Modern apartment building exterior representing Australian body corporate properties
Skip to main content

Privacy Policy

Version: 2.6.1
Last updated: 16 May 2026
Effective date: 6 January 2026

BodyCorporateFees.com ("we", "us", or "our") operates https://bodycorporatefees.com (the "Website"). This Privacy Policy explains how we collect, use, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using our Website, you agree to the collection and use of information in accordance with this policy.

Collection Notice

When you upload a body corporate statement or manually enter your fees to our Website, we collect and process the following information:

What We Collect

  • Document Upload (Optional): Your body corporate statement (PDF or image file) - only if you choose to upload
  • Property Address: The physical address of the property, including unit/lot number, street address, suburb, state, and postcode
  • Fee Data: Body corporate fee amounts, descriptions, and dates (from your statement or manual entry)
  • Email Address: Optional - only if you choose to receive contributor rankings, suburb overview notifications, and discount codes
  • Building Information (Optional): Building type (low-rise, mid-rise, high-rise, or townhouse), building age, number of units, bedrooms, and amenities (pool, gym, etc.) - collected via the optional property questionnaire after you submit your contribution
  • Technical Information: Submission timestamp, browser type, and IP address
  • Analytics Data: Page views, button clicks, and user interactions to improve our service

How We Use It

  • Create Suburb Overviews: To calculate and display median fees, quartiles, and percentile rankings for suburbs
  • Contributor Recognition: To assign founding contributor rankings and badges (if email provided)
  • Notifications: To notify you when suburb overviews become available for your suburb (if email provided)
  • Contributor Benefits: To provide discount codes for premium report purchases (if email provided)
  • Service Improvement: To improve our AI extraction accuracy and user experience

What We Don't Store

We are committed to privacy-first design:

  • If you upload a document: Your uploaded document is immediately deleted after data extraction (typically within 10-30 seconds)
  • We do NOT store owner names, postal addresses (if different from property address), phone numbers, or other personal identifiers
  • We do NOT store original filenames (if uploaded)
  • All data is anonymised for suburb overview calculations

AI Processing

If you choose to upload a document: Your document is processed using Google Gemini AI API to extract fee data and addresses. The document is sent to Google's servers for processing and is deleted from both our servers and Google's servers immediately after extraction (typically within 30 seconds).

If you use manual entry: No document processing occurs - you simply enter the information directly and no AI processing is required.

Important: If you upload, your document is NEVER used to train AI models. Google's enterprise API guarantees zero data retention and does not use customer data for AI training purposes.

Your Consent

By uploading a document or entering fees manually, you consent to this collection and use of your information. Email notifications are entirely optional - you can contribute anonymously without providing an email address.

1. Information We Collect

1.1 Notification Email Addresses

When you provide your email address, we collect it to notify you when suburb overviews become available for your suburb, send you contributor discount codes, or when we have updates about the service.

1.2 Contribution Information (Upload or Manual Entry)

If you choose to upload a document: When you upload a body corporate statement, we collect:

  • Physical Property Address: Full address including unit/lot, street, suburb, state, and postcode
  • Fee Information: Fee amounts, descriptions, and date ranges (extracted via AI)
  • Document Metadata: Upload date/time, document type (statement/invoice/receipt)
  • Email Address (Optional): For contributor rankings, suburb overview notifications, and discount codes
  • Building Information (Optional): Building type, age, number of units, bedrooms, and amenities - via the optional property questionnaire presented after upload

If you use manual entry: When you manually enter your fees, we collect:

  • Physical Property Address: Full address including unit/lot, street, suburb, state, and postcode
  • Fee Information: Fee amounts, descriptions, and date ranges (as entered by you)
  • Entry Metadata: Submission date/time
  • Email Address (Optional): For contributor rankings, suburb overview notifications, and discount codes
  • Building Information (Optional): Building type, age, number of units, bedrooms, and amenities - via the optional property questionnaire presented after submission

1.3 Contributor Discount Codes

When you contribute fees and provide your email address, we generate and store a unique discount code for you. This includes:

  • Discount Code: A unique code (e.g., CONTRIB-ABC123)
  • Email Address: Linked to your discount code
  • Suburb: The suburb your code is valid for
  • Contribution Reference: Link to the contribution that earned the code
  • Usage Status: Whether the code has been used

Discount codes are:

  • Single-use only (one per suburb contribution)
  • Non-transferable and linked to your email address
  • Valid indefinitely unless misused
  • Provide a discount on premium suburb report purchases
  • Sent to you via email when generated

1.4 Failed Extraction Data

If document processing fails, we temporarily store the uploaded file for up to 72 hours to:

  • Improve our AI extraction prompts
  • Retry extraction with improved methods
  • Contact you (if email provided) about the issue

These files are automatically deleted after 72 hours or when successfully processed, whichever comes first.

