Privacy Policy
Last Updated: 25 June 2026
1. Introduction
Zeogly Pty Ltd (ABN 55 625 307 431) (“we”, “us”, or “our”) operates Agents Wallet, a digital business card platform with peer QR code pass sharing and referral network tracking for real estate professionals, at agentswallet.com.au (“the Service”). This policy explains how we collect, use, disclose, and protect personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect the following categories of personal information:
- Account information: Name, email address, phone number, professional title, and agency name — collected when a real estate agency or agent registers for the Service.
- Pass holder data: The above information, plus a profile photograph (headshot) uploaded directly by the agent themselves, and the agency logo uploaded by the agency admin. Agency admins do not have the ability to upload an agent’s headshot — each agent controls their own profile image. These are displayed in Google Wallet passes issued through the Service.
- Website visitor data: Name, email address, and agency name submitted via the sign-up interest form on this website. We do not collect analytics data or use tracking cookies.
- Pass download data: When a contact scans an agent’s QR code and chooses to save their own copy of the agent’s pass, we collect their name, email address, and phone number via the pass download form. This is provided voluntarily.
- Referral data: Records of referral relationships between contacts (who referred whom), contact history, and referral status within an agent’s network.
- Advocate data: When a past client is added as an advocate or scans an agent’s referral QR code and completes the advocate referral form, we collect their name, email address, and phone number. This data is provided voluntarily and is used to create their referral profile and enrol them in the referral network.
- Communication data: Records of email and SMS messages sent to contacts via the automated review campaign feature, including delivery status. Every automated message includes a functional unsubscribe mechanism as required by the Spam Act 2003 (Cth).
2.1 Pass Download Consent
Pass download consent: Pass download data (name, email, phone number) is collected solely on the basis of voluntary, informed consent. When a contact scans an agent’s QR code, they are taken to a pass download page that explains what information will be collected and who will hold it. Providing contact details is entirely optional — the contact may leave the page without submitting anything. No data is collected from a contact who scans the QR code but does not submit the form. Only if the contact chooses to complete and submit the form is their information collected. Individuals may request removal of their information at any time by contacting us at support@zeogly.com.
2.2 Data Controller for Pass Holders
Data controller for pass holders: For contacts who scan an agent’s QR code and save their own copy of the pass, Zeogly Pty Ltd is the data controller. The subscribing agency is not the data controller for this data — Zeogly holds and is responsible for the personal information collected via the pass download form.
3. How We Use Your Information
We use the personal information we collect for the following purposes:
- To create and manage your digital business card for Google Wallet and Apple Wallet (pass).
- To respond to enquiries and service requests submitted via this website.
- To deliver dynamic pass updates — including personal messages and acknowledgements sent by agents through the platform — to passes installed on clients’ devices. These updates are delivered via Google’s and Apple’s push notification infrastructure.
- To track referral relationships within your agency network and provide CRM functionality.
- To send automated review request and lead-nurture communications, where consent has been given or is implied by the nature of the prior relationship.
- To maintain the security and integrity of the Service.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Lawful basis for processing: We process personal information on one of the following bases: (a) to fulfil our contractual obligations to you (account management, service delivery); (b) with your explicit consent (marketing communications, pass download forms); or (c) where permitted by applicable law based on an existing business relationship. We process information for legal compliance where required by law.
4. Google Wallet Pass Data
Agents Wallet issues Generic passes (digital business card type) via the Google Wallet API. The Service creates and manages these digital passes through the Google Wallet API.
The visible pass displays the agent’s name, professional title, phone number, email address, and the agency’s name and logo only — no Agents Wallet or Zeogly branding appears on the pass face. Agents Wallet acts as the API credential holder on behalf of the subscribing agency.
The following information is transmitted to Google to render your pass and make it available in Google Wallet:
- Your name, professional title, agency name, phone number, and email address.
- Your profile photograph (headshot image) as uploaded to the Service.
- Your agency’s logo image as configured in the agency admin portal.
- A unique QR code for pass sharing.
- Any dynamic messages or personal acknowledgements you choose to send through the platform.
This information is transmitted to Google via the Google Wallet API and is stored on Google’s infrastructure. Google’s handling of this data is governed by Google’s Privacy Policy and the Google Wallet API Terms of Service.
Pass deletion webhook: When a pass holder removes a pass from their Google Wallet, Google notifies us via a pass deletion webhook. We update our records accordingly so that the pass holder is no longer included in any active campaigns.
Pass interaction data received from Google (such as a pass holder adding or removing a pass from their device) is used solely to maintain pass status records. It does not trigger any outbound communications.
Agents Wallet passes are informational only. We do not store or transmit payment card information. No financial data is held within a pass.
