Yumme · Privacy and data protection

Privacy Policy

This Policy explains what personal information Yumme handles, why we handle it, who receives it, how long we keep it, and the choices and protections available to you.

Effective 31 August 2026 Australia-first, global coverage Version 2.0
Section 01

Who we are and what this Policy covers

TRAN Systems (ABN 99 773 857 017), the operator of Yumme (“Yumme”, “we”, “us” or “our”), is responsible for the personal information described in this Policy when we decide how and why it is handled.

This Policy applies to the Yumme mobile application, yumme.network, tran.systems, merchant and business tools, customer ordering experiences, support channels, events, promotions, and any other product or service that links to this Policy (together, the “Services”).

It applies to customers and order recipients; merchants, home cooks and their personnel; delivery or fulfilment participants if those features are offered; business customers; website visitors; applicants; and people who contact us. A feature-specific notice shown when information is collected forms part of this Policy. If a feature-specific notice conflicts with this Policy, the more specific notice applies to that feature.

Important: this Policy does not govern a merchant’s independent handling of information outside Yumme, or an unrelated third-party site, wallet, social platform or payment service. Those organisations must explain their own practices.

We collect for a reason

We limit collection to information reasonably needed for the Services, safety, security, legal compliance and purposes explained to you.

You have controls

You can manage permissions and marketing, correct account details, request access or deletion, and raise a privacy complaint.

We use safeguards

We apply risk-based technical and organisational controls and assess suspected data breaches under applicable law.

We do not sell for money

We do not sell personal information for monetary payment. Some advertising disclosures may be treated as “sharing” or a “sale” under certain laws, for which opt-outs apply.

Back to top
Section 02

Our privacy roles

When Yumme decides the purpose

Yumme acts as the privacy “controller” or responsible organisation when we determine the purposes and means of handling information—for example, operating Yumme accounts, securing the platform, processing Yumme support requests, conducting analytics, and administering marketing preferences.

Merchants and business customers

Merchants and business customers may separately decide how they handle customer, employee or other information. In those circumstances, they are independently responsible for their practices. A merchant may receive the information needed to accept, prepare, fulfil, refund and support an order. Contact that merchant directly about its independent use of the information.

Where Yumme handles personal information solely on documented instructions from a business customer, Yumme acts as that customer’s processor or service provider. We use such information only to provide the contracted service, maintain security, meet legal duties and as otherwise permitted by the agreement and applicable law. A rights request concerning that information may need to be referred to the relevant business customer.

Information about other people

If you provide information about an order recipient, employee, guest, emergency contact or another person, you must be authorised to do so and should make this Policy available to them. Do not provide more information than the feature requires.

Back to top
Section 03

Personal information we collect

The information collected depends on your role, location, settings and the features you use. “Personal information” includes information or an opinion about an identified or reasonably identifiable person, and equivalent concepts under other applicable laws.

