Effective Date: 20th December 2025
Last Updated: 16th July 2026
This Global Privacy Policy explains how IGC Marketing, trading as IGC Loyalty, together with its related entities, authorised licensees and service operators where applicable (“IGC”, “we”, “us” or “our”), collects, uses, stores, protects, discloses and otherwise processes personal information.
This Privacy Policy applies to:
the IGC Loyalty mobile application and any white-label or licensed version of it;
the IGC Loyalty website and related websites;
the IGC Loyalty administrative dashboard, affiliate dashboard, merchant portal and campaign-management systems;
augmented-reality, location-based, navigation-assistance, loyalty, promotional, marketplace and point-exchange functions;
customer service, marketing, demonstrations, testing and business communications; and
any related products, platforms, application programming interfaces, software development kits or services that link to this Privacy Policy.
Together, these are referred to as the “Services”.
By accessing or using the Services, you acknowledge that you have read this Privacy Policy. Where consent is required by law, we will request it separately and you may withdraw it as described below.
This Privacy Policy does not override any mandatory privacy rights available under applicable law.
Unless another entity is identified when your information is collected, the controller, business or responsible organisation for your personal information is:
[IGC Marketing Pty Ltd]
Trading name: IGC Loyalty
Country of registration: Australia
General contact: Via our website IGCloyalty.com
Some campaigns may be offered for, or jointly operated with, a retailer, shopping centre, tourism body, government authority, museum, event operator, franchise, advertiser, licensee, distributor or other organisation.
Depending on the campaign and applicable law:
IGC may act as the independent controller of information relating to accounts, application security, platform administration and general service operation;
IGC and the campaign operator may act as separate or joint controllers for campaign information; or
IGC may process information on behalf of the campaign operator as its service provider or processor.
The relevant campaign notice, sign-up page or collection notice may identify additional responsible organisations.
The information collected depends on how you use the Services, your device settings, the permissions you grant and the campaign in which you participate.
We may collect:
name, username, account identifier and avatar;
email address, telephone number and country;
date of birth or age-range confirmation where necessary;
password or encrypted authentication credentials;
promotional, affiliate, referral or invitation codes;
language and communication preferences;
account status, login history and verification information; and
information supplied through Google, Apple or another authorised login provider.
We do not receive your full password from an external login provider.
Because the Services may provide location-based campaigns, clues, rewards, augmented-reality experiences or navigation assistance, we may collect or infer:
precise or approximate GPS location;
latitude, longitude and altitude;
indoor or outdoor location estimates;
proximity to campaign locations, participating premises, points of interest or safety zones;
movement direction, speed, route progress and arrival status;
entry into or departure from a geofenced area;
floor or building-level estimates;
location timestamps and location accuracy measurements; and
location permission and service status.
Location information may be collected while the application is open. Background location will only be collected where the feature requires it, the operating system permits it and the user has granted the relevant permission.
Location technologies are not perfectly accurate. Location readings may be delayed, incorrect, incomplete or affected by buildings, weather, device quality, network conditions, interference, calibration or other environmental factors.
Where enabled and supported, we may process information from:
accelerometers;
gyroscopes;
magnetometers and digital compasses;
barometers and atmospheric-pressure sensors;
pedometers and step counters;
orientation and heading sensors;
Bluetooth or nearby-device status;
camera and augmented-reality functions;
device motion and movement classifications;
network, Wi-Fi and connectivity information; and
other device sensors reasonably required to provide a requested feature.
Sensor information may be used to estimate direction, movement, floor changes, stairs, lifts, escalators, indoor position or route progress. It may be inaccurate and must not be treated as guaranteed navigation or safety information.
Where you grant camera access, the application may use the camera to:
display augmented-reality objects or promotional content;
scan QR codes, signs, campaign markers or objects;
recognise text or environmental anchors;
validate participation in a campaign;
support positioning or route correction; and
allow you to upload an image or profile picture.
