Privacy Policy

This privacy policy (the Privacy Policy) applies to Paytime Services Pty Ltd ACN 647 450 137, and its affiliates and related companies (together, Paytime, we, us or our). It explains how we collect, hold, use, disclose and protect personal information, including personal information collected through our websites, mobile applications, email, cloud-based services, and any widgets we embed in third-party platforms with a link to this Privacy Policy (Websites). Paytime is bound by the Privacy Act 1988 (Cth) (Privacy Act), including the Australian Privacy Principles (APPs) in Schedule 1, the Notifiable Data Breaches scheme, and the amendments made by the Privacy and Other Legislation Amendment Act 2024. This policy is published to satisfy our obligations under APP 1. By personal information we mean information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not and whether it is recorded in a material form or not. Personal information does not include information that has been effectively de-identified. Our third-party suppliers and commercial partners (our Partners) are independent of Paytime and have their own privacy practices. We are not responsible for their handling of personal information. Where our Websites contain links to third-party sites, those sites are not under our control and this Privacy Policy does not apply. We may amend this Privacy Policy from time to time. The current version is always available on our Website and the date at the top of this policy will be updated. Where changes are material, we will give you reasonable advance notice by email or in-product notification before they take effect.

Minor Employees (under 18 years of age)

Where you are under 18 years of age, your employer has authorised your access to Paytime Services and has done so on the basis that the collection, use and disclosure of your personal information for the purposes described in this Privacy Policy is necessary to provide Paytime Services to you as part of your employment. Your employer’s authorisation of your access represents an additional basis on which Paytime collects and uses your personal information. We will not send direct marketing communications to employees we know to be under 18 years of age. If you are unsure how your personal information is handled, please contact your employer or our Privacy Officer at the details in section 14.

1. What personal information we collect and why we collect it

The table below sets out the categories of personal information we usually collect, examples of what each category includes, and the purposes for which we collect, hold, use and disclose that information. We will not use your personal information for a purpose other than one of these primary purposes (or a closely related secondary purpose you would reasonably expect) unless you consent, or we are required or authorised by law to do so.
Category of information Examples Purpose(s) of collection
Identity & contact Name, date of birth, address, geolocation, phone, email, government identifiers where required Establishing and administering your Paytime account; verifying your identity; meeting AML/CTF obligations; preventing fraud.
Employment & payroll Employer name, position, employment status, salary, leave balances, payroll/HRIS records Calculating your accrued earnings; reconciling withdrawals against your pay cycle; processing transactions; responding to your employer in connection with Paytime Services.
Financial Bank account details, transaction history, fees, repayments Processing transactions; collecting fees; producing transaction records; investigating disputes; meeting record-keeping obligations.
Device & usage IP address, device identifiers, OS, browser type, pages visited, in-app activity, security/fraud signals Operating, securing and improving the Websites and Paytime Services; detecting and preventing fraud and unauthorised access.
Marketing preferences Subscription status, channel preferences, engagement with our communications Sending service updates and (where you have not opted out and are 18 or over) marketing communications; measuring effectiveness of our communications.
Job applicants & supplier staff Name, contact details, position, CV/work history, referee information (applicants only) Assessing your application for employment with Paytime; managing commercial relationships with suppliers and Partners.
Support & complaints Correspondence with our support team, records of phone calls, complaint and dispute records Responding to your enquiries; handling complaints and disputes; improving our products and customer support.
If you do not provide some of the information described above, or we cannot verify it, we may be unable to provide you with Paytime Services, verify your identity, comply with our legal obligations, or otherwise do business with you.

2. Sensitive information

Some of the information we collect (for example, government identifiers, biometric information used in an identity check, or health information provided in support of a hardship request) is sensitive information under the Privacy Act. We collect sensitive information only where it is reasonably necessary for one of our functions or activities and either you have consented, or the collection is required or authorised by law. We will not use or disclose sensitive information for any purpose other than the purpose for which it was collected, unless you consent or an exception in the Privacy Act applies. Where you are under 18 years of age, Paytime collects sensitive information on the additional basis of the employer authorisation described in the Minor Employees section above.

