PRIVACY POLICY
Byte and Bite Innovations Pty Ltd.
Version 2.0
PRIVACY POLICY
Byte and Bite Innovations Pty Ltd. (ACN 699477766) trading as Byte and Bite Innovations (Split-it, we, us or our) respects your privacy. This Privacy Policy explains how we collect, hold, use and disclose your Personal Information in connection with the Split-it mobile application and our related services (the App) and our website at thesplitit.com (the Website).
This Privacy Policy is governed by the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles set out in the Privacy Act (APPs). By using the App or the Website, you consent to the collection, use and disclosure of your Personal Information as described in this Privacy Policy.
1. Information We Collect
We collect the following kinds of Personal Information about you. The exact information we hold about you depends on how you use the App and Website and the choices you make about device permissions.
1.1 Personal Information You Provide
When you create or use a Split-it account we collect Personal Information that you give us directly, including:
- (a)Account information: your name (or chosen display name), mobile phone number, profile photo (if you choose to upload one), and any other information you choose to add to your profile;
- (b)PayID: where you choose to enter a PayID into the App, the mobile number or email address you have registered with your Australian financial institution under the NPP PayID service. Entering a PayID is optional. We explain in section 3 how your PayID is stored, displayed and used;
- (c)Expense information: the details of expenses you enter into the App, including the amount, currency, payee description, category, date, allocation between participants, free-text notes you choose to add, and any settlement or payment status you record. We treat free-text notes as Personal Information of both you and any other user mentioned in them;
- (d)Group and friend information: the names and identifiers of other Split-it users you have added as friends or with whom you share an expense, and the structure of any group you have created in the App;
- (e)Contacts you choose to share: where you have given the App permission to access the contacts on your device, the names and contact details of people in your address book. We use this information only to suggest friends in the App, as described in section 1.4;
- (f)Communications: the content of any communication you send to us, including support requests, feedback, survey responses and any attachments you choose to provide;
- (g)Identity verification information: where we need to verify your identity (for example, in response to a security incident, a regulator request or a dispute), any government-issued identification, selfie, proof of address or other verification information you provide. We collect this only where it is necessary and we limit who within Split-it can access it; and
- (h)Job application information: if you apply to work with Split-it, your CV, cover letter and any other information you choose to provide in connection with your application. We use this only for recruitment purposes.
1.2 Information We Collect From Your Device
When you use the App or the Website, we automatically collect certain information from your device, including:
- (a)Device identifiers: hardware identifiers such as the Identifier for Vendors on iOS or an equivalent identifier on Android, the device model, the operating system and version, the App version and build number, the device language and locale, and the time zone set on your device;
- (b)IP address and approximate location: the IP address from which you connect to the App or the Website. We derive an approximate location (typically at the city or region level) from your IP address. We do not collect your precise GPS location;
- (c)Network information: the type of network connection you are using (Wi-Fi or mobile) and, where you have allowed it, the mobile country code and network operator;
- (d)Push notification token: a token issued by Apple or Google that allows us to send notifications to your device;
- (e)Usage data: information about how you interact with the App and the Website, including the screens you view, the features you use, the categories of expense you log, the frequency and timing of your sessions, and the buttons, links and notifications you tap;
- (f)Performance and crash data: diagnostic information collected when the App crashes or encounters an error, which may include partial logs, stack traces and a snapshot of relevant device state. We use this information to fix defects and improve the App; and
- (g)Referrer information: where you reach the App or the Website through a link, the source of that link (for example, a referral code shared by another user).
1.3 Information from Cookies and Similar Technologies
We use cookies and similar technologies (such as software development kits, pixels and local storage) on the Website and within the App. The categories we use are:
- (a)Strictly necessary: required for the Website and App to function (for example, to authenticate you, remember your session and protect against fraud). We do not need your consent for these.
- (b)Performance and analytics: help us understand how users interact with the App and the Website so that we can fix problems and improve features. These are anonymised wherever practicable.
- (c)Functional: remember the choices you have made (for example, your language or notification preferences).
- (d)Marketing: only used with your express consent. We do not use third-party advertising cookies on the Website or in the App.
