through a private @handle discovery system, tiered access plans, secure messaging, voice notes, voice calls, video calls, and subscription-based coaching relationships. Tocca is operated from Australia and is subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Privacy questions and requests: hello@tocca.app Company legal name Tocca App T/as Syndico Pty Limited, registered address Suite 2, Level 1, 336 Keira Street, Wollongong, NSW 2500 and ABN: 60662042195
4.2 Information We Collect
We collect information in the following categories:
• Identity and account information: Full name, email address, gender, password or authentication tokens, profile photo, role (Connector or Coach), onboarding details, and account settings. Coaches are assigned a unique @handle that serves as their discoverable identity on the platform — personal contact details (phone numbers, personal email) are never exposed to other users through this system.
• Coach profile and marketplace content: @handle, biography, professional title, expertise categories, media you upload, and content you choose to publish or share on your profile. Coach profiles are publicly discoverable within the platform.
• Tiered plan data: Plan configuration set by coaches (plan name, price, message bundle size, expiry window); plan tier selected by each client (Starter, Silver, Gold); subscription status, renewal history, and plan expiry records.
• Availability and calendar data: Coach-set availability windows, booking timestamps, session history, and cancellation records.
• Communications: Text messages (up to 500 characters per message), voice note audio recordings (up to 3 minutes), shared images, files, attachments, and related metadata (participants, timestamps, message counts, and plan-limit enforcement records). We store voice note audio files to deliver the service. We do not record video or voice call audio/video by default unless a feature clearly states otherwise and obtains any required notice and consent.
• Payments and payouts: All payment processing, subscription billing, coach payout disbursements, and related financial transactions are handled directly by Stripe, Inc. (“Stripe”) as an independent payment processor subject to its own terms and privacy policy. Tocca does not store card numbers or sensitive payment credentials on its own servers. Tocca retains transaction identifiers, amounts, currency, status, plan or session purchased, platform fees deducted, invoices, and payout records as needed to operate the earnings console and meet legal obligations. Tax obligations arising from coach earnings — including ABN registration, GST, and income reporting — are the sole responsibility of the coach. Tocca does not provide tax advice.
• Earnings and financial dashboard data: Coach-side revenue totals, per-client revenue breakdowns, active client counts, plan uptake data, and payout history, used to operate the coach earnings console.
• Campaign and referral data: QR code generation events, bio link click-throughs, referral source attribution, and campaign link activity associated with your account.
• Social DM routing data (where applicable): Where you connect a social platform (such as Instagram, TikTok, or X) to route inbound messages into Tocca, we receive the source platform identifier, the routed message content, and conversion data. This feature is governed by the applicable platform’s own terms and data-sharing policies.
• Device and technical data: Device type, OS version, app version, language preference, push notification tokens (Firebase Cloud Messaging), IP address, approximate location derived from IP where needed for security purposes, crash logs, and diagnostics.
• Usage data: Screens viewed, feature interactions, referral sources, session frequency, and similar analytics events used to operate and improve the Services.
• Support data: Information you provide when contacting support, including attachments and correspondence.
4.3 How We Use Information
We use personal information to:
• Create and manage accounts, @handles, profiles, and authentication.
• Provide marketplace features: discovery, tiered plans, messaging (including voice notes), voice calls, video calls, subscriptions, and related notifications.
• Enforce plan-tier limits on messages and interactions as configured by coaches.
• Process payments through Stripe, plan renewals, refunds, coach earnings records, and payout disbursements.
• Provide customer support and respond to requests, disputes, and safety reports.
• Detect, prevent, and investigate fraud, abuse, spam, security incidents, and Terms violations.
• Improve product quality, reliability, performance, and user experience.
• Generate de-identified or aggregated data for analytics, product development, and reporting. De-identified data does not identify you personally and may be used and shared without restriction.
• Send transactional messages (receipts, security alerts, service notices, booking confirmations, plan renewal reminders).
• Send marketing messages only where permitted under the Spam Act 2003 (Cth) or equivalent law, and always with a clear opt-out option.
• Comply with legal obligations, enforce our Terms of Service, and protect the rights and safety of users and Tocca.
4.4 Legal Bases (Where Applicable)
For users in Australia, we process personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For users in jurisdictions with GDPR-style requirements, we process personal data on the following bases:
• Performance of a contract: To provide the Services you have signed up for.
• Legitimate interests: Security, fraud prevention, product improvement, and platform integrity — balanced against your rights.
• Consent: Where we explicitly ask for it (for example, marketing communications or optional features).
• Legal obligation: To comply with applicable tax, financial, and regulatory requirements.
4.5 Cookies and Tracking Technologies
Our websites and apps may use cookies, pixel tags, session tokens, and similar tracking technologies to operate the Services, maintain authentication, remember your preferences, measure usage, and support analytics. We use:
• Essential cookies/tokens: Required for authentication, session management, and security. These cannot be disabled without affecting core functionality.
• Analytics technologies: To understand how the Services are used and to improve them. These may include Firebase Analytics or equivalent tools.
• Marketing and attribution: Where used, these track referral sources and campaign performance. You may opt out through your device settings or browser privacy controls.
You can control cookies through your browser or device settings. Disabling non-essential cookies will not prevent you from using the core Services.
4.6 Subscriptions and Billing — Data Context
Where you subscribe to a coaching plan, we collect and process the billing and renewal data described in section 4.2. The commercial terms of subscriptions — including pricing, auto-renewal, cancellation, and refunds — are governed by our Terms of Service (section 5.5). This section concerns only the personal information collected in connection with subscription transactions.
