Privacy Policy
How Blackcube Capital handles personal information.
This policy applies to our commercial lending and business finance services and website interactions.
Last updated: 6 October 2026
Who We Are
This privacy policy explains how BLACKCUBE CAPITAL PTY LTD trading as Blackcube Capital handles personal information when we provide commercial lending and related business finance services.
This policy is intended to describe, in a clear and accessible way, how we collect, hold, use and disclose personal information in connection with funding enquiries, business finance services, website interactions and ongoing client relationships.
What We Collect
Depending on how you deal with us, we may collect personal information such as your name, business name, job title, email address, phone number, ABN or ACN details, identification information, financial information, bank statements, trading history, funding requirements, director or guarantor details and correspondence with us.
We may also collect technical or website usage information, such as IP address, browser or device information and basic site interaction data, through our website, hosting environment or service providers.
When Reddit advertising measurement is enabled and you submit a public website enquiry, we may share a Lead conversion event with Reddit containing your email address, phone number, client IP address, browser user agent, screen dimensions, Reddit click identifier, Reddit pixel identifier, requested funding amount and a unique conversion identifier. We do not include your name, business name, ABN, turnover, funding purpose or free-text responses in that event. The browser and server copies use the same conversion identifier so Reddit can deduplicate them.
When Meta advertising measurement is enabled and you submit a website enquiry from one of our Meta advertising landing pages, we may share a Lead conversion event with Meta containing your email address and phone number in hashed form, client IP address, browser user agent, Meta click and browser identifiers, the page address, requested funding amount and a unique event identifier. We do not include your name, business name, ABN, turnover, funding purpose or free-text responses in that event. The browser and server copies use the same event identifier so Meta can deduplicate them.
How We Collect It
We generally collect personal information directly from you when you submit an enquiry, complete a form, speak with us by phone, email us, provide supporting documents, or otherwise engage us to help arrange funding.
In some cases, we may collect information from third parties where reasonably necessary for our services, including lenders, introducers, professional advisers, publicly available registers, identity verification providers and other parties you authorise us to deal with.
Blackcube Capital Client Portal Collection Notice
When you submit a website enquiry or Client Portal application, Blackcube Capital collects the identity, contact, business, funding, credit-history, tax-position and existing-finance information shown on the relevant form. We also record how you would like personal follow-up to continue and, where supplied, your preferred callback timing. Providing a phone number does not by itself give us permission to call, with one limited exception: if you enter your name and mobile number in our quick enquiry form and leave before sending it, we save those details with the answers you had already given and may contact you to help you complete your enquiry. Those saved details are deleted automatically after 30 days. We require this information to securely prefill, assess and progress your enquiry, communicate with you, prepare suitable options and meet our legal, fraud-prevention, security and record-keeping obligations. If required information is not provided, we may be unable to assess or progress the application.
If you arrive at the Client Portal through a campaign or advertisement, we may record allowlisted campaign details with the enquiry or application, including UTM source, medium, campaign, term or content values, common advertising click identifiers, the landing path, the referring website hostname and the time captured. We do not retain arbitrary query strings or full referring URLs for this attribution. First-touch campaign attribution may be kept in first-party browser storage for up to 30 days so a later direct visit does not replace the original campaign.
We use service providers to operate the Blackcube Capital Client Portal, including Supabase for authentication, enquiry and application data and private document storage, Vercel for website hosting and privacy-bounded product analytics, Resend for authentication and application email delivery, Google Sheets as a transitional secondary destination for new website enquiries, an external bank-statement provider and, if regional automated document scanning is configured, Cloudmersive. We may also disclose relevant application information to prospective lenders, funders and verification or professional-service providers where authorised or reasonably necessary to progress the enquiry.
We use non-identifying Client Portal funnel events, such as application starts, step views, step completions, submission failures and successful submissions, to understand and improve the service and measure advertising performance. Advertising pixels are limited to public marketing and ordinary public enquiry pages. Private login, authentication, admin and client-portal pages use only Vercel Analytics; query strings and fragments are removed and identifier-shaped URL paths are replaced before those analytics events are sent. These events do not include the applicant's name, email address, phone number, ABN, business name, funding answers or free-text responses.
When Client Portal document uploads are enabled, accepted files are stored in a private Supabase bucket and remain quarantined while their recorded size and file signature are checked and a security review is completed. That review may be performed manually by authorised Blackcube Capital staff in a controlled local environment or, if configured, through an approved Australian or APAC Cloudmersive processing endpoint with no fallback to its global scanner. A file is unavailable as a ready client document until the review is approved. Files that fail type or security verification are rejected and removed; files awaiting review remain inaccessible in quarantine.
The Client Portal does not receive or store your bank-statement files. When statements are requested, you leave the portal to complete the external statement-provider process; the portal stores the provider link and timestamps showing when statements were requested, when you reported completion and when our staff recorded their review.
Secure-access emails and Client Portal application-stage, offer and outcome emails are automated for every contact preference, including online-portal-only. Personal follow-up for online-portal-only clients stays inside the portal. Statement and offer SMS messages may be prepared for staff to send manually for other clients, but no automatic SMS campaign is used. An email dispatch timestamp records a successful handoff to our email provider, not confirmation that the message reached or was opened in the recipient's inbox; an SMS dispatch timestamp may be a staff record of manual sending.
Why We Collect It
We collect, hold, use and disclose personal information so we can assess finance enquiries, understand your business circumstances, identify suitable commercial lending options, communicate with you, submit applications to lenders or funding partners, manage our relationship with you and comply with legal, regulatory and risk-management obligations.
We may also use personal information to improve our service delivery, maintain internal records, respond to questions or complaints and, where permitted, send relevant updates about our services.
Who We May Disclose It To
We may disclose personal information to lenders, non-bank funders, private credit providers, referral partners, aggregators, introducers, valuers, legal or accounting advisers, identity or verification providers, IT and cloud service providers, payment or communications providers, and our regulators or professional bodies where required.
We only disclose information where it is reasonably necessary for our commercial lending and business finance activities, to operate our business, or to comply with applicable laws and lawful requests.
Overseas Disclosure
Some of the service providers we use to operate our website, communications or internal systems may store or process personal information outside Australia. Where this occurs, we take reasonable steps to ensure those providers handle personal information in a manner consistent with the Australian Privacy Principles.
Direct Marketing
If permitted by law, we may send you updates about our services or related commercial finance information. You can ask us to stop sending marketing communications at any time by contacting us or using any unsubscribe option included in the communication.
Security And Retention
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps may include access controls, secure platforms, document management procedures and restricting access to people who need the information for legitimate business purposes.
We keep personal information for as long as reasonably necessary for our services, internal business purposes, dispute resolution, record-keeping and legal or regulatory obligations. When information is no longer required, we take reasonable steps to destroy it or de-identify it.
Access And Correction
You may request access to personal information we hold about you, and you may ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify your identity before responding, and in some cases the law may permit or require us to refuse access.
Complaints
If you have a privacy complaint, please contact us first using the details below and provide enough information for us to understand and investigate the issue. We will review the complaint and respond within a reasonable period.
If you are not satisfied with our response, you may be able to make a complaint to the Office of the Australian Information Commissioner.
Changes To This Policy
We may update this privacy policy from time to time to reflect changes to our business practices, technology, service providers or legal obligations. The latest version will be published on this page.
Contact Us
If you have any questions about this privacy policy or how we manage personal information, contact BLACKCUBE CAPITAL PTY LTD at info@blackcubecapital.com.au or call us.