You can control cookies through your browser settings and, on mobile, through the device-level tracking controls offered by Apple and Google. Blocking strictly necessary cookies may prevent the App or Website from working properly.
1.4 App Permissions
The App may ask for permissions on your device. You can grant or deny these permissions and change your choice at any time through your device settings. The permissions we use, and the purposes for which we use them, are:
- (a)Push notifications: to deliver transactional notifications about your account and your expenses and, where you have consented, marketing notifications. You can disable some notification categories within the App while keeping others enabled;
- (b)Contacts: to suggest friends from your address book. If you grant contacts permission, the App accesses the names and contact details in your address book to find people who already use Split-it. You can decline contacts access at no impact to the core functionality of the App;
- (c)Camera (where offered): to scan a receipt or QR code that you choose to attach to an expense. We process the image to extract information you ask us to extract and we discard the original where you have not chosen to keep it; and
- (d)Photo library (where offered): to attach photos to expenses or to upload a profile photo.
We do not ask for permissions we do not need. We do not collect any information from a device permission unless and until you grant the permission.
1.5 Information from Linked Sign-in Services
If you choose to sign in to Split-it using Apple, Google or another linked sign-in service we may offer, we receive limited information from that provider, typically your name and the email address you have chosen to share with us. Some providers (for example, Apple) allow you to share a relay email address rather than your real one. We do not receive your password from a linked sign-in provider, and we do not receive payment details from those providers. You can disconnect a linked sign-in at any time through your account settings.
1.6 Sensitive Information
We do not seek to collect sensitive information (as defined in the Privacy Act, which includes information about your health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and biometric information) from you. Please do not include sensitive information in expense descriptions, notes, communications with us or other content you enter into the App. If you do include sensitive information, you consent to us handling it consistently with this Privacy Policy.
2. How We Collect Your Information
We collect Personal Information about you in three main ways:
2.1 Directly from you
Most Personal Information we hold about you is information you give us directly. This happens when you:
- (a)create or update your Split-it account or profile;
- (b)add or edit an expense, balance, payment, friend or group;
- (c)enter a PayID into the App;
- (d)contact us by email, web form or any in-App support feature;
- (e)respond to a survey, fill in a form, or participate in user research; or
- (f)apply for a position with us.
2.2 Automatically through your use of the App and Website
We collect some information automatically when you use the App or the Website. The categories of information we collect automatically are described in section 1.2 (Information We Collect From Your Device) and section 1.3 (Information from Cookies and Similar Technologies).
2.3 From third parties
We may collect Personal Information about you from third parties, including:
- (a)linked sign-in providers (where you choose to sign in using Apple, Google or another linked service);
- (b)identity verification providers (where we engage one to confirm your identity);
- (c)payment service providers (where we have integrated one to allow you to send or receive payments through the App);
- (d)analytics, crash reporting and security providers (within the scope they collect data on our behalf);
- (e)other Split-it users (where they include you in an expense, add you as a friend or send us a complaint about you); and
- (f)publicly available sources (rarely, and only where it is reasonable and necessary to do so).
3. Why We Collect, Hold, Use and Disclose Your Information
We collect, hold, use and disclose your Personal Information only where there is a legitimate reason for doing so. This section sets out our purposes, the legal bases on which we rely, our approach to automated decision-making and our approach to anonymised data.
