1. The short version
Vouchley runs a B2B incentive rewards platform. When your employer or supplier enrols you in a Vouchley programme, we collect your name, email, optionally your phone, your shipping address when you redeem points for goods, and your activity on the platform (points earned and spent, badges, orders).
We use this information to operate the platform — sign you in, deliver your rewards, notify you about orders, and report aggregated programme metrics to the organisation that enrolled you.
We share your information with the third parties we need to deliver the service (our email, payment, and hosting providers, and the consumer retailers we order your rewards from). We list them all below.
Our main database is in Australia (Sydney). We also keep a backup copyof it with an overseas provider, in case of disaster — we scramble that copy with strong encryption before it leaves us and we hold the only key, so the provider cannot read it. That backup may be stored outside Australia; we can’t pin it to a country, and we don’t claim otherwise. Some service providers also operate from overseas; we name them and the country.
Under the Australian Privacy Act you have rights to access, correct, and (in most cases) request deletion of your information. You can email privacy@vouchley.com.au to exercise any right.
The legalese starts below. If you only read one section, read §5 (what we share with retailers) and §10 (your rights).
2. Who we are + how to contact us
Vouchley Pty Ltd (ACN 699 968 655) (ABN 75 699 968 655), an Australian proprietary company limited by shares, trading as Vouchley (“Vouchley”, “we”, “us”, “our”), operates the Vouchley B2B incentive rewards platform via:
- the marketing website at vouchley.com.au;
- the participant and administrator web application at app.vouchley.com.au;
- the Vouchley mobile application (Android via Google Play and iOS via the App Store, when published); and
- sign-up and enrolment pages on app.vouchley.com.au, including where you reach them via a QR code or invitation from the organisation that enrols you.
Privacy Officer + complaints contact:
- Email: privacy@vouchley.com.au
- A postal address is available on request — email us at the address above and we’ll provide it.
- We aim to respond to privacy requests within 30 days.
This Policy was last updated 2026-09-04.
The operator named above (Vouchley Pty Ltd, trading as Vouchley) is regulated under the Privacy Act 1988 (Cth) as an APP entity in respect of the Vouchley platform. The Privacy Act’s small-business exemption does not apply, because Vouchley is a contracted service provider to other organisations and collects personal information for purposes related to those organisations.
3. Our data-controller declaration (Vouchley vs Customer)
Vouchley provides services to organisations (“Customers”, typically employers, suppliers, or distributors) who run incentive programmes for their own staff, distributors, retailers, or other participants (“End Users”).
With respect to the personal information we handle:
- Vouchley is the APP entity (and where applicable the GDPR-equivalent data controller) for the End User’s relationship with the platform — including (without limitation) authentication identifiers, points balance, order history, redemption activity, consent preferences, and account communications.
- The Customer that enrolled you is the APP entity for the act of providing Vouchley with your identity details via a bulk participant upload, system integration, or invitation list. They do that under their own privacy obligations to you (employee, contractor, or business- relationship privacy notice).
- On Customer-branded parts of the platform (for example your programme page, which can display your Customer’s logo and colour scheme), even when you see your Customer’s brand, Vouchley operates the platform and Vouchley decides how your data is processed. The Customer is our customer; they are not the controller of your data on Vouchley’s platform.
A Data Processing Addendum between Vouchley and your Customer sets out the technical, organisational, and contractual safeguards that apply to the data we handle for them. We can share its sub-processor list with you on request.
3.1 If you joined our waitlist and aren’t a programme participant
Most of this Policy is written for people using a Vouchley rewards programme. If you gave us your email on our website to hear about our launch, you’re in a different position, and this section is the part that applies to you.
What we collect: your email address, and — only if you chose to give them — your nameand your answer to “I’m interested as a…” (supplier, participant, or other). Nothing else. We don’t buy, append, enrich or look up anything about you.
Why we collect it — and it depends which boxes you ticked. The form has two.
