Last updated: 4 September 2026
v2.10, 4 September 2026
This summary is a guide only. The numbered sections below are the full policy.
OneAddress Pty Ltd (ABN 43 696 078 869) operates the OneAddress platform at oneaddress.io. We are an Australian company based in Western Australia. When we say "OneAddress", "we", "us", or "our", we mean OneAddress Pty Ltd.
How privacy law applies to us. We apply the Australian Privacy Principles (APPs) as our operating standard, and we comply with the Privacy Act 1988 (Cth) where it applies to us. Where this policy describes a right, a limit, or a commitment, we honour it as a matter of policy whether or not the Act compels it. If our circumstances change so that the Act applies to us differently, we will update this policy and tell you as described in section 12.
Children. OneAddress is intended for individuals aged 18 and over. The service requires a government-issued identity document and an identity check, so it is not designed for or directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact privacy@oneaddress.io and we will delete it.
The zero-knowledge guarantee applies specifically to your address vault. Other information we hold, such as your email address, phone number, and transmission records, is standard account data stored on our servers and handled in accordance with this policy.
Your vault data (addresses, service connections) is encrypted in your browser. The keys that can decrypt it are derived on your device from your 6-digit PIN (or, for vaults created since late July 2026, from your recovery code) and never leave your device in usable form. We store only encrypted data we cannot decrypt.
Account information: When you create an account, we collect your email address and authentication credentials (email verification code, a password with optional two-step verification, or Google/Apple sign-in). If you sign in with Google, we receive your unique account identifier, email address, and display name from Google. If you sign in with Apple, we receive your unique account identifier, email address, and display name on first sign-in only; on subsequent sign-ins Apple provides only the identifier.
Guest sessions (updating without an account): If you use the "Update without account" flow at /quick, we create a short-lived guest session keyed only to an email-verified one-time code. We hold your email, phone number, and the name and any alias names you supply so we can dispatch your update and contact you with the result; these, along with the per-service account or member numbers you enter, are encrypted at rest under a server-held key. See section 5A for the full guest-flow retention and processing detail.
Contact details: The guest flow collects your phone number. If you have an account, we also collect a phone number when you choose to add or verify one, or to change the number we hold; verifying it means we send a one-time code to that number by text message, which involves an overseas provider (see sections 7 and 11). Both flows collect your preferred full name and (optionally) the alternate names you are known by (e.g. nickname, maiden name). Your name and any alternate names are transmitted to services only inside the same per-service encrypted envelope as your address, so a service can match you to their records after decrypting it. Your phone number and email address are transmitted to a service only if you specifically ask us to update that detail with them. They are never included in an address update, and a service receives them only if they have told us they accept that kind of update. When they are sent, they travel inside the same per-service encrypted envelope as everything else. Otherwise your phone number and email address are used only by OneAddress, to contact you about your updates. See section 5.
Encrypted vault / payload data: Your addresses are stored in encrypted form. In the account flow, your vault is encrypted client-side with a key derived from your PIN. In the guest flow, your new address is encrypted client-side with an ephemeral key held only in your browser (and, after submission, in the URL fragment of your magic link). In neither case can we decrypt the address.
Transmission records: When you send an address update, we record the service name, timestamp, and delivery status for your transmission history. We do not store the address content, only that a transmission occurred.
Payment information: Payments are processed by Stripe. We do not store credit card numbers or bank details. Stripe's privacy policy applies to payment data.
Identity verification: Before each address dispatch, we ask you to complete an identity check using our provider, Global Data Pty Ltd. The document capture and selfie step runs entirely within Global Data's own hosted verification flow: your selfie and the photograph of your identity document are captured by, and stay within, Global Data's systems, and never reach OneAddress's servers. When the check finishes, Global Data returns to us only the outcome (pass or fail), a reference number, and, if the check passes, your verified name and date of birth. We do not receive or store your selfie, your document photograph, or your document number. We use your verified name to prepare the authorisation letter we send to the service provider you asked us to update (see section 5), and we never share your date of birth with your service providers. See section 6 for the full detail.
Biometric information: The liveness step (a short selfie video used to confirm you are a real, present person) is carried out entirely by Global Data Pty Ltd within their hosted verification flow, and is covered by their privacy policy. Your selfie and the face photograph from your document are processed by Global Data and never reach OneAddress's servers. We do not receive, hold, analyse, or store any biometric information, so we have none to share with anyone.
