Privacy Policy and AML/CTF Privacy Collection Notice
Last updated: 23 August 2026
1. About us and this policy
Shine Bright Property Group Pty Ltd (ABN 46 681 000 555), trading as Shine Bright Property Group (Shine Bright, we, us or our), provides real estate sales, leasing, property management and related services in Queensland.
This policy explains how we collect, hold, use and disclose personal information when you visit our website, contact us or use our real estate services. It also includes our privacy collection notice for customer due diligence under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply, including when information is handled for or in connection with our AML/CTF obligations. We also comply with the AML/CTF Act and Rules and applicable Queensland property laws, including the Property Occupations Act 2014 (Qld), Property Law Act 2023 (Qld) and Residential Tenancies and Rooming Accommodation Act 2008 (Qld).
Using our website does not by itself amount to consent to every collection, use or disclosure described in this policy. We rely on applicable law, the services you request, reasonable expectations and consent where consent is required.
2. Personal information we may collect
Depending on your dealings with us, we may collect:
- your name, date of birth, residential, postal or business address, email address and telephone number;
- occupation, employer and business or professional details;
- details of properties you own, occupy, manage, rent, wish to buy or wish to sell;
- agency appointments, property appraisals, offers, contracts, leases, tenancy applications, references, inspection records, maintenance requests and correspondence;
- bank account, payment, bond, rental, deposit, finance, insurance and settlement information where reasonably necessary;
- identity information, including the type, number, issuing authority and expiry date of a driver licence, passport or other government-issued document;
- information about companies, trusts, partnerships, representatives, directors, trustees, beneficial owners and persons who control an entity;
- records of telephone calls, emails, messages, meetings, consents and instructions;
- website and device information, including IP address, browser type, pages viewed, cookies and analytics data; and
- other information reasonably necessary to provide our services, comply with law, prevent fraud or manage a dispute.
3. AML/CTF customer information
When we provide a designated real estate service, we may be required to conduct initial, ongoing or enhanced customer due diligence. Depending on the customer and the level of risk, we may collect and verify:
- your full legal name, former or other names, date of birth and residential address;
- country of residence, citizenship or nationality and occupation or employment details where relevant;
- identity-document details and the result of identity verification;
- a photograph, selfie, facial image or liveness result where you agree to use a remote biometric identity-verification process;
- the identity and authority of anyone acting for you and the identity of the person on whose behalf a transaction is conducted;
- company, trust, partnership, beneficial ownership and control information;
- the nature and purpose of the business relationship or property transaction;
- source-of-funds or source-of-wealth information where required by our risk-based AML/CTF program;
- politically exposed person, sanctions, terrorism-financing sanctions and adverse-media screening results;
- customer and transaction risk assessments, monitoring outcomes, review notes and escalation records; and
- information reasonably necessary to meet reporting, record-keeping, compliance and regulatory obligations.
We only collect information that is reasonably necessary for our functions or activities, including our AML/CTF obligations. The AML/CTF laws generally do not require us to retain a complete copy of an identity document. Where a copy is collected to perform verification, we will take reasonable steps to destroy or de-identify it once the copy is no longer required, while retaining the information and verification records that the law requires.
4. How we collect personal information
We may collect information:
- directly from you in person, by telephone, email, message, website form, application, agreement or secure online process;
- from a person authorised to represent you, a joint owner, co-applicant, guarantor, referee, employer or emergency contact;
- from solicitors, conveyancers, accountants, mortgage brokers, lenders, insurers, property owners, tenants, buyers and sellers;
- through Securexchange and InfoTrack, including identity verification, customer questionnaires, screening, reliance reports and compliance workflows;
- from another AML/CTF reporting entity where we are permitted to rely on customer due diligence it has conducted;
- from real estate portals, tenancy platforms, service providers and contractors;
- from public and government sources, including land-title records, ASIC registers, court or insolvency records and sanctions lists; and
- automatically when you use our website, through cookies, analytics and server logs.
If you provide us with another person’s information, you must be authorised to do so and should make them aware of this policy where it is reasonable and lawful.
