PRIVACY POLICY
- INTRODUCTION
Bano Pty Ltd ACN 643 260 431 trading as Bolt Financial Group and its related entities (collectively Bolt, we, us or our) respects the privacy of all customers, third parties, suppliers and visitors (you, your or yours) and is committed to protecting your personal information. We have implemented this Privacy Policy to provide information about what kinds of personal information we may collect or hold, how we collect, hold, use and disclose that personal information, choices you have regarding our use of that personal information, and your ability to access or correct that personal information. If you wish to make any inquiries regarding this Privacy Policy, you should contact our Privacy Officer in any of the ways specified in paragraph 13.
This Privacy Policy applies to all personal information collected by us, or submitted to us, whether offline or online, including personal information submitted by you through our website and any mobile sites (Websites), applications, widgets and other mobile interactive features (collectively, our Apps), or through our official social media pages that we control (our Social Media Pages), as well as through HTML-formatted email messages that we send to you (collectively, the Apps, Social Media Pages and Websites, are the Sites).
By visiting the Sites and otherwise providing personal information to us, you are accepting and consenting to the practices described in this Privacy Policy. If you do not agree with any of the terms of this Privacy Policy, please do not use the Sites or submit any personal information to us.
- WHAT IS PERSONAL INFORMATION
The Privacy Act 1988 (Cth) (Privacy Act) defines personal information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether the information or opinion is recorded in a material form or not (personal information).
- KINDS OF PERSONAL INFORMATION WE COLLECT
Bolt offers two types of services -- payments and payment processing services for individual or business customers (Bolt Payments) and a service that provides a platform for businesses and organisations operating financial services to manage their own financial services (Bolt Build). As part of the services we offer under Bolt Build, we may also facilitate identity verification checks of end users of Bolt Build customers by connecting the Bolt Build customers with the services of third party identity verification providers.
The types of personal information we may collect about an individual will depend upon the nature of our interaction with them, e.g. if you are a customer or user of Bolt Payments, a staff member of a customer using Bolt Build, an end user of a Bolt Build customer or if you otherwise come into contact with us.
Personal information that we collect may include (but is not limited to) the following:
- our Bolt Build customers and potential customers: details required to provide our products and services, set up your business account with us and monitor, identify and prevent fraud, including: your full name; date of birth; contact details; current and previous addresses; document identification numbers (such as passports, driver's licence, Medicare numbers, or other national cards); geographical location; business or company details including ABN and ACN; and the further information set out in paragraph 3.3
- our Bolt Build customers' customers: any data our Bolt Build customers process and store on our platform which may include their own customers' personal information; identity documents to enable us to facilitate identity verification checks on our customers' behalf through third party identity verification service providers, and the further information set out in paragraph 3.3. We note that we do not directly collect any personal information from Bolt Build customers' own customers, and we only hold this information about such individuals on behalf of our Bolt Build customers
- our Bolt Payments customers and potential customers: details to verify your identity, details required to provide our products and services, and monitor, identify and prevent fraud, including: your full name; date of birth; contact details; current and previous addresses; document identification numbers (such as passports, driver's licence, Medicare numbers, or other national cards); information about your financial position, like your income, expenses, savings and assets, your reasons and objectives for applying for a product or service; financial account details including bank account and credit card / debit card numbers; bank statements; invoices or proof of purchases relating to card transactions; geographical location; business or company details including ABN and ACN; transaction data including acquired card, QR code, Buy Now Pay Later, and spent card transaction data and the further information set out in paragraph 3.3
- our investors and shareholders: identification information and information about your shareholding, to identify our investors and shareholders and to administer their investment in us
- our suppliers, potential suppliers, and their representatives: generally information to assess your business (such as its key personnel); and business contact information (names, roles, contact details) to communicate with you, arrange and administer your provision of goods and services to us
- our employees past and present, including job applicants: occupation and employment details including employment status and any previous work experience; information in connection with your employment with us (which may include health information); and information from or in connection with your resume or job application if you apply for a position with us (including information from referees and to verify your qualifications, work and academic history), and
- any person who comes into contact with us or our technologies: information about your contact with us, including: data and metadata produced by collected data or interactions with us, including all user interactions with our devices, Sites, and other technologies; photographs and/or images from camera footage such as CCTV cameras in our premises; and information from social media accounts and profiles, and other publicly available sources.
