Firstmac ×
Firstmac ×



Privacy Policy

Privacy & Credit Reporting Policy

April 2026

Our Privacy Policy is designed to provide you with general information about how we collect, store, use and disclose your personal information.

In this Privacy Policy, we, our, us or Firstmac means Firstmac Limited (ACN 094 145 963) and its related entities in the Firstmac Group (including but not limited to Firstmac Origination Pty Ltd, Firstmac Services Pty Ltd, Firstmac Mortgages Pty Ltd, First Mortgage Company Pty Ltd, Firstmac Asset Funding Pty Ltd and Firstmac Asset Funding (Commercial) Pty Ltd). The Firstmac Group offers a range of financial products and services across Australia.

We collect, use and disclose your personal information in accordance with the Privacy Act 1988 and all other relevant laws (Privacy Law) and this Privacy Policy. When you decide to acquire a product or service from us, we may provide you with further information about privacy in the form of a Privacy Statement or other form of privacy disclosure (Privacy Statement).

The Privacy Statement will give you specific information about how we will handle the personal information you have given to us. We may also seek your specific consent in relation to the collection, use or disclosure of your personal information.

What do we mean by 'personal information'?

The types of personal information we collect will depend on your relationship with us, such as whether you are a website or app user, customer, or another third party (such as a broker).

When you deal with us, we may collect personal information about or relating to you such as:

  1. our name, date of birth, contact details, nationality, marital status, gender, dependents;
  2. financial information such as your employment details, income, pay slips, bank account details, copies of bank statements and credit card statements from other financial institutions;
  3. credit information (see below);
  4. government related identifiers and documents such as tax file numbers, Medicare card, passport, licence details, citizenship, death and marriage certificates, occupation, residency and visa details;
  5. transaction information about transactions you make using our products; and
  6. details about your interactions with us, like phone calls and emails, as well as information about your use of our website or applications using cookies or other digital tracking technology.

Sensitive information is a subcategory of personal information. Sensitive information we may collect includes:

  1. health information (where relevant to a financial hardship claim);
  2. race or ethnicity (if we need to ask what language you speak for translation purposes);
  3. criminal history (if relevant to a regulatory requirement); and
  4. biometric identifiers, such as facial images used for identity verification.

What do we mean by ‘credit information’?

Credit information is a type of personal information about an individual.

We may collect the following kinds of credit information and exchange this information with credit reporting bodies and other entities:

  • credit liability information about your existing finance;
  • repayment history information, which is information about whether you meet your repayments on time;
  • information about the type and amount of finance that you are applying for;
  • financial hardship information (including information that any repayments are affected by a financial hardship arrangement);
  • default information (including overdue payments);
  • new arrangement information;
  • details of any serious credit infringements;
  • personal insolvency information;
  • publicly available information;
  • payment information; and
  • court proceedings information.

We also use the term ‘credit information’ to refer to credit eligibility information, which is credit reporting information supplied to us by a credit reporting body (‘CRB’), and any information that we derive from it.

Why do we collect your personal and credit information?

We collect personal and credit information for the purposes of assessing your application for finance and managing that finance, including in relation to complaints, serving you as a customer and improving our business.

As part of our ongoing legal obligations, we are required to collect and verify basic identity information and assess potential risks as part of our efforts to prevent money laundering, terrorism financing, and fraud.

We may also collect your personal information for the purposes of direct marketing and managing and personalising our relationship with you. From time to time, we may offer you other products and services. We will only use your personal information for direct marketing if we have a legal basis for doing so. You may opt out of receiving direct marketing communications from us at any time by using the unsubscribe facility provided or by contacting us.

We sometimes use your information (for example, your transaction and interaction summaries) to train and develop artificial intelligence models for purposes such as:

  • summarising your interactions with us, including your interactions on our online chat;
  • protecting you from fraud and scams; and
  • responding to your enquiries about our products and services and recording these interactions.

How do we collect your personal information?

We collect your personal information from you where it is necessary for our business functions and activities. You give us your personal information in a number of ways such as completing an application form or other website form, requesting a product or service over the phone or internet, or by visiting an office in person. We also collect personal information at other times during our relationship with you.

Do we collect your personal information from third parties?

