Crew Commercial Property Pty Ltd (ABN 30 647 250 299) Crew Property Management Pty Ltd (ABN 55 655 454 907)
Version 2.0 - effective 1 August 2026
We are committed to protecting your personal information and handling it in line with the
Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Policy covers both Crew Commercial Property Pty Ltd (commercial sales and leasing) and Crew Management Pty Ltd (property management). In this Policy, “Crew”, “we”, “us” and “our” refer to both companies. The two companies share systems and support functions, and may share your information with each other where it is relevant to the services you receive.
This Policy explains what we collect, why, who we share it with, and what choices you have. The current version is always available at https:// crewcommercial.com.au/ privacy-policy/
If you would like a copy in an alternative format, contact our Privacy Officer (section 12) and we will provide one free of charge.
The rest of this Policy sets out the detail.
We collect most information directly from you — when you enquire, inspect a property, apply for a tenancy, appoint us, sign a contract, or contact us. Where it is reasonable and practical to do so, we collect it from you rather than anyone else.
What we collect depends on how you deal with us.
Name, contact details, business or residential address, entity and ownership details (including directors, trustees and beneficial owners), bank and payment details, property and financial details relating to the transaction, and correspondence with us.
Name and contact details, the properties and price ranges you are interested in, your enquiry and inspection history, and correspondence with us. For tenancy applications: trading history, financial and business information, references, guarantor details, and the results of the checks described in section 3.5.
Additional identity and background information, described separately in section 5.
Tenant and guarantor details, lease and rent records, arrears and payment history, maintenance requests, incident and inspection reports, contractor details, insurance and body corporate correspondence, and owner statements and distributions.
To advise our clients properly and assess risk, we may carry out searches and obtain information from third parties. Depending on the matter, this may include:
Company, business name and registration searches (ASIC, ABN Lookup)
Where you instruct us to, we may also request council, statutory and property searches on your behalf. In doing so we may need to provide your name and details to the council or authority conducting the search.
We also receive information from referrers, other agents, solicitors and conveyancers, accountants, financial institutions, landlords and tenants, and government agencies.
When you visit our website we automatically collect technical information such as your IP address, device and browser type, pages viewed and how you arrived at the site. If you submit an enquiry form, we collect the details you provide. Section 7.2 explains how this information is used, including for advertising.
If we receive personal information we did not ask for and could not have collected lawfully, we will destroy or de-identify it as soon as practicable after we become aware of it, where it is lawful and reasonable to do so.
You can browse our website, attend an open inspection and make a general enquiry without telling us who you are. We cannot provide most of our services — and cannot act on a sale or purchase at all — without identifying you.
We use personal information to:
We will only use your information for another purpose where you would reasonably expect it, you have consented, or the law requires or permits it.
From 1 July 2026, real estate professionals are reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). If you are buying or selling a property through Crew Commercial Property Pty Ltd, we are legally required to verify your identity and carry out customer due diligence. These requirements do not apply to property management or ordinary leasing.
Full name, date and place of birth, residential address, and details of government-issued identification such as a driver licence or passport. For companies and trusts, we also collect ownership, control and beneficial ownership details. Depending on the transaction and its risk rating, we may also collect information about your source of funds or source of wealth.
The verification process also records technical details of your submission, including the date, time and the approximate location of the device you used. This is held by our
verification provider as part of the audit trail.
We do not adopt your driver licence, passport or other government-issued numbers as our own identifier for you. We use them only to verify your identity.
We use Securexchange (a triSearch platform) to conduct verification of identity and customer due diligence. Securexchange advises that its data handling is carried out onshore in Australia.
Where you consent, your name, date of birth and document details are checked against the records of the issuing authority through the Australian Government’s Document Verification Service (DVS). We do not receive a copy of any government record — the authority returns only a match or no-match result. More information is available at idmatch.gov.au.
Verification also involves capturing a facial image or short video of you, sometimes with a “liveness” check. This is biometric information, which is treated as sensitive information under the Privacy Act.
We use it only to confirm that you are a real person, physically present, and that your face matches the photograph on your identification document. It helps prevent impersonation and identity fraud.
Biometric information is captured and stored by our verification provider within its platform. A limited number of authorised Crew personnel can view the image there in order to manually confirm that the match is correct - verification is not left to the system alone.
Our provider automatically deletes the full verification report, including the facial image, approximately 90 days after the check is completed, and replaces it with a summary report. We retain only the summary report, which records that verification was completed and its outcome. It does not contain your facial image.
We will not use your biometric information for any purpose other than identity verification and related compliance obligations.
We ask for your consent before capturing biometric information. If you would prefer not to provide it, tell us and we will discuss whether an alternative verification method is available for your transaction.
We, or our verification provider, may screen you against sanctions lists, politically exposed
person (PEP) databases, watchlists and adverse media sources. This screening is carried out using data supplied by Dow Jones Risk & Compliance, and is run on both individuals and the entities they represent. This can involve collecting sensitive information, such as information about political affiliations or criminal history. We collect this only where the AML/CTF regime requires or authorises it, and only for compliance purposes.
We retain a summary AML onboarding report recording that the required checks were completed, the outcome of each, and the risk rating applied. Identity document numbers are masked in the records we keep.
Consistent with regulatory guidance, we do not retain copies of full identity documents for AML/CTF purposes. The underlying documents and images are collected and stored by our verification provider within its platform, where authorised Crew personnel can view them for the purposes described in sections 5.2 and 5.3, and are automatically deleted by the provider after approximately 90 days. Access within our organisation is restricted to a small number of authorised administrators who need it for compliance purposes.
The AML/CTF regime allows reporting entities to rely on customer due diligence already completed by another reporting entity, such as a solicitor or conveyancer. Where this applies, we may receive your verification details from them, or provide ours to them, so you are not asked to verify yourself twice.
