Privacy Policy — Allsorts of Loans
Home Loans · ABN Vehicles · Assets · Equipment · Machinery · Business & Specialist lending

Privacy Policy

We are committed to protecting your privacy in accordance with the Privacy Act 1988 and the Australian Privacy Principles.

1. Open and transparent management of information

This Privacy and Credit Information Policy describes how Allsorts of Loans ("we", "us", "our"), Carter McLean Pty Ltd ATF Adventurer Finance Solutions Unit Trust, Australian Credit Licence 491549, manages your personal, sensitive, and credit-related information. We are committed to protecting client data in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), Part IIIA of the Privacy Act, the Privacy (Credit Reporting) Code 2024 (CR Code), and the National Consumer Credit Protection Act 2009 (NCCP).

As an independent credit licence holder managed directly by its appointed Responsible Managers, we gather, verify, and store credit-related client data directly to perform credit assistance.

2. Kinds of information we collect and hold

To deliver lending services across our lending suite — including consumer mortgages, commercial options, and asset or equipment finance — we collect and hold the following:

  • Identity and Verification Data: Full name, date of birth, residential history records, and government-issued identification used for customer due diligence under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (such as driver's licences, passports, and Medicare details).
  • Financial Position: Income, employment records, tax returns, company financial statements, trust deeds, ABN/ACN verifications, liability schedules, and verified household expenditure records.
  • Credit Information and Credit Eligibility Information: Credit reporting data sourced from Credit Reporting Bodies (CRBs), containing credit scores, active credit accounts, repayment history, repayment defaults, court judgements, and suspected serious credit infringements.
  • Commercial and Asset Data: Descriptions of commercial assets, supplier invoices, valuation metrics, and vehicle or equipment registration papers.

3. How we collect your information

Where practicable, we obtain information directly from you via application documents, electronic entries on our website forms, digital communications, and direct consultation. We also collect information from authorised third-party industry channels:

  • Licensed Aggregation Platforms: Secure CRM software and electronic submission software provided by our primary mortgage aggregator and our specialist asset finance aggregator.
  • Directly Accredited Partners: Lenders, credit providers, and funding institutions with whom we maintain direct, independent corporate accreditations.
  • Credit Reporting Bodies (CRBs): Sourced exclusively following your explicit, signed consent (including Equifax, Experian, or illion).
  • Professional Reference Networks: Appointed accountants, legal representatives, real estate agents, or verified employers.

3A. Information Collected via Website Forms and Calculators

When you enter information into financial calculators, borrowing estimators, or digital contact fields on our website, we capture those specific elements. This data is transferred to our business environment via encrypted security routes. If you abandon an online form prior to final submission, the information you have entered may still be collected and retained securely to help resolve your lending enquiry.

3B. Cookies, Digital Tracking and Analytics

Our website deploys technical cookies and analytical tracking tags to monitor traffic and analyse browsing behaviour.

  • First-Party Session Cookies: Active to hold data consistent across our calculation fields while you browse.
  • Third-Party Analytics: We use tools such as Google Analytics to extract de-identified, high-level logs tracking browser movement.
  • Tracking Pixels: If pixel markers from digital ad networks are active, they log interactions. Those networks may link your behaviour back to your external profile, making you identifiable to that third party. You can restrict cookie permissions within your browser settings.

4. Why we collect, hold, use and disclose information

We process your data to perform authorised credit assistance procedures under our licence, which include:

  • Analysing financial limits, asset allocations, and borrowing requirements.
  • Formulating product selection and authoring your regulatory Credit Guide and Credit Proposal documentation.
  • Routing loan submissions through our residential mortgage aggregator pipeline, our equipment finance aggregator network, or our direct corporate funding channels.
  • Executing verification requirements under national anti-money laundering laws.

4A. Use of Automated Decision-Making Systems

We use digital calculation software, loan filters, and evaluation matrices owned by our lenders and aggregators to cross-reference your financial data against lending rules. These systems calculate product suitability. Final recommendations or loan filing actions are never isolated to automated routines — they require assessment by our Responsible Managers. You may request an explanation of how any automated tools contributed to a decision that affects you, and you may request human review.

In line with the Privacy Act 1988 (Cth) automated decision-making transparency requirements (APP 1.7, commencing 10 December 2026), we advise that: the kinds of personal information used in this process are your financial position, credit information and credit eligibility information described in Section 2; the kinds of decisions involved are preliminary product suitability and serviceability filtering only, not a final credit decision; and no automated system makes, or is authorised to make, a final decision to approve, decline, or price your loan — that decision is always made by a lender's credit team or by your Responsible Manager. You may contact our Privacy Officer to request further information about, or a review of, any automated process used in connection with your application.

5. Disclosure of personal and credit information

We do not trade, rent, or lease your personal data. Information is shared strictly to arrange the specific loans or asset finance you request, through the following channels:

  • Lenders and Funding Entities: Submitted via secure aggregator software platforms or directly via independent corporate accreditation channels. This includes our Aggregator Connective Broker Services Pty Ltd and any of its related companies. All Connective staff are required by the terms of their employment to maintain confidentiality of customer information, and access to your information is restricted to those employees whose job requires that information.
  • Credit Reporting Bodies (CRBs): Accessed to obtain credit profile information with your signed authorisation. See Schedule 2 — Credit Reporting Bodies in our Credit Guide for the full list.
  • Transaction Services: Conveyancers, settlement agents, asset surveyors, property valuers, lenders' mortgage insurers, and equipment suppliers.
  • Professional and Support Services: Banks and finance organisations, valuation companies, mortgage insurers, real estate agents, settlement agents, solicitors, information technology companies, loan processors, bookkeepers and mailing organisations.
  • Statutory Authorities: Regulatory bodies such as ASIC or AUSTRAC under applicable compliance enforcement laws.

