paarvay · Ms Digital Crafts Pty. Ltd.
Privacy Policy
Effective: 22 June 2026
1.Who we are and what this policy covers
paarvay is operated by Ms Digital Crafts Pty. Ltd. (ABN 66 698 682 254, ACN 698 682 254), an Australian proprietary limited company with its registered office in Victoria, Australia. In this Privacy Policy, "paarvay", "we", "us", and "our" refer to Ms Digital Crafts Pty. Ltd.
This Privacy Policy describes how we collect, hold, use, and disclose personal information when you access or use:
- the paarvay website at https://paarvay.com;
- any related applications, APIs, integrations, or services we make available (together, the Service); and
- any communications you have with us in connection with the Service.
This policy does not apply to any third-party websites, products, or services that you may access through, or that may be integrated with, the Service — including, without limitation, services provided by Google, Supabase, Upstash, Resend, Pushover, Vercel, and Render. Those services are governed by their own privacy policies and terms, and we are not responsible for their privacy practices.
By accessing or using the Service, providing us with personal information, or otherwise interacting with us, you agree to the collection, use, and disclosure of your personal information in accordance with this Privacy Policy. You also confirm that you are at least 18 years of age. If you do not agree, you must not use the Service.
We comply with our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you have questions about this policy or how we handle your personal information, contact us at support@paarvay.com.
We may update this Privacy Policy from time to time in accordance with Section 9. The most current version is always available at https://paarvay.com/privacy.
2.The personal information we collect
We collect and generate personal information about you through a range of channels. The categories below are illustrative and not exhaustive — we may collect any other information you choose to provide to us, or that we reasonably consider necessary to operate, secure, improve, or evolve the Service. The specific information collected in any given case depends on how you use the Service.
2.1Information you provide directly
This includes (without limitation):
- Account information: your email address, display name, profile photo, and any other identifiers you supply. paarvay does not use passwords — sign-in is by one-time code (OTP) sent to your email, or via Google.
- Profile and preferences: suburbs you flag as interests, notification preferences, settings, and any other profile content you provide.
- Inspector applications (if you apply to inspect): biography, certifications, qualifications, service regions, and any supporting material you submit.
- Booking information: property address, slot, notes, instructions, and any other particulars relating to inspections you request, attend, or perform.
- Communications: the content of chat messages, attachments, files, links, images, and any other content you transmit through the Service, together with all correspondence you send to us by any channel.
- Anything else you submit to us. Any information you provide to us or make available to us — whether or not we asked for it — is treated as collected under this policy.
2.2Information we receive from Google when you sign in with Google
If you sign in with Google, we receive — at minimum — your Google account email address, name, profile picture URL, language and locale, and a stable Google-issued account identifier. We also receive and store the OAuth tokens necessary to authenticate your account. Google may provide additional information in accordance with its own terms and your Google account settings, and may change what it provides at any time without notice to us.
2.3Inspection meeting recordings
Inspection meetings conducted through the Service are recorded in full, including audio, video, screen-sharing, chat within the meeting, and all metadata generated by the meeting provider.
By joining an inspection meeting, you irrevocably:
- acknowledge that the meeting is being recorded;
- consent to the recording, storage, processing, transcription, analysis, use, and disclosure of the recording in accordance with this policy and our Terms of Service;
- waive any expectation of privacy in respect of anything you say, show, share, display, or transmit during the meeting; and
- agree that recordings are governed by Section 3.4 and our Terms of Service.
Inspector warranties. Each inspector who uses the Service warrants on a continuing basis that they have obtained the permission of the property owner, agent, or other person with authority to film on the property; will not deliberately record any private conversation of any person without that person's consent; will comply with the Surveillance Devices Act 1999 (Vic) and comparable legislation; and will not publish, broadcast, or distribute the recording or derivative material in a manner that identifies any person at the property without that person's consent or other lawful basis. Attendees and other participants give no equivalent warranty about other people at the property — they are not there.
You should not say, show, or share anything during an inspection meeting that you do not want recorded, stored, and potentially disclosed in accordance with this policy and our Terms of Service.
2.4Information collected automatically
When you access or use the Service, we and our service providers automatically collect technical and usage information. This includes (without limitation):
- IP address, device identifiers, device and browser type and version, operating system, language, time zone, screen resolution, and other technical attributes that may be used to identify or fingerprint your device;
- approximate location inferred from your IP address or other technical signals;
- session identifiers, authentication tokens, the date, time, and duration of each access, and the pages, features, content, and actions accessed or taken;
- performance, crash, latency, and error telemetry; and
- cookies, local storage, and similar technologies for authentication, security, performance, analytics, and similar purposes. You can configure your browser to refuse cookies, but parts of the Service may not function correctly if you do.
2.5Information generated for security, abuse prevention, and legal purposes
We may collect, generate, and retain information that we consider necessary to detect, investigate, prevent, or respond to fraud, abuse, security incidents, unauthorised access, breaches of our Terms of Service, complaints, disputes, and legal claims. This may include device fingerprints, behavioural patterns, signal correlations across accounts, and records of communications, even where you have asked us to delete other information.
2.6Information we receive from third parties
We may receive information about you from:
- identity, authentication, and login providers (for example, Google);
- our infrastructure, communications, and operations providers (for example, Supabase, Upstash, Vercel, Render, Resend, Pushover);
- payment, dispute, or risk-scoring providers we may use from time to time;
- publicly available sources, including without limitation the Australia Post Postcode dataset; and
- any other person or organisation that lawfully provides information about you to us.
We make no representation or warranty as to the accuracy, completeness, currency, or lawfulness of information we receive from any third party, and we are not responsible for any third party's collection or handling of your information, even where that third party is integrated with or accessible through the Service.
2.7Sensitive information
paarvay does not seek to collect sensitive information as defined under the Privacy Act 1988 (Cth) (including, without limitation, information about health, racial or ethnic origin, religious or philosophical beliefs, political opinions, sexual orientation or practices, criminal record, and biometric information).
However, you may at your own risk disclose sensitive information through the Service — for example, by including it in chat messages, profile content, support correspondence, or what you say, show, or share during an inspection meeting. If you do, you expressly consent to our collection, use, storage, and disclosure of that sensitive information in accordance with this policy.
2.8Combination, de-identification, automated processing, and analytics
We may at any time:
- combine any personal information we hold about you with other information we hold or receive about you, from any source, for the purposes described in this policy;
- de-identify or aggregate personal information into datasets from which you cannot reasonably be re-identified. Once de-identified or aggregated, that data is no longer personal information and is not subject to this policy. We may use, share, sell, or retain it for any purpose, without limit; and
- apply automated processing, including without limitation artificial intelligence, machine learning, profiling, and analytics, to any information we hold or generate, for any purpose described in this policy.
2.9Anonymity and pseudonymity
Where it is lawful and practicable to do so, you have the option of dealing with us without identifying yourself, or by using a pseudonym. It is not lawful or practicable for us to deal with you on that basis for any of the core functions of the Service — including, without limitation, creating an account, booking or performing an inspection, joining a meeting, or receiving notifications — and we will require you to identify yourself in those cases.
2.10Children
The Service is intended for people aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided personal information to us, please contact support@paarvay.com and we will take steps we consider appropriate to delete it.
2.11Choosing not to provide information
You are not required to provide personal information to us. However, if you choose not to provide information that we ask for or that we need to operate the Service (for example, an email address to create an account, or a property address to book an inspection), we may not be able to provide all or part of the Service to you, and we will not be liable to you for any consequence of that.
2.12Changes to what we collect
The categories of information we collect may evolve as the Service evolves. By continuing to use the Service after a change to this policy or to our collection practices, you are deemed to accept the change in accordance with Section 9.
3.How we use your personal information
We may collect, use, hold, process, disclose, transfer, and otherwise deal with personal information for the purposes set out in this section, for any other purpose disclosed to you at the time of collection, for any purpose required or authorised by or under law, and for any purpose to which you have consented.
The list of purposes below is illustrative and not exhaustive. Each purpose is independent — the absence of any particular purpose from this section does not preclude us from acting on it, and we are not required to choose the least-intrusive use available to achieve a given outcome. We may apply any one or more of these purposes at the same time, at our sole and absolute discretion.
