Who we are. This Privacy Policy explains how Roost 360 Pty Ltd ("Roost", "we", "our", "us") handles personal information in connection with the Roost services. It is available free of charge on our website and within the Roost app.
Quick summary. We collect information needed to provide RoostInspect and related services, use limited analytics and operational data to run and improve the platform, disclose information to service providers that help us host, secure, support, and operate the services, and may process communication details so reminders, notices, and other records can be sent through the platform where enabled.
This Policy is not legal advice. Information provided through the Roost platform — including any compliance-related content, state-specific rules, or inspection guidance — is general information only. It is not legal advice and should not be relied upon as such. You should seek independent legal advice for your specific circumstances.
This Policy covers personal information we collect through the Roost website, mobile app, support channels, RoostInspect workflows, and RoostCare workflows once released. It also covers information we collect from or about landlords, co-owners, tenants, co-tenants, occupiers, applicants, emergency contacts, contractors, service providers, and other authorised users where relevant to the operation of the Services.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. If there is any inconsistency between this Policy and a requirement of the Privacy Act, the Privacy Act prevails.
Depending on how you use the Services, we may collect:
We only collect personal information that is reasonably necessary for one or more of our functions or activities as described in this Policy. If you choose not to provide certain information, we may not be able to provide some or all of the Services to you. For example, without a valid email address we cannot create an account; without property address details we cannot support inspection workflows.
We collect personal information when you create an account, fill in forms, upload content, complete inspections, log maintenance issues, contact support, respond to communications, connect integrations, or otherwise interact with the Services.
When users capture inspection media through Roost, that media may include parts of an occupied property and, in some cases, a tenant's furniture, belongings, or other visible items. Users should only capture what is reasonably necessary for the inspection or record being created and should ensure any required notice, permission, or consent for entry and image capture has been obtained where applicable. Roost will process such content only for the purposes described in this Policy.
We may also collect personal information automatically through the app and website, including through cookies, SDKs, event tracking, server logs, and similar technologies. Some information may be provided to us by another authorised user, such as a landlord inviting a tenant into an inspection flow, or a tenant sharing information relevant to a maintenance request.
Where a property or tenancy involves co-owners or co-tenants, the primary account holder may provide us with personal information about those individuals — including their names and contact details — when setting up the property or tenancy in the Services. We rely on the primary account holder's representation (made in accordance with our Terms of Service) that they are authorised to provide this information and that all relevant parties have been identified. When a co-owner or co-tenant is identified in this way, we will send them an invitation to access the Services and will take reasonable steps to make this Policy available to them at or before the time they first access their records through the Services.
At or before the time of collection, or as soon as reasonably practicable, we take reasonable steps to ensure you are aware of the matters set out in this Policy, including our identity, the purposes for collection, how to access or correct your information, and how to make a complaint.
We may sometimes receive personal information that we did not solicit — for example, information about a third party included incidentally in an uploaded document, inspection photo, maintenance note, or support communication.
When we receive unsolicited personal information, we will within a reasonable time determine whether we could have collected that information under APP 3 had we solicited it. If we determine that we could not have collected it under APP 3, and we are not required by law to retain it, we will take reasonable steps to destroy or de-identify that information as soon as practicable.
We collect, hold, use, and disclose personal information only for the primary purpose for which it was collected, or for a related secondary purpose that individuals would reasonably expect, or where otherwise permitted by law. We may use personal information to:
We handle personal information where it is reasonably necessary for our functions and activities, where users provide information to use the Services, where collection is authorised by another user with an appropriate basis, where consent has been provided for optional features or permissions, or where handling is otherwise required or authorised by law.
We may send you product updates, feature announcements, educational content, or service offers where you would reasonably expect to receive such communications given the nature of your relationship with us, or where you have otherwise consented.
Every marketing communication we send will include a clear, functional mechanism to opt out. If you ask us to stop sending marketing communications, we will action your request within 5 business days and at no cost to you. We will still send non-marketing service notices, operational reminders, legal notices, and other account-related communications where necessary to operate your account, deliver requested workflows, or meet legal obligations.
Our electronic marketing communications comply with the Spam Act 2003 (Cth). Each commercial electronic message we send will clearly identify Roost as the sender, include our contact details, and contain a functional unsubscribe mechanism.
We may use contact details, device tokens, communication preferences, and related metadata to send account messages, reminders, inspection prompts, signing requests, support responses, billing notices, policy updates, and other service-related communications electronically through the App, in-app inbox, push notifications, email, SMS, or similar channels.
Where an owner, landlord, lessor, co-owner, or other authorised user asks Roost to send reminders, notices, statutory forms, signing requests, or other communications to a tenant, co-tenant, occupier, contractor, or other recipient, we may process the relevant contact details, message content, send history, delivery status, and interaction data needed to support that workflow. This may include, where enabled, notice or reminder workflows for entry, inspections, maintenance, acknowledgements, and related record-keeping.
