Aller au contenu

English legal centre

Privacy Policy

How GoBro collects, uses, stores and discloses personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

1. Introduction

This Privacy Policy explains how GoBro handles personal information when you use our website, book through the platform, publish a listing or contact our team.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. Who we are

GoBro is operated by Curtis De Seixas, sole trader, ABN 30 291 712 177, based in Perth, Western Australia.

You can reach us at hello@gobro.com.au for general matters and privacy@gobro.com.au for privacy matters.

3. Scope

This policy applies to the GoBro website, the member area, our messaging and support tools, and the emails we send about bookings and accounts.

It does not apply to the separate practices of members you deal with, or to third-party websites we link to.

4. What personal information we may collect

  • Account details: username, email address, password (stored hashed), phone number and language preference.
  • Your sign-in email address is never shown to other members. Only the GoBro team (admin and support) can view it, for support, account checks and security, and every view is recorded in our internal log (who, when, which member).
  • Profile details: display name, photo, description, location area.
  • Listing and booking details: addresses, dates, prices, vehicle or accommodation details, job descriptions.
  • Identity verification details: identity document images and the verification result.
  • Payment-related details: amounts, references, payment status, bank transfer receipts (card numbers are never stored by GoBro).
  • Communications: messages between members, support conversations, complaints and evidence you upload.
  • Technical details: IP address, device and browser information, pages viewed, security logs.

5. How we collect it

We collect most information directly from you when you create an account, publish a listing, make a booking, upload documents or contact us.

We also collect some information automatically from your device, and some from our service providers (for example a payment status from Stripe).

6. Information collected when using the website

When you browse the site we may record your IP address, browser type, the pages you view and the time of the visit. This is used for security, fraud prevention and to keep the service reliable.

Analytics information is only collected if you consent to analytics cookies. Security logs are kept for 12 months.

7. Through forms

Contact, support and listing forms collect the information shown in the form. Fields marked as required are mandatory; without them we cannot process the request. Other fields are optional.

Form submissions are stored with your account and kept in line with the retention periods below.

8. Through bookings, listings and transactions

When a booking is made we record the parties involved, dates, amounts, the service fee, the deposit, the generated contract and its signatures.

This information is mandatory for the booking to exist, is shared with the other party to the booking, and is kept for 7 years as a transaction record.

The GoBro team can access the messages and documents attached to a booking (contract, payment evidence, handover photos, attachments) for safety, support and dispute resolution. Access is limited to authorised staff, recorded in an internal log, and applies once both parties have signed the contract.

9. Identity verification information

To be verified you may provide an identity document. What: the document image and the details visible on it. Why: to confirm you are who you say you are and to reduce fraud. Mandatory to obtain a verified badge, otherwise optional.

Document images are deleted within 30 days after verification. Only the result (verified or not, and the date) is kept. Images are visible only to the small number of staff who carry out verification.

10. Payment-related information

Card payments are processed by Stripe. GoBro never sees or stores your full card number; we receive only the payment status and a reference.

For bank transfers we record the reference, the amount and the receipt you upload, so the team can validate it (usually within 24 hours). Payment records are kept for 7 years.

11. Communications and support records

Messages exchanged on the platform, support conversations and complaint files are stored so that we can help you, resolve problems and keep a record of decisions.

Messages linked to a transaction, contract or dispute are kept for 7 years; other messages are kept for 2 years.

12. Chatbot and AI information

Our assistant, BROZA, records the messages you send it so we can improve the help we give and keep a record of what was said. Assistant conversations are kept for 90 days.

Please limit what you share with the assistant. Never send passwords, full card numbers, unnecessary medical information, identity documents (unless our team officially asks you to), or sensitive information about other people.

Your conversations are not used to train AI models.

13. Sensitive information

We do not seek sensitive information (such as health, racial or ethnic origin, religious or political views). Please do not provide it unless it is genuinely necessary, for example an accessibility need for a stay or a ride.

If you do provide it, we only use it for the purpose you gave it to us and delete it when it is no longer needed.

14. Why we collect

  • To create and secure your account.
  • To publish listings and process bookings, contracts, payments and refunds.
  • To verify identity and prevent fraud.
  • To provide support and handle complaints.
  • To meet record-keeping, tax and other legal obligations.

15. How we use it

We use personal information only for the purposes above, for closely related purposes you would reasonably expect, or where you have consented, or where the law requires it.