CategoryExamplesWhen it is collected
Account and contactName, username, email, phone number, postal or billing address, profile photo, language, preferences, encrypted or hashed authentication credentials, and account identifiers.When you register, update a profile, sign in, place an order, join a business account or contact us.
Merchant and professionalBusiness name, ABN or other registration details, licences, role, workplace contact details, menu or catalogue, pricing, availability, personnel permissions and authorised representatives.When a merchant or business registers, verifies its operations, lists products, manages staff or uses business tools.
Identity and eligibilityDate of birth or age range, government-issued identification, document verification result, selfie or likeness, signature and evidence of authority to act for a business.Only where reasonably needed for identity, fraud, age-restricted products, regulated services, account recovery or legal compliance.
Orders and commercial activityItems viewed or ordered, substitutions, instructions, merchant, recipient, pickup or delivery details, time, price, discounts, promo codes, receipts, returns, refunds, subscriptions and transaction history.When you browse, order, fulfil, receive or manage products or services.
Payment and financialPayment method, tokenised card details, billing details, payment status, refunds, chargebacks, merchant settlement information, bank account details and tax information.When a payment, payout, subscription or verification is initiated. Full card data is generally collected directly by a payment processor rather than stored by Yumme.
Location and fulfilmentApproximate location from IP; precise device location if permission is enabled; entered addresses; pickup, delivery and route information; timestamps; and location-sharing status.When needed to show nearby services, confirm a service area, facilitate fulfilment, prevent fraud or support safety. Device permission may be withdrawn at any time.
Device, log and usageIP address, device and advertising identifiers, browser, operating system, app version, carrier, language, referring URL, pages and features used, clicks, session times, diagnostic events, crashes and security logs.Automatically when you use the Services, subject to device, browser and consent controls.
Communications and supportEmails, chats, messages between platform participants, call details, support tickets, recordings where notice and consent are required, survey answers, incident reports and related attachments.When you communicate through the Services, contact support, report safety or fraud concerns, dispute a transaction or respond to a survey.
Content and reputationReviews, ratings, comments, photos, videos, menu content, public profile information, reports and responses to reports.When you upload, publish, rate, review or otherwise contribute content.
Preferences and inferencesFood, merchant or product preferences; likely interests; service recommendations; fraud or security signals; and segments derived from interactions.Generated from account, order, usage and device information to personalise, protect and improve the Services, subject to applicable choices.
Recruitment and workforceEmployment history, qualifications, references, work rights and application materials.When you apply to work with us or provide services to us. A separate workforce notice may also apply.

Sensitive information

We do not ask for sensitive information merely because it may be useful. We collect it only where reasonably necessary for our functions and with consent, or where another legal permission applies. Depending on the feature, this may include precise geolocation; identity document data; biometric information used for identity verification; accessibility information; allergy or dietary information included in an order; health or safety information in an incident report; or government identifiers.

We do not intentionally collect genetic information, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex-life or sexual-orientation information unless you voluntarily include it in a communication or content, or a clearly explained feature lawfully requires it. Please avoid including sensitive information in free-text fields unless necessary.

If information is required

Some information is optional. If required information is not provided, we may be unable to create or secure an account, process an order or payment, provide a requested feature, verify eligibility, fulfil a legal duty or investigate an incident. We will indicate required fields where practical.

Back to top
Section 04

How we collect information

We collect personal information:

  • from you, including through accounts, forms, orders, uploads, device permissions, support, promotions and communications;
  • through your use of the Services, including device, usage, cookie, location, order and transaction events;
  • from other users, such as an order purchaser, recipient, referring user, merchant, delivery participant, account administrator or person reporting an incident;
  • from service providers and partners, including payment processors, identity-verification services, fraud-prevention providers, analytics services, maps, communications providers, app stores, delivery or fulfilment providers and social-login providers;
  • from business customers, where an employer or other organisation authorises your access to a Yumme business account;
  • from public and official sources, such as business registers, sanctions lists, public websites and regulators where verification or compliance requires it; and
  • through integrations you authorise, subject to the permissions shown by that provider.

If we receive unsolicited personal information, we assess whether we could lawfully have collected it. If not, we will destroy or de-identify it where lawful and reasonable.

