RoostRoost
How it worksFeaturesPricingRoost Care SoonFAQBlog
Learn more
How it worksFeaturesPricingRoost Care SoonFAQBlog

Roost Privacy Policy

Last updated: August 2026
Applies to: Roost website, mobile app, RoostInspect at launch, and RoostCare when released.
Entity: Roost 360 Pty Ltd · ACN 697 382 979 · ABN 44 697 382 979

Who we are. This Privacy Policy explains how Roost 360 Pty Ltd ("Roost", "we", "our", "us") handles personal information in connection with the Roost services. It is available free of charge on our website and within the Roost app.

Quick summary. We collect information needed to provide RoostInspect and related services, use limited analytics and operational data to run and improve the platform, disclose information to service providers that help us host, secure, support, and operate the services, and may process communication details so reminders, notices, and other records can be sent through the platform where enabled.

This Policy is not legal advice. Information provided through the Roost platform — including any compliance-related content, state-specific rules, or inspection guidance — is general information only. It is not legal advice and should not be relied upon as such. You should seek independent legal advice for your specific circumstances.

1. Scope

This Policy covers personal information we collect through the Roost website, mobile app, support channels, RoostInspect workflows, and RoostCare workflows once released. It also covers information we collect from or about landlords, co-owners, tenants, co-tenants, occupiers, applicants, emergency contacts, contractors, service providers, and other authorised users where relevant to the operation of the Services.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. If there is any inconsistency between this Policy and a requirement of the Privacy Act, the Privacy Act prevails.

2. The kinds of personal information we collect

Depending on how you use the Services, we may collect:

  • identity and contact details, such as names, email addresses, phone numbers, postal addresses, and login credentials;
  • account and profile information, such as role type, property portfolio setup, notification settings, communication preferences, electronic delivery preferences, and related settings;
  • property-related information, such as property addresses, room and area details, inspection schedules, issue logs, and communications;
  • inspection content, such as photos, videos, notes, comments, timestamps, geolocation if enabled, signatures, and generated reports, which may incidentally include personal belongings or other items visible at the property;
  • maintenance information, such as issue descriptions, severity, attachments, task history, and communication records, once RoostCare is released;
  • device and technical information, such as device model, operating system, app version, IP address, event logs, crash diagnostics, push notification tokens, and app messaging identifiers. Device sensors such as compass heading and accelerometer tilt may be used to guide systematic room photography. Sensor data is used in real-time only and is not stored;
  • usage and analytics information, such as feature interactions, session events, navigation patterns, aggregate performance data, and records about whether communications were sent, delivered, opened, or interacted with where supported;
  • billing and transaction information, which may include plan type, invoice records, and billing status, while payment card details are generally handled by our payment processor rather than stored by Roost directly;
  • biometric authentication data: we offer optional biometric authentication (Face ID / fingerprint) to unlock the app. Biometric data is processed entirely on your device by the operating system. We never receive, access, or store your biometric data.
  • co-owner and co-tenant information, such as names, email addresses, and phone numbers provided to us by a primary account holder when identifying the parties to a multi-party property or tenancy in the Services. Where a co-owner or co-tenant is identified in this way, we will send them an invitation to access the Services and will take reasonable steps to make this Policy available to them at or before the time they first access the Services. See Section 3 for more detail on how this information is collected;
  • inspection attribution and audit trail information, such as records of who conducted each inspection (including where a Delegate conducted an inspection on behalf of a landlord or owner), which parties reviewed and signed an Inspection Report, which parties reviewed without completing sign-off, annotations or notes added by parties who did not complete sign-off, and timestamps associated with each action taken on a report. This information is maintained as part of the immutable audit trail for each Inspection Report and is associated with the relevant property record.

We only collect personal information that is reasonably necessary for one or more of our functions or activities as described in this Policy. If you choose not to provide certain information, we may not be able to provide some or all of the Services to you. For example, without a valid email address we cannot create an account; without property address details we cannot support inspection workflows.

3. How we collect personal information

We collect personal information when you create an account, fill in forms, upload content, complete inspections, log maintenance issues, contact support, respond to communications, connect integrations, or otherwise interact with the Services.

