Privacy Policy
Last updated: July 2026
1. Introduction
Walkthrough Digital Limited ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and share your information when you use our Platform.
We operate in New Zealand and Australia and comply with:
- The Privacy Act 2020 (New Zealand) and the Information Privacy Principles (IPPs)
- The Privacy Act 1988 (Cth) (Australia) and the Australian Privacy Principles (APPs)
In this Privacy Policy, "Platform" means our AI powered platform, products and services that may be purchased and used via our website and any associated mobile applications or API.
2. Information We Collect
We collect personal information directly from you through the Platform, and also through third-party services that operate on our behalf. The following sets out the categories of information collected, including data that our service providers (Didit and Seam) process when facilitating identity verification and smart lock access on our behalf.
2.1 Information Collected by the Platform
When you register and use the Platform, we collect:
- Full name, date of birth, email address, and phone number
- Device type, browser, IP address, pages visited, and session duration
- Search queries, tour interactions, and feature usage
- Support requests, emails, and messages sent to us
- Questions and messages you submit to our in-property AI guide, and the responses generated for you
- Identity verification results returned from our verification provider, including the pass/fail outcome, the checks performed and their results, and limited identity details extracted from your document (your name, document type, issuing country, and expiry date)
- Property access logs generated by our Platform, including timestamp, user identity, and property address
- Duration of property visits.
- Corporate information and details as may be available on public registries or as provided by or on behalf of the user.
- Such other information as set out in our Terms of Use or on our website.
2.2 Information Collected for Identity Verification (via Didit)
Before accessing a property, you are required to verify your identity. This process is handled by Didit, our third-party identity verification provider. When you begin verification, we send you a secure link (by SMS) to complete the process on Didit's hosted verification flow. Didit collects and processes the following information on our behalf:
- A photo of your government-issued identity document (e.g. driver licence, passport) — front and back
- A biometric facial image and liveness video captured via your device camera, and a comparison of that image against your identity document (face match)
- Personal information extracted from your identity document, including your full name, date of birth, document number, document type, issuing country, and document expiry date
- Device and network information, including your IP address and related signals, used for fraud prevention and analysis
- Verification results from the document-validation and identity data sources Didit uses to confirm your identity document is genuine and valid
Didit retains identity verification data in accordance with its own retention policies. Please refer to Didit's Privacy Policy for further details (available at didit.me). Raw identity document images and biometric data are not retained within our own Platform systems — we store only the verification result and limited identity details (such as your name, document type, issuing country, and expiry date) needed to confirm your verified status.
Further details on Didit and identity verification are set out below at Section 4.
2.3 Information Processed for Smart Lock Access (via Seam)
We use Seam, a third-party smart device API provider, to facilitate access to properties via connected smart locks. When you are granted access, Seam processes the following on our behalf:
- Your name and contact information (to the extent provided to Seam for access provisioning)
- Access credentials and the timeframe for which you are authorised to access a property
- Lock event data, including attempted and successful access events, event type, and timestamps
Seam retains device event and access data in accordance with its own data retention policies. Please refer to Seam's Privacy Notice for further details (available at seam.co/legal/seam-privacy-notice).
2.4 Information Processed by our AI Property Guide
The Platform includes an AI-powered property guide that answers questions about a listing. When you interact with this guide, the questions and messages you submit are sent to a third-party AI provider to generate a response. This provider processes your input solely to generate responses on our behalf and does not use it to train its models.
We log these conversations, including your questions and the responses generated, in order to operate, secure, and improve the AI property guide. Please do not enter sensitive personal information (such as identity document numbers, financial details, or health information) into the AI guide, as it is not required and the guide is not designed to collect it.
3. How We Use Your Information
We use your personal information for the following purposes:
- Verifying your identity for Platform access.
- Granting and logging property access.
- Operating our AI property guide and generating responses to your questions.
- Communicating with you about your account and our products and services.
- Complying with legal and regulatory obligations.
- Improving our Platform, products and services.
- Detecting and preventing fraud and abuse.
- To undertake credit checks of any user (if necessary, as determined by us).
- To protect and/or enforce our legal rights and interests, including defending any claim.
- To invoice any User and to collect money that a user owes to us, including authorising and processing credit or debit card transactions.
- To respond to communications from a user, including any complaints.
- To co-operate with any government, industry or regulatory authorities.
- For any other purpose as contemplated in our Terms of Use.
We will not use your information for purposes materially different from those above without your consent.
