Legal
Acceptable Use Policy
Last updated September 13, 2026
Contents
- 1. Scope and acceptance
- 2. Prohibited uses
- 3. Messaging and anti-spam
- 4. Honoring unsubscribe and message integrity
- 5. Handling other people's data lawfully
- 6. PS Pay and payments
- 7. Responsible use of AI features
- 8. Security and testing
- 9. Consequences of breach
- 10. Reporting abuse
- 11. Changes to this Policy
Effective date: July 11, 2026. Last updated: September 13, 2026.
This Acceptable Use Policy (the "AUP" or "Policy") sets out the rules for acceptable use of the PropertyStack website (this marketing site) and the PropertyStack product application at app.mypropertystack.io (together, the "Services"). It is published by PropertyStack Software Pty Ltd (ABN 91 674 505 821; ACN 674 505 821), an Australian private company located in Brisbane, Queensland, Australia ("PropertyStack", "we", "us", "our"). Correspondence about this Policy should be directed to legal@propertystack.ai; general support inquiries may be sent to support@propertystack.ai.
PropertyStack is an Australian business that provides an all-in-one, AI-agent-driven property management platform for short-term and vacation rentals — including guest messaging, multi-calendar and channel management, tasks and maintenance, trust accounting, owner, guest and contractor portals, a direct booking site, PS Pay card payments, PS Verify guest identity and booking verification, smart-lock integrations, analytics and upsells.
This Policy forms part of the terms under which you use the Services and should be read together with them. Capitalized terms not defined here have the meaning given in those terms. Where the language is general it is meant to be read broadly; examples introduced by "including" or "for example" are illustrative and not exhaustive.
1. Scope and acceptance
This Policy applies to everyone who accesses or uses the Services: visitors to the PropertyStack website; customers who subscribe to the PropertyStack product; and the authorized users, staff, contractors, property owners, guests and other individuals a customer permits to use the product on its behalf (together, "you"). If you use the Services on behalf of an organization, you accept this Policy for that organization and confirm you are authorized to do so.
This Policy forms part of, and is incorporated by reference into, the agreement under which you use the Services — the Terms of Service for the website (see our Terms of Service) and the customer agreement or subscription terms for the product. Where a signed customer agreement or Data Processing Addendum (see our Data Processing Addendum) applies, that agreement governs if it conflicts with this Policy; otherwise this Policy controls.
By accessing or using the Services, you agree to comply with this Policy. If you do not agree, you must not use the Services.
The Services are operated from Australia. This Policy applies alongside, and does not limit, your own obligations under every law that applies to your use of the Services. In Australia these include the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) and the Spam Act 2003 (Cth). Where your activities reach individuals or transactions in other regions, they may also include the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA) and comparable US State privacy laws (including those of Virginia, Colorado, Connecticut and Utah), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). You are responsible for identifying and meeting the laws that apply to you.
This Policy is not exhaustive. We may refuse, restrict or remove any use, content or activity that we reasonably consider to breach this Policy, to be unlawful, or to create risk or liability for PropertyStack, our other customers or the public — whether or not it is specifically listed below.
2. Prohibited uses
You must not use the Services, must not permit or encourage any other person to use the Services, and must not attempt or facilitate the use of the Services, to do any of the following:
- Illegal activity — break any applicable law, regulation, sanctions regime or court order, or engage in, promote or facilitate any unlawful activity.
- Infringing content — upload, store, transmit or otherwise process content that infringes or misappropriates any intellectual-property, privacy, publicity, confidentiality or other right of any person.
- Harmful or illegal content — create, store or distribute content that is unlawful, defamatory or obscene, or that depicts or promotes child sexual abuse, terrorism, extreme violence, self-harm or other seriously harmful material.
- Harassment and abuse — harass, threaten, defame, stalk, bully, or incite violence or hatred against any person, or otherwise engage in abusive conduct toward guests, owners, contractors, our staff or other users.
- Deceptive or fraudulent conduct — impersonate any person or entity, misrepresent your identity or affiliation, publish false or misleading listings, availability, pricing or reviews, or engage in phishing, fraud or other misleading or deceptive conduct (including conduct that would breach the Australian Consumer Law).
