Skip to content

Legal

Privacy Policy

How Surepayd collects, uses, stores and discloses personal information, and how to reach us about it.

Last updated

Who we are

SurePayd Services Pty Ltd (ABN 92 617 873 935), trading as Surepayd, provides Working Capital Infrastructure to businesses in Australia and New Zealand. This policy covers both this website and the platform we operate for our clients.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we hold information about people in New Zealand, we also act in accordance with the Privacy Act 2020 (NZ).

Privacy enquiries, requests to access or correct your information, and privacy complaints should be sent to enquiries@surepayd.com.

Information we collect

What we hold about you depends on how you came to us. There are three relationships and they are genuinely different, so they are set out separately.

If you use this website
Almost nothing, unless you contact us. The site sets no cookies. It counts visits using privacy-preserving analytics that cannot identify you and cannot follow you to another site. If you submit the contact form we collect your name, work email address, company and your message. Your role and the ERP you run are optional.
If you use Surepayd for your employer
Your name, work contact details, role and permissions, and a record of the actions you take in the platform. The audit trail is a product feature your employer relies on, so it is not optional.
If you owe money to a business that uses Surepayd
We hold what that business gave us: typically your name and contact details, your account and invoice history, payment records, and any disputes or payment arrangements. We collected it from them, not from you, and we hold it on their behalf.

Where a client uses our onboarding and credit modules, we also obtain credit information from credit reporting bodies and carry out PPSR searches. We do that on the client's behalf, under the authority they obtained from the applicant.

The contact form carries one hidden field and a timestamp. They exist to detect automated submissions and are discarded with the rest of the submission. They record nothing about you.

How we use your information

  • To answer your enquiry and arrange a conversation.
  • To provide the platform to the client who engaged us: presenting invoices, taking payments, sending reminders, recording disputes and maintaining account history.
  • To contact our clients' customers on their behalf, by email, SMS, voice or through the customer portal.
  • To assess credit applications and monitor credit risk, where a client uses those modules.
  • To keep the platform secure, investigate misuse and meet our legal obligations.

We do not sell personal information, and we do not use it for advertising.

We do not train models on one client's data and then use them to serve another. Models are trained per client, on that client's own data, and nothing crosses the boundary between clients. Your transactions do not teach a model that someone else uses, and no model we run for you has learned anything from anyone else's.

Who we share it with

We share personal information with the providers that make the platform work, and with nobody else, unless the law requires it of us.

WhoWhat forWhere they hold it
The client who engaged usTheir own customer, account and payment dataAustralia and New Zealand
Payment providersProcessing a payment you choose to makeAustralia and New Zealand
Credit reporting bodiesCredit assessment and monitoring, on a client's authorityAustralia and New Zealand
Communications providersSending email, SMS and voice messagesVaries by provider
ResendDelivering enquiries submitted through this websiteUnited States
Plausible AnalyticsCounting visits to this website, without identifying youEuropean Union

Platform data is stored and processed within Australia and New Zealand. Enquiries submitted through this website are different: they are delivered by Resend, which operates from the United States, so a website enquiry does leave Australia. If you would rather not send personal information offshore, email us at enquiries@surepayd.com instead.

Storage, security and retention

Platform data is held in Australia and New Zealand. It is encrypted with AES-256 at rest and TLS 1.3 in transit. Access is role-based, with single sign-on and multi-factor authentication enforced, and every action is written to an immutable audit log that can be exported on request.

Surepayd holds SOC 2 Type II certification, and our information security management is aligned to the ISO 27001 standard. The platform is penetration tested annually by an independent security firm.

An enquiry submitted through this website is kept for 24 months and is then deleted.

Client data is kept for 90 days after an agreement ends, which leaves time to export it and to settle any final reconciliation, and is then deleted. Where the law requires us to keep something for longer, we keep only what it requires, for only as long as it requires.

Accessing and correcting your information

You can ask what personal information we hold about you, ask us to correct it, and ask us to delete it where we are not required to keep it. Write to us and we will respond within 30 days.

If you are a customer of a business that uses Surepayd, that business controls the information and we hold it for them. Ask them first, because they can act on it immediately where we would have to seek their instruction. If you cannot reach them, or they do not respond, contact us and we will help.

We will not charge you for making a request. If we refuse one we will tell you why, in writing.

Cookies and analytics

This website sets no cookies. It runs no advertising tags and no tracking scripts. Nothing is stored in your browser, and we do not ask you to accept anything in order to read the site.

We do measure how the site is used, with Plausible Analytics. It is built so that measurement does not require identifying you. It sets no cookie, stores nothing in your browser, and creates no lasting identifier, so it cannot recognise you tomorrow, on another device, or on any other website.

It records the page you viewed, where you arrived from, your browser and device type, your approximate location from your country down to your city, and how far you read. Your IP address and browser identification string are used in the moment to work those out and are then discarded rather than stored. The daily identifier that counts you as one visitor rather than several is scrambled using a value that is destroyed every twenty-four hours, which is what stops it following you from one day to the next.

All of it is held in the European Union and does not leave it. Because none of it is personal information and none of it is stored on your device, no consent is required for it under Australian, New Zealand or European law, which is why this site has no cookie banner. We chose the tool specifically so that it would not need one.

If that changes, this section will be updated before the change goes live. If a tool we add requires your consent, we will ask for it rather than assume it.

Complaints about privacy

If you think we have mishandled your personal information, tell us. Our complaints process sets out how to raise it and what happens next, and a privacy complaint follows the same path.

If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner, or, in New Zealand, to the Office of the Privacy Commissioner. You do not need our agreement to do that.

Changes to this policy

We update this policy when what we do changes. The date at the top of this page is the date of the current version.

Where a change materially affects how we handle information we already hold, we will tell affected clients directly rather than relying on you noticing the date.