Welcome

OCCUBUY AUSTRALIA PTY LTD – PRIVACY POLICY

Occubuy Australia Pty Ltd (ABN 15 659 763 523) (Occubuy, we, us or our) is committed to protecting your privacy.

This policy explains how we collect, use and protect your personal information.

It applies to all personal information we handle, whether we collect it through our website, in person, or through other means.


Occubuy is a rewards platform that helps aspiring home buyers earn points (Occubuy Points) by tracking their rental payments, including through open banking.

Our platform allows you to consolidate financial data, monitor your credit score, and compare relevant financial products and services to support your journey towards home ownership.

To deliver these features, we collect and process personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).


Quick overview

  • We collect information you provide to us and information we gather when we interact with you

  • We use this information to provide our services and improve your experience

  • We securely collect your banking data through our trusted partners Effi (via Yodlee) to track your payments and award you Occubuy Points and other benefits

  • We protect your information using secure systems and processes

  • We do not store your banking passwords

  • We do not share your banking data without your consent

  • We share your information with our service providers and partners, including cloud providers, payment processors, marketing platforms, our property partners, property professionals, and mortgage brokers.

  • You have rights regarding your personal information, including access and correction rights.

Information we collect

Basic identifying and contact details

  • Name, address, email address and phone number

  • Professional details

  • Government-issued identification (for verification purposes)

Financial and transaction information

  • Banking transaction data obtained through open banking

  • Rental payment history and property data

  • Income and employment details

  • Financial position including liabilities

  • Credit score information

  • Superannuation details

Service related information

  • Payment and transaction details for products and services you've purchased from us

  • Your preferences for our services and your marketing preferences

  • Feedback and survey responses

Digital information

  • IP address and general location information derived from your IP address

  • Search and browsing behaviour, including timestamps and pages visited

  • Website usage patterns

  • Browser / device type and version

  • Cookie preferences

Professional information (for job applicants and workers)

  • Employment history

  • Professional experience

  • Required authorisations and licences

  • Professional registrations

Sensitive Information

We do not actively request sensitive information about you. If at any time we need to collect sensitive information about you, unless otherwise permitted by law, we will first obtain your consent and we will only use it as required or authorised by law.


How we collect personal information

Directly from you when you:

use our platform, interact with us, contact us, and fill out forms


Automatically when you:

use our mobile application or visit our website, use our technologies, and interact with our online services


From third parties:

  • Open banking service providers: Effi and Yodlee, with your express consent, when you connect your bank account through our open banking integration.
    Yodlee’s privacy policy can be found at https://www.yodlee.com/au/legal/privacy-notice

  • Credit reporting: Experian, when you ask us to request or monitor your credit score

  • Identity verification: FrankieOne, for identity and “know your customer” verification

  • Technology providers: MongoDB (data storage), Jotform (forms), Firebase (analytics and notifications), Klaviyo (communications), and analytics/advertising providers

  • Payment processors / loyalty marketing providers: Zai, PokitPal, Apple and Google (for in-app purchases)

  • Marketing and advertising providers: Google Ads, Meta (Facebook/Instagram), Commission Factory (where we use affiliate links), News Corp

  • Public sources: including Linkedin and registers published by the Australian Securities and Investments Commission

  • Others: our other service providers, business partners, government organisations and organisations or people authorised by you.

Why we collect, hold, use and disclose personal information

We collect and use your personal information to run our business and provide our services as set out below.


Business operations

  • To track your transactions through open banking and provide you with Occubuy Points

  • To enable you to redeem Occubuy Points with our partners or service providers

  • To provide credit score monitoring and budgeting tools

  • To monitor your progress towards home ownership

  • To manage our relationship with you as a customer or supplier

  • To identify and suggest offers provided by us or businesses that we partner with

  • To process and deliver our products and services

  • To handle your inquiries, support requests, and communications

  • To maintain accurate records for billing and administration

  • To detect and prevent fraud and misuse

  • To verify your identity when required or permitted by law

  • To comply with legal and regulatory obligations (e.g “know your customer” and anti-money laundering)