The first box is required, and it’s narrow. You agreed we could contact you about the Vouchley launch. That means the launch announcement itself, and any material update about the launch beforehand — a date, a delay, a change to what’s launching. If that’s the only box you ticked, that is the limit of what we’ll use your details for, and we’ll stop after the launch.
The second box is optional, and it’s the wider one. If you also ticked “send me occasional Vouchley updates”, you’ve asked to keep hearing from us after the launch — new features, guides and news. You can unsubscribe from those at any time, from any message we send, and you never had to tick it to join the waitlist.
What we will not do with it. If you ticked only the first box, we will not add you to a newsletter or a marketing sequence — you’ll hear about the launch and then we’ll stop. (If you ticked the second box as well, ongoing updates are exactly what you asked for, and you can unsubscribe from them whenever you like.) Either way, we will not use your “interested as” answer to target you with a sales campaign — at most it changes the emphasis of the message itself. And we will never email you for the sole purpose of asking permission to email you about something wider: the choice to keep hearing from us is offered on the form itself, and again inside the launch message, and ignoring it is a complete answer.
Who else sees it:our email provider, Customer.io, sends the message on our behalf and is listed with the others at §5.1. Nobody else. We don’t sell it, share it, or pass it to any Vouchley customer.
How long we keep it:see §8 — in short, we delete or de-identify your details within 90 days of sending the launch announcement, unless you’ve separately opted in to hear more from us.
Your rights are the sameas everyone else’s in this Policy: you can ask us what we hold, correct it, or ask us to delete it at any time — email privacy@vouchley.com.au. Every message we send you also carries a one-click unsubscribe.
3.2 If we contacted you about Vouchley because of your job (and you aren’t a participant or a waitlist subscriber)
If you received an email from us introducing Vouchley — because your role involves running or influencing an incentive, channel, trade-marketing or sales programme at your organisation — this section is the part that applies to you.
What we collect: limited businesscontact details — your name, your work email address, your job title or role, and the organisation you work for. Nothing else. We do not collect any personal, financial, or sensitive information about you, and we do not build a profile of you.
Where we got it: from a licensed business-data provider, or from a business source that has been published (for example a company website or a public professional listing). You can ask us at any time exactly where we obtained your details — email privacy@vouchley.com.au and we’ll tell you, free of charge.
Why we’re allowed to email you: Australia’s Spam Act lets a business send a commercial message to a work address that has been conspicuously published without a “no unsolicited email” notice, where the message is relevant to that person’s role. We only contact published work addresses of people whose role Vouchley is relevant to. The message itself is our lawful basis — obtaining a contact from a data provider is not consent, and we don’t treat it as one.
Every message carries a one-click, no-cost unsubscribe, it stays active, and we act on it promptly. An unsubscribe is permanent— we keep a record of it so we never contact you again, across every future campaign.
What we will not do: we will not sell your details; we will not add them to any list other than the outreach that introduced Vouchley to you; and we will never send you a message whose only purpose is to ask permission to send you more.
How long we keep it:see §8 — if you don’t respond or opt in, we delete or de-identify your details within 12 months of collecting them. If you unsubscribe, we keep only the record needed to honour that.
Your rights are the sameas everyone else’s in this Policy — ask us what we hold, correct it, or ask us to delete it, at privacy@vouchley.com.au— plus the right above to ask where we got your details.
4. The personal information we collect
We collect and hold the following categories of personal information.
4.1 Identity (used to sign you in and contact you)
- Your name
- Your email address
- Your mobile phone number (optional, if you provide it for SMS notifications)
- An anonymous authentication identifier issued by our authentication provider Clerk
- For Customer administrators: the organisation you belong to and your role within it
APP basis: performance of contract (APP 3.1) + consent for SMS marketing (APP 7).
4.2 Postal + shipping information (used to deliver your rewards)
- Recipient name (yours or a gift recipient’s, if you choose to redeem to a different address)
- Street address line 1 + line 2
- Suburb, state, postcode
- Optional shipping contact phone number
- Optional notification email override (for gift redemptions)
APP basis: performance of contract (APP 3.1).
