Privacy Policy

Last updated: June 6, 2026

TrackMyPlace ("we", "our", "us") operates the TrackMyPlace platform at trackmyplace.com. We are committed to protecting your privacy. This policy explains how we collect, use, store, and safeguard your information when you use our real estate campaign management platform.

1. Information We Collect

We collect the following types of information:

  • Account information: Your name, email address, and profile details provided during registration or via Google Sign-In.
  • Platform data: Listings, client details, campaign stages, notes, documents, and other data you enter into TrackMyPlace.
  • Usage data: Pages visited, features used, browser type, IP address, and device information.
  • Google account data: If you choose to connect your Google account for integrations, we access specific Google data as described in Section 9 below.

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the TrackMyPlace platform.
  • Authenticate your identity and manage your account.
  • Send transactional emails (e.g. password resets, notifications you have enabled).
  • Provide Google-integrated features you have explicitly enabled (email, calendar, contacts, drive).
  • Monitor and prevent fraud, abuse, or security incidents.

We do not sell, rent, or trade your personal information to third parties.

3. Legal Basis for Processing

We process your personal data based on:

  • Contract performance: To provide the services you signed up for.
  • Consent: When you connect third-party services such as Google.
  • Legitimate interests: To improve our platform and ensure its security.

4. Data Storage and Security

Your data is stored securely using industry-standard encryption. We use Supabase for authentication and data storage, which provides enterprise-grade security including encryption at rest and in transit (TLS 1.2+). Google OAuth tokens are encrypted using AES-256 before being stored in our database.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide our services. If you delete your account, your account will enter a 14-day grace period during which you may restore it. If you do not restore your account during that period, we will delete or anonymise your personal data from active systems, except where we are required or permitted by law to retain limited records. Google OAuth tokens are deleted immediately when you disconnect your Google account.

We also keep an internal audit log of mutating actions (such as creating, updating, or deleting a listing, document, or conversation) so we can investigate security incidents and respond to data-access requests. Audit log entries are retained for 13 months from the date of the action and are then automatically purged by a nightly job. You can request a copy of the audit log entries associated with your account at any time via the Export My Data tool in Settings.

6. Cookies

We use cookies and similar technologies in three categories: strictly necessary (to maintain your session and core platform functionality), analytics (aggregate usage and performance metrics — off by default), and marketing (currently inactive). Non-essential cookies are only set after you give consent via the cookie banner shown on your first visit. You can change your choice at any time from the banner or from Settings → Account. See our Cookies Policy for the full list of cookies, vendors, and retention periods.

7. Sub-processors and Cross-Border Disclosure

To operate TrackMyPlace, we engage the sub-processors listed below. Some of these recipients are located outside Australia. Before disclosing your personal information overseas we take reasonable steps as required by Australian Privacy Principle 8 (cross-border disclosure of personal information), including reviewing each vendor's privacy and security terms, entering into appropriate contractual protections where available (such as data processing terms or equivalent privacy and security commitments), and choosing recipients with safeguards consistent with the Australian Privacy Principles. The list below sets out the recipients, the purpose of disclosure, and the country in which processing occurs.

VendorPurposeData categoriesCountry of processingDPA / SCC
SupabaseAuthentication, primary database (Postgres), file storage.Account, platform and usage data.Singapore / USDPA
VercelApplication hosting, edge/serverless execution, web analytics.Account, usage data, IP address.USDPA
Google (Workspace APIs)Gmail, Calendar, Contacts and Drive integrations (opt-in per user).Account email, OAuth tokens, Google data you choose to access through TrackMyPlace.USDPA
Google Maps PlatformAddress geocoding and Places autocomplete used by the prospecting and address-search features.Property and search address strings; no user identifiers.USDPA
Microsoft (Graph)Outlook email integration (opt-in per user).Account email, OAuth tokens, Microsoft 365 data you choose to access through TrackMyPlace.US / EUDPA
StripeSubscription billing and payment processing.Account email, billing address, payment method metadata.US / IrelandDPA
TwilioSMS delivery to clients you contact through TrackMyPlace.Recipient phone number, message content, delivery metadata.USDPA
ResendTransactional email delivery (password resets, notifications, client-facing email).Recipient email address, message content, delivery metadata.US / EUDPA
SlackTeam messaging integration (opt-in per team).Account email, message content you choose to send through the integration.USDPA
SentryApplication error and performance monitoring.Account ID, request metadata, IP address, error stack traces.US / GermanyDPA
UpstashRedis-backed rate limiting and short-lived caching.Hashed account/IP identifiers, rate-limit counters.USDPA

