This is a draft, not a finished legal document.
It has not been reviewed by a lawyer and must not be treated as legal sign-off, including on compliance with the Privacy Act 1988 (Cth) or the Australian Privacy Principles (APPs). A qualified Australian lawyer should review and approve a final version before Keyfolio launches to real users or processes real personal information at scale. Every specific representation below (data residency, entity details, retention periods, complaints timeframes) is written to reflect this codebase's actual current behaviour as of the date below, not aspirational policy -- if the product changes, this document needs to change with it.
Privacy Policy
Draft -- last updated 26 July 2026.
1. Who this policy covers
Keyfolio is a service operated by MYM Group (ABN 52 203 327 554) ("Keyfolio", "we", "us"). Keyfolio currently operates in Victoria, Australia only -- listings, agent service areas, and the accounts using the platform are all expected to be Victoria-based, and this policy is written on that basis. This policy explains how we collect, hold, use, and disclose personal information through the Keyfolio platform, and how it applies each of the 13 Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. The 13 Australian Privacy Principles, applied to Keyfolio
This section exists so every APP is addressed somewhere in this document, even briefly -- the sections referenced go into more operational detail.
- APP 1 -- Open and transparent management. This policy is publicly available at /privacy without requiring an account. Complaints and access requests are handled per sections 9 and 10.
- APP 2 -- Anonymity and pseudonymity. Browsing the marketing site and reading public agent profiles (/agents/[id]) requires no account. Actually listing a property, submitting a proposal, or messaging requires an identified account -- the service can't function as a two-sided marketplace with anonymous participants on either side.
- APP 3 -- Collection of solicited information. See section 3 for exactly what's collected and why.
- APP 4 -- Unsolicited information. If we receive personal information we didn't solicit (e.g. sent to our support inbox by mistake) and it's not something we'd have been entitled to collect under APP 3, we delete or de-identify it where lawful and reasonable to do so.
- APP 5 -- Notification of collection. This policy is that notification, linked from the sign-up page at the point information is first collected.
- APP 6 -- Use or disclosure. See section 4 -- this is the section that matters most for Keyfolio, since the product's entire design is built around exactly when contact and document details unlock.
- APP 7 -- Direct marketing. Keyfolio does not currently send marketing/promotional email at all -- every automated email the product sends is a transactional notice about something that happened to your own account or listing (new proposal, acceptance, due-diligence deadline, verification outcome, an invitation to quote). If that changes, this section will be updated to describe the applicable opt-out.
- APP 8 -- Cross-border disclosure. See section 6.
- APP 9 -- Government related identifiers. Keyfolio does not use Medicare numbers, driver's licence numbers, or other government identifiers as an account identifier. Ownership-verification documents may contain government-issued ID (see section 3) but that ID number is never used to identify your Keyfolio account -- your account is identified by your email address.
- APP 10 -- Quality of information. You can view and correct most of your own account, listing, and profile information directly in the product. See section 10 for anything not editable in-product.
- APP 11 -- Security. See section 7.
- APP 12 -- Access. See section 10.
- APP 13 -- Correction. See section 10.
3. What we collect
- Account details: name, email address, password (stored hashed, never in plain text), and account role (homeowner, agent, or admin).
- For agents: a real estate agent license number (see the Terms of Service -- not yet verified against any regulator register); the postcodes, state, and property categories the agent chooses to service; and profile details an agent chooses to add themselves -- a photo, bio, phone number, business location, and company/agency name, all of which are shown publicly on that agent's profile page.
- For homeowners: listing details you submit, including the property's full address, features, known defects, and any contact phone number you choose to provide.
- Ownership verification documents. Before a listing can go live, a homeowner uploads a Section 32 (Vendor's Statement) and a title search to prove they own the property being listed. This is the most sensitive category of personal information Keyfolio collects. These documents are stored in a dedicated, private storage bucket. Only the uploading homeowner, Keyfolio administrators, and -- once the homeowner accepts that agent's proposal -- the accepted agent can access them. There is no code path that grants any other agent, or any other homeowner, access to another user's ownership documents.
- Proposal and message content submitted through the platform.
- Reviews: once a listing is marked completed, the homeowner may leave a star rating and written review of the agent they worked with. Unlike everything else in this list, reviews are public by design-- they're displayed on the agent's public profile page to anyone, without requiring a Keyfolio account, the same way a review would appear on any public business listing.
- Payment-related metadata for agents (subscription status, plan tier, and a Stripe reference ID) -- not full card numbers, which Keyfolio never receives or stores (see section 5).
- For agents: a timestamped confirmation, given at sign-up, that the agent has considered their own AML/CTF obligations as a real estate professional. This is a factual record of when that confirmation was made -- not itself a determination by Keyfolio of what an agent's obligations are.
4. How we use it, and who we disclose it to (APP 6)
This describes the platform's actual access rules, not a generic statement:
- A listing's full street address, postcode, and uploaded property photos are disclosed to any licensed agent browsing Keyfolio once the listing is live and ownership-verified -- there is no acceptance gate on the address or photos themselves. The homeowner's ownership documents (Section 32, title search) and any other supporting documents remain withheld until that specific agent's proposal is accepted.
