Spaces By

Privacy Policy

Issued by Recursive Holdings Pty Ltd
Effective date May 2026
Version 1.0
Your privacy matters. This Privacy Policy explains how Recursive Holdings Pty Ltd (ACN 696 188 128) collects, uses, stores, and discloses your personal information when you use the Spaces By platform. We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Section 1

About Us

Recursive Holdings Pty Ltd (ACN 696 188 128) ("Company", "we", "us", "our") operates the Spaces By platform at spacesby.com.au ("Platform"). Spaces By is a design and fulfilment service for home renovation projects.

We are an Australian Privacy Act entity. If you have any questions about this policy or our privacy practices, please contact us using the details in Section 13.

Section 2

What Personal Information We Collect

We collect personal information that is reasonably necessary to provide the Platform and associated services. This includes:

  1. Identity and contact information: your name, email address and postcode;
  2. Account information: login credentials and authentication data, including data received when you sign in via Google OAuth (name, email address and profile picture);
  3. Project information: the postcode of the property subject to renovation, room measurements and layout details, design preferences (style, colours, materials), appliance selections, and budget information;
  4. Payment and transaction information: records of quotes, project agreements, and payment processing data. Note: full payment card details are processed by our third-party payment processor and are not stored on our systems;
  5. Technical and usage information: IP address, browser type, device type, pages visited, session duration, and interaction logs, collected automatically when you use the Platform;
  6. Communications: any messages, feedback, or enquiries you send to us.

Where practicable, we will tell you at the point of collection why we are collecting particular information and how it will be used.

Section 3

How We Collect Personal Information

We collect personal information in the following ways:

  1. Directly from you when you register an account, complete a project intake form, submit an enquiry, or communicate with us;
  2. Via Google OAuth when you choose to sign in using your Google account, in which case Google shares certain profile information with us as described in Section 2(b);
  3. Automatically through cookies, server logs, and analytics tools as you interact with the Platform;
  4. From third parties such as our manufacturing partners or tradespeople, where relevant to coordinating your renovation project;
  5. Via Google reCAPTCHA, which collects behavioural data (including mouse movements, browser fingerprint, and interaction patterns) to detect automated abuse. This data is processed by Google in accordance with Google's Privacy Policy.

You are not obliged to provide personal information to us, but if you choose not to, we may be unable to provide you with access to the Platform or deliver renovation services.

The Platform is not directed at children under the age of 18. We do not knowingly collect personal information from persons under 18 years of age.

Section 4

Anonymity and Pseudonymity

Where lawful and practicable, we offer you the option of interacting with us anonymously or under a pseudonym. You may browse publicly available areas of the Spaces By website without identifying yourself.

However, to create an account, initiate a renovation project, or engage our managed partner network, we require you to provide accurate identifying information. Anonymous or pseudonymous use is not practicable for these core services.

Section 5

Why We Collect and Use Your Personal Information

We collect, hold, use, and disclose your personal information for the following primary purposes:

  1. To create and manage your account and verify your identity;
  2. To design, quote, and coordinate your project;
  3. To facilitate transactions between you and our supplier partners;
  4. To communicate with you about your project, including updates, quotes, scheduling, and completion;
  5. To improve the Platform, including by analysing usage patterns and testing new features;
  6. To send you service-related communications and, where you have opted in, marketing communications about Spaces By products and services;
  7. To comply with our legal obligations, resolve disputes, and enforce our terms;
  8. To detect and prevent fraud, abuse, or unauthorised access.

We will not use or disclose your personal information for a purpose other than those listed above (or a directly related purpose) without your consent, unless required or authorised by law.

Section 6

Disclosure of Personal Information

We may disclose your personal information to the following categories of recipients:

  1. Manufacturing partners and tradespeople engaged to quote or fulfil your renovation project — limited to the information necessary to complete the relevant work (e.g. project address, specifications, and scheduling details);
  2. Cloud infrastructure providers — your data is hosted on Amazon Web Services (AWS) infrastructure located in Australia. Access is protected by Cloudflare Zero Trust;
  3. Google LLC — for authentication (OAuth), bot detection (reCAPTCHA), and font delivery services;
  4. Stability AI — style preference data and design parameters may be transmitted to Stability AI's image generation API to produce visual previews of your renovation design. Stability AI is based in the United States;
  5. Anthropic PBC — project description data may be processed by Anthropic's AI API to assist with design recommendations and platform features. Anthropic is based in the United States;
  6. Payment processors — payment transaction data is processed by our third-party payment provider in accordance with their privacy policy;
  7. Professional advisors — lawyers, accountants, and auditors, under obligations of confidentiality;
  8. Regulatory authorities — where required by law, court order, or regulatory requirement.