When users capture inspection media through Roost, that media may include parts of an occupied property and, in some cases, a tenant's furniture, belongings, or other visible items. Users should only capture what is reasonably necessary for the inspection or record being created and should ensure any required notice, permission, or consent for entry and image capture has been obtained where applicable. Roost will process such content only for the purposes described in this Policy.

We may also collect personal information automatically through the app and website, including through cookies, SDKs, event tracking, server logs, and similar technologies. Some information may be provided to us by another authorised user, such as a landlord inviting a tenant into an inspection flow, or a tenant sharing information relevant to a maintenance request.

Where a property or tenancy involves co-owners or co-tenants, the primary account holder may provide us with personal information about those individuals — including their names and contact details — when setting up the property or tenancy in the Services. We rely on the primary account holder's representation (made in accordance with our Terms of Service) that they are authorised to provide this information and that all relevant parties have been identified. When a co-owner or co-tenant is identified in this way, we will send them an invitation to access the Services and will take reasonable steps to make this Policy available to them at or before the time they first access their records through the Services.

At or before the time of collection, or as soon as reasonably practicable, we take reasonable steps to ensure you are aware of the matters set out in this Policy, including our identity, the purposes for collection, how to access or correct your information, and how to make a complaint.

3A. Unsolicited personal information

We may sometimes receive personal information that we did not solicit — for example, information about a third party included incidentally in an uploaded document, inspection photo, maintenance note, or support communication.

When we receive unsolicited personal information, we will within a reasonable time determine whether we could have collected that information under APP 3 had we solicited it. If we determine that we could not have collected it under APP 3, and we are not required by law to retain it, we will take reasonable steps to destroy or de-identify that information as soon as practicable.

4. Why we collect, hold, use, and disclose personal information

We collect, hold, use, and disclose personal information only for the primary purpose for which it was collected, or for a related secondary purpose that individuals would reasonably expect, or where otherwise permitted by law. We may use personal information to:

  • create and manage accounts and verify user access;
  • deliver RoostInspect workflows, evidence capture, report creation, signing, and record management;
  • deliver RoostCare workflows, issue tracking, communication, automation, reminders, and service coordination once released;
  • operate, secure, troubleshoot, monitor, and improve the Services;
  • send service messages, transactional notifications, reminders, security notices, and support responses;
  • process payments, administer plans, and keep financial records;
  • develop and improve features, including AI-assisted and automated features, using aggregated or de-identified insights where practicable;
  • send relevant content to third-party AI service providers, including OpenAI and other model providers we may use from time to time, where needed to provide AI-assisted features requested or triggered within the Services — see Section 9 for more detail on AI data handling, including our approach to model training;
  • send signing requests, review notifications, and related service communications to co-owners and co-tenants identified in multi-party property or tenancy workflows, and to maintain attribution and audit trail records in connection with their participation or non-participation in the signing process;
  • comply with legal obligations, enforce our terms, resolve disputes, and protect rights, safety, and property.

5. Legal and practical bases for handling information

We handle personal information where it is reasonably necessary for our functions and activities, where users provide information to use the Services, where collection is authorised by another user with an appropriate basis, where consent has been provided for optional features or permissions, or where handling is otherwise required or authorised by law.

6. Direct marketing

We may send you product updates, feature announcements, educational content, or service offers where you would reasonably expect to receive such communications given the nature of your relationship with us, or where you have otherwise consented.

Every marketing communication we send will include a clear, functional mechanism to opt out. If you ask us to stop sending marketing communications, we will action your request within 5 business days and at no cost to you. We will still send non-marketing service notices, operational reminders, legal notices, and other account-related communications where necessary to operate your account, deliver requested workflows, or meet legal obligations.

Our electronic marketing communications comply with the Spam Act 2003 (Cth). Each commercial electronic message we send will clearly identify Roost as the sender, include our contact details, and contain a functional unsubscribe mechanism.

6A. Electronic communications, reminders, and notices

We may use contact details, device tokens, communication preferences, and related metadata to send account messages, reminders, inspection prompts, signing requests, support responses, billing notices, policy updates, and other service-related communications electronically through the App, in-app inbox, push notifications, email, SMS, or similar channels.

Where an owner, landlord, lessor, co-owner, or other authorised user asks Roost to send reminders, notices, statutory forms, signing requests, or other communications to a tenant, co-tenant, occupier, contractor, or other recipient, we may process the relevant contact details, message content, send history, delivery status, and interaction data needed to support that workflow. This may include, where enabled, notice or reminder workflows for entry, inspections, maintenance, acknowledgements, and related record-keeping.

