Last updated: 2 September 2026
v1.8, 2 September 2026
By creating an account, completing a one-shot "Update without account" flow at /quick, or otherwise using the OneAddress platform, you agree to these Terms of Service. If you do not agree, do not use the platform. These terms constitute a binding agreement between you and OneAddress Pty Ltd (ABN 43 696 078 869).
OneAddress is a secure address management platform that enables you to transmit encrypted address updates to connected service providers (banks, insurers, government agencies, utilities). The platform includes: a zero-knowledge encrypted vault for storing your address; identity verification before each address update; encrypted address transmission to selected services; address history tracking and PDF export.
You must provide accurate information when creating your account. You are responsible for maintaining the security of your account credentials and vault PIN. You must notify us immediately if you believe your account has been compromised. You must be at least 18 years of age to use the platform.
Whose address you may update. You may use OneAddress for your own address, or for someone else's only if you are genuinely authorised to act for them. Before we send anything we ask you to confirm this, and you must not confirm it unless it is true. Changing another person's address without their authority may be an offence and it can cause them real harm, including redirecting their mail.
Identity checks prove who you are, not what you control. Our identity check confirms that you are the person on your identity document. It does not, and cannot, confirm that you hold an account with a particular service provider or that you are entitled to change it. That remains your responsibility, and each provider applies its own checks before acting on what we send.
Joint, business and represented accounts. Where an account with a service provider is held jointly, held by a business, or operated under a power of attorney or similar authority, you may only include it if you are authorised to change that account's address. We may ask you for evidence of that authority, and we may decline or reverse an update where we are not satisfied. If you are unsure, contact us at support@oneaddress.io before you pay.
If an account holder dies. Authority to act for a person generally ends when they die. Once we are on notice of a death we will not send any address update for that account, including one already scheduled. An executor or administrator should contact privacy@oneaddress.io; the Privacy Policy sets out what we need and what we can and cannot do.
(Account flow only, the "Update without account" flow does not use a vault PIN; see section 4A.)
Your vault is protected by a 6-digit PIN that you create. Your PIN protects the key material that encrypts your vault data (for vaults created since late July 2026, your recovery code independently protects the same key material), and all encryption and decryption happens on your device: neither your PIN, nor your recovery code, nor any key usable to decrypt your vault is ever sent to us. We cannot recover your PIN ourselves. You are solely responsible for remembering your PIN and, separately, for keeping the one-time recovery code shown when you first set up your vault. If you lose your PIN but still have your recovery code, you can use it from the "Forgot PIN?" link on the vault unlock screen to set a new PIN, your vault, services, and address history are preserved. We do not store your recovery code ourselves, so if you lose both your PIN and your recovery code, "Forgot PIN?" instead offers to wipe your vault: a confirmation code is sent to your registered email address, and confirming permanently deletes your encrypted vault data (your saved services, account references, and address history) so you can start fresh with a new PIN. Your account and payment history are preserved either way. We strongly recommend storing both your PIN and your recovery code in a secure password manager.
The one-shot guest flow at /quick lets you update your address without creating an account. By using this flow you also acknowledge:
oneaddress.io/quick and select "Resend status email" (available for up to 30 days after submission).When you initiate an address update, you authorise OneAddress to transmit your encrypted address data to the services you have selected. You are responsible for ensuring the accuracy of the address information you provide. Transmissions are final once dispatched. You cannot recall a sent transmission. Services process address updates according to their own policies.
Address already current (account flow). When you update from a OneAddress account, some services' systems can check the address you submit against the address they already hold. If such a service responds that your address is already up to date, we show this as an "already in sync" outcome on your status page: no change is made and no refund is issued, because your address was already correct at that service. This applies only to services whose systems support that check; updates made through the "Update without account" guest flow are always dispatched.
Data shared with services. Alongside the encrypted address, each webhook includes routing information (an update identifier, a pseudonymous user identifier, the service identifier, and a timestamp) and a verification attestation containing no personal details. Your name, any alternate names, and the account or member number you provided are encrypted together with your address in a per-service envelope that only the receiving service can decrypt with their private key; your name is carried to that service in a separately encrypted authorisation letter. Your phone number and email address are transmitted to a service only if you specifically ask us to update that detail with them, and never as part of an address update; when they are sent, they travel inside the same per-service encrypted envelope and only to a service that has told us it accepts that kind of update. No address or identity content travels in readable form.