In this section, references to "we", "us", and "our" include Ms Digital Crafts Pty. Ltd., its related bodies corporate (as defined in the Corporations Act 2001 (Cth)), its successors, assigns, and any person to whom paarvay or any part of it is sold, assigned, or transferred.
3.1To provide and operate the Service
Including, without limitation, to:
- create, authenticate, secure, configure, and manage your account, including processing email one-time codes and the Google OAuth sign-in flow;
- enable you to use the Service, including booking, scheduling, claiming, performing, joining, recording, storing, retrieving, and reviewing inspections;
- match attendees with inspectors, surface relevant suburbs, properties, and slots, operate the inspector queue, and apply any ranking, prioritisation, filtering, or matching logic, including logic that is automated and operates without human review;
- generate, schedule, host, record, transcribe, index, store, analyse, and play back inspection meetings;
- deliver in-app, email, push, and any other notifications we consider appropriate;
- process payments, refunds, payouts, fees, taxes, chargebacks, and any other financial transactions; and
- maintain, host, monitor, support, troubleshoot, modify, change, withdraw, evolve, and improve the Service in any manner we consider appropriate.
3.2To secure the Service, prevent abuse, and protect our rights
Including, without limitation, to:
- detect, investigate, prevent, mitigate, and respond to actual, threatened, or suspected fraud, abuse, harassment, spam, malware, security incidents, unauthorised access, scraping, automated access, account takeover, identity misuse, money laundering, sanctions evasion, or any other unlawful, harmful, or prohibited activity, whether involving you or any other person;
- monitor activity on the Service — including, without limitation, account behaviour, message and chat content, file uploads, sign-in patterns, device signals, and the content and conduct of inspection meetings — for any of the purposes in this section;
- enforce our Terms of Service, this Privacy Policy, and any other agreement, policy, rule, or determination applicable to the Service;
- verify, re-verify, and assess your identity, eligibility, and the accuracy of information you provide;
- investigate complaints, disputes, chargebacks, and reported safety concerns;
- maintain logs, audit trails, and evidentiary records that we consider necessary for any of the above, including after you stop using the Service and including information you have asked us to delete; and
- restrict, throttle, suspend, terminate, ban, or block any account, device, or person, in our sole and absolute discretion, with or without notice or reason.
3.3To communicate with you
Including, without limitation, to:
- send you transactional, security, and operational communications — for example, sign-in codes, booking confirmations, inspector-claim alerts, notification emails, recording-ready alerts, incident notices, policy-change notices, and other communications we consider necessary or appropriate. You cannot opt out of these communications while you have an active account. If you do not want to receive them, your only remedy is to close your account in accordance with our Terms of Service;
- respond to your enquiries, requests, complaints, support tickets, and any other correspondence; and
- send you marketing, promotional, product-update, research, survey, recruitment, partner, or referral communications about the Service. You may opt out of marketing communications at any time by using the unsubscribe link in the relevant message or by emailing support@paarvay.com. Opting out of marketing does not stop transactional, security, or operational communications.
3.4To use inspection meeting recordings and meeting-derived information
Without limiting any other section of this policy or our Terms of Service, we may use, store, retain, copy, reproduce, transcribe, translate, summarise, redact, edit, excerpt, analyse, index, embed, vectorise, and disclose inspection meeting recordings (and any audio, video, image, transcript, summary, embedding, dataset, voiceprint, facial-geometry signature, or other information derived from them) for any of the following purposes, or any other purpose we consider related or incidental:
- making the recording or derived content available to participants of the inspection, and to any other person we consider entitled to access it;
- investigating, responding to, and resolving any complaint, dispute, claim, or query relating to the inspection, the property, the attendees, the inspector, or any other matter;
- investigating, responding to, and acting on safety concerns, abuse, harassment, misconduct, or any actual or suspected breach of our Terms of Service;
- service quality monitoring, complaint review, safety review, and improvement of the Service (we do not performance-manage, coach, evaluate, train, or direct inspectors in the legal sense of any of those words — see Section 2.3 of the Terms);
- training, testing, evaluating, fine-tuning, deploying, operating, and improving automated systems, including artificial intelligence and machine-learning models, whether operated by us, by our service providers, or by parties to whom we license access — provided that any external use is, where reasonably practicable, on a de-identified or aggregated basis;
- product research, analytics, feature development, benchmarking, and demonstration;
- complying with our legal and regulatory obligations and exercising or defending any legal right or claim;
- providing the recording or derived content to law-enforcement agencies, regulators, courts, public authorities, or any other person where we believe disclosure is required, requested, lawful, appropriate, or in the interests of safety;
- transferring the recording or derived content to a successor or acquirer of paarvay in connection with a corporate transaction; and
- any other purpose described in this policy, in our Terms of Service, or disclosed at the time you join the meeting.
By participating in an inspection meeting, you expressly consent to:
- the collection, use, and disclosure of any sensitive information (including, without limitation, biometric information such as voiceprints and facial-geometry signatures) that may be derived from the recording for any of the purposes set out in this section;
- the recording being retained indefinitely, used for any of the purposes above after you stop using the Service, and used after you delete other personal information held by us; and
- (to the maximum extent permitted by law) all acts and omissions by us, our personnel, and our service providers in relation to the recording that would otherwise infringe any moral rights, performance rights, image rights, publicity rights, or similar rights that you may have in the recording or its contents.
3.5To improve the Service and develop new products
Including, without limitation, to:
- analyse usage patterns, measure engagement, monitor performance, and run experiments, A/B tests, and other research;
- conduct product research and develop, test, launch, evolve, withdraw, and commercialise new features, products, services, integrations, datasets, and business lines;
- train, evaluate, fine-tune, deploy, operate, and improve automated systems, including artificial intelligence and machine-learning models; and
- generate de-identified or aggregated datasets in accordance with Section 2.8, which we may then use, license, sell, share, publish, or otherwise commercialise for any purpose without further notice or compensation to you.
3.6To comply with law and protect rights
Including, without limitation, to:
- comply with our legal, regulatory, contractual, tax, accounting, audit, recordkeeping, and reporting obligations;
- respond to lawful requests by courts, law-enforcement agencies, regulators, public authorities, and other competent bodies, in Australia or overseas;
- establish, exercise, and defend legal rights, claims, and proceedings, whether brought by, against, or involving us, you, an inspector, an attendee, a property owner, or any other person; and
- protect the rights, property, safety, security, reputation, and interests of paarvay, our personnel, our service providers, our users, and the public.
3.7Safety and emergencies
We may collect, use, and disclose personal information where we believe, in our sole and absolute discretion, that doing so is necessary or appropriate to:
- prevent or address an actual, threatened, or suspected risk of harm to any person or property;
- respond to a medical, safety, security, or other emergency; or
- protect the vital interests of any individual.
We may take any of these actions without notice to you, and we are under no obligation to verify the existence or seriousness of the risk before doing so.
3.8Other purposes you would reasonably expect
Consistent with Australian Privacy Principle 6, we may use or disclose personal information for any secondary purpose that is related to a primary purpose for which it was collected (or, in the case of sensitive information, directly related) and that you would reasonably expect in the circumstances.
3.9Corporate transactions and successors
We may transfer, assign, license, or otherwise disclose all or any of the personal information we hold to any actual or prospective successor, acquirer, financier, investor, partner, joint venturer, lender, or other counterparty to any actual or prospective merger, acquisition, sale, financing, reorganisation, restructuring, insolvency, or other corporate transaction or arrangement involving paarvay or any part of its business or assets. We may disclose personal information to such persons on a confidential basis for due-diligence purposes prior to any such transaction.
3.10Other purposes you consent to; withdrawal of consent
We may use or disclose personal information for any other purpose to which you have consented, whether in advance or at the time of use. Consent may be express or implied, including (without limitation) implied by your continued use of the Service after a change to this policy or after the introduction of a feature with a clearly described purpose.
Where our use of your personal information is based on your consent, you may withdraw that consent at any time by contacting us at support@paarvay.com. Withdrawal of consent:
- operates only prospectively, and does not affect the lawfulness of any use or disclosure made before withdrawal;
- does not require us to delete or stop using any information that we are otherwise entitled or required to retain or use, including for the purposes described in Sections 3.2, 3.4, 3.5, 3.6, 3.7, and 3.9;
- may take a reasonable period to give effect to; and
- may result in us being unable to provide all or part of the Service to you, in which case Section 2.11 applies, and we will have no liability to you of any kind for the consequences.