Users are responsible for ensuring they have authority to provide recipient details and to use electronic delivery where required by law or agreement. We may keep records relating to delivery, timestamps, communication settings, and acknowledgements for audit, support, dispute handling, and product integrity purposes. Where a person withdraws consent to electronic communications and the law requires consent, some workflows may need to stop or move outside the platform.
We do not intentionally require sensitive information (as defined in the Privacy Act, including health information, racial or ethnic origin, religious or political beliefs, and similar categories) for normal use of the Services. If sensitive information is included in uploaded documents, notes, media, or support communications, we will handle it in accordance with the Privacy Act and our internal access controls. Users should avoid uploading unnecessary sensitive information. We will not use or disclose sensitive information for purposes other than those for which it was collected without consent or as otherwise permitted by law.
We may use cookies, pixels, local storage, mobile SDKs, and similar tools to keep the Services working, remember settings, analyse performance, reduce fraud, and understand product usage. The exact technologies used may change over time as the product evolves.
Where required by law or platform rules, we will request consent for tracking or optional analytics. You can also control some tracking through device settings, browser settings, or our in-app controls where available.
Roost may use AI-assisted tools, machine learning, image analysis, template logic, summarisation, categorisation, duplicate detection, and other automation to support inspection and maintenance workflows. These features help users work faster but may produce incorrect or incomplete outputs. Users should review outputs before relying on them. We do not use solely automated outputs as a guarantee of legal, tenancy, safety, or repair correctness.
To provide these features, we may disclose prompts, free-text entries, uploaded documents, images, videos, metadata, or other relevant content to third-party AI service providers, including OpenAI and other providers we may use from time to time.
AI provider data use and model training. We do not authorise our AI service providers to use personal information submitted through Roost to train or improve their general AI models. Where we engage AI providers, we seek to do so under terms that restrict providers from using submitted content for model training beyond what is necessary to deliver the specific feature requested. However, provider terms and technical configurations vary, and we recommend users avoid submitting unnecessary personal information when using AI-assisted features.
If at any time we become aware that a provider's terms permit use of submitted data for general model training, we will update this Policy and, where required, seek your consent before continuing to use that provider in a way that would involve your personal information.
Our AI provider mix may change over time as the product evolves. Current providers include OpenAI. We maintain this list in our records and disclose changes through updates to this Policy.
Automated decisions. Where any feature uses automation in a way that could significantly affect your rights or interests — for example, flagging inspection findings, triaging maintenance issues, or generating compliance-related suggestions — that output is intended as an input to a human decision, not a final determination. We will provide further disclosures about specific automated decision-making features as required by law, including any requirements that take effect from December 2026 under amendments to the Privacy Act.
We may disclose personal information to:
We do not sell personal information to third parties for their own marketing or commercial purposes.
We may store or process personal information using service providers in Australia and overseas. Based on our current setup, this may include:
australia-southeast1 as the primary hosting region;asia-south1 for backup or resilience workflows;us-east1 and/or other US-based services for analytics or service tooling where applicable;Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the APPs in relation to that information. Those steps may include:
Where we cannot obtain adequate contractual protections from an overseas recipient, or where you choose to use a feature that involves cross-border disclosure without those protections in place, we will, where required, seek your informed consent to that disclosure and note that the overseas recipient may not be subject to the APPs.
You acknowledge that, despite our reasonable steps, overseas recipients may be subject to the laws of their own jurisdiction, and those laws may not protect personal information in the same way as the Privacy Act.
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Security measures may include encryption in transit and at rest, role-based access controls, audit logging, backup controls, monitoring, secure development practices, and incident response processes.
No system is completely secure. You are responsible for maintaining the security of your own devices, passwords, and access settings.
When personal information is no longer needed for the purposes described in this Policy, and we are not required by law or a legitimate operational reason to retain it, we will take reasonable steps to destroy or de-identify it.
If you become aware of a security concern relating to your Roost account or the Services, please contact us immediately using the details in Section 21.
We aim to collect only the information reasonably needed for our services and to keep that information accurate, complete, and up to date. Before using or disclosing personal information for a significant purpose, we take reasonable steps to ensure it is accurate, up to date, complete, and relevant having regard to that purpose. Users should review and update information they provide, especially contact details, property details, inspection records, maintenance records, and the contact details of any co-owners or co-tenants they have identified in the Services.
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain records, manage disputes, meet legal obligations, prevent fraud, and enforce agreements. Retention periods may vary by record type, account status, dispute risk, and legal requirements.
When personal information is no longer needed and no legal obligation requires its retention, we will take reasonable steps to destroy it securely or de-identify it so that it can no longer be linked to any individual. Backups and archived copies may remain for a limited period after deletion requests or account closure as part of disaster recovery, security, and integrity processes, and will be destroyed or de-identified at the end of that period.
