Privacy policy
Marsden Park Homes Pty Ltd ("we", "us", "our") respects your privacy and handles personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
This policy explains what we collect, why, and what you can do about it.
1. What we collect
We collect personal information directly from you when you:
- Enquire about a listing — your name, email address, phone number (if provided), and the contents of your enquiry message.
- Save a search or property alert — your email address and the filters you applied.
- Create an agent account — your name, email, mobile, agency, ABN, real-estate licence number, photo, bio, and any social-media handles you choose to add.
- Pay an agent subscription — Stripe (our payments processor) collects your card details directly. We receive a tokenised payment method, the last four digits of your card, your billing postcode, and your subscription status. We never see or store the full card number.
We also automatically collect technical information when you use the site:
- IP address, browser type and version, device type, referring URL, and the pages you view.
- Cookies and similar technologies as described in section 8.
2. Why we collect it
We collect personal information only where it is reasonably necessary for, or directly related to, one or more of our functions:
| Purpose | Information used |
|---|---|
| Routing your enquiry to the listing agent | Your name, email, phone, message |
| Sending you the property alerts you signed up for | Your email, your saved search filters |
| Running the agent platform — accounts, profile pages, billing | Agent KYC details, payment method |
| Detecting and preventing fraud, abuse, or misuse | Technical data, behavioural patterns |
| Improving the product and measuring use | Aggregated analytics (see section 8) |
| Complying with our legal obligations | Any of the above as required |
3. Who we share it with
- The listing agent for the property you enquire about. Your name, email, phone (if provided), and message are forwarded to them so they can reply.
- Our infrastructure providers as sub-processors:
- Amazon Web Services (Sydney region) — hosting, file storage, transactional email via SES.
- Stripe — payment processing for agent subscriptions.
- Mapbox — interactive map tiles (no personally identifiable information shared).
- Authorities or third parties where we are required to by law, or where we believe in good faith disclosure is necessary to protect our rights, your safety, or the safety of others.
We do not sell your personal information to anyone, and we do not share it with third-party marketers.
4. Where it is stored
We store personal information on servers operated by Amazon Web Services in the Sydney (ap-southeast-2) region, with database backups held in the same region.
Stripe processes payment information on its own servers — see stripe.com/au/privacy.
5. How long we keep it
| Category | Retention period |
|---|---|
| Enquiries | 24 months from the date sent, then deleted |
| Saved-search subscribers | Until you unsubscribe |
| Agent accounts and profiles | While the account is active, plus 7 years after closure (for tax and regulatory reasons) |
| Invoices and payment records | 7 years (Tax records as required by the ATO) |
| Technical and analytics data | 14 months (aggregated only after 90 days) |
| Audit logs | 5 years |
6. Your rights
Under the Australian Privacy Principles you can ask us to:
- Access the personal information we hold about you.
- Correct information that is inaccurate, incomplete, or out of date.
- Delete information we no longer have a lawful basis to retain.
- Stop receiving any direct marketing from us.
Email privacy@marsdenparkhomes.com.au with your request. We will respond within 30 days. There is no charge.
If you are not satisfied with our response you can refer the complaint to the Office of the Australian Information Commissioner at oaic.gov.au or by phone on 1300 363 992.
7. How we secure it
- All traffic to and from the site uses TLS 1.2 or later.
- Passwords are not stored — we use single-use magic-link sign-in tokens.
- Personal information is encrypted at rest using AES-256.
- Access to production systems is limited to a small number of staff and audited.
- We run automated dependency scans and security reviews quarterly.
No system is perfectly secure, but we treat your data as if it were our own.
8. Cookies
We use a small number of strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
authjs.session-token |
Keeps you signed in | 30 days |
authjs.csrf-token |
CSRF protection on form submissions | Session |
We also use first-party analytics — pageview counts, anonymised IP addresses, and aggregated demographics — to understand how the site is used. We do not use third-party advertising trackers.
You can clear all cookies at any time through your browser settings.
9. Children
The site is not directed at children under 18. We do not knowingly collect information from children. If you believe we have, email us and we will delete the record.
10. Changes to this policy
We may update this policy from time to time. The current version is always at this URL and dated below. Material changes will be announced on the homepage for at least 30 days before taking effect.
11. Contact
Privacy Officer
Marsden Park Homes Pty Ltd
ABN TBC
privacy@marsdenparkhomes.com.au
Last updated: 27 June 2026.
This policy is a working draft and must be reviewed by Australian legal counsel before publication. See /data-sharing for a summary of who receives what.