3.11Targeted advertising and audiences
We may share contact details or other identifiers (in hashed, encrypted, or other technically protected form) with advertising platforms, social-media platforms, and other third parties to create, target, and measure custom and look-alike audiences for marketing the Service. Where required by law, we will obtain your consent to do so or offer you an opt-out.
3.12Cross-border use
We may use, host, process, and store personal information anywhere in the world for any of the purposes set out in this policy, subject to the disclosures in Section 4 below.
4.How we share and disclose your personal information
We may share, disclose, transfer, license, and otherwise make available your personal information to the recipients described in this Section 4, and to any other person to whom you have consented, to whom we are required or authorised by or under law to disclose, or to whom we reasonably consider disclosure necessary, appropriate, or incidental for any of the purposes set out in Section 3.
The categories of recipient below are illustrative and not exhaustive. We may add, change, replace, or remove recipients (including service providers, sub-processors, and the countries in which they operate) at any time, in our sole and absolute discretion, and without notice to you. Each disclosure described in this section is independent and severable. If any disclosure, consent, or part of this section is held to be invalid, all other disclosures and consents remain in full force and effect.
Recipients of personal information under this Section 4 are not parties to, and are not bound by, this Privacy Policy. Once personal information has been disclosed to a recipient, that recipient's handling of the information is governed by its own terms, privacy policy, and applicable law, and is not within our control.
4.1Other users of the Service
Some personal information you provide will be visible to other users of the Service in the ordinary course of its operation. This includes (without limitation):
- your display name, profile photo, and (if you apply to be an inspector) your inspector biography, certifications, qualifications, and service regions;
- the content of chat messages and attachments you send in an inspection, which is visible to the other participant of that inspection;
- the property address, slot, and booking details associated with an inspection, which are visible to the inspector who claims it, to any other person authorised to view the inspector queue, and to our personnel; and
- your participation in, and contributions to, any inspection meeting recording, which may be visible to other participants and to any other person to whom we make the recording available under Section 3.4.
Other users are not bound by this Privacy Policy and owe no obligations to you under it. You are solely responsible for the consequences of any information you choose to make visible to, or share with, other users. There is no expectation of privacy between you and other users in respect of information shared through the Service.
4.2Our service providers and sub-processors
We disclose personal information to third parties that provide infrastructure, hosting, communications, identity, analytics, payments, monitoring, security, support, automated-processing, AI/ML, advertising, marketing, and other services to us. As at the effective date of this policy, those providers include (without limitation):
- Google LLC and its affiliates (United States; global infrastructure) — for OAuth sign-in, video meetings (Google Meet), calendar scheduling (Google Calendar), recording storage and retrieval (Google Drive), and related services;
- Supabase, Inc. (incorporated in the United States; the paarvay PostgreSQL database and object-storage buckets are hosted in Sydney, Australia; corporate, support, and administrative access may occur from the United States and elsewhere) — for managed database and storage;
- Upstash, Inc. (incorporated in the United States; the paarvay Redis instance is hosted on AWS in Sydney, Australia (ap-southeast-2); corporate, support, and administrative access may occur from the United States and elsewhere) — for in-memory data storage, key-value caching, pub/sub event delivery, and presence and typing-indicator state;
- Vercel Inc. (United States; global edge infrastructure) — for hosting and serving the paarvay web application;
- Render Services, Inc. (incorporated in the United States; the paarvay server compute is hosted in Singapore; corporate, support, and administrative access may occur from the United States and elsewhere) — for hosting and serving the paarvay server application;
- Resend, Inc. (United States) — for transactional and notification email delivery;
- Superblock Systems, Inc. (Pushover) (United States) — for operational push notifications to our personnel;
- payment, analytics, monitoring, support, security, advertising, and AI/ML providers, as engaged from time to time; and
- any other service provider, contractor, agent, consultant, sub-processor, or sub-sub-processor we engage, or that any of the above providers engages, for any purpose described in this policy.
Our service providers and their sub-processors may engage further sub-processors of their own. We do not maintain, and are not required to maintain or disclose to you, a current, accurate, or complete list of all sub-processors in our supply chain at any given time. By using the Service, you consent to disclosure of your personal information to any such sub-processor, regardless of identity, location, or function.
4.3Professional advisers, insurers, financiers, and related parties
We may disclose personal information to our lawyers, accountants, auditors, tax advisers, insurers, brokers, financiers, lenders, investors, advisers, and other professional and related parties, in each case on a confidential basis, for any purpose described in Section 3.
4.4Successors, acquirers, and prospective counterparties
We may disclose personal information to any actual or prospective successor, acquirer, financier, investor, partner, joint venturer, lender, administrator, liquidator, receiver, or other counterparty in connection with any actual or prospective merger, acquisition, sale, financing, reorganisation, restructuring, joint venture, partnership, insolvency, administration, liquidation, receivership, or other corporate transaction or arrangement involving paarvay or any part of its business or assets, including for due-diligence purposes.
We are not required to seek your consent, give you notice, or offer you any opportunity to object to any disclosure under this section, whether or not the transaction or arrangement ultimately proceeds.
4.5Law enforcement, regulators, public authorities, and dispute counterparties
We may disclose personal information to courts, tribunals, law-enforcement agencies, regulators, public authorities, government bodies, intelligence services, taxation authorities, dispute-resolution bodies, and other competent persons, in Australia or overseas, where we believe in our sole and absolute discretion that disclosure is required, requested, permitted, lawful, appropriate, or in the interests of safety, security, or our legal or commercial interests.
We may also disclose personal information to any other party to actual, threatened, or anticipated legal proceedings, complaints, claims, or disputes (whether involving us or any other person), for the purposes of investigating, responding to, exercising rights in, or defending those proceedings.
We may make any disclosure under this section with or without notice to you, and we are under no obligation to:
- challenge, test, narrow, or seek to set aside the validity, scope, or proportionality of any request or order before complying;
- verify the existence, accuracy, or seriousness of any underlying matter before disclosing;
- inform you that a disclosure has been made, whether at the time, in advance, or afterwards;
- comply with any non-disclosure or gag obligations imposed by an authority by also concealing the existence of that obligation from you; or
- consider, weigh, or balance your interests against the requester's, the public's, or our own.
4.6Anyone you authorise, or who appears to be authorised
We may disclose personal information to anyone you direct or consent to us disclosing it to, including (without limitation) any person identified by you when you use a feature of the Service that involves sharing information with that person. We may also disclose personal information to any person we reasonably believe to be acting on your behalf or with your authority, even if that person is not in fact acting on your behalf or with your authority, and we are not liable to you for any disclosure made in good faith on that basis.
4.7De-identified and aggregated data
We may share, license, sell, publish, distribute, or otherwise commercialise de-identified or aggregated data (including data derived from inspection meeting recordings, chat content, usage data, and any other personal information we hold) with any person, in any country, for any purpose, on any terms, without limit and without further notice or compensation to you, in accordance with Section 2.8.
4.8Disclosure overseas (APP 8)
Many of the recipients described in this Section 4 are located, operate from, are incorporated in, store, host, process, access, or otherwise deal with personal information in countries outside Australia. As at the effective date of this policy, the countries to which your personal information may be disclosed (or in which it may be accessed) include (without limitation):
- Australia — including, without limitation, the Sydney-hosted Supabase database and object-storage buckets, and the Sydney-hosted Upstash Redis instance, that hold the operational data of the Service;
- the Republic of Singapore — including, without limitation, the Render-hosted compute that runs the paarvay server application;
- the United States of America — where Google LLC, Vercel Inc., Render Services, Inc., Supabase, Inc., Upstash, Inc., Resend, Inc., Superblock Systems, Inc., and many of our other current and prospective service providers and sub-processors are incorporated, headquartered, or operate corporate, administrative, support, engineering, or infrastructure functions;
- any country in which any of our service providers, sub-processors, advisers, affiliates, related bodies corporate, successors, acquirers, financiers, advertising or AI/ML providers, or other recipients identified in this Section 4 are located, operate from, or maintain personnel, infrastructure, or data centres from time to time; and
- any country to which personal information may transit through global content-delivery networks, edge computing, email routing, push-notification, telecommunications, or similar networks during the ordinary operation of the Service.
