1. Who We Are
This Privacy Policy describes how Cascade Apartment 4 ("we", "us", "our") collects, uses, stores and protects your personal information when you visit our website at www.cascadeskiapartments.com, make a booking enquiry, or complete a reservation for our property at Baw Baw Village, Mt Baw Baw, VIC 3833, Australia.
We are committed to handling your personal information responsibly, transparently and in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy applies to personal information we collect directly from you and through automated means when you use our website.
By using our website or making a booking with us, you consent to the collection, use and disclosure of your personal information as described in this policy. If you do not agree, please do not use the website or submit a booking.
If you have any questions or concerns about how we handle your personal information, please contact us using the details in Section 10.
2. Information We Collect
We collect personal information that is necessary to provide you with accommodation booking services and to communicate with you about your stay. The types of information we collect include:
Information you provide directly to us:
- Name: Your full name (and names of other guests in your party where provided) to identify the booking and ensure we can address you personally.
- Email address: Used to send your booking confirmation, pre-arrival information, and any follow-up communications about your stay.
- Phone number: Used to contact you about your booking or in case of urgent matters relating to your stay or the property.
- Payment information: Your card number, expiry date and security code are collected at the point of payment. This information is passed directly and securely to our payment processor, Stripe. We do not store raw card details on our own systems (see Section 4).
- Enquiry and message content: The content of any messages you send to us via contact forms, email or phone, including details of your travel requirements, group size, dates and any special requests.
- Number of guests: To verify compliance with the maximum occupancy and to tailor communications about your stay.
Information collected automatically when you visit our website:
- Browser and device information: Including the type of browser you use, your device type (desktop, tablet, mobile), and your operating system. This is used to ensure the website functions correctly on your device.
- IP address: Recorded for security and fraud-prevention purposes.
- Pages visited and session data: We may record which pages of the website you visit, how long you spend on each page, and the path you take through the site, in order to understand how guests use the website and improve its usability.
- Referral source: How you arrived at our website (for example, from a search engine or another website).
We do not collect sensitive personal information (such as health information, government identifiers or financial information beyond what is needed for payment processing) unless you voluntarily provide it to us and it is relevant to your stay.
3. How We Use Your Information
We use the personal information we collect for the following purposes:
- To process and manage your booking: Including confirming your reservation, taking payment, sending booking confirmation and receipts, and maintaining records of your stay.
- To communicate with you about your stay: Including sending pre-arrival information such as check-in instructions, oversnow transport details, and any updates relevant to your booking dates.
- To respond to your enquiries: Whether you contact us by email, phone or contact form, we use your information to respond to questions and discuss availability.
- To resolve issues and disputes: Including investigating any complaints, property damage claims, or other matters arising from your stay.
- To comply with our legal obligations: Including maintaining financial records as required by the Australian Taxation Office (ATO) and responding to lawful requests from government or law enforcement authorities.
- To improve our website and service: Aggregated, non-personally identifiable data about website usage is used to understand guest behaviour and make improvements to the booking experience.
- To contact you about future availability (optional): If you have stayed with us previously and have not opted out, we may on occasion contact you to let you know about upcoming season availability. You may opt out of these communications at any time by contacting us at hello@cascadeskiapartments.com.
We will not use your personal information for any purpose that is unrelated to the services we provide to you, unless we have your explicit consent or are required to do so by law.
4. Payment Processing
All payment transactions on our website are processed by Stripe, a world-leading payment platform certified to the highest level of the Payment Card Industry Data Security Standard (PCI-DSS Level 1). Stripe handles the secure capture, transmission and processing of your card details.
We never see, store or have access to your raw card number, CVV/security code, or full card expiry date. When you enter your payment details on our checkout page, that information is transmitted directly and securely to Stripe's servers using encrypted connections. We receive only a confirmation of payment outcome and a tokenised reference to your payment method, which is used to manage your booking record and to process any applicable refunds.
For more information about how Stripe handles your data, you can review Stripe's Privacy Policy at stripe.com/privacy.
Your card details are safe: We never store raw card numbers on our systems. Payment data is handled exclusively by Stripe, which operates to the highest industry security standards. We only retain a tokenised reference to process refunds if applicable.
5. Data Sharing
We take your privacy seriously. We do not sell, rent or trade your personal information to any third party for marketing, advertising or commercial purposes. Your information is shared only in the following limited circumstances:
- Stripe (payment processing): As described in Section 4, your payment details are shared with Stripe solely for the purpose of processing your payment and, where applicable, issuing a refund. Stripe's use of your data is governed by their own privacy policy.
- Legal and regulatory requirements: We may disclose your personal information to government authorities, law enforcement agencies, or courts if we are required to do so by law, court order, or regulatory requirement, or where we believe disclosure is necessary to protect our legal rights or the safety of any person.
