AU Privacy Policy

Overview – the key information you should be aware of.

(A) Who we are: We are Openpay Pty Ltd. If you need it, our Australian Company Number (ACN) is 159 699 126 and our registered office is 15/520 Collins Street, Melbourne, Victoria, 3000.All references in this policy to “Openpay”, “our”, “us” or “we” refer to Openpay Pty Ltd, or our group companies, as appropriate. All references in this policy to “our website”, refer to the website owned by Openpay at https://www.opy.com/

(B) Our values and what this policy is for: We value your privacy and want to be accountable and fair to you as well as transparent with you in the way that we collect and use your personal information.

In line with these values, this privacy policy tells you what to expect when we collect and use personal information about you. We have tried to make it easy for you to navigate so you can find the information that is most relevant to you and our relationship with you.

We are always looking to improve the information we provide to our customers and contacts so if you have any feedback on this privacy policy, please let us know using our contact details in Section 13.

(C) Who this policy applies to: This policy applies to:

  1. Visitors to our website (e.g. a website browser);
  2. Our customers (both Consumer and Merchant applicants).


Depending on our relationship, we will collect and use your information in different ways. Please click on the links above to find out the information that we collect about you and how we use this information.

(D) What this policy contains: This privacy policy describes the following important topics relating to your information:

  1. How we obtain your personal information;
  2. Collection of your personal information and how we use it:
  3. Our legal basis for using your personal information;
  4. How and why we share your personal information with others;
  5. Credit Providers and Reporting Bodies;
  6. Your rights;
  7. Children;
  8. Marketing;
  9. Where we may transfer your personal information;
  10. Risks and how we keep your personal information secure;
  11. Links to other websites;
  12. Changes to this privacy policy; and
  13. Further questions and how to make a complaint;
  14. Meaning of words.


(F) What you need to do and your confirmation to us: Please read this privacy policy carefully to understand how we handle your personal information. By engaging with us in the ways set out in this privacy policy, you confirm that you have read and understood the entirety of this privacy policy, as it applies to you.

The detail – the key information you should be aware of.

1. How we obtain your personal information.

Openpay allows you to pay for a purchase in the instalments and frequency as is set out in your Openpay Plan.

1.1 You may provide us with your personal information (including credit information) voluntarily within our application form. We may also receive information about you from third parties such as marketing agencies, credit reference agencies, market research companies, our suppliers, group companies, public websites and public agencies, which we refer to as “third party sources” or “suppliers” throughout this policy.

1.2 You may give us personal information about yourself through our website, mobile applications, merchant portal, consumer portal, phone, email or by any other means through which you setup an account with us. This includes, for example, any circumstance where you provide your personal information to us in order to receive information or services from us.

2. Collection of your personal information and how we use it.

Please go to the section or sections below that best describes our relationship with you to find out the information that we collect about you and how we use this information. We refer to this as “personal information” throughout this policy.

2.1 Visitors to our website (e.g. a website browser)

(a) What personal information we collect about you

We, or third parties on our behalf, may collect and use any of the following information about you when you visit our website:

(i) information provided when you correspond with us;

(ii) any updates to information provided to us;

(iii) if you are a Merchant, we may also collect your name including your title, your postal address, your email address and your telephone number;

(iv) personal information we collect about you or that we obtain from our third party sources;

(v) the following information created and recorded automatically when you visit our website:

(A) Technical information. This includes: your device ID, the Internet Protocol (IP) address used to connect your computer to the internet address; the website address and country from which you access information; the files requested; browser type and version; browser plug-in types and versions; operating system; and platform. We use this personal information to administer our website, to measure the efficiency of our systems and to undertake an analysis on the locations from which people access our webpages; and

(B) Information about your visit and your behaviour on our website (for example, the pages that you click on). This may include the website you visit before and after visiting our website (including date and time), time and length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, traffic data, location data, weblogs and other communication data and information provided when requesting further service or downloads.