- Malware — introduce, transmit or store any virus, worm, ransomware, malicious code or other harmful component, or use the Services to distribute the same.
- Circumventing security — circumvent, disable or interfere with any authentication, security, rate-limiting, usage-metering or access-control feature of the Services, or any technical measure that protects them.
- Unauthorized access — access, or attempt to access, any account, data, system or network that you are not authorized to access; use another user's credentials without permission; or breach the boundaries between customers in our multi-tenant environment.
- Scraping and overloading — use any robot, spider, scraper or other automated means to access or extract data from the Services except through interfaces and rate limits we expressly permit; or take any action that imposes, or may impose, an unreasonable or disproportionately large load on our infrastructure, or that disrupts or degrades the Services (including denial-of-service activity).
- Reverse engineering — decompile, disassemble, reverse engineer, or otherwise attempt to derive the source code, underlying AI models or non-public components of the Services, except to the extent this restriction is prohibited by applicable law.
- Unauthorized resale — resell, sublicense, rent, lease, timeshare, or provide the Services to third parties as a service bureau, or otherwise commercialize the Services, except as expressly permitted in your customer agreement.
- Misrepresentation — misrepresent your relationship with PropertyStack, use our name, logos or trademarks without authorization, or state or imply any endorsement, partnership or certification that has not been granted.
3. Messaging and anti-spam
The product includes guest messaging, a unified inbox and automated or AI-assisted communications across channels such as email, SMS and WhatsApp. Messages are delivered through third-party channels and gateways, including Twilio Inc. (SMS and telephony) and Twilio SendGrid (transactional email); the authoritative, current list of product sub-processors accompanies our signable Data Processing Addendum, available on request from legal@propertystack.ai. You are responsible for every message sent from your account, whether it is composed by you, your staff, an automation, or an AI agent.
You must have a lawful basis, and any consent required by law, to contact each recipient — including guests, owners, contractors and leads — for the purpose and on the channel you use. You must keep records of consent where the law requires, and you must not use the Services to send unsolicited bulk or mass marketing, or to message people who have no relationship with you and have not consented.
In particular, when using the Services to send communications you must comply with the laws that apply to your recipients, including:
- Spam Act 2003 (Cth) (Australia) — for commercial electronic messages to Australian recipients: send only with consent, clearly identify yourself as the sender, and include a functional unsubscribe facility that you action promptly.
- CAN-SPAM Act (United States) — for commercial email to US recipients: use accurate routing and header information and non-deceptive subject lines, identify the message as an advertisement where required, include a valid physical postal address, and honor opt-out requests.
- Telephone Consumer Protection Act (TCPA) and Do-Not-Call rules (United States) — for calls and SMS to US recipients: obtain the consent the law requires (including prior express written consent for autodialed or pre-recorded marketing calls and texts), honor STOP and Do-Not-Call requests, and observe permitted contact hours.
- GDPR / UK GDPR and ePrivacy rules (EU/UK) — for electronic marketing to EU and UK recipients: rely on a valid lawful basis and, where required, prior consent, and provide an easy means to opt out in every message.
- Other regions — comply with equivalent rules for your recipients elsewhere, including Canada's Anti-Spam Legislation (CASL) for Canadian recipients.
4. Honoring unsubscribe and message integrity
You must promptly action every unsubscribe, opt-out, STOP or deletion request, and must not send further messages of that type after a person has opted out. You must not remove, disable or obscure any unsubscribe mechanism, sender identification, or other legally required element from messages sent through the Services.
Messages must not be deceptive, must accurately reflect the booking or service context, and must not be used to harass recipients. We do not routinely monitor message content, but we may investigate and act on complaints, on high spam-complaint or bounce rates, or on suspected abuse, including by suspending messaging.
5. Handling other people's data lawfully
When you use the product to process personal information about your guests, owners, contractors, leads or staff, you act as the controller (and, under the Privacy Act 1988 (Cth), the responsible APP entity) for that information, and PropertyStack acts as your processor and service provider, processing it on your behalf and on your instructions under the customer agreement and Data Processing Addendum (see our Data Processing Addendum).
