Privacy policy
Legal / Privacy / Your information

Your information. Handled with care.

This policy explains how MainTraining Pty Ltd, trading as Sarah Cordiner, collects, uses, stores, shares and protects your personal information. It is written in plain English on purpose, because a privacy policy nobody can understand protects nobody.

Updated 28 September 2026 Version 3.0 Australian Privacy Principles

Privacy question? sarah@sarahcordiner.com

No fine-print tricks
My privacy promises

What you can count on.

  • We never sell or rent your personal information.
  • You can unsubscribe from marketing at any time, in one click.
  • You can ask to see, correct or delete the information we hold about you.
  • We never see or store your full card number. Payments are handled by secure payment providers.
  • If a data breach is likely to cause you serious harm, we will tell you and the regulator.
  • A real human is always available to review any automated decision.
The short version

Privacy in 60 seconds.

Here is the whole policy boiled down. The full version below is the one that counts legally, so please read it too.

01

What we collect

Your contact details, what you buy or sign up for, what you tell us, and how you use our websites, emails and programs.

02

Why we collect it

To deliver what you asked for, run your membership or booking, support you, send marketing you agreed to, keep things secure and improve what we do.

03

We never sell it

Your information is shared only with our small team and trusted service providers who help us run the business. Some of them are overseas.

04

Marketing is your call

We only market to you with your consent or where the law allows. Every email has an unsubscribe link, and we honour it fast.

05

Recordings and AI

Live sessions may be recorded and transcribed, and we use AI tools to help run the business. We tell you when, and a human reviews anything important.

06

You are in control

Ask to access, correct or delete your information, or make a complaint. We respond within 30 days, and you can go to the OAIC if you are not happy.

This summary is for convenience only. If anything in it differs from the full policy below, the full policy applies.

Effective date: 28 September 2026 (Version 3.0). This policy replaces all earlier versions.

In this policy, "we", "us" and "our" means MainTraining Pty Ltd (ABN 74 164 108 954), trading as Sarah Cordiner. "You" means anyone whose personal information we handle, including website visitors, subscribers, customers, Legends Lab members, event attendees, event organisers, affiliates, partners, contractors and job applicants.

By using our websites, programs or services, or by giving us your personal information, you acknowledge that you have read this policy. Where the law requires your consent, we will ask for it.

01Who we are and what this policy covers

MainTraining Pty Ltd is an Australian company based in Queensland. We trade as Sarah Cordiner and provide business, AI, automation and tech education, including the Legends Lab membership, online courses, workshops, masterclasses, bootcamps, events, one-on-one sessions, keynote speaking, corporate training, consulting, free resources, a blog and a podcast.

This policy applies to personal information we collect through:

  • sarahcordiner.com and its subdomains (including training.sarahcordiner.com, links.sarahcordiner.com, offer.sarahcordiner.com and affiliates.sarahcordiner.com), and any other website or page that links to this policy;
  • our online courses, membership areas, communities, apps, forms, booking calendars, checkouts and emails;
  • live and online events, workshops, calls and sessions;
  • social media, messaging platforms and anything else you send us; and
  • our dealings with customers, suppliers, partners, affiliates and contractors.

Tekmatix is a separate business. Tekmatix is a software platform founded by Sarah Cordiner and operated by a separate company. We use Tekmatix as one of our service providers (see section 12). If you are a Tekmatix customer, Tekmatix's own privacy policy covers how it handles your information as a Tekmatix customer.

02The laws we follow

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as amended by the Privacy and Other Legislation Amendment Act 2024. We choose to meet these standards across our whole business, even where an exemption might otherwise apply to us.

We also comply with other laws that affect how we handle information, including:

  • the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) for emails, SMS and calls;
  • the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act;
  • the Australian Consumer Law;
  • the Invasion of Privacy Act 1971 (Qld) in relation to recording conversations;
  • any registered APP code that applies to us, including the Children's Online Privacy Code once it is registered and to the extent it applies; and
  • where we deliver services under contract to a government agency, the privacy terms of that contract and any state privacy law it requires us to follow, such as the Information Privacy Act 2009 (Qld).