Camera frames used for local augmented-reality functions may be processed temporarily on the device and may not be transmitted to us unless required for a feature, submitted by you, needed for fraud prevention or clearly disclosed at the point of collection.
You must not intentionally capture or upload another person’s image, private information, identification document or confidential material without lawful authority.
We may collect:
points collected, transferred, redeemed, cancelled or expired;
digital items, rewards, vouchers and promotional codes;
campaign participation and completion records;
reward eligibility and prize information;
marketplace activity;
merchant and redemption records;
purchase, refund and chargeback status;
wallet identifiers or transaction references; and
anti-fraud and verification records.
Payment card details are normally processed by the relevant payment provider. We may receive a limited transaction record, such as payment status, amount, currency, payment reference and partial card information.
We may automatically collect:
IP address;
device identifiers and advertising identifiers where permitted;
device model, manufacturer and operating system;
application version and language;
browser type;
session, screen-view and feature-interaction information;
referral source;
crash reports, diagnostic logs and performance information;
timestamps and authentication events;
cookie and similar-technology information;
security, fraud and abuse indicators; and
aggregated or statistical activity information.
For merchants, administrators, affiliates, licensees, agencies, campaign managers and other dashboard users, we may collect:
business name, role and job title;
business email address and telephone number;
account permissions and access level;
organisation, branch, campaign or territory assignment;
campaign settings, locations, clues, media and reward rules;
affiliate and commission information;
payment and tax information where required;
dashboard access and audit logs;
support communications and instructions;
documents submitted for business verification; and
actions taken within the dashboard.
We may collect information you send through:
email;
in-app support;
website forms;
surveys;
social media;
telephone calls;
demonstrations, meetings and trade events; and
complaints, privacy requests or dispute processes.
Calls or demonstrations may only be recorded where lawful and appropriate notice is provided.
We may receive information from:
login providers;
campaign partners and participating merchants;
payment providers;
analytics and advertising providers;
application stores;
fraud-prevention and cybersecurity providers;
affiliates and referral partners;
business customers and licensees;
public databases; and
government or law-enforcement authorities where lawful.
A business customer must have a lawful basis and all required permissions before entering, uploading or disclosing personal information through the dashboard.
We do not intentionally request health, biometric, racial, religious, political, sexual-orientation, criminal-record or other legally sensitive information unless:
it is strictly necessary for a disclosed feature;
collection is lawful;
appropriate consent or another lawful basis has been established; and
enhanced safeguards are applied.
Users and dashboard operators must not upload sensitive information unless expressly authorised by IGC and legally permitted.
We may use personal information to:
create, authenticate and administer accounts;
provide location-based, augmented-reality and loyalty functions;
display nearby clues, offers, campaigns, rewards and participating locations;
estimate route progress, heading, floor level and proximity;
process points, rewards, vouchers, referrals and redemptions;
operate marketplace and promotional functions;
personalise language, content and application settings;
provide customer and technical support;
communicate service, account, security and campaign information;
administer competitions, promotions and reward eligibility;
manage merchants, dashboard users, affiliates, campaigns and permissions;
process payments, commissions, refunds and financial reconciliation;
maintain audit trails and business records;
analyse performance, usage and campaign effectiveness;
identify faults and improve accuracy, reliability and usability;
protect users, businesses, IGC and the public from fraud, abuse, cheating, spoofing, bots and unauthorised access;
enforce our Terms and Conditions and other agreements;
investigate suspected misconduct, complaints or security incidents;
comply with laws, court orders and lawful government requests;
establish, exercise or defend legal claims;
complete corporate transactions, audits, insurance or due diligence; and
perform other purposes disclosed when the information is collected.
We may combine information collected through different parts of the Services where lawful and reasonably necessary for these purposes.
The Services may process location and sensor information to support navigation assistance, augmented-reality experiences, geofencing, floor estimation, rewards and safety-related notifications.