Back to top
Section 05

How and why we use personal information

PurposeWhat this includesLegal basis where required
Provide the ServicesCreate and manage accounts; display relevant merchants or products; process and track orders, subscriptions, returns and refunds; provide receipts; support pickup or delivery; and maintain preferences.Contract; requested pre-contract steps; legitimate interests; consent where a permission requires it.
Enable platform interactionsShare necessary order and contact details among customers, recipients, merchants, authorised business administrators, and fulfilment participants; enable in-app or masked communications; and publish content you choose to make public.Contract; legitimate interests; consent for optional sharing features.
Payments and merchant settlementAuthorise payments, issue refunds, calculate fees, process payouts, maintain financial records and address chargebacks or payment disputes.Contract; legal obligation; legitimate interests in preventing loss and resolving disputes.
Safety, security and platform integrityAuthenticate users; detect spam, abuse, account takeover, unsafe conduct and fraud; verify eligibility; protect people and property; investigate incidents; enforce policies; and maintain service availability.Legitimate interests; legal obligation; vital interests; substantial public interest or other permission for sensitive information.
Customer and merchant supportRespond to requests, diagnose problems, moderate disputes, investigate complaints, restore accounts and provide service communications.Contract; legitimate interests; legal obligation.
PersonalisationRemember settings, rank search results, recommend merchants or products, tailor content, estimate availability and improve the relevance of offers.Legitimate interests; consent where required for tracking or sensitive data.
Research, analytics and developmentMeasure performance, troubleshoot, test features, conduct surveys, produce aggregated insights, improve accessibility and develop new services. We use de-identified or aggregated data where reasonably possible.Legitimate interests; consent where required.
Marketing and advertisingSend offers you have requested or may lawfully receive; measure campaigns; manage referrals and promotions; and, where permitted, personalise marketing or ads.Consent where required; legitimate interests for limited direct marketing; always subject to opt-out rights.
Legal, insurance and regulatory mattersKeep required records; respond to lawful process; establish, exercise or defend claims; support audits, insurance and tax; comply with licences; and protect legal rights.Legal obligation; legitimate interests; vital interests; legal claims.
Corporate operationsGovernance, accounting, due diligence, restructuring, financing, merger, acquisition, sale or transfer of assets.Legal obligation; legitimate interests, with appropriate confidentiality protections.

Under Australian law, we generally use or disclose personal information for the primary purpose for which it was collected, a related purpose you would reasonably expect, with consent, or as otherwise authorised or required by law. Where consent is the basis, you may withdraw it prospectively, but this does not affect earlier lawful handling or handling supported by another legal basis.

We may aggregate or de-identify information so it no longer identifies or is reasonably likely to identify you. We may use and disclose that information for analytics, research, reporting and service improvement. We do not attempt to re-identify protected de-identified data except to test privacy safeguards or where permitted by law.

Back to top
Section 06

Automated processing, recommendations and fraud controls

Yumme may use rules, algorithms and machine-learning tools to operate and protect the Services. These tools may:

  • rank search results or recommend merchants, products, content and promotions based on location, availability, prior activity and stated preferences;
  • estimate fulfilment times, service areas, inventory relevance, fees or other service information;
  • detect unusual logins, payment risk, duplicate accounts, abuse, prohibited transactions or other patterns associated with fraud and platform harm; and
  • moderate or prioritise support, content and incident reports.

Automated signals may lead us to request verification, delay or decline a transaction, restrict a feature, withhold a payout where contractually and legally permitted, or refer a matter for review. We design these systems to use data relevant to the stated purpose and monitor them proportionately for accuracy, security and unfair outcomes.

Human review: if a solely automated decision produces legal or similarly significant effects, and applicable law gives you a right to explanation, objection or human review, contact us. We will provide meaningful information about the main factors where permitted and arrange review by an authorised person. We may withhold information that would compromise security, fraud prevention, another person’s rights or law-enforcement activity.

Back to top
Section 07

When we share or disclose information

We disclose only information reasonably relevant to the recipient’s role and require service providers to protect it through contractual or equivalent controls where appropriate.

