CB
CloudBookMod
Client Area Client

Shop

  • Catalog
  • Modules
  • Pricing
  • Integrations
  • Compare
  • ROI calculator

Learn

  • Blog
  • Guides
  • Academy
  • FAQ
  • Changelog
  • API

Company

  • About
  • Contact
  • Support
  • Security
Ready to plug into NewBook Cloud? Browse the shop
Home / Privacy Policy

Privacy Policy

Effective from: 11 August 2026. This Privacy Policy explains how CloudBookModMod Pty Ltd collects, uses, holds, discloses and protects personal information in connection with the operation of the online shop at cloudbookmod.org and the modules, extensions and integrations distributed through it. It is drafted to comply with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.

1. Who we are

The entity responsible for the handling of your personal information is CloudBookModMod Pty Ltd, a proprietary company limited by shares incorporated in Australia, ABN 82 743 951 268, ACN 743 951 268, with its registered office at 156 Collins Street, Level 12, Melbourne VIC 3000, Australia. Our director is Sarah Mitchell. You can contact us at any time by writing to support@cloudbookmod.org or by telephoning +61 3 9642 7853 during ordinary business hours in Melbourne, Australia.

For the purposes of the Privacy Act 1988 (Cth), CloudBookModMod Pty Ltd is an APP entity. Where we handle personal information belonging to guests of a customer property that is transmitted through our modules from a customer's NewBook Cloud account, we act as a service provider to that customer and process such information under the terms of our Data Processing Agreement.

2. Independence and non-affiliation

CloudBookMod is an independent third-party shop of modules, extensions and integrations designed to work with the NewBook Cloud property management system. CloudBookMod is not affiliated with, sponsored by, endorsed by, associated with or otherwise connected to NewBook Pty Ltd or its parent company. All references to NewBook Cloud in this policy describe purely technical interoperation between our modules and the NewBook Cloud application programming interface as exposed to authorised customers of NewBook Pty Ltd.

3. The kinds of personal information we collect and hold

We only collect personal information that is reasonably necessary for one or more of our functions or activities, as required by APP 3. The categories we may collect are:

  • Identity and business contact information: your first and last name, business email address, position or role at the property, the legal and trading name of your organisation, its postal address, and, where you choose to supply them, your direct telephone number and ABN.
  • Account information: a unique account identifier we generate for you, magic-link sign-in tokens, session identifiers, CSRF tokens and, for security auditing, the date, time and internet protocol address of each successful and failed sign-in attempt to the Client Area.
  • Billing information: your order history, invoice numbers, amounts invoiced in Australian dollars, the goods and services tax applied, the payment method type (card, PayID, direct debit) and a tokenised reference issued by our payment processor. We never store your full card number, its expiry date, its card verification value or your bank account number.
  • NewBook Cloud application programming interface credentials: the API key or token you provide when activating a module. Such credentials are stored encrypted at rest and decrypted only in volatile memory at the exact moment they are required to authenticate an outbound request to NewBook Cloud.
  • Module usage logs: for each active module, the timestamp of each API call, the endpoint invoked, the HTTP response code, the duration of the call and, where applicable, an anonymised error identifier suitable for support diagnostics.
  • Cookie and technical information: your internet protocol address, user-agent string, browser type and version, operating system, referring uniform resource locator, pages visited on our site, session duration and language preference.
  • Support correspondence: the content and attachments of any communication you send to our support address, together with our replies.

We do not knowingly collect sensitive information within the meaning of section 6 of the Privacy Act 1988 (Cth). We do not solicit or collect government-related identifiers such as tax file numbers, Medicare numbers or driver licence numbers for our own account holders. Guest data flowing through a customer's modules may include such categories, in which case CloudBookMod acts as a service provider to the customer under a separate Data Processing Agreement.

4. How we collect personal information

We collect personal information directly from you whenever you place an order in our shop, sign in to the Client Area, activate or configure a module, contact our support team or subscribe to service notices. We collect technical and cookie information automatically from your browser through server logs and first-party analytics. Where you connect a module to a customer's NewBook Cloud account, we collect the applicable API credentials directly from you at the moment of activation. We do not purchase personal information from data brokers and we do not collect personal information from third-party sources without your knowledge.

5. Why we collect, hold, use and disclose personal information

The purposes for which we handle personal information, and the lawful basis under the Australian Privacy Principles that supports each purpose, are summarised in the table below.