Individuals also have the right to take legal action for serious invasions of privacy under Schedule 2 of the Privacy Act (in force since 10 June 2025). Nothing in this policy limits any right you have under the law.

03What personal information we collect

"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable. Technical information such as IP addresses, device identifiers and cookie IDs can be personal information when it is linked to you. We only collect what we reasonably need. Depending on how you deal with us, this may include:

Identity and contactMost peopleName, email address, phone number, postal or business address, business name, job title, website and social media handles.
Purchases and accountsCustomers and membersProducts and memberships purchased, subscription status, order history, login details, course progress, billing address, invoices and refund history. Card details are collected and processed by our payment providers, not stored by us.
Your businessClients and membersInformation about your business, goals, challenges, offers, audience and tech set-up that you share in forms, surveys, sessions, questions or community posts.
CommunicationsAnyone who contacts usEmails, messages, form submissions, support requests, chat and comments, and our notes of our conversations with you.
Recordings and imagesSessions and eventsVideo, audio, transcripts, AI-generated summaries, screenshots, photographs and chat logs from live sessions, calls and events (see section 8).
Technical and usageWebsite and email usersIP address, approximate location, browser and device type, pages viewed, links clicked, referring sites, time on page, email opens and clicks, and cookie and pixel data (see section 11).
Speaking and eventsEvent organisersOrganiser contact details, event details, audience information, contracts and invoicing details.
Affiliates and suppliersPartners and contractorsABN, bank account details for payouts, tax information, referral and commission records, and contract details.
ApplicantsPeople applying to work with usCV, work history, references, skills and anything else you include in your application.
Feedback and testimonialsOptionalSurvey answers, reviews, testimonials and case studies, including your name, photo and business name if you agree to them being published.

We do not ask for, or adopt as our own identifier, any government-related identifier such as a tax file number, Medicare number, driver licence or passport number, unless the law requires or allows it.

04Sensitive information

Sensitive information includes health information, racial or ethnic origin, religious or political beliefs, sexual orientation, criminal records and biometric information. We do not seek to collect it.

We will only collect sensitive information with your consent and where it is reasonably necessary, for example dietary or accessibility requirements so we can look after you at an event. If you choose to share sensitive information in a session, form or community without us asking, you consent to us handling it in line with this policy. Please think carefully before sharing sensitive information in group settings.

05How we collect it

We collect personal information directly from you wherever we can, for example when you:

  • sign up for a free resource, newsletter, webinar, challenge or event;
  • buy a product, join the Legends Lab or book a session;
  • fill in a form, survey, quiz, application or booking calendar;
  • attend a live session, workshop, call or event;
  • post in our communities, comment on our content or message us on social media; or
  • email, message or call us.

We also collect information automatically through cookies, pixels and similar technologies, and sometimes from third parties, such as payment providers, event organisers who book Sarah, affiliates and partners who refer you, social media and advertising platforms, lead generation forms, and publicly available sources such as your business website or LinkedIn profile.

Information we did not ask for

If we receive personal information we did not ask for, we will decide within a reasonable time whether we could have lawfully collected it. If not, we will destroy or de-identify it where it is lawful and reasonable to do so.

If you do not give us your information

If you choose not to provide information we ask for, we may not be able to deliver a product, give you access to a program, process your booking or respond to your enquiry.

06Staying anonymous or using a pseudonym

You can browse our websites and read our free content without telling us who you are. Where it is practical and lawful, you can also deal with us using a pseudonym, for example a display name in a community. To buy, join a membership, attend a paid event or book a session, we will need your real name and contact details so we can deliver and invoice correctly.

07Why we collect, use and hold it

We collect, use and hold your personal information for the purpose you gave it to us, and for related purposes you would reasonably expect, including to:

  • deliver the products, memberships, courses, events, sessions, speaking and services you have asked for;
  • create and manage your account, give you access to programs, and track your progress;
  • process payments, subscriptions, refunds, invoices and affiliate commissions;
  • answer your questions and provide support;
  • send you service messages such as receipts, access details, reminders, schedule changes and policy updates;
  • send you marketing about our products, events and offers, and relevant partner offers, where you have agreed or the law allows (see section 10);
  • run and moderate our communities and keep them safe;
  • create training content, replays, resources and case studies (see section 8);
  • understand how people use our websites and content, and improve our offers, content and customer experience;
  • show you relevant advertising and measure how our advertising performs (see section 11);
  • prevent, detect and deal with fraud, misuse, security threats, chargebacks and breaches of our terms;
  • manage our business, including accounting, tax, insurance, audits, legal advice and business planning;
  • comply with our legal obligations, and establish, exercise or defend legal claims; and
  • consider applications to work with us.

