Privacy Policy

Last Updated: 16 August 2026

1. About this Privacy Policy

  1. Cyber Civic Solutions Pty Ltd, trading as Strack (Strack, we, us or our), operates the Strack website, the Strack application and associated products and services (the Services).
  2. This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with the Services.
  3. We are committed to managing personal information in accordance with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) where they apply.
  4. We may update this Privacy Policy from time to time to reflect changes to our Services, technology, business practices or legal requirements. The current version will be made available through our website and will show the date it was last updated.
  5. Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.

2. Personal information we collect and hold

  1. The types of personal information we collect and hold depend on how an individual interacts with Strack and how our customers use the Services.
  2. Personal information may include:

a. name, telephone number, email address and postal address;

b. property, lot, unit, strata plan, owners corporation, body corporate or other scheme information;

c. information about an individual’s relationship with a scheme, including whether they are an owner, occupier, committee member, strata manager, representative or service provider;

d. account and user profile information;

e. levy, payment, account balance and other financial or transaction information relevant to scheme administration;

f. correspondence, notices and communications;

g. meeting, voting, resolution and committee information;

h. documents and records uploaded to or maintained within the Services;

i. enquiries, support requests and other communications with Strack; and

j. technical and system information associated with the use of the Services, such as IP address, login activity, date and time of access, browser information and activity within the Services.

  1. We do not generally seek to collect sensitive information unless it is reasonably necessary for a legitimate purpose and its collection is permitted by law. However, documents or records uploaded by customers or authorised users may occasionally contain sensitive information.

3. How we collect personal information

  1. We may collect personal information:

a. directly from an individual when they register for, access or use the Services;

b. when an individual contacts us by telephone, email, through our website or by another method;

c. from an owners corporation, body corporate, strata or community titles scheme, strata management agency or other customer using the Services;

d. from committee members, property owners, occupiers, service providers or other authorised persons;

e. from documents, financial records, strata records or other information uploaded to or maintained within the Services; and

f. from third parties where collection is authorised, reasonably expected or otherwise permitted by law.

  1. Strata schemes and their managers may be required under applicable legislation to maintain records containing personal information about owners, occupiers and other relevant persons. This information may be maintained within Strack for purposes such as scheme administration, levy management, communications, notices, meetings and record keeping.
  2. In many cases, Strack holds and processes information through the Services on behalf of an owners corporation, body corporate, strata scheme, strata management agency or other customer. Those organisations may have their own legal obligations and privacy policies relating to the collection and handling of personal information.
  3. Where lawful and practicable, individuals may make general enquiries without identifying themselves. However, identification may be required where it is reasonably necessary to provide access to an account, scheme information or other Services.

4. Cookies and technical information

  1. We may use cookies and similar technologies in connection with our website and Services.
  2. Cookies may be required for functions including authentication, maintaining a user session, security and operation of the Services.
  3. Most internet browsers allow users to control the use of cookies. Disabling cookies may prevent some parts of the website or Services from operating correctly.
  4. When the Services are accessed, we may record technical information such as IP address, date and time of access, browser information, pages or functions accessed and system activity. This information may be associated with a registered user account.

5. How we use personal information

  1. We collect, hold, use and disclose personal information where reasonably necessary to operate and support the Services and for purposes including:

a. creating and administering user accounts;

b. providing access to the Services;

c. supporting the administration and management of strata schemes, owners corporations, bodies corporate and similar property schemes;

d. administering levies, payments, accounting and financial records;

e. facilitating communications, correspondence and notices;

f. supporting meetings, voting, resolutions and committee activities;

g. maintaining scheme, owner and occupier records;

h. providing customer and technical support;

i. responding to enquiries;

j. sending service-related email, SMS, push notifications and other communications;

k. maintaining the security, integrity, availability and performance of the Services;

l. identifying, investigating and responding to suspected misuse, security events or unauthorised activity;

m. maintaining and improving the quality and functionality of the Services;

n. administering our relationships with customers and service providers; and

o. complying with applicable legal, regulatory and contractual obligations.

  1. Communications relating to the administration of a scheme may be sent where required or permitted under applicable strata, community titles or other legislation, or as authorised by the relevant scheme or customer.
  2. Where we send marketing communications, we will do so in accordance with applicable law and provide an appropriate means of opting out.