You can schedule an address update for a future date, such as your moving day. When you do, we prepare and encrypt your update straight away, but we do not send it until you confirm on the day.
We ask you to confirm on the day. On the date you chose, we email you and ask you to confirm that you still want the update to go ahead. You have 48 hours from that message to confirm. You can confirm from the link in the email or from your dashboard. We also remind you about the upcoming date roughly seven days and two days beforehand, so the confirmation is never a surprise.
If you do not confirm, we do not send it. If the 48 hours pass without your confirmation, we will not transmit your update. Nothing is shared with any of the services you selected and your address is not changed with them. We will email you to tell you it was not sent. The payment for that update is not refunded, because we have already carried out and paid for the identity verification that the update depends on. You can start a new update at any time.
We do this because an address update should reflect what you want on the day it is sent, not only what you planned when you scheduled it. It also means we will not act on an instruction that the person who gave it is no longer able to confirm.
You can change the date or cancel a scheduled update at any time before it is sent, from your dashboard. Cancelling before your identity check is carried out is refunded in full, as set out in section 6.
Address updates are charged at the price displayed before you confirm. Payments are processed by Stripe. We may change our pricing from time to time. Any price change applies only to address updates you start after the change takes effect, and you will always see and confirm the exact price before any charge is taken, so a price change never affects an update you have already paid for.
Refund policy. A refund is automatically issued when OneAddress fails to deliver your update because of a problem on our side, for example, our system did not transmit your update at all, or a systemic fault on our end (such as a signing or configuration error) prevented delivery to most or all of the services you selected. In those cases we refund you in full, because we did not deliver the service you paid for.
When refunds are not issued. Refunds are not issued when an individual service provider's own system was unavailable at the time we transmitted your update while your other selected services were updated, that is an outage on the provider's side, not ours, and we delivered what we could. Refunds are also not issued when a provider reports "no matching account" because the account number, name, or alias you supplied did not match their records. To reduce mismatches, we run a pre-payment account-existence check (see section 4A and our Privacy Policy section 5A) so you can correct a mistyped account number before any charge is taken. Where only a small number of services were involved and delivery did not complete, we review the update before deciding. Before any service delivery is treated as failed, we automatically retry for up to 48 hours (see section 7); refund eligibility is assessed only after that retry window has closed. Once a transmission has been accepted by a provider, the payment for that transmission is non-refundable even if other providers in the same batch fail, because that part of the service was delivered. This does not affect any refund or other remedy you may be entitled to under the Australian Consumer Law if we fail to provide the overall service with due care and skill.
Cancelling an in-progress update. You may cancel an in-progress update at any time before it is submitted. If you cancel before starting your identity check, any payment taken will be refunded in full to the original payment method. Once you begin the identity check, your payment is non-refundable. OneAddress is charged by our verification provider at that point regardless of the outcome. We surface this warning on screen before you start the check.
Approved refunds are returned to the original payment method via Stripe. Allow up to 10 business days for the refund to appear on your statement, depending on your card issuer. Where required by Australian Consumer Law, your statutory rights are unaffected.
Refund processing. Eligible refunds are processed typically within 1 to 3 business days of the triggering event, and often sooner. If your eligible refund has not appeared within 5 business days, please contact us at support@oneaddress.io.
Chargebacks. If you believe a charge is incorrect, please contact us at support@oneaddress.io before initiating a chargeback with your bank or card issuer. In most cases we can resolve the issue directly and more quickly. If you do initiate a chargeback, we may provide Stripe and your issuer with evidence of service delivery, including dispatch records and service confirmation timestamps.
What the statuses mean. We report exactly what each provider tells us, and nothing beyond it. In particular, a positive status is not a promise that the provider has changed its records:
If you need certainty that a provider has actually updated your records, check with that provider directly. We can tell you what we sent and what came back; only they can tell you what they did with it.
OneAddress maintains a network of participating service providers. Our agreement with each of them calls that organisation a Participating Organisation; these terms call them services, and our technical documentation, developer materials and partner-facing pages call them partners. All three terms are interchangeable and refer to the same organisations. We do not guarantee the availability, accuracy, or responsiveness of any service. Services are independent organisations that process address updates according to their own policies.
If initial delivery of your address update to a service fails, we will automatically retry for up to 48 hours. If delivery cannot be completed within that window, automatic retries stop and you will be notified by email. No further automatic delivery attempts will be made after this point. You will need to contact the service directly or submit a new address update through OneAddress.