By accessing or using the Service, providing personal information to us, or otherwise interacting with us, you expressly consent under Australian Privacy Principle 8.2(b) to the disclosure of your personal information to overseas recipients in the countries identified in this Section 4.8 (and in any other country in which a recipient is located, operates from, or maintains infrastructure from time to time), on the basis that:
- you acknowledge that you have been clearly and prominently informed of the consequences of providing this consent;
- Australian Privacy Principle 8.1 will not apply to such disclosures;
- section 16C of the Privacy Act 1988 (Cth) (which would otherwise make us accountable in respect of acts and practices of overseas recipients) will not apply to such disclosures;
- we will not be liable to you for any act, omission, or breach (whether of the Australian Privacy Principles, this policy, applicable law, or otherwise) of any overseas recipient in relation to your personal information; and
- to the maximum extent permitted by law, you release us from, and waive, any claim, demand, action, suit, or proceeding you may have against us in respect of any such act, omission, or breach of any overseas recipient.
If you do not consent to the disclosures and waivers described in this Section 4.8, you must not access or use the Service.
We may, at any time and without notice to you, change the recipients of overseas disclosures, the countries in which those recipients are located, the categories of information disclosed, and the purposes for which disclosure is made.
4.9Aggregation with other users' information
We may disclose your personal information in combination, bundled, or aggregated with personal information about other users, properties, inspections, recordings, or other matters, and we are not required to disaggregate, segregate, or separate your information for the purposes of any disclosure described in this Section 4.
4.10Other disclosures
We may disclose personal information for any other purpose described in this policy, in our Terms of Service, or otherwise disclosed to you at the time of collection.
5.How we hold your personal information and how long we keep it
This Section 5 describes, at a high level, where and how we hold personal information and how long we retain it. Nothing in this Section 5 is a representation, warranty, undertaking, covenant, guarantee, or commitment about any particular retention period, deletion practice, holding arrangement, or operational standard, and we may change any of them at any time, in our sole and absolute discretion, without notice to you. Nothing in this Section 5 gives rise to any obligation that exceeds the minimum we are strictly required to meet under the Privacy Act 1988 (Cth). No standard described in any other source — including, without limitation, industry guidance, professional codes, "best practice", "reasonable care", or comparable standards — applies to us in respect of the matters in this Section 5, except to the extent that the Privacy Act 1988 (Cth) strictly requires it.
5.1Where personal information is held
We hold personal information in the manner, locations, and arrangements described in Section 4 (and any subsequent disclosures we make from time to time), including (without limitation):
- on the Sydney-hosted Supabase PostgreSQL database and object-storage buckets that hold the operational data of the Service;
- on the Sydney-hosted Upstash Redis instance for in-memory state, pub/sub, and presence;
- on the Singapore-hosted Render compute that runs the paarvay server application;
- in the systems of, and infrastructure operated by or for, the other service providers and sub-processors described in Section 4 and engaged from time to time, including in any country in which they operate;
- in active production systems, transient and persistent caches, in-memory data stores, key-value stores, pub/sub channels, event buses, presence and typing-indicator stores, queues, message brokers, search indices, vector stores, derivative datasets, machine-learning model artefacts, model weights, prompts, training corpora, redundancy replicas, disaster-recovery copies, backups, archives, audit logs, security records, dispute records, and any other operational store we maintain or that any of our service providers maintains; and
- in the systems of any third party to whom we have disclosed personal information under Section 4, which we do not control and for which we are not responsible.
We may at any time, and without notice to you, move, replicate, mirror, cache, copy, archive, transcode, transform, vectorise, embed, or otherwise duplicate personal information across or between any of these locations, providers, jurisdictions, and storage forms.
5.2Form in which personal information is held
We hold personal information primarily in electronic form. We may also hold personal information in physical form, and we may convert personal information between electronic and physical form at any time. Personal information may exist simultaneously in multiple copies, derivatives, summaries, embeddings, transcripts, indexes, models, and aggregations. You acknowledge that you have no right to require us to hold personal information in any particular form, on any particular medium, with any particular provider, in any particular location, with any particular level of redundancy, or with any particular level of accessibility.
5.3How long we keep personal information — general principle
We retain personal information for as long as we consider it necessary, useful, appropriate, prudent, convenient, or required for any of the purposes set out in Section 3, this policy, our Terms of Service, or any other purpose we may identify from time to time (including purposes not yet known to us at the effective date of this policy), or for any other purpose required, authorised, or permitted by law. We are not required to apply, and do not undertake to apply, any data-minimisation principle beyond what the Privacy Act 1988 (Cth) strictly requires of us.
The categories below are illustrative only. They describe our general practice as at the effective date of this policy, but are not binding undertakings.
- Account information (email, name, profile photo, preferences, suburb interests, settings) — retained for as long as you have an account, and for so long after you stop using the Service or close your account as we consider necessary (which may be indefinitely).
- Inspection records and metadata (bookings, slot details, property addresses, status history, inspector assignments, chat messages and attachments, notifications) — retained for as long as we consider necessary (which may be indefinitely).
- Inspection meeting recordings and content derived from them (including transcripts, summaries, embeddings, voiceprints, facial-geometry signatures, training datasets, model weights derived from them, and analytic outputs) — retained indefinitely, in accordance with Section 3.4, and not subject to any deletion request.
- OAuth tokens, session tokens, sign-in records, and verification artefacts — retained for as long as we consider necessary for authentication, security, audit, and abuse-prevention purposes.
- Logs, telemetry, audit trails, security records, abuse-investigation records, dispute records, and complaint records — retained for as long as we consider necessary.
- Backups, disaster-recovery copies, replicas, and archives — overwritten, rotated, or refreshed in accordance with our then-current operational practices, which may result in personal information persisting in these systems for an extended period after it has been removed from active production systems.
- De-identified and aggregated data — once de-identified or aggregated in accordance with Section 2.8, the resulting data is no longer personal information and may be retained, used, shared, sold, licensed, or otherwise dealt with indefinitely, without limit.
5.4Retention after account closure or deletion request
Closing your account, or asking us to delete personal information, does not require us to delete, and does not result in deletion of, personal information that we are entitled or required to retain. We may continue to hold and use personal information after account closure or a deletion request for any purpose described in Section 3, including (without limitation):
- maintaining inspection meeting recordings and content derived from them in accordance with Section 3.4;
- maintaining logs, telemetry, audit trails, security records, abuse-investigation records, and dispute records;
- complying with our legal, regulatory, tax, accounting, audit, recordkeeping, and reporting obligations;
- exercising, defending, or responding to legal rights, claims, complaints, and proceedings, including those that may arise in the future;
- preventing, detecting, investigating, and responding to fraud, abuse, harassment, safety risks, and other prohibited conduct;
- enforcing our Terms of Service and any other applicable agreement, policy, or rule;
- retaining records that we consider necessary or useful to evidence your previous consent, conduct, identity, account state, transactions, or use of the Service; and
- providing information to other users who participated with you in any inspection, communication, or other interaction on the Service, where we consider that those other users are entitled or would reasonably expect to continue to have access to that information.
5.5Limits on deletion
Even where we agree, or are required, to delete personal information, you acknowledge and agree that:
- "Deletion" means marking personal information as inactive, deleted, or unavailable in our active production systems. It does not require, and does not include, the overwriting, shredding, forensic destruction, or irreversible removal of personal information from backups, replicas, caches, archives, derivative datasets, or any other system in which it may exist;
- personal information may persist in backups, disaster-recovery copies, replicas, archives, audit logs, security records, caches, in-memory data stores, key-value stores, pub/sub channels, event buses, presence and typing-indicator stores, queues, message brokers, search indices, vector stores, model artefacts, model weights, derivative datasets, and other operational stores for an extended period — potentially indefinitely;
- personal information may be unintentionally re-introduced into active systems through the restoration of a backup, the re-import of data from a service provider, or any other operational event, and any such re-introduction is not a breach of this policy or of any obligation we owe you;
- de-identified or aggregated data derived from your personal information is not personal information and is not subject to deletion;
- personal information that has been disclosed to a third party under Section 4 will continue to be held by that third party, on terms outside our control, and we are not responsible for, and cannot guarantee, the deletion of any personal information from any third party's systems;
- personal information held in inspection meeting recordings, transcripts, embeddings, model weights, and derivative materials is retained in accordance with Section 3.4 and is not subject to any deletion request;
- personal information that we are required or entitled to retain for legal, regulatory, security, abuse-prevention, dispute, consent-evidence, or other purposes described in Section 5.4 or otherwise in this policy is not subject to deletion;
- we may decline any deletion request, in whole or in part, in our sole and absolute discretion, and we are not required to give reasons for any such decision beyond those required by law; and
- we do not warrant, represent, or undertake that any deletion is permanent, irreversible, forensically complete, or recoverable-proof.