Sometimes we may collect your personal information from other sources where necessary for our business functions or activities. Examples of where we may receive personal information about you from another source and why this may happen are:

  • a credit reference about you from a credit reporting body while assessing your application for a loan;
  • an authorised deposit holding institution such as Indue Ltd, who provides payment solutions;
  • your agent, where you have appointed an agent to act on your behalf in dealing with us, such as a broker, legal adviser or other third party representative;
  • as required or authorised by law, for example to government agencies, or regulatory bodies for purposes related to public health or safety or the prevention or detection of unlawful activities;
  • a third party to whom we have contracted to provide a financial service or product to our customers;
  • any external third parties where you have asked them to provide your personal information to us.

Who do we disclose your personal information to and receive personal information from?

The parties to whom we may disclose your personal information to and receive personal information from will depend on what product or service you receive from us. Some examples of the parties to whom we may disclose your personal information to and receive personal information from are:

  • associated companies to the Firstmac Group, including loans.com.au, carloans.com.au Pty Ltd, Infochoice.com.au Pty Ltd and YourMortgageBroker Pty Ltd;
  • an authorised deposit holding institution such as Indue Ltd, who provides payment solutions;
  • intermediaries, including your agent, adviser, a dealer, a broker, a representative acting on your behalf, our authorised representatives, advisers and our agents;
  • to a mortgage insurer to assess the risk of providing mortgage insurance or to assess the risk of default;
  • auditors, insurers and re-insurers;
  • government, law enforcement or statutory and regulatory bodies;
  • legal, finance and other professional advisers;
  • our service partners which included those who we partner with to provide our products and services such as external technology service providers, mailing houses, market research companies and cloud service providers;
  • trustees, custodians, managers and responsible entities associated with investments, managed funds, and superannuation;
  • organisations providing verification of your identity;
  • organisations and service providers that assist with identifying, preventing or investigating fraud, unlawful activity or misconduct;
  • debt collection agencies, organisations involved in valuing, surveying or registering a security property, or which otherwise have an interest in such property, purchasers of debt portfolios; and
  • in connection with funding financial accommodation by means of an arrangement involving securitisation, or any other proposed transfer of or proposed dealing with your loan.

Some of the parties with which we exchange your personal information, including our service providers and other third parties listed above, may be located outside Australia in countries including the Philippines, the US, the EU and the UK.

Automated Decision Making

We may use automated systems to make some decisions about you, including profiling. These systems assess personal information you provide to us, as well as information we receive from other sources such as credit reporting bodies and fraud prevention services. They help us understand your circumstances, assess risk, and identify potential fraud.

Our credit approval process relies on automated analysis of personal information provided by you and information received from credit referencing and fraud prevention agencies. These automated decisions can affect the products or services we offer you. For example, they may determine:

  • eligibility – whether we can offer you a loan, on what terms, and whether there are any indicators of
    fraud; and
  • affordability – the maximum loan amount we can responsibly provide (ie. the credit limit).

Credit information

If we have provided you with a financial product or service, we exchange your credit information with credit reporting bodies. We use the credit information that we exchange with the credit reporting body to assess your creditworthiness, assess your application for finance and manage your finance.

If you fail to meet your payment obligations in relation to any finance that we have provided or arranged or you have committed a serious credit infringement, then we may disclose this information to a credit reporting body.

You have the right to request access to the credit information that we hold about you and make a request for us to correct that credit information if needed. Please see the heading “How do you access and correct your personal information?” below.

Sometimes your credit information will be used by credit reporting bodies for the purposes of pre-screening direct marketing on the request of other credit providers. You can contact the credit reporting body at any time to request that your credit information is not used in this way.

You may contact the credit reporting body to advise them that you believe that you may have been a victim of fraud. In Australia, you can ask a CRB not to use or disclose your credit-related personal information for a period of 21 days without your consent if you believe on reasonable grounds that you are, or are likely to be, a victim of fraud, including identity fraud.

The credit reporting bodies we use are Equifax and Experian. You can download a copy of their privacy policies at https://www.equifax.com.au/privacy and https://www.experian.com.au/privacy-policy-terms-conditions.

You are entitled to obtain a free copy of your credit report from each CRB once every three months.

You can also request a free copy if:

  • you have been refused credit within the past 90 days; or
  • your credit-related personal information has been corrected.

Sometimes a CRB may charge a fee but it must not be excessive.

If you believe you may be a victim of fraud, you may also request that the CRB place a ban on your credit report to prevent them from being able to use or disclose the information as part of a credit check.