(b) How we use your personal information

We will collect, use and store the personal information listed above for the following reasons:

(i) to allow you to access our website;

(ii) to receive enquiries from you through the website about our business and services;

(iii) for improvement and maintenance of our website and to provide technical support for our website;

(iv) to ensure the security of our website;

(v) to recognise you when you return to our website, to store information about your preferences, and to allow us to customise the website according to your individual interests; and

(vi) to evaluate your visit to the website and prepare reports or compile statistics to understand the type of people who use our website, how they use our website and to make our website more intuitive. Such details will be anonymised as far as reasonably possible and you will not be identifiable from the information collected.

If you are a Customer, please see sections 2 for more details about how we use your personal information.

(c) A word about cookies

(i) Some pages on our website use cookies, which are small files placed on your internet browser when you visit our website. We use cookies in order to offer you a more tailored experience in the future, by understanding and remembering your particular browsing preferences.

(ii) Where we use cookies on our website, you may block these at any time. To do so, you can activate the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies), you may not be able to access all or parts of our website or to use all the functionality provided through our website.

2.2 Our customers (both consumers and Merchants, and including users of our App)

(a) What personal information we collect about you

We, or third parties on our behalf, may collect, hold and use any of the following information (including credit information and credit eligibility information) about you:

(i) your name;

(ii) your postal address;

(iii) your email address;

(iv) your telephone number;

(v) your date of birth;

(vi) your gender;

(vii) your credit card details;

(viii) your plan and repayment transaction records;

(ix) information provided when you correspond with us;

(x) any updates to information provided to us;

(xi) if you are an App user your location data if you opt-in to our service to make you aware of any Openpay locations near you;

(xii) information about the services we provide to you:

(A) information needed to provide the services to you;

(B) customer services information; and

(C) customer relationship management and marketing information;

(xiii) information you provide to help us provide you with improved service for example if we ask you to fill in a survey or questionnaire; and

(xiv) your credit file from third parties based on data given to us by you.

(xv) credit card balances and limits;

(xvi) default information and when the default has been paid;

(xvii) any new arrangements with us because of a default;

(xviii) information about your application for credit with us including the type and amount;

(xix) publicly available information;

(xx) any serious credit infringements;

(xxi) credit reporting information we obtain from credit reporting bodies including your credit score;

(xxii) any CP derived information about you which we derive from credit reports we obtain about you;

(xxiii) payment history with third parties; and

(xxiv) information that we require to identify customers, including as required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, which may include details or copies of passports or driver’s licences or utility bills or other documentary evidence of applicants’ identities.

(xxv) Your Australian Medicare information

(xxvi) Your Australian passport information

(xxvii) Your Australian driver’s license information

(b) How we use your personal information

We will collect, use and store the personal information (including credit information and credit eligibility information) listed above for the following reasons:

(i) to assess your credit risk in order to determine your individual credit limit and assess whether it is appropriate to agree to advance you the funds which you requested. This will involve automated profiling and decision-making and our algorithms will assess things such as your credit score (which will include information that you have provided to us, information that we may already hold and information provided by third parties such as Credit Reporting Bodies). Our automated systems will assess this information to predict behaviour and make decisions on your individual credit limit. If you have any accounts with us, then we may continue to use automated decision making when deciding whether to change your individual credit limit. If you disagree with the result or would like further information about this process then please feel free to contact us using the details set out in Section 13;

(ii) to ensure that you are age appropriate to receive our financial services;

(iii) to deal with any enquiries or issues you have about our services that you request from us, our app or our online consumer portal which helps you manage our services, and about our services;

(iv) to send you certain communications (including by email or post) about our services such as administrative messages (for example, setting out changes to our terms and conditions and keeping you informed about our fees and charges);

(v) if you have consented to us doing so, to contact you (including by telephone, SMS or post) with information about our services or the products and services of our suppliers which either you request, or which we feel will be of interest to you

(vi) to provide you with our services including taking the repayments on your purchases in accordance with the plan intervals that you have nominated;

(vii) where we collect your location data, we use this to make you aware of any nearby Openpay locations;

(viii) to carry out statistical analysis and market research on people who may be interested in our services;

(ix) if you have consented and it is in our legitimate interests for business development and marketing purposes, to contact you (including by telephone or post) with information about our services or the products or services of our suppliers which either you request, or which we feel will be of interest to you;

(x) if you are an individual, a sole trader or a non-limited liability partnership and if you have consented, to contact you by email with information about our services or the products and services of our suppliers which either you request, or which we feel will be of interest to you;

(xi) to assist you to avoid defaulting on your loan;

(xii) to recover overdue amounts you owe us where you have failed to meet your payment obligations to us; and

(xiii) to verify your identity for the purposes of the Anti-Money Laundering and Counter-Terrorism Financing Act.

