| Privacy Policy LockSmart: Smart Lock Access |
Effective 30 July 2026 | Version 1.0 | Australia
| In plain languageLockSmart uses information to create and secure accounts, connect to smart locks and Wi‑Fi bridges, share access, show lock locations when enabled, send service messages, and keep the service reliable. We do not sell personal information, show third-party advertising, or use personal information for cross-app advertising. |
1. About this policy
This policy explains how the LockSmart mobile applications, web and admin portal, APIs, support pages, and related smart-lock and Wi‑Fi bridge services (together, the “Service”) handle personal information.
For this policy, “LockSmart”, “we”, “us” and “our” refer to Ricardo Luz, the developer and operator of LockSmart: Smart Lock Access. Privacy enquiries can be sent to developer@locksmart.app.
2. Information we collect
Account and identity information
• Contact details. Your name, email address, mobile number, country code, profile image, and account preferences.
• Authentication information. A password hash for email accounts; identity-provider identifiers and tokens for Sign in with Apple or Google; security, session and two-factor authentication records; and account status.
• Role and organisation information. Where the admin or property features are used, this can include organisation, agency, landlord, tenant, trade-person, property and role information.
Locks, bridges, properties and access
• Device and asset details. Lock and bridge serial numbers, names, images, firmware and configuration, property details and addresses, and device ownership or association.
• Access information. Invitations, invitee contact details, access levels, schedules, passcode or card-management events, unlock activity, sharing history and administrative audit information.
• Wi‑Fi bridge setup. Wi‑Fi network names and credentials that you provide are used to configure a nearby bridge. The mobile app passes them to the bridge over Bluetooth; they are not intended to be retained by LockSmart’s central service.
Location, contacts, photos and device information
• Location. Precise location, accuracy, signal strength and timestamps when you enable lock-location, last-seen, crowd-sourced location or automatic-unlock features. Background location is used only after the operating system grants permission and a relevant feature is enabled.
• Contacts. The contact details you select when inviting someone. LockSmart uses the system contact picker and does not intend to upload your whole address book.
• Photos and camera. Images you choose or capture for a lock, bridge or profile.
• Device and network data. Device model, operating system and app version, IP address, connection state, Bluetooth and nearby-device events, notification tokens, language, time zone and technical identifiers needed to provide the Service.
• Diagnostics. Crash reports, error records, performance and reliability information, including information collected through Firebase Crashlytics.
• Support and communications. Messages, attachments and other information you provide when contacting us or responding to service communications.
3. How information is collected
We collect information:
• directly from you when you register, update your profile, add a lock or bridge, configure access, choose a contact or image, or contact support;
• automatically from the app, browser, connected hardware and service logs as you use the Service;
• from Apple, Google and Firebase when you choose a federated sign-in method;
• from another authorised user, property manager, landlord, agency or administrator when they invite you or manage a relevant property or asset; and
• from device permissions and operating-system services only after the applicable permission or choice is available to you.
4. Why we use information
• Provide the Service. Create accounts; connect, configure and operate locks and bridges; manage properties; share and schedule access; display relevant lock status and location; and deliver requested features.
• Authenticate and protect. Verify identity, support optional two-factor authentication, detect misuse, investigate security events, enforce access rights and protect people, property and the Service.
• Communicate. Send transactional email, SMS and push notifications, including verification, password-reset, invitation, access-change and device-status messages.
• Support and improve. Troubleshoot problems, respond to requests, measure reliability, correct faults and improve the Service. LockSmart does not currently use Firebase Analytics for advertising or marketing.
• Comply and enforce. Meet legal obligations, resolve disputes, enforce agreements and respond to lawful requests.
5. Permissions and features you control
Your device controls permission for Bluetooth, nearby devices, location, contacts, camera, photos, notifications and biometrics. You may refuse or later revoke optional permissions in device settings, although the related feature may stop working.
• Bluetooth and nearby devices. Used to discover, configure and operate compatible locks and Wi‑Fi bridges.
• Precise and background location. Used for enabled last-seen, crowd-location and automatic-unlock features. Background access is not required for basic account use.
• Contacts, camera and photos. Used only when you choose a contact or image for a supported feature.
• Face ID or device biometrics. The operating system performs biometric matching. LockSmart receives only the success or failure result, not your face template or biometric data.
