// Legal · Privacy Notice

Privacy Notice

Last updated 6 September 2026

This notice explains what personal data SISR consulting collects through TurnProof, why we collect it, who we share it with, and the rights you have over it.

[1]

Who is responsible for your data

TurnProof is operated by SISR consulting of Queensland, Australia. SISR consulting is the data controller for the personal data described in this notice. You can reach us at sisrconsulting@gmail.com.

[2]

Whose data this covers

This notice covers hosts who hold accounts, and people who use property access codes or links we call “crew access” — cleaners, maintenance workers, lawn and garden crews and other contractors completing a report on a host's behalf. It also touches on guests, who may appear incidentally in evidence photos taken at a property; we do not collect anything directly from guests.

[3]

What personal data we collect

  • Account data: your name (if provided), email address, and sign-in credentials managed through our authentication provider.
  • Property data: property names and addresses, room, bed and bathroom counts, inventory checklists and notes you enter.
  • Evidence photos: photographs captured through the in-app camera, with server-recorded capture times and SHA-256 fingerprints of the image files.
  • Report data: checklist statuses, issue notes, submission times, and the identity of who submitted a report (host or crew).
  • Crew access data: names or labels of contractors, visit types and dates entered on maintenance or turnover reports, and the access codes and links issued to them.
  • Billing data: handled by Paddle as our Merchant of Record; we store subscription status, plan quantity and receipt references. Card numbers are never stored by us.
  • Technical data: IP address and device details processed when you connect, used for security and fraud prevention.
[4]

Why we use it, and our legal basis

  • Providing the service — accounts, property setup, reports, photo storage, PDFs, sharing links. Legal basis: performance of our contract with you.
  • Billing and subscriptions — plan coverage, invoices and receipts. Legal basis: contract performance; billing mechanics are handled by Paddle.
  • Security and fraud prevention — enforcing access codes, protecting accounts, detecting misuse. Legal basis: our legitimate interests in keeping the service and its users safe.
  • Product improvement — understanding how features are used so we can fix and improve them. Legal basis: legitimate interests.
  • Support and service messages — answering your questions, retention warnings before photos are deleted. Legal basis: contract performance (and consent where required).
  • Legal obligations — keeping records where law requires. Legal basis: legal obligation.
[5]

Who we share data with

We share personal data only with the categories of recipients below, never for their own marketing:

  • Service providers / sub-processors — our hosting, database, storage and email providers, who process data on our instructions to run the service.
  • Paddle.com — as our Merchant of Record, Paddle handles the sale of the product, subscription management, payments, tax compliance and invoicing. Paddle is the seller of record for your purchase and processes your payment details under its own privacy policy.
  • Professional advisers — legal, accounting and insurance advisers where reasonably needed.
  • Authorities — where required by law, court order or to protect vital interests.
[6]

Photo retention — 90 days

Evidence photos are stored for 90 days from the moment the report is submitted, then permanently deleted. Before the deadline we show countdowns in the workspace and send reminder emails to the host. Hosts are expected to download the high-resolution PDF records during that window; the PDFs are the host's permanent archive.

Report text, checklists, server timestamps, submitter identity and SHA-256 hashes are kept indefinitely, because they are what make an archived photo verifiable years later.

[7]

How long we keep other data

Account data is kept while your account is open, and for a short period afterwards to handle any follow-up, then deleted or anonymised. Billing records are kept for the period required by Australian tax and commercial law. Data that is no longer needed is deleted or anonymised.

[8]

Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls so a host's evidence photos can only be opened by that host (or via the specific links they share), and immutable records that cannot be quietly altered after submission. No system is perfectly secure, but we design the platform so that tampering is detectable.

[9]

Cookies

TurnProof uses only strictly necessary cookies and equivalent browser storage: keeping you signed in, securing forms, and remembering workspace preferences. We do not use advertising or cross-site tracking cookies. You can clear or block these in your browser settings, but the workspace needs them to function.

[10]

International transfers

Our service providers may process data outside Australia, including in the United States and the European Union. Where personal data leaves the UK or EEA, we rely on appropriate safeguards such as the European Commission's standard contractual clauses or an adequacy decision for the destination country.

[11]

Your rights

Under the Australian Privacy Principles, you can ask us for access to the personal data we hold about you, ask us to correct it, and complain if you think we have mishandled it. We respond to requests and complaints within a reasonable time.

If you are in the UK or EEA, you additionally have the right to: access your data; rectify inaccurate data; erase data; restrict or object to processing; data portability; withdraw consent where processing is based on consent; and lodge a complaint with your local supervisory authority. We respond within one month.

To exercise any of these rights, email sisrconsulting@gmail.com. If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or your local supervisory authority.

[12]

Changes to this notice

We may update this notice as the service changes. The “last updated” date at the top shows the current version, and material changes will be highlighted in the workspace.