However:
the Services are not an emergency service;
the Services are not a certified navigation, evacuation, traffic, aviation, maritime, medical or personal-safety system;
location, direction, floor and hazard information may be inaccurate, delayed, unavailable or incomplete;
a warning not appearing does not mean that an area is safe;
a warning appearing does not mean that the danger has been independently verified; and
users must remain aware of roads, vehicles, water, cliffs, stairs, escalators, lifts, platforms, balconies, windows, glass doors, glass barriers, construction, private property, restricted areas and all other surrounding conditions.
Location and sensor information may be retained where reasonably necessary to validate rewards, prevent fraud, investigate an incident, analyse application accuracy or maintain legal records.
Where feasible, analytics are aggregated, de-identified, truncated or otherwise reduced.
Where applicable law requires us to identify a legal basis, we rely on one or more of the following:
Processing may be necessary to provide the Services, administer an account, process rewards, fulfil campaign rules or perform an agreement with a user or business customer.
We may rely on consent for precise location, background location, camera access, certain communications, advertising technologies, sensitive information or other activities where consent is legally required.
Consent may be withdrawn through device settings, account settings or by contacting us. Withdrawal does not affect processing already lawfully performed.
We may process information for legitimate interests including:
operating and improving the Services;
protecting accounts and systems;
preventing fraud, cheating and misuse;
understanding campaign performance;
communicating with business customers;
maintaining records;
enforcing agreements; and
protecting legal rights.
We balance these interests against the rights and reasonable expectations of affected individuals.
We may process information to comply with taxation, accounting, consumer, privacy, anti-fraud, sanctions, court, regulatory and law-enforcement obligations.
In limited circumstances, information may be processed or disclosed to protect a person’s life, health or physical safety, or for another substantial public interest permitted by law.
Depending on the device and feature, the Services may request permission to access:
precise or approximate location;
background location;
camera;
motion, activity and fitness information;
notifications;
photos or stored files;
Bluetooth or nearby devices; and
microphone, only where a voice-enabled feature requires it.
You may manage permissions through your device settings. Refusing or withdrawing a permission may prevent the relevant feature from operating correctly.
Turning off a permission does not automatically delete information previously collected. A separate deletion request may be required.
Our websites, dashboard and Services may use cookies, software development kits, pixels, local storage, device identifiers and similar technologies to:
maintain sessions;
remember settings;
secure accounts;
diagnose faults;
measure usage and campaign performance;
prevent fraud;
deliver content; and
support advertising where legally permitted.
Where required, non-essential cookies and technologies will not be activated until consent is obtained.
You may manage available controls through the cookie banner, application settings, device settings or browser controls. Blocking some technologies may affect functionality.
We may use contact and usage information to send service updates, offers, campaign announcements or business communications where permitted.
You may unsubscribe from promotional email through the unsubscribe link or contact us. You may continue to receive essential service, security, transactional and legal communications.
We may work with advertising or measurement providers. Depending on applicable law and configuration, certain disclosures may be considered “targeted advertising”, “sharing” or a “sale” of personal information even where money is not exchanged.
Where required, we will provide a lawful opt-out mechanism, including a “Do Not Sell or Share My Personal Information” control.
IGC does not knowingly sell the personal information of children.
We may disclose personal information to:
cloud-hosting and infrastructure providers;
application-development, maintenance and testing providers;
mapping, geolocation, sensor, augmented-reality and navigation-technology providers;
authentication and communication providers;
analytics and crash-reporting providers;
payment processors and financial institutions;
cybersecurity and fraud-prevention providers;
customer-support providers;
professional advisers, auditors and insurers;
campaign operators, merchants and reward providers;
authorised licensees, distributors and affiliates;
government authorities, regulators, courts and law-enforcement agencies;
actual or potential purchasers, investors or transaction advisers; and
other parties authorised by you or permitted by law.
We require service providers to process information only for authorised purposes and to apply appropriate confidentiality and security safeguards, subject to applicable law and contractual arrangements.
