Privacy Policy
1. About this Privacy Policy
1.1 Liquid Transfer Pty Ltd (ACN 678 982 888) (“liquid”, “we”, “us”, “our”) is committed to keeping your information safe and secure in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1.2 By using our website (www.liquid.net.au) or engaging our services including remit (our consumer remittance service), rails (our business payments platform), and vault (our treasury and wealth platform) (collectively, “the Services”), you (and your business) consent to our handling of personal information as set out in this Privacy Policy.
1.3 This Privacy Policy applies to all individuals whose personal information we collect, including individual customers, business customers and their personnel, directors, shareholders, beneficial owners, transaction recipients, and website visitors.
1.4 This Privacy Policy is intended to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where applicable to our services, we also comply with obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and Australian Consumer Law.
2. Collection of Personal Information
2.1 liquid may collect and use the following kinds of information:
-
information about your use of the Website or Services (including your IP address; browser type; device identification number, version and language; operating system; pages viewed while browsing; page access times; cookies; and referring website address);
-
identity and verification information (full legal name, date of birth, residential address, government-issued photo identification, proof of address, ABN and other business identifiers, and - where lawful and reasonably necessary - Tax File Number);
-
financial information (bank account details including account number, BSB, and account holder name; PayID information; wallet addresses for cryptocurrency transactions; income or revenue information for the vault product);
-
contact information (email address, mobile phone number, postal address, preferred contact method);
-
transaction information (all transaction details including sender, recipient, amount, currency, date, time; payout method and destination; FX rates applied; fees charged; payment status and tracking);
-
business information for rails and vault customers (business legal structure, registration documents, director and shareholder details, beneficial ownership information for shareholders holding 25% or more, business purpose and anticipated transaction volume, accounting software integration details);
-
behavioural and preference information (user settings and preferences, automation rules and thresholds for the vault product, communication preferences, service usage patterns, support interactions).
2.2 Information may be collected from you in a variety of ways, including but not limited to:
-
when you register for the Services;
-
when you, your contractors, agents, employees, directors, or your customers interact with liquid electronically or in person;
-
when you access liquid’s Website or Services;
-
from third-party identity verification providers for KYC/KYB verification;
-
from banking, payout and payment partners;
-
from compliance screening vendors and sanctions screening providers;
-
from regulatory authorities including AUSTRAC;
-
when you contact us by phone, email, or online forms;
-
automatically through website analytics, app usage tracking, device identifiers, and cookies.
Of course, the partners and providers we use may change from time to time.
2.3 Under the AML/CTF Act, we are legally required to collect certain personal information including full identity verification documents, beneficial ownership information, ongoing transaction monitoring data, Politically Exposed Person (PEP) screening results, suspicious transaction reporting information, and payer (sender) and payee (recipient) information required to accompany value transfers under the AML/CTF Act’s value transfer (‘travel rule’) obligations. Non-compliance with these obligations results in significant regulatory penalties and operational restrictions. This collection is mandatory.
3. Use and Disclosure of Personal Information
3.1 liquid may use your personal information to:
-
enable your access to the Website and Services;
-
verify your identity and conduct KYC/KYB compliance as required by the AML/CTF Act;
-
conduct AML/CTF monitoring and report suspicious transactions to AUSTRAC;
-
process your remittances, payments, and treasury transactions;
-
execute FX conversions and settlements;
-
receive information from, and disclose information to, payout partners, liquidity providers, and custody providers as needed to fulfil your transactions;
-
contact you about transactions, delivery status, changes, complaints, or dispute resolution;
-
collect payments and manage accounts;
-
detect and prevent fraud through pattern analysis and behavioural monitoring;
-
operate, maintain, and improve the Website and our Services (including analytics and security);
-
comply with legal and regulatory obligations (including tax, law enforcement requests, AUSTRAC reporting);
-
send you service or marketing communications related to our products and Services (opt-out available);
-
for audit and record keeping purposes;
3.2 While this list is not exhaustive, any purposes outside of this list will be consistent with those permitted under the Privacy Act.
3.3 liquid will not disclose personal information about you unless it is required, incidental, or otherwise related to the primary purpose of providing Services to you or a third party for which you have consented to by engaging liquid’s Services.
