Cookie Policy

Swipelocal ABN: 41 668 081 945, ("we", "us", or "our") is an Australian-based payment gateway provider offering services such as PayTo, PayID, Point-of-Sale (POS) solutions, and risk management systems. Our website, https://swipelocal.au/, uses cookies and similar tracking technologies to enhance your experience, ensure secure payment processing, analyse site performance, and provide personalized content. This Cookie Policy explains what cookies are, how we use them, the types of cookies we deploy, and how you can manage your cookie preferences.

This policy applies to all users of our website, including merchants (businesses using our services), end-users (customers making payments via merchants), and general visitors. It complements our Privacy Policy (available at https://swipelocal.au/privacy-policy.php) and aligns with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and best practices for transparency and user control.

By using our website, you consent to the use of cookies as described in this policy, except for essential cookies, which are necessary for the site to function. You can manage or withdraw your consent for non-essential cookies at any time, as outlined in Section 5.


1. What Are Cookies?

Cookies are small text files stored on your device (e.g., computer, smartphone, tablet) when you visit a website. They contain information about your browsing activity, such as preferences or session data, and are sent back to the website on subsequent visits to improve functionality, performance, or personalization. We also use similar technologies, such as web beacons, pixel tags, and local storage, which serve comparable purposes

Cookies may be
  • Session Cookies: Temporary, deleted when you close your browser.
  • Persistent Cookies: Remain on your device for a set period or until deleted.
  • First-Party Cookies: Set by Swipelocal (our domain).
  • Third-Party Cookies: Set by external services (e.g., Google Analytics).

2. Why We Use Cookies

We use cookies to deliver a secure, efficient, and user-friendly experience on https://swipelocal.au/. Our primary purposes include:

  • Essential Functionality:
    • Enabling core website features, such as navigation, payment processing, and access to secure areas (e.g., merchant dashboards).
    • Maintaining user sessions during payment transactions or account logins.
  • Security:
    • Detecting and preventing fraud or unauthorized access (e.g., validating user sessions).
    • Supporting risk management for payment processing (e.g., bot detection).
  • Performance and Analytics:
    • Analysing how users interact with our site (e.g., page views, bounce rates) to improve performance and usability.
    • Monitoring site errors or transaction failures to enhance reliability.
  • Personalisation:
    • Remembering user preferences (e.g., language, currency) for a tailored experience.
    • Providing relevant content based on browsing behaviour.
  • Marketing:
    • Delivering targeted advertisements or promotions (with your consent).
    • Measuring the effectiveness of marketing campaigns (e.g., ad clicks).

We ensure cookie usage complies with APP 7 (direct marketing) and APP 5 (notification of collection) under the Privacy Act 1988.


3. Types of Cookies We Use

We categorise cookies based on their purpose and functionality. Below is a detailed breakdown of the cookies used on https://swipelocal.au/:

Category Purpose Examples Duration First/Third Party
Essential Cookies Enable core website functions, such as payment processing, user authentication, and session management. Required for the site to operate and cannot be disabled.
  • Session ID cookies (e.g., for merchant dashboard logins).
  • Security tokens for payment forms.
  • Cookies for PayTo/PayID transaction validation.
Session or up to 24 hours First-Party
Security Cookies Protect against fraud, unauthorized access, and cyber threats. Support PCI DSS compliance and risk management systems.
  • Fraud detection cookies (e.g., for bot or anomaly detection).
  • CSRF (Cross-Site Request Forgery) protection tokens.
Session or up to 30 days First-Party, Third-Party (e.g., fraud detection providers)
Analytics Cookies Collect anonymized data on site usage to improve performance and user experience. Help us understand traffic patterns and optimize content.
  • Google Analytics (_ga, _gid) for page views, session duration, and traffic sources.
  • Hotjar (_hjid) for heatmaps and user interactions.
Up to 26 months (Google Analytics default) Third-Party (e.g., Google, Hotjar)
Marketing Cookies Support targeted advertising and measure campaign performance. Used only with your consent.
  • Google Ads cookies for ad personalization.
  • Pixel tags for tracking ad clicks or conversions.
Up to 90 days Third-Party (e.g., Google, Meta)
Preference Cookies Store user preferences to enhance browsing (e.g., language, currency, or region settings).
  • Language selection cookies.
  • Currency preference for multi-currency payment displays.
Up to 12 months First-Party

Third-Party Cookies

We use trusted third-party services that may set cookies, including:

  • Google Analytics: Anonymised tracking of site usage (IP anonymization enabled by default).
  • Hotjar: Heatmaps and user behaviour analysis (anonymised data).
  • Fraud Detection Providers: Real-time risk scoring for payment security (e.g. Sift).
  • Advertising Partners: Google Ads or social media platforms (e.g., Meta Pixel, with consent).

All third-party providers are contractually bound to comply with privacy laws equivalent to the APPs and PCI DSS standards.


4. How We Manage Cookies

We prioritize transparency and user control over cookies, in line with best practices and Australian privacy laws.

