Modern apartment building exterior representing Australian body corporate properties
Skip to main content

Privacy Policy

Version: 3.1.0
Last updated: 2 August 2026
Effective date: 6 January 2026

BodyCorporateFees.com ("we", "us", or "our") operates https://bodycorporatefees.com (the "Website"). This Privacy Policy explains how we collect, use, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using our Website, you agree to the collection and use of information in accordance with this policy.

Collection Notice

When you contribute your body corporate fees to our Website, we collect and process the following information:

What We Collect

  • Property Address: The physical address of the property, including unit/lot number, street address, suburb, state, and postcode
  • Fee Data: Body corporate fee amounts, descriptions, and the period they cover, as entered by you
  • Email Address: Optional - only if you choose to receive contributor rankings, suburb overview notifications, and discount codes
  • Building Information (Optional): Building type (low-rise, mid-rise, high-rise, or townhouse), building age, number of units, bedrooms, and amenities (pool, gym, etc.) - collected via the optional property questionnaire after you submit your contribution
  • Technical Information: Submission timestamp, browser type, and your IP address. The IP address is never stored in readable form — it is converted to a keyed, irreversible hash used solely to detect abuse, and that hash is deleted after 7 days
  • Analytics Data: Page views, button clicks, and user interactions to improve our service

How We Use It

  • Create Suburb Overviews: To calculate and display median fees, quartiles, and percentile rankings for suburbs
  • Contributor Recognition: To assign founding contributor rankings and badges (if email provided)
  • Notifications: To notify you when suburb overviews become available for your suburb (if email provided)
  • Contributor Benefits: To provide discount codes for premium report purchases (if email provided)
  • Service Improvement: To improve the accuracy of our suburb overviews and the user experience

What We Don't Store

We are committed to privacy-first design:

  • We do NOT accept or store documents. There is no facility to send us a body corporate statement, invoice or receipt — you enter the fee figures yourself
  • We do NOT store owner names, postal addresses (if different from property address), phone numbers, or other personal identifiers
  • All data is anonymised for suburb overview calculations

AI Processing

Your contribution is not processed by AI. The fee amounts, dates and address you enter are stored exactly as you submit them. No AI reads your contribution, and no AI is trained on it.

We use the Google Gemini API in two places that are unrelated to your contribution: the chat assistant on this Website, and the search that helps the assistant find relevant guidance. Chat queries you type are sent to Google for processing under an enterprise API agreement that guarantees zero data retention and no training on customer data. See Section 3.3 for detail.

Your Consent

By contributing your fees, you consent to this collection and use of your information. Email notifications are entirely optional - you can contribute anonymously without providing an email address.

1. Information We Collect

1.1 Notification Email Addresses

When you provide your email address, we collect it to notify you when suburb overviews become available for your suburb, send you contributor discount codes, or when we have updates about the service.

1.2 Contribution Information

When you contribute your fees, we collect:

  • Physical Property Address: Full address including unit/lot, street, suburb, state, and postcode
  • Fee Information: Fee amounts, descriptions, and date ranges (as entered by you)
  • Entry Metadata: Submission date/time
  • Email Address (Optional): For contributor rankings, suburb overview notifications, and discount codes
  • Building Information (Optional): Building type, age, number of units, bedrooms, and amenities - via the optional property questionnaire presented after submission

1.3 Contributor Discount Codes

When you contribute fees and provide your email address, we generate and store a unique discount code for you. This includes:

  • Discount Code: A unique code (e.g., CONTRIB-ABC123)
  • Email Address: Linked to your discount code
  • Suburb: The suburb your code is valid for
  • Contribution Reference: Link to the contribution that earned the code
  • Usage Status: Whether the code has been used

Discount codes are:

  • Single-use only (one per suburb contribution)
  • Non-transferable and linked to your email address
  • Valid indefinitely unless misused
  • Provide a discount on premium suburb report purchases
  • Sent to you via email when generated

1.4 Automatically Collected Information

When you visit our Website, we automatically collect analytics data using PostHog to understand how visitors use our service. This data is collected anonymously and is NOT linked to your identity.

  • IP address (anonymised)
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on each page
  • Referring website
  • Button clicks and user interactions (e.g., "FAQ search used", "contribute button clicked")
  • Search queries within the site (e.g., suburb names searched)

This information helps us improve our Website, understand how visitors use it, and identify issues or areas for improvement. We do NOT track individual users or create user profiles.