3.4 However, liquid may disclose your personal information to:
-
AUSTRAC as required by the AML/CTF Act, including customer identification records, Suspicious Matter Reports (SMRs), Threshold Transaction Reports (TTRs), and any other reports, notices or information required by law or regulatory direction;
-
law enforcement and government agencies including Australian Federal Police (AFP), Australian Criminal Intelligence Commission (ACIC), Australian Signals Directorate (ASD), Australian Tax Office (ATO), and state and territory police;
-
third party identity verification providers for KYC/KYB verification, document validation, and PEP screening;
-
banking and payment partners and global payment infrastructure;
-
payout partners for transaction settlement and delivery;
-
other financial institutions, remittance providers, and virtual asset service providers in the transfer chain, to whom we transmit (and from whom we receive) the payer (sender) and payee (recipient) information - including name, address or date of birth, account or wallet identifiers, and a unique transaction reference - that is required to accompany value transfers under the AML/CTF Act’s value transfer (‘travel rule’) obligations, including where those institutions are located overseas;
-
custody, liquidity, and (where applicable) DeFi or yield-related service providers (and other third-party partners we may engage from time to time) for custody, liquidity provision, or execution of vault features;
-
wallet infrastructure and key management providers for embedded wallet creation, authentication, and cryptographic key management;
-
third-party service providers (hosting/cloud, payment processors, IT, communications, and analytics);
-
professional advisers and insurers;
-
government agencies, regulators, or dispute resolution bodies where required or authorised by law.
3.5 liquid, in its sole discretion, may disclose your personal information if it is required to do so by law or legal process, including: in order to establish, exercise, or defend its legal rights; as required or authorised by law; or to the extent required to permit liquid to investigate suspected fraud, harassment, money laundering, sanctions violations, or other violations of any law, rule or regulation, our policies, or the rights of third parties.
3.6 liquid may also use your personal information to protect the copyright, trademarks, legal rights, property, or safety of liquid, the Website, its customers, or third parties.
3.7 If there is a change of control in our business or a sale or transfer of business assets, we reserve the right to transfer to the extent permissible at law our user databases, together with any personal information and non-personal information contained in those databases. This information may be disclosed to a potential purchaser under an agreement to maintain confidentiality.
4. Data Ownership and De-Identification
4.1 We own operational records that we create while processing transactions, managing accounts, and coordinating with partners (including transaction records, correspondence, and compliance records).
4.2 We may create and retain de-identified and aggregated operational statistics (for example, transaction volumes, settlement times, generic service usage trends) for benchmarking and service improvement. No individual is reasonably identifiable from these datasets.
4.3 Customers are granted a limited, non-exclusive right to access transaction records and statements we hold for your account, subject to confidentiality and legal constraints.
5. Security and Accuracy
5.1 It is important that you advise liquid of changes to your personal information that you have provided, as it is essential that your personal information is accurate, complete, and up-to-date in order for liquid to provide the Services to you.
5.2 liquid will take commercially reasonable steps to protect your personal information from misuse, loss, unauthorised access, modification, and disclosure, including:
-
using secure cloud servers in Australia for data storage;
-
implementing encryption in transit (TLS 1.2+) and at rest (AES-256);
-
implementing role-based access controls and authentication measures;
-
conducting regular security assessments, penetration testing, and audits;
-
training staff on data protection and security practices;
-
using secure key management with cryptographic key rotation;
-
maintaining firewall protection, network segmentation, and DDoS protection;
-
implementing intrusion detection with 24/7 monitoring for unauthorised access attempts.
5.3 For cryptocurrency-related information, we implement additional security measures including cold storage for Bitcoin holdings (via custody partners or self-custody options), smart contract interactions using only audited protocols, and private keys never stored on our servers.
5.4 liquid uses a third-party key management provider to create and manage embedded wallets on your behalf. Authentication is handled via passkey credentials tied to your device, and private keys are cryptographically sharded so that no single party - including liquid, the key management provider, or any individual third party - holds complete access to your wallet. liquid does not store, access, or have the ability to reconstruct your complete private keys at any time. This architecture is designed to ensure that even in the event of a compromise of any single system, your wallet cannot be unilaterally accessed.
5.5 However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will take commercially reasonable steps to protect personal information and to respond to suspected security incidents in accordance with applicable law.
5.6 liquid will take commercially reasonable steps to destroy or permanently de-identify personal information if it is no longer needed for the purposes of providing our Services to you, no longer needed for the purposes of developing new products and services, and retention of that information is no longer required by law.
