1. Who We Are, and How This Policy Is Arranged
This Privacy Policy explains how PAYBTC Pty Ltd (ACN 694 153 832, ABN 52 694 153 832), trading as paybtc ("we", "our", or "us"), collects, uses, discloses, stores, and protects your personal information across our two products:
- the paybtc web exchange at paybtc.com.au, and
- the b app, our native iOS Bitcoin wallet.
We do two different things, and which one you use decides what we hold about you.
- The wallet is a self-custody Bitcoin wallet in the b app, available in the countries where we offer it. It needs no identity verification, and we never learn who you are. Section 2 sets out what we hold about a wallet user.
- Buying and selling Bitcoin for Australian dollars, through the app or the paybtc.com.au web exchange, is available in Australia only, to customers who verify their identity and are 18 or over. That is where the AML/CTF Act requires us to verify your identity, monitor transactions, and keep records for seven years.
Both are non-custodial for your Bitcoin, with one exception, an optional custodial Card balance that is not yet available and that exists only to make Visa card payments work in Australia.
This policy is in four parts, so that you can read the part that describes you rather than work out which paragraphs apply.
| Part | What it covers | Read it if |
|---|---|---|
| This first part | Who we are and how this policy is arranged | Everyone |
| The b wallet | What we hold about a wallet user, how your wallet reaches the Bitcoin network, your keys and what we cannot do, and using the app outside Australia | You use the b app |
| Buying and selling Australian dollars | Identity verification, our obligations under the AML/CTF Act, who we disclose information to, and sending information overseas | You buy or sell Australian dollars, in the app or on the web exchange |
| Everything else | Security, how long we keep information, your rights, breaches, marketing, complaints, and how to reach us | Everyone |
If you use the wallet and nothing else, the part on buying and selling does not describe you. None of it is collected, because we never ask you who you are.
We are registered with AUSTRAC under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) ("AML/CTF Act"), registration number DCE100926176-001. Following amendments to that Act which took effect on 31 March 2026, businesses previously registered as digital currency exchange providers are registered as virtual asset service providers. Our registration number is unchanged. We are a member of the Australian Financial Complaints Authority (AFCA).
We handle your personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the thirteen Australian Privacy Principles ("APPs").
This policy is a notice, not a consent form. Where we rely on your consent for something specific, such as marketing, we ask you for it separately and you can withdraw it.
The b wallet
2. What We Hold About a Wallet User
If you use the wallet and nothing else, we do not hold a record that says who you are. We do not ask for your name, your address, or any document, and we do not verify your identity.
That is not the same as being untraceable. The first time you open the app it creates an account with our server automatically, identified by a key your device generates, and every request your app makes to us carries your IP address. We do not know whose IP address it is. Your internet provider does. If a court or a law enforcement agency compels us, we hand over what we hold, and combined with your provider's records that can be enough for them to identify you.
What we receive is:
- the wallet account described in section 4.6, being an account number we assign, a public key your device generates, and a device check issued by Apple. It carries no name and we cannot turn it into your name, but it is the same account every time your app connects, so it lets us recognise the same wallet over time;
- the Bitcoin addresses your app asks our server about, including the internal addresses your wallet uses for change, and the IP address it asks from, see section 4.2;
- the receiving addresses your app registers with us so we can notify you when a payment arrives, which it does whenever the app opens;
- the transaction identifiers of your on-chain transactions, which your app sends us so we can return the Bitcoin price at the time of each one and show your history in your own currency;
- technical records about your Spending balance that let us watch the Bitcoin network on your behalf and warn you if your funds ever need rescuing. These are references to your Lightning positions, not keys, and we cannot spend from them;
- the times your app connects. While the app is open it asks us for the Bitcoin price regularly, so this is a continuing signal rather than an occasional one;
- if you choose a payment handle ending in @getb.app, the handle you chose and the payments it receives;
- crash and stability reports, if your device is set to share analytics with developers, and a push notification token if you allow notifications; and
- anything you write to us if you contact support, including any file you attach.
The silent payments scan key described in section 4.3 goes to a third party, not to us.