1.5 Browser Storage

We use browser local storage to improve your experience on our Website. Local storage data is stored on your device only and is never transmitted to our servers. We store the following information in your browser's local storage:

  • Checklist Access Flag: A simple true/false value indicating you have provided your email for checklist access. This prevents re-prompting for your email when you visit other checklists.
  • Contributor Email: When you contribute your fees and provide your email address, we store your email in local storage to pre-fill contributor recognition features and streamline future contributions.
  • Suburb Purchase Information: When you purchase a premium suburb report, we store your email address and purchase details (suburb name, state, postcode, purchase timestamp) in local storage to verify your access to purchased reports without requiring login.

Why we store this information locally:

  • To provide seamless access to purchased reports across browser sessions
  • To pre-fill your email address for contributor features
  • To remember your checklist access preferences
  • To avoid requiring account creation and login

Your control: All local storage data can be cleared at any time through your browser settings. See Section 8.4 for detailed instructions on how to manage local storage.

1.6 API Key Holders

We issue API keys to authorised developers, businesses, and AI agents that access our service programmatically. For API key holders, we collect and retain:

  • Key Label: A descriptive name assigned to the key by the administrator (e.g., "MyApp Integration")
  • Usage Metadata: The date and time the key was last used and a count of requests made over rolling periods
  • Key Hash: A cryptographic hash of the key (the plaintext key is never stored)

API keys are issued to organisations or individuals, not anonymous users. Key records are retained for as long as the key is active and for a reasonable period after revocation for audit purposes. No personal documents or sensitive personal information are collected from API key holders - only the usage metadata described above.

2. How We Use Your Information

We use the information we collect to:

  • Create Suburb Overviews: Calculate median fees, quartiles, and suburb statistics
  • Send Notifications: Email you about launch updates, suburb overview availability, and contributor rankings (only if you opted in)
  • Provide Contributor Benefits: Issue discount codes for premium report purchases
  • Improve Service: Enhance the accuracy of our suburb overviews and the user experience
  • Prevent Duplicates: Use fingerprinting to detect duplicate submissions
  • Respond to Inquiries: Answer your questions and support requests
  • Comply with Legal Obligations: Meet our legal and regulatory requirements

We will never sell, rent, or share your personal information with third parties for their marketing purposes.

3. Third-Party Services

3.1 Email Service Provider

We use Mailcoach to manage email subscriptions and send notifications. Your email address is shared with Mailcoach for this purpose. Mailcoach complies with privacy regulations and does not use your data for any other purpose.

3.2 AI Processing

Your contribution is not processed by AI. The fee amounts, dates and property address you enter are saved directly, without any third-party processing.

We use the Google Gemini API only for the chat assistant on this Website and the search that supports it. If you use the chat, the question you type is sent to Google's servers to generate an answer. Your contribution data is not sent to Google.

3.3 AI Processing vs AI Training

We understand many users have concerns about their information being used to train AI models. Here's our clear commitment:

  • Your contribution is NEVER used for AI training: The fees, dates and address you submit are stored as structured data and are not sent to any AI provider.
  • Chat queries are processed, not retained: If you use the chat assistant, your question is sent to Google's Gemini enterprise API to generate an answer. It is processed in real time and not retained by Google.
  • AI Training (what we DON'T do): We do not use your contributions or your chat queries to train any AI model, and Google's enterprise API does not use customer data for model training.
  • Service Improvement: We may analyse aggregate patterns in the structured data you've already consented to share (like common fee categories or address formats) to improve our suburb overviews. This uses aggregate patterns only.

Google Gemini Enterprise API Data Policy: Google's enterprise API customers (like us) benefit from contractual guarantees that submitted content is not used to train or improve Google's AI models. Chat queries are processed ephemerally and not retained by Google.

3.4 Analytics

We use PostHog to collect and analyse usage data about how visitors interact with our Website. PostHog helps us understand user behavior, identify bugs, and improve our service.

Anonymous tracking only: We track events anonymously without identifying individual users. We do NOT:

  • Use PostHog's identify() function to link events to individual users
  • Track email addresses, names, or other personal identifiers in analytics events
  • Enable session recording or screen capture
  • Enable automatic data capture that might collect form inputs or sensitive data

Data collected: Page views, button clicks, user interactions (e.g., "contribute button clicked"), device information, anonymised IP addresses, and non-personal context (e.g., suburb names for search queries).

Data retention: PostHog retains analytics data for up to 7 years for historical analysis and trend monitoring.

Your control: PostHog respects Do Not Track (DNT) browser settings. You can also opt out of analytics tracking by disabling cookies in your browser settings (see Section 8.3 below).

3.5 Server and Database Hosting

Our application server and database are hosted by Hetzner in Helsinki, Finland. Your data is encrypted in transit and at rest.

