Simple Loyalty Privacy Policy
Effective date: 28 May 2026
Version: 1.0
Last updated: 28 May 2026
1. About this
Simple Loyalty Pty Ltd ABN 53 674 990 937 Including its trading Division Loyalty Worx ("Loyalty Worx", "we", "us", "our"). We operate digital loyalty card programs (the "Program") and provide related services to business customers and partner merchants.
This Privacy Policy explains how we collect, hold, use, disclose and protect personal information in accordance with the Privacy Act 1988 (Cth) (the "Privacy Act"), the Australian Privacy Principles ("APPs"), the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) and, where applicable, the Privacy (Credit Reporting) Code 2014.
This Policy is governed by the laws of New South Wales, Australia.
It applies to two groups, and where their treatment differs we say so:
- Loyalty Members , individuals or entities who enrol in the Program through our app, website, partner merchants or other channels (B2C);
- Loyalty Providers and Loyalty Merchants may companies, sole traders, partners, directors, employees, guarantors and contacts of organisations that hold a commercial account with us or participate in the Program as a merchant (B2B).
2. Personal information we collect
The categories of personal information we collect depend on how you interact with us.
2.1 Loyalty Members (B2C)
- Enrolment data: name, date of birth (for age verification and birthday offers), gender (optional), mobile number, email, residential or delivery address, preferred store/location.
- Account & loyalty data: member ID, digital loyalty card number, password (stored hashed), points balance, tier status, rewards earned and redeemed.
- Transaction data: purchase history at our and our partner merchants' outlets ,including SKU/product, basket value, store, date and time, payment method type (we do not store full payment card numbers ,see section 5).
- App, device and online data: IP address, device identifiers (IDFA/AAID), device type, operating system, app version, push notification tokens, crash logs, session data, and cookies and similar technologies (see section 9).
- Location data: where you opt in, approximate or precise location used for store-locator, geofencing and beacon-based offers. You can disable this in your device settings at any time.
- Communications and engagement data: your communication preferences, opens, clicks, redemptions, in-app behaviour and survey responses.
- Inferred data: customer segments, predicted preferences and lifetime value, churn risk, and other insights derived from your activity in the Program.
2.2 Loyalty Providers and Loyalty Merchants (B2B)
- Account application data: business name, ABN/ACN, trading address, contact persons, role/title, business email and phone.
- Identification and verification data for individuals associated with the business (directors, sole traders, partners, authorised representatives).
- Personal guarantee and credit information: where you provide a personal guarantee or apply for deferred payment terms, we collect identity information, financial information and credit-related information (see section 8).
- Trade referee information that you nominate, and information from publicly maintained registers (e.g. ASIC, PPSR).
- Transactional and account data: orders, invoices, payments, disputes and correspondence.
- Partner merchant data: for partner merchants, the data necessary to operate the Program at your locations (POS integration data, settlement details, redemption reporting).
2.3 Sensitive information
We generally do not seek to collect "sensitive information" as defined in the Privacy Act (including health, racial or ethnic origin, religious beliefs and similar categories).
We acknowledge that aggregated purchase history may indirectly reveal sensitive attributes (for example, health-related product purchases). We take the following steps:
- we do not deliberately profile Members on the basis of sensitive categories;
- where SKU data could disclose sensitive information, we either de-identify it for analytics or exclude it from personalisation; and
- if we ever need to collect sensitive information, we will do so only with your consent and where the collection is reasonably necessary for our functions or activities, consistent with APP 3.3.
3. How we collect personal information
We collect personal information in the following ways:
Loyalty Members:
- when you sign up to the Program through our app, website, a partner merchant or an in-store sign-up;
- when you use your physical or digital loyalty card, including through Apple Wallet or Google Wallet;
- through partner merchant point-of-sale systems when you earn or redeem points;
- through your use of our app and website (including cookies, SDKs and device APIs);
- when you contact us, respond to surveys, or participate in promotions or referral programs.