As the controller, you are responsible for the following:
- Notices and lawful basis — provide the privacy notices, and obtain any consents or other lawful basis, required for your collection and use of that information and for entrusting it to PropertyStack and our sub-processors.
- Individual rights — honor the data-subject and consumer rights that apply to the people whose information you process, including rights of access, correction, deletion, portability and objection under the APPs, GDPR/UK GDPR, CCPA/CPRA, PIPEDA and comparable laws, and cooperate with us where our assistance is needed to respond.
- Security — keep credentials confidential, use the security controls we make available (such as strong authentication and least-privilege roles), and do not expose personal information through insecure configurations, public links or unnecessary sharing.
- Sensitive data — do not misuse sensitive information. Do not collect or store payment card data outside the PS Pay flow or other approved fields; do not upload government-identity documents or other sensitive categories of information except through features designed for that purpose (for example, PS Verify guest identity and booking verification) and with a lawful basis; and do not use identity or verification data for any purpose other than the one for which it was collected.
- No unlawful profiling or discrimination — do not use the Services, or the data in them, to profile or discriminate against guests, owners or applicants in any way the law prohibits.
- Rights to the data — you represent that you are entitled to provide to PropertyStack all data you submit, and that our processing of it on your instructions will not breach any law or third-party right.
6. PS Pay and payments
PS Pay lets you accept card payments and handle related flows, and the product supports trust accounting, owner statements, disbursements and GST handling. PS Pay is provided in partnership with Kovena, our third-party payments provider, which processes cardholder data to deliver card payments; card data is handled by Kovena and is not stored on PropertyStack servers, and Kovena's own terms and privacy policy also apply to payment processing. Business verification (KYC) is required before PS Pay is activated for your account. If you use PS Pay or any payment feature, the following apply in addition to the applicable payment terms and the rules of the relevant card networks and payment providers:
- No prohibited or high-risk transactions — do not use payment features for any transaction that is illegal, for goods, services or business categories prohibited or restricted by the applicable card networks, acquirers or payment processors, or for high-risk activities for which you are not approved.
- Card-network and scheme rules — comply with the operating rules of the applicable card networks (such as Visa and Mastercard) and any requirements of Kovena as our payment processor, including rules on surcharging, refunds, chargebacks, receipts, and the secure handling of cardholder data (PCI DSS).
- Accurate and authorized charges — charge only amounts the payer has authorized, for genuine bookings, deposits, damages or services; clearly describe what is being charged; and handle deposits, holds, refunds and cancellations in line with the terms disclosed to the payer and with applicable consumer law.
- No fraud or money laundering — do not process fraudulent, unauthorized or laundered transactions, structure transactions to evade limits or reporting, or use the Services to facilitate money laundering, terrorist financing or sanctions evasion. You must comply with applicable anti-money-laundering, counter-terrorism-financing and sanctions laws.
- Trust accounting integrity — where you use trust accounting, owner-statement, disbursement or related features, you remain responsible for operating any trust or client account in accordance with the laws and licensing rules that apply to you. PropertyStack provides tooling, not accounting, tax, GST or legal advice.
7. Responsible use of AI features
The Services include AI-agent features — for example, AI-assisted guest messaging in the product, and the "Ask PropertyStack" assistant on this website. Our AI providers process customer and visitor data solely to provide the service to us; we do not permit them to use it to train their general-purpose models, and we retain human oversight for consequential actions. AI output can nonetheless be inaccurate, incomplete or unsuitable for a particular situation. When you use these features you must:
- Keep human oversight — maintain meaningful human oversight of AI-generated actions and messages that affect guests, owners, bookings, payments or safety, and review and approve output before relying on it where the stakes warrant.
- Not over-rely on AI output — do not rely on AI output as a substitute for professional judgment or advice in legal, financial, tax, accounting (including trust accounting and GST), insurance, medical or safety-critical decisions without independent review by a qualified person.
- Not submit unlawful content — do not submit unlawful, infringing or harmful content to AI features, and do not use them to generate spam, disinformation, harassing or deceptive content, or any content that would breach this Policy or applicable law.
