TOSS AU Privacy Policy


Introduction

Toss Australia Pty Ltd (referred to as “TOSS AU,”we,” “us,” or “our”) is committed to protecting your privacy. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in handling your personal information. As an operator of a financial app in Australia offering services like money transfers, personal data management, and reward programs, we collect and use personal information to provide these services. In doing so, we promise to:

  • take steps to keep your information safe and confidential in accordance with this Policy;
  • only use your information for the purposes described in this Policy;
  • never sell your personal information; and
  • allow you to access, manage, or update your personal information and marketing preferences at any time.

This Privacy Policy explains what personal information we collect, how we use and disclose it, how you can access or correct your information, and how to make a privacy complaint. “Personal information” in this Policy means any information or opinion about you where you are identified or reasonably identifiable. By using our services or providing personal information to us, you consent to the collection, use, and disclosure of that information in accordance with this Privacy Policy and any applicable laws.

What Personal Information Do We Collect?

We collect various types of personal information in order to operate our services and fulfill legal requirements. The types of personal information we may collect include:

  • Identity Information: Name, date of birth, Gender, and identification details (such as nationality, country of residence, address, occupation, driver’s licence or passport numbers, and copies of identity documents) for verifying your identity.  
  • Personal and Contact Information: Personal and contact details like your name, date of birth, phone number, email address, and postal address.
  • Account Details: Information related to your accounts with us, such as your username or user ID, and password (which we will securely store).
  • Financial Information: Transaction details when you send or receive money using our services, including account numbers, transaction amounts, and recipient-related information (such as the recipient’s name, phone number, and account number). In addition, financial data that you choose to aggregate from other financial institutions through our app, including details of transaction and savings accounts, mortgage and personal loans, investment accounts, term deposits, insurance, foreign currency accounts, and credit cards, as well as related transaction histories, merchant information, and payment locations.
  • Device and Technical Information: Details about the devices and technology you use to access our app or website, such as device type, operating system, browser, IP address, GPS location information (collected solely for identity verification, anti-fraud monitoring, and compliance with anti-money laundering obligations), and other online identifiers or cookies (described further below).
  • Usage and Interaction Data: Information about how you use our app and services – for example, features you use, pages visited, links clicked, and transaction history. This also includes communication records (like customer support calls, emails, or chat logs) when you contact us or we contact you.
  • Sensitive Information (limited): In general, we do not actively collect sensitive personal information (such as information about your health, ethnicity, or criminal record) unless necessary. However, in certain cases we may collect biometric information – for example, a photo or video of your face for identity verification (facial recognition) as part of our onboarding/security process. We will only collect sensitive information with your consent or as otherwise permitted by law.
  • Other Information You Provide: Any other personal information you give us directly. For instance, if you respond to surveys, enter a promotion, refer a friend, or otherwise submit information to us, we will collect whatever information you choose to provide. If you provide us with personal information about someone else (for example, details of a payment recipient or a joint account holder), you must have their permission to do so and you should inform them of this Privacy Policy.

We aim to only collect information that is reasonably necessary for our functions or activities. If you choose not to provide certain information we request (or if you request to deal with us anonymously or under a pseudonym), we may not be able to provide you with our services or respond effectively to your needs. Due to the nature of our financial services and legal obligations (for example, anti-money laundering laws), it is generally impracticable for us to serve customers who are not identified to us.

How Do We Collect Your Personal Information?

Directly from You: In most cases, we collect personal information directly from you. You provide information to us when you create an account, fill in forms or application fields in our app, including before completing KYC or onboarding, use our services, communicate with us (such as via customer support inquiries, email, or social media), or respond to our surveys or promotions. For example, we obtain personal details during sign-up and identity verification, and we gather transaction information when you make a transfer or use other features.

Automatically from Your Use of Services: When you use our mobile app or website, we automatically collect certain technical and usage information through tools like cookies and similar technologies. This includes data such as your IP address, device type, operating system, browser settings, and activity logs (e.g., pages or screens you view, buttons you click). We use this information to understand how users interact with our services, to personalize your experience, and to maintain and improve our platform’s functionality and security. (See Cookies and Analytics below for more detail on how we use cookies.)

