Legal
Effective 4 September 2026. Last updated 4 September 2026.
This policy describes how we actually handle personal information. It is not marketing copy. It is written for the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and for people in New South Wales.
If this policy does not match how the product works, the product description in this policy is the one we intend to stand behind. Practices change; when they do, we will update the date at the top and the relevant sections.
Reverb is the name of the software service at https://www.reverbprop.com and related application, API, and @reverbprop.com email addresses.
The business is operated from New South Wales, Australia.
Contact: nickolmos@team.reverbprop.com.
A registered company name and ABN are not published on this website. You may request those details at the contact email above.
Reverb is software for real estate agents. It is not a licensed real estate agency. We do not sell or let property as an agent. Agents who use Reverb remain responsible for their own licensing under the Property and Stock Agents Act 2002 (NSW) and equivalent laws in other States and Territories.
This policy applies to personal information handled through:
It covers four groups of people:
The Privacy Act 1988 (Cth) and the APPs apply to APP entities. A business with annual turnover of $3 million or less is often a “small business operator” and outside the Act (s 6C and s 6D). That exemption does not apply to every small business. Among other exceptions, it does not apply if the business provides a benefit, service, or advantage to collect personal information about another individual from anyone else, or discloses such information for a benefit, service, or advantage, unless an exception (including consent) applies (s 6D(4)).
Reverb’s paid service includes collecting and processing Contact information (including from realestate.com.au, Domain, Tally forms, and inbound email) so that Customers can run lead follow-up. This policy is written on the basis that we handle that information in line with the APPs. We do not rely, in this policy, on the small business exemption.
From 1 July 2026, many real estate agents who are reporting entities under anti-money laundering laws are APP entities even if their turnover is under $3 million. That is the Customer’s position, not a statement that Reverb is itself a real estate agent.
Other laws that matter to this service include the Spam Act 2003 (Cth); the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)), which applies in NSW through the Fair Trading Act 1987 (NSW); and the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. The Privacy and Personal Information Protection Act 1998 (NSW) applies to NSW public sector agencies, not to this private business.
This policy is not legal advice. APP 5 still requires a collection notice at or around the time of collection. This policy is the public APP 1 document. It does not replace a specific notice on a form or in an email where one is required.
We handle some personal information for our own business (accounts, billing, marketing, product analytics, security). For that information, we determine the purposes of handling.
We also handle Contact information in order to provide the Service the Customer has asked for: ingesting enquiries, storing conversations, generating draft emails, sending email from a Reverb alias, scoring leads, and booking appointments. The Customer decides to connect portals and forms, turn automation on, and continue or stop a conversation. The Customer remains responsible for telling Contacts how that Customer handles personal information, and for complying with the Privacy Act, the Spam Act, and real estate advertising rules in connection with those Contacts.
We still choose the processors, hosting, and AI providers used to run the platform. Overseas disclosure of Contact information to those providers is described in this policy because it happens on our systems.
Visitors. Device and usage information generated by the site (pages viewed, performance timing). If you are on a Vercel-hosted deployment, Vercel Analytics and Speed Insights may record aggregated or limited usage and performance data. We set authentication cookies when you sign in. We do not run a separate advertising cookie stack in the application code. Optional analytics libraries (for example Plausible, Google tag, or PostHog) only fire if those scripts are present in the page; they are not bundled into the application as of the date of this policy.
Prospects. Name, email, agency, phone, team size, free-text message, audit answers, and similar fields you submit. We may also hold IP address and user agent on some marketing endpoints (waitlist, marketing demo email) for abuse control. Waitlist and sales-enquiry records are stored in our database.
Customers. Account email and password hash or Google account identifiers; name; phone; agency name and address; licence number if you enter one; location; listing preferences; AI voice preferences; automation settings; login times; subscription and usage counters. We do not have an ABN field for agents. We do not store card numbers; Stripe does.
Contacts. Information varies by source. Typical fields include name, email, phone, suburb or location interest, intended purchase timing, price range, financing or mortgage pre-approval status, first-home-buyer status, date of birth (if submitted on a Tally form), other decision-makers, inspection preferences, listing identifiers and addresses, notes, lead scores, and appointment times and locations. We store the full text and HTML of emails we send or receive for that conversation, including subject lines and email addresses. We may store a structured “customer profile” extracted from messages (for example budget or timeline signals).
