Skip to main content
Roomfolio

Privacy policy

Last updated · May 2026

Draft. This document accurately describes how the platform behaves today, but it has not yet been reviewed by a lawyer. Before going public, run it past an Australian privacy/IT lawyer familiar with the Privacy Act and the Australian Consumer Law.

1. Who we are

Roomfolio (“we”, “us”, “our”) is a flatshare marketplace operating in Australia. This policy explains what data we collect, why, and what choices you have. We follow the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

2. What we collect

  • Account basics: name, email, password (hashed), date of birth (for the age check), and any photos you upload.
  • Listings: property details, photos, house rules, lifestyle preferences. Public unless flagged by a moderator.
  • Verifications: mobile number, email token, government-issued ID image. ID images are stored encrypted, admin-only, and EXIF/GPS metadata is stripped before storage.
  • Messages: conversation contents, sent with AES-256-GCM encryption at rest. Read receipts and timestamps are stored for the participants only.
  • Payments: when you buy a featured slot we share the transaction with Stripe; we never see your card number. We do store a payment ID + status for accounting.
  • Usage logs: page views, search filters, rate-limit counters, and admin-action audit trails. Most are kept 90 days; audit logs longer.
  • Reviews: public 1–5 star ratings + body you leave on profiles, plus hidden reviews moderators have removed. The hidden ones remain visible to the subject in their own dashboard.

3. How we use it

  • Running the service — search, messaging, payments.
  • Showing the right people to each other (lifestyle match, host-fit hints) — only with data you've actively entered.
  • Sending transactional emails (verification, password reset, listing-status changes). You can opt out of each category under Settings → Notifications, except the bare minimum operational ones (e.g. password resets).
  • Fraud and abuse prevention — rate-limiting, ID checks, report handling.

4. Who we share with

We do not sell personal data. Limited sharing happens with the third parties we need to run the service:

  • Stripe — payment processor for featured slots. Their privacy policy applies to what they collect.
  • Twilio — sends the SMS verification code when you verify your phone.
  • Resend — sends transactional emails.
  • Cloud storage (S3 or local disk, depending on the deployment) — listing photos and ID documents.
  • Law enforcement — only when required by a valid Australian legal request.

5. Retention

Account data stays as long as your account exists. When you delete your account, public traces (listings, reviews) are anonymised; messages are kept only inasmuch as the other participant still has access; ID documents are deleted within 30 days. Audit logs and payment records are kept for 7 years under Australian tax/financial-services rules.

6. Your rights

You can access, correct, and delete your data from the dashboard (Settings + Verification). For anything that's not exposed in the UI, email [email protected] from your account address and we'll respond within 30 days. You can complain to the OAIC if you think we've mishandled your data.

7. Cookies

We use first-party cookies for authentication (NextAuth session) and CSRF protection. No third-party analytics or advertising cookies are set by default. If we add analytics in the future, the cookie banner you see will name them and let you opt out.

8. Changes

When we change this policy materially, we'll send everyone a notification + email at least 14 days before the new version takes effect. Cosmetic edits (typos, formatting) go live without notice.

9. Contact