4.1 Apple Wallet (PassKit)
Agents Wallet issues Apple Wallet passes via Apple PassKit, alongside Google Wallet Generic passes. The same pass holder information described above (name, professional title, agency name, phone number, email address, headshot, agency logo, and QR code) is transmitted to Apple’s infrastructure to render and deliver the pass. This data is governed by Apple’s Privacy Policy and delivered to devices via Apple’s push notification service (APNs).
5. Third-Party Services
We use the following third-party services to operate the Agents Wallet platform:
- Google Wallet API — for digital pass generation, delivery, and updates. Data transmitted includes pass holder information as described in Section 4.
- Supabase — cloud database, authentication, and file storage service. Your account data and pass records are stored in a Supabase-managed PostgreSQL database. Agent profile photographs and agency logo images are stored in Supabase Storage. Supabase stores data in the United States (AWS us-east-1 region) unless a specific regional configuration is applied. Supabase’s privacy policy is available at supabase.com/privacy.
- Resend — transactional email delivery service used to send service notifications and pass download confirmation emails. Email content includes the recipient’s name and the relevant agent’s contact details. Resend’s privacy policy is available at resend.com/privacy.
- Stripe — payment processing for Agents Wallet subscriptions. Billing data (card details, transaction records) is handled entirely by Stripe and is not stored on our systems. See stripe.com/privacy.
- Apple PassKit (Apple Wallet) — for digital pass generation, delivery, and updates on iPhone. Data transmitted includes pass holder information as described in Section 4.1.
Each third-party service has its own privacy policy governing how it handles personal information. We encourage you to review those policies.
6. Data Retention
We retain your personal information for as long as your account is active or as necessary to provide the Service. If you request account deletion, we will remove your personal information within 30 days, except where retention is required by applicable law (for example, financial records required for tax compliance).
Usage data may be retained in de-identified or aggregated form for service improvement purposes after account deletion.
- Agents Wallet pass-holder data (name, email, and phone number voluntarily submitted via the QR code download form): retained for the life of the subscribing agency’s active subscription. Upon cancellation or account closure, pass-holder data associated with that agency is removed within 30 days.
7. Your Rights
Pass holders (contacts who scanned an agent’s QR code and saved a pass): Your name, email address, and phone number are held only because you voluntarily submitted them via the pass download form. You may request removal of this information at any time by emailing support@zeogly.com with the subject line “Data Deletion Request”. Removal takes effect within 30 days and causes the associated pass to be expired.
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Request deletion of your personal information, subject to legal retention obligations (see Section 6).
- Withdraw consent for marketing communications at any time, without affecting the lawfulness of processing based on consent before withdrawal.
- Complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have mishandled your personal information.
How to request deletion of your personal information:
Email support@zeogly.com with the subject line “Data Deletion Request”. Please include: (1) your full name, (2) the email address associated with your account or the communications you received. We will acknowledge your request within 5 business days and complete the deletion within 30 days, except where retention is required by applicable law. We will confirm in writing once deletion is complete.
8. Security
We implement technical and organisational measures to protect your personal information from unauthorised access, disclosure, or misuse. These include encrypted data storage and token-based authentication.
Agents Wallet passes use a single-use installation link generated per QR scan. Each time a contact scans an agent’s QR code, a unique installation link is created that can only be used once. Once the pass has been saved to a device, the installation link is invalidated and cannot be forwarded or reused, preventing unauthorised copies of the pass from being installed by others.
No method of transmission over the internet is completely secure. We cannot guarantee absolute security, but we take reasonable steps consistent with industry best practice to protect your data.
Notifiable Data Breaches: We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we experience an eligible data breach — one that is likely to result in serious harm to one or more affected individuals — we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
9. Cookies
We do not use analytics or advertising cookies. We use Google reCAPTCHA on our contact form, which may set cookies as part of its fraud-detection operation.
10. Cross-Border Data Transfers
Some of the third-party services we use (including Supabase and Resend) process or store personal information outside Australia, including in the United States. Supabase stores data in the United States (AWS us-east-1 region). Where cross-border transfers occur, we take reasonable steps to ensure your personal information is handled consistently with the Australian Privacy Principles.
11. Children’s Privacy
The Service is not directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will take steps to delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. We will notify existing users of material changes by email. The current policy is always available at agentswallet.com.au/privacy-policy. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
13. Contact
For all privacy-related queries, access requests, and complaints:
- Email: support@zeogly.com
- Phone: +61 434 929 211
- Company: Zeogly Pty Ltd ABN 55 625 307 431
- Location: 1 Ruth Bedford Street, Franklin ACT 2913, Australia
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.