RecipientWhy information is sharedTypical information
Customers, recipients and group participantsTo fulfil an order, provide updates, support a group or guest transaction, or enable a feature you request.Name or display name, order details, status, relevant instructions and limited contact information.
Merchants and their authorised personnelTo accept, prepare, fulfil, refund and support orders; administer merchant tools; manage compliance and settle funds.Order and recipient details, necessary contact or location information, payment status, support history and ratings.
Delivery and fulfilment providersTo collect, route, deliver, verify receipt, support safety and resolve incidents if such services are offered.Pickup and delivery details, recipient name, masked or limited contact details, order size or handling notes, and status.
Business account administratorsTo manage authorised users, budgets, expenses, orders and compliance for an organisation.Business profile, account membership, eligible transactions and policy-compliance information. Personal transactions are not disclosed merely because the same email is used, unless the feature and notice say otherwise.
Payment and financial providersTo authorise and settle payments, make payouts, prevent fraud, handle chargebacks and comply with financial laws.Identifiers, payment tokens, billing details, transaction information, risk signals and merchant settlement data.
Technology and operational providersHosting, cloud storage, communications, support, identity verification, maps, analytics, security, fraud prevention, professional advice and service maintenance.Only the information needed to perform the contracted function.
Advertising and measurement partnersWhere permitted, to measure campaigns or show relevant advertising, subject to consent and opt-out rights.Cookie or device identifiers, hashed contact identifiers, approximate location, interactions and inferred audience segments—not full payment-card details.
Affiliates and corporate participantsTo provide shared services or evaluate and complete a financing, restructuring, merger, acquisition, sale or transfer.Information relevant to the operation or transaction, subject to confidentiality, purpose limits and applicable law.
Authorities, courts, insurers and advisersWhere reasonably believed necessary to comply with law or valid legal process, respond to emergencies, address claims, enforce agreements, prevent harm or protect rights and safety.Information reasonably related to the request, event, claim or legal duty.
Others at your directionWhen you use a sharing feature, link another service, authorise an integration, enter a joint promotion or otherwise direct us to disclose information.As explained at the time and within the permission you grant.

We may challenge requests that are unlawful, overbroad or inconsistent with human rights, and we notify affected users before disclosure where lawful and appropriate. In an emergency involving a serious threat to life, health or safety, we may disclose relevant information to emergency services or other appropriate recipients as permitted by law.

Sale of information: Yumme does not sell personal information in exchange for money. Certain privacy laws define “sale” or “sharing” broadly to include disclosures for cross-context behavioural advertising. Where those laws apply, you may opt out as described in sections 9, 10, 16 and 18.

Back to top
Section 08

Payments, financial data and blockchain features

Card and conventional payments

Payment providers may collect card, bank-account or wallet information directly under their own privacy notices. Yumme generally receives a payment token, limited card descriptors, transaction status and fraud signals rather than the complete card number or security code. We use payment data to process charges and payouts, issue refunds, reconcile accounts, prevent fraud, address disputes and meet legal obligations.

Digital assets and public blockchains

If Yumme enables a digital-asset or blockchain feature, we may handle public wallet addresses, transaction identifiers, token type and amount, network, smart-contract events and related compliance information. Blockchain transactions may be public, permanent, replicated globally and outside Yumme’s control. They may not be erasable or reversible. Do not place names, contact details, order notes, health information or other unnecessary personal information into a public blockchain transaction.

Where possible, Yumme keeps directly identifying account data off-chain and links it to on-chain activity only as needed for the feature, security, accounting, fraud prevention or compliance. A request to delete a Yumme account cannot remove information already recorded on a public blockchain, but we will delete or de-link off-chain information where required and technically feasible.

Back to top
Section 09

Cookies, SDKs and similar technologies

Yumme and authorised partners may use cookies, pixels, local storage, software development kits (“SDKs”) and similar technologies in our websites, apps, emails and advertisements.

  • Strictly necessary: sign-in, security, fraud prevention, load balancing, shopping-cart and core service functions.
  • Preference: language, region, accessibility and other remembered settings.
  • Analytics: performance, errors, feature use and audience measurement.
  • Advertising: campaign measurement, frequency control, attribution and personalisation where permitted.

