Camera Hire Privacy Policy

Effective 11 August 2026. This policy replaces all previous versions of the Camera Hire privacy policy.

1. Introduction

Camera Hire Group Pty Ltd (ABN 67 687 095 192) (“Camera Hire”, “we”, “us” or “our”) provides camera, lighting, grip and related production equipment for hire. This policy explains how we collect, hold, use and disclose personal information, and applies to visitors to camerahire.com.au, clients and their contacts, guarantors and nominated third parties (such as brokers or insurers), and anyone completing our online identity verification or Certificate of Currency process at verify.camerahire.com.au.

We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By providing personal information to us, including through our website, over the phone, in person, or through our online verification system, you consent to the collection, use and disclosure of that information as described in this policy.

2. Personal information we collect

The kinds of personal information we collect depend on your relationship with us, and may include:

  • Identity and contact details — name, business or trading name, postal and delivery address, email address, and phone numbers.

  • Identity verification information — copies of a government-issued identity document (such as a driver licence, passport or proof-of-age card), the data extracted from that document, and the outcome of our automated identity checks.

  • Financial and account information — confirmation that a payment card has been placed on file (not the card number itself — see section 7), account/credit terms, on-stop or credit-hold status, and billing and transaction history.

  • Certificate of Currency (insurance) information — where a specific booking requires proof of insurance, the insurer’s name, policy number, expiry date, and the types and limits of cover shown on your certificate.

  • Booking and rental information — equipment hired, booking and job reference numbers, delivery instructions, and equipment condition, loss or damage records.

  • Communications — emails, SMS messages, call notes and other correspondence with our staff.

  • Technical information — IP address, device and browser details, and cookies (see section 8).

We only collect identity documents and Certificate of Currency information where reasonably necessary for the purposes set out below.

3. How we collect personal information

  • Directly from you — through booking forms, over the phone, by email, in person, and through our online identity verification and Certificate of Currency links.

  • From CurrentRMS, our rental management system, which holds our authoritative booking and client records. Our verification and portal systems read from CurrentRMS but never write information back into it.

  • From Didit and Stripe, which return the outcome of an identity check or confirmation that a card is on file (see sections 5, 7 and 9 for what these providers actually receive).

  • From your organisation, where you are named as a contact, guarantor or nominated recipient on someone else’s booking.

  • Automatically, through cookies when you visit our website (see section 8).

4. Why we collect, hold, use and disclose personal information

We collect, hold, use and disclose personal information to:

  • assess, process and manage bookings and hire agreements, and provide the equipment and services you request;

  • verify identity, as a condition of certain bookings, to deter fraudulent hires and protect our equipment against loss or theft;

  • assess creditworthiness, apply account terms, and manage overdue accounts, including placing an account on stop;

  • confirm adequate insurance is in place where a hire requires a Certificate of Currency;

  • take payment, issue invoices, and manage billing and accounting;

  • communicate with you about bookings, deliveries, equipment returns and account matters;

  • recover equipment that is lost, stolen, or not returned, and investigate suspected fraud or pursue legal claims arising from a booking, including by engaging debt collectors, insurers, or law enforcement where appropriate;

  • comply with our legal, regulatory, insurance and accounting obligations;

  • operate and improve our business, including internal reporting and quality assurance; and

  • send you direct marketing, where you have not opted out.

We may refuse or cancel a booking where identity verification cannot be completed, is incomplete, or raises fraud concerns, or where a required Certificate of Currency is not provided.

5. Our identity verification system

For certain bookings — typically those involving higher-value equipment — we ask clients to complete identity verification before equipment is released, to protect our business and equipment against fraud, theft and loss.

  • How it works. We send you a secure, single-use link to a dedicated verification page (verify.camerahire.com.au). You provide your personal details, upload a photo of a government-issued identity document, and place a payment card on file via Stripe (section 7). The link expires automatically and can only be used once.

  • Automated document checking. Your identity document is sent to Didit, a specialist identity verification provider, which checks the document’s authenticity and returns a result — approved, declined, or requiring further review. A Camera Hire staff member always reviews the outcome before a final decision is made; an automated “declined” result is never treated as final or shown to you as a rejection. See section 9 for what Didit receives and its own security practices.

  • Storage and security. Identity documents are stored in an encrypted, private cloud storage bucket that is never publicly accessible. Documents can only be viewed by authorised staff who need access for booking or verification purposes, using a time-limited link, and every view is individually logged.

  • Retention. We retain identity verification records for the duration of our relationship with you and generally up to seven years afterwards, to meet legal, accounting, insurance and debt-recovery obligations, or until you validly request deletion and we are not otherwise required to retain it.