Usage data: We collect server-side request logs (IP address, request path, timestamp) for security monitoring and abuse prevention. We do not use third-party analytics tools or track individual browsing behaviour.
There is a small "Feedback" tab on some pages. If you open it, you can tell us how you are finding OneAddress, what you would change, what you would like us to work on next, and anything that has gone wrong. It is entirely optional and nothing on the form is required.
What we collect. Only what you type or select in that panel: a rating out of five, the areas you tick as priorities, and your written answers. We also record the date you sent it and which part of the site you sent it from, for example the dashboard or the quick update.
We do not record who you are. We do not attach your name, your account, your session, or your device to your feedback. This is true whether or not you are signed in. Your browser does not even send us your sign-in cookie when you use this panel. Because nothing identifies you, we cannot look up the feedback a particular person sent us, and neither can anyone else who can read our database.
Unless you ask us to contact you. There is a box you can tick if you are happy for us to follow up. If you tick it, you can give us an email address or a phone number. That is the only situation where a piece of feedback carries anything that identifies you, and it happens only because you chose it. We use those details for one thing: to ask you about the feedback you sent. We do not add you to a mailing list, and we do not connect the details to your OneAddress account.
How long we keep it. Your written feedback is kept for as long as it is useful to us, which may be indefinitely. It carries nothing that identifies you, so once you have sent it there is no personal information in it to delete. Contact details you gave us are different. We delete those 180 days after you send the feedback, whether or not we have been in touch, and the feedback itself stays without them.
Stopping spam. We limit how many messages can be sent from one internet connection in an hour. To do that we keep a scrambled, one-way version of your IP address for the length of that hour and then it is gone. It is held separately from your feedback, and there is no way to match the two back together.
Changing your mind. If you gave us contact details and want them removed before the 180 days are up, email privacy@oneaddress.io and tell us roughly when you sent the feedback and what address you gave. Because feedback is not linked to an account, we cannot find it from your account details alone, so we may need to ask you what you wrote.
This panel is built and run by us. Your feedback is stored in our own database in Australia (see section 7) and is not sent to any third-party feedback or survey service.
We use your information to: provide and operate the OneAddress platform; arrange verification of your identity before transmitting addresses to services; process address update transmissions to your selected services; send you email notifications about transmission confirmations and account activity; improve our product and fix issues; comply with legal obligations.
We do not sell, rent, or trade your personal information to third parties. We do not share your personal information with any third party for their own commercial or marketing purposes.
The organisations we transmit to are formally called Participating Organisations in our agreement with each of them. This policy calls them services. Our technical documentation, developer materials and partner-facing pages call the same organisations partners. All three terms are interchangeable and refer to the same organisations.
When you initiate an address update, your address is encrypted in your browser before it leaves your device. It is transmitted to the service using end-to-end encryption keyed to that service's credentials. Only the service can decrypt it. OneAddress cannot read the address during or after transmission.
Alongside the encrypted address, each webhook carries only routing information: an event type and protocol version (e.g. address.updated / 2.0), an update identifier, a pseudonymous user identifier (a stable reference used to link your dispatches at that service), the service's identifier, a timestamp, a key-share expiry date (indicating how long a service is expected to retain cryptographic session data), a payment reference (used by some service integrations for deduplication), and a verification attestation (a record that your identity was checked, containing no personal details). Your name, any alternate names, and the account or member number you provided are encrypted together with your address in the same per-service envelope, so only the receiving service can read them after decrypting with their private key; a separately encrypted authorisation letter carries your name to that service alone. No address or identity content travels in readable form.
You choose which services to notify. You can select or deselect individual services before each transmission.
The "Update without account" flow at /quick is a one-shot path that lets you send an address update to selected service providers without registering. Because there is no vault and no PIN, the data model differs from the account flow in three ways:
#k=, which servers cannot see); the email we send does not contain this key. OneAddress only ever sees the ciphertext.Magic link. After you submit, we email you a one-time URL of the form oneaddress.io/g/<token>. This link lets you view delivery status for each service and, if eligible, request a refund. It does not show your address content, because the server never holds the decryption key. That key exists only in your browser session at the moment you submit. If you want to view the address you sent, you must follow the browser redirect at submission time. If you lose the email, you can request a resend from the guest status flow; status and refund eligibility are always available, but the address itself cannot be recovered after that browser session ends.