6. Data Retention and Deletion
6.1 Under the AML/CTF Act, we must retain customer identification records and transaction records for seven (7) years after account closure or final transaction. This is a legal requirement and records cannot be deleted within this period.
6.2 Transaction records may be retained for up to ten (10) years where extended retention is required for regulatory investigations or legal proceedings.
6.3 Other information retention periods are: device and analytics data (12-24 months for fraud detection and analytics); support communications (2-3 years for legal protection and dispute resolution); and marketing communications (until unsubscribed plus 12 months).
6.4 Where information is no longer required and no legal retention obligation applies, we will destroy or de-identify it using cryptographic erasure.
6.5 Customer account information will be retained for as long as the account is active and as needed to provide Services.
7. Access and Correction
7.1 You are responsible for ensuring that the information you provide to liquid is accurate, complete, and up-to-date.
7.2 By request, you may contact liquid and ask to know what sort of personal information is held about you, for what purposes, and how it is collected, held, used, and disclosed. We will respond within thirty (30) days.
7.3 By request, you may access your personal information by contacting legal@liquid.net.au. liquid reserves the right to charge a reasonable administration fee for this access.
7.4 If you believe that information liquid holds about you is incorrect, incomplete, or inaccurate, you may request that we amend it, and liquid will consider if the information requires amendment and will respond to your request within a reasonable timeframe.
7.5 liquid may refuse access to, or correction of, personal information where permitted by the Privacy Act or other applicable law. Certain compliance records (including identity verification information collected for AML/CTF purposes) must match official records and may not be able to be altered other than by updating them with correct supporting evidence.
7.6 Under Australian law, you do NOT have an unconditional right to be “forgotten”. We cannot delete AML/CTF compliance records (7-year legal retention), transaction records (7-year legal retention), information subject to ongoing legal proceedings, or information required for regulatory compliance.
8. Identifiers and Anonymity
8.1 You acknowledge that liquid retains, collects, and maintains your personal information for statistical analysis purposes (whether for commercial or non-commercial purposes).
8.2 We may disclose de-identified and aggregated operational metrics to third parties for analytics, benchmarking, service improvement, and reporting purposes. We do not disclose de-identified information where we reasonably believe it could be used to re-identify an individual.
8.3 For the sake of certainty, any shared analytics will only be de-identified operational metrics (for example, transaction volumes, settlement times), not customer personal information.
8.4 You have a limited right to interact with us anonymously. We cannot provide anonymity for account creation (KYC/KYB is mandatory), transaction processing (AML/CTF is mandatory), or customer support (identity verification is required). We will accept anonymous feedback and general inquiries where practical.
9. Trans-Border Data Flows
9.1 liquid operates as a cross-border payment platform, and as such, your personal information will necessarily be transferred internationally, including to recipients in:
-
The Americas (United States of America, Mexico, El Salvador, Guatemala, Brazil);
-
Africa (Nigeria, Kenya, Ghana, South Africa, Senegal, Morocco, Rwanda, Gabon, Benin, Togo, Malawi, Zambia, Gambia, Tanzania, Uganda, Cameroon, Côte d’Ivoire and Ethiopia);
-
Europe (the Eurozone and the United Kingdom);
-
Asia (the Philippines, Singapore, India, South Korea, Hong Kong, China and the United Arab Emirates);
-
identity verification and compliance screening providers (United Kingdom and other jurisdictions);
-
cloud hosting, data storage and infrastructure providers; and
-
blockchain networks, where smart contract interactions are inherently global and immutable.
9.2 You acknowledge that, due to the cross-border nature of the Services, it may be necessary for us to transfer personal information to foreign jurisdictions to provide the Services.
9.3 In addition to the above and to comply with the APPs, we will transfer personal information to someone in a foreign country only where:
-
liquid reasonably believes that the recipient of the information is subject to a law, binding scheme, or contract which effectively upholds principles for fair handling of the information that are substantially similar to the Australian Privacy Principles;
-
the individual consents to the transfer;
-
the transfer is necessary for the performance of a contract between you and liquid, or for the implementation of pre-contractual measures taken in response to your request;
-
the transfer is necessary for the conclusion or performance of a contract concluded in your interest between liquid and a third party; or
-
liquid has taken reasonable steps to ensure that the information which it has transferred will not be held, used, or disclosed by the recipient of the information inconsistently with the Australian Privacy Principles.
