Collective Compound
Privacy Policy
Last updated 26 August 2026
Draft, not yet legal advice
This is a working draft. It has not been reviewed by a qualified Australian privacy lawyer, and it is missing some contact and governance facts that only Collective Compound's founder can supply, marked below. Nothing on this page should be treated as final until both of those are resolved.
1. Who this policy is about
This policy explains how Entity name pending ASIC registration ("we", "us") handles personal information in connection with Collective Compound ("the Platform"). It covers three different groups of people, and they are not treated the same way: account holders who sign in and use the Platform; invited advisers such as accountants, brokers and family members who are given scoped access by an account holder; and people we hold information about who are not users and never agreed to anything, most importantly tenants. That third group has the highest privacy exposure and the least consent, and section 3 deals with it directly.
2. What personal information we collect
This is a real inventory, taken from what the Platform actually stores, not a generic list.
- Identity and contact: name, date of birth, email, phone, postal address, suburb, state and postcode, preferred contact method, referral source, profile image, relationship and living situation, and marketing preference.
- Household and family: names and dates of birth of dependent children, details of a partner who may not hold an account, and free-text life-event notes.
- Employment and income: profession, employer, employment status, salary, bonus, other income and income projections.
- Personal financial position: living expenses, planned one-off expenses, personal assets (cash, shares, super, vehicles) and personal liabilities (cards, loans) with balances, rates and repayments.
- Banking: where you connect a bank feed, the connection record, institution name, and individual transactions including date, amount, account name and the raw bank narration (which routinely names other people). We do not store BSBs, account numbers, card numbers, tax file numbers, Medicare numbers, passport or licence numbers - there is no field for any of them.
- Loans:lender, balance, rate, term, offset and redraw details, and your mortgage broker's contact details.
- Property:address, purchase and sale details, valuations, physical attributes, rent, ownership structure and share, and any recorded co-owner's name.
- Tax: marginal rate, taxable income, entity and trust type, ABN, residency flags, CGT inputs, GST treatment, depreciation schedules, land tax figures, and end-of-year sign-off records.
- Documents: uploaded files and the content extracted from them: rental and bank statements, insurance policies, quantity-surveyor reports, contracts, invoices, inspection photos, and council, strata and land-tax notices. We store the original filename, the file bytes, and the extracted content.
- Account and activity: email, password hash where set, sign-in codes in hashed form, session and invitation tokens, an audit log of who changed what and when, and interface preferences.
- Free text: notes on properties, tenancies, loans, inspections and goals, and messages between an account holder and their accountant. We ask that health information and government identifiers not be entered in these fields, but cannot technically prevent it.
3. Information about people who are not our users
Most privacy policies leave this out. We are stating it directly: to do its job, the Platform holds personal information about people who have no account, received no notice from us, and gave us no consent.
- Tenants: name, lease dates, rent, bond amount and how it was disposed of, payment history, arrears position, and, where an inspection report is uploaded, per-room condition notes and photographs of the inside of the home they live in.
- Dependent children: name and date of birth.
- Partners who do not hold an account: name, date of birth, email, phone, salary and employer.
- Co owners, property managers, brokers, conveyancers, inspectors and other advisers: name, and often firm, email, phone or licence number.
- People invited but who never accepted, or who requested an account and were declined: their email, name and any note they wrote remain stored.
In almost every case this information reaches us because an account holder entered or uploaded it, typically from a managing agent's rental statement or a lease. We do not collect it from the individual concerned, and in most cases we have no contact details for them and no relationship with them. Our Terms of Service require the account holder to warrant they are entitled to provide it.
A person who is not a user can still contact us at support@collectivecompound.com.au to ask what we hold about them, to ask for it to be corrected, or to complain, even though they are not our customer.
4. Why we collect and use this information
We use it to run the Platform and calculate your portfolio position, cash flow, equity, loan position and forecasts; to produce tax-related estimates and end-of-year extracts for your own registered tax agent; to match uploaded statements and documents to properties and ledger entries; to provide scoped access to advisers you invite; to send transactional messages such as sign-in links, invitations and alerts you have configured; and to maintain security and meet our own legal and record-keeping obligations. We do not sell personal information, we do not use it for advertising, and we do not share it with data brokers.
5. Who we disclose information to
An account holder can invite advisers, family members and accounting firms and grant them access to specified sections of the portfolio. Access is scoped, can be time limited, and can be revoked. Personal Details cannot be shared with a guest.
We also use service providers to run the Platform. Where processing region could not be confirmed from how the service is configured, we say so rather than guess.
- Application hosting and the database: Sydney, Australia.
- Email delivery and inbound document intake: sign-in links and codes, invitations, alerts, and documents emailed to a portfolio intake address, including attachments, processed in the United States.
- Bank feed aggregation: under Consumer Data Right arrangements through Fiskil Pty Ltd, an accredited data recipient (accreditation number ADRBNK000246), processed in Australia. Section 7 explains this arrangement in full.
- Automated document and spreadsheet content extraction: the contents of uploaded rental statements, bank statements and spreadsheets are sent to a hosted extraction service so figures can be read out of them, processed in the United States. No region pinning or zero-retention configuration is in place for that provider yet.
