top of page

Privacy Policy

Effective Date: 1 May 2026

RFID.com.au (“RFID.com.au”, “we”, “our”, or “us”) is committed to safeguarding the privacy of users (“you” or “your”).

This Privacy Policy explains how we collect, use, disclose, and protect personal data when you access or use our websites, applications, and services (collectively, the “Services”).
 

1. Introduction

This Privacy Policy governs the collection and processing of personal data through the Services. RFID.com.au is committed to complying with applicable data protection and privacy laws, including the GDPR, the Australian Privacy Act and other relevant regulations.
 

2. Personal Data We Collect

2.1 Types of Personal Data

We may collect and process the following categories of personal data:

  • Identity Information: Name and account identifiers used for account creation, authentication and service delivery.

  • Contact Information: Email address and phone number used for account verification, password recovery, customer support, notifications and marketing communications (where permitted and with consent where required).

  • Payment and Billing Information: Billing address and transaction references. Payment card data is processed by third-party payment providers and is not stored by RFID.com.au.

  • Bluetooth and Device Proximity Data: Used to detect proximity to supported hardware, vehicles, or fare media. This data is processed temporarily and not retained long-term unless required for dispute resolution or fraud prevention.

  • Usage and Technical Data: App usage metrics, diagnostics, crash data, and performance information.

  • Transaction and Activity Records: Service usage history, receipts, billing records and regulatory logs.

  • Account Preferences: Notification settings, interface preferences, and configuration options.
     

2.2 Sensitive Personal Data

Where required by law, sensitive personal data is processed with additional safeguards:

  • Location Data: May be processed continuously where required for service delivery, including background operation, subject to device permissions.
     

3. Legal Basis for Processing

We process personal data on one or more of the following legal bases, depending on jurisdiction:

  • Contractual Necessity: To provide the Services you request.

  • Consent: Where required by law, including for marketing communications or optional features.

  • Legitimate Interests: To operate, secure and improve the Services, provided those interests do not override your rights.

  • Legal Obligation: To comply with applicable laws, regulations and lawful requests.
     

4. How We Use Personal Data

Personal data is used for the following purposes:

  • Account creation, authentication and management

  • Service delivery, including real-time functionality

  • Communications, notifications and customer support

  • Payment processing and billing

  • Fraud detection and security monitoring

  • ​Analytics and service improvement

  • Legal and regulatory compliance
     

5. Data Retention

Personal data is retained only as long as necessary for its intended purpose or as required by law:

  • Active Accounts: Retained while the account remains active

  • Payment and Transaction Records: Typically 5–7 years

  • Inactive Accounts: Data may be anonymised or deleted after 24 months of inactivity

  • Anonymised Data: May be retained indefinitely
     

6. Data Security

RFID.com.au implements reasonable technical and organisational safeguards, including:

  • Encryption in transit and at rest

  • Role-based access controls

  • Secure third-party payment processing

  • Ongoing monitoring and security reviews
     

7. Sharing and Disclosure

We may share personal data with:

  • Service Providers: Cloud hosting, analytics, payment processors and operational partners.

  • Legal and Regulatory Authorities: Where required by law or lawful request.

  • Corporate Transactions: In connection with mergers, restructures or asset transfers.

​All disclosures are made in accordance with applicable data protection laws.
 

8. Cross-Border Data Transfers

Personal data may be transferred to jurisdictions outside your country of residence, including Australia, the European Union, the United States, and Indonesia. Appropriate safeguards are applied to ensure lawful transfer and protection.
 

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data

  • Correct inaccurate or incomplete data

  • Request deletion (subject to legal obligations)

  • Object to certain processing activities

  • Request data portability

  • Withdraw consent where processing is based on consent

Requests may be made to marketing@umd.com.au. We aim to respond within 30 days.
 

10. Notifications and Communications

Marketing communications are sent only where permitted and may be opted out at any time.
We may send:

  • Service and account notifications

  • Transaction confirmations

  • Emergency or safety alerts
     

11. Cookies and Tracking Technologies

Cookies and similar technologies are governed by the RFID.com.au Cookie Policy.
Non-essential cookies are used only where permitted by law and, where required, with your consent.
 

12. Data Breach Response

In the event of a data breach, RFID.com.au will take reasonable steps to mitigate impact and notify affected users and authorities as required by law.
 

13. Payment Processing

Payment information is processed by PCI-DSS-compliant third-party providers. RFID.com.au does not store payment card details.
 

14. Fraud Detection

We use automated and manual tools to detect and prevent fraud, misuse and unauthorised activity.
 

15. Disputes Related to Data

Privacy-related concerns should be directed to marketing@umd.com.au. Disputes are handled in accordance with applicable laws and the RFID.com.au Terms and Conditions.
 

16. Regulatory Compliance

RFID.com.au complies with applicable privacy laws, including:

  • GDPR (European Union)

  • Australian Privacy Act

  • CCPA (California, where applicable)

  • PIPEDA (Canada, where applicable)

  • ​Children’s data is handled in accordance with applicable legal requirements
     

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material changes will be communicated via the Services. Continued use after changes take effect constitutes acceptance.
 

18. Contact

For privacy enquiries or rights requests, contact marketing@umd.com.au

bottom of page