9.4 We may disclose personal information to recipients located outside Australia (including our payout, banking, custody, compliance, and cloud providers). Where we do so, we take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles in relation to that information, unless an exception under the Privacy Act applies (for example, where you consent or the disclosure is required or authorised by law). Overseas recipients may also be subject to foreign laws and lawful access requests, and you may have different avenues for complaint or redress.
9.5 Certain transactions (particularly rails and vault products) involve blockchain smart contracts and cryptocurrency networks where: transactions are immutable (once recorded on-chain, information cannot be deleted); transactions are pseudonymous but traceable (wallet addresses are publicly visible on blockchain); privacy is limited (transaction amounts, dates, and parties can be viewed on public blockchains); and information persists indefinitely (blockchain records may exist forever). You acknowledge that cryptocurrency transactions involve inherent privacy limitations.
9.6 Where you use vault or other yield-related Services, your deposited funds may be converted to stablecoins and allocated to third-party decentralised finance (“DeFi”) lending protocols to generate yield on your behalf. While your personal identity is never exposed on any blockchain network, the underlying transactions - including wallet addresses, transaction amounts, timestamps, and smart contract interactions - are recorded on public blockchain ledgers and are permanently and publicly visible. These records are pseudonymous (linked to wallet addresses, not to your name or personal details), but they cannot be deleted, modified, or made private once recorded. liquid maintains the separation between your identity and on-chain activity; however, you acknowledge that blockchain analytics techniques may, in some circumstances, allow third parties to correlate on-chain activity with other publicly available information. This is an inherent characteristic of public blockchain networks and is not within liquid’s control.
9.7 Where you send or receive an international transfer, the value transfer (‘travel rule’) obligations under the AML/CTF Act require us to transmit information about the payer (sender) and payee (recipient) to, and to receive that information from, the financial institutions, remittance providers and virtual asset service providers in the transfer chain. Some of those recipients are located overseas, in the regions listed in clause 9.1.
10. Sensitive Information
10.1 Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record, or health information.
10.2 We collect limited sensitive personal information, limited to: identification documents (government-issued photo ID, legally required for AML/CTF compliance); beneficial ownership information (may include immigration status, required for KYB compliance); and Politically Exposed Person (PEP) status (derived from public sources, required for AML/CTF screening).
10.3 We do not collect: health information, genetic information, criminal history, religious or political beliefs, sexual orientation, or trade union membership.
10.4 We collect limited biometric information solely for identity verification purposes. As part of our KYC/KYB process, our third-party identity verification provider may collect and process facial geometry data by matching a live selfie or liveness check against your government-issued photo identification. This biometric data is processed by the verification provider at the point of verification and is not stored on liquid’s servers. Once the verification decision has been issued, the biometric data is deleted by the provider in accordance with their data retention policies. liquid receives only the verification result (pass, fail, or manual review required) and a copy of the submitted identification documents as required under the AML/CTF Act.
10.5 Where sensitive information is collected, we will only use it for the primary purpose for which it was obtained, for a secondary purpose that is directly related to the primary purpose, with your consent, or where required or authorised by law.
11. Direct Marketing
11.1 liquid may use your personal information to directly offer you remittance, payment, and treasury services we believe may be of interest to you, including product updates and announcements, promotional offers, and educational content.
11.2 If you do not want to receive direct marketing offers from us, please contact us using the contact details below, use the opt-out facility provided to you (click “Unsubscribe” in any marketing email or reply “STOP” to SMS messages), or manage preferences in your account settings.
11.3 For email and SMS marketing, we require your explicit opt-in consent. We do not send marketing to those who have not consented, use pre-ticked consent boxes, or continue marketing after you unsubscribe.
11.4 We will continue to send mandatory communications including transaction confirmations, critical security alerts, regulatory required notifications, and account status updates regardless of marketing preferences.
12. Notifiable Data Breaches
12.1 liquid is subject to the Notifiable Data Breaches (NDB) scheme under the Australian Privacy Act and will act in accordance with the requirements of the NDB Scheme and the guidance of the Office of the Australian Information Commissioner (OAIC) in assessing and responding to suspected notifiable data breaches.