4.3 Account activity (used to run the rewards programme)
- Points balance (per programme)
- Points transaction ledger (earn / redemption / reversal / manual adjustments — all appended, never edited)
- Order history (orders placed, items, cash top-up paid, status, dispatch + delivery confirmations)
- Tier (Bronze / Silver / Gold / Platinum)
- Badges earned + streak data
- Cart contents + wishlist (per programme)
- Product view history (used to surface “Recently viewed” + “Top picks” on your catalogue)
- Leaderboard rank (if your programme has a leaderboard and you have not opted out)
- Login event log (a per-day signal we use to compute streaks and to operate the platform’s security audit log)
APP basis: performance of contract (APP 3.1) + legitimate interest for behavioural personalisation (APP 6.1 with notification).
4.4 Payment-related identifiers (we never see your card)
When you add a cash top-up to a redemption, the payment is processed by Stripe on its own hosted checkout page. Vouchley never sees, stores, or transmits your card number, CVV, expiry, or any other cardholder data. What Vouchley holds is the Stripe-issued opaque identifiers (customer id, payment intent id, charge id, refund id, dispute id) and the amounts in cents.
APP basis: performance of contract (APP 3.1) + statutory tax retention obligations (Income Tax Assessment Act 1997 + ATO TR 2002/9).
4.5 Support and free-text information (you control what you put in here)
When you cancel an order, report a problem with a delivery, or interact with our support team, we collect the text you submit and the response we provide. Customer administrators with appropriate roles may see these text fields in their activity log lens (subject to the confidentiality obligations in the MSA between Vouchley and the Customer).
We ask you not to include sensitive personal information (medical, financial, family, racial, religious, political, and so on) in free-text fields unless it is directly needed to resolve your issue.
APP basis: performance of contract (APP 3.1).
4.6 Marketing-site visitor information (separate to platform data)
When you visit our marketing site at vouchley.com.au:
- We do not currently use third-party analytics, advertising pixels, or behavioural tracking.
- Our infrastructure providers (Vercel for CDN, Sentry for error monitoring) log standard request metadata including your IP address, browser user-agent, and the URL you accessed.
- We use a small number of strictly-necessary cookies and browser storage items as described in our Cookie Policy.
APP basis: legitimate interest for security and reliability (APP 6.1) + consent for any future analytics or marketing cookies (APP 7 + cookie banner per Cookie Policy).
4.7 What we do NOT collect
For clarity, we do NOT collect:
- Your card number, CVV, expiry, or any other cardholder data (Stripe handles this end-to-end).
- Health, biometric, genetic, racial, ethnic, political, religious, philosophical, sexual orientation, or trade union information.
- Information about people under 16 (see §13 — Children).
- Government identifier numbers (Tax File Number, Medicare number, driver licence, passport).
If you submit any of these to us by mistake (for example in a free-text field), please email privacy@vouchley.com.au and we will redact or delete the information per our APP 11.2 obligations (see §10).
5. Who we share your information with
This section is load-bearing under APP 6 (use and disclosure) and APP 8 (cross-border disclosure).
5.1 Service providers (sub-processors)
We engage the following sub-processors to deliver the platform. Each one is contracted under a Data Processing Addendum, and we have taken reasonable steps to assess each provider’s privacy posture before engaging them.