5.6No warranty as to retained or deleted information
We do not warrant, represent, or undertake that personal information we hold, retain, or delete is or will be accurate, complete, current, intact, retrievable, accessible, or fit for any purpose; maintained in any particular form, format, structure, location, jurisdiction, provider, redundancy, accessibility, or quality; available for retrieval, export, or production within any particular time, or at all; protected against loss, corruption, degradation, inaccessibility, or destruction; produced or made available in any particular form, format, language, or medium; or protected against re-introduction following backup restoration, service-provider re-sync, or other operational event.
You bear the entire risk of, and we are not liable for, any loss, corruption, degradation, inaccessibility, unavailability, destruction, or re-introduction of personal information, however caused, except to the extent that liability cannot lawfully be excluded.
5.7Legal holds, limitation-period retention, and evidence
We may, in our sole and absolute discretion, place any personal information under a legal hold, regulator hold, internal-investigation hold, or other retention hold, and we may do so without notice to you. While a hold is in place, we are not required to delete, anonymise, or alter the held information.
We may retain personal information for the limitation period applicable to any actual, threatened, anticipated, or potential claim, complaint, or proceeding involving us, plus such additional period as we consider appropriate.
We may retain personal information specifically to evidence (i) your consent to any matter described in this policy, our Terms of Service, or any other agreement, (ii) your conduct on or in relation to the Service, (iii) our compliance with any obligation, (iv) any disclosure we have previously made under Section 4, (v) the contents of any communication between us and you or any other person, and (vi) any other matter we consider material to our legal or commercial interests.
5.8Events outside our control
Our retention, holding, and deletion practices may be affected, suspended, modified, or rendered impossible by events outside our reasonable control, including (without limitation) outages, system failures, data loss, security incidents, sanctions, government orders, court orders, regulator action, insolvency or failure of a service provider, force majeure events, and acts or omissions of third parties. We are not liable for any consequence of any such event.
5.9Requests — declination, cost recovery, and vexatious requests
We may decline, defer, or aggregate any request relating to the holding, retention, or deletion of personal information where we consider, in our sole and absolute discretion, that the request:
- is repetitive, manifestly unfounded, vexatious, or frivolous;
- is part of a mass, coordinated, automated, or organised campaign;
- is made for a purpose other than the protection of the requester's own personal information;
- would impose excessive cost or operational burden on us relative to the value of compliance;
- relates to information we are entitled or required to retain under this policy or otherwise; or
- cannot be satisfied without disclosing personal information of, or otherwise prejudicing, another person.
We may charge a reasonable fee to recover the cost of complying with any non-trivial request, except to the extent that the Privacy Act 1988 (Cth) prohibits us from doing so. We are not required to maintain or produce historical retention metadata, deletion logs, internal records, or any other record of our retention practices, except to the extent strictly required by law.
5.10Right to change
We may at any time, and without notice to you, change the manner, location, form, jurisdiction, provider, redundancy, retention period, deletion practice, request-handling practice, and any other aspect of how we hold personal information. No such change is a breach of this policy or any obligation we owe you. Continuing to use the Service after any such change is deemed acceptance of it in accordance with Section 9.
6.Security of personal information
6.1The standard that applies to us
We take such steps as are reasonable in the circumstances to protect personal information we hold from misuse, interference, loss, and unauthorised access, modification, or disclosure, in accordance with Australian Privacy Principle 11. That standard, and that standard alone, governs our security obligations to you. No other standard, expectation, or undertaking applies, including (without limitation) any industry guidance, code of practice, security framework, certification, "best practice", "reasonable care", "state of the art", or comparable standard — except to the extent that the Privacy Act 1988 (Cth) strictly requires it.
What constitutes reasonable steps in any given case is determined by us in our sole and absolute discretion by reference to our specific circumstances, capabilities, resources, and threat assessment at the relevant time, and not by reference to any external benchmark, peer comparison, hypothetical alternative, or what any other person takes, claims to take, or could take.
6.2No guarantee of security
Notwithstanding any steps we take, we do not warrant, represent, undertake, or guarantee that:
- the Service or any part of it is, or will remain, secure, private, confidential, or free from unauthorised access, modification, disclosure, loss, or destruction;
- any personal information we hold, transmit, process, or disclose is, or will remain, secure, accurate, complete, available, or protected from any threat;
- any specific security control, technology, certification, accreditation, encryption, authentication, monitoring, audit, or other measure is, will be, or will remain in place;
- the Service is suitable for the transmission, storage, or processing of any particular category of information; or
- any security incident will be detected, prevented, mitigated, contained, investigated, or notified within any particular time, in any particular manner, or at all (except to the extent expressly required by law).
The internet, public telecommunications networks, and electronic systems are inherently insecure. You acknowledge this, and acknowledge that you transmit personal information to and through the Service at your own risk.
You also acknowledge that we may be the target of organised, well-funded, persistent, or state-sponsored attacks. We are not required to defend against any such attack at any particular level, and we are not liable for any consequence of any such attack.
6.3Your responsibility for your account and credentials
You are solely responsible for the security of your account, the email address used to receive one-time codes, your Google account (if you sign in with Google), the devices on which you access the Service, and any other credential, code, link, or token that permits access to your account. You must (without limitation):
- keep your sign-in email address and any associated email account secure, and use a strong, unique password and multi-factor authentication on it;
- not share, forward, screenshot, or otherwise disclose one-time codes, magic links, session tokens, or other authentication credentials to any person, including (without limitation) anyone purporting to be from paarvay;
- not allow any other person to access or use your account;
- log out of the Service on any shared, public, or untrusted device;
- promptly notify us at support@paarvay.com if you suspect any unauthorised access; and
- take any other steps a reasonable person would take to keep their account and credentials secure.
Any failure on your part to do these things is at your sole risk. We are not liable for any loss, damage, or other consequence arising from any unauthorised access to, or use of, your account, your email, your Google account, your devices, or your credentials, whether or not that access was preventable by us.
Account recovery. We are under no obligation to recover, restore, transfer, unlock, or grant access to any account that has been compromised, is suspected of being compromised, or has been suspended or terminated. We may decline any recovery request in our sole and absolute discretion.
6.4Acts of other users
We are not responsible for any act or omission of any other user of the Service, including (without limitation) any unauthorised use, disclosure, copying, recording, screen-capturing, redistribution, or onward transmission of any personal information you share with that user through the Service. There is no expectation of security or confidentiality between you and other users, and we do not, and cannot, control what other users do with information shared with them.
6.5Acts and omissions of service providers and sub-processors
Our service providers and sub-processors (including those identified in Section 4.2) maintain their own security arrangements, which are outside our control. We do not warrant, and are not responsible for, the security practices, controls, certifications, or performance of any service provider or sub-processor. We have no liability to you for any act, omission, breach, incident, failure, or compromise of any service provider or sub-processor in relation to your personal information, except to the extent that liability cannot lawfully be excluded.
6.6No undertaking to monitor, test, audit, or certify
We are under no obligation to:
- monitor the Service, any account, session, device, or communication for security incidents, abuse, or any other matter (and any monitoring we do conduct is voluntary, may be ad hoc or selective, and may be discontinued at any time);
- conduct, commission, repeat, or maintain any penetration test, security audit, vulnerability assessment, code review, threat model, risk assessment, security certification, accreditation, or comparable activity;
- assess, document, communicate, or warn you of any specific security risk, threat, vulnerability, or limitation;
- operate, participate in, or reward any bug bounty programme, vulnerability disclosure programme, or comparable arrangement; or
- adopt, implement, or comply with any framework, standard, or recommendation made by any third party.