Retention. Guest sessions are pruned 30 days after submission. Abandoned sessions (no submission, no payment) are pruned shortly after they expire. Once a session is pruned, your personal information and the encrypted address blob are deleted from our systems; transmission records (service, timestamp, status) are kept for the same period as the account-flow records described in section 8.
Before your encrypted address can be transmitted to a service, OneAddress requires you to complete an identity verification. This protects you, and your service providers, from someone updating your registered address without your authority.
We use Global Data Pty Ltd, an Australian identity service provider and an approved Gateway Service Provider for the Australian Government's Document Verification Service (DVS), to perform the verification on our behalf. Global Data submits your identity data to the DVS under its own participation arrangement with the Australian Government; OneAddress does not connect to the DVS directly. The flow runs within Global Data's hosted verification page and has three steps:
Sensitive information and consent. Identity verification uses sensitive information, including photographs and biometric data. We ask for your express consent on our own screen, before the verification window opens and before anything is collected. That screen sets out what will happen, displays the notice about the Document Verification Service that we are required to show you, and asks you to confirm that you are authorised to provide the identity details you are about to present. We record which version of that wording you agreed to, so your consent can always be matched back to exactly what you were shown. Global Data separately obtains any consents its own hosted flow requires. You can decline at that point without affecting any other part of your OneAddress account. For information on how Global Data handles this data, see their privacy policy.
Where data is processed. Global Data has confirmed to us in writing that document capture, text extraction, face matching and image storage all take place in Australia, on infrastructure Global Data controls in Australian regions. One step is an exception. The liveness check, the short selfie video used to confirm a real person is present, is performed on servers in the United States. Global Data has confirmed that no data from that step is stored or retained there. This is an overseas disclosure and is covered by the APP 8 disclosure in section 7.
What Global Data keeps, and for how long. The captured images (the liveness image, the document front, back and photo, and any identity photo) are deleted by Global Data within seven days of the check completing, and on Global Data's default setting for this service they are deleted as soon as it completes. The identity details read from your document are encrypted by Global Data under a key created for that single check, and that key is deleted from Global Data's systems when the check completes, so from that point Global Data cannot read them and only we can. That encrypted record is kept by Global Data for up to three months. The DVS match result, and the logs of the DVS call, are kept for seven years, which the Document Verification Service framework requires.
What we receive. The document capture, selfie, and DVS cross-check all take place within Global Data's hosted verification flow. Your selfie, the photograph of your document, and your document number never reach OneAddress's servers, so we do not receive, hold, or delete them. When the check reaches a final result, pass or fail, Global Data returns to us only the outcome, a reference number, and, on a pass, your verified name and date of birth. Those are handled as described in "What we keep, and for how long" below. Global Data's own retention of the source photographs and liveness video is governed by their privacy policy.
What we keep, and for how long. For each identity check that reaches a final result, we permanently store the result (pass or fail), a reference number, and a timestamp as an audit record. When the check passes, we also temporarily retain the name and date of birth extracted during the check as part of the verification record; these are encrypted at rest and removed from our systems after a minimum 48-hour retention period following dispatch (typically within 49 hours). Your date of birth is never sent to your service providers. The audit record is kept until your account is closed.
Compliance log we must keep for seven years. Separately, and independently of your account, we keep a de-identified compliance log: a record that an identity check took place, with its date, its outcome, and a one-way hash of your account identifier. This log contains no name, photograph, identity document, or date of birth. We are legally required to retain it for seven years under our participation agreement for the Australian Government's Document Verification Service (Identity Verification Services Act 2023 (Cth)); Australian Privacy Principle 11.1 permits us to keep records we are legally obliged to hold. After seven years the log is automatically and permanently deleted.
One verification per dispatch. Each completed verification authorises a single address transmission. Subsequent updates require a fresh verification.
No AI/ML profiling. OneAddress does not perform machine learning, profiling, or automated decision-making on your personal data. Our platform was developed with AI assistance, but no ML models process your address or identity information. The liveness check performed by Global Data uses computer vision to confirm physical presence and document authenticity; this is performed by Global Data (not by OneAddress) and is limited to identity verification.
