PRIVACY POLICY
ScrapTrade.com.au – Mobile Application
Mobeius Technologies Pty Ltd | ABN: 49 693 656 932
Effective Date: 1 February 2026 | Last Updated: 23 June 2026
Note: This Privacy Policy has been updated to include mobile application-specific provisions required for iOS App Store and Google Play Store submission. All existing website provisions remain in full effect and are incorporated herein.
1. INTRODUCTION
1.1 Our Commitment to Privacy
ScrapTrade.com.au (Mobeius Technologies Pty Ltd having ABN: 49 693 656 932) ("we", "us", "our", or "ScrapTrade") is committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information.
1.2 Scope
This Privacy Policy applies to:
- All users of the ScrapTrade.com.au website and mobile applications ("Service");
- All personal information collected through the Service;
- Information collected offline in connection with the Service;
- Third-party service providers acting on our behalf.
1.3 Agreement
By using the Service, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree, please do not use the Service.
1.4 Updates to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be notified via email or prominent notice on the Service. Your continued use after changes constitutes acceptance.
2. DEFINITIONS
"Personal Information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in material form or not.
"Sensitive Information" means personal information about an individual's racial or ethnic origin, political opinions, membership of political associations, religious or philosophical beliefs, sexual orientation or practices, criminal record, health information, genetic information, or biometric information.
"APP Entity" means an organisation with an annual turnover of more than $3 million, or that trades in personal information, or that provides a health service or is a contracted service provider for a Commonwealth contract.
"Credit Information" includes information about credit applications, credit history, and credit worthiness.
"User" means any person or entity that accesses or uses the Service.
3. INFORMATION WE COLLECT
3.1 Personal Information Collected Directly
We collect the following personal information directly from you:
Account Registration Information:
- Full legal name (individual or business name)
- Australian Business Number (ABN) or Australian Company Number (ACN)
- Trading name (if different from legal name)
- Email address
- Telephone number(s) (mobile and landline)
- Physical business address
- Postal address (if different)
- Date of birth (for identity verification)
Licence and Verification Information:
- Scrap metal dealer licence number
- Second-hand dealer licence number
- Other relevant permits and registrations
- Proof of identity documents (driver's licence, passport)
- Business registration documents
- Professional certifications
Financial Information:
- Bank account details (BSB and account number)
- Credit card or payment card information (processed by third-party payment processors)
- Billing address
- Payment history
- Transaction records
- Tax File Number (TFN) or Australian Business Number (where required for tax reporting)
Transaction Information:
- Listing details (materials, quantities, grades, prices)
- Purchase and sale records
- Communication with other users
- Delivery and collection details
- Inspection reports
- Dispute records
Profile Information:
- Business description
- Services offered
- Operating locations
- Trading hours
- Profile photograph or business logo
- Preferences and settings
Communication Information:
- Messages sent through the Service
- Email correspondence
- Support tickets and inquiries
- Feedback and reviews
- Survey responses
3.2 Information Collected Automatically
When you use the Service, we automatically collect:
Device Information:
- IP address
- Device type and model
- Operating system and version
- Browser type and version
- Unique device identifiers
- Mobile network information
Usage Information:
- Pages visited and features used
- Time and date of visits
- Referring and exit pages
- Search queries
- Click-stream data
- Session duration
- Interaction with listings and content
Location Information:
- Geographic location (with your consent)
- Approximate location based on IP address
- GPS coordinates (for mobile app users who grant permission)
Cookies and Tracking Technologies:
- Cookies (session and persistent)
- Web beacons
- Pixel tags
- Local storage
- Analytics data
3.3 Information from Third Parties
We may collect personal information from:
Identity Verification Services:
- Government databases for licence verification
- Credit reporting agencies
- Identity verification providers
- Background check services
Business Information Services:
- ASIC business registers
- ABN Lookup
- Credit reference agencies
- Industry associations
Social Media and Public Sources:
- Information from your social media profiles (if you link accounts)
- Publicly available business information
- Online reviews and ratings
- Public records
Other Users:
- Reviews and ratings about you
- Reports of policy violations
- Dispute information
- References and testimonials
3.4 Information We Do Not Intentionally Collect
We do not intentionally collect Sensitive Information as defined by the Privacy Act 1988 (Cth) unless:
- You voluntarily provide it;
- It is reasonably necessary for our functions or activities;
- We have your explicit consent;
- It is required or authorised by law.