Where you participate in a branded campaign, the responsible campaign partner may receive information reasonably required to:
validate participation;
issue or redeem rewards;
prevent fraud;
provide support;
measure campaign performance; or
satisfy legal and accounting requirements.
Campaign partners may have their own privacy policies and independent legal responsibilities.
Information you voluntarily publish through a public profile, leaderboard, social feature, shared campaign or public submission may be visible to other users or the public.
Do not publish information you wish to keep private.
Each business customer, licensee, merchant, affiliate administrator and dashboard user must:
access personal information only for authorised business purposes;
comply with privacy, marketing, employment and consumer laws;
maintain accurate user permissions;
protect login credentials;
immediately remove access when personnel no longer require it;
not export, copy, scrape, sell or misuse personal information;
provide all required collection notices and obtain required consents;
not upload information obtained unlawfully;
not use dashboard information to discriminate, harass, track or harm a person;
promptly report suspected unauthorised access or data loss;
follow IGC’s security and deletion instructions; and
ensure that all campaign content and data collection are lawful.
Business customers are independently responsible for their own collection, use, disclosure, retention and export of personal information unless a written agreement expressly states otherwise.
IGC may suspend dashboard access, preserve audit records and investigate suspected unauthorised use.
To protect the Services, users and campaign partners, we may detect and investigate:
falsified or spoofed GPS information;
automated bots or scripts;
emulator or modified-device activity;
repeated or impossible travel patterns;
account sharing;
reward manipulation;
unauthorised application modifications;
suspicious payment activity;
unauthorised dashboard access; and
attempts to bypass security controls.
We may use automated indicators to flag activity for restriction or review. Where required by law, users may request human review of a decision that produces a significant legal or similarly significant effect.
Fraud-prevention records may be retained after account closure where reasonably necessary to prevent repeat abuse, enforce legal rights or comply with law.
IGC may operate internationally. Personal information may be accessed, hosted or processed in countries other than the country in which it was collected.
Privacy laws in those countries may differ.
Where required, we will use appropriate safeguards, which may include:
adequacy decisions;
standard contractual clauses;
international data-transfer agreements or addenda;
contractual privacy and security obligations;
transfer-risk assessments;
encryption and access controls;
data localisation where mandatory; and
other approved legal transfer mechanisms.
By operating a dashboard or campaign across multiple countries, a business customer must ensure it has lawful authority for any international transfer it initiates.
We retain personal information only for as long as reasonably necessary for the relevant purpose, including:
providing an active account;
processing rewards and transactions;
maintaining campaign and financial records;
preventing fraud;
resolving disputes;
maintaining security and audit logs;
satisfying legal, tax, accounting and regulatory obligations; and
establishing, exercising or defending legal claims.
Retention periods may vary by data type, country and relationship.
Indicative retention periods may include:
Account information: while the account is active and for a reasonable period after closure;
Transaction and reward records: generally for the period required by financial, consumer and tax laws;
Security and access logs: for a reasonable security and investigation period;
Location and sensor data: for the shortest period reasonably necessary for functionality, validation, analytics, safety review or fraud prevention;
Support and legal correspondence: for the duration of the matter and any applicable limitation period;
Marketing records: until consent is withdrawn or the information is no longer required; and
De-identified statistics: potentially indefinitely where they can no longer reasonably identify an individual.
Information may remain temporarily in encrypted backups until the backup cycle expires.
Deletion may be delayed where retention is required by law, needed to protect another person, necessary to investigate fraud or required to establish or defend legal rights.
We use administrative, technical and organisational safeguards appropriate to the nature of the information and the risks involved.
Safeguards may include:
encryption in transit and, where appropriate, at rest;
authentication and role-based access controls;
access logging and monitoring;
secure development and testing practices;
data minimisation;
vulnerability management;
service-provider assessments;
employee and contractor confidentiality obligations;
incident-response procedures; and
backup and recovery controls.
No application, transmission or storage system can be guaranteed to be completely secure.