4.7 How We Share Information
We do not sell personal information. We share information only as needed to operate the Services:
• Service providers / processors: Stripe (payment processing and payouts), hosting and infrastructure providers, analytics services, Firebase Cloud Messaging (push notifications), video call infrastructure, email delivery, customer support tools, and similar vendors operating under contractual data protection obligations.
• Other users: Profile information and content you choose to make visible — including coach public @handles, profiles, plan details, and messages you send to another user — is shared with that user. Coach profiles are publicly discoverable within the platform.
• Social platforms (where connected): If you integrate a social platform for DM routing, limited data is exchanged with that platform in accordance with its own terms. Disconnecting the integration stops future routing; historical routed messages remain in your Tocca inbox.
• Legal and safety: When required by applicable law, regulation, court order, or to protect the rights, safety, or integrity of the Services or its users.
• Notifiable Data Breaches: Where we reasonably believe an eligible data breach has occurred under the Privacy Act 1988 (Cth) Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) to the best of our knowledge and as promptly as practicable in the circumstances. We cannot guarantee that every incident affecting third-party systems will come to our immediate attention or that we will hold complete information at the time of notification.
• Business transfers: In connection with a merger, acquisition, asset sale, financing, or restructuring, subject to appropriate continuity of protection for your personal information.
4.8 International Transfers
Your information may be processed in countries other than your own, including by our infrastructure and service providers such as Stripe and Google/Firebase. Where required, we use appropriate safeguards for cross-border transfers consistent with the APPs and, where applicable, GDPR requirements.
4.9 Retention
We retain personal information for as long as your account remains active and as needed to provide the Services. After account deletion or deactivation:
• We may retain limited information where required for legal, tax, accounting, dispute resolution, fraud prevention, or security purposes.
• Transaction records and payout history are retained for at least seven (7) years as required under Australian tax law.
• Message content, voice note audio, and media files are deleted from active storage following account deletion, subject to backup expiry and technical deletion processes.
• De-identified data derived from your usage may be retained indefinitely.
4.10 Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, restrict, or export certain personal data, and to object to certain processing or withdraw consent where processing is based on consent.
Australian users may request access to or correction of their personal information under the APPs by contacting hello@tocca.app. We will respond within 30 days. If you are not satisfied with our response, you may contact the OAIC at oaic.gov.au.
You may request account deletion in-app where available, or by emailing hello@tocca.app. Some data may be retained after deletion as described in section 4.9. You may control push notifications in your device settings. Marketing communications include a one-click opt-out in every message.
4.11 Security
We implement technical and organisational measures designed to protect personal information, including encryption in transit, access controls, and security monitoring. Voice note audio files, messages, and payment data are handled with appropriate safeguards. No method of transmission or storage is 100% secure; please use a strong password and protect your devices.
In the event of a data breach affecting your personal information, we will act in accordance with our obligations under the Notifiable Data Breaches scheme to the best of our knowledge, as described in section 4.7. The liability framework applying to data incidents is addressed in our Terms of Service (section 5.11).
4.12 Children
The Services are not directed to children under 15 in Australia or under 13 in other jurisdictions (or the minimum age required in your country). We do not knowingly collect personal information from children below these ages. If you believe a child has provided personal information without appropriate consent, contact hello@tocca.app and we will take appropriate steps, including deletion.
4.13 Third-Party Services — Data Practices
The Services integrate third-party services including Stripe (payment processing and coach payouts), video call infrastructure, Firebase Cloud Messaging (push notifications), and social platform APIs (where connected). These providers may process your personal information in the course of providing their services to Tocca and are governed by their own privacy policies. Coaches receiving payouts must separately agree to Stripe’s Connected Account terms, which govern Stripe’s handling of coach financial data. The commercial obligations relating to these integrations are addressed in our Terms of Service (section 5.5).
4.14 Platform Role — Data Context
Tocca is a technology marketplace. Coaches are independent providers and not employees of Tocca. Content and information shared with a coach is received by that coach as an independent party. Tocca processes communications data to facilitate delivery of the Services and enforce plan-tier limits, but does not monitor, endorse, or take responsibility for coaching content. The full contractual framework, liability allocation, and coach obligations are set out in our Terms of Service.
4.15 Data Accuracy
You are responsible for ensuring that personal information you provide to Tocca is accurate, complete, and current. Inaccurate information may affect the quality of service we can provide. Please keep your account information updated or contact hello@tocca.app if you need assistance. Your contractual obligation to provide accurate account information is set out in our Terms of Service (section 5.2).
4.16 Account Suspension — Data Implications
Where an account is suspended or terminated under our Terms of Service, we will retain personal information in accordance with the retention periods in section 4.9. Access to your data may be restricted during a suspension period. Your right to request data access or deletion continues regardless of account status, subject to legal retention obligations. Account suspension and termination rights are governed in full by our Terms of Service (section 5.9).
4.17 Data Incident Liability
We implement reasonable security measures as described in section 4.11. To the extent permitted by applicable law, our liability for loss or damage arising from data incidents is subject to the limitation of liability provisions set out in our Terms of Service (section 5.11). Nothing in this Policy limits liability that cannot be excluded under the Australian Consumer Law or the Privacy Act 1988 (Cth).
4.18 Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date on our website and/or in the app. For material changes, we will provide additional notice (for example, via email or in-app notification) where required by law. Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.
4.19 Contact
Privacy requests, access requests, and corrections: hello@tocca.app
Company legal name Tocca App T/as Syndico Pty Limited, registered address Suite 2, Level 1, 336 Keira Street, Wollongong, NSW 2500 and ABN: 60662042195
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.