Reverb
HomeFeaturesTrustPricing
Sign InRequest a demo
Reverb

The enquiry desk for listing offices.

Product

  • Features
  • Pricing
  • Trust
  • Request a demo

Legal

  • Privacy Policy
  • Terms of Service

Company

  • Contact
  • Work with us

© 2026 Reverb. All rights reserved.

Legal

Privacy Policy

Effective 4 September 2026. Last updated 4 September 2026.

This policy describes how we actually handle personal information. It is not marketing copy. It is written for the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and for people in New South Wales.

If this policy does not match how the product works, the product description in this policy is the one we intend to stand behind. Practices change; when they do, we will update the date at the top and the relevant sections.

Contents

  1. 1. Who we are
  2. 2. What this policy covers
  3. 3. The law this policy is written under
  4. 4. Our role and the Customer’s role
  5. 5. Kinds of personal information we collect and hold
  6. 6. How we collect personal information
  7. 7. Why we collect, hold, use, and disclose it
  8. 8. Email identity (read this if you use or receive Reverb mail)
  9. 9. Artificial intelligence
  10. 10. Who we disclose personal information to
  11. 11. Overseas disclosure
  12. 12. Cookies and similar technologies
  13. 13. How we hold information, and for how long
  14. 14. Access, correction, and deletion
  15. 15. Direct marketing and the Spam Act
  16. 16. Data breaches
  17. 17. Complaints
  18. 18. Changes to this policy
  19. 19. Contact

1. Who we are

Reverb is the name of the software service at https://www.reverbprop.com and related application, API, and @reverbprop.com email addresses.

The business is operated from New South Wales, Australia.

Contact: nickolmos@team.reverbprop.com.

A registered company name and ABN are not published on this website. You may request those details at the contact email above.

Reverb is software for real estate agents. It is not a licensed real estate agency. We do not sell or let property as an agent. Agents who use Reverb remain responsible for their own licensing under the Property and Stock Agents Act 2002 (NSW) and equivalent laws in other States and Territories.

2. What this policy covers

This policy applies to personal information handled through:

  • the websites at reverbprop.com and www.reverbprop.com, including marketing pages (features, pricing, book a demo, early-access waitlist, and the lead-response audit)
  • the Reverb application (accounts, dashboard, leads, conversations, appointments, properties, automation, billing)
  • the API at api.reverbprop.com
  • email sent from or received at addresses on reverbprop.com

It covers four groups of people:

  • Visitors: people who load the website or application
  • Prospects: people who join the waitlist, request a demo, submit a sales enquiry, run the audit, or ask for a marketing demo email
  • Customers: agents and agency staff who create an account
  • Contacts: buyers and other individuals whose details sit in a Customer’s account (enquiries, emails, forms, appointments)

3. The law this policy is written under

The Privacy Act 1988 (Cth) and the APPs apply to APP entities. A business with annual turnover of $3 million or less is often a “small business operator” and outside the Act (s 6C and s 6D). That exemption does not apply to every small business. Among other exceptions, it does not apply if the business provides a benefit, service, or advantage to collect personal information about another individual from anyone else, or discloses such information for a benefit, service, or advantage, unless an exception (including consent) applies (s 6D(4)).

Reverb’s paid service includes collecting and processing Contact information (including from realestate.com.au, Domain, Tally forms, and inbound email) so that Customers can run lead follow-up. This policy is written on the basis that we handle that information in line with the APPs. We do not rely, in this policy, on the small business exemption.

From 1 July 2026, many real estate agents who are reporting entities under anti-money laundering laws are APP entities even if their turnover is under $3 million. That is the Customer’s position, not a statement that Reverb is itself a real estate agent.

Other laws that matter to this service include the Spam Act 2003 (Cth); the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)), which applies in NSW through the Fair Trading Act 1987 (NSW); and the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. The Privacy and Personal Information Protection Act 1998 (NSW) applies to NSW public sector agencies, not to this private business.

