Legal
Privacy Policy
Last updated: 1 July 2025
1. Who we are
Prestige Luxury Rentals Pty Ltd Prestige operates the Prestige mobile app and the companion web portal.
Contact: bookings@prestigeluxuryrentals.com.au
2. What this policy covers
This policy explains how we collect, use, disclose and safeguard your personal information when you:
- • sign up on our website and log in to the Prestige app;
- • pay the AUD $20/month membership fee; or
- • take part in our rewards programme.
It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
3. The information we collect
Category | Purpose | Mandatory? | Collected by |
---|---|---|---|
Full name | Create account; identify bookings & rewards | Yes | Web sign-up form |
Email address | Account login; send booking confirmations & reward updates | Yes | Web sign-up form |
Payment token | Process subscription fees | Yes, if subscribing | Stripe |
Device metadata | App security & diagnostics | Automatic | App & Supabase logs |
No driving-licence, age-verification or further identity documents are collected inside the app. These are handled in person when you pick up the vehicle.
4. How we use your data
Use case | Legal basis under the APPs |
---|---|
Account creation & authentication | APP 3 & APP 6 – necessary for our functions |
Managing the $20 subscription | Same as above |
Allocating & tracking rewards | Same |
Business analytics (aggregated, de-identified) | Our legitimate interests under APP 6 |
Transactional emails (receipts, password resets) | Same |
Complying with legal obligations (e.g. tax) | APP 6 – required or authorised by law |
We do not use your data for advertising or share it with ad networks.
5. Disclosure to third parties
Recipient | What they get | Reason | Location |
---|---|---|---|
Stripe Payments Australia Pty Ltd | Payment token & email | Recurring billing | AU data centre |
Supabase Inc. (Australian region) | All data you store with us | Managed database & authentication | Sydney |
AWS (Amazon Web Services) | Encrypted backups (7-day retention) | Disaster recovery | Sydney |
All providers are bound by contract to keep your data confidential and secure.
6. Overseas transfers
Your data is stored in Australia. We do not transfer it overseas unless you book a service hosted abroad and expressly consent.
7. Security
• TLS 1.2+ encryption on all traffic
• Role-based access controls in Supabase
• Stripe is PCI-DSS Level 1 compliant
• 72-hour incident-response window for any notifiable data breach
8. Data retention
Data | Retention period |
---|---|
Account profile (name, email) | Until you or we delete the account |
Subscription & payment records | 7 years (tax law) |
Server logs & backups | 7 days, then purged |
9. Your privacy rights
Under the APPs you may:
• Request access to or correction of your personal info
• Withdraw consent for marketing (we currently send none)
• Lodge a complaint with the OAIC
Email bookings@prestigeluxuryrentals.com.au and we'll respond within 30 days.
10. Account deletion
At present you can cancel your subscription and delete your account via the web portal. (In-app deletion will be added in a future release.) Deletion removes active credentials but payment records remain for statutory purposes.
11. Changes to this policy
We may update this Privacy Policy from time to time. We'll notify you in-app or by email at least 14 days before changes take effect.
Questions about this Privacy Policy? Contact us at bookings@prestigeluxuryrentals.com.au