1. About this policy
This Privacy Policy explains how RewardPay collects, holds, uses and discloses personal information about individuals in New Zealand, including customers, prospective customers, and individuals connected with a business customer (such as directors, owners, employees or authorised contacts) (you).
This policy applies to personal information collected in connection with RewardPay’s New Zealand operations, carried on by RewardPay (NZ) Limited (RewardPay, we, us or our), and is intended to meet our obligations under the Privacy Act 2020 and the Information Privacy Principles it sets out.
RewardPay does not offer credit, lending, or deferred payment products, and we do not collect, use or disclose credit information about you, or obtain reports from credit reporting agencies or commercial credit-worthiness providers, in connection with our New Zealand services.
2. Personal information we collect
Depending on your relationship with us, we may collect the following kinds of personal information:
- Identity information, such as your name, date of birth, and government-issued identification details;
- Contact information, such as your address, email address and telephone number;
- Financial and account information, such as bank account details and payment card numbers, to the extent needed to provide our payment services;
- Employment and business information, such as your employer or business name, and business role;
- Information about how you use our website, app and services, such as transaction history and usage data;
- Other information relevant to our services we provide; and
- Any other information you choose to give us, for example when you contact our support team.
We do not seek to collect information about your health, race, ethnicity, religious or political beliefs, or sexual orientation, and we ask that you do not provide such information to us. If you do provide it, we will handle it in accordance with this policy and the Privacy Act 2020.
We do not collect information from credit reporting agencies.
3. How we collect personal information
We usually collect personal information directly from you, for example when you:
- register for or use our website or app;
- apply to become a RewardPay customer or complete onboarding;
- contact our support or sales team by phone, email or online chat; or
- otherwise interact with us in person, by phone, by mail or online.
We may also collect personal information from third parties, such as our banking and payment partners, identity verification providers, loyalty partners, alliance/referral partners, fraud prevention and risk management providers, your employer where you are a nominated contact of a business customer, and publicly available sources and registers.
Where we collect personal information about you from a source other than you, we will take such steps as are reasonable in the circumstances to make you aware of the fact that we have collected the information, the purpose for which it was collected, the intended recipients of the information, our name and address, and your rights to request access to and correction of the information, unless an exception under the Privacy Act 2020 applies (for example, where notification would be impracticable, would prejudice the purposes of collection, or is not reasonably practicable in the circumstances).
4. Why we collect, hold and use your personal information
We request, collect, hold and use personal information for purposes including:
- verifying your identity, including to meet our obligations under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009;
- providing, operating and improving our products and services, and administering your account;
- processing payments and transactions you ask us to carry out;
- customer support, training and quality control;
- research and product development;
- detecting and preventing fraud, error and unlawful activity; and
- with your consent or where otherwise permitted, sending you marketing communications about products and services that may interest you (you can opt out of these at any time).
You do not have to provide us with your personal information. However, if you choose not to provide information we require, we may be unable to verify your identity, open or maintain your account, or provide some or all of our services to you.
5. Who we disclose personal information to
We may disclose personal information to:
- our banking, card scheme, loyalty and payment processing partners, to enable us to provide our services;
- professional advisers, including lawyers, accountants and insurers;
- service providers who help us operate our business, such as IT, fraud prevention, hosting and customer support providers;
- a person you have nominated to receive a payment or benefit through our services;
- regulators, law enforcement or government agencies, where required or authorised by law; and
- any other party with your consent.
We do not disclose your personal information to credit reporting agencies or commercial credit-worthiness information providers.
6. Sending information overseas
RewardPay is part of a group of companies headquartered in Australia, and some of the service providers referred to above may be located outside New Zealand, including in Australia. Before we disclose your personal information to a person or organisation outside New Zealand, we will take reasonable steps to ensure that:
- the recipient is subject to the New Zealand Privacy Act 2020 (for example, because it carries on business in New Zealand); or
- the recipient is subject to privacy laws that, overall, provide comparable safeguards to the Privacy Act 2020 (for example, RewardPay’s related entities in Australia are subject to the Australian Privacy Principles under the Privacy Act 1988 (Cth)); or
- the transfer otherwise fits within an exception under Information Privacy Principle 12, including that we have your express authorisation after informing you that the overseas recipient may not be required to protect your information in a way that provides comparable safeguards to the Privacy Act 2020.
7. Storage and security
We take reasonable steps to protect personal information we hold from loss, unauthorised access, use, modification or disclosure, including through the use of physical, technical and administrative safeguards.
We retain personal information for as long as reasonably necessary for the purposes described in this policy, or as required by law, and in accordance with our data retention policy.