4. Cross-Border Disclosure

Your personal information may be disclosed to overseas recipients in the following countries:

  • Finland: Application server and database hosting (Hetzner, Helsinki)
  • United States: Chat assistant queries (Google Gemini API) - processed in real-time with zero retention; Google does not use your data for AI training under enterprise API terms. Your contribution data is not sent to Google. Analytics data (PostHog) - usage data and anonymised visitor information.
  • Email Service: Mailcoach (server location varies by plan)

We take reasonable steps to ensure these providers handle your information in accordance with Australian privacy laws and have appropriate security measures in place.

5. Data Storage and Security

5.1 Security Measures

We implement comprehensive security measures to protect your personal information:

  • No Document Storage: We do not accept or store documents of any kind
  • Secure Transmission: All data transmitted via HTTPS/SSL encryption
  • Encryption: Data encrypted at rest
  • Access Controls: Restricted database access with authentication
  • No Sensitive PII Storage: We do not store owner names, phone numbers, or personal postal addresses
  • Duplicate Prevention: Cryptographic fingerprinting prevents duplicate submissions
  • Environment Security: API keys and secrets stored in secure environment variables

5.2 Data Retention

However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

6. How Long We Keep Your Information

6.1 Contribution Data

We retain property addresses and fee data indefinitely to maintain suburb overview accuracy and historical trends. This data is anonymised and cannot be traced back to individuals.

6.2 Email Subscription Data

We keep your email address and subscription preferences until you unsubscribe or request deletion.

6.3 Discount Codes

Discount codes are retained indefinitely to prevent reuse and maintain purchase history. However, the email address linked to a discount code can be deleted upon request (see Section 7.3).

6.4 Technical Information

The keyed hash of the IP address that accompanied a contribution is deleted 7 days after the contribution is made. We never store the IP address itself, and abuse detection only ever examines the previous 24 hours, so the hash serves no purpose beyond that window.

7. Your Rights

Under the Australian Privacy Act, you have the right to:

  • Access your personal information we hold
  • Correct inaccurate or incomplete information
  • Delete your information (subject to legal obligations and anonymised suburb overview data)
  • Opt-out of marketing communications at any time
  • Complain to us or the Office of the Australian Information Commissioner (OAIC)

7.1 Data Access Requests

To request access to your personal information:

  1. Email [email protected] with subject "Data Access Request"
  2. Provide your email address and/or property address to help us locate your data
  3. We will respond within 30 days with your data in a portable format (JSON or CSV)

There is no fee for access requests unless the request is manifestly unfounded, excessive, or repetitive.

7.2 Correction Requests

To request correction of your personal information:

  1. Email [email protected] with subject "Data Correction Request"
  2. Specify what information is incorrect and provide the correct information
  3. We will review and respond within 30 days

If we correct your information, we will notify any third parties to whom we disclosed the incorrect information (unless it's impracticable or unlawful to do so).

7.3 Deletion Requests

To request deletion of your personal information:

  1. Email [email protected] with subject "Data Deletion Request"
  2. Provide your email address and/or property address
  3. We will delete your email subscription and personal identifiers within 30 days

Note: Anonymised contribution data (property address and fees) may be retained for suburb overviews, as it cannot be traced back to you and is necessary for our service.

7.4 Unsubscribe from Emails

Every email we send includes an unsubscribe link at the bottom. Clicking this link will immediately remove you from our mailing list. You can also email [email protected] with subject "Unsubscribe" and we will remove you manually within 2 business days.

8. Cookies

We use cookies on our Website to ensure secure operation and to understand how visitors use our service. Cookies are small text files stored on your device by your web browser.

8.1 Strictly Necessary Cookies

We use one essential cookie for security purposes:

  • CSRF Token Cookie: A session cookie that protects against Cross-Site Request Forgery (CSRF) attacks. This cookie ensures that form submissions come from legitimate users of our Website, not malicious third-party sites.

This cookie is classified as "strictly necessary" because it is required for the Website to function securely. Without this cookie, we cannot safely process your form submissions.