12.2 Where a breach of personal information occurs that is likely to cause serious harm to individuals, liquid will:
-
contain the breach and perform a preliminary assessment as soon as practicable;
-
assess the risks associated with the incident in accordance with the Notifiable Data Breaches scheme;
-
notify the OAIC and affected individuals as soon as practicable where notification is required;
-
advise affected individuals of recommended protective steps; and
-
take steps to prevent future breaches.
12.3 Notification will include what information was involved, when the breach occurred, what we are doing to respond, steps you should take, and contact details for further information.
12.4 If you believe that any personal information liquid holds about you has been impacted by a data breach, you can contact liquid using the contact details below.
13. Cookies
13.1 liquid may use cookies, web beacons, and measurement software on the Website and the Services to:
-
maintain your login session and remember your preferences;
-
analyse Website traffic, trends, and reporting statistics to improve the Website and Services;
-
detect fraudulent activity and enhance security;
-
provide you with targeted marketing communications; and
-
provide you with relevant advertisements when you visit the Website.
13.2 Cookie types include: Essential/Functional cookies (session maintenance, login, security; session or 12 months duration; cannot be disabled); Analytics cookies (Google Analytics, usage tracking; 24 months duration; can be disabled in privacy settings); Marketing/Advertising cookies (retargeting, audience analysis; 12 months duration; can be disabled in privacy settings).
13.3 You may reject or delete the use of cookies through the settings on your browser or mobile settings.
13.4 If your browser has “Do Not Track” enabled, we will respect your preference where technically feasible, continue to collect essential analytics for fraud detection and security, and allow you to opt-out of non-essential tracking.
14. Third-Party Sites
14.1 The Website may from time to time have links to other websites not owned or controlled by liquid, including payment provider websites, liquidity provider platforms, DeFi protocol interfaces, external educational resources, and social media profiles.
14.2 These links are meant for your convenience only. Links to third party websites do not constitute sponsorship or endorsement or approval of these websites.
14.3 Please be aware that liquid is not responsible for the privacy practices of other such websites.
14.4 We encourage our users to be aware, when they leave our website, to read the privacy statements of each and every website that collects personal identifiable information.
15. Children and Minors
15.1 liquid services are not intended for children under eighteen (18) years old.
15.2 We do not knowingly collect information from minors. If we become aware that a minor has provided information without parental consent, we will delete such information, notify the minor and guardian, and cease services to the minor.
15.3 If you believe we have collected information from a minor, please contact legal@liquid.net.au immediately.
16. Complaints
16.1 As a valued customer, if you have any complaints in relation to this Privacy Policy or our privacy practices, please feel free to contact liquid using the contact details below.
16.2 A complaint should identify whether it is about: the collection of personal information; the use of personal information; the disclosure of personal information; the security or storage of personal information; the accuracy of personal information; a refusal to give access to or provide information about their personal information; or a refusal to change or delete personal information.
16.3 liquid values your opinions and takes complaints very seriously. Upon receiving written notice of your complaint about privacy, liquid will respond in a timely manner (within ten business days) to advise you of the outcome following any related enquiry.
16.4 You will also be invited to respond to its outcome. If a response is received, liquid will assess your response and advise if it has changed its view.
16.5 If you are unsatisfied with the final outcome, liquid will advise further options including, if appropriate, making a complaint with the Office of the Australian Information Commissioner (OAIC). Website: www.oaic.gov.au; Phone: 1300 363 992; Mail: GPO Box 5218, Sydney NSW 2001.
17. Variation to this Privacy Policy
17.1 liquid reserves the right to modify or amend this Privacy Policy at any time, for any reason, by posting a revised version on its website.
17.2 For major changes affecting you, we will provide thirty (30) days’ notice, notify you via email or account notification, and seek re-consent if legally required.
17.3 Any changes to this Privacy Policy will become effective when liquid posts the revised Privacy Policy on the website. Your use of the Services following these changes means that you accept the revised Privacy Policy.
18. Contact
18.1 Please contact liquid if you have any questions regarding this Privacy Policy.
Privacy inquiries:
Email: legal@liquid.net.au
Response Time: Within ten (10) business days
Regulatory complaints:
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Mail: GPO Box 5218, Sydney NSW 2001
END OF PRIVACY POLICY
This Privacy Policy is current as of July 2026.
The most current version is always available at www.liquid.net.au