You have the right to request access to personal information we hold about you and to ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
To make an access request, contact us using the details in Section 21. We will respond to your request within 30 days of receiving it. We will not charge you for making an access request. In some cases, we may charge a reasonable fee to cover the cost of providing access (for example, where a large volume of records must be retrieved and compiled), but we will notify you of any such fee before proceeding.
We may refuse access in limited circumstances — for example, where providing access would pose a serious threat to life or safety, where the information relates to existing or anticipated legal proceedings, where providing access would unreasonably prejudice the privacy of another individual, or where required or authorised by law. If we refuse access, we will give you written notice of the refusal, the reasons for refusal (to the extent we are permitted to do so), and the mechanisms available to you to complain about the refusal.
To request a correction, contact us using the details in Section 21. We will take reasonable steps to correct the information within 30 days of receiving your request. We will not charge you for making a correction request.
If we correct information that we have previously disclosed to a third party, we will take reasonable steps to notify that third party of the correction unless it is impracticable or unlawful to do so.
If we refuse to correct personal information as you have requested, we will give you written notice setting out our reasons for the refusal (to the extent we are permitted to do so) and the mechanisms available to you to complain about the refusal. If we refuse a correction request, you may ask us to associate a statement with the relevant record noting that you believe it is inaccurate, out of date, incomplete, irrelevant, or misleading. We will take reasonable steps to associate that statement in a way that will make it apparent to users of the information.
You may also request deletion of certain information, subject to legal, contractual, security, or operational limitations. Some requests may need identity verification before we act on them.
In many cases, you cannot use the core Services anonymously or under a pseudonym because account identification and property workflow integrity are central to the service. However, you may contact us with general enquiries without providing full account details. Where it is lawful and practicable to allow anonymity or pseudonymity for a particular interaction, we will offer that option.
We do not adopt, use, or disclose government-related identifiers (such as tax file numbers, Medicare numbers, or driver's licence numbers) as our own identifier of individuals, and we do not require you to provide such identifiers to use the Services. If a government-related identifier is provided incidentally in an uploaded document, it will be handled consistently with the Privacy Act and the APPs.
The Services are intended for adults aged 18 years and over. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected personal information from a person under 18, we will take reasonable steps to delete it. If you believe we may have collected information from a minor, please contact us using the details in Section 21.
Our obligations under the Notifiable Data Breaches scheme. We are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). Under this scheme, if we reasonably believe there has been an eligible data breach — that is, unauthorised access to, or disclosure of, personal information that is likely to result in serious harm to one or more individuals — we are required to:
We maintain an internal incident response process to detect, assess, and respond to data security incidents. If we become aware of a security incident, we will:
If you become aware of or suspect a security or privacy incident involving your personal information or the Roost platform, please contact us immediately at support@my-roost.com with the subject line SECURITY. We will acknowledge your report promptly and investigate in accordance with our incident response process.
The Office of the Australian Information Commissioner can be contacted at www.oaic.gov.au or by telephone on 1300 363 992 if you have concerns about how we have handled your personal information or a potential data breach.
If you have a privacy complaint or concern, we encourage you to contact us first using the details in Section 21. Please describe the issue clearly and include enough information for us to investigate and respond. We will acknowledge your complaint within 5 business days and aim to provide a substantive response within 30 days.
If you are not satisfied with our response, or if we fail to respond within a reasonable time, you may lodge a complaint with the Office of the Australian Information Commissioner:
We may update this Policy from time to time to reflect changes in our practices, technology, legal obligations, or for other operational reasons. The latest version will be published on our website and may also be linked in the App and app store listings where required. The date at the top of this Policy reflects when it was last updated. Material changes may also be notified through the Services or by email where we consider it appropriate to do so.
Privacy contact: support@my-roost.com
General support: support@my-roost.com
Security and breach reports: support@my-roost.com — subject line: SECURITY
Legal entity: Roost 360 Pty Ltd
ACN: 697 382 979
ABN: 44 697 382 979
Location: New South Wales, Australia
Website: www.my-roost.com.au
APP index. For reference, the following table maps each Australian Privacy Principle to the section of this Policy where it is primarily addressed.
| APP | Subject | Section(s) |
|---|---|---|
| APP 1 | Open and transparent management of personal information | 1, 20, this Policy as a whole |
| APP 2 | Anonymity and pseudonymity | 16 |
| APP 3 | Collection of solicited personal information | 2, 3 |
| APP 4 | Dealing with unsolicited personal information | 3A |
| APP 5 | Notification of the collection of personal information | 2, 3 |
| APP 6 | Use or disclosure of personal information | 4, 9 |
| APP 7 | Direct marketing | 6 |
| APP 8 | Cross-border disclosure | 11 |
| APP 9 | Adoption, use or disclosure of government related identifiers | 16A |
| APP 10 | Quality of personal information | 13 |
| APP 11 | Security of personal information | 12, 14 |
| APP 12 | Access to personal information | 15 |
| APP 13 | Correction of personal information | 15 |
| NDB scheme | Notifiable Data Breaches | 18 |