drooda

Privacy Policy

Last Updated: 5 June 2026

This Privacy Policy explains how Drooda ABN: 57 431 054 627 ("we", "our", or "us") collects, uses, discloses, and protects your personal information when you use our mobile application, website located at www.drooda.com.au, and related services (collectively, the "Platform").

We are committed to protecting your privacy and ensuring the security of your personal information. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Privacy Policy applies to all Users of our Platform, including both Providers (those offering goods or services for rent) and Customers (those renting goods or services), as well as visitors to our website who do not register for an account.

By accessing or using our Platform, you consent to the collection, use, and disclosure of your personal information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not use our Platform.

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new Privacy Policy on our Platform and, where appropriate, by email. We encourage you to review this Privacy Policy periodically.

1. Information We Collect

1.1 Personal Information

We collect the following types of personal information:

Identity Information

  • Full name
  • Email address
  • Phone number
  • Physical address
  • Photo identification (for Provider accounts)
  • Proof of address documents (for Provider accounts)

Account Information

  • Username and password (in encrypted form)
  • Account preferences and settings
  • Account activity history
  • User ratings and reviews

Financial Information

  • Payment method preferences (such as preferred payment method)
  • Bank account information (for Providers, for payment processing)
  • Security deposit information
  • Partial payment information (such as last four digits of payment cards, expiration dates) for reference purposes only
  • Transaction history and records

Communication Information

  • Messages between Users through our Platform
  • Communications with our customer support team
  • Feedback, reviews, and dispute information

Device and Technical Information

  • IP address
  • Device identifiers
  • Browser type and version
  • Operating system
  • Mobile device information
  • Access times and dates
  • Geographic location (if location services are enabled)

Rental-Specific Information

  • Listing details and descriptions
  • Booking information and history
  • Images of rental items
  • Rental item condition documentation
  • Security deposit transaction details

1.2 Non-Personal Information

We also collect non-personal information that does not directly identify you:

  • Analytics data
  • Aggregated usage statistics
  • User behaviour patterns
  • Platform performance metrics
  • Conversion rates and navigation paths
  • Session cookies, persistent cookies, web beacons, pixel tags, and local storage data

2. How Information Is Collected

2.1 Information You Provide Directly

We collect personal information that you voluntarily provide when you:

  • Create or update your account
  • Verify your identity
  • Create or manage listings
  • Make or manage bookings
  • Communicate with other Users
  • Contact our customer support
  • Provide feedback or reviews
  • Participate in surveys or promotions
  • Upload photos or documentation

2.2 Information Collected Automatically

We automatically collect certain information when you use our Platform:

  • Usage data through cookies and similar technologies
  • Device information when you access our Platform
  • Location information (if you enable location services)
  • Log information such as access times and pages visited

2.3 Information from Third Parties

We may receive information about you from third parties:

  • Payment processors (such as VISA, MasterCard, PayPal, and Stripe)
  • Identity verification services
  • Fraud detection and prevention services
  • Other Users (through reviews and dispute processes)

2.4 Cookies and Similar Technologies

We use cookies and similar technologies to collect information about your browsing activities on our Platform.

Types of cookies we use:

  • Essential cookies: Required for the Platform to function properly
  • Functional cookies: Remember your preferences and settings
  • Analytics cookies: Help us understand how users interact with our Platform
  • Marketing cookies: Used to deliver relevant advertisements and track campaign performance

You can control cookies through browser settings or opt-out options in our cookie banner and footer. Disabling cookies may limit your ability to use certain features of our Platform.

3. How We Use Your Information

3.1 Providing and Improving the Platform

  • Create and maintain your account
  • Process transactions between Users through secure third-party payment processors
  • Facilitate communication between Users
  • Authenticate your identity
  • Manage security deposits
  • Provide customer support
  • Maintain and improve the Platform
  • Develop new features and services
  • Personalise your experience

3.2 Communications

  • Send service-related notifications
  • Provide transaction updates
  • Respond to inquiries and support requests
  • Send marketing communications (which you may opt out of)
  • Inform you about Platform updates and changes

3.3 Security and Legal Compliance

  • Verify your identity
  • Detect and prevent fraud, spam, and abuse
  • Protect the security of our Platform
  • Comply with applicable laws and regulations
  • Enforce our Terms and Conditions
  • Resolve disputes between Users
  • Establish, exercise, or defend legal claims

3.4 Analytics and Business Operations

  • Analysing usage patterns and trends
  • Measuring the effectiveness of our services
  • Conducting market research and analysis
  • Business planning and financial reporting
  • Service optimisation and improvement

4. Information Sharing and Disclosure

4.1 Information Shared Between Users

For Providers: your name, profile photo, verification status, listing details, general location (not exact address), ratings, reviews, and Platform communications with Customers.

For Customers: your name, profile photo, general location (not exact address), ratings, reviews, booking details, and Platform communications with Providers.

4.2 Service Providers and Third Parties

We may share your information with trusted third parties who assist us in operating our Platform:

  • Payment processors (including Stripe, VISA, MasterCard, Debit/Credit card processing, Apple Pay, Google Pay, and PayPal)
  • Cloud hosting and storage providers
  • Identity verification services
  • Customer support service providers
  • Analytics and data processing providers
  • Legal and professional advisors

These service providers are authorised to use your personal information only as necessary to provide services to us and are contractually obligated to keep your information confidential and secure.