Users are responsible for ensuring they have authority to provide recipient details and to use electronic delivery where required by law or agreement. We may keep records relating to delivery, timestamps, communication settings, and acknowledgements for audit, support, dispute handling, and product integrity purposes. Where a person withdraws consent to electronic communications and the law requires consent, some workflows may need to stop or move outside the platform.

7. Sensitive information

We do not intentionally require sensitive information (as defined in the Privacy Act, including health information, racial or ethnic origin, religious or political beliefs, and similar categories) for normal use of the Services. If sensitive information is included in uploaded documents, notes, media, or support communications, we will handle it in accordance with the Privacy Act and our internal access controls. Users should avoid uploading unnecessary sensitive information. We will not use or disclose sensitive information for purposes other than those for which it was collected without consent or as otherwise permitted by law.

8. Cookies, SDKs, analytics, and similar technologies

We may use cookies, pixels, local storage, mobile SDKs, and similar tools to keep the Services working, remember settings, analyse performance, reduce fraud, and understand product usage. The exact technologies used may change over time as the product evolves.

Where required by law or platform rules, we will request consent for tracking or optional analytics. You can also control some tracking through device settings, browser settings, or our in-app controls where available.

9. AI-assisted features, automated processing, and model training

Roost may use AI-assisted tools, machine learning, image analysis, template logic, summarisation, categorisation, duplicate detection, and other automation to support inspection and maintenance workflows. These features help users work faster but may produce incorrect or incomplete outputs. Users should review outputs before relying on them. We do not use solely automated outputs as a guarantee of legal, tenancy, safety, or repair correctness.

To provide these features, we may disclose prompts, free-text entries, uploaded documents, images, videos, metadata, or other relevant content to third-party AI service providers, including OpenAI and other providers we may use from time to time.

AI provider data use and model training. We do not authorise our AI service providers to use personal information submitted through Roost to train or improve their general AI models. Where we engage AI providers, we seek to do so under terms that restrict providers from using submitted content for model training beyond what is necessary to deliver the specific feature requested. However, provider terms and technical configurations vary, and we recommend users avoid submitting unnecessary personal information when using AI-assisted features.

If at any time we become aware that a provider's terms permit use of submitted data for general model training, we will update this Policy and, where required, seek your consent before continuing to use that provider in a way that would involve your personal information.

Our AI provider mix may change over time as the product evolves. Current providers include OpenAI. We maintain this list in our records and disclose changes through updates to this Policy.

Automated decisions. Where any feature uses automation in a way that could significantly affect your rights or interests — for example, flagging inspection findings, triaging maintenance issues, or generating compliance-related suggestions — that output is intended as an input to a human decision, not a final determination. We will provide further disclosures about specific automated decision-making features as required by law, including any requirements that take effect from December 2026 under amendments to the Privacy Act.

10. Who we may disclose personal information to

We may disclose personal information to:

  • cloud hosting and infrastructure providers, including Google Cloud;
  • analytics, diagnostics, communication, authentication, storage, support providers, and AI service providers such as OpenAI and other model providers we may use from time to time;
  • payment processors and accounting providers;
  • professional advisers, insurers, auditors, and legal advisers;
  • other users within your authorised workflow, such as landlords, co-owners, tenants, co-tenants, owners, occupiers, contractors, or invited participants, including where information is disclosed to send reminders, notices, signing requests, documents, inspection reports, or maintenance-related communications you have requested, and including audit trail and attribution information associated with a jointly signed Inspection Report where it is disclosed to the relevant signing or reviewing parties;
  • government agencies, regulators, courts, tribunals, law enforcement, or other parties where required or authorised by law;
  • a buyer, investor, or successor entity in connection with a merger, acquisition, restructuring, or sale, subject to appropriate safeguards.

We do not sell personal information to third parties for their own marketing or commercial purposes.