(c) Source of personal information. We may receive some of your personal information from third parties, such as from Credit Reporting Bodies. For more information on Credit Reporting Bodies see section 5.

(d) Information we need to provide services to you. We need certain types of personal information so that we can provide services to you and perform contractual and other legal obligations that we have to you. If you do not provide us with such personal information, or if you ask us to delete it, you may no longer be able to access our services.

2.3 Whatever our relationship with you is, we may also collect, use and store your personal information (including credit information and credit eligibility information) for the following additional reasons:

(a) to deal with any enquiries or issues you have about how we collect, store and use your personal information, or any requests made by you for a copy of the information we hold about you. If we do not have a contract with you, we may process your personal information for these purposes where it is in our legitimate interests for customer services purposes;

(b) for internal corporate reporting, business administration, ensuring adequate insurance coverage for our business, ensuring the security of company facilities, research and development, and to identify and implement business efficiencies. We may process your personal information for these purposes where it is in our legitimate interests to do so;

(c) to comply with any procedures, laws and regulations which apply to us – this may include where we reasonably consider it is in our legitimate interests or the legitimate interests of others to comply, as well as where we are legally required to do so; and

(d) to establish, exercise or defend our legal rights – this may include where we reasonably consider it is in our legitimate interests or the legitimate interests of others, as well as where we are legally required to do so.

2.4 Further processing

Before using your personal information for any purposes which fall outside those set out in this section 2, we will undertake an analysis to establish if our new use of your personal information is compatible with the purposes set out in this section 2.

3. Legal basis for use of your personal information.

3.1 We consider that the legal basis for using your personal information as set out in this privacy policy are as follows:

(a) our use of your personal information is necessary to perform our obligations under any contract with you (for example, to perform our services in accordance with our terms and conditions) or

(b) our use of your personal information is necessary for complying with our legal obligations (for example, identifying you in accordance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)); or

(c) where neither (a) nor (b) apply, use of your personal information is necessary for our legitimate interests or the legitimate interests of others (for example, to ensure the security of our website). Our legitimate interests are to:

(i) run, grow and develop our business in accordance with our internal risk appetite;

(ii) operate our website and app;

(iii) carry out marketing, market research and business development; and

(iv) for internal group administrative purposes.

If we rely on our (or another person’s) legitimate interests for using your personal information, we will undertake a balancing test to ensure that our (or the other person’s) legitimate interests are not outweighed by your interests or fundamental rights and freedoms which require protection of the personal information.

3.2 We may process your personal information in some cases for marketing purposes on the basis of your consent (which you may withdraw at any time after giving it, as described below).

3.3 If we rely on your consent for us to use your personal information in a particular way, but you later change your mind, you may withdraw your consent within the consumer portal and we will stop doing so. However, if you withdraw your consent, this may impact the ability for us to be able to provide you with our services.

4. How and why we share your personal information with others.

4.1 We may share your personal information with our group companies where it is in our legitimate interests to do so for internal administrative purposes (for example, for corporate strategy, compliance, auditing and monitoring, research and development and quality assurance).

4.2 We will share your personal information with the following third parties or categories of third parties:

(a) credit Providers and Credit Reporting Agencies who provide us with your credit file and/or other information about your creditworthiness. For more information see Section 5;

(b) fraud prevention services, including fraud databases such as the Australian Financial

Crimes Exchange;

(c) identity matching services;

(d) ACI Red and other, similar companies who provide us with credit card fraud detection services;

(e) SMS gateways who use your mobile number to send text messages for mobile verification loops;

(f) our other service providers and sub-contractors, including payment processors, utility providers, suppliers of technical and support services, insurers, logistic providers, and cloud service providers;

(g) companies that assist in our marketing, advertising and promotional activities, such as the marketing automation platform dotdigital;

(h) analytics and search engine providers that assist us in the improvement and optimisation of our website such as Google analytics;

(i) debt collection agencies who provide us with debt collection and recovery services; and

(j) The merchant(s) where the purchase was made for the purpose of processing refunds and account reconciliation.