Loyalty Providers and Loyalty Merchants
- when you complete a Commercial Account Application Form or partner merchant onboarding;
- when you provide a personal guarantee or apply for deferred payment terms;
- from trade referees you nominate, credit reporting bodies, public registers (ASIC, PPSR, court records) and your own published sources;
- when you place orders, raise tickets or otherwise communicate with us.
Both: we collect information you give us in person, by phone, online, in writing, or through our apps.
If you do not provide the information we request, we may not be able to enrol you in the Program, fulfil orders, extend credit, or provide the services you have asked for.
3.1 Anonymity and pseudonymity (APP 2)
You may interact with us anonymously or under a pseudonym in limited circumstances ,for example, browsing our website or making a general enquiry. To earn and redeem points, hold a commercial account, or receive personalised offers, we need to identify you.
4. Why we collect, hold, use and disclose personal information
4.1 Primary purposes, Loyalty Members
- to register and administer your Program membership and loyalty card;
- to record purchases and accrue, hold and redeem points and rewards;
- to personalise offers, recommendations and content based on your purchase history and preferences;
- to send you Program communications, promotional content and service messages (subject to your preferences ,see section 6);
- to operate analytics, customer insights and reporting (including aggregated and de-identified reporting to partner merchants);
- to detect, investigate and prevent fraud, including fraudulent points accrual or redemption and account takeover;
- to provide customer support and handle complaints;
- to comply with legal obligations.
4.2 Primary purposes ,Loyalty Providers and Loyalty Merchants (B2B)
- to assess and onboard partner merchants and commercial accounts;
- to manage trade accounts, including ordering, billing, debt recovery and dispute resolution;
- to assess applications for deferred payment terms and to deal with guarantors;
- to register security interests on the Personal Property Securities Register;
- to conduct credit checks via credit reporting bodies and to manage credit-related dealings (see section 8);
- to provide reporting, settlement and operational support to partner merchants;
- to comply with legal and regulatory obligations.
4.3 Secondary purposes
We will only use or disclose personal information for a secondary purpose where:
- you have consented; or
- you would reasonably expect the secondary use, and it is related (or, for sensitive information, directly related) to the primary purpose; or
- the use or disclosure is otherwise permitted, required or authorised by or under Australian law.
4.4 Automated decision-making
Some Program features rely on automated processes ,for example, eligibility for offers, tier progression, fraud holds on redemptions, or segmentation for marketing. If a decision producing legal or similarly significant effects on you is made by substantially automated means, we will provide meaningful information about that processing on request and, where required by law (including the Privacy and Other Legislation Amendment Act 2024 reforms), disclose this in our policy and provide a means to request human review.
5. How we hold and protect personal information (APP 11)
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These include:
- encryption of personal information in transit and at rest;
- multi-factor authentication for our member app and administrative systems;
- role-based access controls and the principle of least privilege;
- fraud monitoring on points accrual and redemption;
- regular security testing, vulnerability management and staff privacy and security training;
- physical security controls for any paper records and our premises;
- incident response and business continuity processes; and
- contractual privacy and security obligations on our service providers.
We do not store full payment card numbers; payment processing is handled by PCI-DSS compliant payment service providers.
While we take these steps, no system is completely secure and you should also protect your own credentials. If you suspect any unauthorised access to your Program account, contact us immediately.
5.1 Retention and destruction (APP 11.2)
We retain personal information only for as long as we need it for the purposes set out in this Policy or as required by law. Indicative retention periods:
- Active Members: for the life of your Program membership;
- Lapsed Members: where there has been no Program activity for [] months/years, we will de-identify or destroy transactional and behavioural data, retaining only what we are required to keep by law;
- Business Customers: for the life of the commercial relationship, plus [] years to comply with tax, accounting, credit reporting and statute of limitations requirements (generally 7 years);
- Credit information: in accordance with Part IIIA of the Privacy Act and the CR Code;
- Marketing records and consent evidence: for as long as we rely on them, plus a reasonable period to evidence compliance.
You may ask us to close your Program account at any time (see section 10). On closure, we will de-identify or destroy your personal information except where retention is required or permitted by law.