4.3 Legal Requirements and Business Transfers

  • To comply with legal obligations, court orders, or legal processes
  • To protect our rights, property, or safety
  • To enforce our Terms and Conditions
  • In connection with a business transition such as a merger, acquisition, or sale of assets

4.4 Transfer Locations

We use third-party cloud services, including Amazon Web Services (AWS) and MongoDB Atlas, to store and process your information. This means your information may be transferred to, and stored at, locations outside Australia, including the United States, Singapore, and other countries where these providers operate data centres.

4.5 Safeguards

Our cloud service providers implement appropriate safeguards for international data transfers, including standard contractual clauses and binding corporate rules where applicable. We take reasonable steps to ensure that any overseas recipient will deal with your personal information in a way that is consistent with the Australian Privacy Principles.

5. User-to-User Information Exchange

5.1 Platform's Limited Role

Our Platform facilitates the exchange of information between Users. While we provide the technology to enable this exchange, we:

  • Do not control what information Users choose to share directly with each other
  • Cannot guarantee the conduct of Users or the accuracy of information they provide
  • Do not monitor all communications between Users in real-time

5.2 User Responsibilities

  • Exercise caution about what personal information you share
  • Review the other User's profile, ratings, and reviews
  • Report suspicious behaviour or policy violations to us
  • Follow our safety guidelines for in-person interactions

5.3 Communication Monitoring and Record Keeping

  • Maintain records of communications sent through our Platform
  • May review communications for fraud prevention, dispute resolution, and policy enforcement
  • May use automated systems to monitor communications for prohibited content

6. Sensitive Information

We generally do not collect sensitive information. However, if we do collect sensitive information about you, we will only do so with your consent or where required by law. Any sensitive information we collect will be used and disclosed only for the purpose for which it was provided or a directly related secondary purpose.

7. Children's Privacy

Our Platform is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe we have collected information from your child, please contact us so we can delete the information.

8. Security Measures

8.1 Information Security

  • Encryption of sensitive information in transit and at rest
  • Secure authentication procedures
  • Regular security assessments and audits
  • Staff training on data protection
  • Access control restrictions

8.2 Payment Processing Security

We do not directly collect, process, or store your full payment card details on our servers. Payments are processed by third-party providers including Stripe, VISA, MasterCard, Apple Pay, Google Pay, and PayPal. These processors comply with PCI DSS. We may store limited payment information (such as last four digits, expiration date, and payment method) for record-keeping.

8.3 User Account Security

  • Maintain the confidentiality of your account credentials
  • Use strong, unique passwords
  • Log out of your account when using shared devices
  • Notify us immediately of any unauthorised access

8.4 Security Limitations

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of information transmitted to or from our Platform.

9. Data Breach Response

9.1 Data Breach Notification

In the event of a data breach involving your personal information, we will:

  • Take immediate steps to contain and assess the breach
  • Determine whether the breach is likely to result in serious harm
  • Notify affected individuals in accordance with the Privacy Act 1988 (Cth) if serious harm is likely
  • Notify the Office of the Australian Information Commissioner (OAIC) if required
  • Provide recommendations on steps you can take to protect yourself

9.2 Information Provided in Notifications

  • A description of the breach
  • The kinds of information concerned
  • Recommendations about steps you should take
  • Our contact details for questions or concerns
  • Information about how we are responding to the breach

9.3 Third-Party Breaches

If a data breach occurs with one of our third-party service providers, we will work with them to ensure appropriate notification and remediation steps are taken in accordance with applicable laws.

10. Retention and Deletion

10.1 Retention of Information

We retain your personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Account information: while your account is active and up to 2 years after closure
  • Transaction records: at least 7 years for financial reporting and tax purposes
  • Payment information: partial details up to 3 years after your last transaction
  • Communications between users: 3 years after the last message
  • Customer support communications: 2 years after resolution
  • Device and technical information: up to 13 months
  • Dispute-related information: 7 years from resolution
  • Marketing preferences: until you change preferences or close your account

10.2 Deletion of Information

When your personal information is no longer required, we will take reasonable steps to destroy or permanently de-identify it, unless retention is required by law or for ongoing business needs.

10.3 Account Closure

If you close your account, we will deactivate your account, de-identify or delete your personal information where practical, and retain information necessary for legal, security, and operational purposes.

11. Your Privacy Rights and Choices

11.1 Access and Correction

You have the right to access and correct personal information we hold about you. Contact us using the details below.

11.2 Deletion

In certain circumstances, you may request that we delete your personal information. We will comply unless we are required or permitted to retain it under applicable law.

11.3 Marketing Communications and Consent

We distinguish between service communications (essential account and booking messages) and marketing communications (promotional content). You can provide or withdraw marketing consent through account settings, unsubscribe links, or by contacting us. Service-related communications will still be sent when necessary.

11.4 Complaint Process

If you believe we have breached the Australian Privacy Principles, contact us using the details below. We will investigate and respond within a reasonable time. If you are not satisfied, you may complain to the OAIC at www.oaic.gov.au or call 1300 363 992.

12. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at: support@drooda.com

See also our Terms and Conditions.