Okuru’s Privacy Policy

Privacy at OkuruThis notice explains what personal information Okuru collects, why we use it, who we may share it with, how we protect it and how you can exercise your privacy rights.

1. About this Privacy Notice

Okuru Pty Ltd (Okuru, we, us or our) operates the Okuru mobile application, website, consumer marketplace, Partner services and related digital services (Services). We are based in Western Australia.

This Privacy Notice explains how we collect, hold, use and disclose personal information. We aim to handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) where they apply to us, and other applicable privacy laws. Additional rights may apply to individuals in other jurisdictions, including the EuropeanEconomic Area or United Kingdom.

2. The personal information we collect

Depending on how you use the Services, we may collect:

Identity information, such as name, display name, username and profile image.

Contact information, such as email address, mobile number and address where required.

Account and authentication information, including login identifiers and security records.

Transaction information, including Gift Card purchases, transfers, redemptions, balances, refunds, payment status and transaction identifiers.

Partner and business information, including business name, registration details, contact people, banking information and Partner activity.

Device and technical information, such as IP address, device identifiers, operating system, browser or app version, security logs and diagnostic information.

Usage information, including interactions with the Services, searches, features used and app activity.

Approximate or precise location information where you enable location features or where location is reasonably inferred for fraud prevention or service delivery.

Marketing and communications preferences, feedback, survey responses and communications with our support team.

Fraud, risk and compliance information reasonably required to protect users, investigate suspicious activity or comply with law.

We do not intentionally collect more personal information than is reasonably necessary for our functions and activities.

3. How we collect personal information

Directly from you when you create an account, make a purchase, send or receive a Gift Card, contact us, complete a form or participate in a promotion or survey.

Automatically when you use the Services, including through app telemetry, server logs, cookies or similar technologies where applicable.

From Partners when necessary to administer Partner Gift Cards, redemptions and customer support.

From payment providers, fraud-prevention providers, identity or verification providers, analytics providers and other service providers.

From publicly available sources or other sources where collection is lawful and reasonably necessary.

4. Why we use personal information

We may use personal information to:

Create, maintain and secure user and Partner accounts;

Process Gift Card purchases, payments, delivery, transfers, balances and redemptions;

Provide customer and Partner support and investigate transaction issues;

Prevent, detect and respond to fraud, cyber threats, misuse, chargebacks and suspicious activity;

Operate, maintain, troubleshoot, analyse and improve the Services;

Personalise relevant parts of the user experience;

Communicate important service, security, legal and transaction notices;

Send marketing where permitted by law and according to your communication preferences;

Comply with legal, regulatory, tax, accounting, reporting and law-enforcement obligations; and establish, exercise or defend legal claims and enforce our agreements.

5. Partner Gift Card transactions

When you purchase, receive or redeem a Partner Gift Card, we may share relevant information with the Partner that issued the Gift Card where reasonably necessary to administer the transaction, validate or redeem the Gift Card, provide customer service, prevent fraud or resolve a dispute.

If a Partner closes, sells or transfers its business, enters administration or liquidation, or otherwise becomes unable to honour outstanding Partner Gift Cards, we may disclose relevant transaction and contact information to the Partner, its administrator, liquidator, receiver, successor, purchaser or professional advisers where reasonably necessary andlawful to administer outstanding Gift Cards, resolve customer claims or comply with legal obligations.

6. Who we disclose personal information to

We may disclose personal information to:

Partners, to the extent reasonably necessary to administer Partner Gift Cards and related transactions;

Payment processors, banks and financial service providers involved in a transaction;

Cloud hosting, infrastructure, communications, customer support, analytics, security, fraud-prevention and technology providers;

Professional advisers, insurers, auditors and consultants where reasonably necessary;

Regulators, courts, law-enforcement agencies and government bodies where required or authorised by law;

A buyer, successor or adviser in connection with a proposed or completed sale, merger, restructuring or transfer of all or part of Okuru's business or assets; and other recipients where you have consented or where disclosure is otherwise permitted or required by law.

We do not sell personal information to advertisers.

7. Overseas disclosures

Some of our service providers, technology systems, Partners or professional service providers may be located outside Australia or may access personal information from overseas. Where the Australian Privacy Principles apply, we take reasonable steps required by APP 8 before disclosing personal information to an overseas recipient, subject to applicable exceptions.

Where practicable, we will identify in this Privacy Notice or an associated service-provider list the countries or regions in which overseas recipients are likely to be located. Because our providers and operating regions may change, we may update that information from time to time.

8. Direct marketing

We may send marketing communications where permitted by law. You can unsubscribe using the link in a marketing message or by contacting us. We may still send non-marketing messages that are necessary for your account,transactions, security or legal notices.

9. Cookies, SDKs and similar technologies

Our websites and apps may use cookies, software development kits, device identifiers, analytics tools and similar technologies to enable core functionality, remember preferences, measure performance, improve the Servicesand support security and fraud prevention. Where consent is required by applicable law, we will request it.

10. Data quality and security

We take reasonable technical and organisational steps designed toprotect personal information from misuse, interference, loss, unauthorisedaccess, modification and disclosure. These measures may include accesscontrols, encryption, monitoring, secure development practices, backups andsecurity procedures.

No method of electronic transmission or storage is completelysecure. If we become aware of an eligible data breach, we will respond andnotify affected individuals and regulators where required by law.

11. Retention

We retain personal information only for as long as reasonablynecessary for the purposes described in this notice or as required by law.Transaction, fraud, tax, accounting and legal records may need to be kept forlonger periods. When information is no longer required, we take reasonablesteps to delete, destroy or de-identify it, subject to lawful retentionrequirements.

12. Access, correction and account requests

You may request access to personal information we hold about youor ask us to correct information that is inaccurate, out of date, incomplete,irrelevant or misleading. We may need to verify your identity beforeresponding. We may refuse or limit a request where permitted by law and willexplain the reason where required.

You may also request account closure or deletion of information,but we may retain information where necessary to comply with law, preventfraud, resolve disputes, enforce agreements or preserve transaction records.

13. Privacy complaints

If you have a privacy concern or complaint, contact us using thedetails below. We will review the matter and aim to respond within a reasonabletime. If you are not satisfied, you may have the right to complain to theOffice of the Australian Information Commissioner or another privacy regulatorwith jurisdiction over your complaint.

14. Children

The Services are not intended for children under 16 and we do notknowingly seek to collect personal information from children under 16 withoutappropriate authority. If you believe a child has provided personal informationto us inappropriately, please contact us.

15. Additional rights for EEA and UK individuals

Where the EU or UK GDPR applies to our processing, you may haverights including access, correction, erasure, restriction, objection, dataportability and withdrawal of consent, subject to applicable conditions andexemptions. We will rely on an appropriate lawful basis for processing and anappropriate transfer mechanism where required for international transfers.

16. Changes to this Privacy Notice

We may update this Privacy Notice from time to time. If a changematerially affects how we handle personal information, we will take reasonablesteps to notify affected users. The current version will display its lastupdated date.

17. Contact us

Privacy enquiries and requests:Okuru Pty Ltd24 Augusta Street, Willetton WA 6155, AustraliaEmail: customer.care@okuru.app

Last updated: 7 September 2026