Legal

Privacy Policy

Last updated: 1 June 2026 · RentRolli Pty Ltd ABN 20 666 275 556

In plain words

The short version of what this document says:

  • We collect information to run the platform. Most of it is business data (your agency, ABN, portfolio metrics), but some of it is personal (name, email, phone).

  • We don't sell your data. Ever.

  • We use Stripe for payments and Persona for ID checks. We don't see your card numbers or your government ID. Those companies hold that data, not us.

  • Your portfolio data is hosted on Supabase and Vercel in the US. Google Gemini processes AI-generated descriptions and summaries. By using RentRolli, you agree to that data being processed overseas.

  • We share your identity with another user only after you both sign a digital NDA.

  • You can request, correct, or delete your data at any time. Email privacy@rentrolli.com.

  • If we have a serious data breach, we'll tell you and the regulator within the timeframes the law requires.

The full Privacy Policy below is the binding version. This summary is for context only.

RentRolli Pty Ltd (ABN 20 666 275 556) (we, us, or our) is committed to protecting your privacy and managing personal information in an open and transparent manner. This Privacy Policy details how we collect, use, disclose, store, and protect your personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1

Personal Information We Collect

We only collect personal information that is reasonably necessary for, or directly related to, our business functions as a B2B SaaS marketplace and diagnostic platform. The types of personal information we may collect include:

1.1

Account and Registration Data

Your name, email address, phone number, agency name, job title, corporate address, and Australian Business Number (ABN).

1.2

Identity Verification Status

To preserve platform integrity, we require identity verification. This process is conducted by our third-party identity verification partner, Persona. Persona collects images of your government-issued identification documents and a video selfie verification. RentRolli does not receive, view, or store these underlying identity documents or biometric data streams; we are only provided with and store an automated verification status confirmation (e.g. Verified or Failed).

1.3

Financial and Payment Records

All credit card transactions and payment processing activities are securely managed by our third-party payment provider, Stripe. RentRolli does not store, process, or transmit full credit card numbers or sensitive CVV data on our servers. Stripe retains this data in accordance with international PCI DSS compliance frameworks.

1.4

Marketplace and Portfolio Operational Metrics

When users input listing parameters or upload portfolio files to generate a RolliScore, we extract business metrics such as managed property addresses, weekly rental figures, management fee percentages, vacancy statistics, compliance tracking parameters, and historical arrears records. While this information relates predominantly to business assets and operations, any addresses or structured operational metadata that could indirectly identify individuals will be managed in accordance with this Privacy Policy.

1.5

Communication Data

We collect and store logs, texts, and messages exchanged within the deal rooms and messaging infrastructure hosted on our Platform.

1.6

Device and Usage Information

We collect technical data automatically via system logs, including your internet protocol (IP) address, device fingerprints, operating system type, browser parameters, cookies, access times, and interaction analytics.

2

How We Collect Personal Information

We collect personal information through several primary pathways:

  1. (a)Directly from you when you create an account, fill out profiles, create listings, upload data, or communicate with other users on the Platform;
  2. (b)Automatically through cookies, system trackers, and embedded diagnostic tools as you navigate the website; and
  3. (c)From third-party integrated services, such as receiving verification indicators from Persona or transactional confirmations from Stripe.
3

How We Use Personal Information

We process and use your personal information strictly for the following operational purposes:

  1. (a)To supply, manage, host, maintain, and protect the Platform and its algorithmic tools;
  2. (b)To process subscription and boost transactions and verify business identities;
  3. (c)To enable the execution of binding digital NDAs and manage anonymous marketplace matches;
  4. (d)To analyse, refine, optimise, and train our diagnostic algorithms, including the RolliScore engine;
  5. (e)To provide customer service support, resolve platform issues, and enforce our Terms of Service;
  6. (f)To generate anonymous, aggregated commercial property data, industry reports, and macro market benchmarks; and
  7. (g)To send essential transactional emails, service updates, and occasional direct marketing communications in strict compliance with the Spam Act 2003 (Cth).
4

Disclosure of Personal Information

We do not sell, rent, or lease your personal information to third parties. We may disclose your personal information in the following limited circumstances:

4.1

Marketplace Interventions

When a buyer and seller mutually execute a digital NDA, the platform will disclose the respective verified identities and corporate contact details to both parties to open the designated digital data room.