11. Overseas disclosure and cross-border processing

We may store or process personal information using service providers in Australia and overseas. Based on our current setup, this may include:

  • Google Cloud Sydney australia-southeast1 as the primary hosting region;
  • Google Cloud Mumbai asia-south1 for backup or resilience workflows;
  • Google Cloud US East us-east1 and/or other US-based services for analytics or service tooling where applicable;
  • OpenAI (United States) and other AI service providers who may process content in the United States or other overseas locations where their infrastructure is located.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the APPs in relation to that information. Those steps may include:

  • entering into data processing agreements or contractual terms that require the overseas recipient to handle personal information consistently with Australian privacy requirements;
  • assessing the recipient's privacy and security standards, certifications, and practices before engagement;
  • applying technical controls such as encryption, access restrictions, and audit logging; and
  • conducting periodic reviews of provider terms and practices.

Where we cannot obtain adequate contractual protections from an overseas recipient, or where you choose to use a feature that involves cross-border disclosure without those protections in place, we will, where required, seek your informed consent to that disclosure and note that the overseas recipient may not be subject to the APPs.

You acknowledge that, despite our reasonable steps, overseas recipients may be subject to the laws of their own jurisdiction, and those laws may not protect personal information in the same way as the Privacy Act.

12. Data security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Security measures may include encryption in transit and at rest, role-based access controls, audit logging, backup controls, monitoring, secure development practices, and incident response processes.

No system is completely secure. You are responsible for maintaining the security of your own devices, passwords, and access settings.

When personal information is no longer needed for the purposes described in this Policy, and we are not required by law or a legitimate operational reason to retain it, we will take reasonable steps to destroy or de-identify it.

If you become aware of a security concern relating to your Roost account or the Services, please contact us immediately using the details in Section 21.

13. Data quality and minimisation

We aim to collect only the information reasonably needed for our services and to keep that information accurate, complete, and up to date. Before using or disclosing personal information for a significant purpose, we take reasonable steps to ensure it is accurate, up to date, complete, and relevant having regard to that purpose. Users should review and update information they provide, especially contact details, property details, inspection records, maintenance records, and the contact details of any co-owners or co-tenants they have identified in the Services.

14. Retention

We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain records, manage disputes, meet legal obligations, prevent fraud, and enforce agreements. Retention periods may vary by record type, account status, dispute risk, and legal requirements.

When personal information is no longer needed and no legal obligation requires its retention, we will take reasonable steps to destroy it securely or de-identify it so that it can no longer be linked to any individual. Backups and archived copies may remain for a limited period after deletion requests or account closure as part of disaster recovery, security, and integrity processes, and will be destroyed or de-identified at the end of that period.

15. Access and correction

You have the right to request access to personal information we hold about you and to ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.

Access requests

To make an access request, contact us using the details in Section 21. We will respond to your request within 30 days of receiving it. We will not charge you for making an access request. In some cases, we may charge a reasonable fee to cover the cost of providing access (for example, where a large volume of records must be retrieved and compiled), but we will notify you of any such fee before proceeding.

We may refuse access in limited circumstances — for example, where providing access would pose a serious threat to life or safety, where the information relates to existing or anticipated legal proceedings, where providing access would unreasonably prejudice the privacy of another individual, or where required or authorised by law. If we refuse access, we will give you written notice of the refusal, the reasons for refusal (to the extent we are permitted to do so), and the mechanisms available to you to complain about the refusal.

Correction requests

To request a correction, contact us using the details in Section 21. We will take reasonable steps to correct the information within 30 days of receiving your request. We will not charge you for making a correction request.

If we correct information that we have previously disclosed to a third party, we will take reasonable steps to notify that third party of the correction unless it is impracticable or unlawful to do so.

If we refuse to correct personal information as you have requested, we will give you written notice setting out our reasons for the refusal (to the extent we are permitted to do so) and the mechanisms available to you to complain about the refusal. If we refuse a correction request, you may ask us to associate a statement with the relevant record noting that you believe it is inaccurate, out of date, incomplete, irrelevant, or misleading. We will take reasonable steps to associate that statement in a way that will make it apparent to users of the information.

Deletion and other requests

You may also request deletion of certain information, subject to legal, contractual, security, or operational limitations. Some requests may need identity verification before we act on them.

16. Anonymity and pseudonymity

In many cases, you cannot use the core Services anonymously or under a pseudonym because account identification and property workflow integrity are central to the service. However, you may contact us with general enquiries without providing full account details. Where it is lawful and practicable to allow anonymity or pseudonymity for a particular interaction, we will offer that option.