None of this carries a name, an address or a document. Taken together it is still a durable record of one wallet's addresses, transactions and connection times.
The identity, financial, and transaction information in sections 10.1 to 10.3 is collected only from customers who verify to buy or sell Australian dollars, which is available in Australia only. If that is not you, we hold none of it.
If you later verify your identity to buy or sell. The wallet account above is the same account your verification attaches to. From the moment you verify, the identity information in sections 10.1 to 10.3 sits alongside the wallet records we already held for that device, including addresses and transaction identifiers from before you verified.
3. What Stays on Your Device
The following is created and held on your device. We never receive it and we have no technical means of obtaining it:
- your Recovery Phrase, the twenty-four words that control your Bitcoin, generated on your device using the operating system's cryptographic random number generator;
- the private keys that spend your Bitcoin, which are derived from your Recovery Phrase and used on your device to sign each transaction; and
- your Face ID or Touch ID data, which iOS keeps in the Secure Enclave. No app can read it, including ours. We only ever receive a yes or no answer from iOS about whether you unlocked.
About your iCloud backup. Your Recovery Phrase is backed up to your own iCloud account, and this is a requirement of creating a wallet in b, not an optional extra. If you are not signed in to iCloud, the app cannot create a wallet for you.
How it works. Your device encrypts your Recovery Phrase on the device and stores the encrypted result in our app's private area of your iCloud account. The key that unlocks it is held in your iCloud Keychain, which Apple protects with end-to-end encryption. Apple therefore holds an encrypted file it cannot read and a key it cannot read. We hold neither. We cannot retrieve your Recovery Phrase, because we do not hold it or the key that unlocks it.
What this means for you. Turning iCloud Keychain off does not remove the backup, it removes your ability to restore from it on another device, so do not treat it as a way to opt out. If you want a backup you control, export your Recovery Phrase from the app's settings and keep it somewhere safe. The export shows the words one at a time and is hidden from screenshots and screen recordings.
One important exception is set out in section 4.3. A scan key derived from your Recovery Phrase is shared with the third party service that finds silent payments, every time the app starts, for every wallet, whether or not you use the feature. It cannot move or spend your Bitcoin. It can see payments made to you. Section 4.3 explains this in full.
4. How Your Wallet Talks to the Bitcoin Network
A Bitcoin wallet has to ask the network about your addresses in order to show your balance and history. That is how every Bitcoin wallet works. This section explains who your app talks to and what they can see, because we think you should be able to find that out without reading our source code.
4.1 The public blockchain
Bitcoin transactions are recorded on a public blockchain that anyone can read. We are not responsible for that public availability, and we cannot reverse, freeze, or amend a confirmed transaction. We record the wallet addresses and transaction hashes associated with your account, because the wallet cannot show you your balance and history without them.
4.2 The servers your wallet queries
To show your Savings balance and history, the b app queries a Bitcoin server about the addresses in your wallet.
- Normally this is our own server. That means our infrastructure can see which Bitcoin addresses belong to your wallet, along with your IP address and the time of the request. We use it to operate the wallet and to meet our obligations. We do not sell it and we do not use it for advertising.
- If our server is unavailable, the app falls back to public Bitcoin servers run by unrelated operators, so that your wallet keeps working. Those servers are located in various countries. They can see the addresses queried and your IP address. They do not receive your name, your account, or your identity documents, and they have no relationship with us.
- You can point the app at a Bitcoin server of your own choosing in the app's settings. The app will prefer it, but if it stops responding the app still falls back to our server and then to the public ones, and choosing your own server does not change what section 2 says we receive.
4.3 Silent payments and the scan key
The b app supports silent payments, a newer Bitcoin feature that gives you a reusable address that does not reveal your payment history publicly. Finding payments made to a silent payment address requires scanning the blockchain, which is too heavy to do on a phone. The app therefore uses a specialist scanning service, operated by a third party, and it shares a scan key and your silent payment public key with that service so the service can tell your app which transactions may be payments to you. The connection stays open while the app is running, so that operator also sees your IP address.