From Third Parties: In some cases, we may obtain personal information about you from third-party sources, such as:

  • Verification Services: We may use third-party identity verification providers or databases (for example, electronic document verification services) to confirm your identity or eligibility. These services might provide us with verification results or additional identity data as allowed by law.
  • Linked Financial Accounts: If you choose to connect external bank accounts or other financial services to our app (to use our personal data management features), we will retrieve information from those third parties with your authorization. For instance, through secure data-sharing mechanisms, we might collect your account balances, transaction history, or other financial data from external institutions that you link to TOSS AU.
  • Remittance: In the course of processing a remittance, we receive the recipient’s personal information through an intermediary service provider.
  • Marketing or Referral Partners: If you were referred to TOSS AU via a marketing promotion or partner, we might receive basic personal details from that third party (for example, your name and contact information) to facilitate the referral or honor a promotion. We only deal with such partners where they have confirmed that you consented to your info being shared with us.
  • Public Sources and Others: Where lawful, we may collect information from publicly available resources or government registers (for example, to verify information you provided or for fraud prevention). We might also receive information from credit reporting bodies or financial institutions for specific services (with your consent or as required by law).

If we receive personal information that we didn’t request (unsolicited information), we will determine if it is necessary for our purposes. If not, we will promptly destroy or de-identify that information, provided it is lawful and reasonable to do so. We will not keep unsolicited personal data unless it is relevant to our services or we are required to retain it.

Cookies and Analytics: We use cookies and similar tracking technologies on our website to enhance your user experience and analyze usage of our services. Cookies are small text files that are placed on your device by websites. They help us remember your preferences and understand how visitors use our site. For example, cookies enable features like keeping you logged in, and they help us gather aggregate data about site traffic (such as number of visitors, popular pages, and user location on a general level). This data collected via analytics is typically anonymous and does not identify you personally. You can control or disable cookies through your web browser settings (for example, you may choose to block or delete cookies). However, please note that if you disable cookies, some features of our website or services may not function properly. By using our site without disabling cookies, you consent to our use of cookies as described in this Policy.

How Do We Use Your Personal Information?

We collect and hold personal information about you so that we can effectively conduct our business and deliver the services you expect. We may use your personal information for purposes including:

  • Providing Services: To provide, operate, and maintain our services for you. This includes using your information to establish your account, enable transactions (such as processing payments or remittances), enable financial data aggregation and viewing, asset and spending management, and the display of insights (if you use our data aggregation features), and generally deliver the features of our app that you request.
  • Ongoing Account Management: To manage your relationship with us and meet your ongoing needs. For example, we use your contact information to communicate with you about account updates, transaction alerts, and service changes, and to provide customer support or respond to inquiries.
  • Verification and Security: To verify your identity when you sign up or as required (complying with “Know Your Customer” regulations), resume or pre-fill KYC or onboarding, and to protect against fraud, unauthorized transactions, money laundering or other illegal activities. Personal data is used in our fraud monitoring systems and security measures to ensure our platform remains safe and secure.
  • Improvement and Development: To review, analyse, and improve our products and services and KYC-related processes. We may use usage data and feedback to fix issues, enhance functionality, and inform the development of new features or products that better serve our customers’ needs.
  • Personalization: To personalize or tailor aspects of our services for you. For instance, we might use information about your usage and preferences to recommend new features, content, or promotions that are relevant to you.
  • Marketing and Offers: To provide you with information, offers, or promotions about our services or those of partners that we believe may interest you (in accordance with the Direct Marketing section below). For example, we may let you know about new features, special promotions, or rewards programs that you might benefit from.
  • Compliance and Legal Obligations: To comply with legal and regulatory requirements that apply to us and our services. This includes using certain data to fulfill our obligations under financial regulations (such as reporting to AUSTRAC for anti-money laundering), responding to lawful information requests, and maintaining records as required by law.
  • Complaints and Inquiries: To consider and address any concerns or complaints you raise with us. If you make a complaint about our services or privacy practices, we will use the relevant personal information to investigate and resolve your complaint and communicate with you about it.
  • Other Related Purposes: For other purposes that are related to the above and which would be reasonably expected in the context of your relationship with us. For example, uses related to one of the primary purposes above, or where you have otherwise consented. We will only use sensitive information for the purpose for which it was provided or a directly related purpose, unless you agree otherwise or the law permits an exception.