1.5 Automatically Collected Information

When you visit our Website, we automatically collect analytics data using PostHog to understand how visitors use our service. This data is collected anonymously and is NOT linked to your identity.

  • IP address (anonymised)
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on each page
  • Referring website
  • Button clicks and user interactions (e.g., "FAQ search used", "upload button clicked")
  • Search queries within the site (e.g., suburb names searched)

This information helps us improve our Website, understand how visitors use it, and identify issues or areas for improvement. We do NOT track individual users or create user profiles.

1.6 Browser Storage

We use browser local storage to improve your experience on our Website. Local storage data is stored on your device only and is never transmitted to our servers. We store the following information in your browser's local storage:

  • Checklist Access Flag: A simple true/false value indicating you have provided your email for checklist access. This prevents re-prompting for your email when you visit other checklists.
  • Contributor Email: When you upload a body corporate statement and provide your email address, we store your email in local storage to pre-fill contributor recognition features and streamline future uploads.
  • Suburb Purchase Information: When you purchase a premium suburb report, we store your email address and purchase details (suburb name, state, postcode, purchase timestamp) in local storage to verify your access to purchased reports without requiring login.

Why we store this information locally:

  • To provide seamless access to purchased reports across browser sessions
  • To pre-fill your email address for contributor features
  • To remember your checklist access preferences
  • To avoid requiring account creation and login

Your control: All local storage data can be cleared at any time through your browser settings. See Section 8.4 for detailed instructions on how to manage local storage.

1.7 API Key Holders

We issue API keys to authorised developers, businesses, and AI agents that access our service programmatically. For API key holders, we collect and retain:

  • Key Label: A descriptive name assigned to the key by the administrator (e.g., "MyApp Integration")
  • Usage Metadata: The date and time the key was last used and a count of requests made over rolling periods
  • Key Hash: A cryptographic hash of the key (the plaintext key is never stored)

API keys are issued to organisations or individuals, not anonymous users. Key records are retained for as long as the key is active and for a reasonable period after revocation for audit purposes. No personal documents or sensitive personal information are collected from API key holders - only the usage metadata described above.

2. How We Use Your Information

We use the information we collect to:

  • Create Suburb Overviews: Calculate median fees, quartiles, and suburb statistics
  • Send Notifications: Email you about launch updates, suburb overview availability, and contributor rankings (only if you opted in)
  • Provide Contributor Benefits: Issue discount codes for premium report purchases
  • Improve Service: Enhance AI extraction accuracy and user experience
  • Prevent Duplicates: Use fingerprinting to detect duplicate submissions
  • Respond to Inquiries: Answer your questions and support requests
  • Comply with Legal Obligations: Meet our legal and regulatory requirements

We will never sell, rent, or share your personal information with third parties for their marketing purposes.

3. Third-Party Services

3.1 Email Service Provider

We use Mailcoach to manage email subscriptions and send notifications. Your email address is shared with Mailcoach for this purpose. Mailcoach complies with privacy regulations and does not use your data for any other purpose.

3.2 AI Processing

If you upload a document: We use Google Gemini API to extract data from uploaded documents. Your document is temporarily sent to Google's servers for processing and is immediately deleted after extraction. Google does not use your documents to train AI models.

If you use manual entry: No document processing or AI extraction occurs. Your manually entered data is saved directly without any third-party processing.

3.3 AI Processing vs AI Training

We understand many users have concerns about their documents being used to train AI models. Here's our clear commitment:

  • Your documents are NEVER used for AI training: We use Google Gemini's enterprise API which guarantees zero data retention. Your documents are processed in real-time and immediately deleted from both our servers and Google's servers.
  • AI Processing (what we do): Your document is temporarily analysed to extract structured data (fee amounts, dates, property address). This processing happens once and the document is deleted within 30 seconds.
  • AI Training (what we DON'T do): We do not store, retain, or use your documents to train any AI models. Google's enterprise API does not use customer data for model training.
  • Service Improvement: We may analyse patterns in the structured data you've already consented to share (like common fee categories or address formats) to improve extraction accuracy for future users. This uses aggregate patterns from the extracted data only - never your original documents.

Google Gemini Enterprise API Data Policy: Google's enterprise API customers (like us) benefit from contractual guarantees that uploaded content is not used to train or improve Google's AI models. Your documents are processed ephemerally and not retained by Google.