Communication and support

  • To respond to your questions and support requests

  • To communicate important updates about our services

  • To handle inquiries made through our website or platforms

  • To manage your participation in surveys, feedback sessions, or events

Service improvement

  • To conduct analytics and market research

  • To improve our business operations and services

  • To develop and enhance our applications and platforms

  • To understand how our services are used

Marketing and promotions

  • To send you promotional information about our services and events

  • To inform you about products or services that may interest you

  • To manage your marketing preferences

  • To run competitions, promotions, and special offers

  • To provide additional benefits to our customers

Employment purposes

  • To assess employment applications

  • To evaluate candidate qualifications

  • To manage professional certifications and licences

  • To maintain employment records

Legal and compliance

  • To comply with our legal obligations

  • To respond to court orders or legal processes

  • To maintain required business records

  • To fulfill regulatory requirements or reporting obligations

  • To protect our legal rights and interests or as authorised by law

Our disclosures of personal information to third parties

We may disclose personal information to:


Service providers

  • IT service providers, including Jotform and Klaviyo

  • Referral/rewards partners, including PokitPal

  • Data storage providers, including MongoDB

  • Web hosting and server providers

  • Payment processors, including Zai, Apple and Google (for in-app purchases)

  • Marketing and advertising providers, including Google, Meta and News Corp

  • Analytics and notification providers, including Firebase

Professional advisers

  • Bankers

  • Auditors

  • Insurers and insurance brokers

  • Legal advisers

Business partners

  • Affiliates, contractors, employees

  • Property partners and real estate professionals

  • Mortgage brokers

  • Commission Factory and other referral networks

  • Our existing or potential agents

  • Our business partners or contractors

Corporate transactions

If we merge with or are acquired by another company, or sell our business assets:

  • Your information may be disclosed to our advisers

  • Your information may be disclosed to the potential purchaser's advisers

  • Your information may be included in the transferred assets

Legal and regulatory bodies

  • Courts and tribunals

  • Regulatory authorities including as required for reporting obligations

  • Law enforcement officers

Other parties

  • Third parties you have authorised

  • Emergency services when necessary

  • Any other parties as required or permitted by law

Overseas disclosure

Storage and access

We store your personal information in Australia. However, your information may be accessed from or transferred to locations outside Australia in these circumstances:

  • When our service providers are located overseas

  • When we work with overseas business partners

  • When using cloud-based services or data storage solutions

Our approach to overseas disclosure

Before disclosing your personal information overseas, we take reasonable steps to ensure that the recipient treats your information in accordance with applicable law by only sending what is necessary, requiring recipients to protect your information through contractual agreements which require the recipient to comply with the privacy standards in applicable law or through other mechanisms that provide comparable safeguards and by monitoring how recipients handle your information.


Your privacy rights and choices

Providing information

You can choose whether to provide personal information to us, however, if you don't provide certain information, we may not be able to provide some services.

Let us know if you don’t want to provide information and we will let you know when information is required versus optional.


Access to your information

You can request access to the personal information we hold about you and we will respond to your request within a reasonable time.

We may charge a reasonable administrative fee for providing access and if we cannot provide access, we will explain why and explore alternative ways to share relevant information.


Correction rights

You can ask us to correct any information that is inaccurate, out of date, incomplete, irrelevant or misleading and we will take reasonable steps to correct your information promptly.

If we cannot make the correction, we will explain why and discuss alternatives.

You can ask us to add a statement to your information noting your requested correction.


Marketing communications

You can opt-out of receiving marketing communications at any time. Each marketing communication will include an unsubscribe option.

You can change your marketing preferences through your account or by contacting us.

We will process your request as soon as practicable.


How to contact us about your rights or to make a complaint and what happens next

Step 1: Contact our privacy officer

Email: admin@occubuy.com.au

Post: 622 Harris St, Ultimo NSW 2007

What to include: Your full name, contact details, clear details about your request or complaint, and any relevant dates or reference numbers.


Step 2: Our response

We will:

  • Verify your identity before processing your request

  • Investigate thoroughly (for complaints) or process your request (for rights)

  • Respond to you in writing within reasonable timeframes

  • Explain what actions we will take and keep you updated on progress

  • Not charge you for making a request (except for reasonable access fees if applicable)

  • Help you understand and exercise your rights

Step 3: If you're not satisfied (complaints only)

If you're not satisfied with our response to your complaint, you can:

  • Ask for a review by our senior management, or

  • Contact external bodies:
    Australian residents: Office of the Australian Information Commissioner (Phone: 1300 363 992, Website: www.oaic.gov.au)

This is the same process whether you want to access your information, correct mistakes, change marketing preferences, or make a complaint about our privacy practices.