This happens for every wallet, not only for wallets that use silent payments. Each time the app starts it connects to that service and shares the scan key, whether or not you have ever chosen a silent payment address, and there is currently no setting to switch it off.
What this means in practice. The scan key cannot move, spend, or freeze your Bitcoin. It is a viewing key, not a spending key. What it does allow is for the operator of that scanning service to see payments made to your silent payment address. This happens as part of the wallet's normal operation. Your Recovery Phrase and your spending keys are not shared, and they never leave your device.
We may operate this scanning service ourselves in future, so that the scan key stays within our systems.
4.4 Lightning
Your Spending balance operates over the Lightning Network. You hold the keys and you sign each payment. We cannot reverse a Lightning payment once it is made.
4.5 Price data
The app gets the Bitcoin price from our own servers, not from a third party market data service. While the app is open it asks us for current and historical prices. Those requests carry your IP address, and they are frequent enough that our server logs show when your app is open. They do not carry your addresses or your balances.
4.6 The account your app creates
The first time you open the b app it creates an account on our servers automatically. You are not asked to sign up and it holds no name. It consists of an account number we assign, a public key your device generates and keeps, and a check from Apple that tells us the app is genuine and running on a real device that has not been tampered with. We record when your app connects.
We do this so that our servers can tell one installation from another, so we can stop people abusing our infrastructure, and so your app can ask us for things such as the Bitcoin price, notifications, and the network watching described in section 4.4. It is not linked to your name, and it stays unlinked unless you verify your identity to buy or sell Australian dollars, in which case section 2 explains what happens.
5. Custody, and What We Cannot Do
5.1 The web exchange
Fully non-custodial. Bitcoin you buy is delivered to the external wallet address you provide. We never hold it or control the keys.
5.2 Savings, in the b app
On-chain Bitcoin in a self-custody wallet on your device. Your keys, your Bitcoin. We cannot move, freeze, or recover it. Backup is your responsibility. Creating a wallet requires a signed-in iCloud account, and an encrypted backup is placed in your own iCloud, as section 3 explains. A manual export is available in the app's settings.
5.3 Spending, in the b app
Bitcoin on the Lightning Network in a self-custody wallet on your device. Your keys, your Bitcoin. Every payment is signed on your device.
5.4 The Card, not yet available
The Card balance will be the only custodial product we offer. It will be available only to Australian customers who complete identity verification and choose to enrol, and it will be funded by transferring Bitcoin from your own balances into a pool we control, so that we can settle Visa authorisations without your phone being online. At the point of sale, Bitcoin is converted to Australian dollars and paid to the merchant. You will be able to withdraw an unspent balance back to your own wallet. Separate terms will apply and the Card is not available today.
6. The b App on Your Phone
6.1 Your Recovery Phrase
Generated on your device. An encrypted backup is placed in your own iCloud account, which is a requirement of creating a wallet, and neither Apple nor we can read it. See section 3. A manual export is available in the app's settings, which reveals the words one at a time so that a screenshot cannot capture them. We do not prompt you to export at any balance.
6.2 Face ID and Touch ID
Used only to unlock the app on your device. The biometric data is held by iOS and is never available to us. We receive only the result.
6.3 Push notifications
If you allow them, we use Apple's push notification service to deliver transaction confirmations, security alerts, and service notices. You can turn them off in your device settings.
6.4 Crash reports and diagnostics
We receive crash and stability reports through Apple's standard developer tools. The b app does not include any third party analytics, advertising, or tracking software. We do not track you across other apps or websites, and there is nothing in the app that profiles you for advertising.
7. Australian AML/CTF Law Does Not Apply to Your Wallet
Our obligations under the AML/CTF Act, including identity verification, monitoring, reporting, and the seven year retention period in section 20, attach to the Australian exchange services. They do not attach to giving you a self-custody wallet. So the retention periods that bind us for verified Australian customers do not apply to wallet-only users, and the technical data we hold about you is kept for the periods in section 20 for logs and diagnostics, not for seven years.
8. Age
b is for people aged 18 and over. That applies to the wallet as well as to buying and selling.