| Sub-processor | What they do | Where they process |
|---|---|---|
| Clerk | Authentication (sign-in, session management) | United States |
| Customer.io | Lifecycle email + email broadcast delivery | United States |
| Twilio | SMS delivery | United States |
| Stripe | Payment processing for cash top-ups | United States |
| Xero | Accounting (invoice + credit note synchronisation) | Australia |
| Neon | Database hosting | AWS ap-southeast-2 (Sydney, Australia) |
| Cloudflare | Storage of an encrypted offsite backup copy of the database (encrypted by us before it is uploaded; Cloudflare holds no key and cannot read it) | Asia-Pacific region, not pinned to a country — may be outside Australia |
| Vercel | Frontend hosting + CDN edge | Multi-region; primary in United States |
| Railway | API server hosting | Singapore |
| Upstash | Cache + queue (Redis) | United States |
| Sentry | Error monitoring | United States |
| Google Workspace | The orders@vouchley.com.au mailbox that ingests retailer dispatch emails | United States |
| Google Maps Platform | Address autocomplete during checkout (a fragment of your typed address is sent to Google) | United States |
| PayPal | Used as a payment bridge for one retailer’s checkout (not your payment; Vouchley’s own PayPal account) | United States |
| Apple, Google | Mobile push notification delivery (when the mobile app is in use) | United States |
The current list above is correct as of the date in §2. We update this list when we change sub-processors. You can request the current canonical list from privacy@vouchley.com.au at any time.
5.2 Retailers (this is unusual; please read)
Vouchley does not hold inventory. When you redeem points for a physical product, Vouchley places the order at a consumer retailer storefront on your behalf, using Vouchley’s own retailer account. To do this we must share your shipping recipient name, full delivery address, and shipping contact phone with the retailer that ships your order.
Our current retailer panel for Australian deliveries is:
- JB Hi-Fi
- Bunnings
- BCF
- David Jones
- Rebel Sport
- House
- Toyworld
- Strandbags
- Prezzee (for digital gift cards — no shipping address shared)
The retailers receive your shipping details solely to fulfil your order. They are Australian-incorporated businesses subject to the Australian Privacy Principles (or substantially- similar privacy law in Australia), and we rely on APP 8.2(a) in disclosing your information to them.
We do not sell your information to any retailer, and we do not authorise any retailer to use your information for their own marketing. That said, once your information is in the retailer’s system it is subject to that retailer’s own privacy policy + carrier sub-processors (e.g. Australia Post, StarTrack). We name the retailer who shipped your order in the order confirmation and dispatch emails so you can refer to their policy directly if you wish.
If you do not want your information shared with retailers for fulfilment, you should not place a redemption for physical goods. We can offer alternative redemption types (digital gift cards via Prezzee, where the only information shared is the email address the gift card is delivered to). Email privacy@vouchley.com.au to discuss alternatives.
5.3 Your Customer (the organisation that enrolled you)
The Customer that enrolled you in their programme has visibility into:
- Your name, email, and (if you provided it) phone number;
- Your points balance, transaction ledger, order history, badges, tier, and leaderboard rank within their programme;
- Aggregated programme metrics (active participants, redemption rate, ROI estimates);
- Free-text content you submit through cancellation reasons, refund requests, and issue reports (subject to confidentiality obligations under our MSA with the Customer); and
- Audit-log events about your participation (enrolment, redemption, badge awards, and so on).
The Customer is contractually bound to use this information only for operating the programme and is subject to the confidentiality obligations under our MSA. They are NOT permitted under our agreement to use it for their own direct marketing without your separate consent (which Vouchley collects via the cookie banner + transactional comms preferences per our Cookie Policy).
5.4 Legal compliance, dispute resolution, and protection of rights
We may disclose your personal information where required or permitted by law, including:
- to comply with a court order, regulator request, or statutory obligation;
- to the Office of the Australian Information Commissioner (OAIC) or a foreign equivalent regulator responding to a complaint;
- to our legal advisors, insurers, and auditors under their own confidentiality obligations;
- to protect the rights, property, or safety of Vouchley, our Customers, our End Users, or others (including investigating fraud, abuse, or breaches of our Terms of Service);
- in connection with a proposed sale, merger, or reorganisation of Vouchley, in which case the recipient will be subject to substantially similar privacy obligations.
5.5 With your consent
We may share your information with any other party with your express consent. We will tell you who and why before asking for consent.
6. How we collect your information
We collect personal information in the following ways:
- Directly from you when you sign up or enrol, complete your profile, place an order, contact support, or submit a return.
- From your Customer when they enrol you via bulk upload, integration sync, or admin invitation.