Protecting your information

We use industry-standard safeguards to protect your information, including encryption and access restrictions.

However, no transmission over the internet is completely secure.


Public information

Please note that any information you choose to share publicly on online platforms (such as comments or reviews) can be accessed and used by others.

We cannot control or protect information that you make publicly available.


How long we keep your information

We keep your personal information only as long as we need it for the purposes we collected it, or as required by law.

When we no longer need it, we securely destroy or de-identify it.


Cookies, Advertising and Analytics

What We Use

We use cookies, tracking pixels, and similar technologies on our website and in our emails to improve your experience and our services.


Cookies

  • Small text files stored on your device

  • Help remember your preferences

  • Enable certain website functions

  • Make your interactions with our website more efficient

Tracking Pixels

  • Tiny, invisible images in web pages and emails

  • Help us understand how you interact with our content

  • Allow us to measure email engagement

  • Enable more relevant content delivery

How we use these technologies

Essential Functions

  • Remember your login status

  • Maintain your session security

  • Store your preferences

  • Enable core website features

Analytics and Performance

  • Understand how our website is used

  • Measure page views and traffic

  • Analyse user navigation patterns

  • Identify areas for improvement

Personalisation

  • Remember your preferences

  • Tailor content to your interests

  • Improve your browsing experience

  • Provide relevant recommendations

  • Display targeted content and remarketing ads across third-party platforms

Your control

You can manage these technologies by:

  • Adjusting your browser settings to block or delete cookies

  • Using privacy-focused browser extensions

  • Configuring your email client to block images

  • Using our cookie preference settings

Note: Blocking all cookies may affect website functionality and your user experience.


Google Analytics

We use Google Analytics to understand how people use our website.

This involves cookies that collect information about your browsing activity.

You can opt out of Google's advertising features through your Google account settings, browser add-ons, or your device's privacy settings.

Google provides various tools and options to control how your data is used for advertising purposes.

You can learn more about how Google uses your data and your available options on Google's privacy pages.


Meta advertising tools

We use Meta's advertising tools (such as Meta Pixel) to understand how our ads perform and to show you more relevant advertisements on Meta platforms like Facebook and Instagram when you visit our website or app.

You can manage whether we connect information from our website with your Meta account for advertising purposes by adjusting your settings within your Meta account preferences.

Meta’s privacy policy can be found here.


Artificial Intelligence (AI) Technologies

Overview

We use artificial intelligence and machine learning technologies in our business operations and services, including AI tools provided by third parties.

We only use these technologies when legally permitted and necessary for our business.


How we use AI

We may use AI technologies to:

  • Conduct analysis and data processing

  • Generate and modify content and coding

  • Improve and optimise our services and operations

  • Assist with customer support and queries

Data protection and security

When we work with third-party AI providers, we ensure they handle your personal information in accordance with privacy laws through contractual requirements and appropriate safeguards.


Your rights and our commitments

Any information generated or inferred about you by AI technologies is treated as personal information, and you maintain all the rights outlined in this privacy policy.

When using AI with your personal information, we commit to:


Transparency and control

  • We'll inform you when AI is used to make decisions that may significantly affect you

  • We maintain human oversight and review of significant AI-generated decisions

  • Our staff are trained to understand AI limitations and verify outputs before relying on them

  • We implement processes to verify the accuracy of AI-generated outputs

Security

  • We use appropriate technical and organisational measures to maintain the security and integrity of your personal information

  • We regularly test and monitor AI outputs for accuracy and reliability

Risk mitigation

  • We regularly assess and document risks associated with using AI to process personal information

  • We implement appropriate measures to address these risks

  • We continuously monitor AI performance and regularly review their impact

Retention and Deletion of Personal Data

We retain your data only as long as necessary for the purposes outlined.

Data may be retained longer where legally required or for business continuity.

You may request deletion of your account and data via your profile settings or by contacting us directly.


Links to Other Sites

We may link to third-party sites or services not operated by us. We recommend reviewing their privacy policies.

We are not responsible for their content or practices.


Children's Privacy

Our Services are not intended for users under 13. We do not knowingly collect information from minors without verified parental consent.

If discovered, such data will be deleted.


Amendments

We may update this policy at any time by posting the revised version on our website.

You’ll be notified of material changes via email or app alerts.

We recommend that you review our website regularly to stay current with any policy changes.


Last updated: 24 November 2025

© LegalVision ILP Pty Ltd