Your privacy is important to us. This policy explains how we collect, use, disclose, and safeguard your information when you use the LodgeKit platform.
Effective Date: 27 January 2026 · Last Updated: 27 January 2026
We are committed to protecting your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
For users in the European Economic Area, we also comply with the General Data Protection Regulation (GDPR). Your data rights are outlined in Section 7.
1.1 LodgeKit Ltd ("Company", "we", "us", or "our") operates the LodgeKit platform (the "Service"), a Software-as-a-Service accommodation management solution for student accommodation, hotels, vacation rentals, parks, campgrounds, serviced apartments, co-living, and other stay-based operations.
1.2 This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, use our platform, or otherwise interact with us.
1.3 We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained therein. For users in the European Economic Area (EEA), we also comply with the General Data Protection Regulation (EU) 2016/679 (GDPR).
1.4 By using our Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the data practices described, you should not use the Service.
1.5 For the purposes of the GDPR, LodgeKit Ltd is the data controller of the personal information we collect. For information on our role as a data processor (when processing data on behalf of our customers), please see Section 4.
2.1 Personal Information You Provide. When you register for an account or use our Service, we may collect the following personal information:
2.2 Information Collected Automatically. When you access the Service, we automatically collect certain information, including:
2.3 Cookies and Similar Technologies. We use cookies, web beacons, pixel tags, and similar tracking technologies to collect information about your browsing activity. See Section 8 for more details on our use of cookies.
2.4 Information from Third Parties. We may receive information about you from third-party services you connect to our platform, including:
3.1 We use the information we collect for the following purposes:
3.1.1 Service Delivery
3.1.2 Communication
3.1.3 Improvement and Analytics
3.1.4 Legal and Compliance
3.2 Legal Bases for Processing (GDPR). For users in the EEA, our legal bases for processing personal data include:
4.1 We do not sell your personal information to third parties. We may share your information in the following circumstances:
4.2 Service Providers. We share data with third-party service providers who assist us in operating our Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Name, email, payment card details, transaction amounts |
| GoCardless | Direct debit payments | Name, email, bank account details, transaction amounts |
| Xero | Accounting integration | Invoice data, contact information, financial records |
| Supported accounting providers | Accounting connections | Invoice data, contact information, financial records where enabled |
| Sentry | Error monitoring and performance | Technical error data, user identifiers, device information |
4.3 Data Processor Role. When our customers input their guest, resident, member, or booker data into the platform, we act as a data processor on their behalf. Our customers remain the data controllers for this data and are responsible for obtaining appropriate consents from those individuals.
4.4 Legal Requirements. We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to:
4.5 Business Transfers. If we are involved in a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.
4.6 Aggregated Data. We may share aggregated, de-identified information that cannot reasonably be used to identify you, for industry analysis, benchmarking, marketing, and other business purposes.
5.1 We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
5.2 Retention Periods. The following general retention periods apply:
5.3 When the retention period expires, we will securely delete or anonymise your personal information so that it can no longer be associated with you.
5.4 In some cases, we may retain certain data for longer periods where required by law (such as for tax, legal, or regulatory purposes) or where necessary to resolve disputes or enforce our agreements.
6.1 We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction.
6.2 Our security measures include:
6.3 While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
6.4 Breach Notification. In the event of a data breach that is likely to result in serious harm to individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme. For EEA users, we will notify the relevant supervisory authority within 72 hours as required by the GDPR.
7.1 Australian Privacy Act Rights. Under the Australian Privacy Act 1988, you have the right to:
7.2 GDPR Rights (EEA Users). If you are located in the European Economic Area, you have additional rights under the GDPR, including:
7.3 Exercising Your Rights. To exercise any of these rights, please contact our Data Protection Officer at privacy@lodgekit.com. We will respond to your request within 30 days (or within the time period required by applicable law).
7.4 Identity Verification. We may request specific information from you to confirm your identity before processing your request. This is to ensure that personal data is not disclosed to unauthorised persons.
7.5 No Fee Usually Required. You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
9.1 Our Service is not directed to individuals under the age of 18 ("Children"). We do not knowingly collect personal information from children.
9.2 If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us at privacy@lodgekit.com. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers.
9.3 While our platform may be used to manage student accommodation and other stay types, account holders must be at least 18 years of age. Guest, resident, member, or booker records for minors may only be entered by an authorised adult with appropriate parental or guardian consent.
10.1 LodgeKit is based in Australia. If you are accessing the Service from outside Australia, please be aware that your information may be transferred to, stored, and processed in Australia.
10.2 For users in the EEA, transfers of personal data to Australia or other countries outside the EEA will be conducted using appropriate safeguards as required by the GDPR, including:
10.3 Some of our third-party service providers may process data in countries other than Australia (e.g., the United States). We ensure that appropriate data transfer mechanisms are in place with these providers.
10.4 Under the Australian Privacy Act, we take reasonable steps to ensure that overseas recipients of personal information comply with the APPs or are bound by a substantially similar privacy framework.
11.1 We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page with a revised "Last Updated" date.
11.2 For material changes that significantly affect the way we process your personal information, we will provide at least 30 days' notice via email to the address associated with your account before the changes take effect.
11.3 We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
11.4 If you do not agree with the revised Privacy Policy, you must stop using the Service and may request deletion of your account and personal data.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
General Enquiries
Email: support@lodgekit.com
Legal Department
Email: legal@lodgekit.com
Australian Information Commissioner
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):