3.1 SMS Communications
We use your phone number to send you transactional SMS messages, specifically:
- A secure link to complete your identity verification, sent when you begin verification and, if you request it, resent (subject to a short waiting period and a limit on the number of resends)
- One-time booking confirmations sent around the time of your scheduled self-tour
- Time-limited door access PINs required to enter the property during your booked tour window
These messages are delivered via Twilio, our SMS provider, on our behalf. You provide explicit consent to receive these messages during account setup, before providing your phone number.
You may opt out at any time by updating your notification preferences in the Settings page. We will stop sending messages to that number upon receipt of your opt-out request. Note that opting out of SMS will prevent us from delivering your identity verification link and your door access PIN, both of which are required to complete a self-tour.
We do not use your phone number for marketing or promotional messages, and we do not sell or share your phone number with third parties for unrelated purposes.
3.2 Email Communications
We use your email address to send you transactional emails relating to your account and bookings, such as booking confirmations, property access details, and important notices about the Platform. These emails are delivered on our behalf by our email service provider. We do not sell your email address, and we do not send marketing emails without your consent.
4. Identity Verification
Identity verification is required before a property tour can be accessed. ID documents and biometric data submitted for verification are collected and processed by Didit, our third-party identity verification provider. Didit is contractually bound to use your data only for verification purposes and to meet equivalent privacy standards.
Didit collects your identity document images, biometric data (including a facial image, liveness capture and face match), personal details extracted from those documents, and device and network signals to confirm your identity and detect fraud. We store the verification result and limited identity details (such as your name, document type, issuing country and expiry date) on our Platform. Raw document images and biometric data are not retained within our own systems, but may be retained by Didit in accordance with its own retention policies.
5. Property Access Logs
Access logs are collected for security, property owner reporting, and dispute resolution purposes. Access logs collected by our Platform may be disclosed to:
- The property owner or developer for the relevant property — see Section 6 for detail on what is shared and why
- Law enforcement or regulatory authorities if required by law
- Our legal advisors in connection with a dispute
In addition to logs retained on our Platform, Seam (our smart lock access provider) independently retains device-level event data in accordance with its own retention policies.
Platform-held access logs are retained for a minimum of 12 months from the date of access.
6. Sharing Your Information
We do not sell your personal information. We may share your information with the following parties:
6.1 Identity Verification Provider (Didit)
We share your name, contact information, and identity document details with Didit to enable identity verification before property access. Didit processes this information on our behalf and is contractually bound to handle it securely and in accordance with applicable privacy laws.
6.2 Smart Lock Access Provider (Seam)
We share your name, contact information, and authorised access window with Seam to provision smart lock access for a specific property and timeframe. Seam processes this information on our behalf and returns access event data which is used to generate property access logs.
6.3 Property Developers and Owners
We share the following information with the developer or owner of a property you have visited, for the purposes of property management, security, and reporting:
- Your full name and verification status (pass/fail), to confirm you were a verified visitor
- The date, time, and duration of your property visit
- Whether your access was successful or unsuccessful, and any access errors
We do not share your identity document details, biometric data, or contact information with property developers or owners. Information is only shared in connection with visits to properties managed by that developer or owner.
6.4 Cloud Infrastructure, Authentication and Storage Providers
We use third-party cloud hosting, authentication, and file and image storage services to operate the Platform and manage account sign-in. Your data may be stored and processed on infrastructure provided by these providers, who act on our behalf.
6.5 Professional Advisors
We may share information with lawyers, accountants, and other advisors where necessary for the operation of our business.
6.6 Law Enforcement and Regulators
We may disclose information to law enforcement agencies or regulators where required by law or court order.
6.7 AI, Communications and Analytics Providers
We share the minimum information necessary with the following categories of service provider, each of which processes it on our behalf under contract:
- Our AI provider, which receives the questions and messages you submit to the AI property guide in order to generate responses
- Our SMS and email providers, which receive your contact details and message content to deliver transactional communications
- Our analytics and error-monitoring providers, which receive Platform usage and device data to help us understand usage and diagnose technical issues
All third-party service providers are required to handle your data securely and in accordance with applicable privacy laws.
7. Cross-Border Data Transfers
We are based in New Zealand and may store or process data in other countries through the third-party services we use. The following sets out the data residency positions of our key service providers:
- Didit (identity verification): Didit processes identity verification data on infrastructure that may be located outside New Zealand and Australia. Where this occurs, we rely on the contractual data processing protections described below to require Didit to protect your information to comparable standards.
- Seam (smart lock access): Seam is a US-incorporated company (Seam Labs, Inc.) and processes data on infrastructure hosted in the United States. Data transmitted to Seam from outside the United States is transferred to and stored on US-based servers.
- Cloud infrastructure providers: We use cloud hosting services which may store data in Australia and/or other countries.