If you provide Sensitive Information, you consent to our collection and use of that information for the purposes disclosed in this Privacy Policy.
4. HOW WE USE YOUR PERSONAL INFORMATION
4.1 Primary Purposes
We collect and use your personal information for the following primary purposes:
Service Provision:
- Creating and managing your account
- Facilitating listings and transactions
- Processing payments and refunds
- Providing customer support
- Delivering requested services and features
- Personalising your experience
Verification and Security:
- Verifying your identity and credentials
- Confirming licence validity
- Preventing fraud and unauthorised access
- Detecting and preventing illegal activity
- Protecting against security threats
- Investigating policy violations
Communication:
- Responding to inquiries and requests
- Sending transactional notifications (account, listings, transactions)
- Providing customer support
- Sending administrative messages
- Resolving disputes
Legal Compliance:
- Complying with legal obligations under Australian law
- Responding to lawful requests from authorities
- Meeting regulatory requirements (AML/CTF, tax, licensing)
- Enforcing our Terms and Conditions
- Protecting our legal rights
4.2 Secondary Purposes
With your consent or as permitted by law, we may also use your personal information for:
Marketing and Promotions:
- Sending promotional emails and newsletters (with consent)
- Informing you about new features and services
- Providing targeted advertising
- Conducting marketing campaigns
- Sending industry news and updates
Analytics and Improvement:
- Analysing usage patterns and trends
- Improving Service functionality and performance
- Developing new features and services
- Conducting research and surveys
- Creating anonymised statistical data
Business Operations:
- Managing business relationships
- Training staff
- Quality assurance
- Risk management
- Business planning and strategy
4.3 Direct Marketing
We may use your personal information to send direct marketing communications about:
- Our services and features;
- Industry news and trends;
- Promotional offers and discounts;
- Events and webinars;
- Partner services (with consent).
Your Rights:
- You can opt-out of marketing communications at any time
- Use the unsubscribe link in emails
- Contact us directly to update preferences
- We will not charge you for opting out
- We may still send transactional and administrative messages
Our Obligations:
- We will only send marketing if we have consent or an existing relationship
- We will clearly identify ourselves
- We will provide an easy opt-out mechanism
- We will honour opt-out requests within a reasonable timeframe
5. DISCLOSURE OF PERSONAL INFORMATION
5.1 Disclosure to Other Users
To facilitate transactions, we disclose certain information to other users:
Sellers May See (about Buyers):
- Name and business name
- Contact information (as provided for the transaction)
- Profile information
- Transaction history and ratings
- Messages sent through the platform
Buyers May See (about Sellers):
- Name and business name
- Contact information (as provided in listings)
- Business location
- Profile information
- Listings and pricing
- Ratings and reviews
- Licence information (where publicly available)
Control:
You can control what information is visible in your profile settings, subject to minimum disclosure requirements for transaction completion.
5.2 Disclosure to Service Providers
We disclose personal information to third-party service providers who perform services on our behalf:
Payment Processors:
- Processing credit card and bank transactions
- Managing payment accounts
- Fraud detection and prevention
Cloud Hosting and Storage:
- Amazon Web Services (AWS) – Australia region
- Microsoft Azure – Australia region
- Data storage and backup services
Identity Verification:
- ID verification services
- Licence verification providers
- Credit checking agencies
- Background check services
Communication Services:
- Email service providers (e.g., SendGrid, Mailchimp)
- SMS providers
- Customer support platforms
Analytics and Marketing:
- Google Analytics
- Marketing automation platforms
- Advertising networks
- Survey tools
Professional Advisors:
- Legal counsel
- Accountants and auditors
- Business consultants
- Insurance providers
All service providers are contractually required to: use personal information only for specified purposes; protect personal information with appropriate security; not disclose to unauthorised parties; comply with Australian privacy laws; and delete or return information when no longer needed.