• Notifications. Used for security, access-sharing and lock or bridge service messages. You can turn them off in device settings.
6. When information is disclosed
We disclose information only as reasonably necessary for the purposes in this policy:
• People and organisations you authorise. Lock owners, co-owners, invitees, tenants, landlords, agencies, tradespeople and administrators may see information relevant to their authorised role and access.
• Cloud and authentication. Google Cloud and Firebase provide hosting, authentication, push-notification and crash-diagnostic services. Apple and Google provide sign-in and mobile-platform services.
• Maps and location. Google Maps Platform supports map, address and place features.
• Communications. Apple Push Notification service and Firebase Cloud Messaging deliver notifications; Amazon Web Services may deliver transactional SMS; Resend delivers transactional email; and TinyURL shortens invitation links.
• Professional, legal and safety needs. Advisers, insurers, regulators, law-enforcement bodies or other parties where reasonably necessary to comply with law, protect safety or rights, investigate misuse, or manage a dispute.
• Business change. A buyer, successor or adviser involved in a merger, financing, reorganisation or sale, subject to appropriate confidentiality and privacy protections.
| No advertising sale or cross-app trackingLockSmart does not sell or rent personal information. We do not show third-party advertising and do not use personal information to track you across apps or websites owned by other companies for advertising. |
7. Overseas processing
LockSmart is operated from Australia. Our service providers operate global infrastructure, so personal information may be processed in Australia, the United States and other countries where those providers or their subprocessors operate. Privacy laws in those countries may differ from Australian law.
We select established providers and require information to be handled consistently with applicable law and the protections described in this policy. Provider privacy terms and contractual controls also apply to their processing.
8. Retention and account deletion
We retain personal information only for as long as reasonably necessary to provide and secure the Service, meet legal obligations, resolve disputes and enforce agreements. Retention depends on the type of information and why it is needed.
• Active accounts. Account, lock, bridge, property, sharing and access information is generally kept while the account or relevant relationship remains active.
• Account deletion. In the app, open Settings, then Account Settings, and select Delete Account. After fresh identity verification, the deletion process permanently removes the LockSmart account record, active API tokens, password-reset records, owned locks and ownership history, and access-sharing records. It also removes local account and lock data and requests deletion of the linked Firebase sign-in identity where applicable.
• Limited residual records. We may keep minimal hashed deletion receipts, security records, legal records, or information that has been de-identified where needed to complete deletion safely, prevent fraud, establish legal rights or meet a legal obligation. These records are not used to recreate the deleted account.
• Backups and caches. Copies in protected backups and transient caches are isolated from ordinary use and removed or overwritten through normal retention cycles.
If you cannot sign in, follow the account-deletion instructions at https://gcp-demo.locksmart.app/account-deletion/ or email developer@locksmart.app.
9. Security
We use technical and organisational safeguards designed to protect personal information, including encrypted network connections, access controls, restricted production credentials, device keychain or encrypted storage for supported secrets, token-based sessions, security logging and controlled provider access.
No service can guarantee absolute security. Keep your device, email account, passwords, one-time codes, lock credentials and recovery information secure. LockSmart support will not ask you to disclose a password, one-time verification code, API key, lock password or recovery credential.
10. Access, correction, choices and complaints
You may update common profile and permission choices in the app or device settings. You may also request access to or correction of personal information, ask a privacy question, withdraw consent where processing depends on consent, or make a complaint by emailing developer@locksmart.app.
Please describe your request and the account email concerned. We may need to verify your identity before acting. We will respond within a reasonable period and explain if an exception applies. If you are not satisfied with our response and Australian privacy law applies, you may contact the Office of the Australian Information Commissioner.
11. Children
The Service is not directed to children under 13. We do not knowingly create accounts for children under 13 without appropriate parental or guardian involvement. If you believe a child has provided personal information contrary to this policy, contact us so we can investigate and take appropriate action.
12. Changes to this policy
We may update this policy when the Service, providers or legal requirements change. The current version and effective date will be published at the privacy-policy address. If a change materially affects how personal information is handled, we will provide additional notice where reasonably required.
13. Contact
| Developer and operator | Ricardo Luz — LockSmart |
| Privacy contact | developer@locksmart.app |
| Privacy-policy URL | https://locksmart.app/privacy-policy |
| Operating country | Australia |