Legal
Privacy Policy
Effective date: 24 August 2026. This policy is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
The marketplace at huntingpropertiesaustralia.com.au (Hunting Properties Australia) is operated by Townsend Investment Group Pty Ltd, ABN 42 649 952 983 (we, us, our), from Queensland, Australia. This policy explains what personal information we collect, why we collect it, how we hold it, who we share it with, and how you can access it, correct it or complain.
1. What we collect
We collect the information needed to run a booking marketplace:
- Account information: your name, email address, password (stored only as a salted cryptographic hash), and any phone number or profile bio you choose to add.
- Host information: listing details for your property, and the payout account details you provide directly to our payment provider, Stripe, when you set up payouts. We receive an account identifier and onboarding status from Stripe, not your bank details.
- Booking information: the property, dates, guest count, price, payment status and any message you send with a booking.
- Content: reviews, photos and other material you submit.
- Compliance documents: to book a hunt you provide copies of your firearms licence, proof of SSAA or AHO membership and, where the property's state requires one, a game licence, along with any reference number, issuing state and expiry you enter. This is sensitive information under the Privacy Act, collected with your consent for the sole purpose of confirming your eligibility to hunt.
- Landholder verification documents: to list a property you provide a copy of your council rates notice (or an equivalent ownership document) and a photo ID (driver licence, passport or firearms licence). This is collected with your consent for the sole purpose of verifying your identity and your control of the property before a listing goes live, and is never shown to guests.
- Technical information: IP address, browser type and pages visited, collected through server logs and essential cookies, used for security (including rate limiting) and to operate the service.
We do not collect payment card numbers; Stripe processes payments directly. The compliance documents above are provided by you and held securely: they are visible only to you and our authorised reviewers, are never published or shared with Hosts, and are served only over authenticated, non-cached connections.
2. Why we collect it
We collect, hold and use personal information to:
- create and administer accounts, listings and bookings;
- confirm that hunters hold the firearms licence, membership and any game licence required to hunt lawfully, and review the documents you provide for that purpose;
- process payments and host payouts through Stripe;
- send transactional messages (booking confirmations, cancellations, payout notices) and, with your consent, marketing you can opt out of at any time;
- keep the Platform secure and prevent fraud and misuse;
- moderate content and enforce our Terms of Service; and
- meet our legal obligations.
If we cannot collect the information we need, we may be unable to provide the service (for example, we cannot confirm a booking without contact details).
3. Who we share it with
- Between Guests and Hosts: when a booking is made, we share the details each party needs for the stay to happen: names, booking dates, guest count and messages. Contact details - phone numbers, email addresses and app handles - are hidden in messages until a booking between you is confirmed, and can be exchanged freely from that point. We do not share your compliance documents with Hosts.
- Service providers: Stripe (payments and payouts), our email delivery provider, and our hosting and database providers, in each case only to the extent needed to provide their service to us.
- Legal requirements: where disclosure is required or authorised by law, including to law enforcement in connection with suspected unlawful activity such as firearms offences.
- Advertising measurement: when we run ads, we report conversion events (for example that a signup happened after an ad click) to the ad platform, currently Meta, so we can measure whether the ads work. Where an email address or name is included it is hashed (SHA-256) before it leaves our server, and your compliance documents are never part of this reporting.
We do not sell personal information, and we do not share it with third parties for their own marketing.
4. Overseas disclosure
Some of our service providers (including Stripe, our email provider and cloud hosting) may store or process information on servers located outside Australia, including in the United States. We take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs, including through the providers' contractual and certification commitments.
5. How we hold and protect it
- passwords are stored only as salted bcrypt hashes;
- data is transmitted over encrypted connections (HTTPS);
- production data is held in access-controlled databases with role-restricted administrative access;
- uploaded identity documents (licences, membership cards, photo ID and rates notices) are additionally encrypted at the application layer with AES-256, under a key held outside the database;
- compliance documents are not placed on any public address; they are served only over authenticated connections to the document owner or an authorised reviewer, and are marked not to be cached; and
- we apply security headers, input validation and rate limiting across the Platform.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
6. Cookies
We use essential cookies to keep you signed in (session authentication) and to protect the Platform (security tokens). If you arrive from one of our ads, we also store the ad click identifier in a first-party cookie so we can attribute a later signup to that ad. We do not load third-party advertising scripts, and we do not use third-party advertising cookies.
7. Data retention
We keep personal information while your account is active and for as long as needed afterwards to meet legal, accounting and dispute obligations (generally up to 7 years for transaction records). Compliance documents are kept only while they are needed to support your bookings: the file itself is destroyed when you remove it, when it is superseded, or when you close your account, and what remains is the record that a document of that kind was checked and on what date.
Closing your account scrubs your name, email address, phone number, biography and profile picture, and the account can never be signed into again. Your booking history and the releases you signed are not deleted. Those documents record an agreement between you, a landholder and us about a hunt that actually took place - they carry the signature, date and version that were captured at signing, and they are the evidence all three of us would rely on if that hunt were ever the subject of a claim or a dispute. Australian privacy law allows us to keep records we need to establish or defend a legal claim, and we keep these for that reason and no other. They are never used for marketing, and they are not shared except as section 3 describes.
8. Access, correction and deletion
You can view and update most of your information from your account. You may also ask us for a copy of the personal information we hold about you, ask us to correct it, or close your account. Closing is described in section 7: your personal details are scrubbed and the account is locked for good, while the signed releases and booking history we are required to keep stay on file. You can close your own account from your account page at any time, or contact us through the contact page and we will respond within 30 days. We may need to verify your identity before acting on a request.
9. Complaints
If you believe we have mishandled your personal information, contact us first and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by phone on 1300 363 992.
10. Changes to this policy
We may update this policy from time to time. The current version is always available on this page, and material changes will be notified by email or by notice on the Platform.