We do not check your age for the wallet, because we do not collect any identity information for it, so that is a rule you agree to rather than one we verify. For buying and selling we check date of birth during identity verification, before any account is created for transacting, so that one is enforced.
We do not knowingly collect personal information from anyone under 18, and if we find that we have, we delete it. If you believe someone under 18 is using the app, tell us and we will delete what we hold about that device.
Bitcoin is not reversible, and a lost Recovery Phrase cannot be recovered by anyone. Nobody, including us, can undo a payment you make or recover funds you lose.
9. If You Are Outside Australia
The b app wallet is available in the countries where we offer it, and most of this policy applies to you in the same way wherever you are. This section covers what is different.
9.1 If you are in the European Economic Area or the United Kingdom
Where the General Data Protection Regulation or the UK GDPR applies to you, the following applies as well as the rest of this policy. Where anything in this section conflicts with the rest of the policy, this section wins for you.
Who is responsible. PAYBTC Pty Ltd (ACN 694 153 832) is the controller of your personal data. We are established in Australia and we have no establishment in the European Union or the United Kingdom.
The b app is available in the countries where we offer it, which includes the European Economic Area and the United Kingdom. The paybtc.com.au web exchange is a separate service, offered to Australian residents only and priced in Australian dollars, so the buying and selling part of this policy does not apply to you.
You can raise anything in this policy with us directly using the contact details at the end of it.
Why we are allowed to process your data. We rely on:
- performance of a contract (Article 6(1)(b)), to give you the wallet you asked for and to make it work, which includes asking a Bitcoin server about your addresses so we can show you your balance;
- our legitimate interests (Article 6(1)(f)), to keep the app secure, to prevent fraud and abuse, and to diagnose crashes and faults. We have considered your interests and rights against ours and consider these uses to be ones you would reasonably expect from a wallet application; and
- your consent (Article 6(1)(a)), for push notifications and for marketing, which you can withdraw at any time without affecting the wallet.
We do not rely on consent to operate the wallet itself, so you are not asked to consent to something you cannot refuse.
Your rights. You may ask us to give you a copy of your personal data, correct it, erase it, restrict how we use it, or give it to you in a portable form. You may object to processing we carry out on the basis of legitimate interests. You may withdraw any consent you have given. We will respond within one month, and will tell you if we need longer because a request is complex.
Two practical limits, stated plainly. First, we cannot identify you from a wallet alone, so if you ask us to find "your" data we may be unable to locate it without information that identifies your device or connection, and Article 11 allows us to say so rather than collect more data about you in order to answer. Second, Bitcoin transactions are recorded on a public blockchain that we do not control and cannot alter, so no right of erasure or rectification can reach them.
Where your data goes. We are in Australia and your data is handled here. When you use the wallet, your device gives us your data directly, so under European Data Protection Board guidance that is collection rather than an international transfer, and the transfer rules in Chapter V of the GDPR do not apply to it. It is still processed outside the European Economic Area and the United Kingdom, and we are telling you so because you are entitled to weigh it. Australia has no adequacy decision from the European Commission and none from the United Kingdom, and Australian law gives Australian authorities powers to compel access to data in some circumstances. We have taken that into account in how we secure what we hold and how long we keep it, and section 19 sets out the protections.
The transfer rules do apply when we pass your data to someone else outside the European Economic Area. If you use the wallet and nothing else, the recipients are:
- the silent payments scanning service described in section 4.3, operated by a third party, which receives the scan key and your IP address;
- the Lightning service provider that your self-custody Spending balance runs on, which sees the payment activity of that balance and your IP address;
- Apple Inc, in the United States, which delivers the app, delivers push notifications, and passes us crash reports if your device is set to share analytics with developers;
- Bitcoin servers run by unrelated operators in a number of countries, which your app uses if ours is unavailable and which see the addresses queried and your IP address, see section 4.2; and
- the providers who host our own systems.
Where a recipient is in a country without an adequacy decision, our agreement with that recipient incorporates the standard contractual clauses approved by the European Commission, or for the United Kingdom the International Data Transfer Agreement or the UK Addendum. You can ask us for a copy of those safeguards and we will give you one with commercial terms removed.
