Privacy Policy

Privacy Policy

Last updated: 9 August 2026

Chenashe (“we”, “us”, “our”) operates the Chenashe Property Management System available at app.chenashe.au and the marketing website at chenashe.au. This policy describes how we collect, use, and protect personal information in compliance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

1. Information we collect

Account information: When you sign up for Chenashe, we collect your name, email address, organisation name, and role. For tenant portal users, we collect the phone number or email address used for login.

Organisation data: The data your organisation enters into the system (tenant records, financial records, inspection reports, documents, communications) is your data. We process it on your behalf as a data processor. We do not access, use, or share your organisation’s data except as necessary to provide the service, respond to support requests, or comply with legal obligations.

Marketing website: When you visit chenashe.au, we may collect standard web analytics data (pages visited, referral source, browser type) via Google Analytics. No personal information is collected from the marketing site unless you contact us or sign up for a trial.

Payment information: Subscription payments are processed by Stripe. Card numbers are handled entirely by Stripe and are never transmitted to, processed by, or stored on Chenashe servers.

2. How we use your information

  • To provide, maintain, and improve the Chenashe service
  • To authenticate users and manage account security
  • To send transactional emails (account confirmation, password resets, system notifications)
  • To respond to support requests
  • To monitor system health and prevent abuse
  • To comply with legal obligations

We do not sell, rent, or trade personal information to third parties. We do not use your organisation’s data for marketing, analytics, or AI model training.

3. Data storage and security

All data is stored in Sydney-region infrastructure within Australia. We use encryption in transit (TLS) and at rest. Multi-factor authentication is mandatory for all staff and admin accounts. Row-level security policies enforce data isolation between organisations at the database level. See our Security page for more detail.

4. Data sharing

We share information only with service providers who assist us in operating the platform: hosting infrastructure (Supabase, Netlify), email delivery (Resend/SMTP2GO), SMS (Twilio), payment processing (Stripe), and error monitoring (Sentry — with PII scrubbed before transmission). These providers process data on our behalf under contractual obligations.

When your organisation connects third-party integrations (Xero, MYOB, Gmail), data flows to those services under their own privacy policies and your organisation’s direct authorisation.

5. Indigenous Data Sovereignty

Chenashe provides specific consent controls for tenants who identify as Aboriginal and/or Torres Strait Islander. Tenants can opt out of aggregate reporting, AI-assisted drafting, and data sharing via their portal privacy settings. These opt-outs are enforced automatically in all dashboards and funder reports.

6. Your rights

Under the Australian Privacy Principles, you have the right to access and correct personal information we hold about you. Organisation administrators can export their data at any time. To make a privacy request, contact us at hello@chenashe.au.

7. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email to account administrators. The “Last updated” date at the top reflects the most recent revision.

8. Contact

For privacy questions or requests, contact us at hello@chenashe.au.