5.2 Notifiable Data Breaches
We comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If we become aware of a data breach that is likely to result in serious harm to affected individuals and which is not remediated in time, we will notify the affected individuals and the Office of the Australian Information Commissioner ("OAIC") as required by law.
6. Disclosure of personal information
We disclose personal information only as described below.
6.1 Related entities and service providers
We disclose personal information to our related bodies corporate within the Simple Loyalty Pty Ltd group, and to service providers and contractors who help us run the Program and our business, including:
- cloud hosting and infrastructure providers;
- mobile app and analytics platforms (e.g. crash reporting, product analytics, attribution);
- customer data platforms and marketing automation providers (email, SMS, push notification, in-app messaging);
- mobile wallet providers (Apple, Google);
- payment processors and card-linked offer providers;
- identity verification, fraud prevention and anti-money laundering providers;
- credit reporting bodies and trade insurers (for B2B accounts);
- customer support, contact centre and survey providers;
- printers, mailing houses and logistics providers;
- professional advisers including legal, accounting and audit firms;
- debt collection agencies.
We require our service providers to handle personal information consistently with the APPs and this Policy.
6.2 Loyalty Providers and Merchants
Where Loyalty Members earn or redeem points at a Loyalty merchant, we share with that merchant the information necessary to operate the transaction (e.g. member ID, redemption details and limited transaction data). Loyalty Providers may also receive aggregated and de-identified Program reporting. Loyalty Providers are independent controllers of personal information they collect from you directly, and their own privacy practices apply to that information.
We do not sell Loyalty Member personal information to Loyalty Merchants for their independent direct marketing without your express consent.
6.3 Other disclosures
We may also disclose personal information where:
- you have consented (expressly or, where permitted, by reasonable inference);
- it is to a credit reporting body, your creditor, banker, financier, mortgage insurer or trade insurer in connection with your commercial account, guarantee or credit assessment;
- it is to a person involved in an actual or proposed dealing affecting some or all of our assets or business, on a confidential basis, limited to what is reasonably necessary for the transaction, and with personal information de-identified where practicable for due diligence purposes;
- it is required, authorised or permitted by or under an Australian law or court/tribunal order;
- it is reasonably necessary for one of the permitted general situations or permitted health situations in the Privacy Act; or
- it is to a law enforcement agency where we reasonably believe disclosure is reasonably necessary.
7. Direct marketing (APP 7, Spam Act, Do Not Call Register)
7.1 Our marketing
We may send you direct marketing about the Program, our products and services, partner merchant offers and related information by:
- email;
- SMS;
- push notification and in-app messages;
- post; and
- telephone (only where you have consented or where otherwise permitted).
Where we use your transaction history and inferred preferences to personalise offers, we will do so consistently with this Policy.
7.2 Opt-out
Every commercial electronic message we send will identify us as the sender and include a clear and functional unsubscribe option, as required by the Spam Act 2003 (Cth). You can also:
- update communication preferences in the member app preference centre;
- reply STOP to opt out of SMS marketing;
- click unsubscribe in any marketing email;
- disable push notifications in your device settings; or
- contact our Privacy Officer (see section 12).
We honour the Do Not Call Register Act 2006 (Cth) for any telemarketing.
7.3 Partner marketing
Where a partner merchant wishes to direct market to you using personal information sourced from us, we will only enable this with your express consent.
7.4 Sensitive information
We will not use sensitive information for direct marketing without your consent.
8. Credit reporting (B2B only)
Where you apply for a commercial account, deferred payment terms, or provide a personal guarantee, we may:
- collect credit information about you (and any related guarantor);
- disclose information to, and obtain credit reports from, credit reporting bodies; and
- exchange information with other credit providers, mortgage insurers and trade insurers.
Our handling of credit-related personal information is governed by Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code 2014. Our separate Credit Reporting Policy sets out the credit reporting bodies we deal with, the kinds of credit information we collect, and your rights ,including in relation to disclosures to overseas recipients and the notifications required by sections 21C and 21D of the Privacy Act. A copy is available free of charge on request or at [link].
