Last updated: 16 August 2026
Privacy Policy
Metapass Pty Ltd (ABN 19 671 041 937) trading as "Metapass" ("we", "us", or "our") is committed to protecting the privacy of your personal information. This Privacy Policy explains how we collect, hold, use, and disclose your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. About This Policy
This policy applies to all personal information collected by Metapass through our website at metapass.io, the Metapass Platform, Metapass Commerce, and through email correspondence, support channels, and other direct interactions with us.
Metapass provides payment orchestration, gateway connectivity, and managed online commerce services to business clients. Where we handle personal information on behalf of a client, that client is responsible for its own privacy obligations to the individuals concerned, and this policy explains our handling of that information as their service provider.
2. What Personal Information We Collect
The types of personal information we may collect include:
- Identity and contact details - your name, email address, phone number, business address, position, and organisation name
- Account information - usernames, authentication credentials, permissions, and access logs for the Metapass Dashboard and Metapass Platform
- Transaction and payment data - transaction metadata, order data, payment method type, settlement records, and related information processed through the Metapass Platform
- Client Data - product data, customer data, order data, and store content uploaded to or processed through Metapass Commerce or the Metapass Platform by our clients and their authorised users
- Correspondence - the content of emails, support requests, or inquiries you send to us
- Technical data - your IP address, browser type, operating system, device information, and referring URLs
Metapass is not an acquirer, card scheme, bank, stored value facility, issuer, credit provider, or holder of client funds. Cardholder data entered at checkout is captured and vaulted through approved payment flows operated by Metapass and its payment providers, and is not collected outside those flows.
We do not collect sensitive information (such as health, racial, or political information) unless you voluntarily provide it to us.
3. How We Collect Your Information
We collect personal information in the following ways:
- Directly from you - when you contact us, request a demonstration, enter into an agreement with us, create an account, or use the Metapass Platform or Metapass Commerce
- From our website and services - automatically through server logs and cookies when you visit our website or access the Metapass Platform
- From our clients - where a client uploads or transmits Client Data to us in order for us to provide the services
- From third parties - payment providers, gateways, acquirers, and other integrated systems connected to the Metapass Platform, where necessary to provide our services or meet our legal obligations
4. Why We Collect Your Information
We collect and use your personal information for the following purposes:
- To provide, operate, and maintain the Metapass Platform and Metapass Commerce
- To route, process, and reconcile transactions through connected payment providers and gateways
- To create and administer accounts and manage authorised user access
- To respond to your inquiries and provide support services
- To improve and optimise our website, platform, and user experience
- To detect, prevent, and investigate fraud, security incidents, and misuse
- To comply with our legal obligations and applicable card scheme, acquirer, and payment provider requirements
- To protect our rights, property, and the safety of our users
We will not use your personal information for purposes other than those described above without your consent, unless required or authorised by law.
5. Cookies
Cookies are small text files stored on your device by a website you visit.
Cookies on this website
Our website at metapass.io uses only the cookies necessary for the site to function and to keep it secure. We do not currently operate analytics, advertising, tracking, or profiling cookies on this website, and we do not build behavioural profiles of visitors.
If we introduce analytics or other non-essential cookies in future, we will update this section before doing so and describe what is collected and how to opt out.
Cookies on the Metapass Platform
The Metapass Dashboard and checkout use cookies and similar technologies that are strictly necessary to authenticate users, maintain sessions, remember preferences, and protect against fraudulent and automated activity. These cannot be disabled without preventing the service from working.
Managing Cookies
Most web browsers allow you to manage cookie preferences through their settings. You can choose to block or delete cookies, though this may affect the functionality of our website and the Metapass Platform. For more information, refer to your browser's help documentation.
6. Disclosure of Your Information
We may disclose your personal information to:
- Payment providers, gateways, and financial institutions - the acquirers, gateways, card schemes, banks, and payment method providers connected to the Metapass Platform, as required to process transactions. Where a client directs us to integrate with a third-party system, the client authorises us to disclose Client Data to that system for the purpose of providing the services
- Subprocessors and service providers - hosting, email, SMS, analytics, and support providers who assist us in delivering the services, bound by confidentiality obligations
- Group companies - Metapass Group Pty Ltd and related entities within the Metapass group, where necessary to provide and improve our services
- Professional advisers - our lawyers, accountants, and auditors where necessary
- Regulatory authorities - government bodies, law enforcement, or regulators where required or authorised by law
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Subprocessors
We use subprocessors, including hosting providers, payment providers, email providers, SMS providers, analytics providers, and support tools, to provide the services. We take reasonable steps to ensure that our subprocessors handle Client Data and personal information consistently with our client agreements and applicable law.
Clients must ensure they have all notices, consents, authorities, and legal bases required to provide Client Data and personal information to us, and to allow us and our subprocessors to process that information for the purpose of providing the services.
7. Storage and Security
We maintain appropriate technical and organisational measures to protect personal information and Client Data from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include:
- Secure hosting with encrypted data transmission (HTTPS/TLS)
- Storage of Client Data with trusted third-party data storage providers
- Access controls limiting who can view personal information
- Vaulting of payment credentials through approved payment flows
- Regular review of our data handling practices
No hosted system can guarantee that loss, corruption, unauthorised access, or interruption will never occur, and we do not warrant that unauthorised third parties will never be able to defeat those measures. There are risks inherent in internet connectivity that could result in the loss of privacy or confidential information, and data transmitted to us across the internet is transmitted at your own risk.
Data Breaches
Where we become aware of a data breach affecting Client Data, we will notify the affected client within 48 hours of becoming aware of the breach.
In the event of a data breach that is likely to result in serious harm to an individual, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth).
Retention and Deletion
We retain personal information only for as long as necessary to fulfil the purposes described in this policy, or as required by law. Following the expiry or termination of a client agreement, we may remove or delete Client Data within a reasonable period, and it is the client's responsibility to request, copy, or download any Client Data it requires before that time. We may retain copies of Client Data to the extent required for legal, compliance, audit, backup, dispute, or security purposes, subject to our confidentiality and privacy obligations.
8. Overseas Disclosure
Some of our service providers and subprocessors (such as hosting, payment, and support providers) may store or process data outside of Australia, including in the United States and the European Union. Before disclosing personal information overseas, we take reasonable steps to ensure that the recipient handles your information in accordance with the APPs.
9. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information that we hold about you
- Request correction of any inaccurate, incomplete, or out-of-date information
- Opt out of direct marketing communications at any time
- Complain if you believe we have breached the APPs
Where the information you are asking about was provided to us by one of our clients, we may need to refer your request to that client, who is the organisation responsible for it. We will tell you if we do.
To exercise any of these rights, please contact us using the details below.
10. Third-Party Links and Integrations
Our website and the Metapass Platform may link to or integrate with external websites and systems that are not operated by us, including payment providers, gateways, and third-party software platforms. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policy of any third-party service you use or site you visit.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically to stay informed about how we protect your information.
12. How to Contact Us
If you have questions about this Privacy Policy, wish to access or correct your personal information, or would like to make a complaint, please contact us:
Metapass Pty Ltd
ABN 19 671 041 937
Level 8, 65 York Street, Sydney NSW 2000, Australia
Email: [email protected]
We will respond to your request within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).