We will not use your personal information for purposes other than those outlined in this Policy unless: (a) you consent to the new use, or (b) it is required or permitted by law. If we ever need to use your information for a completely new, unrelated purpose, we will seek your consent or provide you with notice as required.

Direct Marketing

From time to time, we may use your personal information to send you marketing communications about our services or new products, or about services of third parties that we partner with (for example, promotions jointly offered with a partner bank or merchant). We may contact you for marketing via email, in-app notifications, SMS, phone, or other channels you have agreed to. We will only send you direct marketing: (i) with your consent, or (ii) if you would reasonably expect to receive such communications from us (for example, because you have signed up for our services), and in each case we will provide a simple way to opt out. Every marketing email or message from us will include an unsubscribe option (such as an “unsubscribe” link or instructions to opt out). If you have an online account with us, you may also adjust your communication preferences in your profile settings, or you can always opt out by contacting us. We will respect your choice and ensure you are not sent further marketing material if you opt out. Opting out of marketing communications will not affect your ability to use our services.

We do not share your personal information with third-party companies for their own marketing purposes unless you have expressly consented to that sharing. In other words, we will never sell or rent your personal details to other companies for marketing or advertising. We may share marketing communications from our partners within our own messages (for example, including a special offer from a partner in a newsletter), but those communications will come from us and will be under our control. If you consent to receive marketing from a third party that is facilitated through our platform, that third party’s privacy terms will apply to their use of your information.

Please note that transactional or service communications (such as payment confirmations, account alerts, etc.) are not considered “marketing” – you will continue to receive those as part of using our services, even if you opt out of marketing messages.

Who Do We Share Your Personal Information With?

We take your privacy seriously. We do not disclose your personal information to others except as needed to run our business or as required by law. The types of entities we might share personal information with include:

  • Our Affiliates: We may share your information with other companies within the TOSS group (for example, our parent company in Korea or any subsidiaries) as needed to provide our services and for internal administrative purposes. All group companies that receive your info will comply with this Privacy Policy and applicable privacy laws.
  • Service Providers and Partners: We use trusted third-party companies to perform certain functions on our behalf, and we might disclose necessary personal information to them for those purposes. This includes partners that facilitate the collection of CDR data, partners that verify recipient account information and process remittances, and other service providers as necessary. For example, we engage Zepto to support certain payment and verification services, and personal information may be shared with Zepto as required for these functions. You can review Zepto’s privacy policy here: https://www.zepto.com/privacy-policy 
  • Technology and IT service providers (such as cloud storage providers, data center or hosting companies, IT support and maintenance providers).
  • Payment and banking partners – for example, financial institutions or payment processors involved in processing your transactions, or banking partners enabling certain features.
  • Identity verification and compliance services – services that assist with customer identity checks, fraud prevention, transaction monitoring, and regulatory compliance.
  • Analytics and marketing services – companies that help us analyze data, improve our services, or deliver communications (including analytics tools, email/SMS delivery services, etc.).
  • Professional advisors – such as our lawyers, accountants, auditors, insurers, or other consultants who may need access to personal information to provide their services to us.

These service providers are only given the information necessary for them to perform the contracted service. They are not permitted to use your information for any other purpose and are bound to keep your details confidential and secure. We require our service providers to handle personal information in compliance with applicable privacy laws and this Policy.

