Legal

Privacy Policy

Contents

1. About this policy

Squarepay Pty Ltd (ACN 159 307 150) provides payment infrastructure to Australian businesses. In this policy, “Squarepay”, “we”, “us” and “our” mean that company.

This policy explains what personal information we collect, why we collect it, who we give it to, and what you can do about it. It covers our website, our merchant portal, our APIs and any other dealings you have with us.

“Personal information” means what it means in the Privacy Act 1988 (Cth), which we call the Privacy Act. We must comply with the Privacy Act and with the Australian Privacy Principles set out in it, which we call the APPs. We must also comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and its rules, which we call the AML/CTF Act. That Act requires us to collect, check and keep certain information about you.

If we provide services to a business under a contract, that contract may require more of us than this policy does. Nothing here reduces those obligations.

2. Whose information we handle

We handle information about two groups of people. Which group you fall into affects what rights you have and who you should ask.

People at our business customers. If you apply for or use our services for a business, whether as a director, beneficial owner, signatory, administrator or developer, we collect your information directly and we decide how it is used. This policy covers that information in full.

Payers and payees. If a business uses our services to take money from you or pay money to you, we get your information from that business so we can process the payment. In that case we act on that business’s instructions. We use your information only to make and support the payment, and to meet our legal obligations.

If you are a payer or payee and you want your information corrected or deleted, start with the business you dealt with. That business holds the relationship with you and can instruct us. You can also contact us under clause 19. We will either help you or tell you which business can.

3. What information we collect

What we collect depends on who you are and which services you use. We collect only what we reasonably need for the purposes in clause 5.

Identity information. Your name, date of birth, home and postal address, email address and phone number. Also identifiers such as your driver licence, passport or Medicare card details. The AML/CTF Act requires us to collect and check this information. If a business will not complete identity checks, we cannot provide services to it.

Business and ownership information. Company, trust or partnership details, ABN or ACN, ownership structure, and who the directors, beneficial owners and authorised signatories are. The AML/CTF Act requires us to identify the people who ultimately own or control a business customer, even if those people never use our services themselves.

Financial and account information. BSB and account numbers, account names, PayIDs, PayTo agreement details, and the balance and settlement information for a Squarepay account.

Payment and transaction information. For each payment, the amount, date, reference and description, who was involved, which payment rail was used, and what happened, including returns, disputes, chargebacks and failures. For Confirmation of Payee, we process the account name you submit and the answer the receiving bank sends back.

Correspondence and support information. Records of your dealings with us by email, support ticket and portal message. We also keep recordings of phone calls where we have told you the call is being recorded.

Technical information. Your IP address, browser and device type, operating system, pages viewed, referring URLs and timestamps. For our APIs, which endpoints you call, how often, and what errors occur. Some of this is collected automatically. See clause 10.

We do not collect sensitive information, which the Privacy Act defines to include information about your health, biometrics, racial or ethnic background, political opinions, religious beliefs or sexual orientation. The only exceptions are if you consent or the law requires it. We do not use biometric or facial matching to check identity.

4. How we collect information

Where we can, we collect information directly from the person it is about. We also collect it:

  • from our business customers, when they apply, add users to an account, or send us payment instructions containing payer or payee details;
  • from payment infrastructure, including the banks involved in a payment, the New Payments Platform, and the operators of PayTo and PayID;
  • from identity, fraud and screening providers, who check identity documents, screen against sanctions and politically exposed person lists, and assess fraud risk;
  • from public sources, including the ASIC registers and the Australian Business Register; and
  • automatically, through cookies, server logs and analytics, when you use our website, merchant portal or APIs.

If we receive information we did not ask for and were not entitled to collect, we will destroy or de-identify it where the Privacy Act lets us.