6.7Vulnerabilities discovered by you
If you discover, identify, or suspect any security vulnerability, weakness, or incident in or affecting the Service, you must:
- immediately and confidentially report it to us at support@paarvay.com;
- not publish, distribute, demonstrate, exploit, retain, or disclose to any other person any details of the vulnerability, weakness, or incident, or any information obtained through it;
- not access, attempt to access, or interact with any personal information of any other person; and
- comply with any reasonable direction we give you in connection with the matter.
We are under no obligation to acknowledge any such report, to investigate, to remediate, to compensate, or to take any other action. Conducting unauthorised security research on or against the Service is a breach of our Terms of Service, and you are responsible for all consequences of doing so.
6.8Our right to act on security signals
We may, at any time and in our sole and absolute discretion, with or without notice to you and with or without giving reasons:
- suspend, lock, restrict, throttle, terminate, or close any account or session;
- require additional authentication, re-verification, or proof of identity;
- block, restrict, or ban any device, network address, browser, or person;
- preserve, isolate, copy, examine, or analyse data, sessions, communications, devices, or any other artefact;
- engage automated systems, including artificial intelligence and machine-learning models, to detect and respond to actual or suspected security risks;
- cooperate with, share information with, and refer matters to law-enforcement agencies, regulators, courts, and other authorities; and
- take any other action we consider appropriate.
We are under no obligation to take, or not to take, any of these actions, and we are not liable to you for taking or not taking any of them.
6.9Notification of security incidents
In the event of an eligible data breach within the meaning of Part IIIC of the Privacy Act 1988 (Cth), we will comply with our obligations under that Part. Save for those obligations:
- we are under no obligation to investigate, contain, mitigate, attribute, root-cause, or otherwise respond to any actual or suspected security incident;
- we are under no obligation to notify you, or any other person, of any actual, suspected, or alleged security incident;
- we are under no obligation to provide forensic detail, technical information, root-cause analysis, indicators of compromise, evidence, or any other description of any incident;
- our compliance, or attempted compliance, with Part IIIC or any other notification obligation does not give rise to, or evidence, any liability, admission, fault, breach, or duty on our part;
- any voluntary notification we issue does not create, expand, or imply any obligation to issue further notifications;
- where we are required by law to give notice, we may do so at any time within the maximum period permitted by law; and
- we may limit, restrict, or condition the recipients of any notification, including by giving notice to one affected person but not another.
6.10Recovery, restoration, and remediation
We are under no obligation to:
- recover, restore, reconstruct, replace, or recreate any personal information lost, corrupted, or destroyed in any actual or suspected security incident;
- provide, fund, arrange, or recommend any credit monitoring, identity-theft protection, fraud-prevention service, financial remediation, counselling, or other remediation;
- waive any fee, refund any charge, extend any deadline, or offer any commercial concession; or
- take any other corrective, remedial, or supportive action,
except to the extent strictly required by law. Any action we do take is voluntary, may be ad hoc, may be discontinued at any time, and does not constitute an undertaking to take any further or comparable action.
6.11Events outside our control
Where any actual or suspected security incident is caused or contributed to by an event outside our reasonable control — including (without limitation) a zero-day or previously unknown vulnerability in third-party software, a compromise of a service provider or sub-processor, a supply-chain attack, a credential compromise originating with a user or third party, a nation-state actor, an act or omission of any law-enforcement agency or regulator, sanctions, or a force majeure event — we are not liable for any consequence of any kind.
6.12No fiduciary duty; no expectation of confidentiality; no reliance
Nothing in this policy creates, evidences, or gives rise to:
- any fiduciary duty, trust, agency, or special relationship between us and you;
- any duty of care exceeding the minimum we are strictly required to meet under the Privacy Act 1988 (Cth) and other applicable law;
- any general or specific expectation of confidentiality, secrecy, or privilege in respect of any information you provide to, or transmit through, the Service; or
- any obligation arising from any communication, marketing copy, statement, post, slide, blog, social-media content, conversation, or representation about security or privacy made anywhere other than in this policy and our Terms of Service. Only this policy and our Terms of Service govern our security and privacy obligations to you, and you may not rely on any other source.
Our past compliance with this Section 6 or any obligation under the Privacy Act 1988 (Cth) is not a representation about our future practices, and you may not rely on any such past compliance.
6.13Allocation of risk, liability, and time-bar
Subject only to rights and remedies that cannot lawfully be excluded, restricted, or modified (including, without limitation, the consumer guarantees under the Australian Consumer Law):
- you bear the entire risk of any actual or suspected security incident, unauthorised access, breach, loss, corruption, modification, disclosure, or destruction in relation to any personal information held, transmitted, processed, or disclosed through, by, or in connection with the Service;
- we are not liable to you for any loss, damage, claim, demand, action, suit, proceeding, cost, or expense arising out of or in connection with any of the foregoing, however caused (including by our negligence), and however that liability is characterised (contract, tort, statute, equity, or otherwise); and
- any claim against us in connection with any actual or suspected security incident, security failure, or breach of this Section 6 must be commenced within twelve (12) months of the earlier of (i) the date of the incident and (ii) the date you first became aware, or ought reasonably to have become aware, of the incident, failing which the claim is permanently barred to the maximum extent permitted by law.
The further allocation of risk, limitation, and exclusion of our liability in relation to security and all other matters is set out in our Terms of Service.
6.14Right to change
We may at any time, and without notice to you, change any of our security practices, technologies, providers, controls, notification practices, response practices, monitoring practices, audit practices, vulnerability-handling practices, and any other aspect of how we approach the security of personal information. No such change is a breach of this policy or any obligation we owe you.
7.Your rights and how to exercise them
This Section 7 describes the rights you have under the Privacy Act 1988 (Cth) and the Australian Privacy Principles in relation to personal information we hold about you. Those statutory rights are your only rights in relation to your personal information held by us. Nothing in this policy, and nothing said or done by us, our personnel, our service providers, or anyone purporting to act for us, creates any further or different right or any cause of action beyond the Privacy Act 1988 (Cth).
Our failure or delay in responding to any request is not a breach, except to the extent the Privacy Act 1988 (Cth) strictly requires. Disputes under this Section 7 are governed by the laws of Victoria and the exclusive jurisdiction of its courts.
7.1Access (APP 12)
You may ask us for access to personal information we hold about you under APP 12. We may decline, in whole or in part, on any ground permitted by APP 12.3 or other applicable law — including (without limitation) where the request would unreasonably affect another person's privacy; relates to existing, anticipated, or potential legal proceedings; would prejudice negotiations, enforcement, or commercially sensitive decision-making; is frivolous, vexatious, repetitive, stale, or part of a coordinated campaign; relates to a person under 18; or any other lawful ground.
Where we grant access, we may do so in any form, format, medium, and language (English only) we consider appropriate. Australian law does not currently confer a general right to data portability, and we do not undertake to provide one. We are not required to recreate, reconstruct, or rehydrate any information held only in caches, backups, archives, derivative datasets, model weights, or embeddings described in Section 5, nor to disclose our processes, criteria, algorithms, or reasoning. We may charge a reasonable fee (payable in advance) to the extent permitted by law, and we will give such reasons for declining as the Privacy Act 1988 (Cth) strictly requires, and no more. We will respond within the period APP 12 requires, which we may use in full; if we are unable to do so for any reason, the request is deemed declined and you may resubmit.
7.2Correction (APP 13)
You may ask us to correct personal information you consider inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond in accordance with APP 13. We may decline where we are satisfied the information is accurate, or on any other ground permitted by law, and we are under no obligation to investigate or independently verify any claim made in a correction request.
Where we decline, we may at your written request associate a statement of disagreement with the information. We are under no obligation to correct information held in inspection meeting recordings, transcripts, embeddings, model weights, training datasets, or derivative materials described in Section 3.4; to correct information held in backups, archives, or other systems described in Section 5; to notify any third party of any correction (except where APP 13.5 requires); to accept any particular form of evidence; or to correct information obtained from a third party.