- From Clerk (our authentication provider) when you sign in (Clerk issues you a user identifier and we store it against your Vouchley account).
- From Stripe when you pay a cash top-up (we receive opaque payment identifiers + amounts, never card data).
- From retailers when they email our orders@vouchley.com.au mailbox to confirm dispatch of your order (so we can update your tracking). We process the relevant fields and then archive these emails per §8 retention.
- From your interactions with the platform (page views, product views, login events, badge events).
- Directly from you when you join our waitliston our website — your email address, and optionally your name and your answer to “I’m interested as a…”. This channel applies to people who are not platform users; see §3.1.
- From a licensed business-data provider or a public business source — when we obtain limited business contact details (name, work email, job title, employer) of decision-makers at organisations Vouchley could help, in order to introduce Vouchley to them. This is the only channel on this list that involves information sourced other than from you, your Customer, or the platform, and it applies only to prospective business customers, never to platform participants; see §3.2.
For our platform participants and waitlist subscribers, we do notcollect personal information from third-party data brokers, public records databases, or social- media scraping — what we hold about you comes from you, your Customer, or our own platform, as set out above. The single, bounded exception applies only to prospective business customers(not participants): as described at §3.2, we obtain limited business contact details of decision-makers from licensed business-data providers and publicly available business sources, to introduce Vouchley to them. We do not scrape social media, and we do not buy, append, enrich, or look up information about platform participants.
7. Why we collect, use, and hold your information
We collect, use, and hold personal information for the following purposes:
- To run the platform — sign you in, present you with the right catalogue, accept your redemptions, deliver your rewards, send you order confirmations, dispatch and delivery notifications, refund notifications, and support correspondence.
- To operate your Customer’s incentive programme — show your activity to the Customer’s administrators (per §5.3), compute aggregated programme metrics, and deliver Customer-authored broadcast emails to you if your Customer has chosen to communicate via Vouchley.
- To improve the platform— analyse aggregate usage patterns (no individual-affecting decisions), surface “Recently viewed” and “Top picks” content based on your own activity, and operate engagement features like badges + streaks.
- To meet legal and tax obligations — retain transactional records for the period required under the Income Tax Assessment Act + ATO record-keeping guidance + Corporations Act.
- To protect the platform — operate security logging, fraud detection, dispute investigation, and audit- log integrity.
- To tell waitlist subscribers about our launch — if you gave us your email on our website, to send you the launch announcement and any material update about the launch beforehand. This purpose is limited to the launch; it does not extend to newsletters, marketing sequences, or promotional campaigns (§3.1).
- To introduce Vouchley to prospective business customers — where we obtained your businesscontact details from a licensed business-data provider or a public business source (§3.2), to contact you about Vouchley where it is relevant to your professional role. This purpose is bounded: every message identifies us as the sender, carries a one-click unsubscribe (permanent once used), and tells you how to ask where we got your details. It does not extend to any other use of your details, and it is not profiling.
We do not use your personal information for:
- Automated decision-making that could significantly affect your rights or interests (we describe the limited automation we do run, and our position on it, in §14);
- Sale of your information to third parties (we never sell personal information);
- Behavioural advertising on the open web;
- Profiling for purposes outside running the rewards programme.
8. How long we keep your information (retention)
We keep your personal information for as long as we need it to run the platform for you, meet our legal obligations, and protect ourselves and our Customers from disputes. After that, we delete or anonymise it.
