Privacy

Version 0.1, 25 September 2026. Under legal review; the substance below applies now.

FairLot is a software platform used by strata schemes, bodies corporate and owners corporations to keep their own records. We handle personal information in line with the Privacy Act 1988 and the Australian Privacy Principles. Questions and requests go to hello@fairlot.com.au.

What we collect

Account details for the people who sign up (name, email, phone, password stored as a salted hash), the scheme records that a committee or manager enters or imports (lots, owners, tenants, agents, committee members, insurance, documents, requests), messages you send us through the contact page (your name, email, phone and what you wrote), and technical logs (IP address, browser, pages visited, actions taken) needed to run and secure the service.

Why we collect it

To provide the service the scheme has signed up for, to keep an audit trail of changes (which the scheme's own record-keeping obligations require), to secure accounts, to support users, to reply to your enquiries, and to send service messages. We do not sell personal information, and we never use scheme records or account details for advertising.

Website measurement and advertising

When we are running advertising, the public pages of this website (the ones you can read without signing in) may load a measurement pixel from Meta so we can tell whether an ad led to a sign-up or an enquiry. It sets a cookie and sends Meta the page address and standard browser details. It never receives anything you type into FairLot, and it is never loaded inside the app or the owner portal. You can block it with a browser setting or an ad blocker and everything on the site still works. Meta describes its own handling of that data in its privacy policy.

Who controls scheme records

The scheme (through its committee or manager) decides what goes into FairLot about its owners and tenants and is responsible for that information under its own state's strata law. We process it on the scheme's behalf and only as the service requires. Owners with questions about their own details in a scheme's records should contact the committee first; we will help either party if asked.

Where it is stored

Our servers are located in Australia. Backups are encrypted and also held in Australia.

Who we share it with

Only providers that help us run the service (hosting, email delivery, payment processing when billing goes live), each bound to use it solely for that purpose, and authorities where the law requires. We never share your information with insurers, contractors or marketers.

Access, correction and deletion

You can see and update your own account details in the app. A scheme can export all of its data at any time. To access or correct personal information we hold about you, or to close an account, email us; we respond within 30 days. Some records must be retained for the period a scheme's law requires before they can be deleted.

Security and breaches

Data is encrypted in transit, passwords are hashed with Argon2id, every change is logged, and access is limited to the people who need it. If a breach is likely to cause serious harm we notify affected people and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.

Complaints

Write to us first and we will investigate and reply within 30 days. If you are not satisfied you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.