6. Disclosure of personal information

  1. We do not sell or rent personal information.
  2. We may disclose personal information where reasonably necessary for the purposes described in this Privacy Policy, including to:

a. the relevant owners corporation, body corporate, strata scheme, strata management agency or other customer;

b. authorised owners, occupiers, committee members, managers, representatives and other authorised users of the Services;

c. contractors and service providers engaged by Strack to support the operation and delivery of the Services;

d. contractors and service providers engaged by the relevant scheme or strata manager where access to information is reasonably required to provide services to that scheme;

e. cloud hosting, communications and other technology service providers;

f. professional advisers, including legal, accounting and security advisers;

g. government agencies, regulators, courts or law enforcement authorities where disclosure is required or authorised by law;

h. a party involved in a proposed or actual sale, transfer, restructure or acquisition of all or part of our business or assets; or

i. another party where the individual, relevant scheme or customer has authorised the disclosure or where disclosure is otherwise permitted by law.

  1. We seek to limit disclosure of personal information to information reasonably required for the relevant purpose.

7. Overseas service providers

  1. Strack’s primary production application environment, database and document storage are hosted in Australia.
  2. We may use third-party technology and service providers that operate in, or provide services from, locations outside Australia.
  3. Where personal information is disclosed to an overseas recipient, we take reasonable steps as required by applicable Australian privacy law to ensure that the information is appropriately protected.

8. How we hold and secure personal information

  1. The security and confidentiality of personal and customer information is important to us.
  2. We take reasonable steps to protect personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure.
  3. We use technical, organisational and administrative safeguards appropriate to the nature of the information and the Services. These include controls relating to:

a. access to systems and information;

b. authentication and user permissions;

c. encryption and protection of information where appropriate;

d. system and security monitoring;

e. backup and recovery;

f. software and infrastructure maintenance; and

g. management of security risks and vulnerabilities.

  1. Access to customer information is restricted according to authorised access and operational requirements.
  2. For security and confidentiality reasons, Strack does not publicly disclose detailed network architecture, server configurations, security rules or other internal security information that could reduce the effectiveness of these controls.
  3. No internet-based system can guarantee absolute security. We review our security arrangements having regard to the nature of the information we hold, changes in technology and evolving security risks.

9. Retention and deletion of personal information

  1. We retain personal information for as long as it is reasonably required for the purposes for which it may be used or disclosed, including to:

a. provide and support the Services;

b. maintain customer and scheme records;

c. comply with legal, regulatory, accounting and record-keeping requirements;

d. meet contractual obligations;

e. resolve disputes; and

f. protect legitimate business, security and legal interests.

  1. Retention periods may vary depending on the nature of the information and any requirements applying to the relevant scheme or customer.
  2. Where personal information is no longer required for a purpose for which it may lawfully be used or disclosed, and we are not required by law or a court or tribunal order to retain it, we take reasonable steps to destroy the information or ensure that it is de-identified.

10. Data breaches and security incidents

  1. Strack maintains processes for identifying, assessing and responding to suspected data breaches and security incidents.
  2. Where a data breach is subject to the Notifiable Data Breaches scheme under the Privacy Act, we will assess the incident and make notifications to affected individuals and the Office of the Australian Information Commissioner where required by law.
  3. Where information affected by an incident is held through Strack on behalf of a customer, we may work with the relevant customer to investigate and appropriately respond to the incident.

11. Access to and correction of personal information

  1. An individual may request access to personal information we hold about them or request that information be corrected if it is inaccurate, out of date, incomplete, irrelevant or misleading.
  2. Requests may be made using the contact details in section 13.
  3. We may require reasonable proof of identity before providing access to or changing personal information.
  4. In some circumstances, information maintained within Strack is administered by an owners corporation, body corporate, strata scheme, strata management agency or other customer. Where appropriate, we may refer an access or correction request to that organisation.
  5. There may be circumstances where we are permitted or required by law to refuse or limit access or correction. Where required, we will explain the reason for doing so.
  6. We generally do not charge for making an access request. Where permitted by law, we may charge a reasonable amount for costs associated with providing access.

12. Links and third-party services

  1. The Services may contain links to third-party websites or services.
  2. Where an individual accesses a third-party website or service, the privacy practices of that third party will apply. Strack is not responsible for the privacy practices of third parties that operate independently of Strack.
  3. We recommend reviewing the privacy policy of any third-party website or service before providing personal information to it.

13. Privacy enquiries and complaints

  1. Questions, requests or complaints concerning privacy or our handling of personal information may be directed to:

Cyber Civic Solutions Pty Ltd trading as Strack

Email: info@strack.com.au
Telephone: 1300 STRACK

  1. If you make a privacy complaint, please provide sufficient information for us to understand the nature of your concern.
  2. We will consider the complaint, may contact you if further information is required, and will seek to respond within a reasonable period.
  3. If you are not satisfied with our response, you may have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).

14. Changes to this Privacy Policy

  1. We may amend this Privacy Policy from time to time.
  2. The current version will be published through the Strack website and may also be made available through the Strack application.
  3. The date at the beginning of this Privacy Policy identifies when it was last updated.