Motion LMS
Legal

Privacy Policy

Last updated: 14 June 2026

This Privacy Policy explains how Motion LMS Pty Ltd (“Motion”, “we”, “us” or “our”) collects, uses, discloses, and protects personal information when you use the Motion LMS platform, websites, and services (the “Platform”). We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”), and, where they apply, the EU/UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA/CPRA”).

1. Our role: controller and processor

Motion plays two different roles depending on whose information is involved:

  • For our own customers (Creators and visitors), we are the controller of the personal information we collect about you, and this Policy applies in full.
  • For Learner information that a Creator collects through their academy, the Creator is the controller and we act as a processor on the Creator’s behalf. We process that information under our agreement with the Creator and on their instructions. If you are a Learner with a question about how a particular academy uses your information, please contact that academy directly; their privacy notice governs.

2. Information we collect

2.1 Information you provide

  • Account and profile — name, email address, password, business/academy name, and profile details.
  • Billing — subscription and transaction records. Card details are collected and processed by our payment processor (Stripe); we do not store full card numbers.
  • Content — courses, media, and other materials you upload, and information you submit through forms (for example, demo requests, contact, and support enquiries).
  • Communications — messages you send us and our correspondence with you.

2.2 Information we collect automatically

  • Usage data — pages and features used, actions taken, and dates/times of access.
  • Device and log data — IP address, browser type, device identifiers, operating system, and referring pages.
  • Cookies and similar technologies — as described in section 8.

2.3 Information from third parties

We may receive information from service providers (for example, our payment processor or fraud-prevention and bot-protection tools), and from Creators where you are their Learner.

We do not seek to collect sensitive information (such as health, racial, or religious information) and ask that you do not submit it unless necessary and lawful.

3. How and why we use your information

We use personal information to:

  • provide, operate, maintain, and secure the Platform and create and manage your account;
  • process payments, subscriptions, and transactions, and send related notices;
  • provide customer support and respond to your enquiries;
  • send service and administrative messages, and (with your consent or as permitted by law) marketing communications;
  • monitor, analyse, and improve the Platform, and develop new features;
  • detect, prevent, and address fraud, abuse, security incidents, and technical issues; and
  • comply with our legal obligations and enforce our terms.

4. Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases: performance of a contract with you; your consent (which you may withdraw at any time); our legitimate interests in operating, securing, and improving the Platform (balanced against your rights); and compliance with legal obligations.

5. Disclosure of your information

We do not sell your personal information. We disclose it only as described here:

  • Service providers (sub-processors) who help us run the Platform under confidentiality and data-protection obligations, including, for example: Stripe (payments), Cloudflare (hosting, content delivery, storage, video, and bot protection), Amazon Web Services (cloud infrastructure), and Resend (transactional email).
  • Creators — where you are a Learner, your information is shared with the relevant academy.
  • Legal and safety — where required by law, regulation, legal process, or to protect the rights, property, or safety of Motion, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your consent — for any other purpose disclosed to you at the time.

6. International data transfers

We and our service providers may store and process personal information in countries other than the one in which you are located, including the United States and within the European Economic Area. Where we disclose information overseas, we take reasonable steps to ensure it is handled consistently with the APPs and, where the GDPR applies, that an appropriate safeguard (such as standard contractual clauses) is in place.

7. Data retention

We retain personal information for as long as needed to provide the Platform, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we will take reasonable steps to delete or de-identify it. Where we act as a processor for a Creator, we retain and delete Learner information in accordance with our agreement with that Creator.

8. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, measure and improve the Platform, and protect against abuse. You can manage non-essential cookies through our cookie preferences and your browser settings; disabling some cookies may affect how the Platform works.

9. Security

We take reasonable technical and organisational measures to protect personal information from loss, misuse, and unauthorised access, disclosure, alteration, and destruction, including encryption in transit, access controls, and tenant isolation. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your privacy rights

Depending on where you are and which laws apply, you may have rights to access, correct, update, delete, or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, and to opt out of marketing. To exercise a right, contact us at privacy@motionlms.com. We will respond within the time required by law.

  • Australia (APPs) — you may request access to, and correction of, the personal information we hold about you.
  • EU/UK (GDPR) — you have the rights of access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with your supervisory authority.
  • California (CCPA/CPRA) — you have rights to know, access, delete, and correct personal information, and to opt out of “sale” or “sharing”. We do not sell personal information. We will not discriminate against you for exercising your rights.

If you are a Learner, please direct requests about academy-held information to the relevant academy.

11. Direct marketing

We may send you marketing communications where permitted by law or with your consent. You can opt out at any time using the unsubscribe link in our emails or by contacting us. We will still send you essential service and account messages.

12. Children’s privacy

The Platform is not directed to children, and Creator accounts are intended for users aged 18 and over. Where an academy offers learning to minors, the relevant Creator is responsible for obtaining any required parental or guardian consent and for complying with applicable laws. If you believe a child has provided us personal information without appropriate consent, contact us and we will take reasonable steps to delete it.

13. Third-party links and services

The Platform may link to or integrate with third-party websites and services that we do not control. This Policy does not apply to those third parties, and we encourage you to review their privacy notices.

14. Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will take reasonable steps to notify you (for example, by email or an in-product notice) and update the “Last updated” date above. Your continued use of the Platform after a change takes effect constitutes acceptance of the updated Policy.

15. Contact us and complaints

For privacy questions, requests, or complaints, contact our privacy team at privacy@motionlms.com, or by post to Motion LMS Pty Ltd, Sydney, Australia. We will acknowledge your complaint and aim to resolve it within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or, if the GDPR applies to you, your local data-protection supervisory authority.