How long we keep it. The Australian seven year retention rules do not apply to you unless you become a verified Australian customer. Technical logs and diagnostics are kept for the periods in section 20 and then deleted or de-identified.
Complaining. Come to us first. You also have the right to complain to a supervisory authority, and you do not need our permission or our agreement to do it. In the European Economic Area that is the data protection authority of the country where you live, where you work, or where you say the problem happened. A list is published by the European Data Protection Board at edpb.europa.eu. In the United Kingdom it is the Information Commissioner's Office at ico.org.uk.
9.2 If you are somewhere else
If the law of the country where you live gives you privacy rights beyond those in this policy, we will honour them where that law applies to us. Ask us.
Buying and selling Australian dollars
10. What We Collect
This part applies if you verify your identity to buy or sell Australian dollars. If you use the wallet and nothing else, none of it is collected, because we never ask you who you are.
10.1 Identity and account information
To meet our Know Your Customer obligations under the AML/CTF Act, we collect:
- full legal name, date of birth, and residential address;
- email address, used as your primary account identifier and for login verification codes;
- phone number, used for verification and security communications;
- government issued photographic identification, such as an Australian passport, driver licence, or proof of age card; and
- additional identity evidence where the AML/CTF Act requires it, such as a Medicare card, a utility bill, or certified copies for non-Australian residents.
10.2 Financial information
- Australian bank account details, including BSB and account number;
- PayID information associated with your bank account;
- bank statements you provide for source of funds verification; and
- Bitcoin wallet addresses you provide for receiving or sending Bitcoin.
10.3 Transaction information
- records of buy, sell, and withdrawal transactions;
- amounts in Australian dollars and Bitcoin, the exchange rate applied, and timestamps;
- Bitcoin transaction hashes and blockchain confirmation details;
- where you buy Bitcoin for delivery to a wallet address outside the app, your confirmation that the receiving wallet is yours, recorded with the date and time, which Australian law requires us to collect and keep; and
- for the b app, Lightning send and receive events, and, once the Card is available, top-up and spend records associated with it.
10.4 Communications
- records of correspondence, support requests, and feedback; and
- any other information you choose to give us.
10.5 Information from third parties
- identity verification, transaction monitoring, sanctions and politically exposed person screening, adverse media, and travel rule data from our identity verification and screening provider;
- Australian dollar payment data from our Australian banking and settlement provider;
- sanctions lists published by the Department of Foreign Affairs and Trade and equivalent international bodies;
- information from AUSTRAC, law enforcement, and other government bodies in connection with our regulatory obligations; and
- publicly available information used for identity verification and fraud prevention.
10.6 Sensitive information
We do not seek to collect sensitive information as defined in the Privacy Act, such as health information, racial or ethnic origin, political opinions, or religious beliefs. Government issued identity documents may incidentally contain information of that kind. Where they do, it is collected only for identity verification required by the AML/CTF Act, and handled to the same standard as everything else.
11. How We Collect It
We collect personal information:
- directly from you, when you create an account, verify your identity, transact, or contact support;
- automatically, through cookies, server logs, and the device and connection signals described in section 18; and
- from third parties, as listed in section 10.5.
Where it is reasonable and practicable, we collect personal information from you rather than from someone else.
12. How We Use It
12.1 Running the service
- creating and maintaining your account;
- processing buy, sell, and bank transfers;
- delivering Bitcoin to the wallet address you provide, or to your in-app wallet;
- sending login verification codes and transaction confirmations;
- managing your bank account and PayID details; and
- providing customer support.
12.2 Meeting our AML/CTF obligations
- identity verification and customer due diligence, including ongoing and enhanced due diligence where our procedures require it;
- transaction monitoring, and sanctions, politically exposed person, and adverse media screening, at onboarding and on an ongoing basis;
- collecting, verifying, and where required transmitting payer and recipient information for virtual asset transfers, an obligation that has applied since 1 July 2026;
- reporting suspicious matters and threshold transactions to AUSTRAC; and
- keeping records for the seven year period the law requires.
We do not publish our monitoring thresholds or rule detail. Publishing them would tell people how to structure transactions to avoid detection.
