Security & trust
How we protect your data — and the two things we deliberately never hold.
1 · Where your data lives
Your application data is hosted in Australia — the database, your documents and your media (including inspection photos and video) all sit on Supabase (AWS, Sydney). Some providers process limited data overseas (payments and email); we list each provider and its location in our Privacy Policy.
And a second copy, also in Australia. Every night an encrypted copy of the database and of your stored files is written to separate infrastructure in Sydney, on a different provider to the one running the app — so a failure, or a mistake, at our main provider cannot take your records with it. The copy is encrypted with a key that is not held by the system that makes it, so the backup process itself cannot read what it stores. Deletions flow through: anything destroyed under the windows in section 7 ages out of the backups within 35 days.
And a second copy, also in Australia. Every night an encrypted copy of the database and of your stored files is written to separate infrastructure in Sydney, on a different provider to the one running the app — so a failure, or a mistake, at our main provider cannot take your records with it. The copy is encrypted with a key that is not held by the system that makes it, so the backup process itself cannot read what it stores. Deletions flow through: anything destroyed under the windows in section 7 ages out of the backups within 35 days.
2 · Encryption
Data is encrypted in transit (TLS) and at rest across our database, document store and media storage. On top of that infrastructure layer, the details tenants pay rent into — BSB, account number and PayID — are encrypted by the application itself (AES-256-GCM) before they are written to the database, with the key held outside it. A copy of the database on its own therefore contains no usable account details.
3 · Access is isolated per account
Every request is scoped to the signed-in account: a landlord only ever accesses their own properties, tenancies and records, and the tenant portal is scoped to a single tenancy. Private files have no permanent public URL — media is served through short-lived signed links. Tenant portal links are time-limited: they expire on a window the landlord sets, a fresh link replaces the old one whenever it's re-sent, and they stop working the moment a tenancy ends. The link that sets up a renter's account expires within a day and can only be used once.
4 · We never touch your rent
Rent is paid by the tenant directly to the landlord — bank transfer or PayID, account to account. LandlordMate only records and matches those payments; we never collect, hold, control or access rent funds. Our own charges (your subscription, and an applicant ID check if you order one) are processed by Stripe Payments Australia Pty Ltd (AFSL 500105), a PCI-DSS Level 1 certified provider — card details are captured by Stripe and never touch our systems.
To be clear about the one thing we do store: the account a landlord nominates to receive rent (account name, BSB, account number, PayID) is kept, encrypted, because the tenant has to be told where to pay. Those are pay-to details, not credentials — they authorise nothing on their own, and we hold no direct-debit authority over any account. Changing them triggers a 24-hour cooling-off and a security email, because that is the classic fraud target.
To be clear about the one thing we do store: the account a landlord nominates to receive rent (account name, BSB, account number, PayID) is kept, encrypted, because the tenant has to be told where to pay. Those are pay-to details, not credentials — they authorise nothing on their own, and we hold no direct-debit authority over any account. Changing them triggers a 24-hour cooling-off and a security email, because that is the classic fraud target.
5 · We never store identity documents — anyone's
There is no identity-document upload anywhere in LandlordMate, for landlords or for renters. Identity is always proved with the provider: you photograph your ID and take a selfie directly with Stripe Identity, on your own device. Stripe tells us whether it checked out, and the name it read. The document and the selfie never reach us, so there is nothing here for a breach to expose.
Landlords verify once, and it covers the whole account for good. It's required before anything of theirs reaches someone else — advertising a property, inviting a renter, or sending a lease to sign. Setting up privately first doesn't need it, because nothing has left the account yet. Applicants are only ever asked after a landlord has marked them as their preferred applicant, and the landlord pays. If a landlord sights ID in person instead, we record the document type and the date — never a copy, never a number.
We also make no claim about who is on a property's title. The badge on a listing says the person advertising it is a verified, named individual; it does not say we checked the land register.
Landlords verify once, and it covers the whole account for good. It's required before anything of theirs reaches someone else — advertising a property, inviting a renter, or sending a lease to sign. Setting up privately first doesn't need it, because nothing has left the account yet. Applicants are only ever asked after a landlord has marked them as their preferred applicant, and the landlord pays. If a landlord sights ID in person instead, we record the document type and the date — never a copy, never a number.
We also make no claim about who is on a property's title. The badge on a listing says the person advertising it is a verified, named individual; it does not say we checked the land register.
6 · Infrastructure assurance
Our infrastructure runs on providers that maintain independent security certifications — AWS (via Supabase), Cloudflare and Stripe hold certifications such as ISO 27001, SOC 2 and PCI-DSS. LandlordMate does not yet hold its own ISO 27001 / SOC 2 certification; we build on infrastructure that does.
7 · Data retention
Tenancy records — ledgers, messages, notices, condition reports and the photos attached to them — are kept as dated, unalterable evidence for the life of the account plus seven years after a tenancy ends, after which we strip the tenant's personal details and delete the stored documents. That reflects the bond and tribunal/court limitation periods (up to six years in most states), so the condition evidence is there if a dispute arises long after the tenancy.
Walkthrough video is the deliberate exception, and it goes much sooner. Interior footage of someone's home is the most sensitive thing we hold, so it runs on the shortest clock we can defend: a routine inspection video is destroyed 90 days after the owner has reviewed it, and entry or exit footage — which is bond evidence — 90 days after the tenancy ends. The dated record that the inspection happened survives; the footage does not.
Flagged footage is the exception to the exception. If the owner marked a problem in a clip, or raised a repair from it, that clip stops being routine footage and becomes evidence of a specific issue — so it is kept for the full seven years alongside the rest of the tenancy record. Ninety days is long enough for a problem to be noticed; once it has been, destroying the proof of it would be the wrong call.
Identity documents and card details are never stored at all, so they have no retention period.
Walkthrough video is the deliberate exception, and it goes much sooner. Interior footage of someone's home is the most sensitive thing we hold, so it runs on the shortest clock we can defend: a routine inspection video is destroyed 90 days after the owner has reviewed it, and entry or exit footage — which is bond evidence — 90 days after the tenancy ends. The dated record that the inspection happened survives; the footage does not.
Flagged footage is the exception to the exception. If the owner marked a problem in a clip, or raised a repair from it, that clip stops being routine footage and becomes evidence of a specific issue — so it is kept for the full seven years alongside the rest of the tenancy record. Ninety days is long enough for a problem to be noticed; once it has been, destroying the proof of it would be the wrong call.
Identity documents and card details are never stored at all, so they have no retention period.
8 · If there's a data breach
If a breach is likely to result in serious harm, we notify the affected people and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme, as soon as practicable.
9 · Responsible disclosure
Found a security issue? Please email admin@landlordmate.com.au. We'll acknowledge your report and work with you in good faith — please give us a reasonable chance to fix an issue before disclosing it publicly.