3.4 Analytics

We use PostHog to collect and analyse usage data about how visitors interact with our Website. PostHog helps us understand user behavior, identify bugs, and improve our service.

Anonymous tracking only: We track events anonymously without identifying individual users. We do NOT:

  • Use PostHog's identify() function to link events to individual users
  • Track email addresses, names, or other personal identifiers in analytics events
  • Enable session recording or screen capture
  • Enable automatic data capture that might collect form inputs or sensitive data

Data collected: Page views, button clicks, user interactions (e.g., "upload button clicked"), device information, anonymised IP addresses, and non-personal context (e.g., suburb names for search queries).

Data retention: PostHog retains analytics data for up to 7 years for historical analysis and trend monitoring.

Your control: PostHog respects Do Not Track (DNT) browser settings. You can also opt out of analytics tracking by disabling cookies in your browser settings (see Section 8.3 below).

3.5 Server and Database Hosting

Our application server and database are hosted by Hetzner in Helsinki, Finland. Your data is encrypted in transit and at rest.

4. Cross-Border Disclosure

Your personal information may be disclosed to overseas recipients in the following countries:

  • Finland: Application server and database hosting (Hetzner, Helsinki)
  • United States: AI processing only (Google Gemini API) - Documents processed in real-time with zero retention. Google does not use your data for AI training under enterprise API terms. Analytics data (PostHog) - Usage data and anonymised visitor information.
  • Email Service: Mailcoach (server location varies by plan)

We take reasonable steps to ensure these providers handle your information in accordance with Australian privacy laws and have appropriate security measures in place.

5. Data Storage and Security

5.1 Security Measures

We implement comprehensive security measures to protect your personal information:

  • Immediate Deletion: Uploaded documents are deleted immediately after processing (typically 10-30 seconds)
  • Secure Transmission: All data transmitted via HTTPS/SSL encryption
  • Encryption: Data encrypted at rest
  • Access Controls: Restricted database access with authentication
  • Failed Extraction Retention: Files automatically deleted after 72 hours
  • No Sensitive PII Storage: We do not store owner names, phone numbers, or personal postal addresses
  • Duplicate Prevention: Cryptographic fingerprinting prevents duplicate submissions
  • Environment Security: API keys and secrets stored in secure environment variables

5.2 Data Retention

However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

6. How Long We Keep Your Information

6.1 Contribution Data

We retain property addresses and fee data indefinitely to maintain suburb overview accuracy and historical trends. This data is anonymised and cannot be traced back to individuals.

6.2 Failed Extractions

Failed extraction files are automatically deleted after 72 hours or when successfully processed, whichever comes first.

6.3 Email Subscription Data

We keep your email address and subscription preferences until you unsubscribe or request deletion.

6.4 Discount Codes

Discount codes are retained indefinitely to prevent reuse and maintain purchase history. However, the email address linked to a discount code can be deleted upon request (see Section 7.3).

7. Your Rights

Under the Australian Privacy Act, you have the right to:

  • Access your personal information we hold
  • Correct inaccurate or incomplete information
  • Delete your information (subject to legal obligations and anonymised suburb overview data)
  • Opt-out of marketing communications at any time
  • Complain to us or the Office of the Australian Information Commissioner (OAIC)

7.1 Data Access Requests

To request access to your personal information:

  1. Email [email protected] with subject "Data Access Request"
  2. Provide your email address and/or property address to help us locate your data
  3. We will respond within 30 days with your data in a portable format (JSON or CSV)

There is no fee for access requests unless the request is manifestly unfounded, excessive, or repetitive.

7.2 Correction Requests

To request correction of your personal information:

  1. Email [email protected] with subject "Data Correction Request"
  2. Specify what information is incorrect and provide the correct information
  3. We will review and respond within 30 days

If we correct your information, we will notify any third parties to whom we disclosed the incorrect information (unless it's impracticable or unlawful to do so).

7.3 Deletion Requests

To request deletion of your personal information:

  1. Email [email protected] with subject "Data Deletion Request"
  2. Provide your email address and/or property address
  3. We will delete your email subscription and personal identifiers within 30 days

Note: Anonymised contribution data (property address and fees) may be retained for suburb overviews, as it cannot be traced back to you and is necessary for our service.

7.4 Unsubscribe from Emails

Every email we send includes an unsubscribe link at the bottom. Clicking this link will immediately remove you from our mailing list. You can also email [email protected] with subject "Unsubscribe" and we will remove you manually within 2 business days.