PurposeCategories of personal informationBasis under the APPs
Supplying modules and operating the Client AreaIdentity, account, usage logs, API credentialsAPP 3 — reasonably necessary for our functions
Invoicing and collection of subscription and one-off feesBilling informationAPP 3 and APP 6 — primary purpose of collection
Statutory record keeping for taxation and corporate lawBilling informationAPP 6.2(b) — use or disclosure required by law
Fraud detection and security monitoringSession logs, technical informationAPP 6.2(a) — related secondary purpose reasonably expected
Service emails (order confirmations, invoices, incident notices, security alerts)Contact informationAPP 3 — primary purpose of collection
Direct marketing (product announcements, changelog digests)Contact informationAPP 7 — opt-in consent, opt-out on every message
Aggregated product analyticsPseudonymised usage dataAPP 6.2(a) — related secondary purpose reasonably expected

We notify you of the matters set out in APP 5 at or before the time we collect your personal information through this policy, through the order confirmation email and through contextual notices in the Client Area.

6. Who we disclose personal information to

We disclose personal information strictly on a need-to-know basis to the following categories of recipients:

  • Payment processors to charge the payment method you have selected and to remit funds to our bank account with Commonwealth Bank of Australia, BSB 062-345, account 789012345. Payment processors receive only the information required to process a payment and to comply with card scheme rules and anti-money-laundering legislation.
  • Cloud hosting providers that operate the servers on which our application and its database run. Our production infrastructure is hosted on Amazon Web Services in the Asia Pacific (Sydney) region (ap-southeast-2).
  • Transactional email providers that deliver magic-link sign-in emails, order confirmations, invoices and service notices on our behalf.
  • Error monitoring providers that receive redacted stack traces and error identifiers so that our engineering team can diagnose faults.
  • NewBook Pty Ltd to the strict extent required to authenticate outbound requests made on behalf of a customer to their NewBook Cloud account. We do not share our customer list or commercial data with NewBook Pty Ltd.
  • Professional advisers including our external accountants, auditors and lawyers, each bound by professional confidentiality duties, for the purposes of statutory audit, tax reporting and legal advice.
  • Enforcement bodies, courts and regulators where required by law, court order or a lawful request from an Australian authority.

We do not sell personal information. We do not disclose personal information to advertising networks. We do not carry out automated decision-making that produces legal or similarly significant effects concerning any individual.

7. Overseas disclosure (APP 8)

We host production data on Amazon Web Services in the Asia Pacific (Sydney) region, which is located in Australia. Certain of our sub-processors, however, are companies incorporated overseas or operate infrastructure outside Australia. Before disclosing personal information to any overseas recipient, we take reasonable steps under APP 8.1 to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to the information. Those steps include entering into written contracts that bind the recipient to standards substantially similar to the APPs, obtaining independent security certifications where available, and restricting the categories of information disclosed to what is strictly necessary.

You acknowledge that where you consent to a disclosure to an overseas recipient after being informed that APP 8.1 will no longer apply to the recipient, section 16C of the Privacy Act may operate accordingly. In all other cases we remain accountable for acts and practices of overseas recipients that would breach the APPs.

8. Data security

We take reasonable steps under APP 11 to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Our controls include:

  • All connections to cloudbookmod.org are encrypted using Transport Layer Security 1.3; earlier versions of TLS and SSL are refused at the load balancer.
  • Personal information at rest, including NewBook Cloud API keys, is encrypted using AES-256 with keys managed in a hardware security module operated by our hosting provider.
  • Access to production systems is restricted to a named list of engineers, protected by multi-factor authentication and logged for every session.
  • We do not use passwords for the Client Area; the passwordless magic-link workflow eliminates password reuse and credential-stuffing risks.
  • Dependency vulnerability scans run daily and patches are applied within a defined service-level target.
  • An incident response plan is maintained, exercised and reviewed annually by our director.
  • Encrypted backups are held in a separate Australian region and are periodically tested for successful restoration.

9. How long we hold your personal information

CategoryRetention periodReason for the period
Active customer account informationFor the duration of your subscription plus three (3) years after the last activityOngoing service, defence of legal claims
Tax invoices and accounting recordsSeven (7) years from the end of the financial yearSection 262A Income Tax Assessment Act 1936 (Cth)
Client Area session logsTwelve (12) monthsSecurity and fraud investigation
Module usage logs (debug detail)Ninety (90) daysProduct diagnostics
Module usage logs (aggregated)Twenty-four (24) monthsProduct analytics
NewBook Cloud API keysDeleted within thirty (30) days of subscription terminationContractual purpose exhausted
Direct marketing consent recordDuration of consent plus three (3) yearsProof of consent under APP 7
Support correspondenceThree (3) years from the last exchangeCustomer service continuity

Where personal information is no longer required for any of the purposes for which it was collected, or for a related secondary purpose, and we are not required by an Australian law or court order to retain it, we take reasonable steps to destroy the information or to ensure that it is de-identified, as required by APP 11.2.