Where required, non-essential technologies are not activated until you make a choice. You can use Yumme’s cookie controls, device privacy settings or browser tools to withdraw or change consent. Blocking necessary technology may prevent parts of the Services from working. Browser “Do Not Track” signals are not governed by one universal standard; where applicable law requires recognition of a valid opt-out preference signal, including Global Privacy Control, Yumme treats that signal as an opt-out for the browser or device that sends it.

More details—including current providers, purposes, cookie duration and controls—should be read in Yumme’s Cookie Notice and consent interface. If those sources conflict, the setting that gives you the more specific current choice controls.

Back to top
Section 10

Marketing, notifications and your choices

We may send service messages needed to administer your account or transactions, including receipts, security alerts, policy notices, order updates and support responses. These are not marketing and may continue while you use the relevant Service.

We send direct marketing only where permitted. You can:

  • use the unsubscribe link in a marketing email;
  • reply STOP where an SMS program supports it;
  • turn promotional push notifications off in the app or device settings;
  • adjust cookie or advertising preferences; or
  • contact us to opt out or withdraw consent.

We action opt-outs within the period required by law and may keep a minimal suppression record so we do not add you back to the same marketing list. Withdrawing marketing consent does not prevent service or safety communications. We do not disclose mobile-originator opt-in data or consent to third parties for their independent marketing.

Back to top
Section 11

Public profiles, reviews and user content

Content you choose to publish—such as a merchant profile, menu, image, review, rating, comment or public list—may be visible to other users, search engines and the public. It may be copied or reshared outside Yumme. Check the audience and avoid publishing personal or sensitive information you do not want others to see.

We may use content and related identifiers to display it, attribute it as the feature explains, moderate it, investigate authenticity or abuse, enforce policies and improve the Services. You may request removal through the available feature or by contacting us. Removal from Yumme does not ensure deletion of copies made by others, search-engine caches, legal records or data we must retain for safety, disputes or compliance.

Back to top
Section 12

Overseas storage, access and transfers

Yumme is operated from Australia and may use personnel and providers in other countries. Based on the current operating model, information may be stored in or accessed from Australia, Vietnam, Singapore, the Philippines, Thailand, India, the United States and other countries where our cloud, communications, security, analytics, payment or support providers operate.

Privacy laws and government-access rules may differ from those in your location. Before disclosing personal information to an overseas recipient, we take reasonable steps required by Australian Privacy Principle 8 and other applicable laws. Depending on the transfer, safeguards may include vendor due diligence, data-processing terms, confidentiality and security obligations, access restrictions, encryption, data minimisation, transfer-risk assessments, approved contractual clauses, and monitoring or audit rights.

Australian law may make us accountable for certain acts or practices of an overseas recipient. Exceptions can apply—for example, where informed consent validly applies or another legal exception permits the disclosure. For transfers governed by the EEA or UK rules, we use an adequacy decision, approved contractual safeguards or another lawful transfer mechanism as required.

Back to top
Section 13

Retention, account closure and deletion

We keep personal information only as long as reasonably needed for the purpose collected, a compatible lawful purpose, or a legal requirement. We consider the information’s sensitivity, volume and context; risks of harm; the life of the account or transaction; limitation periods; tax, corporate, consumer and financial-record duties; safety and fraud needs; dispute or enforcement holds; and whether the purpose can be met with de-identified data.

InformationGeneral retention approach
Account and profileFor the account’s life, then deleted or de-identified after a reasonable closure period unless needed for legal, fraud, safety, dispute or reactivation purposes.
Orders, payments, payouts and tax recordsUsually retained for up to seven years after the relevant transaction or financial year, or longer where law, audit, chargeback, litigation or enforcement requires.
Identity verificationVerification results may be retained while needed for account integrity. Copies of identity documents or selfies are removed sooner where practical unless law, fraud prevention or an active investigation requires longer retention.
Location, device and usageKept for the period reasonably needed to provide the feature, maintain security, analyse performance and resolve incidents, then aggregated, de-identified or deleted according to the applicable retention schedule.
Support, incidents and disputesFor the time needed to resolve the matter and for an appropriate legal, insurance, safety or limitation period after closure.
Marketing and consent recordsUntil you opt out or consent expires, plus a minimal suppression and consent record for compliance.
BackupsRemoved on a rolling schedule. Until deletion cycles complete, backup data is isolated from ordinary use and restored only for continuity, security or legal needs.

