Privacy Policy

How Blackcube Capital handles personal information.

This policy applies to our commercial lending and business finance services and website interactions.

Last updated: 25 July 2026

Who We Are

This privacy policy explains how BLACKCUBE CAPITAL PTY LTD trading as Blackcube Capital handles personal information when we provide commercial lending and related business finance services.

This policy is intended to describe, in a clear and accessible way, how we collect, hold, use and disclose personal information in connection with funding enquiries, business finance services, website interactions and ongoing client relationships.

What We Collect

Depending on how you deal with us, we may collect personal information such as your name, business name, job title, email address, phone number, ABN or ACN details, identification information, financial information, bank statements, trading history, funding requirements, director or guarantor details and correspondence with us.

We may also collect technical or website usage information, such as IP address, browser or device information and basic site interaction data, through our website, hosting environment or service providers.

When Reddit advertising measurement is enabled and you submit a public website enquiry, we may share a Lead conversion event with Reddit containing your email address, phone number, client IP address, browser user agent, screen dimensions, Reddit click identifier, Reddit pixel identifier, requested funding amount and a unique conversion identifier. We do not include your name, business name, ABN, turnover, funding purpose or free-text responses in that event. The browser and server copies use the same conversion identifier so Reddit can deduplicate them.

How We Collect It

We generally collect personal information directly from you when you submit an enquiry, complete a form, speak with us by phone, email us, provide supporting documents, or otherwise engage us to help arrange funding.

In some cases, we may collect information from third parties where reasonably necessary for our services, including lenders, introducers, professional advisers, publicly available registers, identity verification providers and other parties you authorise us to deal with.

ONIX Collection Notice

When you submit an ONIX application, Blackcube Capital collects the identity, contact, business, funding, credit-history, tax-position and existing-finance information shown on the form. We require this information to assess and progress your enquiry, communicate with you, prepare suitable options and meet our legal, fraud-prevention, security and record-keeping obligations. If required information is not provided, we may be unable to assess or progress the application.

If you arrive at ONIX through a campaign or advertisement, we may record allowlisted campaign details with the application, including UTM source, medium, campaign, term or content values, common advertising click identifiers, the ONIX landing path, the referring website hostname and the time captured. We do not retain arbitrary query strings or full referring URLs for this attribution. First-touch campaign attribution may be kept in first-party browser storage for up to 30 days so a later direct visit does not replace the original campaign.

We use service providers to operate ONIX, including Supabase for authentication, application data and private document storage, Vercel for website hosting and privacy-bounded product analytics, Resend for authentication email delivery, an external bank-statement provider and, if regional automated document scanning is configured, Cloudmersive. We may also disclose relevant application information to prospective lenders, funders and verification or professional-service providers where authorised or reasonably necessary to progress the enquiry.

We use non-identifying ONIX funnel events, such as application starts, step views, step completions, submission failures and successful submissions, to understand and improve the service and measure advertising performance. Advertising pixels are limited to public marketing and ordinary public application pages. Private login, authentication, admin and client-portal pages use only Vercel Analytics; ONIX removes query strings and fragments and replaces identifier-shaped URL paths before those analytics events are sent. These events do not include the applicant's name, email address, phone number, ABN, business name, funding answers or free-text responses.

When ONIX document uploads are enabled, accepted files are stored in a private Supabase bucket and remain quarantined while their recorded size and file signature are checked and a security review is completed. That review may be performed manually by authorised Blackcube Capital staff in a controlled local environment or, if configured, through an approved Australian or APAC Cloudmersive processing endpoint with no fallback to its global scanner. A file is unavailable as a ready client document until the review is approved. Files that fail type or security verification are rejected and removed; files awaiting review remain inaccessible in quarantine.

ONIX does not receive or store your bank-statement files. When statements are requested, you leave ONIX to complete the external statement-provider process; ONIX stores the provider link and timestamps showing when statements were requested, when you reported completion and when our staff recorded their review.

Authentication emails and ONIX application-stage, offer and outcome emails are automated. Statement and offer SMS messages may be prepared for staff to send manually. An email dispatch timestamp records a successful handoff to our email provider, not confirmation that the message reached or was opened in the recipient's inbox; an SMS dispatch timestamp may be a staff record of manual sending.

Why We Collect It

We collect, hold, use and disclose personal information so we can assess finance enquiries, understand your business circumstances, identify suitable commercial lending options, communicate with you, submit applications to lenders or funding partners, manage our relationship with you and comply with legal, regulatory and risk-management obligations.

We may also use personal information to improve our service delivery, maintain internal records, respond to questions or complaints and, where permitted, send relevant updates about our services.

Who We May Disclose It To

We may disclose personal information to lenders, non-bank funders, private credit providers, referral partners, aggregators, introducers, valuers, legal or accounting advisers, identity or verification providers, IT and cloud service providers, payment or communications providers, and our regulators or professional bodies where required.

We only disclose information where it is reasonably necessary for our commercial lending and business finance activities, to operate our business, or to comply with applicable laws and lawful requests.

Overseas Disclosure

Some of the service providers we use to operate our website, communications or internal systems may store or process personal information outside Australia. Where this occurs, we take reasonable steps to ensure those providers handle personal information in a manner consistent with the Australian Privacy Principles.

Direct Marketing

If permitted by law, we may send you updates about our services or related commercial finance information. You can ask us to stop sending marketing communications at any time by contacting us or using any unsubscribe option included in the communication.

Security And Retention

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps may include access controls, secure platforms, document management procedures and restricting access to people who need the information for legitimate business purposes.

We keep personal information for as long as reasonably necessary for our services, internal business purposes, dispute resolution, record-keeping and legal or regulatory obligations. When information is no longer required, we take reasonable steps to destroy it or de-identify it.

Access And Correction

You may request access to personal information we hold about you, and you may ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify your identity before responding, and in some cases the law may permit or require us to refuse access.

Complaints

If you have a privacy complaint, please contact us first using the details below and provide enough information for us to understand and investigate the issue. We will review the complaint and respond within a reasonable period.

If you are not satisfied with our response, you may be able to make a complaint to the Office of the Australian Information Commissioner.

Changes To This Policy

We may update this privacy policy from time to time to reflect changes to our business practices, technology, service providers or legal obligations. The latest version will be published on this page.

Contact Us

If you have any questions about this privacy policy or how we manage personal information, contact BLACKCUBE CAPITAL PTY LTD at daniel@blackcubecapital.com.au or +61 401 660 454.