We do not seek identity documents or photographs of people. Property images that a Customer uploads are listing photos, stored in object storage. Depending on bucket settings, image URLs may be readable without logging in.
We do not intend to collect “sensitive information” as defined in the Privacy Act (health, racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, criminal records, biometric templates, and similar). Email bodies and form notes can still contain whatever a person writes, including information of that kind. If they do, we hold that content because it arrived in the message or form, not because we asked for those categories.
The Service is aimed at adult agents and adult property enquirers. We do not operate an age gate. Date of birth on a Tally form could in theory relate to a person under 18. We do not use Reverb to target children. If we learn we hold personal information of a child in circumstances where we should not, we will delete it on request where we can.
We collect it in these ways:
Where APP 3 requires collection from the individual, we often collect Contact information from the Customer or from a portal or form the Customer configured, because that is how an enquiry reaches an agent. If you are a Contact, the first time you hear from a reverbprop.com address is usually after you already enquired about a listing.
We use personal information to:
We do not sell personal information. We do not buy marketing lists. We do not use Contact information to market Reverb to those Contacts.
Production email is sent and received through Resend on the domain reverbprop.com. Each Customer is allocated an alias (stored in our database). The same address is used to capture portal enquiries and to send mail to Contacts. The visible From name is the agent’s name; the address is the Reverb alias, not the agent’s personal Gmail. Retired aliases are not reused.
Gmail is not the production mail transport. A Gmail integration still exists in the codebase as a fallback and is not the production path. Google Calendar uses a platform OAuth credential (not each agent connecting their own Google account for mail). Appointment invites can include a Contact’s email address.
Open- and click-tracking pixels are switched off in the production and staging environment configuration we ship. We still store email content in our database.
Outbound drafts, extraction of facts from messages (for example timing, financing, phone numbers), urgency and intent classification, and a price-compliance rewrite are generated by third-party models. The application calls OpenRouter (openrouter.ai). It does not call first-party OpenAI, Google AI Studio, or Anthropic endpoints.
What is sent: message text (including excerpts of inbound email and recent transcript turns), agent identity and voice instructions, listing context used for the reply (advertised price and listing facts; internal property notes are excluded from model context), and similar prompt material. Buyer email content is sent to OpenRouter and then only to a pinned host for that request.
Every model request is required, in application code, to include OpenRouter provider constraints: zdr true (zero-data-retention endpoint only), data_collection deny, allow_fallbacks false, and provider.only set to the host slugs for that chain position. There is no code path that omits that block. If OpenRouter cannot serve the request on a pinned ZDR host, the request fails. It is not retried on an unvetted or first-party (non-ZDR) endpoint. A leftover environment value pointing at an unpinned slug is ignored for this routing.
The pinned chain, verified against OpenRouter ZDR endpoints on 26 August 2026, is: openai/gpt-5-mini on Azure; then google/gemini-3.7-flash on Google Vertex; then anthropic/claude-haiku-4.5 on Amazon Bedrock or Google Vertex. Price-compliance rewrites use the same pinned chain (gpt-5-mini), not a separate unpinned model. Which model and host handled a completion is recorded. Those slugs can be changed by MODEL_CHAIN_* configuration; adding a host is a change to this policy.
Zero-data-retention here means the inference host is one OpenRouter lists as not retaining prompts for training or later use, and that we refuse non-ZDR routes. It does not mean Reverb deletes the enquiry. We still store emails, leads, and related records in our own database as described in section 13. OpenRouter still sees the request long enough to route it. Some pinned hosts support prompt caching for the call; that is not the same as keeping the enquiry to train a model.
We keep usage counts of AI emails per billing period. We do not store a complete archive of every prompt in a dedicated prompt table. Application logs may include truncated snippets. Logs are filtered for some obvious identifiers; that is not a guarantee that no personal information appears in logs. An OpenRouter prompt-injection guardrail is set to flag only; it is not used as a block or as a guarantee that prompts are safe.