10. Your rights under the Australian Privacy Principles

You have, at any time and free of charge, the following rights in relation to the personal information we hold about you:

  • APP 12 — access: to request access to the personal information we hold about you. We will respond within thirty (30) days of receiving your request and, where we agree to give access, do so in the manner requested if it is reasonable and practicable.
  • APP 13 — correction: to request correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading. Where we correct information, we notify third parties to whom we have disclosed the information if you so request and if such notification is practicable.
  • APP 7 — opt-out of direct marketing: to request that we do not use or disclose your personal information for direct marketing purposes. Every marketing email we send contains a plain-text unsubscribe link that operates immediately.
  • Anonymity and pseudonymity (APP 2): where lawful and practicable, to interact with us without identifying yourself, for example when browsing the shop as a visitor.

To exercise any of these rights, please send a written request to support@cloudbookmod.org from the email address on file for your account, or by post to our registered office. We may ask you to provide additional information reasonably necessary to confirm your identity before acting on the request.

11. How to make a complaint to us

If you believe that we have breached the Australian Privacy Principles, or that we have not handled your personal information in accordance with this policy, you may lodge a complaint with us by writing to support@cloudbookmod.org with the subject line "Privacy Complaint" or by mailing our director at 156 Collins Street, Level 12, Melbourne VIC 3000, Australia. Our director will acknowledge your complaint within seven (7) business days and provide a substantive response within thirty (30) days of receipt. We will treat your complaint confidentially and will keep you informed of the progress of our investigation.

12. How to make a complaint to the OAIC

If you are not satisfied with our response, or you do not wish to complain to us first, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC), which is the regulator of the Privacy Act 1988 (Cth). The OAIC's contact details are:

Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
Telephone: 1300 363 992
Website: oaic.gov.au

13. Direct marketing and the Spam Act 2003 (Cth)

Where you have consented to receive commercial electronic messages from us, we send them in accordance with the Spam Act 2003 (Cth). Each message identifies CloudBookModMod Pty Ltd as the sender, includes our postal address in Melbourne and contains a functional unsubscribe facility that we honour within five (5) business days at the latest. You may also revoke your consent at any time by emailing support@cloudbookmod.org. Withdrawing your consent to direct marketing does not affect the delivery of transactional and service messages that we are required to send in connection with your account.

14. Cookies

Our website uses only the cookies strictly necessary to operate the shop and Client Area and, where you have consented, functional and analytics cookies. A complete description of every cookie we set, its purpose and its retention is available in the Cookie Policy, which forms part of this policy.

15. Changes to this policy

This Privacy Policy may be updated from time to time to reflect changes in the law, in our processing operations or in our security posture. The current version and its effective date are always accessible at cloudbookmod.org/privacy. Material changes are notified by email to the address associated with your account at least thirty (30) days before they enter into force.

16. Contact

CloudBookModMod Pty Ltd
156 Collins Street, Level 12, Melbourne VIC 3000, Australia
Director: Sarah Mitchell
Telephone: +61 3 9642 7853
Email: support@cloudbookmod.org
ABN: 82 743 951 268 — ACN: 743 951 268
Regulator: Office of the Australian Information Commissioner (OAIC), oaic.gov.au

Effective from 11 August 2026. Next scheduled review: 11 February 2027.

CloudBookMod

Modules, extensions and integrations for NewBook Cloud PMS

Independent shop of modules, extensions and integrations for NewBook Cloud PMS — the Australian holiday park and hotel property management platform.

Shop

  • All extensions
  • Pricing
  • Compare
  • ROI calculator
  • Checkout

Resources

  • Modules
  • Integrations
  • Blog
  • Guides
  • Academy
  • Changelog
  • API documentation

Company

  • About
  • Contact
  • Support
  • Security
  • Terms
  • Privacy
  • Cookies
  • DPA
  • Refund policy
CloudBookModMod Pty Ltd — ABN: 82 743 951 268 — ACN: 743 951 268 — 156 Collins Street, Level 12, Melbourne VIC 3000, Australia — Director: Sarah Mitchell — support@cloudbookmod.org — Tel: +61 3 9642 7853 — Commonwealth Bank of Australia, BSB 062-345, Acc 789012345.
CloudBookMod is an independent third-party marketplace and is in no way affiliated with, sponsored by or endorsed by NewBook Pty Ltd or its parent company. All trademarks, product names and logos are the property of their respective owners. Supervisory authority for data protection: Office of the Australian Information Commissioner (OAIC). Jurisdiction: Supreme Court of Victoria, Melbourne. Applicable legal framework: Privacy Act 1988 (Cth) — Australian Privacy Principles — Australian Consumer Law under the Competition and Consumer Act 2010 (Cth).
© 2024–2026 CloudBookModMod Pty Ltd. All rights reserved.
Terms Privacy Cookies DPA Refunds

Your cart

Total A$0.00
Checkout →

We use cookies to improve your experience and analyse site performance. Learn more