← Back to Virtual Buyers Agent

Privacy Policy

Last Updated: January 9, 2026•Version 3.1

Minimal Collection

We only collect information necessary to provide our services.

No Data Selling

Your personal information is never sold to third parties.

Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256).

Compliance

Fully compliant with Privacy Act 1988 and Australian Privacy Principles.

What Information We Collect

Account Information (Required)

Name, email address, password (hashed), avatar image, and account preferences. Required for authentication and service delivery.

Examples: Full name, email, profile photo.

Investor Profile Data (Optional)

Information collected through our Investor Profile Quiz to personalise your experience. Includes investment goals, risk tolerance, financial situation, and property preferences.

Examples: Income range, deposit amount, investment timeline, risk tolerance (1-10), property type preferences.

Financial Information (Optional)

Financial details you provide to receive tailored analysis. We do not store complete bank account or credit card numbers—payment processing is handled securely by Stripe.

Examples: Borrowing capacity, deposit amount, LVR tolerance, monthly surplus.

Property Search Data (Optional)

Properties you search for, save, compare, and analyse. Used to personalise recommendations and improve our analysis modules.

Examples: Searched suburbs, saved properties, comparison lists, analysis history.

Usage Analytics (Optional)

How you interact with our platform to improve features and user experience. Collected via PostHog analytics.

Examples: Pages visited, features used, session duration, device type.

Communication Data (Optional)

Support conversations, feedback, and email engagement metrics to provide better service.

Examples: Support tickets, email opens/clicks, notification preferences.

AI Data Processing

Features using AI: Smart Property Search, Investor Profile Fit Score, Chatbot, and document modules (Contract/Strata/Building).

  • OpenAI does not use your data to train their models.
  • All other 19 modules use deterministic calculations—no AI, no external processing.

Third-Party Services

ServicePurposeData SharedLocation
SupabaseAuthentication and database hostingAccount credentials, user dataAustralia (Sydney region)
StripePayment processing and subscriptionsPayment details, billing addressProcessed in Australia
PostHogProduct analytics and UXAnonymised usage dataEU/US (Aus residency option)
ResendEmail deliveryEmail address, nameUS (GDPR compliance)
Domain APIProperty data listingsSearch queries (no personal data)Australia

Your Rights

✓

Access your personal data

Request a copy of all data we hold.

✓

Correct inaccurate information

Update or fix incorrect data.

✓

Delete your account

Request permanent deletion.

✓

Export your data

Receive data in portable format.

✓

Opt-out of marketing

Unsubscribe at any time.

✓

Restrict processing

Limit how we use your data.

To exercise any right, contact info@virtualbuyersagent.com.au. We respond within 30 days.

COMPLETE PRIVACY POLICY

1. Introduction

This Privacy Policy explains how Virtual Buyers Agent Pty Ltd (ACN 694 217 046) ("VBA", "we", "us", "our") collects, uses, discloses, and protects your personal information when you use our platform at virtualbuyersagent.com.au, our mobile applications, and related services. We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using our Service, you consent to the collection and use of your information as described in this policy.

2. Information We Collect

We collect several categories of information: (a) Account Information: name, email, password (securely hashed), and profile photo when you register; (b) Investor Profile: 18 data points including investment goals, risk tolerance, income range, deposit amount, borrowing capacity, property preferences, and investment experience—collected through our onboarding quiz; (c) Financial Context: gross income, available deposit, LVR tolerance, monthly surplus, and debt-to-income ratio—used to personalise analysis; (d) Property Activity: properties searched, saved, compared, and analysed; (e) Behavioural Data: pages visited, features used, session duration, and interaction patterns; (f) Device Data: browser type, operating system, IP address, and device identifiers; (g) Payment Data: processed and stored securely by Stripe—we do not store full credit card numbers.

3. How We Use Your Information

We use your information to: (a) Provide the Service: authenticate your account, deliver property analysis, and personalise recommendations based on your profile; (b) Improve the Service: analyse usage patterns to enhance features, fix bugs, and optimise performance; (c) Communicate with You: send transactional emails, product updates, and marketing communications (with your consent); (d) Process Payments: manage subscriptions, process transactions, and send invoices; (e) Ensure Security: detect fraud, prevent abuse, and protect user accounts; (f) Comply with Law: meet legal obligations and respond to lawful requests. We do NOT use your data for automated decision-making that has legal effects on you.

