Reward Gateway Pty Limited ("we", "us" or "our") is committed to protecting and respecting your privacy under the Privacy Act 1988 (Cth) (Privacy Act) and other applicable laws.
This Privacy Notice ("Notice") describes how we collect, store, use, disclose, share and secure any personal information ("Personal Information") we collect from you or from third parties, including Proactive Health (the "administrator") who we have entered into a Licence Agreement with, about you on this website (the "programme", "Hot Tub Community Hub") will be processed by us.
In the event of a conflict between the terms of this Notice and the terms of the Licence Agreement, the Licence Agreement shall prevail.
We have appointed a Data Protection Team, who can be contacted using the details at the end of this notice should you have any questions, complaints or feedback about your privacy.
Information We Collect From you and How We Use It
We will collect various types of personal information from you when you use Hot Tub Community Hub, depending on the particular services which you use. Further details of how we use your personal information are set out below.
Before you register
Before you register on Hot Tub Community Hub, to allow us to carry out our eligibility checks we will ask the administrator to provide two pieces of information about you (such as your postcode, payroll ID, start date or date of birth).
The administrator has provided us with your information for an account to be created.
When you register
In addition to the personal information provided to us by the Administrator, when you register on Hot Tub Community Hub we will also collect and store some personal information about you, such as your name, company identifier, email address, password, postcode, contact telephone number, gender and date of birth. At the Administrator’s choice, we may also collect additional information about you such as your office location.
You will also need to provide the information necessary to allow us to carry out our eligibility check (which will vary dependent on the information provided by the Administrator, see above).
This information will be used in order to complete your registration and to allow you to use Hot Tub Community Hub. You will not be able to register without at least providing your name, email address, password and postcode or date of birth, as these are used to secure your account and to allow us to confirm your identity if you contact the support team.
When you login
Each time you log in to Hot Tub Community Hub, we automatically conduct checks against your Internet Protocol (IP) address to ensure your security. This includes looking up your IP address against a “proxy denylist” to check that someone is not using your credentials and trying to hide their location. This proxy denylist is operated by MaxMind, Inc. If your IP address appears on it, we will not allow you to login.
We also look up the IP address in a static database we download from MaxMind Inc. to check which country the IP is affiliated with. This helps us to further protect your account against people who may have access to your credentials. If we do spot a change, we will alert you and ask you to confirm your login in order to verify your identity before continuing.
This information along with time and event data (such as successful or failed logins) are also recorded in our database for audit purposes.
Depending on the services you use on Hot Tub Community Hub, we may collect and process additional personal information about you, as set out below.
When you use Cashback
If you visit a Cashback retailer on Hot Tub Community Hub, we will record that you clicked and visited their website for the purpose of tracking the Cashback earned. We will provide the merchant with a pseudo-anonymous ‘click reference’ to allow us to attribute the purchase and Cashback to you.
If you have a problem with the retailer and your Cashback, we may need to provide them with additional information about your order to help. We will ask you for the minimum information we need to do this, but you will be responsible for the accuracy and level of detail it contains.
Each of these retailers are independent on Hot Tub Community Hub so you should check their privacy notices to make sure you are happy with them before providing any other details to them.
When you withdraw your Cashback
If you make a request for a Cashback withdrawal to your bank account, you will need to provide your bank details for us to process the withdrawal but we will only store your bank details until the withdrawal is processed. They will be shared with our bank, HSBC, to process your request after which all the details will be destroyed.
Alternatively you will be able to withdraw your Cashback as part or full payment for goods on Hot Tub Community Hub or ask us to donate it to the nominated charity on Hot Tub Community Hub.
When you make a debit or credit card purchase
If you choose to purchase goods using a credit or debit card through Hot Tub Community Hub, we will collect your payment details from you and pass them to Checkout.com, our secure payment processor, who will use them to process the payment. We do not store or process your credit or debit details on our servers.
We will also collect your delivery address from you, and use the contact details previously provided, to allow us to process the order.
If you opt-in to saving your credit or debit details for future use on Hot Tub Community Hub, your information will be stored securely by Checkout.com. You can update or remove these at any time.
Where goods are dispatched by a third-party supplier, we may need to share your information with them to fulfil your order, such as your contact details and delivery address. This will be clearly indicated to you at the point of purchase. You will be able to review the suppliers’ privacy notice before any information is shared with them.
