Privacy Policy

Last updated: 26 July 2026

In this Privacy Policy, "we", "us" or "our" means Walkable (walkable.com.au), operated by Sah Kilic. We are committed to respecting your privacy and handling your personal information responsibly.

This Privacy Policy sets out how we collect, use, store and disclose your personal information. It applies to all users of our website and services. By providing personal information to us, or by using our services, you consent to our collection, use and disclosure of your personal information in accordance with this Privacy Policy.

We may update this Privacy Policy from time to time by publishing changes on our website. We encourage you to check this page periodically.


1. What personal information do we collect?

We may collect the following types of personal information:

  • Account information — your email address, and optionally your name and phone number, when you create an account via Clerk (our authentication provider).
  • Address and location data — addresses you type into the search bar, addresses you save to your “Saved Places” list, and the geographic coordinates derived from those addresses.
  • Search history — up to five of your most recent address searches, stored to make re-searching convenient.
  • Starred points of interest — the names, addresses and coordinates of supermarkets, gyms or train stations you have starred within the app.
  • Usage preferences — non-identifying preferences such as your chosen travel mode (walking / cycling / driving) and rent display format (weekly / monthly).
  • Product analytics — page views and a small number of specific product events, collected through PostHog. Because a searched address appears in the page URL, that address is included in the page view we record. The events we send are: searching an area we don't cover yet, a suburb having no price data, opening the investor dashboard, interacting with a dashboard figure, and clicking an upgrade prompt. Some carry the suburb and state involved. These events are not linked to your account — we do not attach your user ID or email to analytics data.
  • Technical data — your IP address is processed when you call our address, amenity or transit endpoints, so we can rate-limit abuse and control third-party API costs. It is held in memory for that check only and is not written to our database. If the site hits an error, a diagnostic report (error message, stack trace, browser and page URL) is sent to our error-monitoring provider.

We do not collect: payment or financial information; health or sensitive information; government identifiers (e.g. Medicare number, Tax File Number); or advertising and cross-site tracking data. We do not sell your personal information, and we do not use it for advertising.

2. How do we collect personal information?

We collect personal information:

  • Directly from you — when you register an account, type an address into our search bar, or save a place or point of interest.
  • Automatically from your device — preferences (travel mode, rent period), saved places, starred locations and recent searches are stored in your browser's local storage when you interact with the service. This data stays on your device unless you are signed in, in which case it is also synced to our database so it follows you across devices.
  • Cookies and similar storage — our analytics provider (PostHog) sets a first-party cookie and a local-storage entry to recognise a returning browser across page views. Clerk sets a session cookie when you are signed in. We do not use advertising or cross-site tracking cookies.

3. Why do we collect, use and disclose personal information?

We collect and use your personal information to:

  • Provide the Walkable service — geocoding your address to show walkability results, nearby shops, gyms and transport.
  • Save and sync your preferences, saved places and starred locations across devices (for signed-in users).
  • Authenticate your identity and maintain the security of your account.
  • Improve and maintain the service — for example, caching recent search results to reduce API calls.
  • Understand how the service is used, so we know which features are worth building and which areas people want us to cover next.
  • Detect and fix errors, and rate-limit abuse of our endpoints to keep third-party API costs sustainable.
  • Comply with legal obligations.

We do not use your personal information for direct marketing, advertising, or to share with data brokers or marketing partners.

4. Disclosure to third parties

To provide our services, we share certain data with the following third-party service providers. Each is subject to their own privacy policy.

Mapbox (USA)

We use Mapbox for address geocoding, map display, address autocomplete and travel-time calculations. When you type an address or interact with the map, your query text and derived coordinates are transmitted to Mapbox servers located in the United States. Mapbox's services are subject to the Mapbox Privacy Policy.

Clerk (USA)

We use Clerk for account creation and authentication. Clerk collects your email address (and optionally name and phone number) and manages your session tokens on servers located in the United States. Clerk's services are subject to the Clerk Privacy Policy.

Supabase

We use Supabase as our database. It stores the saved places, search history and starred locations of signed-in users (keyed to your Clerk user ID), our suburb price and rent reference data, and a shared cache of address lookups. Supabase may store this data on servers outside Australia. Please refer to the Supabase Privacy Policy.

Google (USA) — transit routing only

When you request a detailed transit route (walking + public transport) from a saved place, we send the origin and destination coordinates to the Google Routes API for addresses outside NSW, proxied through our server. For NSW addresses, the same origin and destination coordinates are instead sent to the Transport for NSW Trip Planner API (see below) and Google is not contacted. No other data is sent to Google. Google's services are subject to the Google Privacy Policy.