| Information category | Indicative retention period | Why |
|---|---|---|
| Active account information (identity, addresses, points balance, settings) | While your account is active + an “active” account is one that has logged in or been credited with points in the last 36 months | Performance of contract |
| Order + invoice records | 7 years from the date of the order | Income Tax Assessment Act + ATO TR 2002/9 (record- keeping) + Corporations Act s. 286 |
| Refund + credit note records | 7 years from the date of the refund | Same as above |
| Audit log entries containing your data | 7 years for financial / order entries; 24 months for engagement entries (login events, badges, leaderboard rank). Right-to-erasure requests resolved by tombstone- and-anonymise for retained rows. | Audit integrity + legal defence |
| Communication dispatch records (which emails / SMS we sent you) | 24 months from the date of dispatch | Operational + dispute defence |
| Communication suppressions (your opt-outs) | Indefinite, while platform operates | Required to honour your opt-out |
| Consent records (cookie banner choices) | 6 years from the date of consent | Evidence-of-consent under APP 3 + APP 5 |
| Retailer dispatch emails arriving at orders@vouchley.com.au | The parser-relevant fields are extracted and stored against your order; the raw email body is retained for 30 days after processing and then auto-deleted | Operational debugging window |
| Marketing-site request logs (IPs, user-agents, error reports) | Per provider: Vercel 30 days; Railway 30 days; Sentry per its retention plan, currently 30-90 days | Security + reliability monitoring |
| Inactive accounts (no login + no points credit + no order in 36 months) | After 36 months we send a notification email; if no response within 90 days we anonymise the account (free- text PII redacted, name + email replaced with [deactivated], transactional records retained for tax retention) | Minimisation; APP 11 |
| Waitlist sign-ups (email, optional name, optional “interested as”) | 90 days after we send the launch announcement, we delete or de-identify your details — unless you have separately opted in to hear more from us, in which case we keep them for that purpose until you unsubscribe. If no launch announcement has been sent, we delete or de-identify 12 months from the date you signed up. A record that you unsubscribed is kept indefinitely so we can honour it | Minimisation; APP 11.2 — the purpose is discharged once the launch has been announced |
| Prospective-customer business contact details (name, work email, role, employer, and the source we obtained them from) | 12 months from collectionif you do not respond or opt in, then deleted or de-identified. If you unsubscribe, we keep only a suppression record — indefinitely — so we never contact you again. If you become a customer contact, your details are retained under that customer relationship instead | Minimisation; APP 11.2 — the purpose is discharged if the outreach does not lead anywhere |
If we are legally required to retain information beyond these periods (for example to comply with a court order or regulatory hold), we will do so for the period required by the obligation.
Backups — what this means when you ask us to delete something. We take a nightly encrypted backup of our database and keep a rolling window of those backups (a maximum of fourteen nights). When we delete or anonymise your information, we do it in our live systems within the timeframes above — but a copy can still exist inside an encrypted backup taken beforeyour request, until that backup rolls out of the window. Those backups are encrypted, are not used to serve the platform, and are never used to restore information we have deleted at your request. We do not edit backups, because a backup that can be altered is a weaker protection for everyone’s data than one that cannot.
9. How we protect your information (security)
We use reasonable technical and organisational measures appropriate to the sensitivity of the information.
- Encryption in transit: all connections to and from Vouchley use TLS 1.2 or higher.
- Encryption at rest: our primary database (Neon) encrypts every row with AES-256. Sensitive credentials (retailer accounts, integration tokens) carry an additional layer of AES-256-GCM application-level encryption. Our offsite backup copies are encrypted by us with AES-256-GCM before they are uploaded, under a passphrase held only by Vouchley — the storage provider receives scrambled data it has no means of reading, and holds no key to it.
- Access controls: Vouchley personnel access production data only via authenticated, audit-logged interfaces. Production access is restricted to engineering personnel with a legitimate need.
- Card data: we are not in scope for PCI cardholder data (Stripe handles your card; we hold only opaque payment identifiers).
- Audit log: every consequential action on your account is recorded in an append-only audit log that cannot be silently edited.
- Sub-processor diligence:we assess each sub-processor’s security posture (SOC 2 / ISO 27001 / equivalent) before engaging them and re-assess on contract renewal.
- Breach notification: if we suffer a notifiable data breach under the Privacy Act (Privacy Act §26WK), we will notify you and the OAIC within the statutory clock (currently 30 days from awareness, often faster).
No system is perfectly secure. If you believe your Vouchley account has been compromised, email security@vouchley.com.au immediately.