We will also carry out a fraud check during the order process. This check is carried out by our third party provider, Sift Science (“Sift Science”). Sift Science will only act in accordance with our instructions and how they will process your personal information is set out below.
Sift Science will collect information about your behaviour on the programme (such as the length of time between logging in and reaching checkout), technical information about the device used (such as your browser version and IP address) and the details you enter at checkout (such as your contact details and delivery and billing address).
After you have placed your order and before goods are dispatched, Sift Science will use this information to provide us with a score based on the likelihood of fraud. The score provided determines whether your order is automatically accepted by us or queued for our human review. If it is queued for human review, we will carry out a manual fraud check to decide whether to accept or refuse your order or, in some circumstances, require payment to be made by an alternative, more secure mechanism such as a bank transfer. For more information about this processing activity, please contact us using the details provided at the end of this notice in the “Contacting Us” section.
After too many failed orders
If too many failed orders originate from your account, we will automatically restrict access to your account. Before allowing you to access your account again, we will notify you and ask you for further supporting documents such as your driving licence, council tax bill or rates notice, bank or credit card statement, utilities bill or payslip, as evidence that it is you attempting these orders. If these documents are not to our satisfaction, we may contact the Administrator with the intention of verifying that it is you using your account in this way.
These supporting documents will only be used for the purpose of verifying your identity, will not be shared with any third parties and will only be retained by us until we have reviewed them, even if we are not satisfied with their legitimacy or authenticity.
You do not need to provide these supporting documents to us but, if you choose not to, then we will not be able to provide you with access to your account.
When you send an eCard or when you make a nomination
If you ask us to send an eCard, you will need to provide us with the name of the person you are sending the eCard to (“the recipient”). If the recipient has already registered on Hot Tub Community Hub, we will send the eCard on your behalf to their registered email address.
If they have not already registered, you will also need to provide an email address which we will send the eCard on your behalf to. The recipient will be asked to confirm that they have read and understood this notice and agree to our Terms & Conditions before being able to view your message.
You must have the consent of the recipient to give us their name and, if applicable, email address and also any personal information you disclose in your message to them. This information will also be disclosed to the administrator for the purposes of performance management.
When you write a blog or comment / react to content
When you write a blog or comment / react to content on the site, we will display your name and any other personal information you choose to share via your blog or comment.
When you complete a survey
From time to time you may be invited to participate in a survey run by the Administrator.
If you complete a survey, all of the information that you provide in connection with that survey will be provided to the Administrator. Please be aware that the administrator controls the survey and what happens to the survey data, which may include using that data for research purposes or making the survey responses public.
We recommend that you contact the administrator to understand how they will use your survey responses. In some cases, the administrator may decide to provide you with their own separate privacy notice governing the use of your survey data in which case the information you submit in connection with such surveys will be governed by that privacy notice.
When you contact us
If you contact us for support purposes, we will require some information to handle your query. The following data are saved in Zendesk to enable processing: your name, email address, telephone number, and any other personal information you provide to us for the purpose of dealing with your query.
When you visit Hot Tub Community Hub
When you visit Hot Tub Community Hub we will automatically collect information about your visit such as the pages you viewed, offers or services you viewed or searched for, length of visits to certain pages, the times and dates of these actions, details of page response times and any download errors that occurred.
We will also collect data from the device and application that you use to access our services, including your IP address (from which we may infer your geographic location), login information and browser type.
If you arrive at our website from an external source (such as a link on another website or in an email) we record information about that source.
We will use the above information in order to:
- to administer Hot Tub Community Hub and for internal operations, including troubleshooting, data analysis (including analysing the use of the various services available on Hot Tub Community Hub and measuring their popularity and effectiveness), testing, research, statistical and survey purposes, and to comply with our legal obligations/;
- to improve Hot Tub Community Hub to ensure that content is presented in the most effective manner for you and for your computer / device;
- as part of our efforts to keep Hot Tub Community Hub safe and secure to comply with our legal obligations/;
- to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you. We, or our third party advertisers, may use your age or gender to determine whether advertising is relevant to you; and
- to make suggestions and recommendations to you and other users of Hot Tub Community Hub about goods or services that may interest you or them/.