9. Website, app, cookies and online tracking
We use cookies, software development kits (SDKs), pixels, device identifiers and similar technologies on our website and in our app to:
- keep you signed in and remember your preferences;
- understand how our website and app are used (product analytics, crash reporting, attribution);
- secure our services and detect fraud;
- deliver and measure marketing campaigns, including retargeting where you have consented; and
- where you opt in, provide location-based features such as store-locator, geofencing and beacon offers.
You can control cookies through your browser settings, control app tracking through your device's operating system permissions, and disable location services and push notifications in your device settings. Disabling some of these technologies may affect the functionality of the Program.
For logged-in Members, online activity may be linked to your member account.
10. Access, correction and account closure (APP 12 and APP 13)
10.1 Access
You can request access to the personal information we hold about you. For Members, the fastest way is the data download function in the member app. You can also contact our Privacy Officer (see section 12).
We do not charge a fee for making an access request. Any fee for giving access will not be excessive and will not apply to the request itself.
We may refuse access where the Privacy Act permits ,including where access would have an unreasonable impact on the privacy of others, the request is frivolous or vexatious, the information relates to existing or anticipated legal proceedings, or refusal is otherwise authorised or required by law. If we refuse access, we will give you written reasons (to the extent reasonable) and information on how to complain, including to the OAIC.
10.2 Correction
You can correct your profile directly in the member app, or contact us to request correction. We will take reasonable steps to correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading, including on our own initiative where appropriate.
If we have disclosed the information to a third party and you ask us to notify them of the correction, we will take reasonable steps to do so unless impracticable or unlawful. If we refuse to correct, we will give you written reasons and information on how to complain.
10.3 Closing your account
You may close your Program account at any time via the member app or by contacting our Privacy Officer. On closure, we will de-identify or destroy your personal information except where we are required or permitted by law to retain it.
11. Disclosure to overseas recipients (APP 8)
Some of our service providers (and the data centres they use) are located outside Australia. As a result, your personal information may be disclosed to recipients in:
United States, Ireland and Singapore [to be confirmed and updated based on actual data flows ,for example, hosting providers, marketing platforms, analytics and customer support providers].
Before disclosing personal information overseas, we take reasonable steps to ensure the overseas recipient does not breach the APPs, including by entering into contractual arrangements requiring privacy protections substantially equivalent to those under the Privacy Act. Under section 16C of the Privacy Act, we remain accountable for the acts and practices of overseas recipients in relation to personal information we disclose to them, subject to the exceptions in the Act.
12. Complaints and contact
If you have a question or complaint about how we handle your personal information, please contact our Privacy Officer:
- Email: [privacy@loyaltyworx.com.au]
- Post: Privacy Officer, Loyalty Worx, [street address], [suburb] NSW [postcode]
- In-app: Help → Contact Privacy Officer
We will acknowledge your complaint promptly and aim to provide a substantive response within 30 days. We will:
- listen to your concerns;
- investigate and discuss how we can resolve the matter; and
- where appropriate, put in place an action plan and improve our information handling procedures.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner:
- 1300 363 992
- oaic.gov.au
If your complaint relates to credit reporting, please refer also to our Credit Reporting Policy and your right to complain to a recognised external dispute resolution scheme.
13. Children
The Program is intended for individuals aged 16 and over. We do not knowingly collect personal information from children below that age without verifiable parental or guardian consent. If you believe a child has provided personal information to us, please contact our Privacy Officer and we will take steps to delete it.
We will comply with the Children's Online Privacy Code once it is in force.
14. Changes to this Policy
We may update this Policy from time to time. For material changes, we will notify you in advance through the member app, by email, or by other reasonable means, and (where required by law or by changes to existing data use) seek your consent. The current version, with the date last updated, will always be available on our website. Earlier versions are available on request.
15. Governing law
This Policy is governed by the laws of New South Wales, Australia. Nothing in this Policy limits any rights you have under the Privacy Act or other Australian privacy laws.