4.1 Cookie Consent
  • Essential Cookies : These are necessary for the website to function (e.g., payment processing, login security) and do not require consent. They are active by default.
  • Non-Essential Cookies (Analytics, Marketing, Preference):
    • We request your consent via a pop-up banner when you first visit https://swipelocal.au/, as recommended by ePrivacy principles and APP 7.
    • You can accept, reject, or customize your preferences for non-essential cookies.
    • Consent is stored for 12 months, after which we may prompt you again.
4.2 Data Collection Notice

At the point of cookie deployment, we provide clear notice (via the consent banner) about:

  • The types of cookies used.
  • Their purposes (e.g., analytics, marketing).
  • How to manage or withdraw consent. This aligns with APP 5 requirements for open and transparent management.
4.3 Data Retention
  • Session Cookies: Deleted when you close your browser.
  • Persistent Cookies: Retained for specific periods (e.g., 26 months for Google Analytics, 90 days for marketing cookies).
  • Anonymised Data: Analytics data is anonymised after collection and retained for up to 26 months. When no longer needed, cookies are deleted or anonymised to prevent identification.

5. Managing Your Cookie Preferences

You have full control over non-essential cookies and can manage them at any time:

  • Via Our Website
    • Access the cookie consent manager by clicking the “Manage Cookies” link in the website footer or pop-up banner.
    • Choose which categories (e.g., Analytics, Marketing) to enable or disable.
  • Via Your Browser
    • Adjust settings to block or delete cookies (e.g., in Chrome, Firefox, Safari).
    • Enable “Do Not Track” (DNT) signals, which we respect for non-essential cookies.
    • Clear existing cookies from your device’s storage.
  • Via Third-Party Tools
    • Google Analytics Opt-out Add-on: https://tools.google.com/dlpage/gaoptout
    • Hotjar opt-out: https://www.hotjar.com/legal/compliance/opt-out
    • Google ad settings: https://adssettings.google.com

Note: Disabling essential cookies is not possible, as they are required for core functionality (e.g., payment processing, secure logins). Disabling other cookies may limit site features, such as personalised content or analytics-driven improvements.


6. Cookies and Personal Information

Some cookies collect personal information (e.g., IP addresses, device IDs) as defined under the Privacy Act 1988. We handle this information in accordance with our Privacy Policy (https://swipelocal.au/privacy-policy), including:

  • Security: Cookies containing personal information are encrypted (e.g., AES-256 for storage, TLS 1.3 for transmission).
  • Disclosure: Limited to trusted third parties (e.g., Google Analytics, fraud detection providers) under strict confidentiality agreements.
  • Retention: Personal information from cookies is retained only as long as necessary (e.g., 12 months for preferences, 26 months for anonymized analytics).
  • Your Rights: You can access, correct, or request deletion of personal information collected via cookies (see Section 8).

We do not sell or share cookie data for commercial purposes beyond the uses described


7. Security of Cookie Data

We protect cookie data as part of our broader security framework, aligned with PCI DSS and APP 11:

  • Encryption: Cookie data is encrypted during transmission (TLS 1.3) and storage (AES-256).
  • Access Controls: Only authorized systems and personnel access cookie-related data.
  • Audits: Regular security audits (e.g., SOC 2 Type II, ISO 27001) ensure compliance.
  • Fraud Prevention: Security cookies help detect and block malicious activity (e.g., bots, session hijacking).

In the event of a data breach involving cookie data, we follow the Notifiable Data Breaches scheme (Privacy Act 1988), notifying affected users and the OAIC as required


8. Your Rights

Under the Australian Privacy Principles (APPs), you have rights regarding personal information collected via cookies:

Right Description How to Exercis
Access (APP 12) Request details of personal information collected via cookies (e.g., IP addresses, device IDs). Email [email protected]. We respond within 30 days. Reasonable fees may apply for complex requests.
AUD PayID AUPI
Correction (APP 13) Request correction of inaccurate cookie data (e.g., incorrect preferences). Update via the cookie consent manager or email us.
Opt-Out (APP 7) Withdraw consent for non-essential cookies (e.g., marketing, analytics). Use the cookie consent manager, browser settings, or third-party opt-out tools.
Complaints Report concerns about cookie usage or data handling. Email [email protected]. We investigate within 30 days. Escalate to the OAIC (oaic.gov.au, 1300 363 992) if unresolved.

9. Children's Privacy

Our website and services are not directed at individuals under 16. We do not knowingly collect personal information via cookies from children without parental consent. If we discover such data, we will delete it promptly. Contact us at [email protected] if you believe we have inadvertently collected a child’s information.


10. Changes to This Policy

We may update this Cookie Policy to reflect changes in our practices, technology, or legal requirements. Updates are posted at https://swipelocal.au/cookie-policy and effective immediately. For significant changes (e.g., new cookie types), we will notify users via:

  • A website banner or pop-up.
  • Email or dashboard alerts for merchants.
  • Notices to end-users via merchants.

Continued use of our website after updates constitutes acceptance. Check this page regularly for the latest version


11. Contact Us

For questions, requests, or complaints about our use of cookies, contact our Privacy Officer:

Swipelocal

Suite 1238, Level 1, 241 Adelaide St, Brisbane QLD 4000 Australia

Email: [email protected]

Website: https://swipelocal.au

We aim to respond within 30 days. If unsatisfied, you may contact:

Office of the Australian Information Commissioner (OAIC)

Website: oaic.gov.au

Phone: 1300 363 992

Email: [email protected]

This Cookie Policy ensures transparency and user control, aligning with industry best practices and Australian privacy laws. We are committed to protecting your data while delivering a seamless experience on https://swipelocal.au/.