3.1 Purposes for which we collect and use your Personal Information
We collect, hold, use and disclose your Personal Information for the following purposes:
- (a)Providing the App and your account: to register your account, authenticate you, allow you to log and split expenses with friends, calculate balances, deliver transactional notifications and (where you have entered a PayID) display your PayID to the friends you have added in the App;
- (b)Operating the PayID feature: where you have entered a PayID into the App, to store it securely, to display it to other users you have added as friends so that they can use it to pay you directly outside the App, and to take it down where you remove it or close your account. We do not display your PayID to any user who is not your friend. We do not transmit your PayID to any third party except to the extent necessary to operate the App (for example, to our hosting and infrastructure providers);
- (c)Sending notifications and marketing communications: to send you transactional notifications about your account and your use of the App and, where you have given us your express consent (or where we may rely on inferred consent under the Spam Act and APP 7), to send you marketing communications about Split-it including product updates, tips and re-engagement nudges sent to users who have not opened the App for a period set by us. We treat re-engagement push notifications as marketing unless they relate to a specific account event;
- (d)Showing you Affiliate Offers: to decide which Affiliate Offers to display to you within the App, based on the categories of expense you have logged (for example, “dining” or “groceries”). We do not use the content of free-text descriptions or notes, individually identifying details of any payment, or any sensitive information to target an Affiliate Offer. You can opt out of personalised Affiliate Offers through your in-app settings;
- (e)Running our Referral Program: to verify that a referral meets the eligibility conditions, to deliver any reward, to prevent fraud or abuse of the program and to keep adequate records of rewards issued;
- (f)Providing customer support: to respond to your enquiries, troubleshoot problems, investigate complaints and improve our support offering;
- (g)Improving the App and the Website: to monitor and analyse use, identify defects and improvements and develop new features. Wherever practicable we use anonymised or aggregated data for this purpose, as explained in section 3.4;
- (h)Maintaining safety, security and integrity: to protect the security of the App, our users and our systems, to detect and prevent fraud, account take-over and abuse, to enforce these Terms and our Privacy Policy and to investigate complaints or potential breaches of law;
- (i)Meeting our legal obligations: to comply with our obligations under Australian law (including the Privacy Act, the Spam Act, the Australian Consumer Law, tax law and any direction from an Australian regulator or court);
- (j)Recruitment: to assess your suitability for any position you have applied for with us, communicate with you about your application and (where you consent) keep your information on file for future opportunities;
- (k)Corporate planning and transactions: to plan our business, including in the context of a sale, merger, restructure or capital raising, and (specifically) in the context of the transition of the Split-it business from a sole trader operation to a Pty Ltd company; and
- (l)Any other purpose with your consent or as required by law: for any other purpose you have specifically consented to or for which we are otherwise permitted under the Privacy Act.
3.2 Legal bases on which we collect and use your Personal Information
Our principal legal basis for handling your Personal Information is the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Specifically:
- (a)we collect Personal Information that is reasonably necessary for our functions or activities (APP 3);
- (b)we use and disclose Personal Information for the primary purpose for which it was collected, or for a secondary purpose where you would reasonably expect it, where you have consented, or where another APP 6 exception applies;
- (c)we send you direct marketing communications only where we are permitted to do so under APP 7, the Spam Act and the Do Not Call Register Act, and we always provide a simple opt-out;
- (d)we disclose Personal Information overseas only in accordance with APP 8 and section 5 of this Privacy Policy; and
- (e)we take reasonable steps to protect Personal Information consistently with APP 11.
3.3 Automated decision-making and profiling
We use automated processing for limited purposes within the App, including:
- (a)selecting Affiliate Offers to display to you based on the categories of expense you have logged;
- (b)detecting suspicious activity, such as multiple accounts created from the same device, automated abuse, fraudulent referrals or unusual patterns of use; and
- (c)deciding when to send re-engagement notifications based on whether you have opened the App in a defined period.
We do not make decisions about you that produce legal or similarly significant effects on a fully automated basis. A human reviews any decision to suspend, terminate or restrict your account, except in cases of immediate risk to other users or to Split-it. You can opt out of personalised Affiliate Offers through your in-app settings.
3.4 Anonymous and aggregated data
We may anonymise or aggregate Personal Information so that it can no longer reasonably be used to identify you. We use and disclose anonymised and aggregated data for any lawful purpose, including:
- (a)producing usage statistics and trend reports about the App and the Website;
- (b)benchmarking, research and development;
- (c)public reporting (for example, in a blog post or marketing material about the App); and
- (d)sharing insights with affiliate partners, without identifying any individual user or any identifiable group.
Once data is anonymised it is no longer Personal Information under the Privacy Act. We apply current techniques to make re-identification impractical, we do not attempt to re-identify de-identified data and we require any party to whom we disclose de-identified data to agree to the same.
4. Disclosure of Your Information
We disclose your Personal Information only as described in this section. We do not sell your Personal Information.