We are also required by various laws to collect certain information including personal information. Those laws include the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), the AML/CTF Rules under the AML/CTF Act, and other regulatory schemes.
- HOW AND WHEN DO WE COLLECT PERSONAL INFORMATION
We collect personal information about you when it is reasonably necessary for one or more of our activities or functions. This personal information is collected in a number of ways, including through the Sites. For example, we may collect your personal information:
- when you apply for our products and services: when a potential Bolt Payments or Bolt Build customer submits an application for our products and services, including providing personal information so we can perform an identity verification check, on our Bolt Payments customers, or on the account holder of a Bolt Build customer; or when you request general information about our products
- when you use our products or services: when a Bolt Payments or Bolt Build customer uses our products and services, we collect information about that use including when you visit our Sites (see paragraph 5) and via other sources such as public databases, professional bodies (for example under reciprocal arrangements), regulators and government and statutory bodies; when enabled, we also facilitate identify verification checks through third party service providers for our Bolt Build customers, for identity checks they are making to verify their own customers, potential customers and others
- when we receive goods and services from you: when you provide information to manage our relationship with your business; and when we communicate with you
- when you attend our premises: when you visit or attend our premises we may collect visitor information and information from our security cameras and systems
- when you manage your relationship with us or otherwise communicate or interact with us: for example, when you provide feedback or information to us; when you submit a job application; or when you otherwise contact us by any means, and
- in other situations: when otherwise required or authorised by law.
Generally, when providing our products and services, dealing with our personnel, or obtaining goods and services from our service providers, suppliers or contractors, we collect personal information directly from the relevant individual where reasonable and practicable.
We may also collect personal information about you from third parties and other sources such as:
- identity verification service providers, third party databases, document issuers, official record holders, DVS and other sources in order to perform identity verification services for ourselves and on behalf of our Bolt Build customers as part of our Bolt Build service
- your nominated representatives (eg spouse, accountant, power of attorney, brokers and other professional advisors)
- publicly available sources of information, or
- related entities, companies and businesses of us,
but we will only collect your personal information in this way if it is unreasonable or impracticable to collect this information directly from you or if we are otherwise permitted to do so.
The provision of your personal information is voluntary. However, if you cannot, or will not, provide us with the personal information we reasonably require, we may not be able to verify your identity, assess your application for a product or service, manage our relationship with you, contact you or otherwise interact with you, perform our statutory functions, or provide you with some or all of our products and services.
- INFORMATION COLLECTED VIA OUR SITES
We may use various technological methods from time to time to track the visiting patterns of individuals accessing the Sites or using our technology including but not limited to the methods set out in this paragraph 5.
Google Analytics
We use Google Analytics to help analyse how you use our Websites. Google Analytics generates statistical and other information about website use by means of cookies, which are stored on users' computers. The information generated is used to create reports about the use of our Websites. Google will store this information.
If you do not want your Site visit data reported by Google Analytics, you can install the Google Analytics opt-out browser add-on. For more details on installing and uninstalling the add-on, please visit the Google Analytics opt-out page at https://tools.google.com/dlpage/gaoptout.
Click Stream Data
When you read, browse or download information from the Sites, we or our internet service provider may also collect information such as the date, time and duration of a visit, the pages accessed, the IP address of your computer, and any information downloaded. Generally, this information may be used for purposes including statistical, reporting and website administration, maintenance and improvement purposes.
Cookies
The Sites may use ‘cookies’ from time to time. Cookies are small text files that are transferred to a user's computer hard drive by a website for the purpose of storing information about a user's identity, browser type or website visiting patterns. Cookies may be used on the Sites to monitor web traffic, for example the time of visit, pages visited and some system information about the type of computer being used. We use this information to enhance the content and services offered on the Sites.
Cookies are sometimes also used to collect information about what pages you visit and the type of software you are using, and other purposes from time to time. If you access the Sites or click-through to the Sites from a link in an email we send you, a cookie may be downloaded onto your computer's hard drive.
You can configure your browser to accept all cookies, reject all cookies, or notify you when a cookie is sent. Each browser is different, so check the “Help” menu of your browser to learn how to change your cookie preferences.