- A homeowner's contact phone number (if provided) and their uploaded ownership documents are disclosed only to the specific agent whose proposal the homeowner accepts. That agent's phone number is disclosed to the homeowner at the same time. Every other agent with a proposal on that listing is automatically declined and notified that they were not selected -- they are never shown the phone number or documents, or told which agent was chosen.
- A homeowner may also choose to invite a specific agent to quote on their listing. The invited agent is told a vendor has highlighted their profile -- they are never told whether other agents have also been invited or have already submitted a proposal.
- Proposal and message content is disclosed only between the homeowner who owns a listing and the specific agent involved in that proposal or conversation -- never to other agents.
- Ownership verification documents are disclosed only to Keyfolio administrators, for the sole purpose of confirming the uploading homeowner actually owns the property. They are never disclosed to any agent or other homeowner.
- Reviews and the agent-facing parts of a profile (name, photo, company, rating) are disclosed publicly, by design -- see section 3.
- Keyfolio staff with administrator access can view listing, proposal, and account information for support, moderation, and fraud-prevention purposes. Actions administrators take that affect an account (suspension, verification decisions, password resets) are logged in an internal, immutable audit record.
- Payment information is disclosed to Stripe, Inc. to process subscription payments (see section 5). Stripe acts as an independent third party processing this information under its own privacy policy, not as a mere data processor acting only on our instructions in every respect.
5. Stripe and payment data
Agent subscription payments are handled entirely by Stripe. Card numbers and other full payment details are entered directly into Stripe's own checkout interface and are never transmitted to or stored by Keyfolio. Keyfolio retains only a subscription status, plan tier, and Stripe-issued reference identifiers, used to enforce which features an agent's account can access.
6. Overseas disclosure (APP 8)
Keyfolio's infrastructure providers may store or process personal information outside Australia. As of this draft:
- Database and file storage (Supabase): [Region not yet confirmed -- check Supabase Dashboard → Settings → General → Region, and insert the confirmed region and country here before relying on this document.]
- Application hosting (Vercel): Keyfolio is not yet deployed to production hosting. Vercel functions default to a United States region (Washington, D.C.) unless a specific region is configured at deployment -- if launched on Vercel, the region should be explicitly set (Vercel supports a Sydney, Australia region) and this section updated to reflect the actual choice made.
- Payments (Stripe):Stripe processes data across a multi-region infrastructure that includes the United States and Ireland at minimum, and Stripe's own documentation states that payment data may be transferred to the jurisdiction of whichever payment method is used. For Australian merchants, Stripe Payments Australia Pty Ltd is the entity responsible for regulated payment services, though broader data processing occurs through Stripe's global infrastructure.
- Email (Resend): transactional email delivery -- region not yet confirmed for this draft.
Where personal information is handled overseas, APP 8 generally requires Keyfolio to take reasonable steps to ensure the overseas recipient doesn't breach the APPs, or to rely on an available exception. Which applies here depends on the confirmed regions above and each provider's own compliance posture -- this needs a lawyer's assessment once the regions are confirmed, not a generic statement that it's been handled.
7. Data security (APP 11)
Access to personal information is restricted using role-based database rules (Postgres row-level security), so that, for example, an agent account cannot retrieve a homeowner's address, ownership documents, or another agent's proposal by any means other than the specific disclosure rules described in section 4 -- this is enforced at the database layer, not only in the application's user interface. Passwords are never stored in readable form. Administrator actions that affect a user's account (such as suspending it or triggering a password reset) are logged internally in an immutable audit table.
Keyfolio maintains an internal data breach response process covering how a suspected breach is investigated, who is notified, and how affected individuals and the OAIC are contacted where required under the Notifiable Data Breaches scheme. That process currently has a known gap: while administrator actions are fully logged, Keyfolio does not yet have comprehensive logging of ordinary data access (for example, exactly when a given agent viewed a given listing, or an accepted agent's unlocked ownership documents). This is a genuine, named limitation rather than an oversight we're glossing over -- it's tracked internally and should be closed before Keyfolio handles data at meaningful scale.
8. How long we keep information
Keyfolio does not currently have a formal, automated data retention/deletion schedule -- account and listing data generally persists until the account is deleted or removed. [A concrete retention schedule -- e.g. how long ownership documents are kept after a listing closes, how long declined-agent proposal data is kept -- should be defined and inserted here before launch.]
9. Cookies
Keyfolio currently uses only the essential cookies required to keep you signed in. We do not currently use analytics or advertising cookies or trackers.
10. Access, correction, and complaints (APP 12, APP 13)
You can view and update most of your own account and profile information directly within Keyfolio. To request a copy of your personal information, a correction we haven't made available in-product, deletion of your account, or to raise a complaint about how your personal information has been handled, contact us at support@keyfolio.com.au.
Our intended complaints process (to be confirmed as part of legal review): we acknowledge a complaint promptly, and aim to provide a substantive response within 30 days, consistent with OAIC's published guidance for privacy complaint handling. If you're not satisfied with our response, or we haven't responded within a reasonable time, you may complain directly to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.