5. Why we collect and use information

We collect, hold and use information so we can:

  • set up, check and run accounts, including customer due diligence when you join and while you remain a customer;
  • process, settle, reconcile and report on payments made using Direct Debit, PayTo, PayID and Confirmation of Payee;
  • investigate and fix failed payments, returns, disputes and chargebacks;
  • find, investigate and stop fraud, scams, money laundering, terrorism financing and other misuse of our services;
  • meet our AML/CTF Act obligations, including identifying customers, monitoring transactions and reporting to AUSTRAC;
  • follow the rules of the payment schemes we connect to, and the directions of the banks we work through;
  • support you, answer your questions and contact you about your account;
  • run, secure, test and improve our platform, including by analysing usage and fixing faults;
  • manage risk, recover money you owe us, and bring or defend legal claims;
  • tell you about our products and services, subject to clause 9; and
  • meet any other legal obligation that applies to us.

We may combine or de-identify information and use the result for analysis, reporting and product development. Once information can no longer reasonably identify anyone, it stops being personal information and this policy stops restricting how we use it.

We do not sell personal information.

6. Who we give information to

We give out personal information only where we need to for a purpose in clause 5. We may give it to:

Banks and payment infrastructure. Authorised deposit-taking institutions, the operators of the New Payments Platform, BECS, PayTo, PayID and Confirmation of Payee, and the banks we access those payment rails through. A payment cannot be made without giving the details to the banks involved.

Our business customers. If you are a payer or payee, we report the outcome of a payment back to the business that asked for it.

Our service providers. Identity checking, sanctions screening and fraud detection providers, cloud hosting, communications, analytics, support and customer relationship tools, and professional advisers including auditors and lawyers. They may use your information only to do work for us, and they must keep it confidential.

Regulators and law enforcement. AUSTRAC, ASIC, the Australian Taxation Office and the police, where the law requires or allows us to, or where we reasonably need to in order to help prevent or investigate a serious crime.

A buyer of our business. If Squarepay is involved in a merger, acquisition or sale of assets, we may give information to the people involved in that deal and their advisers, subject to confidentiality. If our ownership changes, this policy keeps applying until the new owner tells you what is changing.

7. Where we store information

We store and process personal information in Australia.

Everything we collect to provide payment services and to meet our AML/CTF Act obligations stays in Australia. That includes identity, business, financial, transaction and support records. We do not give any of it to anyone outside Australia.

The one exception is website and product analytics. Google Analytics and PostHog process usage data on servers in the United States. That data is only about how our website and merchant portal are used: pages viewed, events, rough location, and device and browser details. We set PostHog up to mask personal information before it is stored. Analytics data never includes payment data, identity documents or account details. See clause 10.

Before we give personal information to anyone overseas, we take reasonable steps to make sure they handle it in line with the APPs, usually by contract. People overseas are not themselves bound by the Privacy Act. If your information is mishandled overseas, you may have fewer ways to seek a remedy than you would in Australia.

8. How we check your identity

The AML/CTF Act requires us to check who our business customers are, and who owns or controls them, before we provide services. It also requires us to keep checking over time.

We usually check identity electronically, by matching the details you give us against independent data sources. We use Equifax Australia Information Services and Solutions Pty Limited to do this. Equifax tells us whether the details you gave match its records.

An electronic identity check is not a credit check. It is not a credit enquiry, it does not assess whether you are creditworthy, and it does not show up on your credit file as an application for credit.

Equifax explains how it handles your information in its credit reporting policy at equifax.com.au/credit-reporting-policy. You can contact Equifax on 13 8332 or at PO Box 964, North Sydney NSW 2059.

We will ask for your consent before we check your identity electronically. If you do not consent, or if the electronic check does not work, you can give us certified copies of your identity documents instead. If we cannot check your identity either way, we cannot provide the service.

9. Marketing and how to opt out

We may use your information to tell you about our products, features and services by email, phone or post, and through advertising on social media. We only do this where the law allows it.

You can opt out at any time. Use the unsubscribe link in any marketing email, or email us at privacy@squarepay.com.au. We will action your request promptly.

