Cover Captain ← Back to site

Your privacy

Privacy Policy

Last updated: 25 August 2026

This policy explains what personal information Cover Captain collects, why we collect it, who we share it with, and what control you have over it. It is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1.Who we are

Cover Captain is a business of [LEGAL ENTITY NAME] (ABN [ABN]), of [BUSINESS ADDRESS]. In this policy, we, us and our mean that entity.

We are a referral service. We are not an insurer, we are not an insurance broker, and we do not provide financial product advice. We introduce people who ask us to a licensed financial adviser, and we are paid a referral fee for doing so.

2.The information we collect

Information you give us

Information we collect automatically

3.Sensitive information

Health information is sensitive information under the Privacy Act and is subject to stricter protection. The nicotine question in our online check collects health information about you.

We collect it only:

You can withdraw your consent at any time by contacting us, though this will not undo a disclosure we have already made.

4.How we use it

5.Who we disclose it to

RecipientWhat they receive and why
A licensed financial adviser Your full enquiry, including your health answer, so they can contact you and discuss cover. Each enquiry is provided to one adviser only.
Hosting and infrastructure providers [e.g. Cloudflare] host our website and process form submissions.
SMS provider Twilio Inc. receives your mobile number so we can send your verification code.
Advertising platforms Meta Platforms receives event data, and in some cases a hashed (scrambled) version of your email or phone number, so we can measure which ads work. See section 8.
Others Professional advisers, or where disclosure is required or authorised by law.

Your enquiry is stored and routed to the adviser using lead management software that we built and operate ourselves. It is not a third-party service, so your details are not disclosed to anyone in that step.

We do not sell your personal information, and we do not disclose it for any purpose unrelated to your enquiry.

6.Sending information overseas

Some of the providers listed above store or process personal information outside Australia, including in the United States (our hosting provider, our SMS provider Twilio, and Meta Platforms). Before disclosing your information to an overseas recipient we take steps that are reasonable in the circumstances to ensure it is handled consistently with the Australian Privacy Principles, but you should be aware that overseas laws may differ from Australian law.

7.Direct marketing and how to opt out

We may send you emails or SMS about your enquiry and about our services. Every marketing message includes an unsubscribe link, and we will action it promptly.

The adviser we introduce you to will contact you about your enquiry using the consent you gave us. If you would prefer they did not, tell them, or email us at [PRIVACY EMAIL].

You can register your number on the Do Not Call Register. Note that consent you have given can still permit contact despite that registration.

8.Cookies, pixels and advertising

Our website uses cookies and similar technologies, including the Meta pixel. These set identifiers (such as _fbp and _fbc) that let us measure whether someone who saw one of our ads went on to complete the form.

We also send conversion events from our own server to Meta. Where we do, any contact details included are hashed before they are sent, so Meta does not receive them in readable form.

You can block or delete cookies in your browser settings, and you can manage ad personalisation in your Meta account settings. Blocking cookies may affect how parts of our site work.

9.Security and how long we keep it

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Information is transmitted over an encrypted connection and access is limited to people who need it.

We keep your enquiry and your consent record for [RETENTION PERIOD], which allows us to demonstrate that you consented. After that we destroy or de-identify it, unless we are required to keep it for longer.

No system is completely secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

10.Accessing and correcting your information

You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, or ask us to delete it. Email [PRIVACY EMAIL].

We will respond within a reasonable period, normally 30 days. We may need to verify your identity first. If we refuse a request we will tell you why in writing.

11.Complaints

Step 1 — tell us. Email [PRIVACY EMAIL] with the details. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

Step 2 — escalate. If you are not satisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

12.Changes to this policy

We may update this policy from time to time. The current version is always available on this page, and the date at the top tells you when it last changed.

13.Contact us

[LEGAL ENTITY NAME] (ABN [ABN])

[BUSINESS ADDRESS]

Email: [PRIVACY EMAIL]

Phone: [PHONE]