LEGAL & DISCLOSURES / PRIVACY

Privacy Policy.

How we collect, use, hold and disclose information when assisting with your finance needs.

At StoneHaven Finance, we are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth). This Privacy Policy describes our current policies and practices in relation to the handling and use of personal information.

What information do we collect and how do we use it?

When we arrange finance on your behalf, we ask you for the information we need to advise you about your finance needs and your borrowing capacity. We provide any information that the lenders to whom we apply on your behalf require to enable them to decide whether to lend to you and on what terms.

We also use your information to manage your ongoing finance needs, such as refinancing, and to communicate with you about the services you have requested. These service communications are separate from marketing.

We only add you to our marketing email list if you actively subscribe. If you subscribe, we may send you property and finance insights, articles, updates and information about our services. You can unsubscribe using the link in our marketing emails or manage your marketing preferences. Making an enquiry or asking us to assist with a loan does not subscribe you to marketing emails.

We may also use your information internally to help us improve our services and help resolve any problems.

What if you don’t provide some information to us?

We can only fully advise you about your borrowing capacity and the suitability of a loan if we have all relevant information.

How do we hold and protect your information?

We strive to maintain the reliability, accuracy, completeness and currency of the personal information we hold and to protect its privacy and security. We keep personal information only for as long as is reasonably necessary for the purpose for which it was collected or to comply with any applicable legal or ethical reporting or document retention requirements.

We use the client relationship management (CRM) system provided by our aggregator, Outsource Financial, to hold and manage client information. Information may also be held in paper form where needed. Outsource and its service providers operate the systems we use to manage client files.

Cloud and networked storage may be accessed or processed in different countries. Overseas service providers may also be required to disclose information under laws that apply to them.

Disclosure of personal information overseas

Outsource Financial uses third-party providers to support the CRM in which we store client information. Outsource and its providers may review, host, store or process client information overseas as part of providing these services. StoneHaven does not choose or operate each of those providers.

The privacy wording supplied by Outsource lists the following countries as likely locations. The countries involved may depend on its providers and can change:

  • United States
  • Singapore
  • Serbia
  • Philippines

Will we disclose the information we collect to anyone?

We do not sell, trade, or rent your personal information to others.

We provide information to Outsource Financial, our aggregator, where needed to arrange and manage your finance and maintain your client file in its CRM. Outsource may use third-party service providers to operate that system.

We may need to provide your information to contractors who supply services to us, e.g. to handle mailings on our behalf or to other companies in the event of a corporate sale, merger, reorganisation, dissolution or similar event. However, we will do our best to ensure that they protect your information in the same way that we do.

We may provide your information to others if we are required to do so by law or under some unusual other circumstances which the Privacy Act permits.

How can you check, update or change the information we are holding?

Upon receipt of your written request and enough information to allow us to identify the information, we will disclose to you the personal information we hold about you. We will also correct, amend or delete any personal information that we agree is inaccurate.

To request access or a correction, email support@stonehavenfinance.com.au or call 0420 278 594. We may need to verify your identity before providing information or making a change.

We do not charge for receiving a request for access to personal information or for complying with a correction request.

How can you raise a privacy concern or complaint?

Email support@stonehavenfinance.com.au or call 0420 278 594 and tell us what happened. Please include enough detail for us to understand and investigate your concern. We will review the matter, work with Outsource Financial where its systems or providers are involved, and respond with the outcome and any next steps.

For our contact details and steps for other service concerns, visit Client Care & Complaints. If a privacy complaint remains unresolved after you have raised it with us, the Office of the Australian Information Commissioner explains how to take the matter further.

Dealing with breaches

We will deal with breaches in an appropriate and timely manner. There may be internal and external actions that need to be taken. In taking any action, we will be guided by these steps as suggested by the OAIC on responding to a breach (whether it is actual or suspected):

  1. Contain the breach and do a preliminary assessment
  2. Evaluate the risks associated with the breach
  3. Notification
  4. Prevent future breaches

See the OAIC’s Guide to Securing Personal Information for more information.

Our aggregator’s AI use disclosure

We use Outsource Financial’s CRM to manage client information. The following AI disclosure is reproduced from the privacy wording supplied by Outsource; its references to a “broker network” describe Outsource’s services to brokers.

We use Artificial Intelligence (AI) tools to support internal operations, improve efficiency, and enhance the services we provide to our broker network. We are committed to ensuring that all AI use is responsible, transparent, and compliant with Australian regulatory requirements.

How We Use AI

AI may be used for:

  • Drafting internal communications, training materials, and knowledge resources
  • Analysing non-personal operational data to improve service quality
  • Supporting internal workflows and process automation

Data Protection

We do not input personal, sensitive, or credit-related information into external AI systems. All AI use complies with the Privacy Act 1988, Australian Privacy Principles, and relevant ASIC regulatory guides.