We will only use or disclose your information for another purpose with your consent, or where the Privacy Act otherwise allows it, for example where required by law or a court order, or to lessen a serious threat to someone's life, health or safety.

08Recordings, transcripts, photos and AI tools

Live sessions, calls and events

We regularly record live sessions, Legends Lab calls, workshops, webinars, one-on-one and Get It Done sessions, and some meetings. Recordings may include your video, voice, name, chat messages and anything you share on screen. We may also create transcripts and AI-generated summaries of them.

We will tell you when a session is being recorded, usually in the booking or event details and at the start of the session. We use recordings to deliver replays to you and other attendees or members, provide you with transcripts and action notes, create training and marketing content, and keep an accurate record of what was agreed.

You are in control of what you share. In group sessions you can keep your camera off, use your first name only, rename yourself, send questions privately, or ask us before the session not to feature you in any public content. If you appear in a recording we have published and want it edited or removed, contact us and we will do what we reasonably can.

Photos and video at in-person events

We often photograph and film our events. We will let you know at the event, for example on signage or in the event information. If you do not want to be photographed or appear in published content, please tell our team on the day or email us beforehand.

How we use AI tools

We use artificial intelligence tools across our business, including AI assistants and agents, transcription and note-taking tools, and writing, design and automation tools. Some of these tools may process your personal information, for example to transcribe a session, summarise a meeting, draft a reply to your email, organise support requests or help us create content.

  • We choose reputable providers and, where the tool allows it, use settings that stop the provider using our data to train its public models.
  • We do not put more personal information into an AI tool than the task needs.
  • A member of our team reviews AI-generated content before it is used in anything important, and we remain responsible for it.
  • If you are ever talking to an AI assistant on our behalf, rather than a person, we will make that clear.

09Automated decisions

We use computer programs, automations and AI to run parts of our business. Most of these only affect things like which emails you receive. The following automated decisions could affect your access to what you have paid for, so we are telling you about them:

Access to programs and membershipsAutomations give, pause or remove your access to courses, memberships and communities based on your payment and subscription status. Uses: name, email, account and payment status, subscription records
Payment and fraud screeningOur payment providers may automatically decline or flag a transaction they consider risky. Uses: payment details, billing address, IP address, device and transaction history
Offers, eligibility and segmentationAutomations may decide which offers, bonuses, reminders or content you receive, and whether you qualify for a promotion, based on your activity. Uses: contact details, purchase history, tags, email and website engagement

If you think an automated decision about you is wrong, contact us and a real person will review it. We will keep this section up to date in line with the automated decision-making transparency requirements that apply from 10 December 2026.

10Marketing and how to opt out

We send marketing by email, SMS, messaging apps and social media, and may use your information to show you advertising online. We only send commercial electronic messages with your consent (which may be express, such as ticking a box or signing up, or inferred where the Spam Act allows it, such as from an existing customer relationship).

Every marketing message will identify us and include a simple way to unsubscribe. You can opt out at any time by:

We process unsubscribe requests within 5 business days and there is no cost to you. Opting out of marketing does not stop service messages we need to send you, such as receipts, access details and important changes to a program you have bought. We keep a minimal record of your opt-out so we do not accidentally contact you again.

If you ask, we will tell you where we got your information from if you did not give it to us directly. We never sell your personal information to anyone.

11Cookies, pixels and analytics

Cookies are small files stored on your device. Pixels, tags, web beacons and similar technologies do a similar job in websites and emails. We and our service providers use them for the following purposes:

EssentialAlways onMake our sites, logins, checkouts, forms and booking calendars work, and keep them secure.
PreferencesFunctionalRemember your settings and choices to improve your experience.
AnalyticsPerformanceHelp us understand how people use our sites and emails, for example with Google Analytics and our own platform's reporting.
AdvertisingMarketingShow you our ads on other platforms, including retargeting, and measure how they perform, for example with Meta (Facebook and Instagram), Google, YouTube, LinkedIn and TikTok.