Public Transport Victoria (Australia)

For Melbourne addresses, we query the PTV Timetable API with the coordinates of your searched address to display nearby train lines and tram stops. PTV is an agency of the Victorian Government and is subject to the Victorian Information Privacy Act 2000.

Transport for NSW (Australia)

For Sydney and NSW addresses, we query the Transport for NSW (TfNSW) Trip Planner API (api.transport.nsw.gov.au) with the coordinates of your searched address to find nearby stops and plan transit routes. TfNSW is an agency of the NSW Government and is subject to the NSW Privacy and Personal Information Protection Act 1998.

PostHog (USA) — product analytics

We use PostHog to understand how the service is used. It receives the page views described in section 1 — including the page URL, which contains a searched address when you have run a search — along with the specific product events listed there, and standard request metadata such as your IP address, browser and referring page. Data is processed on PostHog's United States infrastructure. We have automatic event capture switched off, so nothing is recorded beyond the page views and the named events. We do not send PostHog your email address or user ID, so analytics data is not connected to your account. PostHog's services are subject to the PostHog Privacy Policy.

Sentry (European Union) — error monitoring

We use Sentry to be told when the site breaks. When an error occurs, Sentry receives the error message and stack trace, the page URL (which may contain a searched address), and basic browser and operating-system details. Our Sentry project is hosted in the European Union. We have session replay and performance tracing switched off, and we have disabled Sentry's optional personal-data collection, so it does not attach your IP address or account details to reports. Sentry's services are subject to the Sentry Privacy Policy.

Vercel (USA)

Our website is hosted on Vercel. Vercel's infrastructure processes HTTP requests and retains platform-level logs (which may include IP addresses and user-agent strings) for operational purposes. We do not access or use these logs. Vercel's services are subject to the Vercel Privacy Policy.

5. Cross-border disclosure

As described above, some of your personal information is disclosed to recipients located outside Australia, including in the United States (Mapbox, Clerk, Google, PostHog, Vercel), the European Union (Sentry) and potentially other countries (Supabase). Transit data stays onshore: PTV and Transport for NSW are Australian government agencies. Before disclosing personal information to overseas recipients, we take reasonable steps to ensure those recipients handle the information in a manner consistent with the Australian Privacy Principles, including relying on contractual data-processing arrangements where available.

By using our services, you acknowledge and consent to your personal information being disclosed to these overseas recipients for the purposes described in this Privacy Policy.

6. How do we store and protect your information?

  • In-app (browser) — your preferences, recent searches, saved places and starred locations are stored in your browser's local storage on your device and are not encrypted at that layer.
  • Cloud database (Supabase) — saved places, search history and starred locations for signed-in users are stored in our Supabase database with encryption at rest. Access requires a valid Clerk authentication token.
  • In transit — all communications between your browser and our service, and between our service and third-party APIs, use HTTPS (TLS encryption).
  • Authentication — account access is managed by Clerk, which stores hashed credentials and manages session tokens.

Signing out of your account does not automatically clear data stored in your browser's local storage. You can clear this data by clearing your browser's site data.

7. Retention

  • Account data (Clerk) — retained until you delete your account.
  • Saved places, starred locations, search history — retained in our database until you delete them within the app or request account deletion.
  • Search cache — anonymised address lookup results are cached for 7 days and then automatically deleted. This cache is keyed by address, not by user, and is shared between all visitors.
  • Analytics events (PostHog) and error reports (Sentry) — retained under each provider's default retention period for our plan. Neither is linked to your account.
  • Rate-limit records — IP addresses used for rate limiting are held in server memory only and expire within a minute. They are never written to our database.
  • Vercel platform logs — subject to Vercel's own retention policy.

8. Your rights — access, correction and deletion

Under the Australian Privacy Principles, you have the right to:

  • Access your personal information — you can view your saved places, starred locations and search history within the app while signed in.
  • Correct your personal information — you can update or remove saved places and starred locations directly in the app. To correct your account details (name, email), use the Clerk account management interface.
  • Delete your personal information — you may request deletion of your account and all associated data by emailing us at privacy@walkable.com.au. We are building a self-service account deletion flow and will update this policy when it is available.

We will respond to access and correction requests within a reasonable time. We may ask you to verify your identity before providing access to or correcting your information.

9. Complaints

If you believe we have handled your personal information in a way that is inconsistent with the Australian Privacy Principles, please contact us at privacy@walkable.com.au. We will endeavour to resolve your complaint within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Contact us

For any privacy-related questions, access or correction requests, or complaints, contact us at:

Walkable
Email: privacy@walkable.com.au
Website: walkable.com.au

This Privacy Policy was prepared with reference to the Australian Privacy Principles contained in the Privacy Act 1988 (Cth). It does not constitute legal advice. We recommend seeking independent legal advice before making decisions based on this policy.