Privacy Policy
Last updated 5 September 2026.
This policy explains what TonkaTuff Pty Ltd (ABN 86 104 471 052), trading as ReelView, does with personal information. It forms part of our Terms of Service. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
What we collect
- Account and organisation details: your email address and a password, stored hashed, which we cannot read. Your name, and, if you add them, your professional title, mobile number, profile link and headshot. For an organisation: its name, logo, office details, accounts contact, postal address and website. Some of this reaches us from an agency administrator rather than from you.
- Your work: the photographs you upload, the property address and the scene instructions and settings you choose. Where you import a listing by URL, the property details extracted from the page you name.
- Payment records: a ledger of credits purchased and used, and the transaction records the payment provider returns to us. Card details are handled by Stripe and never reach us.
- Review and account-activity records: your approval records, which hold the property address, the organisation, the decision, when it was made and the reasons displayed at the time; and the account-activity and notice records we use to run section 14.4 of the Terms, which include when an account was last used while signed in and when a dormancy warning was sent. These are kept separately from the job so they survive deleting one, and your approval records can be downloaded from Your account at any time. They contain no photographs.
- Support and technical information: enquiries and support messages you send us, and the ordinary records a web service keeps (IP address, browser type, timestamps, error traces), used to keep the Service secure and working.
Technical logs are kept for 90 days. That figure covers technical logs only. Account activity, notice records and approval records are kept for the periods in “How long we keep it”.
We do not use tracking or advertising cookies. The only cookie we set when you sign in to your account keeps you logged in. That statement is about cookies we set, and is not a description of every third-party component a page loads. See “Fonts and other page components”.
Fonts and other page components
Our pages request fonts from Google Fonts. This gives Google your IP address and technical request information, such as your browser and referrer headers. Google Fonts does not set or log cookies for these font requests.
Other people in your photographs
Your photographs often contain someone else's personal information: an occupant's possessions, family photographs on a wall, mail on a bench, a car and its plate. Sometimes people themselves.
Please do not upload photographs containing people, identifying documents or other information the walkthrough does not need. Where they do contain someone's personal information, you are the one who has to tell that person (the owner, occupant or tenant) what happens to it, including that it may be processed overseas. The list below is written so you can pass it on.
At upload, we provide a short notice template you can give to an owner, occupant or tenant. It summarises the processing, overseas recipients and public-share-link model. It is a convenience, not legal advice, and does not replace any notice or consent required in your circumstances.
If you are that person and you think your information is in a walkthrough, email support@reelview.com.au and we will help.
Why we collect it
To create your account, produce the walkthroughs you ask for, check their quality, let you make changes, host your share pages, take payment and issue tax invoices, provide support, investigate faults and abuse, keep the Service secure, and meet our legal obligations. Nothing else.
We do not sell your data or use it for advertising.
We may use aggregated, de-identified operating statistics (for example, how often a camera move fails) that identify no person and no space.
Who else sees it
Producing a walkthrough requires sending your photographs to the services that generate and check the video.
| Provider | What it receives | Where it processes | Why |
|---|---|---|---|
| kie.ai | Your photographs and the scene instructions | Not disclosed by the provider. Their documentation does not identify the countries in which they or their upstream video vendors process submitted files | Video generation |
| OpenRouter | Your photographs, scene plans and generated clip frames, and the text of a listing page you import | United States | Vision analysis, quality review and listing-text extraction, under the zero-data-retention controls described below |
| OpenRouter | Your photographs and the scene instructions | United States | Video generation reserve, used when kie.ai is unavailable. The zero-data-retention controls above do not apply to this route. |
| OpenAI | Your photographs, scene plans and generated clip frames | United States | An eligible vision-processing endpoint selected by OpenRouter; also our direct reserve vision route when OpenRouter is unavailable, under the account controls described below |
| Google Fonts | Your IP address and technical request information when a page loads | United States and elsewhere | Serving the fonts our pages use. No cookies are set or logged for these requests |
| Microsoft Azure | Your photographs, scene plans and generated clip frames | United States or European Union | An eligible vision-processing endpoint selected by OpenRouter |
| Amazon Bedrock | Your photographs, scene plans and generated clip frames | United States | An eligible vision-processing endpoint selected by OpenRouter |
| Stripe | Your email and payment details (not your photographs) | United States and Australia | Payments |
| BinaryLane | Everything we store | Australia | Hosting and file storage |
| Synergy Wholesale | Your email address and the message | Australia | Account, warning and support emails |
| Our own backup hardware | Your photographs, outputs and job records | Australia | Nightly backup, so a fault cannot take your work with it |
| Our own offsite storage | Your photographs, outputs and job records | Australia | A second backup copy, kept away from the first |
Private vision processing. For vision analysis, quality review and listing-text extraction sent through OpenRouter, we configure each request to use only endpoints that OpenRouter identifies as not collecting user data and as zero-data-retention. If no endpoint meets both conditions, that request fails rather than being sent to a less restrictive provider.
These controls apply to the vision path only. Video generation does not use them. Video is normally generated by kie.ai. If kie.ai is unavailable, some scenes may instead be generated through OpenRouter's video service, which carries your photographs and the scene instructions and is not covered by the zero-data-retention configuration described above.
Direct OpenAI reserve route. If OpenRouter itself is unavailable, a vision request may be sent directly to OpenAI instead. Requests sent through the API are not used to train OpenAI's models. OpenAI may retain the request for up to 30 days for abuse monitoring under its own policy, and for longer only where the law requires it.
