Legal
Privacy Policy
How Mia Rees handles your personal information.
Last updated 26 July 2026
1. Who this policy is about
Curated Travel by Mia is a website operated by Mia Rees, a sole trader based in Melbourne, Victoria, Australia (ABN 57 760 085 732), who carries on business under her own name. In this policy, “I”, “me” and “my” mean Mia Rees, and “you” means anyone who uses this website or engages me to plan travel.
You can reach me at curatedtravelbymia@gmail.com.
2. My position under the Privacy Act
Most Australian sole traders with an annual turnover of $3 million or less fall under the small business exemption in the Privacy Act 1988 (Cth). That exemption currently applies to me. I have chosen to handle personal information in line with the Australian Privacy Principles regardless, and this policy describes what I actually do rather than the minimum I could do.
3. What I collect
When you use the contact form
- Your name and email address
- The destinations and trip length you enter
- Whatever you write in the message field
Automatically, when you visit
- Your IP address, used to limit how often the contact form can be submitted from one connection. This is a spam control, not analytics.
- Standard web server logs kept by my hosting provider: the time of the request, the page requested, and your browser’s user-agent string.
If you engage me to plan a trip
Planning a real trip needs more detail. Depending on the trip that can include the names and ages of everyone travelling, travel dates, budget, loyalty programme numbers, and preferences around food, mobility or accessibility. Some of that is sensitive information under Australian privacy law — dietary requirements and health or mobility needs in particular.
I collect it only where you volunteer it, only where it genuinely affects the plan, and only to plan your trip. Please send me the minimum that will do the job. I do not need passport numbers to plan a trip; if a specific booking requires one, you provide it directly to that supplier, not to me.
I never collect or store card numbers. Payment of my planning fee is handled outside this website.
4. Cookies and tracking
This website sets no cookies. There is no analytics, no advertising pixel, no session tracking and no third-party script that follows you between sites.
The one external request the site makes is for its two typefaces, which load from Google Fonts. That means Google receives your IP address when the page loads. Google’s handling of that is covered by Google’s privacy policy.
5. Who else handles your information
I use a small number of service providers to run the site. Each only receives what it needs:
- Vercel Inc. (United States) — hosts the website and keeps the server logs described above.
- Resend (United States) — delivers contact form submissions to my inbox. Resend processes the contents of your enquiry in transit.
- Upstash (United States) — where enabled, briefly stores a count of form submissions against your IP address so the form can be rate-limited. It never sees the contents of your message.
- Google Fonts — receives your IP address when typefaces load, as above.
These providers store data on servers in the United States and potentially elsewhere. By using the contact form you consent to your information being transferred and stored overseas. I do not sell your information, and I do not share it with anyone for marketing.
Once you engage me, I will also share details with travel suppliers only where you ask me to — for example, to check whether a restaurant can accommodate an allergy. I will always tell you first.
6. Why I collect it
- To reply to your enquiry and answer your questions
- To research, plan and deliver your itinerary
- To protect the contact form from spam and automated abuse
- To keep the business records Australian tax law requires
7. How long I keep it
- Enquiries that don’t become work: up to 12 months, then deleted.
- Client records, itineraries and invoices: seven years, which is the retention period Australian tax law expects.
- Rate-limiting records: 15 minutes.
- Server logs: for as long as my hosting provider retains them.
8. How it is kept safe
The site is served over HTTPS, so everything you submit is encrypted in transit. Enquiries arrive in an email account protected by a strong, unique password and two-factor authentication. Client documents are stored in access-controlled cloud storage.
No system is perfectly secure, and I can’t guarantee absolute security. If a breach ever affected your information in a way likely to cause you serious harm, I would tell you and take the steps expected under the Notifiable Data Breaches scheme.
9. Access, correction and deletion
Email me at curatedtravelbymia@gmail.com and you can ask me to:
- tell you what personal information I hold about you,
- give you a copy of it,
- correct anything wrong or out of date, or
- delete it, where I’m not required to keep it for tax or record-keeping reasons.
I’ll respond within 30 days, and there’s no charge. I may need to verify who you are first.
10. Marketing
I don’t run a mailing list and I won’t add you to one. Enquiring does not sign you up for anything. If I ever start a newsletter it will be opt-in, and you’ll be able to leave at any time.
11. Children
This website isn’t directed at children. When planning family travel I may receive details about children from the adult arranging the trip — please share only what the plan genuinely requires.
12. Complaints
If you think I’ve mishandled your information, email me first and I’ll try to put it right. If you’re not satisfied, you can raise it with the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992 — noting that the small business exemption in section 2 may limit what they can act on.
13. Changes to this policy
If this policy changes, the updated version will be posted here with a new date at the top. Material changes affecting existing clients will be emailed.
14. Contact
Mia Rees
Melbourne, Victoria, Australia
curatedtravelbymia@gmail.com