3. How we collect personal information

We collect personal information in the following ways:
  • Directly from you, when you sign up for Paytime Services, use our Websites or app, contact our customer support team, respond to a survey, enter a competition, apply for a job with us, or otherwise communicate with us.
  • From your employer or their payroll/HRIS provider, where you have authorised Paytime to receive your employment and payroll information to provide Paytime Services.
  • From publicly or commercially available sources, where necessary to comply with our legal obligations.
  • From social media or other third-party accounts you choose to link to your Paytime account. What we receive depends on your privacy settings with that third party.
  • Automatically, when you use our Websites or app, through cookies, pixels, log files and similar technologies (see section 13).

4. How we use personal information

We use personal information for the specific purposes set out in section 1. In summary, we use personal information to: Provide, administer, secure and improve Paytime Services and the Websites;
  • Process the transactions you request and produce records of those transactions;
  • Verify your identity, including under AML/CTF laws;
  • Communicate with you about your account, including service notices and responses to your enquiries;
  • Send you marketing where you have not opted out and are 18 or over (see section 12);
  • Detect, investigate and prevent fraud, misuse and other unlawful activity;
  • Conduct analytics to understand how Paytime Services are used and to improve them;
  • Consider you for employment with Paytime, if you have applied for a role;
  • Comply with our obligations under applicable laws, court orders and regulator requests; and
  • Defend or exercise our legal rights.

5. Automated decision-making

Paytime uses automated processes (for example, rules-based fraud monitoring and identity verification scoring) to support some decisions about the Paytime Services we provide to you. These automated processes inform human decision-makers; they are not, on their own, used to make decisions that significantly affect your rights or interests. From 10 December 2026, the Privacy and Other Legislation Amendment Act 2024 will require us to publish additional information about any automated decision-making that significantly affects individuals’ rights or interests (new APP 1.7). We are reviewing every decision in the Paytime Services pipeline and will update this section by that date.

6. How we share personal information with other parties

We may disclose personal information to:
  • Our affiliates and related companies, for the purposes described in section 1;
  • Our Partners, suppliers and service providers who help us run our business (for example, identity verification, fraud prevention, payment processing, hosting, analytics, communications and customer service providers) who are contractually required to handle your information consistently with this policy;
  • Your employer and their payroll/HRIS provider, where necessary to deliver Paytime Services or to resolve a complaint;
  • Financial institutions we partner with to jointly create or offer a product;
  • A purchaser or successor entity, in connection with an actual or proposed merger, acquisition, financing or sale of all or part of our business;
  • Law enforcement, regulators, courts or other government agencies, where required or authorised by law;
  • Other third parties where we reasonably believe disclosure is necessary to prevent physical harm or financial loss, or to investigate suspected breaches of our terms; and
  • Any other third party with your consent or at your direction.

7. Disclosure of personal information overseas

Your personal information is stored on Amazon Web Services infrastructure located in Sydney, Australia. Some of our service providers are located in, or may access information from, countries outside Australia, including the United States, the United Kingdom, the European Union, the Philippines and India. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the APPs, either through contractual commitments or because the recipient is bound by a substantially similar privacy regime. Where you have consented to a disclosure, or where the disclosure is required or authorised by Australian law, the additional accountability under APP 8.1 may not apply. We will tell you about any new categories of overseas recipient before we begin disclosing to them.

8. Data retention and deletion

We retain personal information only for as long as we need it for the purposes in this policy, or as required by law. We are required by laws including the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the Corporations Act 2001 (Cth) and tax laws to retain certain transaction and identity records for up to seven years after the end of your relationship with us. When personal information is no longer needed and we are not required to retain it, we will destroy it or de-identify it as soon as reasonably practicable. You can ask us to delete your personal information at any time using the contact details in section 14.

9. How we protect personal information

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, consistent with APP 11.3 as amended by the Privacy and Other Legislation Amendment Act 2024. Our technical measures include:
  • Encryption of personal information in transit (TLS) and at rest;
  • Hosting on Amazon Web Services infrastructure in Sydney, Australia;
  • Multi-factor authentication and least-privilege access controls for staff;
  • Logging, monitoring and alerting for unauthorised or unusual access;
  • Regular vulnerability scanning and security testing of our applications.
Our organisational measures include:
  • Privacy and information-security training for staff;
  • Documented information-security policies, incident response and data-breach response procedures;
  • Contractual privacy and security obligations on our service providers;
  • Periodic review of our security controls against current threats and good industry practice.