- AI, communications, analytics and authentication providers: Our AI, email, analytics, error-monitoring, and authentication and storage providers may process data on infrastructure located in the United States or other countries.
Where personal information is transferred internationally, we take steps to ensure equivalent privacy protections apply, consistent with:
- Information Privacy Principle 12 of the Privacy Act 2020 (NZ), which requires that personal information is only transferred to a country with comparable privacy safeguards, or where the recipient agrees to protect the information in a comparable way
- Australian Privacy Principle 8 of the Privacy Act 1988 (Cth), which requires reasonable steps to ensure overseas recipients do not breach the APPs
The mechanisms we rely on for international transfers include:
- Contractual data processing agreements with our service providers that require them to maintain privacy and security standards equivalent to those required by New Zealand and Australian law
- For transfers to Seam (US), we rely on contractual protections in Seam's Platform Terms of Service, which impose obligations on Seam as a data processor to handle personal information in compliance with applicable privacy laws
- For transfers to Didit, we rely on a contractual data processing agreement that requires Didit to handle personal information in compliance with applicable privacy laws and to comparable privacy and security standards
8. Data Security
We take reasonable technical and organisational measures to protect your personal information, including:
- Encryption of data in transit (TLS) and at rest
- Access controls limiting who can view sensitive data
- Regular security reviews and monitoring
- Incident response procedures
No method of transmission over the internet is 100% secure. If you believe your data has been compromised, contact us immediately at privacy@walkthrough.digital.
9. Data Retention
We retain personal information held on our Platform for as long as necessary to fulfil the purposes outlined in this Policy, or as required by law:
Data Type | Retention Period |
|---|---|
Account information | Duration of account + 7 years |
ID verification result and limited identity details | Minimum 12 months, or as required by law |
Payment records | 7 years (tax/legal compliance) |
Property access logs (Platform) | Minimum 12 months |
AI property guide conversations | 24 months |
Platform usage data | 24 months |
After the applicable retention period, data held on our Platform is securely deleted or anonymised.
Third-party retention: Identity verification data (including document images and biometric data) processed by Didit, and smart lock access event data processed by Seam, are retained by those providers in accordance with their own data retention policies. We do not control the retention periods applied by these providers. Please refer to their respective privacy policies for further information.
10. Your Privacy Rights
Depending on your location, you have the following rights in relation to the personal information we hold about you on our Platform:
New Zealand (Privacy Act 2020)
- Right to request access personal information we hold about you
- Right to request correction of your personal information
- Right to request deletion of your personal information, where we no longer have a lawful basis to retain it
- Right to make a privacy complaint to us or the Office of the Privacy Commissioner
Australia (Privacy Act 1988)
- Right to access and correct your personal information
- Right to request deletion of your personal information, subject to our legal obligations to retain certain data
- Right to request we not use your information for direct marketing
- Right to complain to the Office of the Australian Information Commissioner (OAIC)
To exercise any of these rights, contact us at privacy@walkthrough.digital. We will respond within 20 working days (NZ) or 30 days (Australia).
Please note that some rights may be subject to limitations. For example, we may be required to retain certain data for legal compliance purposes even where a deletion request is made. We will always explain the basis for any refusal.
For the avoidance of doubt, this Privacy Policy does not limit or exclude any rights that a User has or may have under the Privacy Act 2020 and Privacy Act 1988.
For information held by our third-party service providers (Didit or Seam), please contact those providers directly using the details in their respective privacy policies, or contact us and we will assist where we are able.
11. Cookies and Tracking
Our Platform uses cookies and similar technologies to:
- Maintain your session and preferences
- Analyse Platform usage and performance
- Improve user experience
We also use third-party analytics and error-monitoring providers to understand how the Platform is used and to diagnose technical issues. These providers process usage and device data (such as pages visited, interactions, and error reports) on our behalf.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect Platform functionality.
12. Children's Privacy
Our Platform is not directed at, and we do not knowingly collect personal information from, persons under 18 years of age. If you believe we have inadvertently collected information from a minor, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Platform. The updated Policy will be effective from the date it is posted.
14. Complaints
If you have a concern about how we handle your personal information, please contact us first at privacy@walkthrough.digital. If we are unable to resolve your concern, you may contact:
- New Zealand: Office of the Privacy Commissioner — www.privacy.org.nz
- Australia: Office of the Australian Information Commissioner — www.oaic.gov.au
15. Contact Us
Email: privacy@walkthrough.digital
16. Severability
If any part of this Privacy Policy is found by a court to be invalid, void or unenforceable, such provision will be deemed to be deleted from this Privacy Policy and the remaining provisions of will continue in full force and effect.