5.3 Disclosure for Legal Reasons
We may disclose personal information when required or authorised by law:
Legal Obligations:
- Court orders and subpoenas
- Search warrants
- Statutory demands for information
- Regulatory investigations
- Tax and revenue authorities
Law Enforcement:
- Police investigations
- Anti-money laundering reporting
- Counter-terrorism financing obligations
- Suspicious activity reporting
- Fraud investigations
Legal Proceedings:
- Defending legal claims
- Enforcing our rights
- Protecting the rights and safety of others
- Investigating policy violations
5.4 Business Transfers
If ScrapTrade is involved in a merger, acquisition, sale of assets, bankruptcy, or reorganisation, your personal information may be transferred as part of that transaction. We will:
- Notify you via email and prominent notice on the Service;
- Provide information about the acquiring entity;
- Explain any changes to privacy practices;
- Offer choices regarding continued use of your information.
5.5 With Your Consent
We may disclose your personal information to other parties with your explicit consent:
- Partner organisations for joint offerings;
- Industry associations for membership benefits;
- Research organisations for industry studies;
- Public listings or testimonials (with permission).
5.6 Aggregated and De-identified Data
We may share aggregated, anonymised, or de-identified data that cannot reasonably be used to identify you:
- Industry statistics and trends;
- Market research and analysis;
- Academic research;
- Business reporting;
- Service improvement.
Such data is not considered personal information under the Privacy Act.
5.7 Overseas Disclosure
Some of our service providers may be located overseas or store data in offshore facilities. Personal information may be disclosed to entities in:
Common Jurisdictions:
- United States (cloud hosting, analytics, payment processing)
- European Union (software services)
- Singapore (regional data centres)
- Other countries where service providers operate
When we disclose personal information overseas, we take reasonable steps to ensure overseas recipients comply with Australian privacy laws or equivalent protections. By using the Service, you consent to disclosure of your personal information to overseas recipients as described above.
6. DATA QUALITY AND SECURITY
6.1 Data Quality (APP 10)
We take reasonable steps to ensure that personal information we collect is accurate and up-to-date, complete and relevant, and not misleading. You are responsible for providing accurate information and updating it when circumstances change through your account settings or by contacting us.
6.2 Security Measures (APP 11)
We implement reasonable administrative, technical, and physical security measures to protect personal information from misuse, interference, and loss; unauthorised access, modification, or disclosure; and data breaches and cyber threats.
Technical Security:
- Encryption of data in transit (SSL/TLS)
- Encryption of data at rest
- Secure authentication mechanisms
- Regular security updates and patches
- Firewalls and intrusion detection systems
- Access controls and monitoring
Administrative Security:
- Staff training on privacy and security
- Background checks for employees
- Confidentiality agreements
- Access restrictions based on role
- Regular security audits
- Incident response procedures
Physical Security:
- Secure data centre facilities
- Restricted physical access
- Environmental controls
- Backup and disaster recovery systems
6.3 Data Retention
We retain personal information only as long as necessary for the purposes for which it was collected, legal and regulatory requirements, resolving disputes and enforcing agreements, and legitimate business purposes.
Retention Periods:
- Account information: Duration of account plus 7 years
- Transaction records: 7 years (tax and regulatory compliance)
- Financial records: 7 years
- Communication records: 3 years or until resolved
- Marketing data: Until consent is withdrawn plus 2 years
- Legal hold data: Until legal matters are resolved
6.4 Data Breach Response
In the event of an eligible data breach under the Notifiable Data Breaches (NDB) scheme, we will assess the breach within 30 days, determine if the breach is likely to result in serious harm, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) if required, and take remedial action to prevent future breaches.
6.5 Limitations
Despite our security measures: no internet transmission is completely secure; we cannot guarantee absolute security; you use the Service at your own risk; and you are responsible for maintaining the security of your account credentials.
7. ACCESS AND CORRECTION (APP 12 & 13)
7.1 Your Right to Access
You have the right to request access to the personal information we hold about you. We will provide access unless doing so would pose a serious threat to life, health, or safety; have an unreasonable impact on others' privacy; the request is frivolous or vexatious; the information relates to existing or anticipated legal proceedings; or providing access would be unlawful.