You may request account deletion through an available account setting or by contacting us. We first deactivate the account, verify the request where necessary, and delete or de-identify information unless retention is permitted or required. We may retain limited information to prevent a person restricted for serious fraud or safety reasons from immediately recreating an account, to maintain transaction records, or to establish, exercise or defend legal claims.

When information is no longer needed and no exception applies, we take reasonable steps to destroy it securely or ensure it is de-identified. Deletion from live systems may not be immediate where data remains in protected backups, public blockchains, another controller’s systems or records subject to a legal hold.

Back to top
Section 14

How we protect information

We maintain a risk-based privacy and security program designed to protect personal information against misuse, interference, loss, and unauthorised access, modification or disclosure. Depending on risk and system capability, measures may include:

  • encryption in transit and appropriate encryption or equivalent protection at rest;
  • role-based access, least-privilege controls, strong authentication and additional controls for privileged access;
  • logging, monitoring, rate limiting, fraud controls, backups and resilience measures;
  • secure development, code review, vulnerability management, testing and patching;
  • staff confidentiality obligations, privacy and security training, and access removal when roles change;
  • vendor risk assessment, contractual security requirements and incident-notification duties;
  • data minimisation, retention schedules, secure disposal and de-identification; and
  • incident-response, business-continuity and disaster-recovery processes.

No internet, mobile, storage or authentication system is completely secure. You can help by using a unique password, enabling available multi-factor authentication, protecting one-time passcodes, keeping devices and apps updated, checking links and messages, and contacting us promptly about suspected account compromise. We will never ask you to disclose a password or one-time code through an unsolicited message.

Back to top
Section 15

Data breach and incident response

We maintain procedures to identify, contain, investigate, document and remediate suspected privacy or security incidents. We assess what happened, the information and people affected, likely harm, available remedial action, legal notification duties, and measures to reduce recurrence.

Where the Australian Notifiable Data Breaches scheme applies and an eligible data breach is likely to result in serious harm, we notify the Office of the Australian Information Commissioner (“OAIC”) and affected individuals as soon as practicable, unless an exception applies. We also comply with applicable notification laws in other locations. A notice may describe the incident, information concerned, recommended protective steps and how to contact us.

If you believe your Yumme account or information has been compromised, change affected credentials, contact your payment provider if relevant, and report the matter promptly to [email protected] or +61 466 324 030.

Back to top
Section 16

Your rights, choices and account controls

Subject to your location, Yumme’s role, identity verification and lawful exceptions, you may have rights to:

  • know whether we handle your information and obtain access or a copy;
  • correct inaccurate, out-of-date, incomplete, irrelevant or misleading information;
  • request deletion or de-identification;
  • object to or restrict certain handling;
  • withdraw consent prospectively;
  • receive portable data in a commonly used machine-readable format;
  • opt out of direct marketing, targeted advertising, sale or sharing as legally defined, and certain profiling;
  • request information about or human review of certain automated decisions;
  • authorise an agent to act for you where law permits; and
  • complain to us and an applicable privacy regulator without retaliation.

Self-service controls

Where available, use account settings to edit profile details, close an account, manage linked services and set notification preferences. Use device settings to control precise location, camera, microphone, photos, contacts and push notifications. A permission change does not delete information already collected; use a deletion request for that.

Submitting a request

Email [email protected] with the subject “Privacy Request” or write to the address in section 22. Describe the right you wish to exercise, the Yumme service involved, your account contact details and the country or state in which you live. Do not email identity documents unless we specifically request them through an appropriate channel.

