StrataChecks

Privacy Policy

Last updated 17 September 2026

StrataChecks (we, us) operates stratachecks.com.au, a public information tool and report-analysis service for NSW strata property buyers. This policy explains what personal information we collect, why, where it goes, and how to get it corrected or deleted. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

The short version: we collect what we need to run the service and nothing more, we don't sell your data, the report you upload is used only to produce your analysis, and you can ask us to delete everything at any time.

1. What we collect

Account details. When you create an account we collect your email address and a password, which is stored only as a one-way hash (we can never read it). If you sign in with Google we receive your email address and a Google account identifier so we can link your sign-ins; we don't receive your Google password or any other Google data. We also record when you signed up, when you last logged in, and the browser you used, so you can see and end your own sessions.

Reports you upload. To analyse a strata report we store the PDF you upload, its filename and size, the structured information extracted from it (plan number, address, fund balances, levies, insurance, litigation, defects, special levies, building age and similar), our risk assessment, and any custom question you ask about it. Strata reports often contain information about other people — owners, committee members, tenants, contractors. We only ever use that information to produce your analysis; it is never published or added to our public database.

Payments. Card payments are processed by Stripe. We never see or store your card number. We keep your Stripe customer ID, the checkout session and transaction identifiers, the amount paid and a ledger of the credits you have bought, used or been refunded.

Enquiries and requests. If you request an inspection quote, join a waitlist, ask for a referral (conveyancer, home loan, buyer's agent or building inspection), or use the contact form, we collect what you enter: typically your name, email address, phone number, the building address or plan number, and your message. An inspection request may include a letter of authority you upload, which we store with the request.

Usage and technical data. Like most websites we collect information about how the site is used: pages viewed, searches run, buttons clicked, the page that referred you, your approximate location derived from your IP address, and your browser and device type. Our servers and content delivery network also keep standard request logs (IP address, requested URL, time, user agent) for security and abuse prevention.

2. How we use it

  • To provide the service: run your analysis, show your results, keep you signed in.
  • To take payment, credit your account and honour refunds.
  • To respond to enquiries and pass inspection or referral requests to the relevant provider (see section 4).
  • To send you transactional email — verification links, password resets, receipts and notices about an analysis you've started. We don't send marketing email, and if we ever start it will be opt-in with an unsubscribe link in every message.
  • To understand how the site is used, find bugs and improve the product. This is done in aggregate; we don't build advertising profiles.
  • To detect and block abuse, scraping and fraud, and to comply with the law.

We don't use the reports you upload to train any AI model, and we don't sell or rent personal information to anyone.

3. Your uploaded reports in detail

Because the strata report is the most sensitive thing you give us, here is exactly what happens to it:

  • The PDF is stored in private object storage in Sydney, Australia. It is not publicly accessible; it is served only through short-lived signed links to you and to our support staff when troubleshooting an analysis.
  • The document is sent to Google's Gemini API to extract its contents into structured data. Google processes it under its Gemini API terms; a temporary copy used for that processing is deleted from Google's file store once extraction is complete.
  • An upload that is never claimed by an account is deleted from storage automatically after a short period.
  • Otherwise the PDF and its analysis are kept so you can come back to your results. You can ask us to delete a report, or your whole account, at any time (section 9).

4. Who we share it with

We use a small number of service providers to run StrataChecks. Each receives only what it needs to do its job and is bound by its own privacy terms:

  • DigitalOcean — hosting and PDF storage (Sydney, Australia).
  • Supabase — database hosting.
  • Cloudflare — DNS, content delivery and protection against abuse.
  • Google — Gemini API (report extraction), Google Sign-In (if you use it), and Google Maps for address search.
  • Stripe — payment processing.
  • PostHog — product analytics (United States).
  • Sentry — error monitoring (United States).
  • Resend — transactional email delivery (United States).
  • Esri — map tiles shown on plan pages.

Inspection quotes and referrals. If you ask for an inspection quote or a referral, we pass the details you gave us (name, contact details, property, your message and any letter of authority) to the inspection or referral provider so they can respond to you. They are independent businesses with their own privacy policies, and we may receive a referral fee. We won't pass your details to a provider for any request you haven't made.

We will also disclose personal information where the law requires it, or to protect the rights, safety or property of StrataChecks, our users or the public.

5. Overseas disclosure

Your uploaded reports and our database are stored in Australia. Some of the providers above operate outside Australia — in particular PostHog, Sentry, Resend and parts of Google's and Stripe's infrastructure are in the United States. By using the service you consent to that disclosure. We choose providers with strong security practices, but the Privacy Act may not apply to them in the same way it applies to us, and you may not have the same remedies against them.

6. Cookies

We set a small number of cookies, all first-party:

  • sc_session — keeps you signed in. Lasts 30 days and is refreshed while you keep using the site.
  • sc_claim — links a report you uploaded before signing in to the account you create or sign in to afterwards.
  • sc_google_oauth — a short-lived token used only during Google Sign-In to protect against forged requests.
  • Analytics cookies set by PostHog to tell one visit from another. These are served from our own domain and are not shared with any advertising network.

We don't use advertising cookies or tracking pixels. Blocking cookies in your browser will stop you staying signed in but the free search will still work.

7. Analytics and error monitoring

We use PostHog to see which pages and features are used and where people get stuck. If you are signed in, analytics events are associated with your account; otherwise they are tied to an anonymous cookie. We use Sentry to capture errors. When an error occurs Sentry may record a short replay of the screen leading up to it (for a sample of errors) to help us reproduce the problem; text you have typed into form fields is masked in those replays. Neither tool is used on our admin pages, and neither is used to serve ads.

8. How long we keep it

  • Account details, reports and analyses: for as long as your account exists, or until you ask us to delete them.
  • Unclaimed uploads: deleted automatically after a short period.
  • Payment records: for the period Australian tax and record-keeping law requires (up to seven years).
  • Enquiries and lead forms: until the request is dealt with and for a reasonable period afterwards.
  • Server and security logs: a limited period, then discarded.

9. Access, correction and deletion

You can see your email address, credit balance and reports on your account page. To access the rest of the information we hold about you, correct it, or have a report or your whole account deleted, email [email protected] from the address on your account. We'll respond within 30 days and there is no charge. Deleting your account removes your uploaded reports and analyses; we keep the payment ledger for the period required by law and any information we need to resolve a dispute.

10. Security

All traffic is encrypted in transit. Passwords are stored only as salted scrypt hashes. Email verification and password-reset links are single-use, expire quickly, and only a hash of the token is kept. Uploaded PDFs live in a private bucket and are only reachable through short-lived signed URLs. Access to production systems is limited to the people who run the service. No system is perfectly secure, and if we become aware of a breach that is likely to cause you serious harm we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

11. The public property database

The plan, building and manager information you can search on StrataChecks is compiled from public sources — principally the NSW Strata Hub, NSW Planning Portal, NSW Caselaw (NCAT decisions), NSW Valuer General sales data and other government open data, plus Inside Airbnb. It describes buildings and licensed businesses, not the people who use this site, and it does not include anything you have uploaded or entered. If you believe a listing includes personal information about you that shouldn't be there, contact us and we'll review it.

12. Children

StrataChecks is for people buying or owning property and is not directed at anyone under 18. We don't knowingly collect personal information from children.

13. Changes to this policy

We'll update this page when our practices change and update the date at the top. If a change materially affects how we handle information you've already given us, we'll email account holders before it takes effect.

14. Questions and complaints

Email [email protected] or use the contact form. If you're not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

See also our Terms of Service.