We do not sell your personal information to third parties.

Section 7

Overseas Disclosure

As described in Section 6, some of our third-party service providers are located outside Australia, principally in the United States. These providers include Stability AI, Anthropic, Google, and Cloudflare.

Where we disclose personal information to overseas recipients, we take reasonable steps to ensure those recipients handle your information in a manner consistent with the Australian Privacy Principles, including by:

  1. Relying on contractual data processing agreements (DPAs) where available (including with Google and Cloudflare); and
  2. Selecting providers that maintain internationally recognised privacy and security certifications.

For AI services (Stability AI and Anthropic), where comprehensive contractual APP-equivalent protections may not be available, we seek your consent to overseas disclosure at the time of account registration. By creating an account and using the AI-powered features of the Platform, you acknowledge that your design preference data may be transmitted to these overseas providers and that the Australian Privacy Principles may not apply to that handling.

You may opt out of AI-generated image previews by contacting us. This will not affect your ability to use other Platform features.

Section 8

Direct Marketing

We may use your contact details to send you information about Spaces By services, renovation tips, and promotional offers where you have opted in to receive such communications, or where we are otherwise permitted to do so under applicable law.

You may opt out of marketing communications at any time by:

  1. Clicking the unsubscribe link in any marketing email we send you; or
  2. Contacting us directly using the details in Section 13.

Opting out of marketing communications will not affect the delivery of transactional communications related to your active renovation project.

Section 9

Cookies and Tracking Technologies

The Platform uses cookies and similar technologies to operate session authentication, remember your preferences, and analyse Platform usage. The types of cookies we use include:

  1. Essential cookies: required for the Platform to function, including session management and security (e.g. Cloudflare security cookies);
  2. Analytics cookies: used to understand how visitors interact with the Platform so we can improve it;
  3. Third-party cookies: set by Google for reCAPTCHA and OAuth services.

You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using core Platform features.

Section 10

Security of Personal Information

We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and from unauthorised access, modification, or disclosure. Our security measures include:

  1. Encryption of data in transit via HTTPS/TLS across all Platform connections;
  2. Server-side storage of credentials and API keys in secured environment files with restricted access permissions;
  3. Session-based authentication with server-side session management;
  4. Access to the administration environment restricted via Cloudflare Zero Trust (email one-time password verification) and WireGuard VPN;
  5. Role-based access controls limiting staff and partner access to information necessary for their function;
  6. AWS infrastructure security controls including security group rules and IAM access policies.

If you believe your account has been compromised or you become aware of a privacy or security concern, please contact us immediately using the details in Section 13.

In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.

Section 11

Retention of Personal Information

We retain personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by law. As a general guide:

  1. Active accounts: retained for the duration of your account and ongoing relationship with us;
  2. Completed project records: retained for a minimum of seven years following project completion to satisfy our legal, warranty, and tax obligations;
  3. Marketing opt-in records: retained until you withdraw consent;
  4. Technical logs: retained for a period of up to 90 days for security and diagnostic purposes.

When personal information is no longer required, we will take reasonable steps to destroy it or ensure it is de-identified.

Section 12

Access and Correction

You have the right to request access to the personal information we hold about you, and to request that we correct any information that is inaccurate, out of date, incomplete, irrelevant, or misleading.

To make an access or correction request, please contact us using the details in Section 13. We will respond within a reasonable time and, in any event, within 30 days of receiving your request.

We may decline an access request in circumstances permitted by the Privacy Act (for example, where providing access would be unlawful, or would unreasonably impact the privacy of another individual). If we decline your request, we will provide written reasons.

We do not charge a fee for making an access or correction request. However, in some circumstances we may charge a reasonable cost-recovery fee for providing access (for example, where a request requires substantial retrieval work). We will notify you of any such fee before processing your request.


Section 13

Complaints

If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, we encourage you to contact us first so that we can attempt to resolve your concern.

Please direct your complaint in writing to:

Privacy Officer
Recursive Holdings Pty Ltd
hello@spacesby.com.au

We will acknowledge your complaint within 5 business days and aim to respond substantively within 30 days. If you are not satisfied with our response, or if we fail to respond within a reasonable time, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

oaic.gov.au/privacy/privacy-complaints
Phone: 1300 363 992

Section 14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The current version will always be available at spacesby.com.au/privacy.

Where we make a material change, we will notify you by email or by a prominent notice on the Platform prior to the change taking effect.

Your continued use of the Platform after any update constitutes acceptance of the revised policy.

Contact

Get in Touch

For any privacy-related enquiries, access or correction requests, or complaints, please contact:

Recursive Holdings Pty Ltd (ACN 696 188 128)
hello@spacesby.com.au
spacesby.com.au