Each sub-processor has its own privacy policy. We encourage you to review them, and we will update this list when we add, remove, or replace a sub-processor.

8. Your Rights

You have the right to:

  • Access your personal data and request a copy.
  • Correct inaccurate or incomplete data.
  • Delete your account and personal data.
  • Revoke consent for Google integrations at any time by disconnecting your Google account in Settings or via your Google Account permissions.
  • Export your data in a machine-readable format.

To exercise any of these rights, contact us at privacy@trackmyplace.com.

9. Google API Services — User Data Policy

TrackMyPlace offers optional Google integrations that require access to your Google account data. This section describes what data we access, why, and how we handle it.

9.1 Data We Access

When you connect your Google account, we request access to the following scopes:

  • Gmail (read and manage): We read your email messages to display relevant client communications within your TrackMyPlace campaign, and we may mark messages as read/unread, archive them, or apply labels when you take those actions inside TrackMyPlace. We do not permanently delete your emails.
  • Gmail (send): We send emails on your behalf when you compose and send messages through the TrackMyPlace platform. Emails are only sent when you explicitly initiate the action.
  • Google Calendar: We read and create calendar events to help you manage property inspections, client meetings, and settlement dates.
  • Google Contacts (read-only): We read your contacts to help you quickly add clients to your campaign. We do not modify your contacts.
  • Google Drive: We access files you specifically select or create through TrackMyPlace for document management (e.g. contracts, listing agreements).
  • Email address: We use your Google email address to identify your account.

9.2 How We Use Google Data

Google user data is used solely to provide the features described above within TrackMyPlace. Specifically:

  • We do not use Google user data for advertising or marketing purposes.
  • We do not sell, rent, or share Google user data with third parties.
  • We do not use Google user data to train machine learning or AI models.
  • We do not use Google user data for any purpose other than providing and improving the specific features you have enabled.

9.3 Storage and Protection of Google Data

  • Google OAuth tokens (access and refresh tokens) are encrypted using AES-256 encryption before being stored in our database.
  • Google user data is transmitted exclusively over HTTPS/TLS.
  • Access to Google data is restricted to authenticated users viewing only their own data.
  • We do not store copies of your Gmail messages, contacts, or calendar events beyond what is needed for real-time display.

9.4 Revoking Access

You can disconnect your Google account at any time from the Settings page in TrackMyPlace. When you disconnect:

  • Your Google OAuth tokens are immediately deleted from our database.
  • We will no longer have access to your Google account data.
  • You can also revoke access directly from your Google Account permissions page.

9.5 Google API Services Limited Use Disclosure

TrackMyPlace's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10. Children's Privacy

TrackMyPlace is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by posting a notice on the platform or sending you an email. Your continued use of TrackMyPlace after changes are posted constitutes acceptance of the updated policy.

12. Data Breach Response

We maintain an internal Notifiable Data Breaches (NDB) response runbook and a breach register in line with Part IIIC of the Privacy Act 1988 (Cth). If we suspect an eligible data breach may have occurred, we will assess the incident as soon as practicable and, in any event, within 30 days. Where a breach is likely to result in serious harm we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. Our designated Privacy Officer is the accountable person for this process; you can reach the Privacy Officer at privacy@trackmyplace.com. You can also lodge a complaint with the OAIC at oaic.gov.au or by calling 1300 363 992.

13. Contact Us

If you have questions about this privacy policy or how we handle your data, please contact our Privacy Officer at:

privacy@trackmyplace.com

Back to sign in