If you delete your account. The identity verification records held by OneAddress (verification result, reference number, and timestamp, along with any name and date of birth details not yet automatically removed after dispatch) are scheduled for permanent deletion and removed within 48 hours as part of the account deletion process. The only exception is the de-identified seven-year compliance log described above, which we are legally required to keep and which contains no name, photograph, identity document, or date of birth (your account identifier appears in it only as a one-way hash). See section 8.
Your encrypted vault data, transmission records, and identity verification records are stored in Australian data centres (AWS Sydney, ap-southeast-2) via Neon (database) and Vercel (application hosting, Sydney region). Identity verification is performed by Global Data, an Australian identity service provider, in Australia, with the single exception of the liveness check described in section 6.
Overseas transfers (APP 8). Some auxiliary providers process account data outside Australia. Specifically: Stripe (payments) is based in the United States and receives payment metadata and billing information; Resend (transactional email) is based in the United States and European Union and receives your email address and the content of transactional notifications we send you; Upstash (rate limiting and short-lived one-time codes, using a Redis service) is provided by Upstash, Inc., based in the United States, and may store data in data centres outside Australia; it receives IP addresses and hashed identifiers for rate limiting, along with HMAC-SHA256 hashes of short-lived verification codes used for admin sign-in (the plaintext codes are never stored). No address or vault content is stored with Upstash. Sentry (production error monitoring) is provided by Functional Software, Inc. (trading as Sentry), a United States company; our account is on Sentry's European Union data region, so what it receives is stored in the European Union. It receives two kinds of technical report. The first is an error report (error type, stack trace, page URL, and browser and operating-system version) when the application encounters a fault; these are scrubbed before they leave your browser or our servers: request bodies, cookies, and query strings are stripped, email-shaped and otherwise sensitive values are redacted, default personal-data collection is disabled, and session recording is off. The second is a content-security report, which your browser sends directly to Sentry if a page of ours tries to load a script or other resource that our security policy does not permit; it names the page, the page you came from, the resource that was blocked and the policy that blocked it, and nothing from the page's content. Pages whose web address carries a private link code do not ask your browser to send these. No address, vault, or identity content is sent to Sentry. We choose these providers on the basis that they protect your information to standards comparable to the Australian Privacy Principles, and their handling of it is governed by their own published privacy and data-processing terms. We are in the process of documenting the specific data-processing terms that apply to us with each of them, and we will update this policy as that work completes. Encrypted vault data and address payloads are not sent to any of these providers. If you choose to sign in with Google or Apple, Google LLC (United States) and Apple Inc. (United States) act as identity providers: Google receives your account identifier, email address, and display name on each sign-in; Apple receives your account identifier and email address on every sign-in, and your display name on first sign-in only. These transfers are covered by this APP 8 disclosure. Global Data (identity verification) performs the liveness step of the identity check, the short selfie video, on servers in the United States; Global Data has confirmed that no data from that step is stored or retained there, and every other part of the check, including the document photograph, is processed in Australia (section 6). ClickSend (text-message delivery) sends the text message containing your verification code when you add, verify or change a phone number. It receives your mobile number and the content of that message, which is a six-digit code and our name. It does not receive your address, your vault content, your identity documents or your payment details, and we never send anything else to you by text message. Where this goes, and what we have been told. ClickSend has confirmed to us that message content is held on Amazon Web Services infrastructure in Australia, and that personal data contained in communications is deleted after 120 days. The contracting entity is ClickSend Pty Ltd, part of the Sinch group, under the law of Western Australia. Two further things they have told us, which we pass on because they qualify the picture. Their support and development teams sit in Australia, Sweden, the United States and the Philippines, and authorised staff outside Australia may access message content where that is needed for support. And while their privacy policy lists jurisdictions where downstream providers may be located, including the United States, the United Kingdom, New Zealand, Brazil, Vietnam and the Philippines, they have told us they cannot confirm from their published documentation whether a message sent within Australia passes through any particular one. So we are not claiming that this processing happens only in Australia. One thing that is true of text messages generally. A text message is not encrypted on its journey to your handset. Once it is handed to a mobile network for delivery it passes through that network's systems, which may be outside Australia. That is why we ask you to treat a verification code the way you would treat a password, and why the code is valid