We may also share hashed (scrambled) contact details with advertising platforms so we can show relevant ads to existing contacts, find similar audiences, or exclude people who have already bought. These platforms handle that information under their own privacy policies.

Your choices

12Who we share it with

We only share personal information for the purposes in this policy. The people and organisations we may share it with include:

  • Our team: employees, contractors, virtual assistants and support staff who help us run the business, under confidentiality obligations.
  • Our platform and service providers: including Tekmatix (our CRM, website, funnel, email, SMS, course, membership, calendar and automation platform), website hosting, payment processors such as Stripe and PayPal, video and meeting tools such as Zoom, transcription and AI tools, cloud storage, accounting and bookkeeping software, analytics, advertising and social media platforms, and customer support tools.
  • Professional advisers: such as our accountants, bookkeepers, lawyers, auditors, insurers, and grant and tax advisers.
  • Event partners: venues, co-hosts, sponsors and organisers, but only the information needed to run the event, or with your consent.
  • Affiliates and referrers: limited information needed to confirm and pay a referral commission.
  • Other members: your name, photo and posts will be visible to others in communities, group chats and live sessions you take part in.
  • Authorities: government agencies, regulators, courts and law enforcement, where required or authorised by law.
  • A buyer of our business: if all or part of our business is sold, restructured or merged, personal information may be transferred to the new owner or its advisers, who will be required to handle it in line with the Privacy Act.

We take reasonable steps to make sure the providers we use have appropriate privacy and security protections, and we only give them the information they need to do their job.

13Overseas disclosure

Many of the tools we use store or process data outside Australia, and some of our team and contractors work overseas. This means your personal information is likely to be disclosed to, or stored in, other countries.

The countries we are most likely to disclose information to are the United States (where many of our software providers host data), the United Kingdom, European Union member states, Canada, Singapore, India and the Philippines, and any other country where our service providers or team members operate from time to time.

Before we disclose personal information overseas, we take reasonable steps to make sure the recipient handles it in a way that is consistent with the Australian Privacy Principles, for example by choosing established providers with strong security and privacy commitments and contractual protections.

14Keeping your information secure

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. These include:

  • secure, reputable platforms with encryption in transit (HTTPS) and, where available, at rest;
  • multi-factor authentication and strong passwords on our business accounts;
  • access limited to the team members who need it, removed when they leave;
  • confidentiality obligations for our team and contractors;
  • payment card details handled only by PCI DSS compliant payment providers; and
  • regular reviews of the tools we use, what they hold and who can access them.

No system connected to the internet can be made completely secure, so we cannot guarantee the security of information you send us online. Please help by keeping your login details private, using a strong password, and telling us straight away if you think your account has been compromised.

15How long we keep it

We keep personal information only for as long as we need it for the purposes in this policy, or as required by law. When we no longer need it, we take reasonable steps to securely destroy or de-identify it. As a general guide:

Financial and transaction recordsAt least 7 years, as required by tax and corporations laws.
Customer and member accountsWhile your account is active, and for a reasonable period afterwards so you can come back, request records or resolve any issues.
Marketing contactsUntil you unsubscribe or stop engaging with us, after which we keep a minimal record so we respect your opt-out.
Session and event recordingsFor as long as the replay or content is part of a program or library, or as needed for records of what was agreed.
Enquiries and supportGenerally up to 2 years after our last contact, unless the matter is ongoing.

16Data breaches

If we suspect a data breach, we act quickly to contain it and assess it. We aim to complete our assessment within 30 days, as the Privacy Act requires.

If an eligible data breach occurs, meaning one that is likely to result in serious harm to anyone affected, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and tell you what happened and what you can do to protect yourself.

17Communities, groups and things you share

Our communities, group chats, social media groups, comment sections and live sessions are shared spaces. Anything you post or say there can be seen, and potentially copied or shared, by other people. Some of these spaces run on third-party platforms such as Facebook and WhatsApp, which have their own privacy policies.