12.3 Preventing fraud and scams
We use the signals in section 18, together with transaction monitoring, to protect customers from fraud and from scams in which a customer is coerced or deceived into transacting. This includes checks during signup and verification, and warnings at points where scam losses commonly occur.
12.4 Meeting other legal obligations
- tax obligations, including reporting transaction data to the Australian Taxation Office where required;
- responding to lawful requests, subpoenas, warrants, and court orders; and
- complying with other regulatory requirements applicable to our products.
12.5 Service communications
Login codes, transaction confirmations, security alerts, service updates, and notice of changes to our terms or this policy. You cannot opt out of these while you hold an account, because they are part of operating the service safely.
12.6 Marketing
Where you opt in, we may send you marketing about paybtc and the b app. You can withdraw consent at any time using the unsubscribe link in any marketing email, or by contacting us. We do not sell or rent your personal information. We do use Google and Meta advertising and analytics tools on our websites to measure and target our own advertising, which is described in section 16.
13. Automated Decision-Making
We use automated checks in two places that can affect you directly.
| Where | What the system does | What happens next |
|---|---|---|
| Signup and identity verification | Compares technical characteristics of your device and connection for signs of remote takeover or scam coercion | Your account may be frozen automatically and held for manual review by a person before anything else happens |
| Transaction monitoring and screening | Screens you and your transactions against sanctions and watchlists, and applies monitoring rules | A transaction may be delayed or held, and an alert is raised for manual review by a person |
These systems flag and hold, they do not decide. An account is not closed and a transaction is not permanently refused on the say-so of an automated check alone. A person reviews the matter before any final decision.
If an automated check has affected you, you can ask us about it, and you can ask a person to look at it, by contacting us. There will be circumstances where we cannot tell you the reason, because the law prohibits us from disclosing that a suspicious matter report has been made.
14. Who We Disclose Information To
14.1 Regulators and law enforcement
- AUSTRAC, for mandatory reporting and supervisory enquiries;
- the Australian Taxation Office, for tax reporting obligations;
- the Department of Foreign Affairs and Trade, for sanctions compliance;
- the Australian Federal Police and state and territory police, in response to lawful requests, warrants, or court orders;
- the Office of the Australian Information Commissioner, in connection with data breach notification; and
- other Australian regulators where required by law.
14.2 Service providers
| Provider | What they do for us |
|---|---|
| Our identity verification and screening provider | Identity verification, liveness, transaction monitoring, sanctions and politically exposed person screening, adverse media, travel rule |
| Our Australian banking and settlement provider | Australian dollar collections and payouts |
| Cloud hosting and infrastructure providers | Secure hosting of our systems |
| Our Lightning service provider | Operating the Lightning infrastructure behind your Spending balance, which means it sees your Spending public key, your balance and the Lightning payments you make and receive |
| Apple Inc. | App Store distribution, push notifications, and crash reporting for the b app, and storage of the notes, labels and attachments you add to a transaction in your own iCloud |
| Google LLC | Website analytics and advertising measurement, on paybtc.com.au and getb.app |
| Meta Platforms, Inc. | Advertising measurement on paybtc.com.au |
| Email and SMS delivery providers | Delivering login codes, confirmations, and service messages |
| Independent reviewers and auditors | Independent review of our AML/CTF program and our systems |
We require our service providers to protect your information and to use it only for the purpose we engaged them for.
14.3 Professional advisers
Legal, accounting, audit, and tax advisers we engage, and our insurers in connection with professional indemnity and cyber cover.
14.4 On a sale or restructure
If our business or part of it is sold or restructured, we may disclose personal information to the buyer or their advisers, subject to confidentiality, and to their obligation to handle it under the Privacy Act.
