Privacy Policy
What Cars61 collects, why we collect it, who we share it with, and how to reach us about it.
Cars61 is an Australian online vehicle marketplace. This policy explains what personal information we collect, why we collect it, who we disclose it to, and how you can access or correct it. It applies to cars61.com.au and to every account, listing and enquiry on it.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
This policy was last updated on 8 September 2026.
Information you give us
- Account details: your first name, last name, email address, and your phone number if you provide one. Your password is stored only as a salted PBKDF2-HMAC-SHA256 hash, never as the password itself.
- Dealer applications: your business name, ABN, motor dealer licence number, state, suburb, postcode, business phone, website and business description.
- Listings: the registration plate and state, VIN, specifications, price, description, photos, and the suburb, state and postcode the vehicle is located in.
- Enquiries and messages: the name, email address, optional phone number and message you send to a seller, and every message in the conversation that follows. You can send an enquiry as a guest, without an account.
- Saved items: vehicles you save, searches you save and the alert frequency you choose, and the vehicles in your comparison tray.
- Reports and support requests: the listing you reported, the reason you chose, and any details you add.
Information we collect automatically
- Usage events: listing views, searches, enquiries sent, favourites added and removed, listings shared, phone numbers revealed, listings submitted and published, and reports submitted. Each event is stored with a keyed SHA-256 hash of your IP address, not the address itself.
- Sign-in attempts: the email address used, whether the attempt succeeded, a short failure reason, and the IP address it came from. We keep these to detect credential stuffing and to lock an account after repeated failures.
- Administrative actions: when a staff member approves a listing, changes an account or edits a page, we record who did it, what changed, when, and the IP address it came from.
- Standard server logs generated by our hosting provider.
Cookies
We use a small number of cookies. None of them are used to build an advertising profile of you.
- CarMarketplace.Auth is your signed-in session. It is HttpOnly, SameSite=Lax, sent only over HTTPS, and expires eight hours after you sign in. It does not extend as you browse.
- CarMarketplace.Mfa and CarMarketplace.PendingVerification are short-lived, and exist only while you are completing a two-factor or email verification step.
- CarMarketplace.Compare is an opaque identifier that keeps your comparison tray between page loads. It works whether or not you are signed in.
We also load Google Tag Manager on the public site to measure how the marketplace is used. Before a page address reaches it we strip any registration plate, VIN, email address, token, code, key, secret, password or redirect address from the query string and replace it with the word "redacted". Tag Manager is never loaded on the administration area, the media routes, or our API and health endpoints, so other people's accounts, enquiries and vehicle reports are never exposed to it.
Photos
Every photo you upload is decoded and re-encoded into a fresh WebP image before it is stored. All embedded metadata, including EXIF, GPS coordinates, IPTC, XMP and colour profiles, is discarded in the process, and the original file is never stored or served. Photos are held in a private storage bucket and are only ever delivered through a route that checks you are allowed to see them.
Your contact details
Your email address is never published on a listing, and a private seller's phone number is never published either. Enquiries are routed through Cars61 using a masked alias for each conversation, so neither party has to hand the other a direct address.
Approved dealerships are different. The business name, suburb, state, business phone number and website on a dealership profile are published, because a dealer trades publicly.
Vehicle checks and registration data
When you or a member of our team runs a vehicle check, we send the registration plate and jurisdiction, or the VIN, to MotorWeb, our vehicle data provider, over an authenticated connection. MotorWeb returns registration and description details, PPSR security interest results, written-off and stolen status, market valuation, insurance claims history and listing history.
We store the provider's response so the same check does not have to be re-run repeatedly, and so it is possible to show later what a check actually said at the time. A vehicle report is reused for 24 hours before it is refreshed. A registration snapshot taken while a listing is being created is treated as authoritative for 30 days.
These records describe a vehicle rather than a person, but a plate or VIN can be linked back to you, so we treat them as personal information.
Who we share information with
- Supabase, our hosting and database provider, which stores the database, the listing photos and the realtime channel that delivers chat messages.
- The email provider configured for the site, which delivers verification emails, password resets, security codes, enquiry notifications and alerts.
- MotorWeb, for the vehicle checks described above.
- Google, through Google Tag Manager, for the measurement described above.
We do not sell your personal information, and we do not disclose it for another organisation's marketing.
We will disclose information where we are required or authorised by law, or where it is reasonably necessary to investigate fraud, a serious safety concern, or a breach of our terms.
Some of these providers may store or process information outside Australia.
How long we keep it
- Your account, and the listings, saved items and preferences attached to it, are kept until the account is closed.
- Enquiries and their conversations are kept as a record of the exchange. When an account is deleted the enquiries and messages remain but are no longer linked to it, because they also belong to the other party in the conversation.
- Sign-in attempts and administrative audit records are kept as a security and accountability trail, and survive deletion of the account that created them.
- Password reset links expire after 30 minutes, email verification links after 24 hours, and two-factor and phone codes after 10 minutes. Each is stored as a one-time hash and cannot be used twice.
- Vehicle reports and registration snapshots are retained as a compliance record after their reuse window has passed.
How we protect it
- Passwords are stored as salted PBKDF2-HMAC-SHA256 hashes, and are re-hashed with stronger parameters when you next sign in.
- Every one-time token, whether a password reset, an email verification or a two-factor code, is stored as a hash and never in usable form.
- Credentials we hold for our email and vehicle data providers are encrypted at rest with AES-256-GCM.
- Your session is bound to an authentication version, so a password change or a staff suspension signs you out everywhere on the next request.
- Repeated failed sign-ins lock the account temporarily.
- Two-factor authentication is available on your account, with the code delivered to your email address.
- Listing photos are held in a private bucket and served only through an authorising route.
- The administration area is excluded from all third-party tags.
No system is perfectly secure, but these are the controls we operate.
Your choices
- You can turn individual email and in-app notification categories on and off in your notification preferences.
- You can change or delete a saved search, or set it never to alert you.
- You can enable two-factor authentication on your account.
- You can block Google Tag Manager in your browser. The site works without it.
- Providing a phone number is optional on a personal account.
Accessing, correcting or deleting your information
You can view and correct most of your details from your profile, your listings and your dealer profile.
To ask for a copy of the personal information we hold about you, to have something corrected, or to have your account closed, contact us using the details below. We will ask you to verify your identity before we act on the request, and we will respond within 30 days. Where we have to keep something, such as a security record or an enquiry that also belongs to the other party, we will tell you what we kept and why.
Complaints
If you believe we have mishandled your personal information, contact us first and we will investigate. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or on 1300 363 992.
Changes to this policy
We will update this page whenever our handling of personal information changes, and the date near the top will change with it. Continuing to use Cars61 after a change means you accept the updated policy.
Contact us
Email info@cars61.com.au, or use the Contact us page. Please put "Privacy" in the subject line so it reaches the right person.
