1. Introduction
This Privacy Policy explains how Virtual Buyers Agent Pty Ltd (ACN 694 217 046) ("VBA", "we", "us", "our") collects, uses, discloses, and protects your personal information when you use our platform at virtualbuyersagent.com.au, our mobile applications, and related services. We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using our Service, you consent to the collection and use of your information as described in this policy.
2. Information We Collect
We collect several categories of information:
(a) Account Information: name, email, password (securely hashed), and profile photo when you register;
(b) Investor Profile: 18 data points including investment goals, risk tolerance, income range, deposit amount, borrowing capacity, property preferences, and investment experience—collected through our onboarding quiz;
(c) Financial Context: gross income, available deposit, LVR tolerance, monthly surplus, and debt-to-income ratio—used to personalise analysis;
(d) Property Activity: properties searched, saved, compared, and analysed;
(e) Behavioural Data: pages visited, features used, session duration, and interaction patterns;
(f) Device Data: browser type, operating system, IP address, and device identifiers;
(g) Payment Data: processed and stored securely by Stripe—we do not store full credit card numbers.
3. How We Use Your Information
We use your information to:
(a) Provide the Service: authenticate your account, deliver property analysis, and personalise recommendations based on your profile;
(b) Improve the Service: analyse usage patterns to enhance features, fix bugs, and optimise performance;
(c) Communicate with You: send transactional emails, product updates, and marketing communications (with your consent);
(d) Process Payments: manage subscriptions, process transactions, and send invoices;
(e) Ensure Security: detect fraud, prevent abuse, and protect user accounts;
(f) Comply with Law: meet legal obligations and respond to lawful requests.
We do NOT use your data for automated decision-making that has legal effects on you.
4. AI Features and Data Use
VBA uses artificial intelligence in specific features including: Smart Property Search, Investor Profile Fit Score, Chatbot Assistant, and our document analysis modules (Contract Extractor, Strata Analyzer, Building Inspector). These features use OpenAI's GPT models to process your queries and profile data. When you use AI features:
• Your prompts and profile context are sent to OpenAI for processing;
• OpenAI does not use your data to train their models (per our enterprise agreement);
• AI responses are generated in real-time and not stored by OpenAI.
We track AI usage (tokens, cost, latency) through PostHog for quality monitoring. All other 19 analysis modules use deterministic calculations and do not involve AI or external data processing.
5. Data Sharing and Disclosure
We share your data only as follows:
(a) Service Providers: trusted third parties who help us operate the Service (see Third-Party Services section below);
(b) Legal Requirements: when required by law, court order, or government request;
(c) Business Transfers: in connection with a merger, acquisition, or sale of assets (you will be notified of any change in data controller);
(d) With Your Consent: for any purpose you explicitly authorise.
We NEVER sell your personal information to advertisers, data brokers, or any third party for their marketing purposes.
6. Data Retention
We retain your data for as long as necessary to provide the Service and fulfil the purposes described in this policy. Specifically:
• Account Data: retained while your account is active and for 30 days after deletion request;
• Property Activity: retained for 2 years after your last login to support historical analysis;
• Analytics Data: anonymised and retained indefinitely for product improvement;
• Payment Records: retained for 7 years as required by Australian tax law;
• Support Communications: retained for 2 years.
You can request data deletion at any time—we will delete or anonymise your data within 30 days, except where retention is legally required.
7. Data Security
We implement industry-standard security measures to protect your data:
(a) Encryption: all data is encrypted in transit (TLS 1.3) and at rest (AES-256);
(b) Access Controls: role-based access limits who can view your data;
(c) Infrastructure: hosted on Supabase (Sydney region) with SOC 2 Type II compliance;
(d) Authentication: secure password hashing (bcrypt), Google OAuth option, and session management;
(e) Monitoring: real-time security monitoring and automated threat detection.
While we take extensive precautions, no system is 100% secure. We will notify you promptly if a data breach affects your personal information.
8. International Data Transfers
Your data is primarily stored in Australia (Sydney region) on Supabase infrastructure. Some third-party services may process data in other jurisdictions: Stripe (US/EU with Australian processing), PostHog (EU/US), Resend (US), and OpenAI (US for AI features). All international transfers are subject to appropriate safeguards including Standard Contractual Clauses, adequacy decisions, or binding corporate rules. We ensure all data transfers comply with the Privacy Act 1988 and provide equivalent protection to Australian privacy laws.
9. Your Privacy Rights
Under the Privacy Act 1988 and APPs, you have the right to:
(a) Access: request a copy of personal information we hold about you;
(b) Correction: request correction of inaccurate or incomplete data;
(c) Deletion: request deletion of your data (subject to legal retention requirements);
(d) Portability: receive your data in a structured, commonly used format;
(e) Opt-out: unsubscribe from marketing communications;
(f) Complain: lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy.
To exercise any right, contact info@virtualbuyersagent.com.au. We respond within 30 days.
10. Children's Privacy
VBA is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will delete that information immediately. If you believe a child has provided us with personal information, please contact us at info@virtualbuyersagent.com.au.
11. Marketing Communications
With your consent, we may send you: product updates and new features; market insights and property investment education; promotional offers and subscription discounts; weekly digest emails with personalised suggestions.
You can opt-out at any time by:
• Clicking "unsubscribe" in any marketing email;
• Updating preferences in your account dashboard;
• Contacting support at info@virtualbuyersagent.com.au.
We honour opt-out requests within 5 business days. Transactional emails (receipts, security alerts, account updates) are not affected by marketing opt-outs.
12. Cookies and Tracking
We use cookies and similar technologies for authentication, analytics, and payment processing. Essential cookies are required for the Service to function; analytics cookies (PostHog) help us improve the platform; payment cookies (Stripe) enable secure transactions. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using the Service. For complete details, see our Cookie Policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated via email to your registered address at least 14 days before taking effect. The "Last Updated" date at the top of this policy indicates when it was last revised. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
14. Contact Information
For privacy-related inquiries, requests, or complaints:
Privacy Officer, Virtual Buyers Agent Pty Ltd
Email: info@virtualbuyersagent.com.au
For general support: info@virtualbuyersagent.com.au
We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.