Skip to main content Scroll Top
Privacy Policy

Our Square Pty. Ltd. (ABN 17 693 163 423), trading as Our Square, Burpengary QLD 4505. Version 3.0. Effective date: [to be set at go-live]. These terms are under final legal review and may be updated before launch.

Our Square is committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and any other applicable Privacy Legislation.

1. What we collect

1.1 Buyers (with or without an account)

  • Name, email address, and (optionally) phone number when you create an account or verify your email to contact specialists through the anonymous “build my team” journey.
  • Enquiry messages and the identity of specialists you contact, including a permanent record of which specialists a verified email address has already contacted (used solely to prevent duplicate sends).
  • Saved specialist lists, team compositions, and saved land listings.
  • Timestamps of login, enquiry, and feedback events.

1.2 Sellers

  • Name, business or trading name, email, phone.
  • Property information (address, title reference, lot size).
  • Uploaded documents (site plans, covenants, DA documents).
  • Sale history (sold price and date, for the public sold register).

1.3 Specialists

  • Business legal name, contact details, business address.
  • Professional credentials – QBCC licence, QLS certificate, ACL number, AFSL number, or equivalent – depending on service category.
  • Professional indemnity insurance details (where provided).
  • Enquiry response history for marketplace performance metrics.

1.4 All users

  • IP address (stored as a salted SHA-256 hash, not reversibly identifying) and browser user agent for anti-abuse purposes.
  • Feedback submissions (with optional name and email).

1.5 Children

The website is not intended for children and we do not knowingly collect personal information from anyone under 18. If you are a parent or guardian of a child who you believe has provided us with personal information without your consent, please contact us immediately at privacy@oursquare.com.au and we will delete it.

2. How we collect it

  • Directly from you when you create an account, verify your email, submit a form, upload a document, or make an enquiry.
  • Automatically for security and platform operation: IP address, user agent, and page URL of feedback submissions.
  • From public Queensland Government registers when verifying specialist credentials (in particular the QBCC Licensed Contractors Register at data.qld.gov.au). We do not collect personal information from those registers beyond what is publicly published.

3. Why we collect it

Purpose Data used Legal basis
Provide the marketplace service All account and listing data Consent, contract performance
Send enquiries between buyers, sellers, and specialists Buyer name, email, phone (opt), message Consent
Prevent duplicate or abusive sends Email-to-specialist send log Legitimate interests (anti-abuse)
Verify specialist credentials Licence numbers Legitimate business purpose, consent
Retain records of communications Enquiry text, timestamps Commercial record keeping
Comply with tax and legal obligations Transaction and business records Legal obligation
Improve the service Aggregate usage patterns Legitimate interests
Communicate service updates Email address Consent (opt-out available)

4. Who we share it with

We disclose personal information only as necessary to operate the marketplace and only to the following categories of recipient:

  • The other party to an enquiry or listing (a specialist you contact sees your name, email, and any phone number you have provided).
  • Our hosting provider, WP StaQ, which processes personal information on our behalf on servers located in Australia under contractual data-processing terms.
  • Our bot-protection provider (Cloudflare Turnstile), which processes limited technical signals (IP address, browser characteristics) to distinguish humans from bots. This processing may occur outside Australia; we only use providers whose protections are comparable to those required under Australian Privacy Legislation (APP 8).
  • Our content delivery network (AWS CloudFront, provided through our host WP StaQ), which caches public pages and static assets at edge locations that may be outside Australia to speed up the website. Personal information at rest remains on Australian servers; account and portal pages are excluded from edge caching.
  • Payment processors, where applicable in future – these operate as principals for payment data. Our Square does not collect, transmit, or store payment card details; it would hold tokenised references only.
  • Government authorities where required by law (e.g. subpoena, notifiable data breach notification).

We do not sell personal information. Apart from the limited technical processing described above, we do not disclose personal information overseas. If we ever transfer personal information to storage or processing facilities located outside Australia, we will only transfer it to jurisdictions with privacy protections comparable to Australian law.

5. Storage and security

Personal information is stored on servers located in Australia (WP StaQ). Transmission is protected by TLS 1.2+. Passwords are hashed using industry-standard bcrypt-family algorithms. Magic-link tokens and email verification codes are hashed before storage. IP addresses are stored only as salted SHA-256 hashes. No payment card information is collected or stored on our systems.

Access to personal information within Our Square is limited to administrators who need it for their duties. Every administrator action affecting user data is logged in an audit trail retained for 7 years.

Full technical detail, including the encryption, access control, and monitoring measures, is set out in our Security Architecture document, available on request.

6. Retention

We retain personal information only as long as necessary for the purpose for which it was collected, in accordance with APP 11.2, and otherwise as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Our internal Data Retention & Handling Policy implements the following schedule automatically:

Data type Retention Then
Buyer accounts 24 months from last login Deleted (30-day warning first)
Abandoned signups 30 days from creation Deleted (1-day warning first)
Anonymous email verification codes 24 hours Deleted
Anonymous list resume links 90 days Deleted
Enquiry records 7 years from enquiry De-identified
Seller listings (sold) 24-month archive + permanent sold register Archive deleted; register de-identified
Specialist profiles Duration of listing + 24 months Deleted
Feedback 90 days from resolution (configurable) Deleted
Admin audit log 7 years Deleted

7. Your rights and complaints

Under the Australian Privacy Principles you have the right to:

  • Access the personal information we hold about you (APP 12). Export instantly via portal, Account, Export my data, or by request to privacy@oursquare.com.au.
  • Correct inaccurate personal information (APP 13). Green fields are corrected instantly; amber fields via change-request review; other requests to privacy@oursquare.com.au.
  • Withdraw consent to any communication or use of your information not required by law.
  • Delete your account via portal, Account, Delete my account.

We will acknowledge any privacy question, access request, correction request, or complaint within 2 business days, and provide a substantive response within 30 days. If you are unsatisfied with our response you may escalate to the Office of the Australian Information Commissioner (oaic.gov.au). Our internal Complaints Handling Policy governs logging, responsibility, and escalation.

8. Cookies

We use first-party session cookies for authentication and to remember display preferences, and browser local storage to hold anonymous “build my team” progress on your own device. We do not set third-party tracking cookies by default. Consent is managed via the Complianz consent tool. Cookie behaviour is fully documented in the Security Architecture document.

9. Automated decision-making and AI

Our Square does not use artificial intelligence or automated decision-making that produces legal or similarly significant effects. The “journey” selector and team builder are fixed, administrator-configured templates: a chosen journey maps to a fixed list of specialist categories. All emails sent by the platform are fixed templates triggered by user actions; none are AI-generated. If Our Square introduces any AI or automated decision-making feature in future, this policy will be amended first and any transparency obligations regarding automated decisions under the Privacy Legislation will be met.

10. Direct marketing

We only send marketing communications with your explicit consent, given via opt-in at account creation or later at portal, Account, Communication preferences. Every marketing message contains an unsubscribe link, in accordance with the Spam Act 2003 (Cth).

11. Data breach response

We maintain a documented incident response process aligned with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988, set out in our internal Data Breach Response Plan. If an eligible data breach occurs, we will assess it promptly and notify the OAIC and affected individuals as soon as practicable.

12. Contact and updates

Privacy questions: privacy@oursquare.com.au (acknowledged within 2 business days). This policy is reviewed at least annually and updated when our practices materially change. Material changes are notified by a notice posted on the website and by email to registered users.