Access to our premises and computer systems is restricted through locks, password protection, internet firewalls and routers.

6. Cross-border and overseas disclosures

We operate within secure cloud databases hosted in Australia. However, platform networks, software providers, or credit providers on our lender panels may process data elements or house infrastructure overseas — frequently including New Zealand, the Philippines, India, the United Kingdom, or the United States. When data leaves Australian borders, we take precautions to ensure handling is consistent with the Australian Privacy Principles.

Our current service providers include OneDrive, Microsoft 365, Exchange, Xero, Adobe and our Customer Relationship Management (CRM) platform and Aggregator Software and payments systems. In some cases, our CRM provider does not disclose the specific jurisdictions in which its servers or authorised support teams are located. Where this occurs, we take reasonable steps to assess the provider's privacy and security framework (including encryption, access controls and audit logging) and implement contractual and procedural controls to mitigate risk. We remain responsible for your personal information in accordance with the APPs and will update this statement if further location details become available.

7. Information integrity, protection and retention

We apply electronic, technological, and logical controls to protect your files from data loss, unauthorised adjustment, or external interception. Files are held within password-protected, encrypted business systems using multi-factor authentication and role-based access. In accordance with the NCCP Act, complete client records are securely archived for a mandatory minimum of seven (7) years after our last dealing with you, after which they are thoroughly destroyed or permanently de-identified.

Photographic identification documents: In line with the reformed Anti-Money Laundering and Counter-Terrorism Financing Act and OAIC guidance applying to identity verification records collected on or after 31 March 2026, we do not retain copies or images of photographic identity documents (such as driver's licences and passports) once your identity has been verified. Instead, we retain a structured record of the verification — including the document type, document number, expiry date, verification method and outcome — for the statutory seven (7) year retention period. Copies of identity documents collected before 31 March 2026 may continue to be held for the pre-existing statutory retention period, after which they are securely destroyed or permanently de-identified.

8. Security and notifiable data breaches

We assess all suspected data breaches within 30 days to determine whether they are notifiable under the Notifiable Data Breaches (NDB) Scheme. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the NDB Scheme.

9. Accessing and correcting your information

You may request access to the personal and credit information we hold about you, by contacting our Privacy Officer at admin@allsortsofloans.com.au and providing enough information to allow us to identify you. If any information is found to be out of date, inaccurate, or incomplete, you may lodge a correction request. We address correction requests at no charge, with a standard turnaround of 30 days, and will correct, amend or delete any personal information that we agree is inaccurate.

10. Promotional communications

If you are a customer or a potential customer, from time to time we may contact you with information about products and services offered by us, which we think may be of interest to you. When we contact you it may be by mail, telephone, email or SMS.

You may opt out of receiving promotional communications from us by using the unsubscribe link within each email or emailing us to have your contact information removed from our promotional email list or registration database. Although opt-out requests are usually processed immediately, please allow ten (10) business days for a removal request to be processed. Even after you opt out from receiving promotional messages from us, you will continue to receive messages from us regarding our services.

11. Privacy complaints and escalation pathway

For any enquiries regarding this policy, or to lodge a formal complaint regarding a data handling matter, please contact our Privacy Officer directly:

Privacy Officer — Allsorts of Loans
Carter McLean Pty Ltd ATF Adventurer Finance Solutions Unit Trust
ACL 491549
admin@allsortsofloans.com.au

We will investigate your complaint and provide a written response within 30 days.

External escalation to the Privacy Commissioner

If you receive no reply within 30 days, or if you remain unsatisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):

Phone: 1300 363 992
Website: www.oaic.gov.au
Post: GPO Box 5288, Sydney NSW 2001

For disputes relating to service delivery, fees, or loan products, please refer to the dispute resolution process outlined in our Credit Guide, which details our escalation pathway to the Australian Financial Complaints Authority (AFCA), our External Dispute Resolution scheme, Membership 38764.

12. Your rights regarding credit reporting bodies

If you consent to us doing so, we may obtain a report or information about your consumer or commercial credit worthiness from a Credit Reporting Body (CRB), and we may disclose personal information such as your name, date of birth, driver's licence and address to the CRB to obtain an assessment of whether that personal information matches the information held by it. See Schedule 2 of our Credit Guide for the contact details of each CRB we work with.

Under Part IIIA of the Privacy Act and the CR Code, you should also be aware that:

  • A CRB may include information we or a credit provider disclose about you with information from other credit providers to assess your credit worthiness;
  • If you become overdue in making credit payments or commit a serious credit infringement, a credit provider may disclose that information to a CRB;
  • Schedule 1 of our Credit Guide sets out each credit provider's website, which contains details of how you can obtain a copy of their privacy policy or credit reporting policy;
  • You have the right to access and/or correct information held about you, and to complain about conduct that may breach the privacy and credit reporting laws;
  • You have the right to request a CRB not to use your credit reporting information for pre-screening for direct marketing by a credit provider;
  • You have the right to request a CRB not to release information about you if you believe you are, or are likely to be, a victim of fraud; and
  • When we make a credit information request to a CRB, a record of this request will be held by the CRB and may be used and disclosed by them to assess your creditworthiness or calculate your credit score. Making multiple information requests within a short period may negatively impact your overall credit score.

For more information on your privacy rights please visit www.oaic.gov.au.

Ver 3
Australian Credit Licence
ACL 491549
AFCA Member · 38764
External Dispute Resolution
FBAA Member
Finance Brokers Assoc. of Australia