We are not responsible for errors, delays, or failures in service processing caused by service system outages or other factors outside our control.
Late processing after the retry window. In rare cases, a service that was unreachable during our 48-hour retry window may still process your address update after that window has closed, including after a refund has been issued to you. If this occurs, we cannot recall address data that has already been transmitted. If you have concerns about an update being applied by a service after a refund, please contact that service directly.
Nothing in these terms excludes, restricts, or modifies any right or remedy, or any guarantee, warranty, or other term or condition, implied or imposed by the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) or any other applicable law that cannot lawfully be excluded or limited. If the Australian Consumer Law applies to you as a consumer, you have statutory guarantees that cannot be excluded.
Subject to the above, and to the maximum extent permitted by law, we are not liable for: incorrect address information you provide; service failures to process address updates; loss of vault data caused by a forgotten PIN and an unsaved or lost recovery code; service interruptions or downtime outside our reasonable control; or any indirect, incidental, or consequential loss or damage. For services of a kind ordinarily acquired for personal, domestic, or household use, the Australian Consumer Law does not allow us to cap our liability for the consumer guarantees, and we do not attempt to. For any other liability, and only to the extent the law allows it to be limited, our total liability for any claim arising from your use of the platform is limited to the amount you paid to OneAddress in the 12 months preceding the claim. Nothing in this section limits any liability we cannot lawfully limit, including our liability for failing to provide the service with due care and skill.
You may not: use the platform for fraudulent address changes; attempt to decrypt other users' vault data; interfere with the platform's operation; use automated tools to abuse the service; impersonate another person; transmit false or misleading information to services.
You may delete your account at any time from Settings. We may suspend or terminate your account if we reasonably believe you are violating these terms or engaging in fraudulent activity. Where practicable, we will give you notice and a chance to respond first. If we terminate your account, we will refund any payment you have made for an address update that we have not yet dispatched.
When you request deletion, your account enters a 48-hour grace period during which it remains fully active. This window allows any in-progress address updates to complete and gives you the opportunity to cancel the deletion if you change your mind, you can cancel from the banner on your dashboard at any time during those 48 hours. At the 39-hour mark you will receive a final account export email with your complete history and a link to your dashboard where you can cancel the deletion. After 48 hours we delete your encrypted vault data, transmission history and personal information from our active systems, and we do not retain readable copies of any of it. Two things outlive that, and the Privacy Policy sets out both in full: our database provider's short-term disaster-recovery backups, until they age out on its own cycle, and the audit and compliance records we are required to keep, from which your identifier is replaced with a one-way pseudonym.
If OneAddress ceases operating or discontinues the platform, we will give you as much notice as we reasonably can, and at least 90 days by email where it is within our control to do so. We say "where it is within our control" deliberately: an insolvency or a regulatory direction can compress that, and we would rather tell you now than promise something we might not be able to keep. During any notice period:
OneAddress will not sell, license, or transfer your personal data to a third party as part of any wind-down, sale, or acquisition without your explicit prior consent, except as required by law or to the extent necessary to complete the transaction under binding confidentiality obligations. In the event of an acquisition or merger, we will provide at least 30 days' advance notice if the privacy or data practices applicable to your information will materially change, giving you the opportunity to delete your account before those changes take effect.
If you have a complaint about the service, please contact us first at support@oneaddress.io. We will acknowledge your complaint within 2 business days and aim to resolve it within 30 calendar days. This internal process is free and does not limit any of your rights.
If we cannot resolve your complaint within 30 days, you may escalate to an external body:
Nothing in this section limits your right to take legal action or to pursue any statutory remedy available to you under Australian Consumer Law.
These terms are governed by the laws of Western Australia, Australia. Any disputes will be resolved in the courts of Western Australia. The Australian Consumer Law applies to the extent it cannot be excluded.
We may update these terms from time to time. For material changes, those that reduce your rights, add obligations, or change how we handle your data, we will notify you by email at least 30 days before the change takes effect. Minor or non-material changes (such as typographical corrections or clarifications that do not reduce your rights) may take effect immediately. Continued use of the platform after material changes take effect constitutes acceptance of the revised terms. If you do not agree with a change, you can delete your account at any time before it takes effect, at no cost, and export your data first.
For questions about these terms, contact us at legal@oneaddress.io.