7.3Deletion
There is no general right under Australian law to require us to delete personal information we hold about you. Where you request deletion, Sections 5.4 and 5.5 apply. We may, in our sole and absolute discretion, delete or de-identify at any time, but we are under no obligation to do so. Inspection meeting recordings, transcripts, embeddings, model weights, training datasets, and derivative materials described in Section 3.4 are not subject to any deletion request.
7.4Other requests
Australian law does not currently confer general rights to data portability, restriction of processing, objection to processing, or human review of automated decision-making. We do not undertake to provide any such rights, and we may decline or recharacterise any such request in our sole and absolute discretion.
We may also decline any request that is repetitive, vexatious, frivolous, stale, or part of a coordinated campaign; is made by anyone other than you (or your lawfully authorised agent); relates to another person's information; would impose excessive cost or operational burden; relates to information we are entitled or required to retain or withhold; or is made through any channel other than the one designated in Section 7.5.
7.5How to make a request
Email support@paarvay.com with subject line "Privacy request" (or "Privacy complaint" for complaints under Section 7.6) and a clear description of what you want. Requests made through any other channel — chat, social media, inspection meetings, unrelated support tickets, or via third parties who are not your lawfully authorised agent — are not valid and we are under no obligation to act on them.
Identity verification. Before we act, you must satisfy us of your identity using any combination of evidence we consider appropriate (government-issued ID, account-control evidence, knowledge-based or biometric verification, third-party services, or otherwise). Acceptable forms are determined by us in our sole and absolute discretion.
Agents. We may, but are not required to, act on a request made by someone claiming to act on your behalf. We may require notarised authority, a court order, or other instrument we consider appropriate. Journalists, advocates, researchers, and other third parties who are not your lawfully authorised agent have no standing to make requests on your behalf, and any such request will be disregarded. We are not liable for any action we take in good faith on what we reasonably believed was an authorised request.
Automated handling. We may triage, assess, decide, and respond using automated systems, including AI. You have no right to human review except to the extent the Privacy Act 1988 (Cth) strictly requires.
No class or standing requests. Each request must be made by, and relate to, a single individual. We will not consider class, group, representative, standing, or open-ended requests, including requests to apply a particular treatment to all future personal information.
7.6Complaints
Make complaints via the channel in Section 7.5. You must give us a reasonable opportunity to investigate and respond before escalating to any external body. Any complaint must be made within twelve (12) months of the earlier of the matter complained of and the date you first became aware (or ought reasonably to have become aware) of it, failing which we may decline to consider it to the maximum extent permitted by law.
If unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, 1300 363 992, or GPO Box 5288, Sydney NSW 2001.
We handle complaints in any manner we consider appropriate, in our sole and absolute discretion. No specific investigation, response, remedy, compensation, apology, or admission is required. Our response to any complaint, and any settlement discussion, offer, or compromise in connection with it, is provided without prejudice and without admission, is confidential, and must not be published, posted, screenshotted, or otherwise disclosed to any person other than your professional adviser bound by an equivalent obligation, except as required by law.
7.7Misuse
You must not make any request you know or ought reasonably to suspect is false, misleading, or made for an improper purpose (including harassment, intimidation, competitive intelligence, journalistic investigation, or commercial advantage). You indemnify us against any loss arising from any such request. Where we consider a request abusive, fraudulent, or improperly motivated, we may suspend or terminate your account, ban you from the Service, decline all further requests from you, and exercise any other right available to us.
7.8Operational reservations
We are under no obligation to: maintain any particular capability to fulfil requests; preserve records of past requests, responses, or correspondence; voluntarily comply with any informal request from a court, tribunal, regulator, or authority (we will respond only to validly issued and binding legal process, in accordance with Section 4.5); or honour any statement, communication, marketing copy, post, slide, blog, social-media content, or representation made anywhere other than in this policy and our Terms of Service.
Only this policy and our Terms of Service govern your rights in relation to personal information we hold. No other source creates, varies, extends, or evidences any right under this Section 7. We may change any channel, process, evidentiary requirement, fee, or response practice at any time, without notice; continued use of the Service is deemed acceptance.
8.Cookies and similar technologies
8.1What this section covers
In this Section 8, "cookies and similar technologies" means cookies, local storage, session storage, IndexedDB, service-worker caches, Progressive Web App caches, push-notification tokens, device identifiers, advertising identifiers, device fingerprints, tracking pixels, web beacons, software development kits, and any other client-side, browser, device, or operating-system technology used to read, write, persist, infer, or associate information on, about, or across your device or browser. Section 8 applies to all of them.
8.2What we use them for
We and our service providers may use cookies and similar technologies for any of the following purposes:
- strictly necessary — to sign you in (including by storing the bearer token issued to your browser), keep you signed in, secure your session, prevent fraud and abuse, enforce our Terms of Service, route requests, and operate the Service as a Progressive Web App;
- functionality — to remember your preferences, settings, and recently viewed content;
- performance and analytics — to measure usage, diagnose errors, monitor performance, and run experiments;
- fraud, abuse, and security — to detect, prevent, investigate, and respond to fraud, abuse, account misuse, automated access, and security incidents, including (without limitation) by means of cookie-less device fingerprinting and signal correlation across devices, sessions, and accounts;
- advertising and marketing — where used from time to time, to measure marketing effectiveness and to create custom and look-alike audiences in accordance with Section 3.11; and
- any other purpose described in this policy, our Terms of Service, or otherwise notified to you.
We may, at any time and without notice, add, change, replace, or remove any cookie or similar technology. We may set any cookie or similar technology before, during, or after the display of any consent prompt, where the relevant purpose is strictly necessary, required by law, or otherwise permitted by this Section 8.
8.3First-party, third-party, and provider use
Some cookies and similar technologies are set by us. Others are set by our service providers (including, without limitation, those identified in Section 4.2). Service providers may use cookies and similar technologies — and any information collected through them — for their own purposes, on their own terms and privacy policies, which are not within our control. Section 4 applies to any personal information collected by them.
8.4Cross-device, cross-session, and inferred associations
We may use cookies and similar technologies, alone or in combination with other information we hold or receive, to associate your activity across devices, browsers, sessions, accounts, and time, and to infer associations that we cannot directly observe. We may do so by deterministic means (for example, your account identifier), probabilistic means (for example, device fingerprinting or signal correlation), or any combination. We may continue to apply such associations after you sign out, after you close your account, and after you stop using the Service.
8.5Your controls; consequences of disabling
You may configure your browser, device, or operating system to refuse, restrict, or delete cookies and similar technologies, and you may clear local storage, session storage, IndexedDB, and service-worker caches at any time.
You acknowledge that:
- doing so may prevent the Service from functioning correctly, partially, or at all, and we may refuse to provide the Service, or any part of it, to any user we detect as blocking essential cookies;
- strictly necessary cookies and similar technologies are required to use the Service and are not subject to any opt-out;
- some technologies (including service-worker caches, Progressive Web App caches, local storage, and IndexedDB) persist independently of, and are not cleared by, ordinary "clear cookies" actions;
- cookies and similar technologies set on your device are stored at the security level of your device, browser, and operating system, and we do not warrant their security;
- some browsers and devices apply cookie controls inconsistently or unreliably, and we do not warrant that any control you set will be honoured; and
- where your browser, device, or operating system sends ambiguous, contradictory, or non-standard signals, we may interpret those signals in any reasonable manner we choose, including in favour of permitting the use of cookies and similar technologies.
We are not liable for any consequence of your choice to refuse, restrict, or delete cookies and similar technologies, and you indemnify us against any loss arising from your doing so.
We do not undertake to recognise or honour "Do Not Track", "Global Privacy Control", any browser-, device-, operating-system-, or platform-level privacy signal, or any third-party opt-out mechanism, except to the extent the Privacy Act 1988 (Cth) strictly requires.
8.6Consent
Australian law does not currently require a cookie-consent banner. By accessing or using the Service, you consent to our and our service providers' use of cookies and similar technologies for the purposes described in this Section 8 and elsewhere in this policy.
Withdrawal of consent operates only prospectively and does not affect any cookie or similar technology already set, any information already collected, any inferred association already made, or any use already made of any of the foregoing.