To request access, submit a written request to privacy@scraptrade.com.au including your full name and contact details, verification of your identity, specific information you wish to access, and preferred format. We will respond within 30 days.
7.2 Your Right to Correction
You have the right to request correction of personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading. You may update information directly through your account settings or contact us at privacy@scraptrade.com.au. We will respond within 30 days and will not charge for correction requests.
7.3 Associated Statements
If we refuse to correct information and you disagree, you may request that we associate a statement with the information claiming it is inaccurate, out-of-date, incomplete, irrelevant, or misleading.
8. ANONYMITY AND PSEUDONYMITY (APP 2)
8.1 Option to Remain Anonymous
Where practicable, we will give you the option to not identify yourself or to use a pseudonym. Anonymity is possible when browsing public listings (not logged in), making general inquiries, responding to some surveys, or providing public feedback.
We require identification when creating an account, listing materials for sale, making purchases, processing payments, verifying licences and credentials, complying with legal obligations (AML/CTF, tax reporting), protecting against fraud, and enforcing our Terms and Conditions.
8.2 Pseudonyms
You may use a business name or trading name instead of your legal name in some contexts, but we require your legal name for account registration and verification, your ABN/ACN for business entities, and proof of authority to use the business name.
9. COOKIES AND TRACKING TECHNOLOGIES
9.1 What Are Cookies
Cookies are small text files stored on your device when you visit websites. We use cookies and similar technologies to remember your preferences and settings, authenticate your login sessions, analyse Service usage and performance, deliver relevant advertising, and prevent fraud and improve security.
9.2 Types of Cookies We Use
Essential Cookies: Required for Service functionality, enable account login and authentication, remember your session, provide security features. Cannot be disabled without affecting Service functionality.
Functional Cookies: Remember your preferences (language, location), customise your experience, provide enhanced features. Can be disabled in settings.
Analytics Cookies: Track how you use the Service, measure performance and errors, understand user behaviour, improve Service quality. Can be disabled in settings.
Advertising Cookies: Deliver relevant advertisements, measure ad effectiveness, frequency capping, target based on interests. Can be disabled in settings.
9.3 Third-Party Cookies
We use third-party services that may set cookies, including Google Analytics (for usage analytics and reporting) and Facebook Pixel (for advertising and conversion tracking). Please refer to their respective privacy policies for further information.
9.4 Managing Cookies
You can control cookies through your browser settings or through our cookie settings accessible through the website footer. Disabling essential cookies may prevent you from using certain Service features.
9.5 Do Not Track
Some browsers offer "Do Not Track" (DNT) signals. Currently, we do not respond to DNT signals as there is no industry standard for handling them.
10. CHILDREN'S PRIVACY
10.1 Age Restrictions
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.
10.2 Parental Notice
If we become aware that we have collected personal information from a person under 18 without parental consent, we will delete the information as soon as practicable, terminate any associated account, and notify the parent or guardian if contact information is available.
10.3 Parental Rights
If you are a parent or guardian and believe your child has provided personal information to us, please contact us immediately at privacy@scraptrade.com.au.
11. YOUR PRIVACY RIGHTS
11.1 Summary of Rights
Under Australian privacy law, you have the right to:
- Access your personal information;
- Correct inaccurate or incomplete information;
- Request deletion of your information (subject to legal obligations);
- Restrict processing in certain circumstances;
- Object to processing for direct marketing;
- Opt-out of marketing communications;
- Complain to us or the OAIC about privacy concerns;
- Remain anonymous where practicable.
11.2 Exercising Your Rights
To exercise your rights, contact us by email at privacy@scraptrade.com.au. Include your full name and contact details, verification of your identity, a clear description of your request, and any supporting documentation. We will respond within 30 days of receiving a valid request.
11.3 Verification
To protect your privacy, we may require verification of your identity before processing requests. Acceptable verification includes government-issued photo ID, a recent utility bill or bank statement, or other documentation confirming your identity.
