Trace

Privacy policy

This is the privacy policy of Sreejith Vijaya Mandiram trading as Trace (ABN 41 422 354 243) ("Trace", "we", "us").

Contact: hello@withtrace.io · Post: 2/8 Swan Avenue, Strathfield NSW 2135, Australia.

This Privacy Policy is made in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, and protect your data in connection with our website ("the Site") and our AI-powered document review and property data service ("the Service").

By using the Site or the Service, you agree to the collection, use, and disclosure of personal information as described in this Policy and our Terms of Service. If you provide us with personal information about someone else, you must ensure you're authorised to do so and that this Policy is brought to their attention where appropriate.

1. Whose information we handle

Our customers and their teams — the property professionals who subscribe to Trace and the people who use it under their account. For this information, we're the collecting organisation.

Our customers' clients and the people they invite — our customers use Trace to hold information about their own clients and deals and to share it with people they invite (clients, solicitors, inspectors and others). For that information, the customer decides what's collected and why; we store and process it on their behalf. If you're a customer's client or an invited participant and want to access or correct information held about you, contact that customer first — we'll help them respond, and you can also contact us.

Website visitors — if you browse withtrace.io or send us an enquiry.

2. What we collect

Account information — name, work email, organisation, role, and a password (stored only as a secure hash by our authentication provider). A phone number if you provide one. Billing information and payment details, once self-serve billing is live, to process your subscription.

Content you put into Trace — documents, deals, notes, messages, figures and any other material you and your invited participants upload, add or provide to us. This can include personal information about the people involved in a transaction.

Property data — property addresses and related property-specific information you request or that is generated through the Service.

Enquiries and support — what you send us through our contact form or in-app feedback (your message, and basic technical details like the page you were on and your browser).

Technical information — essential login cookies, IP addresses used for security and rate limiting, and logs of actions taken in the platform (who did what, when). We use aggregated or de-identified usage information to improve the product. We don't use advertising trackers or session-recording tools.

Mobile app (if you use one) — device information needed to run and secure the app, push-notification tokens if you enable them, and content you capture such as photos or voice notes, used only for features you invoke and with the operating system's permission prompts.

Browser extension (Trace Clipper, if you use it) — the extension works only on realestate.com.au and domain.com.au, and only when you use it. When you choose to capture a listing, it reads that listing's address and details from the page and — after showing you a summary and getting your confirmation — saves them to your chosen deal; when you open its panel, it looks up your firm's own existing records for the property and street. It does not collect listing photos or media, marketing text, agent contact details, or your browsing history, and it does nothing on any other site.

We don't collect tax file numbers, and we don't buy personal information from data brokers.

3. How we use it

To provide, secure, support and improve the platform.

To process your content as you direct — including AI-assisted document analysis, where the document text and limited deal context are sent to our AI providers (see section 4) to produce candidate findings for you to review.

To communicate with you: service and account notifications, and responses to your enquiries.

To improve and develop the Service including evaluating and improving performance of our AI models using de-identified or aggregated data.

Marketing only with your consent, always with a working unsubscribe. We never market to our customers' clients.

To meet our legal obligations and to establish or defend legal claims.

To detect, investigate, and prevent fraud, misuse, or security incidents.

Automated analysis, not automated decisions. Where Trace's AI reads a document you submit, it uses the document text and limited deal context you provide to produce candidate findings — extracted facts, flagged risks, and suggested questions — for your review. The AI does not decide anything on its own: it does not approve, reject, score, or recommend a property, a client, or a transaction, and no risk, question or action is finalised until a person on your team reviews and confirms it. The AI is an administrative and productivity tool that assists your own professional judgment — it is not used to inform agents or their clients on any decision.

We don't sell personal information. We use our AI providers on paid commercial API tiers whose terms provide that content sent through the API is not used to train their models.

4. Who we share it with

We share personal information only with:

Our service providers, under contracts requiring them to protect it and use it only to provide their service to us:

Our employees and contractors who need it to provide the Service.

Payment processors, for billing purposes, once self-serve billing is live.

Professional advisers (for example legal or accounting), where necessary.

Your organisation and the people it invites, according to the access it sets.

Regulators, law enforcement or courts, where required or authorised by law.

A buyer of our business, if it's sold, on terms that protect your information consistently with this policy.

5. Overseas disclosure

Some of our providers process information outside Australia (see the table above — mainly the United States and the EU). We take reasonable steps to ensure they protect it consistently with the APPs.

Any documents or data you upload or provide to us, which may contain third-party information, are processed by our proprietary AI software to generate summaries, extracts and property-specific data outputs. This processing may involve personal information being transmitted and processed by AI infrastructure and data centres located overseas — as a result, personal information may be transmitted to, stored, and processed in these countries, and potentially other countries where our service providers operate or update their infrastructure.

Before disclosing any personal information overseas, we take reasonable steps required by Australian Privacy Principle 8, including entering into contractual arrangements with overseas recipients requiring them to handle personal information in a manner consistent with the Australian Privacy Principles, where practicable. You acknowledge that overseas recipients may not be subject to the Privacy Act, and the protections and avenues of redress available to you may differ from those in Australia; that by uploading documents containing third-party personal information, you are authorising this overseas transmission and processing for the purpose of receiving the Service; and that it is your responsibility to ensure you are entitled to provide that information for this purpose.

We do not use uploaded documents or data you provide to us to train publicly available third-party AI models. Any use of data to improve our own AI systems is limited to de-identified or aggregated data as described above.

6. Security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure, including staff confidentiality obligations, access controls, encryption in transit and at rest, and separation between customers' data. No system or storage is completely secure, and while we take reasonable steps to protect personal information, we cannot guarantee absolute security. If a data breach is likely to cause you serious harm, we'll notify you and the OAIC as the law requires.

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements, after which it is securely deleted or de-identified.

7. Access, correction and retention

You can ask us to access or correct personal information we hold about you — email hello@withtrace.io and we'll respond within a reasonable time. We keep personal information only as long as needed for the purposes above, then delete or de-identify it — except where a law requires us (or the customer we hold it for) to retain particular categories of records for a minimum period, in which case we keep those records for that period. Routine backups are kept for a limited period before being overwritten.

8. Cookies

We use only essential cookies needed to log you in and keep the service secure. We don't use advertising or tracking cookies. If we adopt an analytics tool in future, we'll update this policy first.

9. Complaints

If you have a privacy concern, contact us at hello@withtrace.io and we'll work to resolve it. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

10. Changes

We may update this policy from time to time to reflect changes in our practices, technology or legal requirements. The updated version will be posted on the Site and note the date at the top. If a change is significant, we'll take reasonable steps to tell you.