- Automated transaction categorisation: the descriptions and amounts of synced bank transactions are sent to a hosted categorisation service, processed in the United States, so an expense category can be suggested. Nothing else is sent: no names, balances, account identifiers or any other field, though a bank narration can itself name a person or merchant. The result is a suggestion only; nothing is recorded without your confirmation, and a merchant already categorised is not sent again.
There is currently no analytics provider and no advertising provider connected to the Platform. An error monitoring service, processing in the United States, receives technical details of application errors so faults can be found and fixed; it is configured to scrub personal information from what it receives, and banking data is never sent to it.
We may also disclose personal information where required or authorised by law, to respond to a lawful request from a regulator or court, or where necessary to prevent a serious threat to life, health or safety.
6. Sending information overseas
Some of the providers above process information outside Australia, or are companies headquartered outside Australia even where the processing itself happens here. Application hosting, the database, and bank feed data are pinned to Australia. The document extraction step sends the contents of uploaded financial documents, including property addresses, tenant names and financial figures, to a service processing in the United States, and no data processing agreement is yet in place for it. The email provider's processing region is unconfirmed. We are stating this directly rather than describing it as resolved: it is a real cross-border disclosure and it needs to be addressed before it is described as compliant.
7. Bank feeds and the Consumer Data Right
Where you connect a bank feed, your banking data is collected under Australia's Consumer Data Right (CDR). We access it as a representative of Fiskil Pty Ltd, an accredited data recipient (accreditation number ADRBNK000246): you grant a consent through Fiskil's hosted consent flow, your bank shares the data with Fiskil, and the Platform retrieves only what the consent covers, being account details, balances and transactions. We never request payment initiation, payees or scheduled payments, and you can exclude any account from transaction collection or limit it to balance only.
- Ending the arrangement:you can stop sharing at any time from Transactions then Bank Feed inside the Platform, or through Fiskil's own consumer dashboard, and consents also expire automatically (after at most 12 months). When a consent ends, however it ends, we immediately stop collecting and delete the staged banking data held under it.
- Deletion on request: you can ask us at any time to delete the CDR data we hold about you, and we also delete CDR data if Fiskil, as the accredited principal, directs us to. Closing your account removes your banking data as part of de-identification.
- What remains yours: transactions you have explicitly confirmed into your ledger become your own accounting records, the same as figures you might have entered by hand from a paper statement, and are retained under your control as described in section 9.
- Complaints about CDR data: raise them with our Privacy Officer (section 15), with Fiskil at consents@fiskil.com.au, or with the Office of the Australian Information Commissioner at oaic.gov.au.
8. How we hold and protect information
Data is held in a managed database in Sydney. Connections to the Platform use HTTPS. Passwords and sign-in codes are stored only as hashes. Access is scoped per portfolio and per role, and an audit log records changes. We do not currently offer multi-factor authentication, and we do not currently publish a documented backup regime. Where we fall short of a protection we intend to offer, we say so here rather than describing it as already in place.
9. How long we keep information
Banking data collected under the Consumer Data Right is the exception with real, enforced deletion: staged banking data is deleted when its consent ends (section 7), automatically ignored transactions are deleted after 60 days, and abandoned connection attempts are removed within an hour. For everything else, stated plainly: there is currently no automated deletion of portfolio, tenant or document data, and no retention period is enforced by the Platform for that data. Records including declined account requests, ended tenancies and uploaded documents persist until deleted by hand. The intended policy, once settled with legal advice, is to keep tax-related records for at least five years consistent with the Income Tax Assessment Act 1936 (Cth), to export and then delete portfolio data within a defined window after account closure, and to delete information about ended tenancies once it is no longer needed for the account holder's tax or legal position. We will not describe a retention promise as met until the deletion capability behind it actually exists.
10. Accessing and correcting information
Account holders can view and edit most of their own information directly in the Platform. Anyone, including a person who is not a user, may ask for access to or correction of information we hold about them by contacting us at support@collectivecompound.com.au. We aim to respond within 30 days, may need to verify identity first, and do not charge for making a request. Some information sits inside an accounting firm's internal working notes, or inside a document supplied by a managing agent; where a correction affects another party's records we will say so rather than silently editing.
11. Complaints and data breaches
If you think we have mishandled your personal information, contact our Privacy Officer at support@collectivecompound.com.au. We will acknowledge the complaint, investigate, and respond in writing. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992.
Where we have reasonable grounds to believe an eligible data breach has occurred under the Notifiable Data Breaches scheme, we will assess it, notify the Commissioner and notify affected individuals, whether or not they are our customers. That expressly includes tenants and other non-users.
12. Cookies and tracking
The Platform sets cookies that are necessary for sign-in and session management. Session and cross-site request forgery cookies are HttpOnly, use SameSite protection, and are marked Secure in production. We do not currently run any third-party analytics, advertising or tracking service. If that changes, this policy will be updated before the change goes live.
13. Children
The Platform is not intended for use by anyone under 18. We do, however, store the names and dates of birth of account holders' dependent children where a parent or guardian enters them for financial planning. That information is used only for portfolio planning and never for marketing.
14. Changes to this policy
We may update this policy. The current version and its effective date are published on this page. Where a change is material we will notify account holders before it takes effect.
15. Contact
Privacy Officer
Email: support@collectivecompound.com.au
Post: postal address to be added