11.4 Fees
We will not charge fees for most requests. However, we may charge a reasonable fee for complex or voluminous access requests, manifestly unfounded or excessive requests, or repeated requests for the same information. We will notify you of any fees before processing your request.
12. COMPLAINTS AND DISPUTES
12.1 How to Complain
If you believe we have breached your privacy rights or Australian privacy laws, please contact us at cs@scraptrade.com.au. Include your contact details, description of the privacy concern, when and how the breach occurred, impact on you, what you would like us to do, and any relevant documentation.
12.2 Our Complaints Process
Step 1 – Acknowledgment (5 Business Days): We will acknowledge receipt of your complaint within 5 business days.
Step 2 – Investigation (30 Days): We will investigate your complaint thoroughly, which may include reviewing relevant records and systems, interviewing staff members, consulting with legal advisors, and assessing compliance with privacy laws.
Step 3 – Response (30 Days): We will provide a written response within 30 days, including our findings, whether we uphold the complaint, remedial action taken or proposed, and your right to escalate to the OAIC.
12.3 Office of the Australian Information Commissioner (OAIC)
If you are dissatisfied with our response, or if we fail to respond within 30 days, you may lodge a complaint with the OAIC. Website: www.oaic.gov.au | Phone: 1300 363 992 | Email: enquiries@oaic.gov.au
13. INTERNATIONAL DATA TRANSFERS
13.1 Data Storage Locations
Your personal information may be stored and processed in Australia (primary storage), the United States (cloud services, analytics), Singapore (regional backups), and the European Union (service providers).
13.2 Cross-Border Disclosure
When transferring personal information overseas, we take reasonable steps to ensure recipients comply with Australian privacy laws or equivalent standards, use contractual clauses requiring privacy protections, assess the privacy laws of destination countries, and implement appropriate safeguards.
13.3 Your Consent
By using the Service, you consent to international transfers as described in this Privacy Policy.
13.4 Accountability
We remain accountable for personal information disclosed to overseas recipients and take reasonable steps to ensure they handle information in accordance with the APPs.
14. CHANGES TO THIS PRIVACY POLICY
14.1 Right to Modify
We reserve the right to modify this Privacy Policy at any time to reflect changes in our practices, changes in applicable laws, technological developments, and business requirements.
14.2 Notification of Changes
We will notify you of material changes by posting the updated Privacy Policy on our website, updating the "Last Updated" date, sending email notification to registered users, and displaying prominent notices on the Service.
14.3 Your Options
If you disagree with changes to this Privacy Policy, you may close your account, withdraw consent for specific uses, or contact us to discuss concerns. Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
15. CONTACT INFORMATION
15.1 Privacy Officer
For all privacy-related inquiries, requests, or complaints:
Privacy Officer
ScrapTrade.com.au | ABN: 49 693 656 932
Email: cs@scraptrade.com.au
Office Hours: Monday to Friday: 9:00 AM – 5:00 PM AEST (Excluding NSW public holidays)
15.2 General Inquiries
For general questions about the Service: Email: cs@scraptrade.com.au
16. ADDITIONAL INFORMATION FOR SPECIFIC USERS
16.1 Business Account Holders
If you register a business account: you represent that you have authority to provide employee/contractor information; you are responsible for obtaining necessary consents from individuals whose information you provide; you must inform individuals about this Privacy Policy; and you must comply with APPs regarding employee information.
16.2 European Users
While this Privacy Policy primarily addresses Australian privacy law, if you are in the European Union, you may have additional rights under the General Data Protection Regulation (GDPR), including: right to data portability; right to be forgotten; right to restrict processing; right to object to automated decision-making. Please contact our Privacy Officer to exercise GDPR rights.
16.3 California Users
California residents may have additional rights under the California Consumer Privacy Act (CCPA). Please contact our Privacy Officer for information about CCPA rights.
17. SPECIFIC INFORMATION HANDLING PRACTICES
17.1 Credit Information
If we collect credit information (as defined by the Privacy Act), we will handle it in accordance with Part IIIA of the Privacy Act and the Credit Reporting Privacy Code. We may collect credit information for assessing creditworthiness for payment terms, identity verification, and fraud prevention.