Automated processing: leads are scored; messages are classified; replies may be sent without a human reviewing each one if the Customer has automation on and confidence checks pass. That can affect how quickly a Contact hears back, what they are asked, and whether an inspection is offered. It does not decide whether someone may buy a property, obtain finance, or enter a contract. Customers can see conversations in the dashboard and take over. From 10 December 2026, APP entities must include certain automated decision-making disclosures in their APP privacy policy where those decisions significantly affect individuals. This section is the disclosure of what the product does today.
We disclose personal information to the service providers that run the product, and otherwise as set out below.
Firebase remains in legacy setup notes. Current application data is stored in Supabase, not Firebase, unless an environment is still configured otherwise.
Yes. We are likely to disclose personal information to overseas recipients (APP 1.4(f)). Where it is practicable to name countries (APP 1.4(g)), they include:
Supabase and Render may store or process data in Australia or overseas. We have not published a confirmed Australian-only region for the production database in the public repository, so you should assume personal information may be stored outside Australia.
APP 8 generally requires us, before disclosing personal information to an overseas recipient, to take reasonable steps to ensure the recipient does not breach the APPs, and we may remain accountable for that handling. For model inference, those steps are the ZDR pinning described in section 9, on OpenRouter’s standard terms and its labelling of ZDR endpoints. We do not claim a separate APP-equivalent contract with Azure, Vertex, or Bedrock, and we do not claim that inference stays in Australia.
Information is held in the processors listed above, accessed over HTTPS. We use account authentication and access controls in the application (including agency scoping). We do not claim a specific certification (for example ISO 27001 or SOC 2) in this policy.
Retention in practice, as the product works today:
APP 11 requires us to take reasonable steps to destroy or de-identify personal information when we no longer need it for a permitted purpose. If you want information deleted sooner, email us. We will say what we can delete and what we must keep.
You can ask us for access to personal information we hold about you, or to correct it if it is wrong, out of date, or incomplete (APP 12 and APP 13). Email contact. We will need enough information to identify you. We may refuse in the circumstances the Privacy Act allows, and we will tell you why if we do.
If you are a Contact, we may also point you to the Customer (the listing agent or agency) because they hold the client relationship. That does not stop you making the request to us. Customers can correct much of their own profile in Settings. There is no export button and no account-erasure button in the product today. We will handle a written request as a support task.
Customers can delete individual leads as described in section 13. Deleting a lead is not a complete wipe of every email copy.
We send product and waitlist email to addresses that were submitted to us for that purpose (waitlist, demo, sales enquiry, audit report). Those messages must identify us and include a way to opt out (Spam Act 2003 (Cth) ss 16–18). Use the unsubscribe link in the message, the unsubscribe page, or email contact. We must give effect to an unsubscribe request within five working days. Do not require a login to opt out of our marketing mail.
Mail we send to Contacts is sent for the Customer, usually because the Contact enquired about a listing. The application will stop automated follow-up if the Contact’s lead record is marked unsubscribed. A Contact can reply with words such as “unsubscribe”, “stop”, or “opt out”, or can email us. Automated buyer emails are generated without an unsubscribe footer in the body (the writer is instructed not to add one). We do not claim that every buyer email currently meets every technical detail of Spam Act s 18. Customers are responsible for their own Spam Act position when they turn automation on. We will still honour a clear opt-out that reaches our systems.
If we have reasonable grounds to believe an eligible data breach has occurred under Part IIIC of the Privacy Act, we will notify the Australian Information Commissioner and affected individuals as required. You can also email contact if you think there has been a breach.
If you think we have mishandled personal information, email contact with “Privacy complaint” in the subject. Include what happened and how we can reach you. We will acknowledge the complaint and respond in writing after we have looked into it.
If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au, phone 1300 363 992). For consumer-contract issues you may also contact NSW Fair Trading. For spam, you may contact the Australian Communications and Media Authority.
We will update this page when our practices or the law require it. The date at the top is the date of the current version. If a change is material, we will also email the address on the Customer account where we reasonably can.
Email: nickolmos@team.reverbprop.com. Place of business: New South Wales, Australia. Website: https://www.reverbprop.com.
If you need this policy in another format, say so in your email (APP 1.6).