- Keep sensitive data out of prompts — do not enter payment card numbers, government identifiers or other sensitive data into AI prompts or the on-site assistant except where a feature is expressly designed to receive it. The on-site assistant streams your conversation to our provider ElevenLabs to power the live demo, so do not share information you do not wish to be processed for that purpose (see our Privacy Policy and Cookie Policy).
- Disclose automated interactions where required — where the law requires you to tell a person they are interacting with an automated system or AI, you are responsible for making that disclosure.
- Not manipulate safeguards — do not attempt to manipulate the AI features to bypass their safety controls, extract underlying models or training data, or produce output the Service is designed to prevent.
8. Security and testing
We welcome good-faith help keeping the Services secure, within the limits below.
- No unauthorized testing — do not conduct penetration testing, vulnerability scanning, load or stress testing, red-teaming or any similar security testing against the Services without our prior written authorization and an agreed scope.
- No exploitation — if you discover a vulnerability, do not exploit it, do not access or alter data that is not yours, do not degrade the Services, and do not disclose the issue publicly before we have had a reasonable opportunity to remediate it.
- Report to security@ — report suspected vulnerabilities, security incidents or exposed data promptly to security@propertystack.ai, with enough detail to reproduce the issue. We appreciate responsible disclosure; for our responsible-disclosure guidance and more detail on our safeguards, see the Security page on this website.
- Protect your own environment — keep your credentials, API keys and devices secure, enable the authentication controls we make available, and notify us promptly at security@propertystack.ai if you suspect any unauthorized access to your account.
9. Consequences of breach
We may investigate suspected breaches of this Policy. Depending on the nature and severity of a breach, and to the extent permitted by your agreement and applicable law, we may take any of the following actions — with prior notice, or without prior notice where the circumstances (such as risk to others, a legal obligation, or ongoing harm) require:
- Issue a warning or a request to remediate within a stated time.
- Remove, disable or quarantine offending content, messages, configurations or automations.
- Throttle, suspend or restrict access to the Services or to specific features (including messaging or payments) for you or affected users.
- Suspend or terminate your account, or the customer agreement, in accordance with its terms.
- Retain, preserve or disclose information where we reasonably believe it is required by law or legal process, or is necessary to protect the rights, safety or property of PropertyStack, our customers or the public.
- Report matters to, and cooperate with, regulators, card networks, payment providers or law enforcement where required or appropriate.
- No waiver — our decision not to act on a particular breach does not waive our right to act on that breach, or any other breach, later.
- Effect of suspension or termination — suspension or termination for breach does not entitle you to a refund except as required by your agreement or by applicable law (including the consumer guarantees under the Australian Consumer Law, which are not excluded), and you remain responsible for loss arising from your breach of this Policy, subject to the limits, consumer guarantees and other protections that apply under your agreement and applicable law.
10. Reporting abuse
If you become aware of any use of the Services that breaches this Policy — including abusive messages, fraud, infringing or harmful content, or a suspected security issue — please tell us so we can investigate. Please include enough detail for us to identify and assess the issue, such as the account, message, URL or content in question and how to reproduce it; we may need to share aspects of a report with the relevant customer, our providers, or the authorities in order to resolve it. Use the contact that best fits your report:
- Security vulnerabilities and incidents — security@propertystack.ai.
- Other abuse, and legal, content, intellectual-property or privacy-infringement complaints — legal@propertystack.ai.
- Privacy requests and questions about personal information handled by this website — privacy@propertystack.ai.
11. Changes to this Policy
We may update this Policy from time to time — for example, to reflect new features, new sub-processors, or changes in the law. When we do, we will post the updated Policy at this location and revise the "last updated" date shown at the top of this Policy. Material changes take effect as described in your agreement, or as otherwise required by law; your continued use of the Services after an update takes effect means you accept the updated Policy.
If any part of this Policy is held to be unenforceable, the remaining parts continue in effect. This Policy is governed by the laws of Queensland, Australia. Subject to the governing-law and dispute-resolution provisions of your agreement with us, the parties submit to the non-exclusive jurisdiction of the courts of Queensland, Australia, and of the Federal Court of Australia.
Questions about this Policy: legal@propertystack.ai.