RoofHero Australia Pty Ltd — Privacy Policy

Effective Date: 30 September 2025
Who we are
RoofHero Australia Pty Ltd (ABN [insert]) and our technology brand “Roover” (together, RoofHero, we, us, our).
This Privacy Policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Quick summary

  • We collect contact and property details to scope roofing jobs, run tenders with local contractors, and support the homeowner–contractor engagement.
  • We’re a marketplace, not the builder. Your contract and payments are with the contractor.
  • Contractors may pay RoofHero a platform/referral fee (this does not add a separate fee to your price).
  • We secure data using MFA, role‑based access (RBAC), encryption and least‑privilege controls.
  • You can request access to, or correction of, your personal information.
  • If a data breach is likely to cause serious harm, we’ll notify affected individuals and the OAIC

2. What personal information we collect

Homeowners / residents

  • Identity & contact: name, email, phone, suburb/address.
  • Property & project: property address, roof area/material/condition, photos, aerial/roof measurements, job brief/scope, preferred dates.
  • Communications: messages, call notes, feedback and complaints.
  • Device/technical: IP address, device identifiers, browser type, site and email interactions (see Cookies & online tracking)

Contractors

  • Business & contact: trading name, ABN, licence number, address, email, phone
  • Compliance & capability: public liability insurance (PL), workers compensation, HBCF eligibility (as applicable), references, performance/quality metrics, conduct records.
  • Billing & platform use: platform fee tier and payment status (processed by third‑party providers; we don’t store full card numbers).

We avoid collecting sensitive information (e.g., health data). If we ever need it, we’ll collect it only with consent or as permitted by law.

3. How we collect information

  • Directly from you (forms, emails, calls, chat).
  • From contractors (quotes, scheduling, post‑job feedback).
  • From service providers we use to operate RoofHero (e.g., aerial/roof data, property data, analytics, cloud hosting, communications and support tools, payment processors).
  • From public sources (e.g., contractor licence registers). We collect by lawful and fair means and only what is reasonably necessary for our functions.

4. Why we collect, use and disclose information

We use your information to:

  • Provide the marketplace service: scope jobs (including remote/aerial measures), invite and manage tenders, present quotes, coordinate inspections, and facilitate the homeowner–contractor engagement.
  • Operate and improve the platform: service delivery, training and quality assurance, analytics and product development (including de‑identified or aggregated insights).
  • Verify compliance: contractor licence/insurance checks, quality and safety standards, HBCF/DBI processes where required.
  • Communicate with you: service updates, support, surveys and (if you opt‑in or as permitted) marketing about RoofHero services.
  • Prevent, detect and respond to fraud, abuse or safety issues; manage disputes and legal claims; and comply with laws and regulatory requests.

We use or disclose personal information only for the primary purpose above, for a related secondary purpose you’d reasonably expect, with consent, or as otherwise permitted by law.

5. Disclosures we commonly make

Depending on your choices, we may:

  • To contractors participating in your tender—limited to what they need to scope and quote.
  • To service providers who help us run RoofHero (hosting, analytics, communications, support, document storage, payment processors for contractor fees).
  • To insurers or scheme administrators where a scheme (e.g., HBCF in NSW) requires information to issue residential building cover.
  • To regulators or law enforcement where required or authorised by law, and to handle safety, fraud or security incidents.
  • Business transfers (e.g., merger or acquisition) subject to confidentiality and this policy.

We do not sell personal information.

6. Cross‑border disclosures

Some providers may process or access personal information outside Australia (for example, the United States, the European Union (e.g., Ireland/Netherlands) or Singapore). Where we disclose personal information overseas, we take reasonable steps to ensure recipients handle it consistently with the APPs (e.g., contractual safeguards). We’ll update this section if our vendor footprint changes.

7. Direct marketing, cookies and online tracking

Direct marketing. We may send you RoofHero news or offers where permitted by law or with your consent. You can opt out at any time via the unsubscribe link or by contacting us.

Cookies & pixels. We use cookies and third‑party tracking pixels to operate the site, measure usage, troubleshoot, and—if enabled—run targeted ads. You can manage preferences via our Cookie Settings link and your browser settings. Turning off non‑essential cookies may reduce some features but core site functions will still work. See our Cookie Policy for details.

Email/SMS. Marketing emails and SMS will always identify us and include a working unsubscribe. We process unsubscribes promptly.

8. Anonymity and pseudonymity

You may browse the site or make basic enquiries without identifying yourself where practicable. For quoting, compliance and contractor engagement, we generally need accurate contact and property details.

9. Security

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Measures include (appropriate to our size and risk profile):

  • Multi‑factor authentication (MFA) on key systems
  • Role‑based access control (RBAC) and least‑privilege access
  • Encryption in transit and at rest
  • Network security, patching and monitoring
  • Vendor due diligence and data processing agreements
  • Staff training, retention rules and secure disposal
  • Backups and tested incident/breach response runbooks

We destroy or de‑identify personal information when it’s no longer needed unless we must retain it by law.

10. Data retention & deletion

We retain personal information only as long as needed to deliver services, maintain records (e.g., tender history, compliance, insurance/disputes), meet legal/tax obligations and maintain security logs. When no longer required, we securely delete or de‑identify it (subject to legal holds).

11. Accessing and correcting your information

You can request access to the personal information we hold about you, and ask us to correct it if it’s inaccurate, out‑of‑date, incomplete, irrelevant or misleading. We’ll respond within a reasonable period (usually 30 days) and may need to verify your identity. If we refuse access or correction (rare and only where permitted), we’ll tell you why and how to complain.

How to lodge a request: email privacy@roofhero.com.au with your name, contact details and what you’d like to access or correct.

12. Data breaches and notifications

If we experience a data breach involving personal information, we will:

  • Contain and investigate
  • Assess whether it’s an eligible data breach (serious harm likely); and
  • Notify affected individuals and the OAIC as required. We assess suspected breaches as quickly as possible (generally within 30 days) and include steps you can take to reduce harm.

13. Government‑related identifiers

We do not adopt, use or disclose government‑related identifiers (e.g., driver licence numbers) as our own identifiers except where permitted or required by law. Where we collect a contractor’s licence number, we use it only for verification and compliance purposes.

14. Children

Our services are intended for adults arranging residential building work. We don’t knowingly collect personal information about children. If you believe a child has provided us information, please contact us so we can delete it or obtain appropriate consent.

15. Automated tools and human review

We use automated tools (including aerial/roof data and estimation models) to pre‑fill measurements and scoping information. Quotes and prices are set by contractors; we do not make solely automated decisions that have legal or similarly significant effects on individuals.

16. Third‑party links and services

Our site may link to third‑party sites or tools with their own privacy practices. Review their policies—this policy does not cover them.

17. How to contact us or make a privacy complaint

Email privacy@roofhero.com.au or write to the address above. Tell us what happened and your desired outcome. We’ll investigate and respond.

If you’re not satisfied, you can contact the Office of the Australian Information Commissioner (OAIC):

Phone: 1300 363 992

Post: GPO Box 5288, Sydney NSW 2001

18. Changes to this policy

We may update this policy to reflect changes to laws, guidance or our services. The Effective date at the top shows the latest version. If changes are material, we’ll take reasonable steps to let you know.

Get Roof Quotes in
Hours not Weeks.

Compare 3 competitive quotes without leaving your couch.