This policy is not legal advice. APP 5 still requires a collection notice at or around the time of collection. This policy is the public APP 1 document. It does not replace a specific notice on a form or in an email where one is required.

4. Our role and the Customer’s role

We handle some personal information for our own business (accounts, billing, marketing, product analytics, security). For that information, we determine the purposes of handling.

We also handle Contact information in order to provide the Service the Customer has asked for: ingesting enquiries, storing conversations, generating draft emails, sending email from a Reverb alias, scoring leads, and booking appointments. The Customer decides to connect portals and forms, turn automation on, and continue or stop a conversation. The Customer remains responsible for telling Contacts how that Customer handles personal information, and for complying with the Privacy Act, the Spam Act, and real estate advertising rules in connection with those Contacts.

We still choose the processors, hosting, and AI providers used to run the platform. Overseas disclosure of Contact information to those providers is described in this policy because it happens on our systems.

5. Kinds of personal information we collect and hold

Visitors. Device and usage information generated by the site (pages viewed, performance timing). If you are on a Vercel-hosted deployment, Vercel Analytics and Speed Insights may record aggregated or limited usage and performance data. We set authentication cookies when you sign in. We do not run a separate advertising cookie stack in the application code. Optional analytics libraries (for example Plausible, Google tag, or PostHog) only fire if those scripts are present in the page; they are not bundled into the application as of the date of this policy.

Prospects. Name, email, agency, phone, team size, free-text message, audit answers, and similar fields you submit. We may also hold IP address and user agent on some marketing endpoints (waitlist, marketing demo email) for abuse control. Waitlist and sales-enquiry records are stored in our database.

Customers. Account email and password hash or Google account identifiers; name; phone; agency name and address; licence number if you enter one; location; listing preferences; AI voice preferences; automation settings; login times; subscription and usage counters. We do not have an ABN field for agents. We do not store card numbers; Stripe does.

Contacts. Information varies by source. Typical fields include name, email, phone, suburb or location interest, intended purchase timing, price range, financing or mortgage pre-approval status, first-home-buyer status, date of birth (if submitted on a Tally form), other decision-makers, inspection preferences, listing identifiers and addresses, notes, lead scores, and appointment times and locations. We store the full text and HTML of emails we send or receive for that conversation, including subject lines and email addresses. We may store a structured “customer profile” extracted from messages (for example budget or timeline signals).

We do not seek identity documents or photographs of people. Property images that a Customer uploads are listing photos, stored in object storage. Depending on bucket settings, image URLs may be readable without logging in.

We do not intend to collect “sensitive information” as defined in the Privacy Act (health, racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, criminal records, biometric templates, and similar). Email bodies and form notes can still contain whatever a person writes, including information of that kind. If they do, we hold that content because it arrived in the message or form, not because we asked for those categories.

The Service is aimed at adult agents and adult property enquirers. We do not operate an age gate. Date of birth on a Tally form could in theory relate to a person under 18. We do not use Reverb to target children. If we learn we hold personal information of a child in circumstances where we should not, we will delete it on request where we can.

6. How we collect personal information

We collect it in these ways:

  • Directly from you: account signup (email and password, or Google sign-in), onboarding, settings, waitlist, demo and sales forms, audit, billing portal actions.
  • From listing portals: if a Customer puts their Reverb alias (for example jane.smith@reverbprop.com) on a realestate.com.au or Domain profile or listing, those businesses email the enquiry to that alias. We read that email and create or update a Contact. The sender of that notification is the portal, not the buyer.
  • From Tally forms: if a Customer uses our Tally intake or property-enquiry forms, Tally sends us the submitted fields.
  • From inbound email: when a Contact replies to a Reverb alias, or when a Customer forwards a portal email to that alias, we store the message and may generate a reply.
  • From our own systems: lead scores, usage counts, delivery metadata, and similar records we create while running the Service.
  • From payment and identity providers: Stripe (subscription status, customer id, email); Google (account profile for sign-in; Calendar event attendees when an appointment is created).