15. Sending Information Overseas
Some of our service providers process personal information outside Australia. The main flows are:
| Recipient | Where | What |
|---|---|---|
| Our identity verification and screening provider | European Economic Area (Germany, Estonia), United Kingdom, United States, Singapore | Identity verification, screening, and monitoring data |
| Our banking and settlement provider | Australia, with related entities in the United States and elsewhere | Payment data |
| Our Lightning service provider | United States | Spending public key, balance, and Lightning payment data |
| Google LLC and Meta Platforms, Inc. | United States | Website analytics and advertising data about your visit, as described in section 16 |
| Apple Inc. | United States | App delivery, push notifications, crash reports, and the notes, labels and attachments you add to a transaction |
| The exchange or institution receiving a transfer | Wherever that business is located | Where you send or receive virtual assets through us, the payer and recipient information Australian law requires us to pass on, see section 12.2 |
If the GDPR or the UK GDPR applies to you, section 9.1 sets out the separate transfer position, including the fact that Australia does not have an adequacy decision from the European Commission.
Before we disclose your personal information to an overseas recipient, we take steps that are reasonable in the circumstances to ensure the recipient does not breach the APPs, as APP 8.1 requires. Those steps include binding the recipient by contract to handle the information consistently with the APPs, limiting them to the purpose we engaged them for, and requiring encryption in transit and at rest.
We remain accountable for these disclosures under APP 8.1.
Section 4 describes a different situation, where your device connects directly to Bitcoin network infrastructure, some of which is operated by others and located overseas.
16. Cookies on the Web Exchange
paybtc.com.au and getb.app use cookies and similar technologies in four categories:
- Essential. Necessary for the platform to work, including session management, security, and login verification. These cannot be disabled.
- Analytics. Aggregated data used to understand how the platform is used and to find technical problems.
- Functional. Remembering your preferences and settings.
Advertising. We use Google Analytics and Google Ads, supplied by Google LLC, and on paybtc.com.au the Meta pixel, supplied by Meta Platforms, Inc. These tell us how our advertising performs and let us show ads to people who have visited us. Both companies are in the United States and both receive the information described in section 17 about your visit. They are listed in sections 14.2 and 15.
You can control cookies through your browser settings, and you can opt out of Google Analytics with Google's browser add-on and of personalised advertising in your Google and Meta account settings. Blocking essential cookies will stop parts of the platform from working.
Where the law of your country requires us to ask before we set advertising or analytics cookies, we do not set them unless you have agreed.
Everything else, which applies to everyone
17. Technical and Device Information
- IP address, and the approximate location derived from it;
- browser type, version, and language settings, on the web;
- device type, operating system, and app version;
- pages visited, features used, and session duration, on the web;
- cookies and similar technologies on the web platform, see section 16; and
- error logs and diagnostic data.
18. Fraud and Security Signals
At signup and at identity verification we collect technical characteristics of the device and connection you are using, and we compare them for signs that an account is being opened or verified under someone else's direction. This exists to catch remote takeover and scam coercion, where a victim is talked through the process by an offender. Where these checks raise a concern, we may freeze the account and review it manually. See section 13.
We do not publish the detail of how these checks work, because doing so would tell the people we are trying to stop how to get around them.
19. Data Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our controls include:
- we do not store your identity documents. Your passport, licence or other document goes to our verification provider and is held by them, not by us. We receive the result of the check and the identity details in section 10.1, not the images;
- encryption of all data in transit, using TLS, between your device, our servers, and the services we rely on;
- multi-factor authentication for administrative access to our systems;
- logging of administrative access and account changes;
- access limited to the people whose work requires it;
- hosting in secure data centres with physical and environmental controls; and
- regular review of our security controls.
No system is perfectly secure. If something does go wrong, section 23 sets out what we do about it.
What we will never do: we will never ask you for your Recovery Phrase, your seed words, or your device passcode. Anyone who does, by any means, including someone claiming to be from paybtc, is attempting to defraud you. Stop and contact us.
20. How Long We Keep It
We keep personal information only as long as we need it for the purpose we collected it, subject to retention periods the law imposes on us.
