PRIVACY NOTICE

How we protect and handle your information

January 2026

Introduction

APG Pay Pty Ltd (“APG Pay,” “we,” “our,” or “us”) is committed to protecting the privacy and security of personal information. This Privacy Notice outlines how we collect, use, store, and disclose personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

To read our full Privacy Policy Statement, please click here.

What Information we collect

We may collect and process the following types of personal information.

  • Identity and Contact Information: Name, address, email, phone number, date of birth
  • Financial Information: Payment details, transaction history, and banking information
  • Business information: Employer details, job title, and professional affiliations.
  • Technical Information: IP address, browser type, and usage data when interacting with our website or services.
  • To facilitate card issuance and payment functions, we adhere to the principle of “Data Minimisation” and process the following information
    • Basic Corporate Information: Prior to card creation, we only require the Company Name/Cardholder Name to identify the entity to which the card belongs.
    • Card Asset Information: Upon successful card creation, we generate and store card credentials, including a tokenised Primary Account Number (PAN), CVV (Security Code), and Expiration Date. We do not retain the full PAN in our environment, instead, we store a secure token that can be used to process transactions without exposing your card number.
    • Authorisation Data: When a transaction is initiated at a merchant, we receive and process authorisation request information from card schemes to verify the card’s validity and the legitimacy of the transaction.

Please note: We only collect personal information that is necessary for the purposes outlined in this Notice or as required by law. Aside from the data essential for business operations mentioned above, we do not directly collect or store sensitive personal identifiable information unless explicitly required by compliance audits or regulatory obligations in specific jurisdictions.

Additionally, referring to the tokenised PAN described above, the tokenisation process reduces the exposure of sensitive card data and is implemented in line with applicable card‑scheme and industry/PCI-DSS security standards.

How we collect personal and business information

At APG Pay, we collect personal information through secure digital channels, including encrypted online software, which is owned and controlled by APG Pay. This ensures that all data is collected, stored, and processed with the highest level of security and confidentiality.

We may collect information directly from individuals or businesses when they register for our services, complete transactions, communicate with us, or interact with our website and platforms. Additionally, we may obtain information from third-party sources such as financial institutions, credit reporting agencies, and regulatory bodies, where permitted by law. Our collection methods are designed to comply with privacy regulations while maintaining transparency and protecting user data.

We collect personal information through:

  • Direct interactions (e.g., when you sign up for services, contact us, or complete forms).
  • Automated technologies (e.g. cookies and analytics on our website).
  • Third parties (e.g., business partners, financial institutions, and identity verification providers).

How we use information

At APG Pay, we use personal information to provide and improve our payment services, ensure compliance with regulatory requirements, and enhance customer experience. In addition to these purposes, we also use personal data to conduct risk and credit assessments for our lending practices. When evaluating eligibility for financial services, we may assess transaction history, creditworthiness, and risk factors to make informed lending decisions. This process helps us manage financial risks, ensure responsible lending, and comply with relevant financial regulations. We apply strict confidentiality measures to protect personal data during these assessments and only use the information in accordance with Australian privacy laws.

We process the aforementioned information solely for the following purposes:

  • Card Issuance and Management: To generate compliant payment credentials for users.
  • Transaction Authorisation Verification: To receive and respond to verification requests from card schemes during a transaction, ensuring only authorised cardholder requests are approved.
  • Risk Control and Compliance: To identify potentially fraudulent activities and fulfil Anti-Money Laundering (AML) and payment industry regulatory obligations.

How we store and protect information

APG Pay utilises the following Google Cloud Platform (GCP) regions for delivering our service:

  • Hosted within the australia-southeast1 (Sydney) region, with auto-scaling and backup containers configured.

Cardholder data (Primary Account Numbers [PANs]) are stored in a PCI-compliant Azure Data centre, hosted within the following Australian Azure Regions:

  • Australia East (New South Wales)
  • Australia Southeast (Victoria); and
  • Australia Central (Canberra).

We take reasonable steps to ensure personal information is securely stored and protected from misuse, loss, and unauthorised access. Security measures include encryption, access controls, and secure data storage practices.

We have established a rigorous security defence system to protect payment credentials:

  • Physical Isolation of PCI Environment: The storage and processing of all clear-text Primary Account Numbers (PANs) and CVVs are conducted exclusively within a strictly regulated PCI Environment. This environment fully complies with the physical and logical isolation requirements of the Payment Card Industry Data Security Standard (PCI DSS).
  • Tokenisation Management: Within our non-PCI business zones, the system does not store clear-text card numbers, Card numbers are immediately tokenised upon entering the system. Business logic interacts only via “Tokens”, effectively eliminating the risk of sensitive data exposure on general servers.
  • Encrypted Transmission: All authorisation verification requests and responses are transmitted via industry-standard encrypted channels (e.g. Transport Layer Security [TLS 1.2+]) between the card schemes and our PCI environment.

Information Sharing and Disclosure

We do not sell your information to any third parties. We only interact with information in the following necessary scenarios:

  • Card schemes and Financial Institutions: To complete transaction authorisation, we must exchange necessary card and transaction data with relevant card organisations (such as Visa, Mastercard, etc.) and settlement banks.
  • Legal and Regulatory Requirements: If we receive a legally binding subpoena, court order, or to cooperate with law enforcement agencies in fraud investigations, we may disclose necessary information as required by law.

We may disclose your information with:

  • Regulatory authorities, law enforcement agencies, and government bodies where required.
  • Third-party service providers who assist in delivering our services, such as credit insurers or commercial credit reporting bureaus such as Allianz Trade and Creditsafe.
  • Business partners; with consent or as necessary for service provision.

International data transfers

Where necessary, we may send your information overseas to service providers and partner entities located outside Australia, including to:

  • APG Pay Group members located in Hong Kong and Singapore, to help us deliver or support the provision of our products and services
  • Contracted service providers and third parties who store data or operate outside of Australia.
  • Contracted organisation we partners with to provide our services
  • Comply with laws and help government or law enforcement agencies.

We ensure that such transfers comply with APP 8 and take appropriate safeguards such as adequacy decisions, standard contractual clauses and other safety measures to protect your information.

Data retention

We retain relevant data only for the duration of the card’s validity and the necessary period required by law. Cardholder data is retained for the life of the card and for any additional period required by law (AML regulations). Non-cardholder personal information is retained only as long as necessary to provide our services or as legally required. For cancelled cards, we will archive data in accordance with the mandatory retention periods required by relevant financial regulations. Upon expiration of the retention period, the data will be permanently deleted or irreversibly de-identified.

Access, Correction, and Complaints

You may view, activate, or deactivate your cards at any time through the platform’s management dashboard. You have the right to access and request correction of any corporate or personal information we hold. We will respond to your request for access or correction of information within 30 days.

If you believe we have breached the APPs, you may submit a complaint to our Risk & Compliance Team at compliance@apgpay.com who will investigate promptly and respond to your complaint within 30 days.

Cookies and Website Tracking

We may use cookies and similar tracking technologies to improve user experience. Users can manage cookie preferences through their browswer settings.

Updates

We may update this notice from time to time based on business developments or changes in the regulatory environment. Any significant revisions will be notified to you via our website or by email.

This notice is effective as of January 2026.

If you have any privacy-related inquiries, requests or complaints, please contact:

Data Privacy Officer c/- APG Pay Risk & Compliance Team

Email: compliance@apgpay.com

Postal: Suite 2, Level 1, 10 Bridge Street, Sydney NSW 2000 Australia