Privacy Policy
We take your privacy seriously. This policy explains what we collect, why, who sees it, and what rights you have.
1. What information we collect
We collect personal information from you during the application process and while you have an active loan with us. This includes:
- Identity data — name, date of birth, residential address, identity document details
- Contact data — email, mobile, postal address
- Financial data — employer, income, expenses, bank statements (90 days, via illion), nominated bank account details
- Credit data — information about your credit activity (limited; see credit reporting below)
- Device data — IP address, browser, device identifiers, usage analytics
- Loan performance data — repayments, arrears, communications, hardship requests
2. Why we collect it
We use your information to:
- Assess your application under responsible lending obligations (NCCP)
- Verify your identity under AML/CTF obligations
- Service your loan — set up PayTo, debit repayments, send reminders
- Respond to queries, complaints, and hardship requests
- Comply with legal obligations (ASIC reporting, AUSTRAC, ATO, court orders)
- Improve our products — always with de-identified or aggregated data
3. Credit reporting
We do not make credit bureau inquiries as part of our decisioning process. We do not list repayment history information or default information on your bureau file for SACC loans.
We may, in limited circumstances, list a serious credit infringement (defined under the Privacy Act) if you have defaulted on a loan and we've exhausted reasonable collection efforts. In that case, we would notify you in writing at least 14 days before listing.
4. Who we share your information with
We share the minimum information necessary with:
- illion BankStatements — to retrieve 90 days of statement data with your consent
- FrankieOne — to verify your identity documents and screen against sanctions/PEP lists
- Monoova — to process PayTo mandates, disbursements, and direct debits
- Bacena Pty Ltd — our ACL holder, for compliance oversight
- AUSTRAC — threshold transaction reports and suspicious matter reports as required by law
- AFCA — in the event of a complaint
- Our cloud and analytics providers — under contracts that require Australian Privacy Principle compliance
We do not sell your personal information. We do not share your information for marketing purposes with third parties.
5. How we protect your data
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Role-based access controls — staff only see data necessary for their role
- Multi-factor authentication for all internal systems
- Audit logs of data access
- Penetration testing and security reviews annually
- ISO 27001-aligned information security management
6. How long we retain your data
We retain your data for 7 years after your loan closes, in line with AUSTRAC record-keeping requirements. After that period, we de-identify or delete the data.
If you apply but do not complete, we retain the partial data for 12 months then delete it, unless you request earlier deletion.
7. Your rights
Under the Privacy Act 1988 you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion (subject to legal retention requirements)
- Opt out of direct marketing communications at any time
- Lodge a complaint about our handling of your data
To exercise these rights, email privacy@cashlift.com.au. We'll respond within 30 days.
8. Complaints about privacy
If you believe we have breached the Australian Privacy Principles, contact privacy@cashlift.com.au. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
9. Overseas disclosure
Some of our service providers are located outside Australia (primarily the Philippines for operational staff, and the United States for certain cloud infrastructure). We ensure that overseas recipients handle your data to standards equivalent to the Australian Privacy Principles.
10. Changes to this policy
We update this policy as our practices or the law change. Material changes are notified to active customers by email. The current version and effective date are shown at the top of this page.