Cookie Details:

  • Purpose: Security (CSRF protection)
  • Type: Session cookie (deleted when you close your browser)
  • Data stored: Random token for request validation
  • Third-party access: None - cookie is only used by our server

8.2 Analytics Cookies

We use PostHog analytics cookies to understand how visitors interact with our Website. These cookies help us:

  • Track which pages are most popular
  • Identify bugs and technical issues
  • Understand user journey and behavior patterns
  • Measure the effectiveness of features and improvements
  • Improve overall user experience

Cookie Details:

  • Purpose: Anonymous analytics and performance monitoring
  • Provider: PostHog (third-party analytics service)
  • Type: Persistent cookies (stored for up to 1 year)
  • Data stored: Random anonymous visitor ID, session information, page view data
  • Third-party access: PostHog (US-based analytics provider)
  • Privacy note: We do NOT use PostHog to identify individual users or link analytics data to your email, name, or other personal identifiers

8.3 Managing Cookies

Strictly Necessary Cookies: Because the CSRF cookie is strictly necessary for security, you cannot opt out of it while using our Website. If you disable all cookies in your browser settings, you will not be able to submit forms.

Analytics Cookies: You can opt out of analytics tracking by:

  • Enabling "Do Not Track" (DNT) in your browser settings
  • Blocking third-party cookies in your browser settings
  • Using browser extensions that block analytics trackers
  • Disabling cookies for bodycorporatefees.com specifically

Opting out of analytics cookies will not affect your ability to use the Website, but will prevent us from understanding how you use our service.

How to manage cookies in your browser:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions

We do not use cookies for:

  • Advertising or marketing purposes
  • Selling your data to third parties
  • Cross-site tracking beyond our Website
  • Storing sensitive personal information

8.4 Browser Local Storage

In addition to cookies, we use browser local storage (localStorage) to improve your experience on our Website. Local storage is a browser feature that allows websites to store small amounts of data on your device.

What we store in local storage:

  1. Checklist Access Flag (key: checklist_access)
    • Purpose: Remember that you've provided your email for checklist access
    • Data stored: A single true/false value
    • Contains personal information: No
    • When stored: When you provide your email to access any free checklist
  2. Contributor Email (key: contributorEmail)
    • Purpose: Pre-fill your email for contributor recognition features
    • Data stored: Your email address
    • Contains personal information: Yes (email address)
    • When stored: When you contribute your fees and provide your email
  3. Suburb Purchase Email (key: suburb_purchase_email)
    • Purpose: Verify access to purchased suburb reports
    • Data stored: Your email address
    • Contains personal information: Yes (email address)
    • When stored: When you purchase a premium suburb report
  4. Suburb Purchases (key: suburb_purchases)
    • Purpose: Track which suburb reports you've purchased for access verification
    • Data stored: JSON object containing email address, suburb name, state, postcode, and purchase timestamp for each purchase
    • Contains personal information: Yes (email address and purchase history)
    • When stored: When you purchase a premium suburb report

Why we use local storage:

  • To provide seamless access to purchased reports without requiring account creation or login
  • To remember your checklist access preferences across visits
  • To pre-fill your email address for contributor features and streamline future contributions
  • To verify purchase access entirely client-side, enhancing privacy and performance

How it works:

  • Local storage data stays on your device only - it is never transmitted to our servers
  • The data persists between browser sessions (unlike session cookies which are deleted when you close your browser)
  • The data is specific to bodycorporatefees.com and cannot be accessed by other websites
  • Local storage is stored per browser - clearing it will not affect data in other browsers or devices

Managing local storage:

You can clear local storage data at any time through your browser settings. This will:

  • Remove your checklist access flag (you'll be prompted for email again)
  • Remove saved email addresses (you'll need to re-enter them)
  • Remove purchase verification data (you may need to verify purchases again via email)

Important: Clearing local storage will NOT:

  • Affect your email subscription status (you'll still receive emails if subscribed)
  • Cancel your purchased suburb reports (your purchases are linked to your email)
  • Delete your data from our servers (contribution data remains in our database)

How to clear local storage:

  • Chrome: Settings → Privacy and security → Cookies and other site data → See all site data and permissions → Search for "bodycorporatefees.com" → Clear data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data → Search for "bodycorporatefees.com" → Remove Selected
  • Safari: Preferences → Privacy → Manage Website Data → Search for "bodycorporatefees.com" → Remove
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions → See all cookies and site data → Search for "bodycorporatefees.com" → Remove

9. Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before providing any information.

10. Children's Privacy

Our Website is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" and "Version" dates at the top
  • Sending an email to registered users for significant changes

Previous versions of this policy are available upon request by emailing [email protected].