For more guidance on credit reporting and information on your rights, please visit CreditSmart at https://www.creditsmart.org.au/.

How do we verify your identity electronically?

We may ask you for your consent to verify your identity electronically in order to comply with our obligations under the AML/CTF Act. When you provide us with your consent to verify your identity electronically, we will provide your personal information to Equifax, a credit reporting body, and request that they provide us with an assessment of whether the personal information matches (in whole or part) the personal information held by Equifax. Equifax may prepare and provide a verification assessment to us, and may use the personal information provided by us, and the personal information held by them (including personal information of other individuals) to prepare the verification assessment.

Your personal information will be handled in accordance with the Privacy Law. When making a verification request, your personal information is “credit information” under the Privacy Act.

How do we keep your personal information accurate and up to date?

It is important that the information we hold is accurate and up to date. We ask that you contact us whenever there are any changes to your personal details, so that we can update our records.

How do you access and correct your personal information?

You may wish to contact us to access your personal information, to seek to correct it, delete it, to make a complaint about privacy or to manage your communication preferences.

If any of the personal or credit information we hold about you is incorrect, inaccurate or out of date you may request that we correct the information. If appropriate we will correct the personal information at the time of the request, otherwise we will provide an initial response to you within seven days of receiving your request. Where reasonable, and after our investigation, we will provide you with details about whether we have corrected the personal or credit information within 30 days. We may consult with other entities as part of our investigation. If we refuse to correct your personal information, we will provide a written notice including our reasons for our decision.

Generally, we do not impose a charge for access, but if permitted to do so by applicable law, we may charge you a reasonable fee for the retrieval costs associated with providing you with access.

What will happen if you do not provide your personal information to us?

If we request personal information about you and you do not provide it, we may not be able to provide you with the financial product or service that you request. In addition, if we are required to comply with certain legislation to provide you with the products and services you choose, then collection of certain personal information will be mandatory.

How safe and secure is the information we hold about you?

We take great care with the information we hold about you. Our aim is to ensure that any details are securely protected from misuse, loss, unauthorised access, modification or disclosure. We use various systems and services including technical and organisational measures to safeguard your personal information we store. This includes in storage and when we transfer or share it, such as across borders.

We maintain industry standard technology and procedures in respect to our information management and provision of online services, encryption techniques, virus protection and fire wall settings. If you make a transaction involving the submission of personal information over the internet to us using one of our online forms then we employ encryption technology to ensure the security of that personal information transmission. User identifiers, passwords or other access codes may also be used to control access to your personal information. Once we have received your personal information, it is stored and protected by a range of security controls, including firewalls, user identification requirements and audit trails.

What are 'cookies' and how do they work?

While browsing our websites, our server may automatically collect navigational data by placing "cookies" in your browser file on your hard drive. Cookies do not capture or track any personal information and cannot identify you as an individual. You may elect to not accept cookies on your browser. We may use third-parties to serve ads on our website. These companies may employ cookies and action tags (also known as single pixel gifs or web beacons) to measure advertising effectiveness. Any information that these third parties collect via cookies and action tags is recorded on an anonymous basis. Information regarding opting out of interest-based advertising is available at https://optout.networkadvertising.org/?c=1.

If you have a complaint

If you have a complaint about the handling, use or disclosure of your personal information, write to our Privacy Officer at the contact address below. We will investigate your complaint and advise you of the outcome as soon as possible. If the matter is not resolved to your satisfaction and you are located in Australia, you can then refer your complaint to the AFCA scheme, which can be contacted by phone on 1800 931 678, by email at info@afca.org.au, or in writing to GPO Box 3, Melbourne VIC 3001, or the Office of the Australian Information Commissioner, who can be contacted at Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001, website: www.oaic.gov.au.

More information and Contact Address

You can request further information about the way we manage the personal information that we hold, or make a complaint, by writing to:

Privacy Officer
Firstmac Group
GPO Box 7001
Brisbane QLD 4000
or email the Firstmac Privacy Officer at: customerrelations@firstmac.com.au

Does our Privacy Policy change?

We review our policies, statements and procedures to keep up to date with changes in the law, technology and market practice. As a result, we may update and change this Privacy Policy from time to time.

Welcome to firstmac.com.au _

Just in case we lose you, may I ask for your contact details....



Loading Form