Where APP 3 requires collection from the individual, we often collect Contact information from the Customer or from a portal or form the Customer configured, because that is how an enquiry reaches an agent. If you are a Contact, the first time you hear from a reverbprop.com address is usually after you already enquired about a listing.

7. Why we collect, hold, use, and disclose it

We use personal information to:

  • create and run accounts, including Google sign-in
  • take payment and manage subscriptions (through Stripe)
  • ingest enquiries, match them to listings and agents, and keep a conversation history
  • generate and send email from the Customer’s Reverb alias, in the Customer’s name, including first-contact email after a portal enquiry
  • score and summarise leads, including automated scoring
  • create calendar events and invite attendees when an appointment is booked
  • enforce usage limits, prevent abuse, and keep the Service secure
  • answer support and demo requests, and send waitlist or product email you asked for
  • improve the product using aggregated or de-identified usage where we can
  • comply with law, deal with disputes, and keep records we are required or entitled to keep

We do not sell personal information. We do not buy marketing lists. We do not use Contact information to market Reverb to those Contacts.

8. Email identity (read this if you use or receive Reverb mail)

Production email is sent and received through Resend on the domain reverbprop.com. Each Customer is allocated an alias (stored in our database). The same address is used to capture portal enquiries and to send mail to Contacts. The visible From name is the agent’s name; the address is the Reverb alias, not the agent’s personal Gmail. Retired aliases are not reused.

Gmail is not the production mail transport. A Gmail integration still exists in the codebase as a fallback and is not the production path. Google Calendar uses a platform OAuth credential (not each agent connecting their own Google account for mail). Appointment invites can include a Contact’s email address.

Open- and click-tracking pixels are switched off in the production and staging environment configuration we ship. We still store email content in our database.

9. Artificial intelligence

Outbound drafts, extraction of facts from messages (for example timing, financing, phone numbers), urgency and intent classification, and a price-compliance rewrite are generated by third-party models. The application calls OpenRouter (openrouter.ai). It does not call first-party OpenAI, Google AI Studio, or Anthropic endpoints.

What is sent: message text (including excerpts of inbound email and recent transcript turns), agent identity and voice instructions, listing context used for the reply (advertised price and listing facts; internal property notes are excluded from model context), and similar prompt material. Buyer email content is sent to OpenRouter and then only to a pinned host for that request.

Every model request is required, in application code, to include OpenRouter provider constraints: zdr true (zero-data-retention endpoint only), data_collection deny, allow_fallbacks false, and provider.only set to the host slugs for that chain position. There is no code path that omits that block. If OpenRouter cannot serve the request on a pinned ZDR host, the request fails. It is not retried on an unvetted or first-party (non-ZDR) endpoint. A leftover environment value pointing at an unpinned slug is ignored for this routing.

The pinned chain, verified against OpenRouter ZDR endpoints on 26 August 2026, is: openai/gpt-5-mini on Azure; then google/gemini-3.7-flash on Google Vertex; then anthropic/claude-haiku-4.5 on Amazon Bedrock or Google Vertex. Price-compliance rewrites use the same pinned chain (gpt-5-mini), not a separate unpinned model. Which model and host handled a completion is recorded. Those slugs can be changed by MODEL_CHAIN_* configuration; adding a host is a change to this policy.

Zero-data-retention here means the inference host is one OpenRouter lists as not retaining prompts for training or later use, and that we refuse non-ZDR routes. It does not mean Reverb deletes the enquiry. We still store emails, leads, and related records in our own database as described in section 13. OpenRouter still sees the request long enough to route it. Some pinned hosts support prompt caching for the call; that is not the same as keeping the enquiry to train a model.