17.2 Government Identifiers
We will not use government-related identifiers (such as driver's licence numbers, passport numbers, or tax file numbers) as our own identifiers for individuals. We may collect government identifiers for identity verification required by law, compliance with AML/CTF obligations, and tax reporting requirements.
17.3 Health Information
We do not generally collect health information. If you voluntarily provide health information (e.g., in relation to workplace safety), we will only use it for the purpose provided, protect it with enhanced security, not disclose it without your consent except as required by law, and delete it when no longer needed.
18. COMPLIANCE WITH AUSTRALIAN PRIVACY PRINCIPLES
This Privacy Policy is designed to comply with all 13 Australian Privacy Principles (APPs), including:
- Open and transparent management of personal information
- Anonymity and pseudonymity
- Collection of solicited personal information
- Dealing with unsolicited personal information
- Notification of collection
- Use or disclosure of personal information
- Direct marketing
- Cross-border disclosure of personal information
- Adoption, use or disclosure of government related identifiers
- Quality of personal information
- Security of personal information
- Access to personal information
- Correction of personal information
MOBILE APPLICATION SPECIFIC PROVISIONS
The following provisions apply specifically to users of the ScrapTrade mobile application available on iOS and Android platforms.
19. MOBILE APPLICATION SPECIFIC PROVISIONS
19.1 Mobile Permissions & Camera Access
The ScrapTrade mobile app requests camera and photo library access to allow users to capture and upload product photos for listings. Depending on your device, you can manage these choices through your system prompts or device settings. We do not store live camera feeds—only the final photos you choose to upload are stored.
Specific permissions the app may request include:
- Camera – to capture new product photos for listings
- Photo Library / Media Access – to select existing photos from your device
- Notifications – to receive alerts about bids, orders, and account activity
- Location (optional) – to display relevant local listings
You can manage all app permissions at any time through your device's system settings. Revoking certain permissions may limit specific app features but will not affect your ability to access the core platform.
19.2 Photo and Image Data
Photos uploaded via the mobile app are transmitted securely to our servers using HTTPS encryption. Photos are processed, stored securely on our cloud servers, and used in accordance with this Privacy Policy.
Users retain ownership of their photos and can delete listings at any time, which permanently removes the associated photos from our active databases.
We do not use your uploaded photos for any purpose other than displaying your listing, internal quality assurance, and where you have provided consent, for platform marketing and promotional purposes. Photos are not shared with third parties except as required for the operation of the Service (e.g., cloud storage providers).
19.3 Local Device Storage
The mobile app stores the following data locally on your device to ensure a seamless user experience:
- Authentication tokens (stored securely to keep you logged in)
- App preferences and status flags (such as onboarding status and temporary transaction flow identifiers)
This data remains strictly on your device and is cleared automatically when you log out or uninstall the app. We do not access or transmit locally stored data without your knowledge, except as necessary to provide the Service.
19.4 Push Notifications
The app may send push notifications about bids, orders, and account activity. You can disable notifications through your device settings at any time.
Push notification types may include:
- Bid and offer alerts
- Order status updates
- Account and security alerts
- Transactional confirmations
- Platform announcements (where enabled)
We use your device token solely to deliver push notifications to your device. This token is not shared with third parties for advertising purposes.
19.5 Stripe Payment Processing
All payments on our platform are processed securely through Stripe. Your payment card data is captured and handled entirely by Stripe in accordance with their strict security protocols and the Stripe Privacy Policy.
We do not store, view, or process full credit card numbers or sensitive authentication data on our servers; all transaction handling is fully compliant with the Payment Card Industry Data Security Standard (PCI-DSS).
For more information on how Stripe handles your payment data, please refer to the Stripe Privacy Policy at stripe.com/au/privacy.
ACKNOWLEDGMENT
By using the Service, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Last Updated: 23 June 2026 | Version: 2.0 (Mobile App Edition) | Effective Date: 1 February 2026
For privacy enquiries: cs@scraptrade.com.au | ScrapTrade.com.au | ABN: 49 693 656 932