Users are responsible for:
maintaining the confidentiality of their credentials;
using a strong and unique password;
protecting their device;
logging out of shared devices;
not sharing verification codes; and
notifying us promptly of suspected unauthorised access.
Dashboard administrators are responsible for properly controlling their organisation’s users and permissions.
Where we become aware of a data breach, we will investigate and take steps reasonably appropriate to the risk.
Where legally required, we will notify affected individuals and relevant privacy regulators.
A notification may describe:
what occurred;
the categories of information affected;
potential consequences;
measures taken;
recommended protective actions; and
contact information for assistance.
Users and business customers must promptly report suspected loss, unauthorised access or disclosure to [insert security/privacy email].
Depending on your location and applicable law, you may have the right to:
be informed about our processing;
request access to personal information;
request correction of inaccurate or incomplete information;
request deletion or erasure;
request restriction of processing;
object to processing;
withdraw consent;
request data portability;
opt out of certain marketing;
opt out of sale, sharing or targeted advertising;
limit certain uses of sensitive personal information;
request information about categories and recipients of disclosures;
not be discriminated against for exercising privacy rights;
complain to a privacy regulator; and
request human review of certain automated decisions.
These rights are not absolute. We may deny or limit a request where permitted by law, including where:
identity cannot reasonably be verified;
another person’s rights would be affected;
information is protected by legal privilege;
retention is legally required;
deletion would compromise fraud prevention or security;
the request is manifestly unfounded or excessive; or
another legal exception applies.
We will explain a refusal where required.
Privacy requests may be submitted to:
Request form: IGCloyalty.com
Please state:
your name;
the account email or telephone number;
your country or state of residence;
the right you wish to exercise; and
enough information for us to locate the relevant records.
We may request information reasonably necessary to verify identity and protect accounts from fraudulent requests.
An authorised agent may act for you where permitted by law, but we may require proof of authority and direct identity verification.
We will respond within the period required by applicable law. Complex or numerous requests may require an extension where legally permitted.
We ordinarily do not charge for a valid request, but a reasonable fee may apply where legally permitted for repetitive, excessive or manifestly unfounded requests.
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, we will handle personal information in accordance with those requirements.
You may complain to us using the contact details above. If you are dissatisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.
Nothing in this Privacy Policy excludes rights that cannot lawfully be excluded under Australian law.
Where the European Union General Data Protection Regulation applies, you may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent.
You may also lodge a complaint with the supervisory authority in the country where you live, work or believe an infringement occurred.
Where legally required, IGC will appoint an EU representative or data protection officer and publish the relevant contact details.
Where the UK GDPR and Data Protection Act 2018 apply, you may exercise the rights described in this Privacy Policy and may complain to the UK Information Commissioner’s Office.
Where legally required, IGC will appoint a UK representative and publish the relevant contact details.
Subject to statutory thresholds and exceptions, California residents may have rights to:
know the categories and specific pieces of personal information collected;
know the categories of sources, purposes and recipients;
request deletion;
request correction;
opt out of sale or sharing;
limit certain uses of sensitive personal information; and
receive equal service and pricing when exercising privacy rights.
IGC will not discriminate against a person for exercising a legally protected privacy right.
Where relevant, requests may be submitted through the contact methods in Section 17 and through any “Do Not Sell or Share My Personal Information” mechanism made available.
Residents of other US states may have rights under applicable state privacy laws, including access, correction, deletion, portability, opt-out and appeal rights.
Where an appeal right applies, a person may appeal a denied request by replying to the decision or contacting the privacy email with the heading “Privacy Appeal”.
Where Canadian privacy law applies, we will collect, use and disclose personal information with valid consent or another lawful authority and provide access and correction rights subject to legal exceptions.
Where Brazil’s Lei Geral de Proteção de Dados applies, individuals may have rights to confirmation, access, correction, anonymisation, restriction, portability, deletion, information about disclosures, consent withdrawal and review of automated decisions.