4.1 Categories of recipient
We may disclose your Personal Information to the following categories of recipient:
- (a)Other users of the App: where you choose to display your PayID, where you include another user in an expense, where you accept a friend request, or where another feature of the App displays your information to a specific other user, we will disclose to that user the relevant information (for example, your name, your PayID and the details of the expense you share with them). Each such user is a separate person under the Privacy Act and is responsible for their own handling of your information after disclosure. We are not responsible for what another user does with your information after it has been disclosed to them, but you can direct any complaint to us in the first instance and we will assist where reasonably practicable;
- (b)Service providers: we use trusted service providers to operate the App and the Website, including cloud hosting providers, infrastructure providers (database, application and content delivery), analytics providers, customer support tools, communications and email providers, push notification gateways, identity verification providers, fraud detection and security providers and, if and when we integrate them, payment service providers such as Stripe Payments Australia Pty Ltd or Square AU Pty Ltd. We disclose only the Personal Information that is necessary for the provider to perform its function. We require each provider to handle your Personal Information consistently with this Privacy Policy, with the Privacy Act and with our written instructions;
- (c)Affiliate partners and gift card issuers: where you click on an Affiliate Offer or where we deliver a reward to you under the Referral Program, we may share limited information with the relevant third party so that the offer or reward can be fulfilled. We do not share expense data, PayID, friend lists or sensitive information with affiliate partners or gift card issuers;
- (d)Professional advisers: our lawyers, accountants, auditors, tax advisers and insurers, where reasonably necessary for them to perform their role;
- (e)Corporate transactions: in connection with a sale, merger, acquisition, restructure, reorganisation or financing of our business, including the transition of our business from a sole trader operation to a Pty Ltd company. Where we transfer Personal Information in this context, we take reasonable steps to ensure that the recipient is bound to handle it consistently with the Privacy Act, and we will tell you about any material change in the way we handle your Personal Information that results from the transaction;
- (f)Regulators and authorities: as described in section 4.2 below; and
- (g)With your consent: to any other party where you have given us your consent.
4.2 Government and law enforcement requests
From time to time, we may receive requests from Australian or overseas government, law enforcement or regulatory authorities for Personal Information about our users. We will only disclose your Personal Information in response to a request that:
- (a)we are required by law to comply with (for example, a subpoena, court order, notice to produce, notice issued under the Privacy Act, Telecommunications (Interception and Access) Act, Surveillance Devices Act or any equivalent law); or
- (b)we reasonably consider necessary to protect life, prevent serious crime, or protect our rights or the rights of others.
We will scrutinise any request we receive and we will not disclose more than is required. We will not disclose your Personal Information to an overseas authority unless the request comes through an appropriate Australian authority or we are required to do so by law. Where we are not legally restricted from doing so (for example, where the request is the subject of a non-disclosure order), we will tell you about the request and give you an opportunity to seek your own legal advice before we respond.
5. Overseas Disclosure
Some of our service providers are based, or store data, outside Australia. The countries to which we may disclose your Personal Information include (without limitation):
- (a)the United States, including for cloud hosting, customer support tooling, communications, analytics and crash reporting;
- (b)the European Union and the United Kingdom, for cloud hosting and security services;
- (c)Canada, India, the Philippines and other countries from which our service providers operate; and
- (d)any other country into which a service provider we engage may transfer data, where that transfer is necessary to operate the App.
When we disclose your Personal Information overseas, we take reasonable steps to ensure that the overseas recipient handles it consistently with the APPs. The steps we take include:
- (e)using contractual arrangements that require the recipient to protect the Personal Information in a way that is consistent with the APPs;
- (f)selecting providers that operate under privacy laws substantially similar to the APPs, where reasonably practicable;
- (g)disclosing only the minimum Personal Information necessary for the provider to perform its function; and
- (h)encrypting Personal Information in transit and at rest, wherever practicable.
You acknowledge that, by using the App, you agree that we may disclose your Personal Information overseas in accordance with this Privacy Policy. By giving this consent you understand that APP 8.1 does not apply to those disclosures, and that we will not be obliged under the Privacy Act to ensure that the overseas recipient does not breach the APPs in respect of your Personal Information. We will still take the reasonable steps described above. If you do not wish to give this consent, please do not use the App.
