Privacy policy · 1 August 2026

Privacy follows the permission boundary.

This policy explains how Onsellr ID (OID) handles personal information when people use its vehicle records, participant workflows, agent network and developer services.

Information we handle

We may handle account identifiers, verified email addresses, participant profile information, claimed relationships to vehicles, contribution and transfer details, sales enquiries, booking or offer details, consent choices, agent conversations, billing references, device and security signals, and evidence submitted through secure upload paths.

How we use information

We use information to operate and secure accounts, issue and maintain vehicle identities, assess claims and contributions, transfer control, deliver permissioned agent services, record consent, prevent abuse, meter platform usage, provide support and meet legal obligations.

Public and restricted records

An OID public record can show vehicle identity details, published events, sources and verification states. Personal contact details, private evidence and controller-only settings are restricted. Publishing a vehicle event does not automatically publish its supporting document.

Connected providers

A connected agent receives only the fields covered by its certified scopes and the vehicle controller's active connection. Where customer consent is required, OID displays the receiving provider and proposed fields before sharing. Providers operate under their own privacy and regulatory responsibilities.

Browser session continuity

After you start a vehicle-agent conversation, OID may keep that vehicle's code, a random session identifier and a 30-day expiry in your browser's local storage so the same device can receive an offer or booking outcome later. OID does not place the conversation transcript, offer amount, contact details or seller identity in that browser record. You can remove it at any time by clearing site data in your browser.

Service providers and overseas processing

OID uses specialist hosting, database, authentication, communications, AI and billing providers. Some may process information outside Australia. We limit access to operational need and use contractual, technical and access controls appropriate to the service.

Retention and security

Contact details in sales enquiries are currently designed to expire after 90 days. Vehicle identity, consent, contribution, transfer and audit records may be retained longer where necessary to preserve record integrity, demonstrate authority, resolve disputes or meet legal obligations. Security measures include encrypted transport, restricted storage, signed webhooks, scoped credentials, rate limits and append-only audit events.

Access, correction and complaints

You can request access or correction, withdraw a revocable consent, or raise a privacy concern by emailing admin@onsellr.com. We may need to verify your identity and authority before acting. Some history or audit information cannot be silently erased where doing so would compromise another person's rights, vehicle-record integrity or a legal requirement.

Policy changes

Material changes will be published here with a revised date. This operational policy should be reviewed by qualified Australian privacy counsel before broad commercial launch.