Skip to content
The Rock The Rock
Home Experiences Spaces Gallery Story Enquire
0458 378 738 [email protected] @the_rock_destination

Legal

Privacy Policy

Last updated 6 October 2026 · Master Key Destinations Pty Ltd · ABN 59 682 341 617

On this page

  1. Information we collect
  2. How we collect it
  3. How we use it
  4. Marketing
  5. Who we share it with
  6. Storage and overseas disclosure
  7. Security and how long we keep it
  8. Cookies
  9. Other websites
  10. Accessing and correcting your information
  11. Data breaches
  12. Complaints
  13. Changes to this policy

Your privacy matters to us. This policy explains what personal information we collect when you visit this website, make an enquiry, book or stay at The Rock, and how we use, store and protect it.

The Rock is operated by Master Key Destinations Pty Ltd (ABN 59 682 341 617) (we, us, our). We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Information we collect

We only collect personal information that we need to respond to you, run bookings and operate the property safely. Depending on how you deal with us, this may include:

Enquiries and viewing requests

  • your name, business or organisation, email address and phone number
  • where you are based, the type of programme you run and your typical group size
  • preferred dates, your website and social media handle
  • anything else you tell us about your programme

Bookings and stays

  • billing and contact details for the person or business making the booking (the Hirer)
  • arrival and departure dates, guest numbers and the services you request
  • payment records, such as amounts, dates and bank transfer references. We do not collect or store credit card numbers.
  • where you choose to share them, details such as dietary requirements, allergies, accessibility needs or an emergency contact. Some of this may be sensitive (health) information. We only collect it with your consent and only use it to look after guests during the stay.
  • insurance certificates and professional details that facilitators provide to us

Website visits

When you browse this website we record basic usage information so we can understand how the site is used and keep it secure:

  • your IP address
  • pages viewed, time spent on each page and how far you scroll
  • the website or campaign link that referred you
  • device type, browser, operating system and screen size
  • language setting, time zone and approximate location (state or country)
  • clicks on phone, email and social media links, and enquiry submissions

We collect this ourselves, on our own server. We do not use Google Analytics, advertising networks or tracking pixels.

Security cameras

For the safety of guests and the property, security cameras operate at the entries and exits of the buildings and in the parking area. Cameras are not used inside the house, bedrooms, bathrooms or wellness areas.

Communications

We keep records of emails, messages and notes of phone calls with you, including any feedback or testimonials you give us.

How we collect it

We collect personal information directly from you wherever we can: when you fill in a form on this website, email or call us, make a booking, or visit the property. Website usage information is collected automatically by our website when pages load.

Sometimes we receive information about guests from the Hirer who books on their behalf, for example a facilitator sharing participant numbers or dietary needs. If you give us information about other people, please make sure they know you are sharing it and have read this policy.

You can deal with us without identifying yourself when you are just browsing. We will need your name and contact details to answer an enquiry or take a booking.

How we use it

We use personal information to:

  • answer enquiries, arrange private viewings and prepare quotes
  • confirm, manage and invoice bookings, and receive payments
  • prepare the property and any services you request, and look after guests during their stay
  • keep guests, staff and the property safe, including responding to incidents
  • understand how people find and use our website so we can improve it
  • detect and prevent fraud, spam, misuse and security threats
  • send you information about The Rock that you may be interested in (see Marketing)
  • meet our legal, tax, insurance and accounting obligations

We will not use your information for a purpose you would not reasonably expect without your consent, unless the law allows or requires it.

Marketing

If you have enquired with us, booked with us or asked to hear from us, we may email you occasional news, availability and offers about The Rock. Every marketing email includes an easy way to unsubscribe, and you can also ask us to stop at any time by contacting us. We comply with the Spam Act 2003 (Cth).

We never sell, rent or trade your personal information.

Who we share it with

We only share personal information where it is needed for the purposes above. This may include:

  • service providers who help us run the business, such as website hosting and development, email, IT support, accounting and bookkeeping. They may only use the information to provide services to us.
  • service providers at the property you ask us to arrange, such as chefs, massage therapists or other practitioners, limited to what they need (for example dietary requirements)
  • the Hirer of a booking, where needed for guest safety or to manage the stay
  • our bank, insurers and professional advisers
  • emergency services where someone's health or safety is at risk
  • police, regulators or courts where required or authorised by law, for example security camera footage relating to an incident

Storage and overseas disclosure

Our website and booking records are hosted on servers located in Australia. Some of the services we use, such as email or online tools, may store or process information on servers overseas, including in the United States. Where that happens, we take reasonable steps to make sure those providers protect your information in a way that is consistent with the APPs.

Security and how long we keep it

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Our booking system is password protected, uses encrypted (HTTPS) connections and is only accessible to authorised people.

We keep information only as long as we need it:

  • Booking, invoice and payment records: 7 years, as required for tax and company records.
  • Enquiries that do not become bookings: generally up to 3 years after our last contact, unless you ask us to delete them sooner.
  • Website usage data, including IP addresses: 14 months, after which it is automatically deleted.
  • Security camera footage: overwritten automatically, usually within 30 days, unless it is needed to investigate an incident.

When we no longer need information, we securely delete it or de-identify it.

Cookies

Our website analytics do not use cookies. Visitors are recognised for one day only, using a code that cannot be used to identify you on other websites and is reset daily.

The only cookies this website sets are strictly necessary ones: a security cookie that protects our forms from misuse, and a sign-in cookie used by our staff when they log in to the booking system. We do not use advertising or third-party tracking cookies.

Other websites

Our website links to other sites, such as Instagram. When you follow those links, the other site's privacy policy applies, and we are not responsible for how it handles your information.

Accessing and correcting your information

You can ask for a copy of the personal information we hold about you, or ask us to correct it if it is wrong, out of date or incomplete. Contact us using the details below. We will respond within 30 days. We do not charge for making a request, though we may charge a reasonable fee for providing large amounts of information. If we refuse a request, we will explain why in writing.

You can also ask us to delete your information. We will do so unless we need to keep it by law, for example booking and tax records.

Data breaches

If a data breach is likely to cause serious harm to anyone affected, we will notify them and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.

Complaints

If you have a concern about how we have handled your personal information, please contact us first so we can try to put it right. We will acknowledge your complaint promptly and aim to resolve it within 30 days.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

Changes to this policy

We may update this policy from time to time. The latest version will always be on this page, with the date it was last updated. If a change significantly affects how we handle your information, we will let you know.

See also our Terms and Conditions.

Questions?

Contact Master Key Destinations Pty Ltd:

  • Email [email protected]
  • Phone 0458 378 738
  • Post PO Box 781 Coolangatta QLD 4225
The Rock

Private, exclusive-use hinterland retreat — 20 minutes from Gold Coast Airport — built for facilitators who host transformative work.

Enquire Call us

Explore

  • Experiences
  • Spaces
  • Gallery
  • Story

Host

  • Talk to us about your retreat
  • 0458 378 738
  • [email protected]
  • @the_rock_destination

Via

Master Key Destinations

Master Key Destinations Pty Ltd
PO Box 781 Coolangatta QLD 4225

© 2026 Master Key Destinations Pty Ltd · ABN 59 682 341 617PrivacyTerms Designed by InFront Tech Admin