Privacy Policy

CasaFlow Pty Ltd  ·  Last updated: 21 April 2026

1. About CasaFlow

CasaFlow is a cloud-based property management platform designed for Australian real estate agencies. We provide tools for managing tenancies, properties, maintenance, trust accounting, inspections, and business development. CasaFlow is operated by CasaFlow Pty Ltd (ABN pending), based in Queensland, Australia.

By using CasaFlow, you agree to the collection and use of information as described in this policy.

2. Information We Collect

We collect information you provide directly, including:

  • Account details: name, email address, phone number, job title
  • Agency information: agency name, ABN, address, branding assets
  • Property data: property addresses, tenancy details, lease terms, rental amounts
  • Financial data: trust transactions, disbursements, invoices (no credit card numbers are stored on our servers)
  • Communication data: notes, correspondence, and activity logs related to properties and tenancies
  • Inspection data: photos, condition reports, area notes

We also collect information automatically, including:

  • Log data: IP addresses, browser type, pages visited, access times
  • Device information: device type, operating system
  • Usage data: features used, actions taken within the application

3. Google Gmail Integration

CasaFlow offers an optional Gmail integration for business development staff. When you connect your Gmail account, CasaFlow requests access to read and index email metadata (subject lines, sender/recipient addresses, snippets, and timestamps) in order to surface relevant email threads alongside your prospect and contact records.

What we access:

  • Email metadata: subject, from/to addresses, date, snippet (first ~100 characters)
  • Thread structure: grouping of messages into conversations

What we do not access or store:

  • Full email body content
  • Email attachments
  • Email from accounts other than the connected staff member
  • Contacts, calendar, or any Google service beyond Gmail

Gmail data is used solely to display email activity within CasaFlow against matching contacts. It is never sold, shared with third parties, used for advertising, or used to train AI or machine learning models.

You can disconnect your Gmail account at any time from within CasaFlow. Upon disconnection, your OAuth tokens are immediately revoked and deleted. Indexed email metadata is removed within 30 days of disconnection.

CasaFlow's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the CasaFlow platform
  • Process trust accounting transactions and generate financial statements
  • Send transactional emails (rent receipts, EOFY statements, maintenance updates)
  • Enable digital document signing via our e-signature integration (Annature)
  • Provide AI-assisted features including our Charlotte voice assistant
  • Respond to support requests
  • Comply with legal obligations under Queensland and Australian law, including the Residential Tenancies and Rooming Accommodation Act 2008 (Qld) and the Agents Financial Administration Act 2014 (Qld)

5. Data Storage and Security

CasaFlow stores data on servers located in Australia via Supabase (hosted on AWS Sydney region). Data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256.

We implement row-level security controls ensuring that each agency can only access their own data. Staff members within an agency can only access records relevant to their role.

6. Sharing Your Information

We do not sell your personal information. We may share data with:

  • Supabase — database and authentication infrastructure
  • Vercel — application hosting
  • Resend — transactional email delivery
  • Annature — digital document signing (Australian provider)
  • Vapi / ElevenLabs — voice AI infrastructure for the Charlotte assistant
  • Google — where you have connected your Gmail account
  • Government and regulatory bodies — where required by law

All third-party providers are contractually required to handle your data in accordance with applicable privacy laws.

7. Your Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your information (subject to legal retention obligations)
  • Withdraw consent for optional integrations (e.g. Gmail) at any time
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)

To exercise any of these rights, contact us at privacy@casaflow.au. We will respond within 30 days.

8. Data Retention

We retain your data for as long as your agency account is active. Upon account termination, data is retained for 7 years to comply with Queensland trust accounting record-keeping requirements under the Agents Financial Administration Act 2014 (Qld), after which it is securely deleted.

Gmail integration data (OAuth tokens and indexed email metadata) is deleted within 30 days of disconnecting the Gmail integration.

9. Cookies

CasaFlow uses session cookies for authentication and to maintain your logged-in state. We do not use advertising cookies or third-party tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify agency administrators by email. Continued use of CasaFlow after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related enquiries, please contact:

CasaFlow Pty Ltd

Queensland, Australia

Email: privacy@casaflow.au

Support: support@casaflow.au

casaflow.au · © 2026 CasaFlow Pty Ltd. All rights reserved.