6. Data Security
6.1 Security measures
We take reasonable steps to protect your Personal Information from misuse, interference, loss, unauthorised access, modification and disclosure. The measures we apply include:
- (a)encryption of data in transit (using TLS) and at rest, where appropriate;
- (b)access controls and the principle of least privilege within our systems, so that only the people who need access to a category of Personal Information for their role have it;
- (c)multi-factor authentication for administrative access to our systems;
- (d)logging and monitoring of access to and use of Personal Information;
- (e)separation of production and non-production environments and limits on the use of production Personal Information in non-production environments;
- (f)vulnerability scanning, patching and (where appropriate) third-party security reviews;
- (g)training of our staff and contractors on privacy and security obligations;
- (h)written agreements with our service providers that require them to apply equivalent protections; and
- (i)incident response procedures that are tested periodically.
Despite these measures, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You also have a role to play. We strongly recommend that you choose a strong password, do not reuse a password you use on any other service, keep your device secure and enable any in-App security features we offer (including biometric or device-level passcodes).
6.2 Notifiable data breaches
We comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If we become aware of unauthorised access to or disclosure of your Personal Information that is likely to result in serious harm to you or to another individual, we will:
- (a)take immediate steps to contain the breach and limit further harm;
- (b)assess the breach in accordance with our internal incident response procedures;
- (c)notify the Office of the Australian Information Commissioner (OAIC) and you, in accordance with the Notifiable Data Breaches scheme, within the period required by the Privacy Act;
- (d)tell you the kinds of Personal Information involved, the circumstances of the breach and the steps you can take to protect yourself; and
- (e)cooperate with the OAIC in any review.
Where we are legally restricted from notifying you (for example, where the breach is the subject of an active law enforcement investigation), we will tell you as soon as those restrictions allow.
7. Data Retention
We retain your Personal Information for only as long as we need it for the purposes set out in section 3, including to comply with our legal obligations, resolve disputes and enforce our agreements. The retention periods we apply to each category of Personal Information are as follows:
- (a)Account information: while your account is active, and for up to 12 months after your account is deactivated or deleted (to allow you to recover an account you have deactivated by mistake). After that period we delete or de-identify your account information, except as required by law;
- (b)Expense data, balances and payment status: while your account is active, and for up to 12 months after your account is deactivated or deleted, except where we are required to retain a record for tax, audit or other legal purposes;
- (c)PayID: until you remove it from your profile, or until your account is deactivated or deleted, whichever is sooner;
- (d)Identity verification records: up to 7 years from collection, where required to comply with anti-money-laundering, tax or other legal obligations, and otherwise for the shortest period necessary;
- (e)Marketing consent records: while your consent is current, and for 12 months after withdrawal (so that we can evidence your withdrawal if needed);
- (f)Support and complaint correspondence: 24 months from resolution, or longer where reasonably necessary to investigate a recurring issue or comply with a legal obligation;
- (g)Server logs and security records: 12 months;
- (h)Crash and diagnostic data: up to 90 days from collection, unless we need to retain it longer to investigate a specific incident;
- (i)Backup copies: in accordance with our backup rotation, typically no more than 35 days for active backups before the older copy is overwritten; and
- (j)Anonymised and aggregated data: indefinitely, because that data is no longer Personal Information.
Where we are required by law to retain Personal Information for longer than the periods set out above (for example, under taxation, audit, anti-money-laundering or financial services laws), we will retain it for that longer period and then delete or de-identify it. Where we no longer have a lawful basis to retain Personal Information, we take reasonable steps to destroy or de-identify it.
8. Your Rights
You have a number of rights in relation to the Personal Information we hold about you. This section explains how to exercise them. To make a request under this section, please contact our Privacy Officer using the details in section 11.
8.1 Access
Subject to the exceptions in the Privacy Act, you have a right to access the Personal Information we hold about you. To request access, please contact our Privacy Officer using the details in section 11. We will respond to your request within 30 days of receiving it (or, where the request is complex, within 60 days, in which case we will tell you why we need extra time).