10. Notifiable data breaches

Paytime is bound by the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth). If we have reasonable grounds to suspect that an eligible data breach has occurred – that is, an unauthorised access to, disclosure of, or loss of personal information likely to result in serious harm – we will:
  • Promptly contain the incident and take steps to mitigate the risk of serious harm;
  • Assess the suspected breach as soon as practicable, and in any event within 30 days;
  • If we conclude that an eligible data breach has occurred, notify the OAIC as soon as practicable;
  • Notify each affected individual as soon as practicable;
  • Where direct notification is not practicable, publish the breach statement on our Website.
You can read more about the NDB scheme at oaic.gov.au/privacy/notifiable-data-breaches.

11. Your privacy rights

11.1 How to make a request

You can ask us, at any time, to give you access to the personal information we hold about you, to correct it, or to delete it. You do not need to use any particular form, but the following information helps us respond quickly:
  • Your full name and the email address or phone number associated with your Paytime account;
  • A brief description of what you are asking for;
  • Where relevant, the corrected information or the specific records you are interested in.
We may need to verify your identity before we act on the request. We will use the least intrusive method of verification reasonably available.

11.2 How to send the request

Email: info@paytime.com.au (preferred) Phone: 1300 80 49 60 (Australia) Post: Privacy Officer, Paytime Services Pty Ltd, PO Box H317, Australia Square NSW 1215 Our Privacy Officer is responsible for responding to privacy requests and complaints. Please put Privacy request in the subject line of any email.

11.3 What you can ask for, and how we respond

What you can ask for How we will respond
A copy of the personal information we hold about you (APP 12) We will acknowledge within 7 days and give you access within 30 days. We will not charge you to make the request.
Correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13) We will acknowledge within 7 days and correct the information, free of charge, within 30 days.
Deletion of your personal information We will delete or de-identify when no longer needed, unless required by law to retain it. We will tell you what we can delete and what we must keep.
A statement attached to your record if we refuse to correct your information We will tell you why in writing. On your request, we will associate a statement with the record noting your view.
A refusal explained We will give you written reasons (except where giving reasons would itself be unreasonable), and tell you how to complain.

11.4 If you are not satisfied – our complaints process

If you think we have breached the Privacy Act or the APPs, or you are unhappy with how we have handled your personal information, please contact us at info@paytime.com.au or write to the Privacy Officer at the postal address above.
  • We will acknowledge your complaint in writing within 7 days of receipt.
  • We will investigate and respond substantively within 30 days.
  • If our response does not resolve your concerns, you can ask us to escalate the matter.
If you are still not satisfied, you can complain to the OAIC:

11.5 Other avenues

Since 10 June 2025, individuals also have a statutory cause of action for serious invasions of privacy under Schedule 2 to the Privacy Act. We encourage you to raise concerns with us first so we have an opportunity to put things right.

12. Marketing communications

We may send you marketing material about Paytime products, and the products of our Partners, using the contact details you have provided. We will not send direct marketing communications to employees we know to be under 18 years of age. You can opt out at any time by using the unsubscribe link in the message, updating your marketing preferences in your Paytime account, or contacting us at support@paytime.com.au. We will action electronic marketing opt-outs within 5 business days and other marketing requests within 30 days. Even after you opt out, we will still send you transactional and service messages (for example, payment confirmations, security alerts and important account notices).

13. Cookies and online tracking

When you visit our Websites or use Paytime Services, we and our service providers place cookies, pixels, local storage and similar technologies on your device. We use them to keep you signed in, remember your preferences, secure the Websites against fraud, measure how the Websites are used, and – where you have not opted out and are 18 or over – deliver marketing that is relevant to you. We use Google Analytics and may use other analytics providers. We do not share information that directly identifies you with analytics providers. You can control cookies through your browser settings or through any in-product cookie controls we provide. Blocking cookies may affect the functionality of the Websites. Most browsers offer a Do Not Track signal. The interpretation of that signal across the industry is not uniform; we currently do not respond differently to Do Not Track signals, but we treat the opt-out controls described above as effective expressions of your preference.

14. Contact us

Privacy Officer, Paytime Services Pty Ltd Email: info@paytime.com.au Phone: 1300 80 49 60 (Australia) Post: PO Box H317, Australia Square NSW 1215 We aim to acknowledge all privacy-related enquiries within 7 days.

Last Updated July 2026