Additional local privacy rights and requirements may apply. Where local law provides greater protection than this Privacy Policy, the mandatory local requirement will prevail.
The Services are not intended for children below the minimum digital-consent age applicable in their country unless:
the relevant service is expressly designed for children;
legally required parental or guardian consent has been obtained; and
appropriate child-protection controls are implemented.
Unless a specific service states otherwise, users must be at least 16 years old, or the minimum age legally permitted in their jurisdiction, to create an independent account.
A parent or guardian must supervise a minor’s use of location-based and augmented-reality features.
We do not knowingly use children’s personal information for targeted advertising or sell it.
Where we learn that a child’s information was collected without required authorisation, we may suspend the account and delete the information, subject to legal and safety requirements.
The Services may link to third-party websites, maps, payment services, social platforms, application stores, merchant pages or other external services.
IGC does not control the independent privacy practices of those third parties.
Users should review the third party’s privacy policy before providing information or enabling an integration.
The inclusion of a link or integration does not mean IGC accepts responsibility for the third party’s privacy, security, accuracy or conduct.
If IGC undergoes a merger, acquisition, financing, restructuring, sale of assets, insolvency process or transfer of business, information may be disclosed to advisers and transferred as part of the transaction.
Any recipient will be required to process personal information in accordance with applicable law and any continuing commitments attached to the information.
We may preserve, use or disclose information where we reasonably believe it is necessary and legally permitted to:
comply with law, legal process or a lawful government request;
investigate fraud, cybercrime or unauthorised access;
protect the safety or rights of a person;
prevent serious harm;
enforce agreements;
recover debts;
defend legal claims; or
protect the integrity of the Services.
We assess government and law-enforcement requests and may challenge requests that appear unlawful, excessive or invalid where appropriate.
We may create aggregated, statistical or de-identified information for:
service improvement;
research and development;
campaign measurement;
foot-traffic and engagement analysis;
system accuracy testing;
commercial reporting; and
industry insights.
Where information has been effectively de-identified so that it is no longer personal information under applicable law, we may use and disclose it for lawful purposes.
We will not knowingly attempt to re-identify information that is legally treated as de-identified except for security testing, validation or where permitted by law.
We may update this Privacy Policy to reflect:
changes to the Services;
new technologies;
new legal requirements;
operational or business changes; or
improved privacy practices.
The updated version will state the revised effective date.
Where a change materially affects how personal information is used, we will provide additional notice or obtain consent where required.
Continued use of the Services after an update does not constitute consent where applicable law requires express consent.
This Privacy Policy may be translated into other languages.
Translations are provided for accessibility. To the extent legally permitted, the English version will govern where there is an inconsistency, except where local law requires the local-language version to prevail.
Questions, requests or complaints regarding this Privacy Policy may be sent to:
Via our website IGCloyalty.com
Please include sufficient information for us to understand and investigate the matter.
We will acknowledge and investigate privacy complaints in accordance with applicable law. We may request further information and will communicate the outcome and available review options.
You may also have the right to contact the privacy or data-protection regulator in your jurisdiction.
This Privacy Policy should be read with:
the IGC Terms and Conditions;
the applicable campaign rules;
the Cookie Policy;
any dashboard or business-customer agreement;
any data-processing agreement; and
collection notices displayed when particular information is requested.
Where documents conflict:
mandatory privacy law prevails;
a specific collection notice prevails for the particular processing it describes;
an executed data-processing agreement governs the controller–processor relationship it covers; and
this Privacy Policy applies to all remaining privacy matters.
By using the Services, you acknowledge that:
you have been provided access to this Privacy Policy;
location, device, sensor and usage information may be processed as described;
information may be processed internationally subject to appropriate legal safeguards;
campaign partners may independently process information as disclosed;
device permissions can be controlled through device settings;
privacy requests are subject to identity verification and lawful exceptions; and
no technological system can provide absolute privacy or security.
Where consent is required, this acknowledgement does not replace a specific consent request.
End of Global Privacy Policy