4.3 We will always ensure that any third parties with whom we share your personal information are subject to privacy and security obligations consistent with this privacy policy and applicable laws.

4.4 We will also disclose your personal information to third parties:

(a) where it is in our legitimate interests to do so including in particular to run, grow and develop our business:

(i) if we sell or buy any business or assets, we may disclose your personal information to the prospective seller or buyer of such business or assets;

(ii) if substantially all of our or any of our affiliates’ assets are acquired by a third party, in which case personal information held by us will be one of the transferred assets;

(b) if we are under a duty to disclose or share your personal information in order to comply with any legal obligation, any lawful request from government or law enforcement officials and as may be required to meet national security or law enforcement requirements or prevent illegal activity;

(c) in order to enforce or apply our terms of use, our terms and conditions for customers or any other agreement or to respond to any claims, to protect our rights or the rights of a third party, to protect the safety of any person or to prevent any illegal activity; or

(d) to protect the rights, property, or safety of Openpay, our staff, our customers or other persons. This may include exchanging personal information with other organisations for the purposes of fraud protection and credit risk reduction.

4.5 We may also disclose and use anonymised, aggregated reporting and statistics about users of our website or our goods and services for the purpose of internal reporting or reporting to our group or other third parties, and for our marketing and promotion purposes. None of these anonymised, aggregated reports or statistics will enable our users to be personally identified.

4.6 Save as expressly detailed above, we will never share, sell or rent any of your personal information to any third party without notifying you and, where necessary, obtaining your consent. If you have given your consent for us to use your personal information in a particular way, but later change your mind, you should withdraw consent within the consumer portal or by contacting us and we will stop doing so.

5. Credit Providers and Credit Reporting Bodies.


5.1 In accordance with section 4.2(a) of this document and as permitted by law, we may disclose and exchange credit information and credit eligibility information (including your credit worthiness or credit history) with credit reporting bodies (CRBs) and with other credit providers;

5.2 We exchange this credit information and credit eligibility information to:

(a) assess an application by you for credit and to notify CRBs and other credit providers of a serious credit infringement or default by you; and

(b) allow the relevant CRB to create and/or maintain accurate records in relation to you

5.3 We may disclose your information to any person reasonably necessary for the purposes of that person taking an assignment of your loan.

5.4 The CRB we use is Equifax Pty Ltd, whose privacy policy and contact details are set out at

https://www.equifax.com.au

5.5 We may disclose credit information and credit eligibility information we hold about you where required or permitted by law.

6. Your Rights.


6.1 You have certain rights in relation to your personal information. If you would like further information in relation to these or would like to exercise any of them, please contact us at any time. You have the following rights:

(a) Right of access. Subject to any exceptions in the Privacy Act, you have a right of access to any personal information (including credit eligibility information) we hold about you. To obtain access to your information, please contact us on the details provided below;

(b) Right to update your information. You have a right to request an update / correction to any of your personal information (including credit information and/or credit eligibility information) which we hold. You can do this by contacting us on the details provided below.

(c) Right to stop marketing: You have a right to ask us to stop using your personal information for direct marketing purposes. If you exercise this right, we will stop using your personal information for this purpose.

We will consider all such requests and provide our response within a reasonable period and in accordance with applicable laws. Please note, however, that we may refuse requests in certain circumstances, for example if giving access would be unlawful or giving access would have an unreasonable impact on the privacy of other individuals. If an exception applies, we will tell you this when responding to your request. We may request you provide us with information necessary to confirm your identity before responding to any request you make.

7. Children.


7.1 You must be aged 18 or over to purchase services from us. Our website and services are not directed at children and we do not knowingly collect any personal information from children.

7.2 If you are a child and we learn that we have inadvertently obtained personal information from you from our websites, or from any other source, then we will delete that information as soon as possible.

7.3 Please contact us if you are aware that we may have inadvertently collected personal information from a child.

8. Marketing.


8.1 We may collect and use your personal information for undertaking marketing by email, SMS, telephone and post.

8.2 We may send you certain marketing communications (including electronic marketing communications) if we have obtained your consent to do so.

