Roost Privacy Policy
Who we are. This Privacy Policy explains how Roost 360 Pty Ltd. ("Roost", "we", "our", "us") handles personal information in connection with the Roost services.
Quick summary. We collect information needed to provide Roost Inspect and related services, use limited analytics and operational data to run and improve the platform, disclose information to service providers that help us host, secure, support, and operate the services, and may process communication details so reminders, notices, and other records can be sent through the platform where enabled.
1. Scope
This Policy covers personal information we collect through the Roost website, mobile app, support channels, Roost Inspect workflows, and Roost Care workflows once released. It also covers information we collect from or about landlords, tenants, occupiers, applicants, emergency contacts, contractors, service providers, and other authorised users where relevant to the operation of the Services.
2. The kinds of personal information we collect
Depending on how you use the Services, we may collect:
- identity and contact details, such as names, email addresses, phone numbers, postal addresses, and login credentials;
- account and profile information, such as role type, property portfolio setup, notification settings, communication preferences, electronic delivery preferences, and related settings;
- property-related information, such as property addresses, room and area details, inspection schedules, issue logs, and communications;
- inspection content, such as photos, videos, notes, comments, timestamps, geolocation if enabled, signatures, and generated reports, which may incidentally include personal belongings or other items visible at the property;
- maintenance information, such as issue descriptions, severity, attachments, task history, and communication records, once Roost Care is released;
- device and technical information, such as device model, operating system, app version, IP address, event logs, crash diagnostics, push notification tokens, and app messaging identifiers. Device sensors such as compass heading, accelerometer tilt guiding you through systematic room photography. Sensor data is used in real-time only and is not stored;
- usage and analytics information, such as feature interactions, session events, navigation patterns, aggregate performance data, and records about whether communications were sent, delivered, opened, or interacted with where supported;
- billing and transaction information, which may include plan type, invoice records, and billing status, while payment card details are generally handled by our payment processor rather than stored by Roost directly;
- we offer optional biometric authentication (Face ID / fingerprint) to unlock the app. Biometric data is processed entirely on your device by the operating system. We never receive, access, or store your biometric data.
3. How we collect personal information
We collect personal information when you create an account, fill in forms, upload content, complete inspections, log maintenance issues, contact support, respond to communications, connect integrations, or otherwise interact with the Services.
When users capture inspection media through Roost, that media may include parts of an occupied property and, in some cases, a tenant's furniture, belongings, or other visible items. Users should only capture what is reasonably necessary for the inspection or record being created and should ensure any required notice, permission, or consent for entry and image capture has been obtained where applicable.
We may also collect personal information automatically through the app and website, including through cookies, SDKs, event tracking, server logs, and similar technologies. Some information may be provided to us by another authorised user, such as a landlord inviting a tenant into an inspection flow, or a tenant sharing information relevant to a maintenance request.
4. Why we collect, hold, use, and disclose personal information
We may use personal information to:
- create and manage accounts and verify user access;
- deliver Roost Inspect workflows, evidence capture, report creation, signing, and record management;
- deliver Roost Care workflows, issue tracking, communication, automation, reminders, and service coordination once released;
- operate, secure, troubleshoot, monitor, and improve the Services;
- send service messages, transactional notifications, reminders, security notices, and support responses;
- process payments, administer plans, and keep financial records;
- develop and improve features, including AI-assisted and automated features;
- send relevant content to third-party AI service providers, including OpenAI and other model providers we may use from time to time, where needed to provide AI-assisted features requested or triggered within the Services;
- comply with legal obligations, enforce our terms, resolve disputes, and protect rights, safety, and property.
5. Legal and practical bases for handling information
For Australian launch purposes, we handle personal information where it is reasonably necessary for our functions and activities, where users provide information to use the Services, where collection is authorised by another user with an appropriate basis, where consent has been provided for optional features or permissions, or where handling is otherwise required or authorised by law.
6. Direct marketing
We may send you product updates, feature announcements, educational content, or service offers where permitted by law. You can opt out of marketing communications using the unsubscribe function or by contacting us. We will still send non-marketing service notices, operational reminders, legal notices, and other account-related electronic communications where necessary to operate your account, deliver requested workflows, or meet legal obligations.
6A. Electronic communications, reminders, and notices
We may use contact details, device tokens, communication preferences, and related metadata to send account messages, reminders, inspection prompts, signing requests, support responses, billing notices, policy updates, and other service-related communications electronically through the App, in-app inbox, push notifications, email, SMS, or similar channels.
Where an owner, landlord, lessor, or other authorised user asks Roost to send reminders, notices, statutory forms, or other communications to a tenant, occupier, contractor, or other recipient, we may process the relevant contact details, message content, send history, delivery status, and interaction data needed to support that workflow. This may include, where enabled, notice or reminder workflows for entry, inspections, maintenance, acknowledgements, and related record-keeping.