The seven year periods below come from the AML/CTF Act and apply to verified Australian customers. They do not apply if you use the wallet and nothing else, because that is not a service the AML/CTF Act regulates. For a wallet-only user the only relevant line is the last one, technical logs and diagnostics. See section 7.
| Record | Retention period |
|---|---|
| Identity verification and customer due diligence records | 7 years after the end of the customer relationship |
| Transaction records | 7 years from the date of the transaction |
| Suspicious matter reports and supporting records | 7 years from the date of the report |
| Account information | Duration of the account, plus 7 years after closure |
| Support and communication records | 7 years, or longer where the law requires |
| Marketing consent records | Until you withdraw consent, plus a short period to action it |
| Technical logs and diagnostics | Up to 2 years, then deleted or de-identified |
Where a record is subject to more than one obligation, the longest applies. After that, we destroy it or permanently de-identify it.
21. Your Rights
21.1 Access (APP 12)
You can ask for the personal information we hold about you. We will respond within a reasonable period. We may charge a reasonable fee for the cost of locating and providing it, but not for making the request. In the limited circumstances the Privacy Act allows, we may refuse, and if we do we will tell you in writing and give the reason to the extent the law allows us to.
21.2 Correction (APP 13)
You can ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond within a reasonable period. If we refuse, we will tell you in writing and give the reason to the extent the law allows us to, and you can ask us to note your disagreement on the record.
21.3 Anonymity and pseudonymity (APP 2)
APP 2 says you should be able to deal with an organisation anonymously or under a pseudonym where that is lawful and practicable. It is not practicable here. The AML/CTF Act requires us to verify the identity of every customer, so we cannot provide the transactional services anonymously.
21.4 Withdrawing consent
Where we rely on your consent, for example marketing, you can withdraw it at any time. Withdrawal does not affect what we did beforehand, and it does not override our record keeping obligations.
21.5 What our legal obligations override
Our obligations under the AML/CTF Act may prevent us from deleting or correcting certain records, or from giving you access to them. Where that applies, we will tell you, and give the reason to the extent the law allows us to.
22. Direct Marketing and Spam
We send commercial electronic messages only in accordance with the Spam Act 2003 (Cth). Every marketing message includes a working unsubscribe facility, and we action unsubscribes promptly. Service messages necessary to operate your account, such as login codes and transaction confirmations, are not marketing.
23. Data Breaches
We comply with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If we suspect a data breach that could cause serious harm, we will:
- assess it promptly, and within 30 days at the outside;
- take reasonable steps to contain it and limit the harm;
- notify the Office of the Australian Information Commissioner where the scheme requires it;
- notify affected individuals as soon as practicable, telling you what happened, what information was involved, and what you should do about it; and
- keep records of the incident and our response.
24. Complaints
24.1 Come to us first
If you think we have mishandled your personal information or breached the APPs, contact our Privacy Officer. If you cannot reach our support form for any reason, including because your account is restricted, you can write to us at the postal address at the end of this policy, and we will treat your letter the same way. We will acknowledge your complaint and respond within a reasonable period. If we need longer we will tell you why and when to expect an answer.
24.2 If you are not satisfied
| Body | Handles | Contact |
|---|---|---|
| Office of the Australian Information Commissioner | Privacy complaints | oaic.gov.au 1300 363 992 |
| Australian Financial Complaints Authority | Financial complaints within its jurisdiction. We are a member. | afca.org.au 1800 931 678 |
| AUSTRAC | AML/CTF conduct | austrac.gov.au |
| Your own data protection authority, if you are in the European Economic Area | Privacy complaints under the GDPR | Listed at edpb.europa.eu |
| Information Commissioner's Office, if you are in the United Kingdom | Privacy complaints under the UK GDPR | ico.org.uk |
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.
25. Changes to This Policy
We may update this policy to reflect changes in our practices, the law, or how our products work. When we make a material change we will:
- publish the updated policy at paybtc.com.au/privacy and in the b app;
- update the date shown at the top of the policy;
- notify you where the law requires; and
- seek your consent where the law requires it before we handle your information in a materially different way.
26. Contact Us
Privacy Officer
PAYBTC Pty Ltd, trading as paybtc
ACN 694 153 832 · ABN 52 694 153 832
Support form: paybtc.com.au/help, marked for the attention of the Privacy Officer
Post: 1 Wyangarie St, Kyogle NSW 2474, Australia
Web: paybtc.com.au