In general, we retain identity verification records, transaction records and related account information for at least five years after the end of our business relationship with you or the date of the relevant transaction, as required by the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, and for longer where a longer period is required for tax, accounting, regulatory, insurance, dispute resolution or fraud prevention purposes.
When personal information is no longer required for any lawful purpose, we will securely destroy or de-identify it.
8. Access to and correction of your personal information
Under the Privacy Act 2020, you have the right to ask us for access to the personal information we hold about you, and to ask us to correct it if you think it is wrong. You may also withdraw any consent or authorisation you have given us in relation to your personal information (including for marketing), although this may affect our ability to provide our services to you. If you no longer wish to receive marketing communications from us, you can opt out using the unsubscribe function in any electronic marketing message, by changing your notification preferences in our app, or by contacting us. To make a request, please contact us using the details in section 9 below.
We will respond to your request within the timeframes required by the Privacy Act 2020, and there is no charge for making a request. In some circumstances we may need to withhold certain information, in which case we will explain why.
9. How to contact us or make a complaint
If you have a question about this policy, or wish to make a privacy complaint, please contact our Privacy Officer:
| RewardPay (NZ) Limited
ATTN: Privacy Officer
C/-RSM NEW ZEALAND
Level 2, RSM House
62 Highbrook Drive
East Tamaki 2013
Auckland |
support@rewardpay.co.nz
(ATTN: RewardPay (NZ) Limited’s Privacy officer)
|
We will investigate any complaint and aim to respond within a reasonable time. If you are not satisfied with our response, you have the right to complain to the New Zealand Office of the Privacy Commissioner:
Office of the Privacy Commissioner
Phone: 0800 803 909
Post: PO Box 10 094, Wellington 6140, New Zealand
Make a complaint to the Privacy Commissioner online
10. Cookies, analytics and similar technologies
Cookies
- Our website and app use cookies, pixels, software development kits and similar technologies to remember your browser or device, keep your account secure, remember your preferences, analyse traffic and usage trends, and measure the performance of our services and marketing.
- The information collected through these technologies may include your device type, operating system, IP address, advertising identifiers, the date and time of your use, and the website or advertisement that referred you. We may link this information to other information we hold about you.
Analytics
- We may use third party analytics and advertising platforms to deliver and measure online advertising. Those providers may set their own cookies and similar technologies, which are governed by their own privacy policies. You can manage cookies through your browser or device settings, although some features of our services may not work properly if you disable them.
Automated monitoring, fraud prevention and financial crime
- We use automated tools and systems to help protect RewardPay, our customers, merchants and partners. These systems assist with identity verification, fraud detection and prevention, transaction monitoring, cybersecurity, sanctions screening, AML/CFT compliance and risk assessment.
- We may analyse account activity, transaction behaviour and other information we hold to identify suspicious, fraudulent or unlawful activity, to investigate security incidents, to comply with our legal obligations and to protect the integrity of our services. Our systems may generate alerts, risk indicators or recommendations.
- Automated tools support, but do not replace, human judgement. Significant decisions affecting you, such as declining or suspending an account, are subject to review by appropriately authorised personnel. If a decision affecting you is made using information we hold, you may ask us for access to that information and ask us to correct it under section 8.
- Where permitted or required by law, we may disclose information relating to suspected fraud, criminal activity, sanctions breaches or other unlawful conduct to regulators, law enforcement agencies, financial institutions and other industry participants.
Payment, loyalty and transaction data
- To provide our payment and rewards services, we receive information about transactions you make, including from merchants, card schemes, banks and payment processors. This may include the amount, date, currency, merchant and category of a transaction, and information needed to calculate and apply rewards, cashback or other benefits.
- We use transaction information to process payments, calculate and deliver rewards, provide statements and support, detect fraud, meet our legal obligations, and analyse and improve our products and services.
- We may create aggregated or de-identified information from transaction data, which does not identify you. We may use and disclose aggregated and de-identified information for any purpose, including analytics, product development and reporting to partners.
- You can manage your preferences for marketing communications about reward offers at any time using the methods described in section 8.
Privacy breaches and security incidents
- No method of electronic transmission or storage can be guaranteed to be completely secure. If we become aware of a privacy breach or security incident involving personal information, we will investigate promptly and take appropriate steps to contain the incident, reduce any potential harm, assess its impact and prevent recurrence.
- Where a privacy breach has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by Part 6 of the Privacy Act 2020.
- You should take reasonable steps to keep your account credentials secure and notify us immediately if you become aware of any unauthorised access to your account or personal information.
11. Changes to this policy
We may update this policy from time to time. The updated version will be posted on our website with a revised “last updated” date.