  • Business Transfers: If we ever transfer or sell part of our business or assets, or in the unlikely event of a merger, acquisition, or insolvency, personal information may be disclosed to potential buyers, new owners, or their advisors as part of that process. In such cases, we would ensure that appropriate confidentiality arrangements are in place and that your information remains protected.
  • Legal and Regulatory: We may disclose personal information to regulatory authorities, government agencies, or law enforcement if required or authorized by law. For example, we might need to share information in response to a subpoena, court order, or a legally valid request (such as under anti-money laundering regulations). We may also share information to protect our rights or the rights, property, or safety of our customers or others, or to assist in the investigation of unlawful activity, suspected fraud, or security issues.
  • Your Consent or Direction: We will share your information with other parties if you direct or consent to us doing so. For instance, if you use a feature that explicitly asks to share data with a third party (such as a financial advisor or a partner service), or if you authorize a data transfer or an integration that requires sharing your details, we will do so with your consent. We may also disclose to any other person or entity that you have been informed of at the time of collection or otherwise, and you have agreed to the disclosure.

In any case of sharing, we will aim to disclose only what is necessary for the purpose at hand and ensure that the recipient will safeguard the information. Aside from the parties listed above, we will not give any other third parties access to your personal information unless it is required by law or we have your permission.

Do We Send Your Information Overseas?

Yes, some of the personal information we collect may be transferred and stored overseas. TOSS AU is part of a global company, and we engage certain service providers located outside of Australia. For example, we may share data with:

  • TOSS Headquarters in South Korea: As a subsidiary of a South Korean company, we may need to transfer some data to our parent company or related entities in South Korea (for reporting, technology support, or compliance purposes).
  • Service Provider Locations: Many of our third-party service providers may operate or store data overseas. Common locations for technology and cloud services include the United States and other countries. For instance, if we use an international cloud hosting service or an analytics provider, your data might be stored on servers in those countries. We only choose providers that meet strict security standards, but note that the countries involved may vary depending on our operational needs. (At present, likely countries include South Korea, the United States, and Germany, and possibly others in Europe or the Asia-Pacific region.)

When we transfer personal information outside Australia, we take reasonable steps to ensure the overseas recipient will handle the information in a manner consistent with the APPs and this Privacy Policy. For example, we may contractually require the overseas recipient to comply with Australian privacy standards, or we may ensure they are subject to privacy laws that offer similar protection. We will not send your data to a country unless one of the following applies: (a) the recipient is governed by privacy laws or binding schemes substantially similar to Australia’s (or we have otherwise ensured appropriate safeguards); (b) you consent to the transfer (after being informed that Australian protections may not apply); or (c) the transfer is otherwise permitted by law.

Important: If we transfer your personal information overseas at your request or with your consent, please understand that the overseas entity may not be bound by Australian privacy law. This means, for such transfers, we may not be accountable under the Privacy Act for any mishandling of your information by that overseas recipient. However, we will seek to minimize this scenario and will only proceed with an overseas transfer in this way if it is necessary and you have explicitly agreed.

How Do We Protect and Store Your Personal Information?

Security Measures: We understand the importance of keeping your personal information secure. We have implemented a range of technical and organizational security measures to protect your data from misuse, interference, loss, and unauthorized access, modification or disclosure. These measures include (but are not limited to):

  • Storing personal information on secure servers with access controls – only authorized personnel who need the information to perform their duties are able to access it. We segregate duties and limit employee access to data on a need-to-know basis.
  • Encryption of sensitive data during transmission and at rest, as appropriate, to prevent interception or unauthorized reading. For example, our app and website use HTTPS/TLS encryption to secure data in transit.
  • Requiring strong passwords and authentication for access to our systems. We enforce two-factor authentication for our internal systems and encourage it for user accounts where possible.
  • Regular security audits, monitoring, and testing of our systems to identify and address vulnerabilities. We log access attempts and have systems to detect and prevent suspicious activities.
  • Physical security controls for any office or data center environment where personal data may be stored – for instance, secure facilities and device management protocols.
  • Employee training and policies: Our staff are trained on privacy and security requirements, and we have internal policies to ensure that personal information is handled properly. Any employee who fails to comply with our privacy and security policies may face disciplinary action.

While we strive to protect your information, please note that no method of transmission over the internet or electronic storage is completely secure. However, we regularly review our security practices to adapt to new threats and to meet or exceed industry standards (such as encryption protocols and cybersecurity frameworks). If a data breach does occur that is likely to result in serious harm, we will notify you and the relevant authorities as required by law.