Verification, authorised agents and responses

We verify requests proportionately to the sensitivity and risk. We may ask you to confirm control of an account, answer account-specific questions or provide limited evidence of identity or authority. An authorised agent may need to provide written permission, and we may confirm the request directly with you. Information collected for verification is used for that purpose and related security or legal compliance.

We respond within the period required by applicable law. For Australian access or correction requests, we aim to respond within 30 days. We may extend a period where law allows and will explain the reason. We do not ordinarily charge a fee, but may charge a reasonable cost or refuse a request where legally permitted—for example, if it is manifestly unfounded, excessive or would unreasonably affect another person’s privacy. If we refuse, we explain the grounds and available complaint steps unless prohibited.

Back to top
Section 17

Australia-specific protections

Yumme handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”) where they apply, as well as other applicable laws including direct-marketing, telecommunications, consumer, financial-record and state or territory requirements.

Anonymity and pseudonymity

You may interact anonymously or under a pseudonym where lawful and practicable—for example, when making a general enquiry. Identification may be necessary for accounts, payments, orders, safety, rights requests, fraud prevention, merchant verification or legal compliance.

Access and correction

You may request access to personal information we hold and correction of information that is inaccurate, out-of-date, incomplete, irrelevant or misleading. If we correct information previously disclosed to another organisation, you may ask us to notify that organisation where required and reasonable. If we decline to correct a record, you may ask us to associate a statement with it.

Government-related identifiers and sensitive information

We do not adopt a government-related identifier as our own account identifier, and use or disclose such identifiers only where permitted. We collect sensitive information with consent where required or under a lawful exception, apply additional access and purpose limits, and do not use it for unrelated advertising.

Direct marketing

You may ask us at any time not to use or disclose personal information for direct marketing and to identify the source of that information where the APPs give you that right. We will not charge for the request.

Privacy complaints

First contact our Privacy Officer using section 22. Include enough detail for us to investigate, but do not send unnecessary sensitive information. We will acknowledge the complaint, investigate it fairly, keep you informed where appropriate, and provide an outcome within a reasonable period—generally within 30 days for a standard complaint.

If you are not satisfied, you may complain to the Office of the Australian Information Commissioner. The OAIC generally expects you to complain to the organisation first and allow a reasonable response time.

Back to top
Section 18

Additional rights in other regions

This section supplements the rest of the Policy. It applies only where the relevant law covers Yumme’s handling and does not limit more favourable rights.

New Zealand

Where the Privacy Act 2020 applies, you may request access and correction and complain to the Office of the Privacy Commissioner. We assess notifiable privacy breaches and overseas disclosures under applicable New Zealand requirements.

EEA, United Kingdom and Switzerland

Where applicable, our legal bases include performance of a contract, compliance with legal obligations, protection of vital interests, your consent and our or another party’s legitimate interests. Legitimate interests include providing and improving the Services, platform security, fraud prevention, support, business administration and proportionate marketing. We balance those interests against your rights and expectations.

You may have rights of access, rectification, erasure, restriction, objection, portability and consent withdrawal, and rights relating to solely automated decisions. You may object at any time to direct marketing. You may complain to your local supervisory authority. For cross-border transfers, see section 12. Contact the Privacy Officer for details of the relevant controller or transfer safeguard for your service.

United States state privacy laws

Residents of California and other states with applicable comprehensive privacy laws may have rights to know, access, correct, delete, obtain a portable copy, opt out of sale, sharing, targeted advertising or certain profiling, limit certain uses of sensitive information, appeal a refusal, and receive equal service for exercising a right.