Opting out does not stop service messages. We will still send you notices about your account, payments, security and changes to legal terms, because you need them to use the service.

We do not send marketing to payers or payees whose information we only received in order to process a payment.

10. Cookies and website analytics

Our website and merchant portal use cookies and similar technologies to keep you signed in, remember your preferences, keep the services secure, and analyse how they are used.

We use two analytics tools:

  • Google Analytics, which reports on overall website traffic, including how visitors find our website and move around it.
  • PostHog, which reports on how the merchant portal is used. We set PostHog up to mask personal information before it is stored, so the record shows how a feature was used rather than who used it or what they typed.

Both tools process data outside Australia. See clause 7.

Most browsers let you block or delete cookies. Blocking them will not stop you reading our website. The merchant portal needs session cookies and will not work properly without them.

11. How we keep information secure

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, change and disclosure. Those steps include encrypting data in transit and at rest, role-based access controls, multi-factor authentication, network segregation, logging and monitoring, formal change management, staff training and confidentiality obligations, and regular review of our service providers.

No method of sending information over the internet is completely secure. We cannot guarantee the security of information you send us.

You are responsible for keeping your account credentials safe. You must use a strong, unique password, turn on multi-factor authentication, keep API keys secret, and replace any key that may have been exposed. Tell us straight away if you think someone has accessed your account without permission.

12. How long we keep information

We keep personal information only as long as we need it for a purpose in clause 5, or as long as the law requires. We then destroy or de-identify it.

The AML/CTF Act requires us to keep identity records for seven years after our business relationship with you ends, and transaction records for seven years after the transaction. We keep other records for as long as we need them for the purpose we collected them for, plus any extra time needed for tax, accounting, disputes or legal claims.

This means we cannot delete your transaction or identity records if you ask us to before those seven years are up.

13. Data breaches

We have a data breach response plan. If a breach happens that is likely to cause serious harm, we will tell the people affected and the Office of the Australian Information Commissioner, which we call the OAIC. Part IIIC of the Privacy Act requires this.

If a breach affects information we received from a business customer, we will tell that business as well, so it can meet its own obligations.

14. How to see and correct your information

You can ask us for a copy of the personal information we hold about you. You can also ask us to correct it if it is wrong, out of date, incomplete, irrelevant or misleading. Email privacy@squarepay.com.au.

We will ask you to prove who you are before we give you anything. We will respond within 30 days. Access is free, though we may charge a reasonable fee if you ask for a large volume of records. We will tell you about any fee before you incur it.

We can refuse access in the limited situations the Privacy Act allows. For example, we can refuse if giving access would unreasonably affect someone else’s privacy, or if it would reveal a suspicious matter report or harm an investigation into fraud or crime. The AML/CTF Act also stops us telling you about any report we have made to AUSTRAC. If we refuse, we will tell you why in writing and explain how to complain, unless the law stops us.

If you are a payer or payee, see clause 2 first.

15. How to make a complaint

If you think we have breached the APPs or otherwise mishandled your information, email us at privacy@squarepay.com.au. Give us enough detail to investigate.

We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If we need longer, we will tell you why and keep you updated.

If you are not happy with our response, you can complain to the OAIC:

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

16. Children

Our services are for businesses and are not aimed at children. We do not knowingly collect information from children, unless it reaches us inside a payment instruction from a business customer. If we find we hold a child’s information without a lawful basis, we will delete it.

17. Other websites

Our website and documentation link to websites run by other people. This policy does not apply to those websites, and we are not responsible for how they handle your information. Read their privacy policy before you give them anything.

18. Changes to this policy

We may change this policy from time to time. The current version is always at squarepay.com.au/privacy. If a change materially affects how we handle your information, we will take reasonable steps to tell you beforehand.

19. How to contact us

For any privacy question, request or complaint, contact our Privacy Officer:

We will respond within the times set out in clauses 14 and 15.