only briefly, can be used once, and is stored on our systems as a keyed hash rather than in readable form. Address lookup: what reaches us, and what stays on your device. Looking up an address happens in two stages, and the second never leaves your browser. First you name a suburb or postcode; what you type there is sent to our servers. We answer it from our own copy of the Australian Government's public address dataset, held in Australia, by sending your browser the addresses in that locality. Your browser then matches the street number and name against that list on your device. So in the ordinary case the street, the number and the unit are never sent to us at all: a suburb is the whole of what we receive. That copy of the dataset is national, covering every state and territory, so address text is no longer sent to any third party for this purpose. This replaces an earlier arrangement in which lookups we could not answer fell back to Google Places and then to OpenStreetMap; that fallback is switched off, and those two providers no longer receive address text from us. Three exceptions, stated plainly. If we cannot find the suburb you are naming, we offer you a control to search every address instead; choosing it sends what you have typed to our servers for that one search, still against our own Australian dataset and nobody else's. If a locality is too large to send to your browser, that one suburb is searched on our servers in the same way. And you can always type your address in by hand, in which case no lookup happens at all. In each case we do not store what you type, and it never enters your encrypted vault in that form. The vault copy of your address, and the copy transmitted to a service, are both encrypted on your device beforehand, and we hold no key that can decrypt either.
Our infrastructure includes: industry-standard encryption of your vault, end-to-end encryption of each service transmission, signed webhooks so services can confirm messages genuinely come from us, encryption in transit for all connections, and session management with automatic timeout.
If a data breach happens. If we discover a data breach that is likely to cause you serious harm, we will notify you as soon as reasonably practicable, and we will notify the Office of the Australian Information Commissioner (OAIC) if the law requires us to.
Legal requests. We may be required to disclose certain account information, such as your email address or transmission records, in response to a valid legal order under Australian law. Where the law permits, we will notify you before complying with any such demand. We cannot disclose the contents of your address vault, because we do not hold the key that decrypts it and we have built no way to recover one. What we could be compelled to hand over is the encrypted data itself, which is of no use without your PIN or recovery code.
Your encrypted vault data is retained for as long as your account is active. Transmission records and identity verification records are retained for the life of your account. You can clear your transmission history and address history at any time from Settings.
Specific retention periods:
dispatch_log): retained for 7 years from the date of each event (aligned with the statute of limitations for contractual disputes). This table contains no plaintext address data and no vault content, only cryptographic references (key identifiers and a cryptographic fingerprint of each payload) and dispatch timestamps.dvs_compliance_events): retained for at least 7 years in accordance with OneAddress's obligations under the Document Verification Service Participation Agreement. This log records verification events keyed by a hashed user identifier only, with no plaintext address or identity-document content.Account deletion. When you request account deletion, your account enters a 48-hour grace period. During those 48 hours your account remains active and you can cancel the deletion from your dashboard. At the 39-hour mark you will receive a final account export email before deletion proceeds. After 48 hours we delete your vault, transmission history, identity verification records and account details from our active systems. We do not retain readable copies of any of them.
Two things survive that deletion, and we would rather set them out than imply otherwise. Backups. Our database provider keeps its own short-term backups for disaster recovery. Deleted data can persist in those until they age out on the provider's own cycle, and it is not restored to the live service. Audit and compliance records. The records listed above are kept for the periods stated, because we are required to. Most contain no identifying information at all. In the remainder we replace your identifier with a one-way pseudonym and clear the free-text fields, which means they cannot be read as being about you, though we do not claim they could never be correlated by someone who already held other records. One deliberate exception: a payment reference is left intact on refund records, because our payment provider keeps its own copy regardless and we need it to prevent a duplicate refund.
We give you the following rights as a matter of policy, and you also hold them as a matter of law wherever the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to us. You have the right to: access the personal information we hold about you; request correction of inaccurate information; request deletion of your account and data; opt out of direct marketing communications; and complain about how we have handled your personal information (see section 9A), including to the Office of the Australian Information Commissioner (OAIC).
How correction works here, which is not the usual way. Because of the encryption, correcting your information splits into three:
Because your vault data is zero-knowledge encrypted, we cannot access it ourselves. You control your data entirely through your vault PIN.
