SMARTTRIPS PTY LTD  ·  A.C.N. 608 269 521

Privacy
Policy

Issued
Melbourne
AU
GOVERNING LAW
Privacy Act 1988 (Cth)
JURISDICTION
Australia
CONTACT
info@smarttrips.com.au
SECTIONS
16

SmartTrips stores your travel documents and itineraries. This policy explains, in plain terms, what we collect, why we collect it, and the choices and rights you have over it.

1. Open and transparent management of personal information

This policy sets out how Smart Trips Pty Ltd (A.C.N. 608 269 521) — "SmartTrips", "we", "us", "our" — collects, discloses, uses, stores and otherwise handles personal information in connection with the SmartTrips application and its services. SmartTrips is a software application that stores personal travel documents and itineraries for your convenience.

We handle your information in accordance with the Privacy Act 1988 (Cth). We collect the personal information reasonably necessary to provide the service — including details needed to establish your identity and that of your family or colleagues — and we may correlate it against public and private sources covering travel preferences, and commercial or government databases relating to visas and other travel requirements. Information you give us may be checked against records held by government and other agencies bound by the Australian Privacy Principles.

2. Anonymity and pseudonymity

If you wish to use a name other than your own with us, it must still match your credit card, Australian Business Number or equivalent tax registration details, and any other identifying details required by law. Verifying individual identity is essential to traveller and public safety — as travel agents, we may be obliged to verify every user's identity and sensitive personal information, and that process is governed by this policy.

This can include the use of English names in place of other names, nicknames, patronymics, or other family or personal names. Where a name has changed — by marriage, deed poll, or, for a corporation, a formal name change — we may ask for evidence of the former name, the circumstances of the change, and official recognition of it.

3. Collection of personal information

Personal information generally means an individual's or entity's name and contact details — address, phone, postal address, email — of the kind shown on a driver's licence, passport or other identification. We do not independently verify information required by travel or government bodies for identity checks; we collect and check personal information only by lawful and fair means, and only as needed for the transaction at hand.

We collect personal information to:

  • verify the identity of our users and customers, and guard against fraudulent, misleading or deceptive conduct;
  • complete legal documentation required for travel or visa applications;
  • facilitate services from approved third parties as requested by the individual or entity;
  • record visits to our websites, including pages viewed, links followed, and technical data such as IP address, browser type and language, access times, and referring addresses; and
  • understand visitor age, gender and general interests via Google Analytics Demographics and Interest Reporting, for internal marketing only — never shared with third parties. You can opt out using the Google Analytics opt-out browser add-on.

We also use browser cookies — small pieces of data sent to your device — to, for example, remember your login across visits. You can configure your browser to alert you to cookies or turn them off entirely. If we collect other types of information in future, we'll tell you why at the time.

We keep personal information only for as long as it's needed to provide the SmartTrips service and to meet our legal obligations, including under state and federal legislation, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, and the Financial Transaction Reports Act 1988. Once it's no longer required, we delete it or de-identify it.

We generally collect personal information directly from you — for example, when you complete an online registration form or send identity-verification materials, including certified copies of identification, to finalise your registration. We'll only collect information from you, your legal representative, or someone you've authorised to operate your account, and we reserve the right to check what you provide against databases held by agencies authorised under Australian law.

4. Unsolicited personal information

If we receive personal information we didn't ask for, we'll assess within a reasonable time whether we could have collected it under the purposes described in Section 3, and we may use or disclose it for the purpose of making that assessment.

If we determine we couldn't have collected it, and it isn't part of a Commonwealth record, we'll destroy it or de-identify it as soon as practicable, provided it's lawful and reasonable to do so.

Where that doesn't apply, we'll still protect the information in line with this policy.

5. Notification of the collection of personal information

The entity collecting your personal information is Smart Trips Pty Ltd (A.C.N. 608 269 521), registered in Australia with its office in Melbourne. Direct enquiries to info@smarttrips.com.au.

We may obtain personal information from third parties, including government agencies and private information service providers, and where possible we require them to observe the Australian Privacy Principles. Information collected may be required by Australian state and territory law to protect the security and validity of transactions and cross-border movement.

Our main purpose in collecting personal information is to organise your travel documentation — including for visa and entry requirements — and to give accurate information to relevant third-party service providers for the purpose of your travel. We may decline to provide the service to anyone unwilling or unable to provide accurate personal information, and may disclose information to entities that apply the Australian Privacy Principles for the purposes described above.

Section 12 below sets out how to access the information we hold about you and request corrections.

6. Use and disclosure of personal information

We use and disclose your personal information for the purpose it was originally collected, and may use it for closely related purposes that would be within your reasonable expectations — such as consumer research, cross-promotions, or adding you to a relevant contact or guest list.

We only disclose sensitive personal information for a secondary purpose directly related to why it was collected, and never without your express consent, unless the disclosure is:

  • required or authorised by law;
  • needed to investigate suspected unlawful activity;
  • required by an enforcement body for its investigative work; or
  • reasonably believed necessary to lessen or prevent a serious threat to someone's life, health or safety, or to public health or safety, or otherwise permitted under the Privacy Act.

Where we rely on that last basis, we make a written record of the use or disclosure. Disclosures may also occur if the business is sold or changes control, and information may be shared with people or companies we employ or appoint as agents, who are contractually bound to protect it consistently with this policy and to use it only to perform services for us.