If you disable the use of cookies on your web browser or remove or reject specific cookies from the Sites or linked sites then you may not be able to gain access to all of the content and facilities in those websites.
Web Beacons
Web beacons are images that originate from a third party site to track visitor activities. We use web beacons to track the visiting patterns of individuals accessing the Sites.
Interaction data
We collect and use all data and metadata produced by collected data or interactions with us, our products and services, the Sites, or our technology for purposes such as data analysis, improving service quality and improving product features. We may use this information generally for our business functions and activities, improving service quality, improving product features, and for use in connection with potential future products.
Third party content
Some of the content on our Sites may include applications made available by third parties, such as social media buttons or links that allow you to share content or links to our Websites through the relevant third party platforms. This also includes where you chose to link a third party account to your Bolt account. These third party applications themselves may facilitate collection of information by those third parties, through your interaction with the applications and sometimes even if you do not interact directly with them. We are not responsible for the technical operation of these applications or the collection and use practices of the relevant third parties. Please visit the relevant third party websites to understand their privacy practices and options they may make available to you in relation to their collection of your personal information.
- USE OF PERSONAL INFORMATION
We will not collect or use your personal information unless it is lawful for us to do so. We collect and use personal information for the following purposes:
- to communicate with you
- to identify you
- to seek identity verification of our Bolt Payments and Bolt Build customers for the provision of our services to them
- to facilitate identify verification services from third party service providers on behalf of our Bolt Build customers
- to consider any application made by you for products or services offered by us
- fulfilling orders or requests for information, products or services (with your consent, if required)
- fulfilling our role as financial services provider, including maintaining customer records, providing information on our services, products and benefits
- for promotional and marketing purposes, including communicating information about our products and services (with your consent, if required)
- monitoring, moderating and improving our Sites
- managing complaints
- providing information to Australian regulators, government and statutory bodies where required or permitted by applicable law
- assessing or improving our products and services, as well as for training and quality purposes, including building profiles, monitoring, recording and analysing online interactions and communications between you and us
- to engage with relevant registries using third party systems to match details contained in your Australian passport, driver licence, Medicare card, birth certificate and any other identification documents you provide us, and
- providing information to third parties as authorised or required by law or a court or tribunal.
We have a legitimate interest in using your information in these ways. It is also fundamental to the nature of the service we provide. In some cases, it will be lawful for us to collect and use your personal information, for example where it is necessary as part of our, or a third party's statutory function or because the law permits or requires us to.
- DISCLOSURE OF PERSONAL INFORMATION
We may disclose, or provide access to, your personal information to third parties in connection with the purposes described in paragraph 6. Depending on the circumstances and the nature of your engagement with us, we may disclose your personal information to our related entities, to third parties that provide products and services to us or through us, or to other third parties (such as your referee(s) in connection with a job application you have submitted).
We may also disclose your personal information to:
- our related and associated companies, affiliates and subsidiaries, including those established in the future: where they provide support and services to us or where they are involved in the provision of products or services to you
- your nominated representatives: in connection with providing you requested products or services and/or administering your account
- third parties involved in providing our services to you: such as payment scheme operators (such MasterCard, EFTPOS); business partners, and any party assisting us in carrying out the purposes described in paragraph 6; parties which participate in joint marketing schemes with us; any agent, contractor or service provider who provides verification of identity, administrative, order processing, payment clearing, credit reference, debt collecting or other services necessary to the operation of our business
- our other supply chain partners and vendors: who supply us goods and services or assist us in providing products and services to you; or who help us administer our business (such as data storage or processing (including in cloud based data storage facilities or through cloud computing service providers), printing, mailing, marketing, planning and product or service development), identity verification service providers, banks, lenders, valuers, insurers, brokers and other IT service providers; medical providers including medical and rehabilitation practitioners for assessing and managing workplace insurance claims (in respect of our employees); employment agencies (in respect of candidates or employees they have supplied or may supply to us)
- guarantors and security providers, credit bureaus, credit providers, brokers, agents, remitters, financial advisors: who assist us in providing products and services to you; or who help us administer our business (including compliance with the AML/CTF Act.