4.2

Third-Party Technical Processors

We share data with trusted third-party service providers who assist us in hosting, securing, maintaining, and running our digital applications. These infrastructure partners are legally bound by strict confidentiality and data protection obligations.

4.3

Legal Requirements

We may disclose your information if required to do so by applicable Australian laws, court orders, or where validly requested by a law enforcement or regulatory authority.

5

Cross-Border Data Transfers (APP 8)

RentRolli utilises cloud hosting, database architecture, and specialised SaaS tooling provided by global tech vendors. Accordingly, your personal information and uploaded portfolio data may be transferred to, stored in, or processed across overseas servers, primarily located in the United States of America.

ProviderCore PurposeJurisdiction
SupabaseCore Postgres database infrastructure, authentication layers, and file structuresUnited States
StripeCommercial billing operations and secure payment pathwaysUnited States
PersonaSecure commercial identity verification and fraud preventionUnited States
ResendDistribution of transactional emails and platform updatesUnited States
VercelApplication deployment, web hosting, and content delivery networkingUnited States
Google (Gemini API)AI-generated portfolio summaries, listing description refinement, and diagnostic narrativeUnited States

By using the Platform and providing us with your personal information, you explicitly consent to the transfer, storage, and processing of your personal information outside of Australia. You acknowledge that while these providers are industry leaders adhering to high-tier data protections, overseas recipients may not always be subject to privacy obligations identical to the Australian Privacy Principles.

6

Data Security and Breach Protocols

6.1

Security Controls

We deploy industry-standard technical and operational security measures, including transport layer encryption (SSL/TLS), access controls, and pseudonymisation techniques, designed to protect your personal information from unauthorised access, loss, misuse, modification, or exposure.

6.2

Data Breaches

While we implement rigorous defensive security, no system connected to the internet can be guaranteed as entirely immune from risk. In the event of an eligible data breach that is likely to result in serious harm to individuals, we will activate our internal data breach response protocols and notify the Office of the Australian Information Commissioner (OAIC) and impacted users in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act.

7

Your Rights: Access, Correction, and Deletion

7.1

Access and Correction (APP 12 & 13)

You have a right to request access to the personal information we hold about you, or to request that we correct any inaccurate, outdated, or incomplete records. You can update most profile information directly through your account dashboard or by submitting a written request to our Privacy Officer.

7.2

Account Deletion and Retention

You may request the deletion of your account and erasure of your personal data at any time. Upon receiving a valid deletion request, we will remove your personal identifiers from our production systems. You acknowledge that we may retain certain transactional data, digital NDA signature logs, or financial records where necessary to comply with Australian tax laws, legal evidence requirements, or corporate record-keeping obligations.

7.3

Marketing Opt-Out

You can opt out of receiving direct marketing communications from RentRolli at any time by clicking the unsubscribe link embedded in the footer of our emails or by adjusting your notifications inside your user settings.

8

Privacy Complaints

If you have a question, concern, or wish to file a formal complaint regarding a potential breach of this Privacy Policy or the Australian Privacy Principles, please contact our Privacy Officer:

Privacy Officer

RentRolli Pty Ltd

privacy@rentrolli.com

3206 / 4 Marina Promenade, Paradise Point QLD 4216, Australia

We will investigate your complaint promptly and provide a formal written response within 30 days detailing our findings and the corrective actions we intend to deploy. If you remain unsatisfied with our response, you have the right to escalate your complaint directly to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

9

Updates to this Policy

We may review and update this Privacy Policy periodically to reflect shifts in technology, corporate models, or changing Australian legislative requirements. The date of the most recent revision will always be displayed at the top of this document.

Privacy questions?

Email privacy@rentrolli.com

Contact Us