  • Your options. If someone else is better placed to provide a required document (for example, a broker or accounts team), you can forward the request to them directly from the verification page.

6. Certificate of Currency (insurance) requests

Separately from identity verification, for bookings that specifically require proof of insurance we may send a dedicated Certificate of Currency request. This is only sent where a particular hire requires it, not as part of every booking.

  • We collect the insurer’s name, policy number, expiry date, and types/limits of cover shown on the certificate you provide, along with the document itself, and this is used solely to confirm adequate cover and reviewed by our staff.

  • We may use an optional automated tool to pre-fill some of these details from your document (see section 9) — if unavailable, our staff simply enter them by hand, with no effect on your booking.

  • Your certificate is stored and access-logged the same way as identity documents (section 5), and you may forward the request to a broker, insurer or accounts contact instead.

7. Payment information

Card payments are processed by Stripe, a PCI-DSS compliant payment processor. Your card number and other sensitive card details are entered by you directly into Stripe’s own secure form and sent straight to Stripe — they are never transmitted to, or stored on, any Camera Hire server or database. We use Xero for invoicing and accounting, and import bank transaction data to reconcile payments against invoices.

8. Cookies and website analytics

Our website uses cookies to help it function and to help us understand visitor traffic and trends, so we can improve our site. You can disable cookies through your browser settings, though some parts of our website may not function correctly if you do so.

9. Overseas service providers and disclosure of personal information

We know some clients have concerns about personal information — particularly identity documents — being handled by service providers based overseas. We keep the number of overseas providers we use to a minimum, and each is given access only to the specific, limited information it needs — none has broader access to your Camera Hire account, booking history, or other records we hold. In detail:

  • Didit (identity verification) — receives only the image of your identity document, sent over an encrypted connection, solely to perform a single automated check at the time you upload it. It does not receive your booking history, payment information, or any other Camera Hire account details, and has no standing or ongoing access to your data. Didit maintains its own security program and privacy policy, independently of Camera Hire, which we have reviewed as part of engaging them as a provider — if you would like more detail on Didit’s own security practices, contact us and we can provide it, or you can review Didit’s published privacy and security information directly.

  • Stripe (payment processing) — receives your card details directly from you; as explained in section 7, this never touches Camera Hire’s own systems.

  • OpenAI — used only on the optional, non-essential Certificate of Currency auto-fill step described in section 6; only the single uploaded document is sent, for that one purpose, and this feature can be switched off entirely without affecting your ability to complete a booking.

  • Google — used to deliver transactional emails such as booking confirmations and verification links.

Our core systems — client database, booking records, and the identity and insurance documents described in sections 5 and 6 — are hosted on infrastructure located in Australia (Sydney), not overseas. We take reasonable steps, including contractual protections, to ensure every overseas provider we do use handles your information consistently with the Australian Privacy Principles, and we do not sell or otherwise disclose your personal information to any other overseas recipient.

10. How we protect your information

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including:

  • role-based staff access and mandatory two-factor authentication;

  • secure, encrypted session handling;

  • a full audit log of sensitive actions, including every occasion an identity document or Certificate of Currency is viewed by staff;

  • encrypted storage of identity and insurance documents in a private, non-public cloud bucket, hosted in Australia; and

  • regular review of who has access to our systems.

No method of storage or transmission is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach likely to result in serious harm, we will handle it in accordance with the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

11. Access, correction and complaints

You may request access to, or correction of, the personal information we hold about you by contacting us in writing using the details in section 14. We will respond within a reasonable time, may need to verify your identity first, and reserve the right to charge a reasonable fee where a request requires substantial time or resources to fulfil.

If you have a concern about how we’ve handled your personal information, contact us first so we can try to resolve it directly. If unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (www.oaic.gov.au, 1300 363 992).

12. Direct marketing

We may use your contact details to send you direct marketing about our products and services. You can opt out at any time by contacting us using the details below, or via the unsubscribe function in our marketing communications.

13. Children

Our services are not directed at children. Hire agreements require the hirer to be at least 18 years of age, and we do not knowingly collect personal information from children.

14. Changes to this policy and contact us

We may update this policy from time to time to reflect changes in our practices, systems, or the law. The current version will always be on our website, with the effective date above updated when changes are made.

Camera Hire Group Pty Ltd
ABN 67 687 095 192
Unit G2, Alexandria Industrial Estate, 46-62 Maddox St, Alexandria NSW 2015
Phone: (02) 8065 8195
Email: info@camerahire.com.au