Privacy Policy

TCN Group Pty Ltd [ABN 87 626 501 568], trading as The Card Network  (“TCN”, we, us, our), is part of the InComm Payments group, a global payments technology company. TCN creates multi-brand gift card products that bring together Australia’s favourite retailers and brands on a single card, giving recipients the flexibility to choose where and how they redeem their gift. These gift card products can be purchased as physical cards in our partner retail stores or online through our websites. They may be delivered physically, via email or SMS on a mobile device. TCN also provides gifting, rewards, loyalty, and corporate incentive solutions for businesses. To support our consumers, we process payments and provide customer service.

TCN processes customer payments, manages card activation and redemption, and provides customer support. We are committed to protecting your privacy and handling your personal information responsibly, transparently, and in accordance with the Privacy Act 1988 (Cth) ("Privacy Act”), including the Australian Privacy Principles (“APPs”). This Privacy Policy (the “Policy”) explains what personal information we collect, how we collect it, why we collect it, how we use and disclose it, and the rights you have in relation to your information. It applies to all personal information we handle in connection with TCN websites, mobile applications, products, and services (together, our “Services”). 

We encourage you to read this Policy carefully. It is available on our website at all times; we will provide a copy free of charge in any particular form you request where it is reasonable to do so.

1. What Personal Information We Collect

We collect personal information that is reasonably necessary for us to provide our Services, comply with our legal obligations, and operate our business.

If you do not provide us with the personal information we request, we may not be able to process your transaction, deliver your gift card, or provide you with customer support.

The types of information we collect depend on how you interact with us, and may include:

1.1  Identity, Contact and Payment Information

This includes information necessary to perform transactions and deliver our products and services, for example: name, email address, address, telephone number, payment card data, billing address, transaction information, and date of birth (where required for verification purposes).

For digital gift card products, we may also collect recipient information (name and email address) that you provide to us in order to complete delivery. Beyond the information you provide to us, we may collect transaction information when the recipient of a gift card uses it to make a purchase.

 If you contact our customer support team, they may request government-issued identification (for example, a national ID card) for identity verification in connection with fraud or dispute resolution. 

1.2  Technical and Usage Information

When you use our websites or mobile app, we automatically collect technical information such as your IP address, device identifiers, browsing information, geolocation data (where enabled), browsing information, including pages visited and actions taken, and information collected through cookies and tracking technologies on TCN websites, including our ecommerce storefronts and redemption websites. 

For more information about cookies and tracking technologies, please see Section 9.4 below.

1.3 Sensitive Information

We do not intentionally collect sensitive information as defined by the Privacy Act 1988, including information about race, religion, ethnicity, political opinions, sexual orientation, trade union membership, criminal records, health information, or biometric data. However, our customer support team may require government-issued identification or other form of identification to verify your identity in connection with certain  complaints. Government identifiers are the highest-sensitivity data category that TCN handles, and we treat them with additional safeguards.

Our automated fraud screening tools may incidentally produce inferences about consumer behaviour. Any such inferences that could constitute sensitive information are transient, are not recorded or stored, and are used only for the immediate fraud determination.

We do not intentionally collect personal information of children under 15 without the involvement of a parent or guardian. For more information, see Section 10.

1.4 Unsolicited Personal Information

If we receive personal information that we did not solicit and determine we could not have collected it under the APPs, we will destroy or de-identify it as soon as practicable, unless retention is required or authorised by law.

2. How We Collect Personal Information

We collect personal information directly from you when you:

  • Use our products and services;
    Purchase a physical gift card from one of our retail partners;
  • Purchase a physical or digital gift card through our websites;
  • Register or activate your gift card;
  • Create an account or profile on our websites;
  • Contact our customer support team (via phone, email, contact form, or online);
  • Interact with our website, app, or marketing communications; or,
  • Participate in surveys, promotions, or feedback requests.
  • We may also indirectly collect personal information about recipients of gift cards where you provide their details for delivery purposes.

In addition, we collect certain information automatically through cookies, analytics services, and other tracking technologies when you visit our websites. For more information, see Section 9.4.

