Security and Privacy
Ownstable is committed to the highest standards of security and privacy.
We partner with leading technology providers to ensure your financial and personal information is protected at every stage.
Ownstable works with trusted and regulated technology partners, employing rigorous security measures to keep your information safe and confidential.
-
OWNSTABLE does not store full credit card or bank account numbers.
Only masked details (for example, the last four digits of a card) and secure Zai-issued tokens are retained.
Even with database access, no one (including OWNSTABLE staff) can view or reconstruct full payment details.
Owners can add or change their own payment methods directly from the website at any time.
-
All OWNSTABLE data stays within Australia, hosted in Microsoft Azure’s Australian regions. These facilities provide redundancy, encryption, and continuous monitoring.
Images and documents are distributed through secure Azure services to ensure speed and reliability.
No personal or financial data is stored outside Australia.
-
Financial data is processed and secured through Zai Australia Pty Ltd, our regulated payment partner.
Zai is licensed and regulated in Australia under an Australian Financial Services Licence (AFSL 527370) issued by ASIC, the national financial-services regulator.
Your card details are handled in a PCI DSS Level 1 environment - the highest standard for card-payment security. Zai is also registered as a third-party agent with Visa and Mastercard, meaning they meet strict card-scheme compliance rules and undergo regular audits. For any cross-border transactions, Zai works with the Currencyfair Group, which is regulated by the Central Bank of Ireland.
Together, this ensures your payments are processed through a secure, audited, and fully regulated financial infrastructure.
All financial transactions are transmitted using strong encryption and stored securely within Microsoft Azure’s Australia-based data centres.
OWNSTABLE itself cannot view or access full credit card or bank account information at any time.
This ensures that your financial information always stays safe and private.
-
Payment information is collected and protected entirely by Zai Australia Pty Ltd, our PCI-certified payment partner.
OWNSTABLE uses Zai’s hosted payment fields, meaning credit card or bank details are entered directly into Zai’s secure environment - never passing through or being stored by OWNSTABLE systems.
We support PayTo, Direct Debit, and Credit Card payments.
OWNSTABLE only receives secure, non-sensitive tokens from Zai to reference your chosen payment method.
-
At the end of each month, OWNSTABLE calculates the total amount owed by each Owner based on all invoices issued up to the final day of that month.
A notification is sent by email and SMS shortly after month-end to let Owners know that a payment is scheduled. Two days later, a reminder is sent to confirm the upcoming deduction.
Payments are then securely processed on the fourth day of the month, or on the next business day if that date falls on a weekend or public holiday.
All transactions are processed through Zai, our PCI-compliant payment partner, and payment statuses are automatically updated within your OWNSTABLE account.
-
Your information is protected using the same security standards trusted by leading banks and enterprises.
Data is stored in Microsoft Azure’s secure data centres protected by enterprise-grade security controls
All information sent between your device and our servers is encrypted, so it can’t be read if intercepted
OWNSTABLE also limits who can access information internally - only authorised staff involved in essential operations may view non-sensitive data
We also use Azure’s built-in monitoring tools to detect and prevent any unusual activity
You can read more in our Privacy Policy, which explains how we collect, use, and safeguard your information.
-
Security is continuously monitored and regularly updated. OWNSTABLE proactively tracks system health, applies Azure’s automated security recommendations, and maintains up-to-date infrastructure patches.
We review our configuration and access controls on an ongoing basis to ensure alignment with current best practices and evolving threat landscapes.