We keep usage counts of AI emails per billing period. We do not store a complete archive of every prompt in a dedicated prompt table. Application logs may include truncated snippets. Logs are filtered for some obvious identifiers; that is not a guarantee that no personal information appears in logs. An OpenRouter prompt-injection guardrail is set to flag only; it is not used as a block or as a guarantee that prompts are safe.

Automated processing: leads are scored; messages are classified; replies may be sent without a human reviewing each one if the Customer has automation on and confidence checks pass. That can affect how quickly a Contact hears back, what they are asked, and whether an inspection is offered. It does not decide whether someone may buy a property, obtain finance, or enter a contract. Customers can see conversations in the dashboard and take over. From 10 December 2026, APP entities must include certain automated decision-making disclosures in their APP privacy policy where those decisions significantly affect individuals. This section is the disclosure of what the product does today.

10. Who we disclose personal information to

We disclose personal information to the service providers that run the product, and otherwise as set out below.

  • Supabase: database, authentication, and file storage (including property images). Production project hostname published in our internal ops docs: kzruvgszraxlzvqbocei.supabase.co. Region is not stated in the application repository.
  • Render: hosts the API.
  • Vercel: hosts the website and application. Vercel Analytics and Speed Insights when the app runs on Vercel.
  • Cloudflare: DNS for reverbprop.com.
  • Stripe: checkout, subscriptions, customer portal. Card data is handled by Stripe, not stored in our database.
  • Resend: inbound and outbound email. Inbound mail for the domain is received via Amazon SES in AWS region ap-northeast-1 (Tokyo).
  • OpenRouter, and the pinned ZDR inference hosts it is allowed to use (currently Azure for gpt-5-mini, Google Vertex for Gemini 3.7 Flash, and Amazon Bedrock or Google Vertex for Claude Haiku 4.5): prompt and completion content as described in section 9.
  • Google: sign-in; Calendar API for appointment events and attendee lists.
  • Tally: form hosting and webhook delivery of enquiry fields.
  • realestate.com.au and Domain: we receive enquiry emails they send to the alias the Customer configured. We do not operate those portals.
  • The Customer and other users on the same agency account, according to the agency sharing settings the Customer uses.
  • Professional advisers, insurers, or a buyer of the business, if required for that purpose.
  • Police, regulators (including OAIC, ACCC, ACMA, NSW Fair Trading), or a court, if required or authorised by law.

Firebase remains in legacy setup notes. Current application data is stored in Supabase, not Firebase, unless an environment is still configured otherwise.

11. Overseas disclosure

Yes. We are likely to disclose personal information to overseas recipients (APP 1.4(f)). Where it is practicable to name countries (APP 1.4(g)), they include:

  • United States — OpenRouter, Stripe, Vercel, Google sign-in, and typically Azure, Google Vertex, and Amazon Bedrock inference (those clouds also operate other regions; OpenRouter may report regional suffixes such as Sweden for Azure)
  • Japan — Resend inbound SMTP (AWS SES ap-northeast-1)
  • Belgium / European Economic Area — Tally (tally.so)

Supabase and Render may store or process data in Australia or overseas. We have not published a confirmed Australian-only region for the production database in the public repository, so you should assume personal information may be stored outside Australia.

APP 8 generally requires us, before disclosing personal information to an overseas recipient, to take reasonable steps to ensure the recipient does not breach the APPs, and we may remain accountable for that handling. For model inference, those steps are the ZDR pinning described in section 9, on OpenRouter’s standard terms and its labelling of ZDR endpoints. We do not claim a separate APP-equivalent contract with Azure, Vertex, or Bedrock, and we do not claim that inference stays in Australia.

12. Cookies and similar technologies

We use cookies and similar storage that are needed to sign you in and keep a session (Supabase Auth). The audit tool may keep answers in localStorage on your device. Vercel Analytics and Speed Insights run on Vercel deployments; they are first-party analytics tools, not a third-party ad network we configure. We do not show a cookie-consent banner. Australia does not copy the EU cookie-consent rule; we still have to be open about collection (APP 1 and APP 5).

