TowerDesk
Privacy Policy
Last updated: March 2026 · Effective for the TowerDesk Android application
1. About This Policy
TowerDesk Pty Ltd (ABN: [YOUR_ABN]) ("TowerDesk", "we", "us") operates the TowerDesk Android application and web platform (towerdesk.com.au). This policy describes how we collect, use, store, and protect personal information when you use the TowerDesk Android app.
2. Information We Collect
2.1 Account Information (Required)
- Email address — used for authentication and communication
- Name — displayed in the building portal
- Unit/lot number — associates you with your building
- Phone number (optional) — for SMS notifications if enabled
2.2 Device Information
- Firebase Cloud Messaging (FCM) device token — used to deliver push notifications
- Device model and Android version — used for debugging and support
- App version — used for compatibility and update management
2.3 Data You Provide
- Photos/files — when you upload attachments to maintenance tickets, incidents, or other records
- Location (optional, with your permission) — used by the Local Directory feature to show nearby businesses
- Ticket descriptions, comments, and other content — stored in your building's database
2.4 Data We Do NOT Collect
- We do not access your contacts, call logs, SMS messages, or browsing history
- We do not use advertising identifiers or serve ads
- We do not sell personal data to third parties
3. How We Use Your Information
- To provide and maintain the TowerDesk building management service
- To send push notifications about tickets, parcels, notices, emergencies, and levies
- To authenticate your identity and protect your account
- To improve app stability and fix bugs
4. Data Storage and Security
Account data is stored on secure servers hosted in Australia. The Android app stores login credentials in Android's EncryptedSharedPreferences using AES-256-GCM encryption. All communication between the app and servers uses HTTPS/TLS. Session cookies are managed by Android's secure cookie store.
5. Third-Party Services
- Firebase Cloud Messaging (Google) — delivers push notifications. Google's privacy policy applies: policies.google.com/privacy
- Firebase Analytics (Google) — anonymous app usage analytics (crash reports, screen views). No personally identifiable information is shared.
- Google ML Kit — QR/barcode scanning is performed entirely on-device. No image data is sent to Google.
6. Data Sharing
We share your data only with:
- Your building's strata manager or owners corporation (as required for building management)
- Service providers who process data on our behalf (hosting, email delivery) under contractual data protection obligations
We do not sell, rent, or trade your personal information.
7. Your Rights
Under the Australian Privacy Act 1988, you have the right to:
- Access your personal information
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Withdraw consent for optional data collection (e.g., location, notifications)
8. Account Deletion
You can request deletion of your account and all associated data by:
Upon request, we will delete your account and personal data within 30 days, except where retention is required by law (e.g., financial records under Australian tax law).
9. Children's Privacy
TowerDesk is not intended for use by children under 18. We do not knowingly collect personal information from minors.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via the app or email. The "last updated" date at the top indicates when changes were made.
11. Contact
If you have questions about this privacy policy or your personal data, contact:
TowerDesk Pty Ltd
Email: privacy@towerdesk.com.au
Website: www.towerdesk.com.au