8. Cookies

We use cookies on our Website to ensure secure operation and to understand how visitors use our service. Cookies are small text files stored on your device by your web browser.

8.1 Strictly Necessary Cookies

We use one essential cookie for security purposes:

  • CSRF Token Cookie: A session cookie that protects against Cross-Site Request Forgery (CSRF) attacks. This cookie ensures that form submissions and data uploads come from legitimate users of our Website, not malicious third-party sites.

This cookie is classified as "strictly necessary" because it is required for the Website to function securely. Without this cookie, we cannot safely process your uploads or form submissions.

Cookie Details:

  • Purpose: Security (CSRF protection)
  • Type: Session cookie (deleted when you close your browser)
  • Data stored: Random token for request validation
  • Third-party access: None - cookie is only used by our server

8.2 Analytics Cookies

We use PostHog analytics cookies to understand how visitors interact with our Website. These cookies help us:

  • Track which pages are most popular
  • Identify bugs and technical issues
  • Understand user journey and behavior patterns
  • Measure the effectiveness of features and improvements
  • Improve overall user experience

Cookie Details:

  • Purpose: Anonymous analytics and performance monitoring
  • Provider: PostHog (third-party analytics service)
  • Type: Persistent cookies (stored for up to 1 year)
  • Data stored: Random anonymous visitor ID, session information, page view data
  • Third-party access: PostHog (US-based analytics provider)
  • Privacy note: We do NOT use PostHog to identify individual users or link analytics data to your email, name, or other personal identifiers

8.3 Managing Cookies

Strictly Necessary Cookies: Because the CSRF cookie is strictly necessary for security, you cannot opt out of it while using our Website. If you disable all cookies in your browser settings, you will not be able to upload documents or submit forms.

Analytics Cookies: You can opt out of analytics tracking by:

  • Enabling "Do Not Track" (DNT) in your browser settings
  • Blocking third-party cookies in your browser settings
  • Using browser extensions that block analytics trackers
  • Disabling cookies for bodycorporatefees.com specifically

Opting out of analytics cookies will not affect your ability to use the Website, but will prevent us from understanding how you use our service.

How to manage cookies in your browser:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions

We do not use cookies for:

  • Advertising or marketing purposes
  • Selling your data to third parties
  • Cross-site tracking beyond our Website
  • Storing sensitive personal information

8.4 Browser Local Storage

In addition to cookies, we use browser local storage (localStorage) to improve your experience on our Website. Local storage is a browser feature that allows websites to store small amounts of data on your device.

What we store in local storage:

  1. Checklist Access Flag (key: checklist_access)
    • Purpose: Remember that you've provided your email for checklist access
    • Data stored: A single true/false value
    • Contains personal information: No
    • When stored: When you provide your email to access any free checklist
  2. Contributor Email (key: contributorEmail)
    • Purpose: Pre-fill your email for contributor recognition features
    • Data stored: Your email address
    • Contains personal information: Yes (email address)
    • When stored: When you upload a body corporate statement and provide your email
  3. Suburb Purchase Email (key: suburb_purchase_email)
    • Purpose: Verify access to purchased suburb reports
    • Data stored: Your email address
    • Contains personal information: Yes (email address)
    • When stored: When you purchase a premium suburb report
  4. Suburb Purchases (key: suburb_purchases)
    • Purpose: Track which suburb reports you've purchased for access verification
    • Data stored: JSON object containing email address, suburb name, state, postcode, and purchase timestamp for each purchase
    • Contains personal information: Yes (email address and purchase history)
    • When stored: When you purchase a premium suburb report

Why we use local storage:

  • To provide seamless access to purchased reports without requiring account creation or login
  • To remember your checklist access preferences across visits
  • To pre-fill your email address for contributor features and streamline future uploads
  • To verify purchase access entirely client-side, enhancing privacy and performance

How it works:

  • Local storage data stays on your device only - it is never transmitted to our servers
  • The data persists between browser sessions (unlike session cookies which are deleted when you close your browser)
  • The data is specific to bodycorporatefees.com and cannot be accessed by other websites
  • Local storage is stored per browser - clearing it will not affect data in other browsers or devices

Managing local storage:

You can clear local storage data at any time through your browser settings. This will:

  • Remove your checklist access flag (you'll be prompted for email again)
  • Remove saved email addresses (you'll need to re-enter them)
  • Remove purchase verification data (you may need to verify purchases again via email)

Important: Clearing local storage will NOT:

  • Affect your email subscription status (you'll still receive emails if subscribed)
  • Cancel your purchased suburb reports (your purchases are linked to your email)
  • Delete your data from our servers (contribution data remains in our database)

How to clear local storage:

  • Chrome: Settings → Privacy and security → Cookies and other site data → See all site data and permissions → Search for "bodycorporatefees.com" → Clear data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data → Search for "bodycorporatefees.com" → Remove Selected
  • Safari: Preferences → Privacy → Manage Website Data → Search for "bodycorporatefees.com" → Remove
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions → See all cookies and site data → Search for "bodycorporatefees.com" → Remove

9. Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before providing any information.