Statutory categoryCollected or processed in the preceding 12 months
Identifiers and customer-record informationYes—for accounts, contact, orders, merchant administration, support and verification.
Commercial and transaction informationYes—for orders, subscriptions, payments, refunds, promotions and merchant settlement.
Internet, device and electronic activityYes—for service operation, analytics, security and, with applicable choice, advertising.
GeolocationYes—approximate location; precise location only where permission or another legal basis applies.
Audio, visual and similar informationYes, if submitted in support, content or incident features, or recorded with required notice.
Professional or employment informationYes, for merchants, business users, applicants and service personnel.
InferencesYes—for recommendations, preferences, security, fraud detection and permissible advertising.
Sensitive personal informationLimited—for login credentials, precise location, payment access, government ID, eligibility, accessibility, safety or identity verification as described in section 3.
Protected characteristics and biometric informationOnly if voluntarily provided, legally required, or a specifically disclosed verification or accessibility feature requires it.

We disclose these categories to the recipient groups in section 7 for the listed business and commercial purposes. We do not sell personal information for money. If advertising disclosures are legally considered sale or sharing, you may opt out through Yumme’s cookie/privacy controls, a recognised opt-out preference signal where required, or a request to the Privacy Officer. We do not knowingly sell or share for cross-context behavioural advertising the personal information of users we know are under 16.

If we deny an appealable US request, respond to our decision with “Appeal” and the reason you disagree. We will review it and provide any regulator contact required by law. California residents may also request information permitted by the “Shine the Light” law about disclosures for third parties’ direct marketing.

Canada, South Africa and other locations

Where applicable law provides access, correction, deletion, objection, consent withdrawal, portability, complaint or other rights, we honour them subject to lawful limits. Canadian users may complain to the Office of the Privacy Commissioner of Canada or an applicable provincial authority. South African users may complain to the Information Regulator. Contact us for the relevant regulator or local route.

Back to top
Section 19

Children and younger users

Yumme’s registered Services are intended for people aged 18 or older unless a clearly identified feature lawfully supports a younger user with appropriate safeguards. We do not knowingly permit a child to create a standard account or knowingly collect a child’s personal information for targeted advertising.

An adult may provide limited information about a child as an order recipient only where authorised and necessary. Do not place sensitive information about a child in order notes unless essential for safe fulfilment. If you believe a child has provided personal information contrary to this section, contact us. We will investigate and delete or restrict it as required, while preserving information needed for safety or law.

Back to top
Section 20

Third-party services and integrations

The Services may link to or integrate with app stores, payment providers, maps, social platforms, identity providers, wallets, merchant sites or other third parties. A link does not mean Yumme controls that organisation. When you leave Yumme or authorise an integration, the third party’s terms and privacy notice apply to its independent collection and use.

Review permissions before connecting an account. Where available, you can remove an integration through your Yumme or third-party settings. Removing access stops future collection through the connection but may not delete information already received by either party. Contact the relevant organisation about its records.

Back to top
Section 21

Changes to this Policy

We review this Policy as our Services, technology and legal obligations change. The effective date and version at the top identify the current Policy. Updated wording applies prospectively from the stated effective date unless law requires otherwise.

For material changes, we provide notice appropriate to the impact—for example, through the Services, by email, or with a prominent website notice. Where a new use requires consent, we request it rather than relying only on continued use. We encourage you to review notices when new features are introduced.

Back to top
Section 22

Contact, rights requests and complaints

Contact Yumme’s Privacy Officer for questions, rights requests, consent withdrawal, account deletion, direct-marketing objections, security reports or complaints.

Yumme Privacy Officer

TRAN Systems
ABN 99 773 857 017
26/198 Adelaide Street
Brisbane City, Queensland 4000
Australia

Contact channels

Email: [email protected]
Phone: +61 466 324 030
Website: yumme.network

For privacy complaints, state “Privacy Complaint” in the subject line and describe what happened, the outcome you seek, relevant dates and the Service involved. We will handle complaints without retaliation. You may also contact the regulator identified in section 17 or 18.

Regulatory contact in Australia:
Office of the Australian Information Commissioner
Website: oaic.gov.au/privacy/privacy-complaints
Phone: 1300 363 992


Back to HOME