8.3 If you wish to stop receiving marketing communications, you can contact us by email, unsubscribe using the link at the bottom of any marketing emails or via the consumer portal.

9. Where we may transfer your personal information.


9.1 Your personal information (including credit information and credit eligibility information) may be used, stored and/or accessed or otherwise disclosed by staff operating outside of Australia working for us, other members of our group or suppliers. These parties may not have an Australian link and may include entities located in the United Kingdom, Philippines, Israel, Ukraine, USA and Ireland. Further details on to whom your personal information may be disclosed are set out in section 4.

9.2 The third parties we use may be located in jurisdictions with privacy regimes which are not comparable to Australia. For the avoidance of doubt, in the event that an overseas recipient breaches the Australian Privacy Principles, that entity will not be bound by, and you will not be able to seek redress under, the Privacy Act.

9.3 If we provide any personal information about you to members of our group or suppliers which are located outside of Australia, we will take appropriate measures to ensure that the recipient adequately protects your personal information.

9.4 We work with a number of retailers, each with their own privacy policy. We will not be responsible or held liable for how your information is collected, managed, stored, accessed or disclosed by our retailers. Prior to purchasing goods and services you should read the retailers privacy policy to ensure that you are familiar with their information handling practices.

9.5 By providing your personal information to us, you consent to us disclosing your personal information to any such overseas recipients for purposes necessary or useful in the course of operating our business.

10. Risks and how we keep your personal information secure.


10.1 The main risk of our processing of your personal information is if it is lost, stolen or misused. This could lead to your personal information being in the hands of someone else who may use it fraudulently or make public, information that you would prefer to keep private.

10.2 For this reason, Openpay is committed to protecting your personal information from loss, theft and misuse. We take all reasonable precautions to safeguard the confidentiality of your personal information, including through use of appropriate organisational and technical measures such as maintaining a PCI DSS Level 1 compliant environment.

10.3 In the course of provision of your personal information to us, your personal information may be transferred over the internet. Although we make every effort to protect the personal information which you provide to us, the transmission of information over the internet is not completely secure. As such, you acknowledge and accept that we cannot guarantee the security of your personal information transmitted to our website and that any such transmission is at your own risk. Once we have received your personal information, we will use strict procedures and security features to prevent unauthorised access to it.

10.4 Where we have given you (or where you have chosen) a password which enables you to access your online account, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

10.5 Your personal information (including credit information and credit eligibility information) is stored electronically within secure environments and systems that are protected in controlled facilities.

11. Links to other websites.


Our website may contain hyperlinks to websites that are not operated by us. These hyperlinks are provided for your reference and convenience only and do not imply any endorsement of the activities of such third-party websites or any association with their operators. This privacy policy only applies to the personal information that we collect or which we receive from third party sources, and we cannot be responsible for personal information about you that is collected and stored by third parties. Third party websites have their own terms and conditions and privacy policies, and you should read these carefully before you submit any personal information to these websites. We do not endorse or otherwise accept any responsibility or liability for the content of such third party websites or third party terms and conditions or policies.

12. Changes to our privacy policy.


We may update our privacy policy from time to time. Any changes we make to our privacy policy in the future will be posted on our website and, where appropriate, notified to you by post or email. Please check back frequently to see any updates or changes to our privacy policy.

13. Further questions and how to make a complaint.


13.1 If you have any queries or complaints about our collection, use or storage of your personal information (including a complaint relating to any failure by us to comply with our obligations under the credit reporting provisions of the Privacy Act 1988 (Cth) or under the Credit Reporting Privacy Code), or if you wish to exercise any of your rights in relation to your personal information, please contact info@openpay.com.au and address your email to The Privacy Officer or call 1300 168 359. We will investigate and attempt to resolve any such complaint or dispute regarding the use or disclosure of your personal information.

13.2 If you are dissatisfied with the handling of your complaint, you may contact the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner

GPO Box 5218, Sydney NSW 2001

Telephone: 1300 363 992

Email: enquiries@oaic.gov.au

14. Meaning of words.


In this privacy policy, all terms defined in the Privacy Act 1988 (Cth) have the same meaning when used in this privacy policy.

The practices described in this privacy policy statement are current as of 17 May 2019.