top of page
Privacy Policy
Effective Date: 1 May 2026
RFID.com.au (“RFID.com.au”, “we”, “our”, or “us”) is committed to safeguarding the privacy of users (“you” or “your”).
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you access or use our websites, applications, and services (collectively, the “Services”).
1. Introduction
This Privacy Policy governs the collection and processing of personal data through the Services. RFID.com.au is committed to complying with applicable data protection and privacy laws, including the GDPR, the Australian Privacy Act and other relevant regulations.
2. Personal Data We Collect
2.1 Types of Personal Data
We may collect and process the following categories of personal data:
-
Identity Information: Name and account identifiers used for account creation, authentication and service delivery.
-
Contact Information: Email address and phone number used for account verification, password recovery, customer support, notifications and marketing communications (where permitted and with consent where required).
-
Payment and Billing Information: Billing address and transaction references. Payment card data is processed by third-party payment providers and is not stored by RFID.com.au.
-
Bluetooth and Device Proximity Data: Used to detect proximity to supported hardware, vehicles, or fare media. This data is processed temporarily and not retained long-term unless required for dispute resolution or fraud prevention.
-
Usage and Technical Data: App usage metrics, diagnostics, crash data, and performance information.
-
Transaction and Activity Records: Service usage history, receipts, billing records and regulatory logs.
-
Account Preferences: Notification settings, interface preferences, and configuration options.
2.2 Sensitive Personal Data
Where required by law, sensitive personal data is processed with additional safeguards:
-
Location Data: May be processed continuously where required for service delivery, including background operation, subject to device permissions.
3. Legal Basis for Processing
We process personal data on one or more of the following legal bases, depending on jurisdiction:
-
Contractual Necessity: To provide the Services you request.
-
Consent: Where required by law, including for marketing communications or optional features.
-
Legitimate Interests: To operate, secure and improve the Services, provided those interests do not override your rights.
-
Legal Obligation: To comply with applicable laws, regulations and lawful requests.
4. How We Use Personal Data
Personal data is used for the following purposes:
-
Account creation, authentication and management
-
Service delivery, including real-time functionality
-
Communications, notifications and customer support
-
Payment processing and billing
-
Fraud detection and security monitoring
-
Analytics and service improvement
-
Legal and regulatory compliance
5. Data Retention
Personal data is retained only as long as necessary for its intended purpose or as required by law:
-
Active Accounts: Retained while the account remains active
-
Payment and Transaction Records: Typically 5–7 years
-
Inactive Accounts: Data may be anonymised or deleted after 24 months of inactivity
-
Anonymised Data: May be retained indefinitely
6. Data Security
RFID.com.au implements reasonable technical and organisational safeguards, including:
-
Encryption in transit and at rest
-
Role-based access controls
-
Secure third-party payment processing
-
Ongoing monitoring and security reviews
7. Sharing and Disclosure
We may share personal data with:
-
Service Providers: Cloud hosting, analytics, payment processors and operational partners.
-
Legal and Regulatory Authorities: Where required by law or lawful request.
-
Corporate Transactions: In connection with mergers, restructures or asset transfers.
All disclosures are made in accordance with applicable data protection laws.
8. Cross-Border Data Transfers
Personal data may be transferred to jurisdictions outside your country of residence, including Australia, the European Union, the United States, and Indonesia. Appropriate safeguards are applied to ensure lawful transfer and protection.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
-
Access your personal data
-
Correct inaccurate or incomplete data
-
Request deletion (subject to legal obligations)
-
Object to certain processing activities
-
Request data portability
-
Withdraw consent where processing is based on consent
Requests may be made to marketing@umd.com.au. We aim to respond within 30 days.
10. Notifications and Communications
Marketing communications are sent only where permitted and may be opted out at any time.
We may send:
-
Service and account notifications
-
Transaction confirmations
-
Emergency or safety alerts
11. Cookies and Tracking Technologies
Cookies and similar technologies are governed by the RFID.com.au Cookie Policy.
Non-essential cookies are used only where permitted by law and, where required, with your consent.
12. Data Breach Response
In the event of a data breach, RFID.com.au will take reasonable steps to mitigate impact and notify affected users and authorities as required by law.
13. Payment Processing
Payment information is processed by PCI-DSS-compliant third-party providers. RFID.com.au does not store payment card details.
14. Fraud Detection
We use automated and manual tools to detect and prevent fraud, misuse and unauthorised activity.
15. Disputes Related to Data
Privacy-related concerns should be directed to marketing@umd.com.au. Disputes are handled in accordance with applicable laws and the RFID.com.au Terms and Conditions.
16. Regulatory Compliance
RFID.com.au complies with applicable privacy laws, including:
-
GDPR (European Union)
-
Australian Privacy Act
-
CCPA (California, where applicable)
-
PIPEDA (Canada, where applicable)
-
Children’s data is handled in accordance with applicable legal requirements
17. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Material changes will be communicated via the Services. Continued use after changes take effect constitutes acceptance.
18. Contact
For privacy enquiries or rights requests, contact marketing@umd.com.au
bottom of page