5. Why we collect, use and disclose information
We may handle personal information to:
- respond to enquiries and provide property appraisals and real estate advice;
- prepare and administer agency appointments, advertising, listings, inspections, offers, contracts, leases, seller disclosure, trust-account and settlement processes;
- manage rental properties, applications, tenancies, bonds, rent, inspections, maintenance and disputes;
- identify and verify customers, representatives and beneficial owners;
- understand the nature and purpose of a customer relationship or transaction;
- assess and manage money-laundering, terrorism-financing, proliferation-financing, fraud and other compliance risks;
- conduct ongoing or enhanced due diligence where required;
- make disclosures or reports and keep records as required or authorised by law;
- protect customers, our business and the integrity of property transactions;
- manage complaints, legal claims, insurance and regulatory enquiries;
- improve our services, systems, website and security; and
- send property alerts or marketing where permitted. You may opt out of marketing at any time.
6. When information is required and what happens if it is not provided
Some information is required or authorised under the AML/CTF Act, AML/CTF Rules or other Australian laws. Other information is necessary for us to perform the service you request.
If you do not provide required information, or we cannot satisfactorily verify it, we may be unable to start or continue providing a designated service, enter into or continue an agency appointment, progress a property transaction or provide another requested service. We may be required to delay, refuse or stop providing a service where permitted or required by law.
7. Who we may disclose information to
Where reasonably necessary, expected, authorised or required by law, we may disclose personal information to:
- our authorised employees, representatives and contractors;
- Securexchange, InfoTrack and their identity-verification, document-verification, screening, technology and compliance service providers;
- the Australian Government Document Verification Service and screening-data providers;
- another reporting entity, such as a solicitor or conveyancer, where an AML/CTF reliance arrangement is permitted;
- property owners, vendors, buyers, tenants, applicants and their authorised representatives where necessary for the transaction or service;
- solicitors, conveyancers, accountants, lenders, brokers, insurers, valuers, building inspectors and settlement service providers;
- real estate portals, advertising providers, property-management platforms, payment providers, tradespeople and utility or connection providers;
- AUSTRAC, the Office of Fair Trading, the Residential Tenancies Authority, Titles Queensland, courts, tribunals, police, regulators and other government or law-enforcement bodies where required or authorised; and
- professional advisers, insurers or other parties involved in a complaint, dispute, claim or business administration.
We do not sell or rent personal information.
8. Confidential AML/CTF information and tipping-off restrictions
We may be required or authorised to provide information to AUSTRAC or another authority. The AML/CTF Act may prohibit us from telling a person about particular reports, suspicions, requests for information or related matters where disclosure would or could reasonably be expected to prejudice an investigation. Where these restrictions apply, we may be unable to confirm that information exists, explain a particular action or provide access to particular information.
9. Sensitive information and biometric verification
Sensitive information may include criminal-history information, health information, racial or ethnic origin, religious beliefs, political associations, professional or trade association membership and biometric information used for automated identity verification.
We collect sensitive information only with consent where consent is required, or where collection is otherwise authorised or required by law. If remote facial or liveness verification is offered, you will be given information about that process and asked for any consent required before it proceeds. Where a practical non-biometric verification option is available, we will explain that option.
10. Government-related identifiers
We may collect and use government-related identifiers, such as driver licence or passport numbers, to verify identity or comply with law. We do not adopt a government-related identifier as our own customer identifier and do not use or disclose it except as permitted by the Privacy Act or another Australian law.
11. Overseas access and disclosure
Some technology and service providers may operate in, or permit controlled access from, locations outside Australia. Where overseas disclosure occurs, we take reasonable steps required by the Australian Privacy Principles to protect the information, unless an exception applies.
As at the date of this policy, InfoTrack states that it stores and retains personal information in Australia, may deal in Australia with multinational organisations operating in the United Kingdom, United States and New Zealand, and may permit strictly limited read-only development access from Vietnam. InfoTrack also states that data collected for its InfoTrackID and verification-of-identity services is not transferred or stored outside Australia. Provider practices may change, and their current privacy policies should also be reviewed.
12. Security
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include:
- secure platforms for identity documents, bank details and confidential transaction information;
- passwords, multi-factor authentication, encryption and access restrictions;
- limiting AML/CTF and identity records to authorised personnel;
- staff privacy, cybersecurity and AML/CTF training;
- secure storage, backups and document disposal; and
- service-provider due diligence and incident-response procedures.
No system can be guaranteed completely secure. Please do not send unencrypted identity documents, passwords or bank-account details by ordinary email unless we specifically confirm an appropriate secure method.