10. Children's Privacy

Our Website is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" and "Version" dates at the top
  • Sending an email to registered users for significant changes

Previous versions of this policy are available upon request by emailing [email protected].

Version History

  • Version 2.6.1 (16 May 2026) - Reduced failed extraction retention period: Updated Section 1.4, Section 5.1, and Section 6.2 to reduce the maximum retention of temporarily stored failed-extraction documents from 30 days to 72 hours. This is a privacy-protective change that aligns the disclosed retention period with our practice of never storing documents longer than strictly necessary.
  • Version 2.6.0 (21 February 2026) - Added building information and API key disclosure: Updated Collection Notice and Section 1.2 to disclose building information collected via the optional property questionnaire (building type, age, total units, bedrooms, amenities). Added new Section 1.7 disclosing data collected from API key holders (label, usage metadata, key hash). Added API access terms to Terms of Service.
  • Version 2.5.1 (6 January 2026) - Enhanced browser local storage disclosure: Updated Section 1.6 to accurately disclose all localStorage usage including contributor emails and suburb purchase information (previously incorrectly stated no personal information was stored in localStorage). Expanded Section 8.4 to provide comprehensive details about all four localStorage keys (checklist_access, contributorEmail, suburb_purchase_email, suburb_purchases), clearly identifying which items contain personal information and their specific purposes. Added detailed management instructions for clearing local storage.
  • Version 2.5.0 (5 January 2026) - Added contributor discount code disclosure: Added new Section 1.3 describing discount code collection and usage, updated Section 2 to include "Provide Contributor Benefits", updated terminology from "benchmarks" to "suburb overviews" throughout user-facing text, removed Section 6.1 (Waitlist Emails) as no longer applicable, renumbered subsequent sections, added Section 6.4 for discount code retention, updated email notification descriptions to include discount codes
  • Version 2.4.0 (1 December 2025) - Added browser local storage disclosure: Added new Section 1.5 describing browser local storage usage for checklist access, added comprehensive Section 8.4 explaining what local storage data we collect, why we use it, and how users can manage it. Local storage is used to remember checklist access across different free tools without storing personal information.
  • Version 2.3.0 (19 November 2025) - Added PostHog analytics disclosure: Updated Collection Notice to include analytics data, added Section 3.4 for PostHog third-party service, updated Section 1.4 to clarify analytics collection, completely rewrote Section 8.2 to disclose analytics cookies and provide opt-out instructions, and updated cross-border disclosure to include PostHog (United States)
  • Version 2.2.1 (15 November 2025) - Updated terminology: Changed "Waitlist Email Addresses" to "Notification Email Addresses" and updated description to reflect live service status (suburb overview availability notifications rather than launch notifications)
  • Version 2.2.0 (1 November 2025) - Enhanced cookie disclosure: Completely rewrote Section 8 to clearly explain CSRF cookie usage, classify it as "strictly necessary" for security, and clarify that we don't use cookies for tracking, analytics, or advertising
  • Version 2.1.0 (1 November 2025) - Enhanced AI training transparency: Added Section 3.3 clarifying AI processing vs training, updated Collection Notice with explicit "never used for AI training" commitment, and enhanced Google Gemini disclosure with enterprise API data policy details
  • Version 2.0.1 (25 October 2025) - Corrected hosting disclosure: Application server and database are both hosted by Hetzner in Helsinki, Finland (not Neon.tech in United States)
  • Version 2.0 (25 October 2025) - Added comprehensive collection notice, third-party services disclosure, security measures, data access/correction procedures, and cross-border disclosure information
  • Version 1.0 (19 October 2025) - Initial privacy policy

12. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or have a privacy concern, please contact us:

Email: [email protected]
Privacy Officer: BodyCorporateFees.com
Response Time: Within 30 days

Complaints

If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us at [email protected]. We will:

  1. Acknowledge your complaint within 7 days
  2. Investigate and respond within 30 days
  3. Work with you to resolve the issue

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):