10. Your rights under the Privacy Act
You have the following rights with respect to the personal information Vouchley holds about you.
10.1 Access (APP 12)
You can ask us for a copy of the personal information we hold about you. We will respond within 30 days of your written request to privacy@vouchley.com.au. We may charge a reasonable cost-recovery fee for substantial requests but we will tell you the fee in advance and you can decide whether to proceed.
10.2 Correction (APP 13)
If any of the information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you can ask us to correct it. You can also update your name, email, and phone directly in your account profile.
10.3 Deletion / right to erasure (APP 11.2)
You can ask us to delete the personal information we hold about you. We will do so except where retention is required or permitted by law (for example tax records, audit records under legal hold, or records subject to a current dispute). Where we cannot delete, we will anonymise where reasonably possible.
How deletion interacts with our audit log: our audit log is engineered as append-only for system integrity. When you request deletion of audit-log entries containing your information, we tombstone the entries and anonymise the personal information fields rather than physically removing the entries, except where retention is no longer lawful. The result from your perspective is the same — Vouchley personnel can no longer view your personal information — but it allows us to preserve the integrity of the audit trail for legitimate purposes (fraud investigation, tax record keeping, programme operations).
Deletion is irreversible — once deleted, we cannot restore your account or order history.
10.4 Withdraw consent
Where we rely on your consent (for example SMS marketing, optional analytics cookies), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing we did before you withdrew. Some platform functions may not work without consent (for example we cannot send you transactional order emails if you opt out of all transactional communications).
10.5 Complaints
If you are not satisfied with how we have handled your personal information, you can complain to:
- Vouchley’s Privacy Officer in the first instance — privacy@vouchley.com.au. We aim to respond within 30 days.
- The Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au — if you are not satisfied with our response or want to escalate directly.
- A foreign equivalent privacy regulator if you have a connection to that jurisdiction (for example if you are a resident of an EU member state and consider GDPR applies, you may contact your local supervisory authority; though Vouchley targets the Australian market only).
10.6 What we ask of you
We may need to verify your identity before responding to an access or deletion request (for example confirming you can sign in to your Vouchley account). We will only ask for the minimum information needed to do this.
11. Cookies and browser storage
We use a small number of strictly-necessary cookies + browser storage items to operate the platform (sign you in, hold your cart between checkout steps). We do not currently use analytics, behavioural, or marketing cookies. Where we add these in future, we will collect your consent first through the cookie banner.
Full details + the cookie management surface live at our Cookie Policy.
12. Cross-border disclosures and data residency
We process your personal information primarily on infrastructure located in Australia:
- Primary database (Neon): AWS ap-southeast-2 (Sydney, Australia). This is where your account, points, orders and history actually live and are served from.
We also keep an encrypted offsite backup copy of that database with Cloudflare (Cloudflare R2), so that we could recover the platform after a disaster. Two things about that copy, stated plainly:
- It is a complete copy.It is a whole-database backup, so it contains the same categories of personal information described in §4 — not a narrow slice.
- Its location is not pinned to Australia. The storage bucket carries an Asia-Pacific region hint, but the provider describes region hints as best effort rather than a guarantee, and does not offer an Australian residency option. So the copy may be stored outside Australia, and we do not claim otherwise.
What protects it: we encrypt that copy ourselves, with AES-256-GCM, before it is uploaded, under a passphrase held only by Vouchley and kept in Australia. Cloudflare stores scrambled data it has no means of reading and holds no key to it. That encryption is the principal step we rely on to protect the copy when it leaves Australia.
We also engage sub-processors located outside Australia. Their countries are listed in §5.1.
Under APP 8 we remain responsible for compliance when we disclose your personal information overseas. We rely on:
- APP 8.2(a) — substantially-similar-law belief for sub-processors in jurisdictions with equivalent privacy frameworks (UK, EU) and for Australian retailers (subject to APPs);
- Standard contractual safeguards for US- based sub-processors via the contractual DPA terms each provider publishes;
- APP 8.1 reasonable steps for the encrypted offsite backup copy described above, where the client-side encryption we apply before upload is the principal step we rely on;
- Express consent where we add a new cross- border sub-processor or recipient that is not covered by the above.