Storage and Retention: Personal information that we collect is generally stored in electronic form in secure databases. Any paper records (if generated) are kept in locked, secure areas. We retain personal information only for as long as necessary to fulfill the purposes we collected it for, including for any legal, accounting, or reporting requirements. For example, we might keep some transaction records for a number of years to comply with financial laws. When we no longer need your personal information for our business or legal purposes, we will take reasonable steps to destroy it or de-identify it.

How Can You Access and Correct Your Personal Information?

Accessing Your Information: You have the right to request access to the personal information we hold about you. To do so, please contact our Privacy Officer using the contact details in the section below. In order to protect your privacy, we will need to verify your identity before giving you access – for example, we might require you to make the request in writing and provide specific identification information. We will aim to respond to your request within 30 days as required by the Privacy Act. If for some reason we refuse access (for example, if giving access would unreasonably impact someone else’s privacy or if it would violate a law), we will provide you with written reasons for the refusal and inform you of any available review mechanisms. In general, we will grant access unless a specific legal exception applies.

Usually, there is no charge for an access request. However, if your request involves a significant amount of work (e.g., retrieving a large volume of data from backup archives), we may charge a reasonable fee to cover the cost of providing the information (such as staff time or photocopying). We will let you know in advance if a fee might apply, so you can decide whether to proceed. We will not charge for simply making the request or for correcting information.

Correcting Your Information: We take reasonable steps to ensure that the personal information we collect is accurate, up-to-date, and complete. If you believe that any information we hold about you is incorrect, incomplete, or not current, you have the right to request that we correct it. You can do this by contacting us with the details of the information to be corrected. Where reasonable, and after verifying your identity, we will correct the information as requested. If the data has been disclosed to a third party as part of our processes and the correction is relevant to them, upon your request we will also notify that third party of the correction within a reasonable time.

In the unlikely event we disagree with the change you have requested (for instance, if we believe the information we have is accurate), we will let you know our reasons. You then have the right to request that we attach a note to the information stating that you claim it is inaccurate, out-of-date, incomplete, or irrelevant. We will always respond to your correction requests and take reasonable steps to resolve any issues. Our goal is to maintain your information as accurate and up-to-date as possible, so we appreciate you keeping us informed of any changes (such as updated contact details).

How to Contact Us or Make a Privacy Complaint

We value your privacy and strive to address any concerns you have. If you: (a) have any questions or feedback about this Privacy Policy or our privacy practices, (b) want to access or correct your personal information, or (c) have a complaint about how we have handled your personal information, please contact us.

Contacting TOSS AU: The easiest way to reach us is by emailing our Privacy Officer at global-support@toss.im. You can also send your requests or complaints in writing to:

Privacy Officer, TOSS AU
 Email: global-support@toss.im

Please provide as much detail as possible about your question or issue. If you are making a complaint, include details such as what happened, when, and what you would like us to do. We will acknowledge receipt of your complaint and work to investigate and respond to you as soon as possible. We aim to resolve all complaints in a timely and fair manner. Our complaints handling process involves investigating the issue, addressing any problems in our processes or policies, and responding to you with the outcome and any actions we will take. We will typically respond to complaints in writing within a reasonable timeframe. If needed, we may get in touch with you to gather more information about your complaint.

If you are not satisfied with our response to your privacy query or complaint, you have the right to escalate the matter to an external authority. In Australia, you can contact the Office of the Australian Information Commissioner (OAIC). The OAIC is the independent regulator for privacy and can investigate complaints about the handling of personal information.

Contact details for the OAIC:

We encourage you to let us try to resolve the issue first, but you are free to contact the OAIC at any time.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal obligations. When we make changes, we will post the updated Policy on our website and change the “Last updated” date at the top or bottom of the Policy. If there are material changes that significantly affect your rights or how we handle personal information, we will take reasonable steps to notify you – for example, by email, by prominent notice on our app or website, or other means. We encourage you to check our website periodically to ensure you are aware of the most current Privacy Policy. Your continued use of our services after any update will constitute your acknowledgment of the amended Privacy Policy.