Turnqey← Home

Privacy Policy

Last updated: 15 April 2026

Template disclaimer. This page is a plain-English starting point. Before you go to market, have an Australian privacy lawyer review it against the Privacy Act 1988 (Cth) and your actual data handling.

1. Who we are

Turnqey (“Turnqey”, “we”, “us”) operates the digital access platform at turnqey.com.au for Australian property managers and short-term rental hosts. We are based in Melbourne, Victoria.

2. What we collect

  • Account information — email, name, phone number, password hash.
  • Property & lock data — addresses, lock identifiers, battery and connectivity state.
  • Access logs — time-stamped events describing who unlocked which door and when.
  • Billing — subscription status; payment details are handled by Stripe, not Turnqey.
  • Technical data — browser/device information, IP, and diagnostic logs.

3. How we use it

  • Provide the core product (issuing codes, activity logs, lock control).
  • Authenticate you and keep accounts secure.
  • Send transactional emails (access codes, password resets, invitations).
  • Improve the product through aggregated, non-identifying analytics.

We do not sell your personal information.

4. Where your data lives

Your data is stored with our infrastructure partners — Supabase (database and auth), Vercel (hosting), Seam (smart lock integration), Stripe (billing), and Resend (email). Some of these providers may host data outside Australia. We choose providers that meet industry-standard security practices.

5. Your rights

Under the Australian Privacy Principles you can request access to, correction of, or deletion of your personal information. Email privacy@turnqey.com.au and we’ll respond within 30 days.

6. Data retention & deletion

We keep access and activity logs while your account is active and for a reasonable period afterwards to comply with legal or audit obligations. Ask us to delete your account and we’ll erase your data from our systems within 30 days, except where law requires retention.

7. Security

Passwords are hashed. Access to production data is restricted to a small set of authorised personnel. Traffic is encrypted in transit. No system is perfectly secure — if we become aware of a breach that affects you, we’ll notify you and the OAIC as required.

8. Cookies

We use first-party cookies to keep you signed in and to remember your preferences. We don’t use third-party advertising trackers.

9. Changes to this policy

We may update this policy. Material changes will be announced via email or in-product notice.

10. Contact