- Professional advisers: In limited circumstances, your information may be shared with our accountants, lawyers or other professional advisers, solely for the purpose of obtaining professional advice related to our business operations. These parties are bound by confidentiality obligations.
We do not use third-party advertising platforms, retargeting services, or social media tracking pixels. We do not share your information with any other short-term rental platforms, marketplaces or accommodation providers.
We do not sell your data. Your personal information is used only to provide you with accommodation services and to meet our legal obligations. It is never sold or shared for advertising or marketing purposes.
6. Data Retention
We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:
- Booking records (including guest name, contact details, payment records and stay dates): Retained for 7 years from the date of the booking. This period is required to comply with the Australian Taxation Office's record-keeping requirements for business income and financial transactions.
- Enquiry records (messages, emails and contact form submissions that did not result in a booking): Retained for 2 years from the date of the enquiry, after which they are securely deleted.
- Website session data and logs: Retained for no longer than 90 days for security and troubleshooting purposes, then deleted or anonymised.
- Opt-out records: If you have asked us not to contact you for future availability, we retain a record of your opt-out request indefinitely in order to honour your preference.
When personal information is no longer required, we securely delete or de-identify it in accordance with our internal data management practices.
7. Your Rights
Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you have the following rights in relation to the personal information we hold about you:
- Right of access: You may request a copy of the personal information we hold about you. We will respond to your request within a reasonable time, typically within 30 days. There is no charge for making an access request, though in some cases a small administrative fee may apply for providing a large volume of records.
- Right of correction: If you believe that personal information we hold about you is inaccurate, out of date, incomplete or misleading, you may ask us to correct it. We will take reasonable steps to correct your information promptly.
- Right to request deletion: You may request that we delete personal information we hold about you. We will do so where we are not required by law to retain it. Please note that where information is required to be retained to comply with our legal obligations (such as ATO record-keeping), we cannot delete it during the mandatory retention period.
- Right to opt out of optional communications: If you have previously received optional communications from us (such as seasonal availability updates), you may opt out at any time by contacting us at hello@cascadeskiapartments.com.
- Right to complain: If you believe we have mishandled your personal information, you are entitled to make a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. We encourage you to contact us first so we have the opportunity to resolve any concerns directly.
To exercise any of the above rights, please contact us using the details in Section 10.
8. Cookies
Our website uses cookies — small text files stored on your browser — to support essential site functionality. We use a minimal set of cookies, described below:
- Session cookies: These temporary cookies are created when you visit the site and are automatically deleted when you close your browser. They are used to maintain your session state as you navigate between pages (for example, to retain your selected dates or booking progress). Session cookies do not contain personally identifiable information.
- Preference cookies: Where applicable, we may store a small amount of data on your browser to remember non-personal preferences (such as calendar view settings). These are not used for tracking purposes.
We do not use advertising cookies, retargeting cookies, or any form of cross-site tracking technology. We do not use Google Analytics, Facebook Pixel, or similar third-party tracking tools. Your browsing behaviour on our site is not shared with advertising networks.
You can control and delete cookies through your browser settings. Note that disabling session cookies may affect the functionality of the booking process on our website.
No ad tracking: We use only essential session cookies needed to run the website and booking system. We do not use advertising networks, analytics trackers, or any cookies that follow you across other websites.
9. Security
We take reasonable and appropriate technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, or destruction. These measures include:
- HTTPS encryption: All data transmitted between your browser and our website is encrypted using Transport Layer Security (TLS/HTTPS). Look for the padlock icon in your browser's address bar.
- Stripe PCI-DSS compliance: Payment data is handled exclusively by Stripe, which is certified to PCI-DSS Level 1 — the highest level of payment security certification available. We do not transmit or store raw card data on our own servers.
- Access controls: Access to personal information held in our booking records is restricted to the property owners and is not shared with third parties except as described in Section 5.
- Email security: We use industry-standard email providers with security features including spam filtering and encrypted storage.
While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of data transmitted over the internet. If you become aware of any security vulnerability or breach affecting our website, please notify us immediately at hello@cascadeskiapartments.com.
10. Contact for Privacy Matters
If you have any questions, concerns or requests relating to this Privacy Policy or the way we handle your personal information, please contact us using the details below. We are committed to addressing all privacy-related enquiries promptly and respectfully.
- Email: hello@cascadeskiapartments.com
- Phone: +61 3 5165 1200
- Website: www.cascadeskiapartments.com
- Property address: Baw Baw Village, Mt Baw Baw, VIC 3833, Australia
We aim to respond to all privacy enquiries within 5 business days. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page will be revised accordingly. We encourage you to review this policy periodically.
Cascade Apartment 4