- people who provide advice or perform functions on our behalf, such as lawyers, auditors and business consultants: including for the purposes of providing that advice to us or performing those functions on our behalf, and
- law enforcement, regulatory and government bodies: such as regulatory authorities, law enforcement agencies, and other authorities or organisations as required or authorised by law (such as AUSTRAC, the ATO, ASIC, DHHS and the Police).
- OVERSEAS DISCLOSURES
Some of your personal information may be disclosed, transferred, stored, processed or used overseas by us, or by third party service providers. This may happen if:
- our offices or related entities are overseas
- we outsource certain activities overseas
- transactions, information, services or products have an overseas connection, or
- our computer systems (including third party IT service providers we may use from time to time) including IT servers are located overseas.
You consent to the collection, use, storage, and processing of your personal information outside of Australia as set out in this Privacy Policy.
In particular, your personal information may be disclosed to recipients in Hong Kong, China, New Zealand and Singapore. All service providers that have access to personal information held by us are required to keep the information confidential and not to make use of it for any purpose other than to provide financial or other services in accordance with their engagement. We will take all steps that are reasonably necessary to ensure your personal information is treated securely and in accordance with this Privacy Policy as well as applicable data protection laws.
- MARKETING
We will use your personal information (with your consent, if required under applicable data protection laws) when we process your personal information to send you carefully selected marketing materials about our products and services (or those of our third party partners) by email, text or push notification, depending on your operating system settings.
You have the right to opt out of receiving such direct marketing at any time by contacting us at the contact details specified at paragraph 13. In your request, please indicate that you wish to stop receiving marketing communications from us. Alternatively, you may opt out by clicking on the ‘Opt out’ or ‘Unsubscribe’ link in a direct marketing communication you receive from us.
- CORRECTION / CONCERNS ABOUT PERSONAL INFORMATION
Individuals may request access to their personal information unless we are permitted by law to withhold that information. Individuals may also request the correction of any personal information which is inaccurate by contacting our Privacy Officer at privacy@bolt.app.
To the extent permitted by law, there are some exceptions where this access may be denied. To request access and seek the correction of personal information held by us, please email, call or write to us. We will endeavour to respond to any access or correction request within 7 working days of receipt.
If you would like any further information about our handling of personal information, or to make a complaint about our handling of your personal information, or you believe there has been a breach by us of the Privacy Act, please lodge a complaint addressed to our Privacy Officer at privacy@bolt.app.
Once we receive your complaint, we will respond to you within a reasonable period of time, usually within 7 working days. If you are unsatisfied with the outcome of your complaint, you may contact us further to advise of your concerns and, if we are unable to reach a satisfactory resolution, you may wish to take your complaint to the Office of the Australian Information Commissioner. Phone: 1300 363 992. Website: www.oaic.gov.au.
- SECURITY OF PERSONAL INFORMATION
We use reasonable organisational, technical and administrative measures and security safeguards to protect, as is reasonable in the circumstances, the personal information we hold from misuse, loss, interference and/or unauthorised access, use, disclosure or alteration of information under our control. Where practicable, we implement measures to require organisations to whom disclosure is made to comply with applicable data protection and privacy laws. If a third party is given access to personal information, we take reasonable steps to ensure that the information is held securely and used only for the purpose of providing the relevant service or activity. Unfortunately, no data transmission over the internet or data storage system can be guaranteed to be 100% secure.
We will only retain your personal information for as long as is necessary for the purpose for which that personal information was collected and to the extent permitted by applicable laws. When we no longer need to use personal information, we will remove it from our systems and records and/or take steps to anonymise it so you can no longer be identified from it.
- VARIATIONS TO THE PRIVACY POLICY
We reserve the right to modify this Privacy Policy at any time by publishing an updated version on our Websites and taking any further action as required by law, after which, your continued use of the Websites or your provision of any further personal information will indicate your acknowledgement to the modified terms of this Privacy Policy.
- HOW TO CONTACT US
If you:
- have a query or concern about this Privacy Policy or our personal information handling processes
- wish to make a complaint in relation to a breach of your privacy
- would like to access your personal information held by us
- would like to update or correct your personal information held by us, or
- would like to opt out of direct marketing,
please contact our Privacy Officer at privacy@bolt.app.
This Privacy Policy was last updated on 21 May 2025