8.7No inventory, no audit, no register
We are under no obligation to publish, maintain, disclose, or produce any list, inventory, register, audit, or other record of the cookies or similar technologies used by us or by our service providers, the purposes for which they are used, their duration, or their behaviour, except to the extent the Privacy Act 1988 (Cth) strictly requires.
8.8Right to change
We may at any time, and without notice to you, change the cookies and similar technologies we and our service providers use, the purposes for which we use them, their duration, and the controls available to you. No such change is a breach of this policy. Continuing to use the Service after any such change is deemed acceptance.
9.Changes to this policy
9.1Our right to change
We may amend, replace, restate, supplement, supersede, withdraw, fork, or replace this policy, in whole or in part, at any time, in our sole and absolute discretion, for any or no reason, with or without notice, and without providing reasons. This includes (without limitation) changes made in response to legal, regulatory, operational, commercial, security, technological, or any other developments, and changes made retrospectively where law permits.
We are under no obligation to consult you, seek your consent, accept your feedback, grandfather any existing user, or preserve any prior position. No user, group of users, or class of use is entitled to grandfathering, exemption, or continued application of any prior version of this policy on any ground.
We may apply different versions of this policy to different users, regions, segments, contexts, products, or features at the same time, in our sole and absolute discretion.
9.2Notice
We will publish the current version of this policy at https://paarvay.com/privacy and update the effective date shown on the policy when we make substantive changes. That publication is the only notice we are required to give. Publication is effected when the new version is accessible at that URL; we are not responsible for any delay or non-delivery caused by your network, internet service provider, browser, device, content-delivery network, local cache, or any other intermediary. Notice is deemed received on publication, regardless of whether you actually access the URL, regardless of whether you are notified by any other means, and regardless of whether you are then using the Service.
We may, in our sole and absolute discretion, make non-substantive changes (including corrections of typographical or formatting errors, link updates, and clarifications) without updating the effective date.
We may, in our sole and absolute discretion, give additional notice for any change (by email, in-app message, banner, sign-in prompt, or re-acceptance gate), but we are under no obligation to do so. Any such additional notice we give for one change does not create an obligation to give similar notice for any other change. The display of any banner, prompt, or notice does not pause, suspend, or defer the application of the amended policy: your continued use of the Service while any such notice is displayed is deemed acceptance.
The English version of this policy controls. We do not undertake to translate this policy into any other language.
9.3When changes take effect
A change takes effect immediately upon publication, unless we specify a later effective date. Changes apply prospectively to your use of the Service from the time they take effect. Any reservation of right, discretion, or operational latitude in a new or amended provision applies to all personal information we then hold, regardless of when it was collected, and we may rely on the new or amended provision in respect of all such personal information from the effective date.
Where law permits and you have impliedly or expressly consented (including by continued use), changes may take retrospective effect from a date we specify.
9.4Continued use is acceptance
By accessing or using the Service after a change takes effect, you are deemed to accept this policy as amended, in full, without further act on your part. No specific act of acceptance — including clicking through any banner, prompt, or sign-in gate — is required for the amended policy to bind you.
No course of dealing, conduct, communication, or representation under any prior version of this policy creates any expectation, estoppel, waiver, or obligation under any current or future version. Past compliance is not a commitment to future practice.
If you do not accept any change, your sole and exclusive remedy is to stop using the Service and, if you wish, close your account in accordance with our Terms of Service. Cessation of use does not undo your acceptance of, or our reliance on, the policy in force during any period of past use, and closure of your account does not affect Sections 3, 5, and 7 (which continue to apply to personal information we are entitled or required to retain).
9.5Material changes
We may, in our sole and absolute discretion, identify any change as material and provide more prominent notice of it. Our characterisation (or non-characterisation) of any change as material is determined by us alone, is not subject to challenge by you or any other person, and confers no additional right on you, including (without limitation) any right to consent to, object to, opt out of, exempt yourself from, or delay the application of the change.
9.6Past versions; no changelog; not bound by third-party commentary
We are under no obligation to publish, preserve, archive, or produce previous versions of this policy, or any changelog, redline, summary of changes, or comparable record, except to the extent strictly required by law.
Any public comment, opinion, analysis, summary, or characterisation of this policy or any change to it by any third party — including (without limitation) press, social-media commentators, advocacy groups, regulators speaking informally, or any other person — is not authoritative and does not bind us. Only this policy itself governs.
9.7Time-bar on challenges
Any challenge, objection, claim, complaint, or proceeding directed at any change to this policy, or at the application of any amended provision to you, must be brought within twelve (12) months of the earlier of (i) the effective date of the change and (ii) the date you first became aware (or ought reasonably to have become aware) of the change. Beyond that period, the change is irrevocable as against you, to the maximum extent permitted by law.
9.8This Section 9 governs itself
This Section 9 applies to all sections of this policy, including itself. We may amend Section 9 in accordance with Section 9.
9.9Severability
If any provision of this policy (including any provision introduced or amended under this Section 9) is held to be invalid, unenforceable, or excessive by any court, tribunal, or regulator, that provision is severed to the minimum extent necessary, and the remainder of the policy continues in full force and effect.
10.Contact us
10.1How to reach us
For any matter relating to this Privacy Policy or your personal information, email us at support@paarvay.com.
Privacy-specific requests and complaints must follow the channel, subject-line, identity-verification, and content requirements in Section 7.
The Privacy Officer of Ms Digital Crafts Pty. Ltd. can be reached at the same address. Postal mail may be addressed to Ms Digital Crafts Pty. Ltd., Victoria, Australia, marked for the attention of the Privacy Officer; however, email is the only channel we are required to monitor.
10.2Our designated channel
The email address above is the only channel we are obliged to monitor for matters under this policy. Communications sent through any other channel — including (without limitation) chat messages in the Service, social-media posts or direct messages, support tickets unrelated to privacy, inspection meetings, telephone calls to any of our personnel, posts on third-party sites, and any other channel — are not effective notice to us and do not bind us, even if received, read, or responded to by any person purporting to act for us.
10.3Response practices
We will respond as, when, and to the extent the Privacy Act 1988 (Cth) or other applicable law strictly requires. Beyond that:
- we are under no obligation to acknowledge receipt of any communication;
- we are under no obligation to respond within any particular time, in any particular manner, or at all;
- we may respond through any channel we consider appropriate;
- we may decline to engage further with any communication that is repetitive, vexatious, frivolous, abusive, threatening, defamatory, off-topic, made in bad faith, or part of a coordinated campaign; and
- our failure or delay in responding is not a breach of this policy or any obligation we owe you.
10.4Identity, authority, and authenticity
We may require you to verify your identity, your authority, and the authenticity of any communication before we act on it, on the same basis as Section 7.5. We are not liable for any action taken or omitted in respect of a communication we reasonably believed in good faith to have been sent by, or with the authority of, the apparent sender, even if it was not.
10.5Recording and monitoring
We may record, log, review, and analyse all communications between you and us (including emails, support tickets, and any other written or recorded correspondence) for any purpose described in Section 3. Communications between you and us are not confidential as between us, except to the extent expressly described in Section 7.6 (complaints) or otherwise expressly agreed in writing.
10.6Authority of personnel
Only an officer of Ms Digital Crafts Pty. Ltd. expressly authorised in writing to do so can vary, waive, suspend, or release any provision of this policy or any obligation under it. No statement, communication, response, undertaking, concession, settlement offer, or representation by any other personnel, contractor, agent, or service provider — including (without limitation) by anyone responding to a communication sent to support@paarvay.com — varies, waives, suspends, or releases any provision of this policy or any obligation under it, and we are not bound by any such statement.
10.7Spam, scam, and phishing
We will not ask you for your password (we don't have one), your one-time codes, your session tokens, your bearer token, your full credit card number, or any other authentication credential by email, telephone, chat, or any other channel. Any communication purporting to be from us that requests any of those things is not from us, and you must not respond to it. We are not responsible for any consequence of your response to any such communication.
10.8Right to change
We may change the contact details, channel, response practices, and any other matter in this Section 10 at any time, without notice. Section 9 applies.
Operated by Ms Digital Crafts Pty. Ltd. (ABN 66 698 682 254, ACN 698 682 254), Victoria, Australia. Contact support@paarvay.com.