Other information and uses
We will also collect the personal information you provide when you use Hot Tub Community Hub:
- to provide you with our newsletter and with information about other third party benefits we offer that are similar to those you have already used or enquired about or that we feel may interest you/.
- to notify you about changes (permanent or temporary) to our service.
- to ensure that content from our website is presented in the most effective manner for you and your computer.
- to administer our website and for internal operations, including troubleshooting, data analysis, testing, research and statistical purposes, and as part of our efforts to keep our website safe and secure.
Information we receive from other sources
We will combine information we receive from other sources (as set out in this notice) with information you give to us. We will use this information and the combined information for the purposes set out in this notice (depending upon the services you access).
Change of Purpose
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose and permitted under data protection laws. If we need to use your personal information for an unrelated purpose, in most cases we will notify you and we will explain the legal basis which allows us to do so.
Disclosures of your Information
We use service providers to help us to provide the website, such as data storage providers, marketing email providers, analysis providers and benefit providers:
- Amazon Web Services EMEA SARL, a cloud hosting provider;
- Emailcenter UK, a transactional and bulk email gateway;
- Google Inc., a web analytics tool;
- FullStory Inc., an analytics service provider;
- Heap Inc., an analytics service provider;
- New Relic Inc., a performance measurement tool;
- Twilio Inc., a SMS / text-messaging gateway;
- Formstack, LLC, a configurable data-capture provider;
- Zendesk Inc., a customer support platform;
- Atlassian Pty Ltd., a ticketing system for our internal teams;
- Mailgun Technologies Inc., a transactional and bulk email gateway;
- WalkMe, Inc., Contextual help, support and assistance for administrators;
We may also share your personal information with:
The Administrator
Because the administrator pays us to operate for you, they’ll want to know how the website is performing. Except as set out elsewhere in this notice, we will only share information with the administrator on an aggregated and anonymous basis about how often you’ve used the website and what services you used. We will not share information with the administrator about how much you’ve spent, where you shop, and how much you’ve saved as an individual, as we treat this as confidential.
Our Internal Teams and Prospective Retailers
We also use information about you on an aggregated and anonymised basis for internal management purposes, to, share it with current or prospective retailers and to use it to target offers that are made to users of Hot Tub Community Hub. This type of information includes, for example, the types of product that you purchase and the value of those purchases. However, you can’t be identified from this information.
Members of our Group
We share personal information with members of our group for the purposes of providing the benefits to you and managing our business: RG Engagement Group Ltd, Reward Gateway Pty Ltd, Reward Gateway (USA) Inc, Reward Gateway (UK) Ltd Branch, SEO Reward Gateway DOOEL Skopje, International Benefits Holdings Ltd., Asperity Employee Benefits Group Ltd
Other Parties
We will also disclose your personal information to third parties:
- in the event that we sell or buy any business or assets, in which case we will disclose your personal information to the prospective seller or buyer of such business or assets;
- if we or substantially all of our assets are acquired by a third party, in which case personal information held by us about our customers will be one of the transferred assets; and/or
- if we are under a duty to disclose or share your personal information in order to comply with any legal obligation, or in order to enforce or apply our Terms and Conditions and other agreements; or to protect the rights, property, or safety of us, our users, customers and providers. This will include sharing your information as part of a legal or official investigation if we have evidence or reason to suspect that purchases on your account could be fraudulent.
Transfers of your Personal Information
A number of the service providers listed above are based outside of Australia and your personal information may therefore be transferred to or accessed from outside of Australia where the data protection laws may differ.
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with the Privacy Act (Australian Privacy Principle 8), this notice, and the GDPR, and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
We remain fully accountable for these transfers in accordance with Section 16C of the Privacy Act.
Your Rights
Under the Privacy Act (Australian Privacy Principles 12 and 13), you have the right to:
- request access to your Personal Information. This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it; and
- request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights above). However, we may charge a reasonable fee if your request for access is manifestly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
We or the administrator may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
To withdraw your consent in relation to direct marketing, please contact us using any of the details set out below in the “Contacting Us” section or change your preferences in the “My Account” section of Hot Tub Community Hub.
Please note that as the administrator may store other information from your use of this service, you should also contact them directly if you would like to exercise your rights in relation to the data held by them.