3. Why We Collect, Hold, and Use Your Personal Information

We collect, hold, use and otherwise process your personal information for purposes including:

  • Providing our Services: To process transactions, activate and redeem gift cards, deliver products and services, and manage your account.
  • Fraud prevention and security: To detect, investigate, and prevent fraud, unauthorised transactions, and other security incidents, and through automated fraud detection systems.
  • Customer support: To respond to your enquiries, requests, and complaints, and to provide after-sale support.
  • Product improvement: To understand how our Services are used, and to improve, develop, and personalise our products and services.
  • Legal and regulatory compliance: To comply with our obligations under Australian law, including reporting and record-keeping requirements.
  • Marketing and communications: To send you information about our products, services, and promotions where you have consented or where permitted by law. You may opt out of receiving marketing communications as described in Section 9.3. All commercial electronic messages we send comply with the Spam Act 2003 (Cth), including identifying the sender, providing accurate contact information, and offering a functional unsubscribe mechanism.

We take reasonable steps to ensure that the personal information we collect, use, and disclose is accurate, up-to-date, complete, and relevant.

We will only use or disclose your personal information for the purpose for which it was collected, or for a related secondary purpose that you would reasonably expect, unless you have consented or the use or disclosure is otherwise permitted or required by law.

4. Automated Decision-Making

We use automated systems and algorithms in connection with certain aspects of our Services, including: 

  • Fraud detection: Automated monitoring systems analyse transaction data to detect unusual account activity, potentially fraudulent transactions, and breaches of our terms of service. These systems may use personal information to identify fraud patterns.
  • Customer support: Automated systems may be used to route customer calls and provide our customers with initial support.

In accordance with the transparency requirements introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) (commencing 10 December 2026), we disclose that:

  • The kinds of personal information used in automated decision-making include payment card data, transaction data (history, location, and amount), device identifiers, and IP addresses;
  • The kinds of decisions made by automated systems include whether to approve, flag, or decline a transaction based on fraud risk scoring; and,Where an automated decision has a significant effect on you (for example, a decision to decline a credit application), you have the right to request more information about how the decision was made and to request a human review of the decision. To make such a request, please contact our Data Protection Officer using the details in Section 12.

5. Disclosure of Personal Information

We may disclose your personal information to the following categories of recipients:

  • Payment processors and financial institutions: To facilitate transactions, transfers, and payments.
  • Fraud prevention providers: To detect and prevent fraud.
  • Card production and fulfilment providers: For physical card production and fulfilment.
  • Customer support providers: To provide customer service support and contact management.SMS delivery providers: For digital code delivery.
  • Regulators and government authorities: Including law enforcement agencies, where required or authorised by law.
  • Professional advisers and service providers: Auditors, lawyers, and IT service providers, who assist us in running our business and are bound by confidentiality obligations.
  • Related bodies corporate: Within the InComm Payments corporate group, for the purposes described in this Policy.
  • Prospective purchasers: In connection with a proposed sale, merger, or restructure of our business, subject to confidentiality obligations.
  • Travel and booking services: In connection with The Hotel Card product.
  • Marketing and communications partners: Where you have consented to receiving marketing communications and disclosure is not prohibited by law.
  • Data analytics providers: Where you have consented to data sharing.

We do not sell or trade your personal information to third partiesWhere we engage third-party service providers, we require them to protect your personal information in a manner consistent with this Policy and applicable law.

6. Cross-Border Disclosure of Personal Information

TCN primarily stores and processes personal information within Australia. However, in connection with our Services, personal information may be disclosed to recipients located overseas. 

The countries to which we may disclose personal information and the purposes for such disclosures are set out below.

 

United States

  • For card activation and redemption;
  • For fraud detection and monitoring;
  • For card production and fulfilment; and
  • For payment processing.

Philippines

  • For customer service support.

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles your personal information in a manner consistent with the APPs, as required by APP 8.1. This includes entering into binding contractual arrangements that require the overseas recipient to protect your information in accordance with standards equivalent to the APPs.

TCN acknowledges that under APP 8.1, if an overseas recipient to whom we have disclosed personal information breaches the APPs in relation to that information, TCN is deemed to have breached the APPs itself. 

If we are unable to meet the standard in APP 8.1, we will obtain your consent before disclosing personal information overseas, or otherwise ensure the disclosure falls within an exception under APP 8.2.

 

7. Data Security

We take the security of your personal information seriously. In accordance with APP 11, as clarified by the Privacy and Other Legislation Amendment Act 2024 (Cth), we implement reasonable technical and organisational measures to protect your personal information from misuse, interference, loss, and from unauthorised access, modification, or disclosure.

These measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256);
  • Multi-factor authentication and role-based access controls;
  • Regular security testing and vulnerability assessments;
  • Staff training on privacy and data security obligations;
  • PCI DSS compliant handling of payment card data;
  • Payment card data is truncated immediately upon transaction authorisation — full card numbers are never stored;
  • Restricting access to personal information to personnel who need it to perform their duties;
  • 24x7x365 Cyber Security Operations Centre (CSOC) monitoring;
  • A formal Privacy Incident Response Plan (PIRP) and Cyber Security Incident Response Plan (CSIRP); and
  • Periodic vendor security assessments.

No method of electronic transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.

8. Retention and Destruction of Personal Information

It is our policy to retain personal information for as long as necessary to fulfill the purposes for which it was collected, We may be required to retain personal information and maintain applicable business records in order to satisfy legal, regulatory, accounting, and reporting requirements. 

Once personal information is no longer required for any of the above purposes, we take reasonable steps to securely destroy or de-identify it in accordance with OAIC guidance, unless we are required or authorised by law to retain it.

9. Your Rights

9.1 Access and Correction

You have the right to request access to the personal information we hold about you and to request correction of any information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond to your request within a reasonable period, generally within 30 days.  

We may charge a reasonable fee to cover the cost of retrieving and providing the information, but we will not charge you for making a request or for correcting information.

In limited circumstances, we may refuse your request for access or correction. If we do, we will provide you with written reasons for the refusal and information about how you may make a complaint.

9.2 Anonymity and Pseudonymity

Where it is lawful and practicable, you have the option of interacting with us anonymously or using a pseudonym. However, due to our legal obligations (including under the AML/CTF Act), we may be required to verify your identity in connection with certain financial products and services. Our customer support team may also require identification in order to assist you.

9.3 Opting Out of Marketing

You may opt out of receiving marketing communications from us at any time by using the unsubscribe function included in our communications or by contacting us using the details in Section 12.

9.4 Cookies and Tracking Technologies

Our websites use cookies and similar tracking technologies to enhance your experience, analyse website usage, and support our marketing activities. You have the same rights with regard to your personal data when it is collected by a cookie as by any other method.

 

To find out more about the use of cookies and similar tracking technologies on our websites, please see our Cookie Notice click here. Our Cookie Notice provides useful information, including what kind of cookies are on our website, their purpose, and how to adjust your cookie preferences.

9.5 Withdrawing Consent

Where we rely on your consent to collect, use, or disclose personal information, you may withdraw that consent at any time by contacting us using the details in Section 12. Please note that withdrawing consent may affect our ability to provide certain Services to you.

10. Children’s Privacy

TCN does not knowingly collect personal information from children under 15 without the involvement of a parent or guardian. Children under 15 are prohibited from using TCN websites.

Our gift card products may be used by individuals under 18; however, purchases are made by adults at retail locations or online.

This Privacy Policy is written in clear, plain language so that it is accessible to a broad audience, including young people. If you become aware that a child under 15 has provided us with personal information without the involvement of a parent or guardian, please contact us using the details in Section 12 so that we can take steps to remove that information.

11. How to Make a Complaint

If you believe that we have breached the Privacy Act, the APPs, or the Spam Act 2003, or if you are unhappy with how we have handled your personal information, you may make a complaint by contacting our Data Protection Officer using the details in Section 12.

 

We will acknowledge your complaint within a reasonable period and aim to provide a response within 30 days. We will investigate your complaint and provide you with a written response setting out our findings and any action we propose to take. 

If you are not satisfied with our response, you may escalate your complaint by contacting:

The Office of the Australian Information Commissioner (OAIC)

Website: www.oaic.gov.au 

Phone: 1300 363 992

12. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or wish to make a complaint, please contact us:

 Jacquelyn Whitlock, Data Protection Officer

Post:

TCN Group Pty Ltd

250-254 Swan Street

Richmond, VIC 3121

Australia

 Email: incommprivacy@incomm.com

Phone: 1300 375 346

Website: thecardnetwork.com.au

Privacy Web Form (link): InComm Privacy Portal

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes, we will update the “Last updated” date at the top of this Policy and, where appropriate, notify you through our website or other means.

 We encourage you to review this Policy periodically to stay informed about how we are protecting your personal information.

 

Last updated October 2026