By completing identity verification you consent to the collection, use and disclosure of your information for identity verification, AML/CTF and related compliance purposes, including checks through the DVS and disclosure to our verification provider.
Your consent is voluntary and you can withdraw it at any time. However, withdrawing consent does not require us to delete records we are legally required to keep, and if we cannot verify your identity we cannot act for you in a property sale or purchase.
The AML/CTF Act contains secrecy provisions, including a prohibition on “tipping off”. Where those provisions apply, we may be legally prevented from telling you that we have reported a matter, from giving you a collection notice, or from giving you access to particular information. Where that happens, we will comply with the law and tell you only as much as we lawfully can.
We photograph and film properties for marketing, inspection records, condition reports and maintenance purposes. This includes still photography, video, floorplans and aerial or drone imagery.
Property imagery may incidentally capture people, vehicles, signage or belongings. We take reasonable steps to avoid capturing identifying detail where it is not necessary, and we will remove or obscure such detail on request where it is reasonable to do so.
We retain property imagery on an ongoing basis, so we can maintain accurate property records and re-market properties in future. If you appear in an image and would like it removed, contact our Privacy Officer.
Our offices are monitored by CCTV. Cameras record images only - they do not record audio. Signage is displayed at the entrance.
We use CCTV to protect the safety of our staff and visitors, to secure our premises and property, and to investigate incidents such as theft, damage or threatening behaviour. We do not use it to monitor individual staff performance.
Footage is accessible only to authorised personnel and is ordinarily overwritten within 30 days, unless it is needed for an investigation, an insurance claim or legal proceedings, or it has been requested by police. We may provide footage to police, insurers or our legal advisers where it is lawful to do so.
If you have been recorded and want to request access, contact our Privacy Officer. We may need to obscure other people who appear in the footage before we can release it.
We use third-party software to run our business, including Rex (customer and transaction management), Re-Leased (property management), Securexchange (identity verification and contract exchange), and cloud storage, email and accounting platforms. These providers handle personal information on our behalf under their own terms and our contractual arrangements with them.
Our website uses cookies and similar technologies, including advertising and analytics tools provided by Meta (Facebook and Instagram) and Google. These tools collect information about your visit and may allow you to be shown our advertising on other platforms.
Where you submit an enquiry through our website, information about that enquiry may be shared with Meta so that we can measure the performance of our advertising and reach people with similar interests. Enquiry details are also recorded in our customer management system.
You can control cookies through your browser settings, and you can adjust advertising preferences directly with Meta and Google. If you would prefer we did not use your enquiry information for advertising purposes, contact our Privacy Officer and we will action that request.
We use AI tools, including Anthropic’s Claude and OpenAI’s ChatGPT, to help with tasks such as reviewing and summarising lease and sale documents, drafting correspondence, and analysing transaction information. These tools are operated by providers based overseas, primarily in the United States, and information we enter may be processed and stored outside Australia.
Documents we review in this way can contain personal information, such as names, signatures and contact details of parties, directors and guarantors.
The documents we process in this way may contain information about our clients, our customers and our suppliers. We do not use AI tools to make decisions about you. Any AI output is reviewed by a person before it is relied on, and responsibility for the resulting advice, decision or document remains with us.
If you would prefer that documents relating to you are not processed using these tools, tell our Privacy Officer and we will accommodate that where we reasonably can.
We may disclose your personal information to:
We do not sell your personal information.
We may contact you about properties, market updates and services we think will interest you, by email, SMS, phone or post.
You can opt out at any time using the unsubscribe link in our messages or by contacting our Privacy Officer. Opting out of marketing does not stop us contacting you about a transaction, tenancy or property we are managing for you.
If you ask, we will tell you where we obtained your contact details.
Some of our providers store or process personal information outside Australia. This includes cloud infrastructure, email and productivity services (typically the United States, Singapore or the European Union), the global sanctions, PEP and adverse media screening databases described in section 5.4, and the AI tools described in section 7.3 (primarily the United States).
Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through our contracts with them. Exceptions apply where disclosure is required or authorised by law.
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include access controls, multi- factor authentication, encryption in transit and at rest where appropriate, staff training, and due diligence on our providers.
No system is completely secure. If a data breach occurs that is likely to result in serious harm, we will assess it and notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme, except where the law prevents us from doing so.
We keep personal information only as long as we need it, or as the law requires. In general:
When we no longer need information, we securely destroy or de-identify it.
Access. You can ask for a copy of the personal information we hold about you. We will respond within a reasonable time, usually 30 days. In limited cases we may refuse access - for example, where the information relates to a third party, or where AML/CTF secrecy provisions apply (section 5.8). If we refuse, we will explain why unless the law prevents us.
Correction. If information we hold is inaccurate, out of date or incomplete, tell us and we will correct it.
Marketing. You can opt out at any time (section 9).
Withdrawing consent. You can withdraw consent at any time, subject to section 5.7. There is no charge for making a request. To make one, contact our Privacy Officer
If you are unhappy with how we have handled your personal information, please contact our Privacy Officer first. We will acknowledge your complaint promptly, investigate it, and respond within a reasonable time - usually 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner:
Privacy Officer Crew Commercial Property Pty Ltd / Crew Management Pty Ltd Email:
jaclyn@crewcommercial.com.au Phone: 0423 311 269 Post: PO Box 1869, Southport BC
QLD 4215 Office: Level 1, 24 Bay Street, Southport QLD 4215
We may update this Policy from time to time to reflect changes in our practices or the law. The current version is always available on our website. Where changes are significant, we will let you know.
Version 2.0 - effective 1 August 2026. Supersedes version 1.0.