Residents of the United Kingdom (UK) and European Economic Area (EEA)
If you are located in the UK or the EEA, you have additional rights under UK and European law with respect to your Personal Information, including the right to request delete, port to another service provider, or object to certain uses of your Personal Information.
We will only collect personal information from you where we need the Personal Information to perform a contract with you (e.g. to provide you with a service), where the processing is in our legitimate interests when your interests and fundamental rights do not override those interests, or where we have your consent.
You also have the right to object to the processing of your Personal Information where we are relying on a legitimate interest (or those of a third party), which is not overridden by your data protection interests or fundamental rights and freedoms. In particular we process your Personal Information to pursue the following legitimate interests:
- to prevent risk and fraud on our platform;
- to provide customized communications, marketing, and advertising;
- to provide reporting and analytics;
- to provide troubleshooting, technical support, or to answer questions;
- to trial new features or additional services; and
- to help improve our services, applications, and websites.
Where we rely on your consent to process your Personal Information, for example in relation to any direct marketing we provide to you, you have the right to withdraw your consent for that specific processing at any time.
In some cases, we may also have a legal obligation to collect Personal Information from you.
If you have any questions, comments or complaints about the handling of your personal information under this notice, or you wish to enquire further about the legal basis on which we collect and use your Personal Information, please contact our representative:
- by email at privacy-requests@rewardgateway.net or;
- by post at Reward Gateway (UK) Ltd., 265 Tottenham Court Road, London, W1T 7RQ.
Resolving your privacy concerns and complaints
If you have a question or complaint about how your Personal Information is being handled by us, our affiliates or contracted service providers, please contact us using the contact details provided below.
We will treat your complaint confidentially and, after investigating your complaint, discuss the ways in which we can remedy the situation. We will ensure that we respond to your complaint within a reasonable time (and in any event within the time required by the Privacy Act.)
You also have the right to make a complaint at any time to:
Australian Information Commissioner
The Australian Information Commissioner receives complaints under the Privacy Act. Complaints can be made:
- online: http://www.oaic.gov.au/
- phone: 1300 363 992
- in writing: Office of the Australian Information Commissioner, GPO Box 5218, Sydney, NSW 2001
Other Data Protection Authorities
If you are based in the European Union, then you may lodge a complaint with your local National Data Protection Authority (‘NDPA’). Your local NDPA can be found using the European Commission website.
If you are based in, or the issue relates to, the United Kingdom, the Information Commissioner’s Office can be contacted online.
Please note that as the administrator may store other information from your use of this service, you should also contact them directly if you would like to exercise your rights in relation to the data held by them.
Updating your information
It is important that the personal information we hold about you is accurate and current. Please keep your records on Hot Tub Community Hub up-to-date. If you wish to update or amend your personally identifiable information or data you may do so by making the change within your account once logged in or by contacting our Helpdesk. We will respond to your request within 5 working days.
Storage of your information
Unless we need to keep your data for legal purposes, we will only retain your personal information for 60 days after the administrator lets us know you no longer work for them or they decide to use a different service.
The legal purposes for which we may need to retain your data for include:
- retaining payment records for one year to comply with PCI DSS regulations;
- retaining backups for up-to 180 days after de-provisioning; and
- retaining your order history for two years from the date of your order in case of a dispute.
We may also retain anonymised data about you for longer periods for integrity and financial reporting purposes.
Recordings of calls are retained for 40 days and chat transcripts are retained for 90 days.
We take the security and confidentiality of your personal information very seriously. We will use strict procedures and security features to aim at preventing unauthorised access, such as being ISO 27001 and ISMS certified, access controls, penetration testing, the use of encryption and hashing and robust physical security controls.
You are also responsible for the security of your personal information by taking precautionary measures, such as keeping your account password confidential and using secure wireless connections.
Changes to this notice
Any changes we make to this notice in the future will be posted on this page and, where appropriate, notified to you by email. Please check back frequently to see any updates or changes to this notice.
Contacting Us
If you have any queries, comments or requests regarding this notice, or you would like to exercise any of your rights set out above, or contact our Data Protection Team, you can contact us in the following ways:
- by email at privacy-requests@rewardgateway.net or;
- by post at Reward Gateway, Suite 13.01, Level 13, Australia Square Plaza 95 Pitt St, NSW 2000.