Photographs are scanned on submission. OpenAI scans image inputs for child sexual abuse material when they are received. If its classifier flags an image, that image is retained for manual review. This applies to every route through OpenAI, including the zero-data-retention endpoints described above.
Importing a listing by URL. If you use the listing-import feature, we fetch the page you name and send its text to the same OpenRouter vision path, under the same controls described above. We do not keep a copy of the page. We request property fields such as the address and room counts, not separate fields for a person's name, email address or phone number. Automated extraction can still put unwanted information in a text field, so check the imported details before proceeding.
The last two rows are backup, not processing: nothing is read from them to run the Service. They are listed because your photographs are copied to them, and you are entitled to know where your client’s and occupants’ information goes. Both are hardware we own and both are in Australia, so backing up your work sends it to no one else and takes it nowhere else.
We also disclose personal information where the law requires it, and to professional advisers or an acquirer if the business is sold, in which case this policy continues to apply until you are told otherwise.
Overseas processing
These providers process data outside Australia. We tell you before upload which providers may be involved and where they process data. For the OpenRouter vision path, we use the technical controls described above and provider arrangements appropriate to the circumstances to protect personal information; the direct OpenAI reserve route relies on the account-level data-retention and sharing controls described above. Those controls do not override overseas law or guarantee that Australian privacy rights can be enforced outside Australia.
That protection is not absolute: an overseas provider is also subject to the laws of its own country, and enforcing Australian privacy rights overseas can be difficult. If you cannot accept overseas processing for a particular space, do not upload it; there is no local-only mode.
Because your uploads usually include information about your client or the occupants, please pass this section on to them (see “Other people in your photographs”).
Share pages are public by design
A share page can be opened by anyone who has its link. That is the point: you send it to a client. A link that is forwarded works for whoever receives it. Do not put confidential information in a walkthrough, and treat the link as public once you send it.
How long we keep it
We keep your photographs and walkthroughs for as long as your account is open. We do not delete them on a timer, for a practical reason: your photographs are what a scene is re-rendered from, so deleting them would take away your ability to ask for changes to an older walkthrough, and would break the share links you have already sent to clients.
You stay in control of that. Delete a job whenever you want it gone, or ask us to close your account and remove everything. Deleting it removes the job from the live Service straight away, and its share link stops working.
Our suppliers keep their own copies for a while. Deleting a job removes it from ReelView, and that is separate from how long the services that generated it hold what we sent. For our video provider, generated clips are deleted after 14 days and the task records, which include the instructions we sent, after two months. Uploaded source files are held temporarily; the provider's own documentation gives conflicting periods, so we state the longer of them. There is no self-service deletion for these copies, and we would have to ask the provider directly.
Backups take longer to catch up. We keep several layers of backup so a fault or an attack cannot take your work with it. Deleted content persists in some of them for a while after it is gone from the Service: whole-server snapshots for three days and database copies for fourteen. The nightly offsite copy mirrors deletions, so a deleted job is gone from it within a day. Nothing in those backups is used to serve the Service; they exist to restore it.
Transaction records are kept for at least five years, as tax law requires. They contain no photographs. Your review record is kept for 7 years so it remains available to you if a walkthrough is ever questioned.
Support enquiries and complaint records are kept for seven years. That includes the messages you send us, our replies, and the record of how a complaint was handled.
Dormant accounts. We do not hold photography we no longer need. An agency account is eligible for deletion only if it has no credits left and none of its users has used the Service while signed in for 90 days. We do not delete an agency's work because the person who created it has gone quiet or left.
We email each agency administrator three times first, about 30, 7 and 1 day before the proposed deletion date, and we do not delete until all three have been sent and a day has passed since the last one. Any signed-in use by anyone at the agency stops it and resets the clock: opening a walkthrough counts, not just logging in. An account with credits on it is never deleted this way, however long it sits: your credits do not expire.
Security
Traffic is encrypted in transit. Passwords are hashed. Access to a job's files is restricted to authenticated users authorised for the job's owner: normally users in the agency account that owns the job. Older jobs that are not assigned to an agency remain restricted to their original creator. A share page is deliberately public so you can send it to a client, and is therefore accessible to anyone holding that link. Our own staff access to customer files is limited to what support and fault investigation require.
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and tell you what to do about it.
Your rights
You may ask us to:
- give you a copy of the personal information we hold about you, including your photographs and videos;
- correct anything inaccurate or out of date;
- delete a job, or close your account and remove its contents;
- explain a decision the Service made, including why something was refused.
Email support@reelview.com.au. We will verify who you are and respond within 30 days. If we refuse a request, we will tell you why in writing.
We do not charge for making an access or correction request, for correcting personal information, or for adding a statement recording a disputed correction. Access is normally free. If an unusually large access request would involve a charge, we will explain the reasonable cost of providing access before proceeding. We will charge only where the law permits, and the charge will not be excessive.
Closing an agency account removes its photographs and videos and stops its share links. Removing an individual user does not by itself delete jobs, photographs or walkthroughs owned by their agency, see section 14.3 of the Terms. Transaction records are retained where tax law requires.
Complaints
If you think we have mishandled personal information, email support@reelview.com.au with “Privacy complaint” in the subject. We will acknowledge within five business days and respond within 30 days.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, GPO Box 5288 Sydney NSW 2001.
Changes to this policy
We may update this policy. We will post the new version and change the “Last updated” date. If a change materially affects how we handle your information, we will email the address on your account before it takes effect.
Contact
TonkaTuff Pty Ltd · ABN 86 104 471 052, trading as ReelView
Business address: 62 Payne Street, Auchenflower QLD 4066
Telephone: 0410 692 691
support@reelview.com.au