  • Please only share what you are comfortable with others seeing.
  • Do not share other people's personal information, or your clients' information, without their permission.
  • Respect the privacy of other members. What is shared in the room stays in the room, and screenshots or recordings of other members must not be shared outside the community without their consent.

We moderate our communities, and we may remove content or members that breach our community rules or put others' privacy at risk. To the extent permitted by law, we are not responsible for how other members or platform operators use information you choose to make public.

18Children

Our websites, programs and services are designed for adults in business and are not directed at children. We do not knowingly collect personal information from anyone under 18 without the consent of a parent or guardian. If you believe a child has given us personal information, please contact us and we will delete it. We will comply with the Children's Online Privacy Code to the extent it applies to us once it is registered.

19Accessing, correcting and deleting your information

Access. You can ask for a copy of the personal information we hold about you. We usually do this free of charge. If a request is complex or unusually large, we may charge a reasonable fee to cover our costs, and we will tell you before we do.

Correction. If you think information we hold about you is wrong, out of date, incomplete, irrelevant or misleading, ask us to fix it. Many details can also be updated directly in your account.

Deletion. You can ask us to delete your personal information. We will do so where we reasonably can, but we may need to keep some information, for example financial records we must keep by law, or information needed to resolve a dispute or enforce our terms.

We will need to verify your identity before acting on a request. We will respond within a reasonable time, usually within 30 days. If we refuse a request, we will tell you why in writing (unless it would be unreasonable to do so) and explain how you can complain. We may refuse access where the Privacy Act allows it, for example where giving access would unreasonably affect someone else's privacy or relates to legal proceedings.

20International visitors

We are based in Australia and serve people in many countries. If you live outside Australia, your information will be handled in Australia and the other countries listed in section 13, and the laws there may differ from yours.

If you are in the United Kingdom or European Economic Area and the UK GDPR or EU GDPR applies to our handling of your information, you may also have the right to object to or restrict processing, to data portability, and to withdraw consent at any time. We rely on your consent, our contract with you, our legal obligations and our legitimate interests in running and promoting our business as our lawful bases for processing. You can also complain to your local data protection authority. Contact us to exercise any of these rights.

21Complaints

If you are concerned about how we have handled your personal information, please contact us first (details in section 24) and give us as much detail as you can. We will acknowledge your complaint within 5 business days, investigate it, and give you a written response within 30 days.

If you are not satisfied with our response, you can complain to the regulator:

Office of the Australian Information Commissioner (OAIC) Online: oaic.gov.au/privacy/privacy-complaints Phone: 1300 363 992 Post: GPO Box 5288, Sydney NSW 2001

22Other websites and platforms

Our websites, emails and content contain links to other websites, tools and platforms, including affiliate links and tools we recommend. We are not responsible for their privacy practices or content. Please read their privacy policies before giving them your information.

23Changes to this policy

Privacy law in Australia is changing, and further reforms to the Privacy Act are expected. We will review this policy regularly and update it when the law, our business or our tools change. The latest version will always be on this page, with the date it took effect. If we make a significant change that affects how we use information you have already given us, we will let you know by email or a notice on our website.

This policy explains how we handle personal information. It does not create a contract or any rights beyond those given to you by law, and it does not limit any rights you have under the law. It is governed by the laws of Queensland and the Commonwealth of Australia.

24Contact us

For any privacy question, request or complaint, contact our Privacy Officer:

Privacy Officer: Sarah Cordiner, Director MainTraining Pty Ltd (ABN 74 164 108 954), trading as Sarah Cordiner Email: sarah@sarahcordiner.com (subject line "Privacy") Post: Suite 5299, 14a Allendale Entrance, Mermaid Waters QLD 4218, Australia

Version history. Version 3.0, effective 28 September 2026: full rewrite for the Privacy and Other Legislation Amendment Act 2024, automated decision-making, AI tools, recordings and overseas disclosure. Replaces the version last updated September 2024.

Still have a question?

Ask me anything about your privacy.

Want a copy of your information, need something corrected or deleted, or just want to know how something works? Send me an email and my team and I will look after you, usually within a few business days.

Sarah x