Making an access or correction request. To access the personal information we hold about you, or to have it corrected, email us at privacy@oneaddress.io. We do not charge a fee for making a request, and we will respond within a reasonable period (normally within 30 days). Where we can, we will give you access in the format you ask for. If we refuse access or correction, we will tell you in writing why, and how you can complain (see section 9A). If we correct information we have already shared with a service, or if you ask us to, we will take reasonable steps to notify them. If we and you disagree about whether information is accurate, you may ask us to attach a statement noting your view, and we will do so.
Dealing with us anonymously or by pseudonym (APP 2). Where it is lawful and practicable, you have the option of dealing with us without identifying yourself. You can browse oneaddress.io, read our documentation, and contact us with a general enquiry without giving your name. However, the core service transmits address changes to your banks, government agencies, insurers, and other providers on your authority, so we are required to verify your identity before each dispatch. This protects you against someone changing your registered address without your consent. For that reason it is not practicable to provide the address-update service anonymously or pseudonymously. Where we do need to identify you, we seek only the minimum personal information needed to do so.
Deceased account holders. If an account holder has died, contact us at privacy@oneaddress.io. We handle these requests under applicable Australian succession law.
If you think we have fallen short of the Australian Privacy Principles we apply, or otherwise mishandled your personal information, please tell us first so we can put it right.
We treat privacy complaints seriously and will not disadvantage you for making one.
OneAddress uses a small number of server-set, functional-only cookies. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
/quick. Contains a signed session identifier (no plaintext PII). HttpOnly, Secure, SameSite=Lax. Expires after 30 days or when you cancel or restart the flow; completing a submission does not immediately clear this cookie.oa-lockdown carries a signed preview-access grant, and oa-lockdown-peek temporarily suppresses such a grant so the holding page can be viewed. HttpOnly, Secure; contain no personal data. Not set for regular users in normal operation.oa-oauth-state, oa-oauth-nonce, oa-oauth-redirect), short-lived (5 minutes) CSRF and nonce tokens set during Google/Apple sign-in. HttpOnly, Secure, SameSite=None (required because Apple's sign-in uses a cross-site POST callback and the cookies must survive it). Deleted immediately after sign-in completes.oa-google-retry, oa-apple-retry), one-shot markers used to prevent an infinite retry loop when a browser drops an OAuth state cookie on the first cross-site redirect. Short-lived (60 seconds), HttpOnly, Secure, SameSite=None. Contain no personal data; deleted after the retry is resolved.__cf_bm), set by Cloudflare, our DNS and DDoS-protection provider, for bot management and traffic security. These are not under OneAddress's control. No personal data is stored by Cloudflare on OneAddress's behalf. Cloudflare's privacy policy applies.Cookies that carry session data or personal information are HttpOnly (inaccessible to JavaScript) and Secure. One non-HttpOnly cookie (oa-auth-hint) is used solely as a browser-side UI signal; it contains no personal data. You can block or delete cookies in your browser settings, but doing so may prevent you from signing in or using the guest flow. On your first visit we show a short cookie notice for transparency; because our cookies are strictly necessary, this notice is informational and does not gate any consent.
We use the following third-party services. Where a provider is based outside Australia, the nature of data transferred is described, see section 7 for the full APP 8 overseas disclosure.
Each provider has its own privacy policy, and their handling of your information is governed by their published privacy and data-processing terms. We do not currently hold a separate negotiated data-processing agreement with each of them. We are documenting the specific terms that apply to us provider by provider, and we will update this section as that work completes (see section 7).
We may update this privacy policy from time to time. For material changes, those that reduce your rights, add new data collection, or change how we share your information, we will notify you by email at least 30 days before the change takes effect. Minor changes (such as clarifications or typographical corrections) may take effect immediately. The “Last updated” date at the top indicates when the policy was last revised.
OneAddress Pty Ltd (ACN 696 078 869 · ABN 43 696 078 869)
Western Australia, Australia
For privacy-related enquiries, contact us at privacy@oneaddress.io. We aim to respond to privacy enquiries within 10 business days. If you believe we have mishandled your personal information, you may also raise the matter with the Office of the Australian Information Commissioner (OAIC).