Users are responsible for ensuring they have authority to provide recipient details and to use electronic delivery where required by law or agreement. We may keep records relating to delivery, timestamps, communication settings, and acknowledgements for audit, support, dispute handling, and product integrity purposes. Where a person withdraws consent to electronic communications and the law requires consent, some workflows may need to stop or move outside the platform.
7. Sensitive information
We do not intentionally require sensitive information for normal use of the Services. If sensitive information is included in uploaded documents, notes, media, or support communications, we will handle it in accordance with applicable law and our internal access controls. Users should avoid uploading unnecessary sensitive information.
8. Cookies, SDKs, analytics, and similar technologies
We may use cookies, pixels, local storage, mobile SDKs, and similar tools to keep the Services working, remember settings, analyse performance, reduce fraud, and understand product usage. The exact technologies used may change over time as the product evolves.
Where required by law or platform rules, we will request consent for tracking or optional analytics. You can also control some tracking through device settings, browser settings, or our in-app controls where available.
9. AI-assisted features and automated processing
Roost may use AI-assisted tools, machine learning, image analysis, template logic, summarisation, categorisation, duplicate detection, and other automation to support inspection and maintenance workflows. These features help users work faster but may produce incorrect or incomplete outputs.
To provide these features, we may disclose prompts, free-text entries, uploaded documents, images, videos, metadata, or other relevant content to third-party AI service providers, including OpenAI and other providers we may choose over time. Those providers may process that content in Australia or overseas depending on the service configuration and provider used.
Users should review outputs before relying on them. We do not use solely automated outputs as a promise of legal, tenancy, safety, or repair correctness. Where a feature uses a third-party AI provider, the provider may process the information needed to generate the output, and our provider mix may change over time as the product evolves.
10. Who we may disclose personal information to
We may disclose personal information to:
- cloud hosting and infrastructure providers, including Google Cloud;
- analytics, diagnostics, communication, authentication, storage, support providers, and AI service providers such as OpenAI and other model providers we may use from time to time;
- payment processors and accounting providers;
- professional advisers, insurers, auditors, and legal advisers;
- other users within your authorised workflow, such as landlords, tenants, owners, occupiers, contractors, or invited participants, including where information is disclosed to send reminders, notices, documents, inspection reports, or maintenance-related communications you have requested;
- government agencies, regulators, courts, tribunals, law enforcement, or other parties where required or authorised by law;
- a buyer, investor, or successor entity in connection with a merger, acquisition, restructuring, or sale, subject to appropriate safeguards.
11. Overseas disclosure and cross-border processing
We may store or process personal information using service providers in Australia and overseas. Based on our current launch setup, this may include:
- Google Cloud Sydney
australia-southeast1as the primary hosting region; - Google Cloud Mumbai
asia-south1for backup or resilience workflows; - Google Cloud US East
us-east1and/or other US-based services for analytics or service tooling where applicable.
Where we disclose personal information overseas, including to cloud, analytics, or AI service providers, we take reasonable steps to ensure recipients handle it consistently with applicable privacy requirements, including through contractual controls, vendor due diligence, access controls, and security standards. However, overseas recipients may be subject to foreign laws.
12. Data security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Security measures may include encryption in transit and at rest where appropriate, role-based access controls, audit logging, backup controls, monitoring, secure development practices, and incident response processes.
No system is completely secure. You are responsible for maintaining the security of your own devices, passwords, and access settings.
13. Data quality and minimisation
We aim to collect only the information reasonably needed for our services and to keep that information accurate, complete, and up to date. Users should review and update information they provide, especially contact details, property details, inspection records, and maintenance records.
14. Retention
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain records, manage disputes, meet legal obligations, prevent fraud, and enforce agreements. Retention periods may vary by record type, account status, dispute risk, and legal requirements.
Backups and archived copies may remain for a limited period after deletion requests or account closure as part of disaster recovery, security, and integrity processes.
15. Access, correction, deletion, and other requests
You may request access to personal information we hold about you and ask us to correct inaccurate information. You may also request deletion of certain information, subject to legal, contractual, security, or operational limitations. Some requests may need identity verification before we act on them.
16. Anonymity and pseudonymity
In many cases, you cannot use the core Services anonymously or under a pseudonym because account identification and property workflow integrity are central to the service. However, you may contact us with general enquiries without providing full account details.
17. Children
The Services are not directed to children, and accounts are intended for adults. If we learn we have collected information in a manner inconsistent with this Policy or applicable law, we will take appropriate steps to address it.
18. Complaints
If you have a privacy complaint, contact us first using the details below. Please describe the issue and include enough information for us to investigate. We will respond within a reasonable time. If you are not satisfied, you may be able to complain to the Office of the Australian Information Commissioner.
19. Changes to this Policy
We may update this Policy from time to time. The latest version will be published on our website and may also be linked in the App and app store listings where required. Material changes may also be notified through the Services or by email.
20. Contact details
Privacy contact: support@my-roost.com
Support: support@my-roost.com
Legal entity: Roost 360 Pty Ltd.
ACN: 697 382 979
ABN: 44 697 382 979
Office address: Headquartered in New South Wales, Australia
Website: www.my-roost.com.au