Legal

Privacy Policy

Last updated: 2026-08-11

This is a starter privacy policy drafted by Nestfinder engineering. It is not legal advice and has not yet been reviewed by a qualified Australian privacy practitioner. The final wording will be revised before any paid launch.

1. Who we are

Nestfinder ("we", "us", "our") is an Australian property-search tool. We operate from Australia and are bound by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

Contact for privacy enquiries: support@nestfinder.au.

2. What we collect

When you create an account or use Nestfinder, we collect:

  • Account details: your email address, first and last name, a salted password hash, and a household taxable income band (e.g. "$1,000- $1,249 per week", never an exact figure). Email, name, and income band are required at signup. We ask for income band so we can match you to suburbs whose affordability profile fits your household - it is compared directly against each suburb's published median household income, which is why we ask for a band rather than a dollar figure (only the band, not the underlying number, is ever stored). Your income band is never shown to a broker or any other user. If that ever changes it will need your separate, explicit, revocable consent, and we will update this policy first (see section 3b).
  • Requirements: data you enter into the Requirements form, which may include your household income, savings, dependents, and other search-relevant information. This data is used to rank suburbs for you. Some of it - your budget and four move-intent answers - also reaches a broker if you ask one to contact you; section 3b lists exactly which fields. You can edit or delete it at any time from your settings.
  • Preferences: which dimensions you weight when ranking suburbs.
  • Requirement & preference history: when you save your Requirements or Preferences (in the wizard or from the settings form), we keep an append-only history of those values so you can see how your search criteria have changed over time, and so we can offer aggregate trend reports to partner organisations. Trend reports are grouped by an internally-hashed identifier (not your user id) and never include individual user data. Before history rows are written, your workplace coordinates are coarsened to roughly a 100-metre grid and your free-text workplace address is dropped. The live record retains the full address and exact coordinates, but the history table only ever sees the coarsened view. A more detailed consent flow + opt-out toggle is on the roadmap.
  • Browser metadata: minimal request metadata via PostHog (page URLs, referrer, anonymised IP, coarse user agent, and the named UI events listed in section 8b). PostHog is self-hosted on our own infrastructure once that service is online; we use PostHog Cloud on the free tier in the interim. We do not load any third-party analytics scripts (no Google Analytics, no Facebook Pixel). Analytics are off by default: the in-app consent banner is opt-in and we honour your browser's Do-Not-Track signal as an automatic decline.
  • Error reports: if the app crashes in your browser, a stack trace and a redacted snapshot of the page state are sent to Sentry for diagnosis. We configure Sentry's PII filters and do not deliberately forward the contents of your Requirements form.

We do not collect: bank-account or credit-card details (we don't process payments yet); biometric or sensitive health information; precise geolocation from your device.

3. Who we share it with

We share data with the following service providers, strictly to operate Nestfinder:

  • Sentry (error reporting). Sentry is hosted in the EU; transfer occurs only if your browser hits an exception.
  • PostHog (product analytics). Long-term we self-host PostHog on our own infrastructure. While we wait for that provisioning to land we use PostHog Cloud (free tier), and events transit to PostHog's US or EU region depending on the configured endpoint. No third-party tracking pixels.
  • Hosting: our application and database run on a self-managed VPS, deployed via plain docker compose and managed with Portainer. The VPS is located in Australia.

We do not share your personal information with advertising networks.

3a. Aggregate cohort exports (opt-in)

We may produce aggregate, anonymised statistics (never personally identifiable) about how users in your region weight property preferences, and share or sell those aggregates to research partners (banks, buyer-agents, developers). Aggregation thresholds: minimum cohort size of N=20 before any cell is exported.

This is opt-in only. We do not include your data in any cohort export unless you explicitly enable the "share my anonymised preferences with research partners" toggle, either at signup or later from Settings → Data & Privacy. The toggle defaults to off; you can revoke at any time. When you revoke, your anonymised preferences are no longer fed into new exports. Aggregates already released before you revoked are, by construction, irreversible: once a cell hits the N=20 threshold and is exported, the underlying contributing rows are no longer distinguishable.

The cohort-export pathway exists because the cohort intelligence is what makes Nestfinder sustainable without ads or per-click upcharges to you. Your one-toggle veto is the load-bearing privacy guarantee.

3b. What brokers see

Nothing below reaches a broker until you act, and it only ever reaches the one broker you acted on.