We do not sell personal information.

16. Legal and operational basis (APP 3)

We collect personal information only where it is reasonably necessary for our functions and activities as a marketplace: running accounts, listings, bookings, payments, verification, support and safety.

Where the information is not necessary for those functions, we do not collect it.

17. Direct marketing

We do not currently send direct marketing. The emails we send relate to your account, your bookings, payments, contracts and support.

If we introduce marketing emails in future, they will be opt-in and every message will include an easy way to opt out.

18. Disclosure

We disclose personal information to the other party to your booking (limited to what is needed: username, verification status, agreed details and contact once the booking is confirmed), to our service providers, and to authorities where the law requires or permits it.

19. Service providers

We use providers for hosting, payments, email delivery, analytics, translation, AI assistance and internal alerts. They may only use the information to provide their service to us.

20. Payment providers (Stripe)

Card payments are handled by Stripe, which acts as an independent controller of the card data it collects. GoBro receives the payment status, the amount and a reference only.

21. Hosting

Our database, files and application are hosted with Supabase on Amazon Web Services infrastructure located in Sydney, Australia.

22. Analytics

We use Google Analytics 4 only if you accept analytics cookies. IP addresses are anonymised and analytics data is kept for 14 months.

You can withdraw consent at any time using the cookie controls; see our Cookies and Tracking Notice.

23. AI providers

The BROZA assistant uses Google Gemini models accessed through the Lovable AI gateway. Messages sent to the assistant are processed by those providers to generate a reply.

Conversations are not used to train AI models.

24. International disclosures (APP 8)

Some of our providers are located overseas. Before disclosing personal information to them, we take reasonable steps to ensure they handle it in a way consistent with the Australian Privacy Principles, including through their contractual commitments.

25. Countries

  • Stripe (payments) — United States and European Union.
  • Resend (transactional email) — United States.
  • Google (sign-in, analytics, translation and Gemini models via the Lovable AI gateway) — United States.
  • Telegram (internal alerts to our team) — European Union.

26. Security

We use encryption in transit, access controls, row-level database security, hashed passwords, logging and staff access limited to what each role needs.

No system can be completely secure, so we also ask you to use a strong, unique password and to keep your account details private.

27. Retention

  • Transactions, contracts and disputes: 7 years.
  • Other messages: 2 years.
  • Security logs: 12 months.
  • Analytics data: 14 months.
  • Assistant conversations: 90 days.
  • Identity document images: deleted within 30 days after verification (result kept).

28. Data breach response

We have a process to contain, assess and remediate suspected data breaches. If a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.

29. Access

You can view and download most of your information from your profile, bookings, contracts and invoices pages. You can also ask us for a copy by emailing privacy@gobro.com.au.

We acknowledge privacy requests within 5 business days and answer within 30 days.

30. Correction

You can correct most details yourself in Profile. If something cannot be edited (for example a signed contract), contact privacy@gobro.com.au and we will correct our records or attach a note where correction is not possible.

31. Deletion

You can ask us to delete your account. We will delete or de-identify personal information we no longer need, but we must keep transaction, contract, dispute and tax records for 7 years.

See our Data Access, Correction and Deletion Procedure for the steps.

32. Privacy complaints

If you think we have mishandled your personal information, email privacy@gobro.com.au with the details and any evidence.

33. How we handle privacy complaints

We acknowledge your complaint within 5 business days and give you a written answer within 30 days. If we need longer, we will tell you why and when to expect a response.

You can ask for an internal review within 14 days of our answer.

34. Contacting the OAIC

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.

35. Children

GoBro is for people aged 18 and over. We do not knowingly collect personal information from children. If we learn that we have, we will delete it.

36. Cookies

We use necessary cookies to keep you signed in and to protect the site, and analytics cookies only with your consent. Full details are in our Cookies and Tracking Notice.

37. Changes

We may update this policy. The current version is always published here with its date, and we will tell you about significant changes by email or on the site.

38. Contact details

Privacy enquiries: privacy@gobro.com.au. General enquiries: hello@gobro.com.au. Complaints: complaints@gobro.com.au.

GoBro — Curtis De Seixas, sole trader, ABN 30 291 712 177, Perth, Western Australia. Support hours: Monday to Friday, 9 am to 5 pm AWST.

39. Date

This version applies from 5 September 2026.

Last updated: 5 September 2026