top of page

1. Purpose and Scope

​

Blue Streak Capital ("BSC", "we", "us", "our") is a specialist non-bank lender providing short-term business and construction/development finance across Australia. In the course of our business we collect, hold, use, and disclose personal information — including credit-related personal information — about individuals such as borrowers, guarantors, directors, brokers, and other stakeholders.

​

This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and, where applicable, Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code 2014 governing credit-related personal information.

​

This Policy applies to all personal information collected by BSC, whether directly from an individual, through a mortgage or finance broker, or from a third party such as a credit reporting body, valuer, or other credit provider.

​

2. Personal Information We Collect

​

The type of personal information we collect depends on our relationship with the individual and the nature of the finance being sought.

​​

​

 

 

​

​

​

​​​​​​

​

​

​

​​​​

 

 

 

Where reasonable and practicable, we collect personal information directly from the individual concerned. We may also collect information from a mortgage broker acting on the individual's behalf, a credit reporting body, another credit provider, a valuer, employer, or publicly available sources, where necessary to assess a credit application or manage a loan.

​

We do not intentionally collect sensitive information (such as health information) except where volunteered by an individual (for example, in a hardship application) and reasonably necessary for that purpose, or where otherwise permitted by law.

​

3.  How We Use and Disclose Personal Information

​

  • Assessing and processing applications for finance, including credit assessment and verification of identity.

  • Managing and administering loans, including arrears management, variations, and discharge.

  • Meeting our obligations to funders and warehouse trust trustees, including reporting on loan performance.

  • Complying with our legal and regulatory obligations, including under the National Consumer Credit Protection Act 2009 (Cth) (where applicable), AML/CTF legislation, and taxation law.

  • Communicating with borrowers, guarantors, and brokers about their loan or application.

  • Direct marketing about products and services that may be of interest, where permitted by law and subject to an individual's right to opt out at any time.

 

3.1 Credit Reporting

​

Where an individual applies for consumer or commercial credit, we may obtain a credit report from a credit reporting body (CRB) to assess the application, and we may disclose information to a CRB, including repayment history information and, in the case of a default, default information, in accordance with the Privacy Act and the Credit Reporting Code.

​

We may also exchange information with other credit providers to assess creditworthiness, verify identity, or investigate suspected fraud, as permitted under Part IIIA of the Privacy Act.

​

3.2 Disclosure to Third Parties

​

  • Funders, warehouse trustees, and their advisers, for the purposes of funding and securitisation arrangements.

  • Mortgage and finance brokers involved in the application.

  • Valuers, solicitors, and settlement agents engaged in connection with a loan.

  • Credit reporting bodies and other credit providers, as described above.

  • Our professional advisers, insurers, and technology service providers (including our loan management system provider), who are bound by confidentiality obligations.

  • Regulators, government agencies, or courts, where required or authorised by law.

 

We do not sell personal information to third parties.

​

4. Overseas Disclosure

​

Some of our technology service providers may store or process data using cloud infrastructure located, or with support functions based, outside Australia. Where this occurs, we take reasonable steps to ensure the overseas recipient handles personal information in a manner consistent with the Australian Privacy Principles, including through contractual protections. We do not otherwise disclose personal information to overseas recipients other than as described in this Policy.

​

5. Data Quality and Security

​

  • We take reasonable steps to ensure the personal information we collect, use, and disclose is accurate, complete, and up to date, and encourage individuals to notify us of any changes to their details.

  • We protect personal information against misuse, interference, loss, unauthorised access, modification, or disclosure through technical and organisational controls, as set out in our Cyber Security Policy (BSC-CSP-01), including encryption, access controls, and staff training.

  • Personal information is retained only for as long as necessary to fulfil the purpose for which it was collected, or as required by law (including record-keeping obligations under credit and AML/CTF legislation), after which it is securely destroyed or de-identified.

  • In the event of a data breach likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

​

6. Access and Correction

​

Individuals may request access to the personal information we hold about them, and request that it be corrected if it is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond to requests within a reasonable period, generally within 30 days, and may charge a reasonable fee for access (but not for correction requests).

​

We may decline a request for access in limited circumstances permitted by law (for example, where it would have an unreasonable impact on the privacy of others, or relates to existing or anticipated legal proceedings), and will provide reasons for any refusal where required to do so.

​

For credit-related personal information, individuals also have specific rights to request correction of credit reporting information under Part IIIA of the Privacy Act, including in relation to information we have disclosed to a credit reporting body.

​

7. Direct Marketing

​

We may use personal information to provide individuals with information about products, services, or promotions that may be relevant to them, where consistent with their reasonable expectations or as otherwise permitted by law. Individuals may opt out of receiving direct marketing at any time by contacting us using the details in Section 9, or via the unsubscribe function in any electronic marketing communication.

​

8. Complaints

​

Individuals who believe BSC has breached the Privacy Act or the Australian Privacy Principles may lodge a complaint by contacting our Head of Compliance using the details below. We will acknowledge complaints promptly and aim to resolve them within 30 days.

​

If an individual is not satisfied with our response, they may refer the complaint to the Office of the Australian Information Commissioner (OAIC).

​

9. Contact Us

​​​

​

​

​

​

​

​

​​

​

​

​

​

​​​​​​​​

10. Changes to this Policy

​

We may update this Policy from time to time to reflect changes in our practices, technology, or legal obligations. The current version will always be available on our website or on request. This Policy was last reviewed and approved on 31 August 2026

ll.png
bottom of page