Privacy policy
How PropRetire handles personal information, service providers, retention and account deletion across the website, accounts and support.
Scope
This policy explains how Propretire Pty Ltd handles personal information when you use the PropRetire website, an account or a support channel.
We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
Information we handle
We handle the identity and account details you provide, the personal and financial information entered in portfolio records, and messages sent through contact or support channels. A portfolio can contain information about clients, household members and other legal owners even though they are not account users.
Using the service also creates authentication, billing and operational records. These can include security-factor enrolment and use, recovery-code status and use, active and revoked sessions, IP addresses, browser or device details, request and error logs, and security events. Stripe sends billing events to PropRetire. The application stores billing references and subscription status, while Stripe remains the invoice and payment record.
Collection and use
Most account, portfolio and support information comes directly from the account user. Technical and security records arise when the website or application is used, and billing records also come from Stripe.
We use this information to create and secure accounts, operate the portfolio records and requested workflows, manage billing, send service messages and notices about changes to an email address or security factor, answer support requests, diagnose faults, investigate misuse and meet applicable legal obligations.
Service providers and disclosure
PropRetire uses Stripe for billing and Resend for transactional email. Hosting, database and security infrastructure also processes the information needed to run the website and application. The information handled by each provider depends on that function.
Property forms can provide Google Places suggestions in the Street address field. PropRetire does not contact Google until the Street address field receives focus. When suggestions are enabled, Google receives the address text you enter and technical request information. You can switch to manual entry instead. Google controls its processing locations and retention under its terms and privacy policy.
PropRetire requests address components only. It does not save a Google place ID, coordinates or the raw Google response. If you submit the form, PropRetire saves the resulting street address, suburb, state and postcode together with the matching official Australian suburb reference.
Information held in a provider system is also governed by our arrangement with the provider, the provider’s privacy terms and applicable law. This policy does not state that a provider stores or processes information only in Australia, and it does not promise a fixed provider retention period.
We may disclose personal information when the law requires it or when needed to investigate misuse, protect an account or protect the service.
Security
PropRetire takes reasonable steps to protect personal information, including authentication, account-to-portfolio authorisation and restricted operational access. No internet service can eliminate every security risk.
Retention and account deletion
Different records serve different account, billing, support, security and legal purposes, so this policy does not promise one retention period for all personal information. Saved account and portfolio records are held in the application database for the life of the account unless a record is deleted through the product. Other operational records may be kept for a different period according to their purpose, provider rules and applicable law.
Ending paid access does not delete an account. When the registered user requests account deletion, confirms the current password and completes a second-factor check when two-step verification is enabled, PropRetire accepts the request and starts cancellation of current Stripe subscriptions and permanent removal of the user, account, portfolios and saved records from the application database. The process continues after the session ends and may take time to complete. It also removes account-owned local email-delivery records. Records belonging to another account’s information request or sent report remain with that workflow under its retention boundary.
Deleting the application account does not itself erase records already held in Stripe or another provider system. Those records remain subject to the provider terms and applicable law.
Access, correction and complaints
You can update account and portfolio information available in the product. You can also ask to access or correct other personal information we hold. For those requests, account deletion questions or a privacy complaint, contact us using the address below. We may ask for identity information reasonably needed and proportionate to the request, and may need to clarify the information involved. Applicable law determines the scope and timing of any required response.
Email privacy@propretire.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.