Privacy Policy
Last updated: 21 November 2025
Privacy Notice
We at PrizeCart (ACN 688 017 692), based in Victoria, Australia, respect the privacy and confidentiality of the personal data of our users, customers, merchants, visitors and everyone we interact with while providing our services. While we aim to make shopping more fun by turning everyday purchases into instant-win prize experiences, we understand that the safety of your personal information is a key concern. We are committed to ensuring that all personal data provided to us remains secure and is only used for purposes that you have been informed of and, where required, have consented to.
We only collect information that is reasonably necessary to:
- Provide access to the PrizeCart platform (website, portal, apps, Shopify integration).
- Track and validate your eligible purchases with participating merchants for prize allocation and affiliate commission.
- Fulfil our legal obligations to properly conduct trade lottery promotions.
- Understand how our services are used so we can improve them for users and merchants.
We collect the minimum information required to achieve these purposes. We share with our merchant and affiliate partners only what is necessary to verify attributed orders, calculate commissions, determine prize eligibility and fulfil prizes.
For tracking purposes, we use cookies and related technologies to attribute your transactions so we can credit prize allocations (e.g., "1 prize box per $5 spent") and ensure commissions are tracked correctly. Where possible, information provided to third parties is limited to aggregated or de-identified data (e.g. trends, volumes, performance insights without identifying individuals).
We do not sell your personal information.
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you have questions or need assistance, contact us at:
- General support: support@prizecart.app
- Privacy matters: privacy@prizecart.app
Personal Data Protection Policy
This document explains how PrizeCart manages, collects, uses and discloses personal data relating to users of our website, Shopify app, browser widgets, software, mobile applications, prize mechanics and other platforms (collectively, the "Services"). Continued use of our Services constitutes agreement to this policy as updated from time to time.
Definition of Personal Data
"Personal Data" refers to information or opinions about an identifiable individual, whether true or not, including information in our records.
"Sensitive information" (as defined in the Privacy Act) includes health or biometric data. We do not collect sensitive information in the ordinary course of business; if required (e.g. high-value prize verification), we will only do so lawfully and with safeguards.
"De-identified information" refers to data that no longer identifies an individual. We may use or share de-identified or aggregated information (e.g. campaign insights without user identities).
Collection of Personal Data
The data we collect depends on the products, Services and promotions you use. We collect data to ensure platform functionality, calculate prize eligibility, prevent fraud, understand usage and support merchant integrations.
You provide Personal Data when you:
- Use our websites, apps or integrations, or submit enquiries.
- Register for a PrizeCart account or onboard as a merchant.
- Interact with PrizeCart experiences embedded on merchant websites (e.g., post-purchase prize notifications).
- Sign up for alerts, newsletters or promotions.
- Contact support via chat, email, phone or other channels.
- Join contests, prize draws, beta tests or surveys.
- Submit job applications.
- Are referred to us by partners or merchants.
Types of Personal Data Collected
Identity Full name, email, phone number, date of birth, country of residence. Delivery address for prize fulfilment. Account identifiers and login data. Device identifiers, IP, browser data.
Interactions Communications (emails, support messages). Interactions with the PrizeCart portal or Shopify widget.
Account Information Profile details, prize history, items, achievements, settings.
Service Usage & Merchant Transactions Pages viewed, actions taken, timestamps. Transaction details with merchants (order ID, value, time, and limited non-sensitive product data). Fraud-related system-generated signals.
PrizeCart does not collect your search engine history, email content, or browsing data outside of PrizeCart-enabled merchant sites.
Preferences Contact preferences, favourite prize types, categories.
Location IP-based or device location (if enabled).
Children's Data Services are not intended for children under 16. If a child's data is found, contact us to remove it.
Anonymity You may interact anonymously where lawful and practicable (e.g., browsing the marketing site), but identification is required for key services such as prize fulfilment.
Other Data Sources We may collect data from merchants, affiliate networks, analytics providers, social platforms, fraud-prevention services or public sources, where allowed.
Cookies
We use cookies to:
- Track transaction attribution
- Keep you logged in
- Remember preferences
- Improve performance
Blocking cookies may prevent us from attributing purchases or providing Services.
Shopify App and Widgets
When you shop on a merchant using PrizeCart, the app/widget may collect:
- Merchant name and domain
- Active promotion indicators
- Order ID, value, time, basic non-sensitive details
- Prize allocation (e.g. "1 box per $5 spent")
- Browser/device info needed to render the widget
We do not collect payment card details or passwords. We do not track browsing on non-PrizeCart websites.
Accuracy of Information
You must ensure your Personal Data is accurate. Incorrect data may affect Services or prize eligibility. When providing data about others, you must obtain their consent.
Use of Personal Data
PrizeCart does not sell your data. We use Personal Data for:
1. Administering Services
Tracking attributed transactions. Calculating prize eligibility. Operating instant-win mechanics. Prize fulfilment. Reconciliation with merchants. Managing promotions and prize draws.
2. Direct Marketing
Notifications about new prize seasons, offers, merchants. Updates on odds, structures, promotions. Targeted/untargeted advertising using hashed identifiers. You can opt out anytime.
3. Improving Services
Handling complaints. Enhancing performance and stability. Understanding user behaviour. Developing new features. Providing merchants with de-identified insights.
4. Customer Service
Responding to enquiries. Providing guidance. Issuing updates. Managing complaints.
5. Security & Compliance
Fraud detection and investigation. Audits and testing. Meeting legal requirements. Assisting law enforcement. Risk management.
6. Job Applications
Recruitment and HR processing.
We retain Personal Data only as long as legally or operationally necessary.
Sharing of Personal Data
We may share data with:
- PrizeCart group companies
- Merchants, brands and affiliate partners
- Payment/payout providers
- Cloud/IT partners
- Analytics platforms
- Customer support tools
- Marketing service providers
- Professional advisers (lawyers, auditors)
We may also share data for business transactions (e.g., mergers) under confidentiality protections, or with regulators where legally required.
Some disclosures may be overseas, with safeguards in place.
We do not sell your personal information.
Security of Personal Data
We apply safeguards including:
- HTTPS/TLS encryption
- Secure servers
- Access controls
- Verification processes
- Breach monitoring
- Secure destruction or de-identification
If an eligible data breach occurs, we will notify the OAIC and affected individuals per the NDB scheme.
Updating Your Personal Data
You may update your data through your account, or email privacy@prizecart.app for assistance.
Access, Use Disclosure & Withdrawal of Consent
Contact privacy@prizecart.app to:
- Access your data
- Request past 12-month usage/disclosure information
- Withdraw consent
We may charge an administrative fee for access. Withdrawing consent may affect our ability to provide Services.
For unresolved complaints, you may contact the Office of the Australian Information Commissioner (OAIC).
Changes to This Policy
We may update this Policy to reflect practices, industry changes or legal requirements. Updates will be posted on our website.
Governing Law
This Policy is governed by the laws of Australia and complies with the Privacy Act 1988 (Cth) and the APPs.