Legal

Privacy Policy

Last updated: 9 April 2026

1. About this Policy

HEARTHSTONE is a home maintenance marketplace operated by Inevara Pty Ltd (ABN [TBD — confirm with Inevara Pty Ltd before public launch]), a company incorporated in Australia (“Inevara”, “we”, “us”, or “our”). HEARTHSTONE is one of the SINGULARITY family of marketplace platforms operated by Inevara.

This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use the HEARTHSTONE platform and associated services (collectively, the “Platform”).

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”). For users in the EEA or UK, additional rights under the GDPR and UK GDPR may apply.

By creating an account or using the Platform you acknowledge you have read this Policy. If you do not agree, please do not use the Platform.

2. Information We Collect

2.1 Account information

When you register, we collect:

  • Full name and display name
  • Email address
  • Password (stored as a salted cryptographic hash — never in plain text)
  • Mobile phone number (optional)

2.2 Property information (homeowners)

To provide maintenance matching, we collect:

  • Property address and postcode
  • Property type, year built, bedrooms, bathrooms
  • Features such as pool or garden
  • Maintenance preferences and annual budget range

2.3 Provider profile information

If you register as a home maintenance professional, we also collect:

  • Business name and ABN (where applicable)
  • Licence type and licence number (e.g. QBCC builder's licence)
  • Insurance and police check documentation
  • Service areas and specialisations
  • Bank account details for payment disbursement (held by our payment processor)

2.4 Booking and transaction records

For every booking, we record:

  • Date, time, service type, and property details
  • Consumer and provider identifiers
  • Booking status history
  • Payment metadata (amount, transaction reference, partial card details)

2.5 Device and analytics data

We automatically collect technical information including IP address, browser type, device identifiers, pages visited, and session data for security monitoring, fraud detection, and product improvement.

3. How We Use Your Information

We use personal information only for the purposes set out below:

  • Creating and managing your account
  • Matching homeowners with suitable maintenance providers
  • Processing bookings and payments
  • Sending booking confirmations and reminders
  • Fraud detection, security monitoring, and abuse prevention
  • Analytics and product improvement (aggregate/de-identified data)
  • Complying with legal obligations
  • Dispute resolution and platform safety investigations

4. When We Share Your Information

We do not sell your personal information. We disclose it only in the following circumstances:

4.1 With providers upon booking

When you confirm a booking, we share your name, contact information, property details, and relevant notes with the provider solely for service delivery.

4.2 Payment processors

Payments are processed by third-party providers including Stripe and/or Paddle. We do not store full card numbers.

4.3 Infrastructure providers

We host the Platform on Amazon Web Services infrastructure in Australia (Sydney, ap-southeast-2) under data processing agreements.

4.4 Legal requirements

We may disclose personal information if required by law, court order, or regulatory direction.

5. How Long We Keep Your Information

  • Account and profile data: retained for the life of your account plus 24 months after closure.
  • Booking and transaction records: retained for 7 years (Australian taxation law requirements).
  • Device and analytics logs: retained for 13 months in identifiable form, then aggregated.

6. How We Protect Your Information

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption at rest for sensitive fields
  • Passwords stored using cryptographic hashing
  • Role-based access controls
  • Multi-factor authentication required for administrative access
  • Data stored in AWS ap-southeast-2 (Sydney) — Australian soil

If you believe your account has been compromised, contact us immediately at [email protected].

7. Cookies and Tracking Technologies

We use essential cookies to maintain your session and authentication state, preference cookies to remember your settings, and analytics cookies (with your consent where required) to improve the Platform.

8. Your Rights and Choices

Under the Australian Privacy Principles, you have the right to:

  • Access: Request a copy of your personal information. We will respond within 30 days.
  • Correction: Request correction of inaccurate information. You can update most details in your account settings.
  • Deletion: Request deletion of your account and associated personal information, subject to our retention obligations.
  • Complaint: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your personal information.

9. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact our Privacy Officer:

Inevara Pty Ltd — Privacy Officer
HEARTHSTONE Privacy Enquiries
Email: [email protected]
Australia

We aim to respond to all privacy enquiries within 30 days.

10. Changes to this Policy

We may update this Privacy Policy from time to time. When we make a material change, we will notify you by email and/or by displaying a prominent notice on the Platform at least 14 days before the changes take effect.

© 2026 Inevara Pty Ltd. All rights reserved.