Before providing access, we may need to verify your identity, which may include asking you to confirm details we already hold about you. There is no fee for a standard access request. Where access would impose a significant cost on us (for example, complex retrieval from archive), we may charge a reasonable fee, but we will tell you about the fee before we incur it. If we refuse access in whole or in part because the request falls within an exception in the Privacy Act, we will tell you in writing why, and explain the avenues available to make a complaint.
8.2 Correction
You have a right to ask us to correct Personal Information we hold about you if it is inaccurate, out of date, incomplete, irrelevant or misleading. You can update some information by contacting Split-it support at support@thesplitit.com.
For other information, contact us at: support@thesplitit.com. We will assess your correction request within 30 days and make the correction if we agree it is needed. If we disagree, we will tell you why in writing. You can ask us to associate a statement with your record noting that you consider the information to be inaccurate, out of date, incomplete, irrelevant or misleading, and we will take reasonable steps to do so.
8.3 Deletion and deactivation
You may request that we delete your Personal Information at any time, or you may deactivate your account through the in-App settings (More > Account Settings > Delete Account). We will action your request within 30 days. When we delete your account:
- (a)we anonymise your profile information so that it no longer identifies you;
- (b)your expense records remain visible to other users who participated in the expense, but your details on those records are replaced with a non-identifying placeholder;
- (c)we delete or de-identify your other Personal Information except where we are required by law to retain it (in which case we will retain only what we need to, for only as long as we need to);
- (d)your PayID is removed from our systems within a reasonable period (typically immediately, and in any event within 7 days); and
- (e)we may retain a record of the deletion request and the steps we took, for our own audit and compliance purposes.
Note that deletion is not always possible. Where we are required by law to retain certain Personal Information (for example, under tax law or in response to a regulator request), we will tell you and explain why.
8.4 Marketing
You can withdraw your consent to marketing communications at any time. You may do so by disabling marketing notifications in your in-app settings, using the unsubscribe link in any marketing email, replying STOP (or as otherwise indicated in the message) to a marketing SMS, or contacting us using the details below. We will action any opt-out request within the period required by the Spam Act 2003 (Cth), which is currently five business days. Even if you opt out of marketing communications, we may continue to send you transactional notifications relating to your account and your use of the App.
8.5 Withdrawing consent
Where we rely on your consent to handle your Personal Information for a particular purpose, you can withdraw that consent at any time by contacting our Privacy Officer or by using the in-App settings (where available). Withdrawing consent does not affect the lawfulness of anything we have done with your Personal Information on the basis of your consent before withdrawal. If withdrawing your consent means we can no longer provide a particular feature of the App to you, we will tell you and explain your options.
8.6 Complaints
If you have a concern or complaint about how we have handled your Personal Information, please contact our Privacy Officer using the details in section 11. We will acknowledge your complaint within 7 days, investigate it and respond to you within 30 days (or, where the complaint is complex, within 60 days, in which case we will tell you why we need extra time). Our response will explain the outcome of our investigation and any action we have taken. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
GPO Box 5288, Sydney NSW 2001
Phone: 1300 363 992
Website: https://www.oaic.gov.au
9. Children
The App is intended for use by individuals aged 18 years or older. The App is not directed to, and we do not knowingly collect Personal Information from, anyone under 18.
If we become aware that an account has been created or used by a person under 18, we will:
- (a)close the account;
- (b)delete or de-identify the Personal Information we hold about the account holder, except where we are required by law to retain it;
- (c)notify the eSafety Commissioner or other relevant authority where required to do so under the Online Safety Act 2021 (Cth) or any other applicable law; and
- (d)cooperate with any parent, guardian or authority who contacts us about the account.
If you are a parent or guardian and you believe a person under 18 has provided us with Personal Information, please contact us using the details in section 11 so that we can take appropriate action.
10. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time. We will give you reasonable notice of any material change, including by posting the updated Privacy Policy on the Website and updating the “Effective date” below. Your continued use of the App or Website after the effective date of the updated Privacy Policy constitutes your acceptance of the updated Privacy Policy.
11. Contact Us
If you have any questions, concerns or requests in relation to this Privacy Policy, please contact our Privacy Officer at:
Email: support@thesplitit.com
Postal address: 603 St Kilda Road, Melbourne, VIC 3004
Last updated: 24 July 2026.