If you follow a link from the SmartTrips service to a third party, that third party's own privacy policy governs your relationship with them — we're not responsible for information you provide there. As a general rule, whoever you're paying for a service is whose privacy policy applies.

7. Direct marketing

From time to time we may use your personal information to let you know about offerings or events — ours or a business partner's — that may interest you. We work with third-party suppliers for tasks like payment processing, marketing and research; where we share personal information with them, we take reasonable steps to ensure they handle it in line with the Privacy Act, this policy, and confidentiality principles.

Emails such as newsletters may include web beacons, customised links or similar technology so we can see whether the email was opened and which links were clicked. We may combine this with other information we hold about you, including from other companies, to improve our services and make your experience more relevant.

If you'd rather not receive direct marketing, let us know and we'll act on it immediately.

8. Cross-border disclosure of personal information

We won't disclose your personal information to overseas recipients without your express consent, unless you are yourself the overseas recipient. Where it is disclosed overseas, that will only be to recipients who have agreed to our terms and conditions, including this policy, or where the law of that country requires it.

9. Adoption, use or disclosure of government-related identifiers

We won't adopt a government-related identifier (such as a passport or Medicare number) as our own identifier for you, unless required or authorised by Australian law, a court order, or otherwise permitted under the Australian Privacy Principles.

10. Personal information quality

We aim to keep all personal information we hold accurate, complete and up to date. Please tell us if your details change, or if you believe information we hold is inaccurate, incomplete or outdated, so we can correct it.

11. Personal information security

We take reasonable precautions to protect your personal information from unauthorised access, loss, misuse or alteration. It may be stored in hard-copy documents or electronically within our systems. We maintain computer and network security with passwords restricting access to authorised staff for approved purposes, and particularly sensitive information is overwritten and manually deleted.

  • Our staff are trained to safeguard your private information and undergo a background check before hiring.
  • Customer data isn't necessarily encrypted, but only authorised employees may view it, and access is granted on a need-to-know basis.
  • All employees sign written agreements requiring them to keep our and our customers' data confidential.
  • Our facilities are secured by various protective devices and systems.

12. Access to personal information

You can request access to the personal information we hold about you. Send your request in writing or by email to info@smarttrips.com.au with as much detail as possible. We'll acknowledge your request within 14 days, and usually grant access within 14 days — or 30 days for more complex requests, and we'll let you know if that timeframe isn't achievable. You'll be asked to verify your identity, and depending on the circumstances, information may be sent by mail or email, or you may need to inspect records in person. A fee may apply where a request is onerous or time-consuming, covering staff and reproduction costs. You'll also have the chance to correct any information that's no longer accurate.

We may not always be able to grant access. This can include where:

  • access would create a serious threat to safety;
  • granting it would unreasonably impact another individual's privacy;
  • denying access is required or authorised by law;
  • the request is frivolous;
  • legal proceedings are already under way;
  • ongoing negotiations could be prejudiced by access; or
  • access would reveal a commercially sensitive decision-making process.

If we refuse access, we'll explain why in writing, which may include an explanation of the commercially sensitive decision-making process involved.

13. Your responsibilities to protect your information

You agree to provide information about yourself that's accurate, current and complete — information that isn't accurate may fall outside the protection of this policy. You're responsible for protecting your user ID, password and any other confidential access codes, particularly when using our websites; we aren't responsible for what happens if you don't. If you believe your credentials have been disclosed to someone else, tell us straight away at info@smarttrips.com.au.

Keep what you submit to us confidential so no one else can access your account, and remember to sign out. Notify us of any theft of your personal data within two days of becoming aware of it. We have no liability for problems arising from your own actions in this regard.

14. Correction

If we're satisfied that information we hold is inaccurate, out of date, incomplete, irrelevant or misleading — or you ask us to correct it — we'll take reasonable steps to update it, having regard to the purpose for which it's held. If we've previously disclosed that information to another entity bound by the Australian Privacy Principles, we'll also take reasonable steps to notify them, unless doing so is impractical or unlawful.

If we refuse to correct information, we'll give you written notice setting out our reasons (except where it would be unreasonable to do so), how to complain about the refusal, and anything else required by the Privacy Regulations. If you then ask us to note that the information is disputed, we'll take reasonable steps to attach that statement so it's apparent to anyone using the information.

15. Complaints

If you believe your privacy has been infringed, you're entitled to complain. Send complaints in writing to info@smarttrips.com.au. We'll respond within 14 working days to let you know who's handling your query, and aim to resolve it within 30 working days — if that's not possible, we'll contact you with a revised estimate.

If you're not satisfied with how we've handled your complaint, you can escalate it to the Australian Information Commissioner:

Office of the Australian Information Commissioner
Level 3, 175 Pitt Street, Sydney NSW 2000
Postal — GPO Box 5218 Sydney NSW 2001, or GPO Box 2999 Canberra ACT 2601
Phone — 1300 363 992
Email — enquiries@oaic.gov.au
Web — oaic.gov.au

16. Changes to this policy

We may change this policy at any time, subject to applicable law. If we make a material change — including to how we disclose your information, or because of a sale or transfer of our business — we'll notify you at least 30 days before it takes effect, either by posting a notice on our website or emailing the last address you gave us. You may have further rights under state or federal law when our privacy policy changes.