Vouchley targets the Australian market only at MVP. We do not currently extend services to End Users outside Australia. If you are accessing the platform from outside Australia, your information may transit through the sub- processor infrastructure above and you accept this as part of using the service.
13. Children
Vouchley is a B2B incentive rewards platform aimed at adult participants in workplace, distributor, retailer, or commercial-network incentive programmes. We do not knowingly collect personal information from individuals under 16.
If you are a parent or guardian and believe your child has provided us with personal information, please email privacy@vouchley.com.au and we will delete the account.
If a Vouchley Customer attempts to enrol participants under 16 through Vouchley’s platform, we will refuse the enrolment and may suspend the Customer’s account.
14. Automated decision-making and profiling
Some parts of the platform run automatically, using your personal information. We describe them here so you know what is automated, what information it uses, and what it does — and because Australian privacy law (Australian Privacy Principle 1, as amended, in force from 10 December 2026) asks us to be transparent about automated decisions that could significantly affect you.
The automated processing we run, and the personal information it uses:
- Your points balance and tier. Your tier (Bronze / Silver / Gold / Platinum) is worked out automatically from the points you have earned over a rolling period, and your points balance updates automatically as you earn and redeem. This uses your points transaction history.
- Leaderboard ranking— only if your programme has a leaderboard and you have not opted out. This ranks you against other participants using your points activity, and you can opt out.
- Engagement badges and streaks, awarded automatically when you meet documented criteria, using your activity and login history.
- Promotion outcomes— where a promotion involves an automated result (for example a spin or scratch game), the platform determines the result. The odds are set at the programme level and the result does not depend on who you are.
- Redemption eligibility— when you place a redemption, the platform automatically checks you have enough points and that the programme has budget, and allows or holds the redemption on that basis. This uses your points balance.
- “Recently viewed” and “Top picks” — drawn from your own past activity. This is content presentation, not a decision about you.
Our position on “significant effect”. These are the kinds of automated processing a voluntary rewards programme runs. In our view none of them is a decision that could reasonably be expected to significantly affect your rights or interestsin the sense the law is concerned with — they operate a commercial rewards benefit under rules set for the programme, rather than deciding something like your access to credit, insurance, housing, employment, healthcare or a government benefit. And you can always reach a person: your reward orders are fulfilled by our team, order problems and disputes are handled by people, and you can query any automated outcome by emailing privacy@vouchley.com.au.
What we do NOT do.We do not use AI or machine-learning models to make decisions about you. There is no automated credit decision, no automated dispute resolution, no automated identity verification, and no automated content moderation. Reward orders are routed to a retailer based on lowest-cost availability — an operational decision Vouchley makes about its own fulfilment, not a decision about you — and catalogue prices are recomputed daily across the whole catalogue, not for you individually.
15. Changes to this Policy
We may update this Privacy Policy from time to time. When we do:
- Material changes (new categories of personal information, new sub-processors, new uses, changed retention) — we will notify you by email at least 30 days before the change takes effect, and the cookie banner will re-prompt if the consent record changes materially.
- Non-material changes(clarifications, formatting, typo fixes) — we will update the “last updated” date in §2 and re-publish.
The current canonical version is always at vouchley.com.au/privacy. Previous versions are archived and available on request.
16. Conflicts with other documents
If there is any conflict between this Policy and:
- Our Terms of Service, this Policy prevails on privacy matters;
- The MSA between Vouchley and a Customer that enrolled you, this Policy prevails on the End User relationship and the MSA + DPA governs the Customer relationship;
- A specific notice or consent we asked you to agree to (for example a cookie banner choice), the specific notice governs the specific point of consent and this Policy applies to everything else.
— Vouchley, Privacy Policy v1.0.6, 2026-09-04.