13. How we hold information, and for how long

Information is held in the processors listed above, accessed over HTTPS. We use account authentication and access controls in the application (including agency scoping). We do not claim a specific certification (for example ISO 27001 or SOC 2) in this policy.

Retention in practice, as the product works today:

  • Customer accounts and Contact records are kept while the account is used to provide the Service, and afterwards for a period we consider necessary for billing, disputes, security, and legal obligations. There is no self-service “delete my account” control in the application.
  • If a Customer deletes a lead in the dashboard, related engagements, conversations, appointments, and lead events are removed. Stored email_messages for that lead are not deleted as part of that action.
  • Email aliases are kept so an address is not given to someone else later.
  • Live-demo workspaces: synthetic demo Contacts and related demo email are purged when that demo is ended.
  • Waitlist: we keep the signup, including an unsubscribed flag if you opt out, so we do not email you again.
  • Marketing demo-email logs are kept in part to stop repeat abuse, including failed sends.
  • There is no scheduled job that wipes old email content. The daily job we run adjusts lead scores; it does not purge personal information.

APP 11 requires us to take reasonable steps to destroy or de-identify personal information when we no longer need it for a permitted purpose. If you want information deleted sooner, email us. We will say what we can delete and what we must keep.

14. Access, correction, and deletion

You can ask us for access to personal information we hold about you, or to correct it if it is wrong, out of date, or incomplete (APP 12 and APP 13). Email contact. We will need enough information to identify you. We may refuse in the circumstances the Privacy Act allows, and we will tell you why if we do.

If you are a Contact, we may also point you to the Customer (the listing agent or agency) because they hold the client relationship. That does not stop you making the request to us. Customers can correct much of their own profile in Settings. There is no export button and no account-erasure button in the product today. We will handle a written request as a support task.

Customers can delete individual leads as described in section 13. Deleting a lead is not a complete wipe of every email copy.

15. Direct marketing and the Spam Act

We send product and waitlist email to addresses that were submitted to us for that purpose (waitlist, demo, sales enquiry, audit report). Those messages must identify us and include a way to opt out (Spam Act 2003 (Cth) ss 16–18). Use the unsubscribe link in the message, the unsubscribe page, or email contact. We must give effect to an unsubscribe request within five working days. Do not require a login to opt out of our marketing mail.

Mail we send to Contacts is sent for the Customer, usually because the Contact enquired about a listing. The application will stop automated follow-up if the Contact’s lead record is marked unsubscribed. A Contact can reply with words such as “unsubscribe”, “stop”, or “opt out”, or can email us. Automated buyer emails are generated without an unsubscribe footer in the body (the writer is instructed not to add one). We do not claim that every buyer email currently meets every technical detail of Spam Act s 18. Customers are responsible for their own Spam Act position when they turn automation on. We will still honour a clear opt-out that reaches our systems.

16. Data breaches

If we have reasonable grounds to believe an eligible data breach has occurred under Part IIIC of the Privacy Act, we will notify the Australian Information Commissioner and affected individuals as required. You can also email contact if you think there has been a breach.

17. Complaints

If you think we have mishandled personal information, email contact with “Privacy complaint” in the subject. Include what happened and how we can reach you. We will acknowledge the complaint and respond in writing after we have looked into it.

If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au, phone 1300 363 992). For consumer-contract issues you may also contact NSW Fair Trading. For spam, you may contact the Australian Communications and Media Authority.

18. Changes to this policy

We will update this page when our practices or the law require it. The date at the top is the date of the current version. If a change is material, we will also email the address on the Customer account where we reasonably can.

19. Contact

Email: nickolmos@team.reverbprop.com. Place of business: New South Wales, Australia. Website: https://www.reverbprop.com.

If you need this policy in another format, say so in your email (APP 1.6).