1.1 This Privacy Policy explains how NoFee Pty Ltd ABN 39 688 232 242 (NoFee, we, us, our) collects, holds, uses and discloses personal information, and how you can access and correct your information or make a privacy complaint.
1.2 NoFee provides a payment facilitation service that enables Australian businesses (Merchants) to receive payments over the New Payments Platform (NPP) using PayID and PayTo. In providing that service we handle personal information about three groups of people: (a) Merchants and their representatives (owners, directors, beneficial owners, authorised users); (b) Merchants’ customers who pay, or authorise payments, through the NoFee Service (Payers); and (c) visitors to our website and people who contact us.
1.3 We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because NoFee operates in the payments sector and has obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), the Privacy Act applies to us in full regardless of our size.
2.1 Merchants and their representatives. To open and operate a Merchant account we collect: business and trading names, ABN/ACN and business registration details; the names, dates of birth, residential addresses and contact details of directors, owners and beneficial owners; government-issued identity documents and verification results; business bank account details (BSB and account number); contact details of authorised users; account login credentials; subscription, billing and support records; and information about the nature of the Merchant’s business.
2.2 Payers. When a person pays a Merchant, or authorises a PayTo agreement, through the NoFee Service, we may collect: their name; their PayID (which may be a mobile number or email address) or BSB and account number; the details of the PayTo agreement they authorise (including amounts, frequency and status); and transaction records relating to their payments.
2.3 Website visitors and other contacts. If you browse our website, contact us, or register interest in NoFee, we may collect your name, contact details, business details, the contents of your communications with us, and technical data described in section 8 (such as device, browser and usage information).
2.4 We do not knowingly collect sensitive information (such as health information or biometric data) and we ask that you do not provide it to us. We do not knowingly deal with individuals under 18.
3.1 We collect personal information: directly from you when you register, complete onboarding, use the dashboard, make or authorise a payment, or contact us; from our payment services provider through payment and mandate processing (for example, webhook notifications of payments received); from identity verification and screening service providers engaged for customer due diligence; from publicly available registers such as ASIC and the ABR; and from Merchants, where a Merchant provides us with details of a Payer for the purpose of a payment or PayTo agreement.
3.2 Where a Merchant provides us with a Payer’s personal information, the Merchant is responsible for ensuring it was collected lawfully and that the Payer has been made aware their information will be handled by NoFee and our payment services provider in accordance with this policy.
4.1 We collect, hold and use personal information to: (a) verify identity and conduct customer due diligence as required by the AML/CTF Act; (b) assess Merchant applications and manage onboarding; (c) provide the NoFee Service, including registering PayIDs, creating and managing PayTo agreements, initiating and tracking payments, and facilitating settlement; (d) administer subscriptions, credits, billing and collections; (e) provide customer support and communicate service information; (f) detect, investigate and prevent fraud, money laundering, terrorism financing and other unlawful activity, and manage transaction disputes; (g) comply with our legal and regulatory obligations, including to AUSTRAC and other regulators; (h) improve our services, website and customer experience; and (i) with your consent or as permitted by law, tell you about NoFee products and services.
4.2 Direct marketing. We may send Merchants and prospective Merchants information about NoFee services by email or SMS. Every marketing message will include a simple way to opt out, and you can opt out at any time by contacting us; opting out does not affect service or account communications we need to send you.
4.3 We do not sell personal information, and we do not use or disclose it for the purposes of third-party advertising.
5.1 We disclose personal information, only for the purposes described in section 4, to: (a) our licensed Australian payment services provider, which provides NPP connectivity, payment processing and settlement infrastructure for the NoFee Service and holds payment-related data; (b) identity verification, screening and fraud-prevention service providers, for customer due diligence and transaction monitoring; (c) financial institutions and NPP participants, to the extent necessary to process, settle, investigate or adjust payments; (d) AUSTRAC, law enforcement bodies, courts and other regulators, where required or authorised by law; (e) our professional advisers (legal, accounting, audit and insurance) under obligations of confidentiality; (f) IT service providers who host or support our systems, such as website hosting, email and data storage providers; and (g) a purchaser or prospective purchaser of our business, under obligations of confidentiality.
5.2 Division of data. Payment-related data (including payment transaction records and mandate processing data) is held by our payment services provider on regulated Australian payment infrastructure. NoFee holds and manages Merchant business and identity information, account credentials, bank reference details, and subscription and billing records.
6.1 Payment processing and settlement for the NoFee Service occur in Australia. Some of our IT service providers (for example, website hosting, email and support tools) may store or process limited categories of data, such as contact details, support communications and website analytics, on servers located overseas, including in the United States. Where this occurs, we take reasonable steps to ensure the overseas recipient handles personal information consistently with the Australian Privacy Principles.
7.1 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include encryption of data in transit, access controls and authentication on our systems, restricting access to personal information to personnel who need it, and engaging reputable service providers.
7.2 We retain personal information for as long as it is needed for the purposes described in this policy and to meet our legal obligations. Records collected for AML/CTF purposes, and transaction records, are retained for at least 7 years as required by law. When personal information is no longer required, we take reasonable steps to destroy or de-identify it.
7.3 Data breaches. If a data breach occurs that is likely to result in serious harm to individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
8.1 Our website may use cookies and similar technologies to remember preferences, measure how the site is used, and improve it. The technical data collected may include IP address, device and browser type, pages visited and referring pages. You can control or disable cookies through your browser settings; parts of the website may not function fully without them.
8.2 Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites, and we encourage you to review their privacy policies.
9.1 You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete or misleading, by contacting us using the details in section 11. We will respond within a reasonable period (usually within 30 days). We do not charge for making a request, though in limited cases permitted by the Privacy Act we may charge our reasonable costs of giving access or decline access, in which case we will tell you why.
9.2 Payers whose information is held in connection with a payment to a Merchant may contact either the Merchant or us; where the relevant data is held by our payment services provider, we will coordinate with them to respond.
10.1 If you believe we have breached the Privacy Act or the APPs, please contact us using the details in section 11 with the details of your concern. We will acknowledge your complaint promptly, investigate it, and respond within 30 days.
10.2 If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): online at oaic.gov.au, by phone on 1300 363 992, or by mail to GPO Box 5288, Sydney NSW 2001.
11.1 Privacy enquiries, access and correction requests, and complaints should be directed to: Privacy Officer, NoFee Pty Ltd, 122a Glengarry Drive, Duncraig WA 6023, or by email to privacy@nofee.com.au.
12.1 We may update this Privacy Policy from time to time, including to reflect changes in our services, technology or the law. The current version will always be published at nofee.com.au with its effective date. For significant changes we will take reasonable steps to bring the change to your attention, such as by email or a notice in the Merchant dashboard.