If you just click a broker's email or phone link, we record a lead for that broker holding the suburb and the time. The broker sees an anonymous enquiry - your name and contact details are not on it. We do still keep the row linked to your account on our side, so that if you go on to ask that same broker to contact you within a few minutes, the same lead becomes the consented one rather than a second row.

If you ask a broker to contact you, you first have to accept a consent request naming the broker and the suburb and asking you to confirm you want to be contacted, and you have to supply a phone number - we will not send the request without one. Accepting shares exactly this with that broker: your first name, your email address, your phone number, whether you told us that number is your own, your budget where you have given us one (buyers who have not set a budget, and anyone searching to rent, share no figure at all), and four answers from the wizard (your move timeline, whether you are also selling, whether you need to buy before you sell, and whether you have bid on anything recently). It also records the suburb and the time, as above. That is the complete list.

If a broker generates a property report for you, which needs either the consent above or your acceptance of a referral invitation from them, that report also carries your first name - or, if we do not hold a first name for you, a bare client number - and the ten preference weights you set in the wizard: safety, affluence, period character, renovated homes, childcare, fitness, health, hospitality, parks and retail.

Your household income band appears in none of this and is never sent to a broker. Your budget is a different field, and as listed above it is shared where you have set one - so a broker you have connected with may see a figure for what you plan to spend, even though your income band stays private.

You can withdraw at any time. Withdrawing removes your contact details and wizard answers from that broker's view and stops future reports including your preferences. It cannot recall a report already generated. There is no in-app withdrawal control yet - email support@nestfinder.au and we will action it.

3c. Climate-risk overlays (we don't collect or share)

We deliberately exclude climate-risk overlays from our scoring. Climate risk depends on house-specific assessment and we're suburb-level only. Treat this as a positive feature: scoring against a suburb-level climate proxy would mislead users about a fundamentally property-specific risk. If we ever change this stance, we will update this policy first and ship a separate opt-in flow, not bundle it into the existing search experience.

4. How long we keep it

  • Account data (email, name, password hash, Requirements, Preferences): retained for as long as your account is active. If you delete your account we remove the personal record within 30 days, save for the minimal audit log required by section 6.
  • Server logs: retained for 60 days, then rotated and discarded.
  • Error reports: retained by Sentry under their default retention (currently 90 days for free-tier projects).

5. Your rights under the Australian Privacy Principles

Under APP 12 and APP 13 you may:

  • Access the personal information we hold about you.
  • Correct any information you believe is inaccurate.
  • Delete your account and the personal data associated with it.
  • Withdraw consent to optional processing.
  • Complain to us first; if unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

To exercise any of these rights, email support@nestfinder.au. We will respond within 30 days.

6. Security

Passwords are stored hashed (PBKDF2 via Django's default password hasher). Traffic to and from the application is encrypted with TLS. Database backups are encrypted at rest. Access to production data is restricted to maintainers.

No system is perfectly secure. If we ever become aware of a notifiable data breach under the Notifiable Data Breaches scheme, we will notify affected users and the OAIC as required.

7. Children

Nestfinder is not intended for users under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, email support@nestfinder.au and we will remove it.

8. Cookies and similar technologies

We use a single session cookie for authentication. PostHog, when you accept the analytics consent banner, stores a first-party nf:analytics-consent key in localStorage plus its own distinct-id cookie/localStorage entry to deduplicate visits. We do not set any tracking or advertising cookies.

8b. Analytics event taxonomy

When analytics are enabled, we send PostHog the following named events along with anonymised page metadata. None of these events include the contents of your Requirements or Preferences forms.

  • wizard_step_view: which step of the onboarding wizard you are viewing.
  • wizard_submit_click: you pressed the final "Submit" button.
  • requirements_saved / preferences_saved: a save succeeded.
  • results_map_view: the ranked-map page rendered.
  • polygon_click: you clicked a postcode polygon (postcode included).
  • outbound_click: you clicked through to an external property portal from a postcode (target site + postcode included).
  • login / register: auth flow completed.

9. Changes to this policy

We will update this page when our practices change and bump the "Last updated" date at the top. Material changes will be announced in-app.

10. Data sources for property statistics

The property and demographic statistics displayed in Nestfinder are aggregated from public datasets; the datasets behind these statistics are named on the Methodology page.