13. Retention and destruction
We retain records for as long as reasonably necessary for the purpose for which they were collected and to meet legal, regulatory, insurance, tax, contractual and dispute-management requirements.
AML/CTF records are generally retained for at least seven years. Customer due diligence records are generally kept for at least seven years after the business relationship ends, and relevant transaction records are generally kept for at least seven years from the applicable transaction or record date. Access to sensitive AML/CTF records is restricted.
When information is no longer required or authorised to be retained, we take reasonable steps to securely destroy or de-identify it. A request for deletion does not override a legal requirement or authorisation to keep information.
14. Access and correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may ask you to verify your identity before responding.
Access may be refused or limited where permitted or required by law, including where access would affect another person’s privacy, legal proceedings, enforcement activities or AML/CTF tipping-off restrictions. If we refuse a request, we will generally explain the reason and available complaint options unless it would be unlawful or unreasonable to do so.
15. Direct marketing, cookies and website analytics
We may use contact details to send property information, service updates or marketing where permitted. You can opt out using an unsubscribe facility or by contacting us. We will still send communications necessary to provide a service or comply with law.
Our website may use cookies and analytics to operate the site, remember preferences, understand site usage and improve services. Browser settings can be used to restrict cookies, although some site functions may be affected. Our website may link to external sites whose privacy practices we do not control.
16. Data breaches
We maintain procedures for responding to suspected data breaches. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm that cannot be prevented through remedial action, we will notify affected individuals and the Office of the Australian Information Commissioner as required.
17. Privacy complaints
If you believe we have mishandled your personal information, please contact us using the details below. Include your name, contact details, a description of the concern and the outcome you seek.
We will acknowledge a complaint within 14 days and aim to provide a substantive response within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au. AML/CTF confidentiality and tipping-off requirements may limit the information we can provide when responding.
18. Changes to this policy
We may update this policy when our practices, service providers or legal obligations change. The current version and its effective date will be published on this website.
19. Contact us
Privacy and AML/CTF Compliance Officer
Shine Bright Property Group Pty Ltd
Email: info@shinebrightproperties.com.au
Phone: 0414 040 234
Post: PO Box 2357, Sunnybank Hills QLD 4109
AML/CTF Privacy Collection Notice for Customer Due Diligence
This notice applies when Shine Bright collects personal information to complete customer due diligence for a designated real estate service. It should be read with the Privacy Policy above and should be provided before, or at the time, we collect AML/CTF information where reasonably practicable.
Why we need your information
We collect personal information to comply with the customer due diligence, risk-management, reporting and record-keeping requirements of the AML/CTF Act and AML/CTF Rules. This includes establishing and verifying identity, confirming authority to act, identifying beneficial owners, understanding the purpose of the service or transaction and assessing relevant money-laundering, terrorism-financing, proliferation-financing and related compliance risks.
What we collect
We may collect your full name, other names, date of birth, residential address, contact details, occupation, identity-document details and verification results. Depending on the customer and assessed risk, we may also collect information about representatives, beneficial owners, entities and trusts, the purpose of the transaction, source of funds or wealth, politically exposed person status, sanctions or adverse-media screening and other information reasonably necessary under our AML/CTF program.
How we collect and verify it
Information may be collected directly from you, your authorised representative, another reporting entity or professional adviser, public registers or government records. We use Securexchange and InfoTrack to support identity verification, customer questionnaires, screening, reliance and AML/CTF record keeping. Remote identity verification may involve document checks and, with any required consent, a photograph, selfie or liveness process.
Who we may share it with
We may disclose relevant information to Securexchange, InfoTrack, identity and screening service providers, the Document Verification Service, another reporting entity under a permitted reliance arrangement, AUSTRAC and regulators or law-enforcement bodies where required or authorised by law. We may be legally restricted from telling you about some disclosures or related information.
If you do not provide the information
If the required information is not provided or cannot be satisfactorily verified, we may be unable to start or continue the agency appointment or other designated service and may need to delay, refuse or stop providing the service.
Your privacy rights
The Privacy Policy above explains how to request access or correction and how to make a complaint. Access or complaint responses may be limited where required by AML/CTF confidentiality or tipping-off laws. Privacy enquiries may be directed to the Privacy and AML/CTF Compliance Officer using the contact details above.