4. AI Features and Data Use

VBA uses artificial intelligence in specific features including: Smart Property Search, Investor Profile Fit Score, Chatbot Assistant, and our document analysis modules (Contract Extractor, Strata Analyzer, Building Inspector). These features use OpenAI's GPT models to process your queries and profile data. When you use AI features: • Your prompts and profile context are sent to OpenAI for processing; • OpenAI does not use your data to train their models (per our enterprise agreement); • AI responses are generated in real-time and not stored by OpenAI. We track AI usage (tokens, cost, latency) through PostHog for quality monitoring. All other 19 analysis modules use deterministic calculations and do not involve AI or external data processing.

5. Data Sharing and Disclosure

We share your data only as follows: (a) Service Providers: trusted third parties who help us operate the Service (see Third-Party Services section below); (b) Legal Requirements: when required by law, court order, or government request; (c) Business Transfers: in connection with a merger, acquisition, or sale of assets (you will be notified of any change in data controller); (d) With Your Consent: for any purpose you explicitly authorise. We NEVER sell your personal information to advertisers, data brokers, or any third party for their marketing purposes.

6. Data Retention

We retain your data for as long as necessary to provide the Service and fulfil the purposes described in this policy. Specifically: • Account Data: retained while your account is active and for 30 days after deletion request; • Property Activity: retained for 2 years after your last login to support historical analysis; • Analytics Data: anonymised and retained indefinitely for product improvement; • Payment Records: retained for 7 years as required by Australian tax law; • Support Communications: retained for 2 years. You can request data deletion at any time—we will delete or anonymise your data within 30 days, except where retention is legally required.

7. Data Security

We implement industry-standard security measures to protect your data: (a) Encryption: all data is encrypted in transit (TLS 1.3) and at rest (AES-256); (b) Access Controls: role-based access limits who can view your data; (c) Infrastructure: hosted on Supabase (Sydney region) with SOC 2 Type II compliance; (d) Authentication: secure password hashing (bcrypt), Google OAuth option, and session management; (e) Monitoring: real-time security monitoring and automated threat detection. While we take extensive precautions, no system is 100% secure. We will notify you promptly if a data breach affects your personal information.

8. International Data Transfers

Your data is primarily stored in Australia (Sydney region) on Supabase infrastructure. Some third-party services may process data in other jurisdictions: Stripe (US/EU with Australian processing), PostHog (EU/US), Resend (US), and OpenAI (US for AI features). All international transfers are subject to appropriate safeguards including Standard Contractual Clauses, adequacy decisions, or binding corporate rules. We ensure all data transfers comply with the Privacy Act 1988 and provide equivalent protection to Australian privacy laws.

9. Your Privacy Rights

Under the Privacy Act 1988 and APPs, you have the right to: (a) Access: request a copy of personal information we hold about you; (b) Correction: request correction of inaccurate or incomplete data; (c) Deletion: request deletion of your data (subject to legal retention requirements); (d) Portability: receive your data in a structured, commonly used format; (e) Opt-out: unsubscribe from marketing communications; (f) Complain: lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy. To exercise any right, contact info@virtualbuyersagent.com.au. We respond within 30 days.

10. Children's Privacy

VBA is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will delete that information immediately. If you believe a child has provided us with personal information, please contact us at info@virtualbuyersagent.com.au.

11. Marketing Communications

With your consent, we may send you: product updates and new features; market insights and property investment education; promotional offers and subscription discounts; weekly digest emails with personalised suggestions. You can opt-out at any time by: • Clicking "unsubscribe" in any marketing email; • Updating preferences in your account dashboard; • Contacting support at info@virtualbuyersagent.com.au. We honour opt-out requests within 5 business days. Transactional emails (receipts, security alerts, account updates) are not affected by marketing opt-outs.

12. Cookies and Tracking

We use cookies and similar technologies for authentication, analytics, and payment processing. Essential cookies are required for the Service to function; analytics cookies (PostHog) help us improve the platform; payment cookies (Stripe) enable secure transactions. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using the Service. For complete details, see our Cookie Policy.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated via email to your registered address at least 14 days before taking effect. The "Last Updated" date at the top of this policy indicates when it was last revised. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

14. Contact Information

For privacy-related inquiries, requests, or complaints: Privacy Officer, Virtual Buyers Agent Pty Ltd Email: info@virtualbuyersagent.com.au For general support: info@virtualbuyersagent.com.au We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

Related Policies

Terms of ServiceDisclaimerCookie Policy

© 2026 Virtual Buyers Agent Pty Ltd (ABN 62 694 217 046)