Version History

  • Version 3.1.0 (2 August 2026) - Strengthened and disclosed IP address handling: The Collection Notice now states that a contributor's IP address is never stored in readable form, only as a keyed irreversible hash used for abuse detection. Added new Section 6.4 (Technical Information) disclosing that this hash is deleted after 7 days. Both reflect privacy-protective changes made to the Website: the hash is now keyed with a secret that is not held in the database, and a scheduled task erases hashes past the retention window.
  • Version 3.0.0 (1 August 2026) - Removed the document upload contribution method: The Website no longer accepts body corporate statements or any other documents. Contributions are made by entering fee details directly. Removed Section 1.4 (Failed Extraction Data) and Section 6.2 (Failed Extractions) in full, as no documents are received and none are retained. Rewrote the Collection Notice, Section 1.2, Section 3.2 and Section 3.3 to reflect that contributions are not processed by AI. Narrowed the Google Gemini disclosures in Section 3.2, Section 3.3 and Section 4 to the chat assistant, which remains the only feature that sends your input to Google. Updated Section 5.1 to state that no documents are stored. Subsequent subsections in Sections 1 and 6 were renumbered; references to section numbers in earlier changelog entries refer to the numbering in force at the time.
  • Version 2.6.1 (16 May 2026) - Reduced failed extraction retention period: Updated Section 1.4, Section 5.1, and Section 6.2 to reduce the maximum retention of temporarily stored failed-extraction documents from 30 days to 72 hours. This is a privacy-protective change that aligns the disclosed retention period with our practice of never storing documents longer than strictly necessary.
  • Version 2.6.0 (21 February 2026) - Added building information and API key disclosure: Updated Collection Notice and Section 1.2 to disclose building information collected via the optional property questionnaire (building type, age, total units, bedrooms, amenities). Added new Section 1.7 disclosing data collected from API key holders (label, usage metadata, key hash). Added API access terms to Terms of Service.
  • Version 2.5.1 (6 January 2026) - Enhanced browser local storage disclosure: Updated Section 1.6 to accurately disclose all localStorage usage including contributor emails and suburb purchase information (previously incorrectly stated no personal information was stored in localStorage). Expanded Section 8.4 to provide comprehensive details about all four localStorage keys (checklist_access, contributorEmail, suburb_purchase_email, suburb_purchases), clearly identifying which items contain personal information and their specific purposes. Added detailed management instructions for clearing local storage.
  • Version 2.5.0 (5 January 2026) - Added contributor discount code disclosure: Added new Section 1.3 describing discount code collection and usage, updated Section 2 to include "Provide Contributor Benefits", updated terminology from "benchmarks" to "suburb overviews" throughout user-facing text, removed Section 6.1 (Waitlist Emails) as no longer applicable, renumbered subsequent sections, added Section 6.4 for discount code retention, updated email notification descriptions to include discount codes
  • Version 2.4.0 (1 December 2025) - Added browser local storage disclosure: Added new Section 1.5 describing browser local storage usage for checklist access, added comprehensive Section 8.4 explaining what local storage data we collect, why we use it, and how users can manage it. Local storage is used to remember checklist access across different free tools without storing personal information.
  • Version 2.3.0 (19 November 2025) - Added PostHog analytics disclosure: Updated Collection Notice to include analytics data, added Section 3.4 for PostHog third-party service, updated Section 1.4 to clarify analytics collection, completely rewrote Section 8.2 to disclose analytics cookies and provide opt-out instructions, and updated cross-border disclosure to include PostHog (United States)
  • Version 2.2.1 (15 November 2025) - Updated terminology: Changed "Waitlist Email Addresses" to "Notification Email Addresses" and updated description to reflect live service status (suburb overview availability notifications rather than launch notifications)
  • Version 2.2.0 (1 November 2025) - Enhanced cookie disclosure: Completely rewrote Section 8 to clearly explain CSRF cookie usage, classify it as "strictly necessary" for security, and clarify that we don't use cookies for tracking, analytics, or advertising
  • Version 2.1.0 (1 November 2025) - Enhanced AI training transparency: Added Section 3.3 clarifying AI processing vs training, updated Collection Notice with explicit "never used for AI training" commitment, and enhanced Google Gemini disclosure with enterprise API data policy details
  • Version 2.0.1 (25 October 2025) - Corrected hosting disclosure: Application server and database are both hosted by Hetzner in Helsinki, Finland (not Neon.tech in United States)
  • Version 2.0 (25 October 2025) - Added comprehensive collection notice, third-party services disclosure, security measures, data access/correction procedures, and cross-border disclosure information
  • Version 1.0 (19 October 2025) - Initial privacy policy

12. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or have a privacy concern, please contact us:

Email: [email protected]
Privacy Officer: BodyCorporateFees.com
Response Time: Within 30 days

Complaints

If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us at [email protected]. We will:

  1. Acknowledge your complaint within 7 days
  2. Investigate and respond within 30 days
  3. Work with you to resolve the issue

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):