Privacy Policy
Last updated: 31 May 2026
This Privacy Policy explains how QRauz ("QRauz", "we", "us" or "our"), a sole trader registered in Australia under ABN 21 674 535 255, collects, uses, discloses, and protects your personal information when you use the QRauz peer-to-peer rental marketplace (the "Platform"). We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). By using the Platform you agree to this Policy. It should be read together with our Terms of Service.
1.Information we collect
| Category | Examples |
|---|---|
| Account | Email address, password (stored only as a secure hash by our authentication provider), display name, and a verification status. |
| Profile | Display name, optional bio, and an optional profile picture (uploaded, or imported from Google if you sign in with Google). |
| Listings | Item titles, descriptions, categories, prices, images, availability, and a suburb-level location (we do not store exact street addresses on listings). Pickup details you choose to add are shared only through chat (see clause 5). |
| Bookings | Dates/times booked, amounts, fees, payout figures, and booking status. We store a payment-processor reference but not your card number. |
| Messages | The content of chat messages between users, including any pickup address or details a user chooses to share there. |
| Reviews & reports | Ratings and reviews you write, and the contents of any abuse report you file or that is filed about you. |
| Technical | Approximate location if you use the "Nearby" feature (with your browser's permission), device/browser information, IP address (used by our providers for security and rate-limiting), push-notification subscription tokens if you opt in, and basic usage data. |
We do not seek to collect sensitive information (such as health, racial, or political information). Please do not include sensitive information in listings, profiles, or messages.
2.How we collect it
We collect information directly from you when you sign up, build a profile, create listings, make or manage bookings, send messages, write reviews, or contact us. We collect some information automatically through your use of the Platform and our service providers (for example IP address and device information for security). If you sign in with Google, we receive your email address, basic profile name, and profile picture from Google to create or match your account.
3.Why we use it
- to create and manage your account and authenticate you;
- to operate the marketplace - show listings, run search and the "Nearby" filter, enable bookings, calendars, and messaging;
- to facilitate payments, fees, holds, captures, refunds, and payouts through our payment processor;
- to send service communications and, if enabled, notifications;
- to keep the Platform safe - prevent fraud and abuse, apply rate limits and bot protection, moderate content, and enforce our Terms;
- to respond to your enquiries and support requests;
- to comply with our legal obligations and to establish, exercise, or defend legal claims.
4.Payments
Payments are processed by Stripe. Your card details are entered into Stripe's secure fields and are handled by Stripe - QRauz does not receive or store your full card number. We store payment metadata such as a payment reference, amounts, fees, and status so we can manage your bookings. Stripe handles your payment information in accordance with its own privacy policy.
5.What other users see
Some information is shared with other users so the marketplace can work:
- your display name, profile picture, bio, ratings, and active listings are visible on your public profile and listings;
- a listing shows its suburb and state, not an exact address;
- when a booking is requested, any pickup address or instructions the owner has added become visible to that renter inside the chat - share an exact address only when you are comfortable doing so;
- for a service performed at your location, the address and any access details you choose to share are disclosed to that provider through the chat after you book, so they can attend - share only what the provider needs to do the job;
- messages are visible to the participants in that conversation.
6.Service providers & overseas disclosure
We share personal information with trusted service providers who help us run the Platform, under contracts that require them to protect it:
- Supabase - database, authentication, file storage, and realtime features;
- Stripe - payment processing;
- Google - optional sign-in;
- Cloudflare - bot and abuse protection (captcha) on sign-up;
- push-notification delivery services operated by your browser/device vendor, if you opt in;
- email delivery for verification codes and account messages.
Some of these providers, or their infrastructure, may be located or store data outside Australia (including in the United States and other countries). By using the Platform you acknowledge that your information may be processed overseas, where privacy laws may differ from those in Australia. We may also disclose information where required or authorised by law, to enforce our Terms, to prevent harm or fraud, or in connection with a sale or transfer of our business. We do not sell your personal information.
7.Browser storage & push notifications
The Platform uses your browser's local storage and similar technologies to keep you signed in and to remember preferences and read/seen state. If you opt in to push notifications, we store a subscription token so we can deliver them; you can turn notifications off at any time in your browser or device settings, and the subscription is removed when it becomes invalid. The "Nearby" feature uses your device location only with your permission and only while you use it.
8.Retention & deletion
We keep personal information for as long as your account is active or as needed to provide the Platform, resolve disputes, and meet legal, accounting, or fraud-prevention obligations. You can delete your account at any time from your account settings. When you delete your account, your authentication record and associated personal data are removed, subject to the following:
- we retain a limited forensic snapshot of certain account details (such as email, display name, bio, and moderation history) for fraud prevention, safety, and to follow up on reports of misconduct;
- content tied to others' records (for example a message you sent, or a review you left) may remain but is disassociated from your identity where practical;
- backups and provider logs may persist for a limited period before being overwritten;
- certain deleted data is purged automatically on a scheduled basis.
We may decline to delete an account while it has active bookings or unresolved obligations until those are resolved.
9.Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, including access controls, row-level database security, encryption in transit, hashed passwords, and abuse/rate-limiting protections. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach likely to cause serious harm occurs, we will respond in line with the Notifiable Data Breaches scheme.
10.Access & correction
You can view and update much of your information directly in your profile and account settings. You may also ask us for a copy of the personal information we hold about you, or ask us to correct it, by contacting us (see clause 15). We will respond within a reasonable time. In the limited cases where we cannot give access or make a correction, we will explain why.
11.Notifications & opt-out
We send transactional and service messages necessary to operate your account (for example verification codes and booking activity). Optional notifications, such as push notifications, are opt-in and can be turned off at any time. We do not currently send marketing emails; if that changes, we will provide a clear way to opt out.
12.Children
The Platform is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can remove it.
13.Complaints
If you have a privacy concern or complaint, please contact us first (see clause 15) and we will try to resolve it. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
14.Changes to this Policy
We may update this Policy from time to time. The current version is always shown here with its "Last updated" date. Material changes will be notified by reasonable means. Continued use of the Platform after a change takes effect means you accept the updated Policy.
15.Contact
The entity responsible for your personal information is QRauz, a sole trader registered in Australia under ABN 21 674 535 255. For privacy questions, access or correction requests, or complaints, contact us via the Contact page or at support@qrauz.com.
See also: Terms of Service.