16A. Government-related identifiers

We do not adopt, use, or disclose government-related identifiers (such as tax file numbers, Medicare numbers, or driver's licence numbers) as our own identifier of individuals, and we do not require you to provide such identifiers to use the Services. If a government-related identifier is provided incidentally in an uploaded document, it will be handled consistently with the Privacy Act and the APPs.

17. Children

The Services are intended for adults aged 18 years and over. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected personal information from a person under 18, we will take reasonable steps to delete it. If you believe we may have collected information from a minor, please contact us using the details in Section 21.

18. Notifiable Data Breaches

Our obligations under the Notifiable Data Breaches scheme. We are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). Under this scheme, if we reasonably believe there has been an eligible data breach — that is, unauthorised access to, or disclosure of, personal information that is likely to result in serious harm to one or more individuals — we are required to:

  • notify the affected individual or individuals as soon as practicable; and
  • notify the Office of the Australian Information Commissioner (OAIC) within 30 days of becoming aware of the eligible data breach.

How we respond to data security incidents

We maintain an internal incident response process to detect, assess, and respond to data security incidents. If we become aware of a security incident, we will:

  • promptly assess whether the incident constitutes an eligible data breach under the NDB scheme;
  • take immediate steps to contain the breach and limit any harm;
  • if it is an eligible data breach, notify affected individuals and the OAIC in accordance with the Privacy Act;
  • notify affected individuals directly — by email to the address associated with their account, or by another reasonable means — including a description of the breach, the kinds of information involved, and the steps we recommend they take in response; and
  • review and improve our processes to reduce the likelihood of recurrence.

Reporting a suspected breach

If you become aware of or suspect a security or privacy incident involving your personal information or the Roost platform, please contact us immediately at support@my-roost.com with the subject line SECURITY. We will acknowledge your report promptly and investigate in accordance with our incident response process.

OAIC contact

The Office of the Australian Information Commissioner can be contacted at www.oaic.gov.au or by telephone on 1300 363 992 if you have concerns about how we have handled your personal information or a potential data breach.

19. Complaints

If you have a privacy complaint or concern, we encourage you to contact us first using the details in Section 21. Please describe the issue clearly and include enough information for us to investigate and respond. We will acknowledge your complaint within 5 business days and aim to provide a substantive response within 30 days.

If you are not satisfied with our response, or if we fail to respond within a reasonable time, you may lodge a complaint with the Office of the Australian Information Commissioner:

  • Website: www.oaic.gov.au/privacy/privacy-complaints
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

20. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal obligations, or for other operational reasons. The latest version will be published on our website and may also be linked in the App and app store listings where required. The date at the top of this Policy reflects when it was last updated. Material changes may also be notified through the Services or by email where we consider it appropriate to do so.

21. Contact details

Privacy contact: support@my-roost.com
General support: support@my-roost.com
Security and breach reports: support@my-roost.com — subject line: SECURITY
Legal entity: Roost 360 Pty Ltd
ACN: 697 382 979
ABN: 44 697 382 979
Location: New South Wales, Australia
Website: www.my-roost.com.au

APP index. For reference, the following table maps each Australian Privacy Principle to the section of this Policy where it is primarily addressed.

APPSubjectSection(s)
APP 1Open and transparent management of personal information1, 20, this Policy as a whole
APP 2Anonymity and pseudonymity16
APP 3Collection of solicited personal information2, 3
APP 4Dealing with unsolicited personal information3A
APP 5Notification of the collection of personal information2, 3
APP 6Use or disclosure of personal information4, 9
APP 7Direct marketing6
APP 8Cross-border disclosure11
APP 9Adoption, use or disclosure of government related identifiers16A
APP 10Quality of personal information13
APP 11Security of personal information12, 14
APP 12Access to personal information15
APP 13Correction of personal information15
NDB schemeNotifiable Data Breaches18
Roost 360 Pty Ltd | ACN 697 382 979 | ABN 44 697 382 979 | www.my-roost.com.au
RoostRoost

Smarter inspections and better property care for landlords and tenants.

Product

FeaturesPricingRoost Care SoonFAQ

Company

BlogContact us

Legal

Privacy PolicyTerms of ServiceEULADisclaimerCookie PolicyAuthenticity Verification
© 2026 Roost Technologies Pty Ltd. All rights reserved.
support@my-roost.com