Cyclio Privacy Policy
Last updated: [DATE]
Draft — not yet finalised
This page reflects the policy as drafted, with placeholders (highlighted below) still to be filled in, including an internal drafting note in section 2 that needs actioning before publication. It has not yet been reviewed by a lawyer and should not be treated as final until both are resolved.
Cyclio manages the information we collect from you in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. In this Privacy Policy, "Cyclio", "we", "our" and "us" means Cyclio Pty Ltd ACN [ACN], an Australian company. Our company details are in the Contact Us section below.
This Privacy Policy describes how Cyclio collects, uses, shares and handles your personal information, and sets out the rights and obligations that both you and Cyclio have in relation to it. Country specific terms in Appendix A also apply.
By accessing www.cyclio.io or any Cyclio application (together, the "Services") you accept the Cyclio Marketplace Terms and Conditions ("User Agreement") and acknowledge that your personal information may be collected, used and disclosed in accordance with this Privacy Policy. Except for terms defined in this Privacy Policy, defined terms have the meaning given in the User Agreement.
The Services are for business use only. You must not use the Services if you are under 18 years old.
A note on business information. Cyclio is a business-to-business marketplace, and much of the information we handle relates to businesses rather than individuals. Information about a company is not personal information. However, information about a sole trader, partner, director, employee or contact person — including a work email address, direct phone number, business name that includes a personal name, or an ABN belonging to an individual — can be personal information, and we handle it in accordance with this Privacy Policy.
Cyclio may modify this Privacy Policy from time to time and will update the web page on which it is displayed. If we materially change the way we use or share personal information previously collected from you through the Services, we will notify you through your Cyclio account, your registered email address, or other communication. You should check your account regularly.
1. The personal information we collect
Information you give us directly
When you pre-register or express interest, we collect your name, business name, email address, phone number and location.
When you register an account, we collect:
your name, position or role, and the name of the business you represent;
your business email address, phone number, and postal and business address;
your ABN or ACN, and business registration or trading name details;
your account login credentials;
your industry, product categories of interest, buying or selling preferences, and the locations in which you buy or sell;
your business's areas of operation, capabilities, certifications, accreditations, licences and insurance details, where you choose to provide them; and
in some cases, a profile photo, logo or business description.
When you transact, we collect and generate:
Listing content you publish, including product names, makes, models, serial numbers, condition details, specifications, photographs, documents, drawings, data sheets, test certificates and manuals;
Orders, Offers, Quotes, Requests for Quote, negotiated prices and agreed terms;
delivery, collection and site addresses, contact names and phone numbers for delivery, and site access instructions you provide;
freight, logistics and tracking information;
messages you exchange with other Users through the Cyclio messaging system;
ratings, reviews and feedback you give and receive; and
Dispute records, including the evidence, photographs and correspondence you submit.
Payment and financial information. Payments on Cyclio are processed by our third party payment provider, Stripe. When you enter card or bank account details, those details are collected and processed directly by Stripe under Stripe's own terms and privacy policy. Cyclio does not collect or store your full card number, CVC or bank account credentials. We receive from Stripe limited information such as the last four digits of a card, the card brand, expiry date, the cardholder or account name, transaction amounts, payment status, payout records and any chargeback or dispute information.
Identity and business verification (KYC). To meet our own and our payment provider's legal obligations — including anti-money laundering, counter-terrorism financing, and sanctions screening requirements — Sellers and some Buyers must complete a verification process. This may involve providing:
identity documents for directors, beneficial owners or authorised representatives, such as a driver licence, passport or other government-issued identification;
date of birth and residential address;
business registration, ownership and control information; and
bank account details for payouts.
Where verification is performed by Stripe or another verification provider, that provider collects the information directly and provides us with the verification outcome and limited associated data.
Credit information. If you apply for a Trade Account or other deferred payment facility, we may collect credit information about you and your business, including credit application details, trade references, financial statements, and information obtained from credit reporting bodies and commercial credit reporting services. Where we handle credit information about an individual, we do so in accordance with Part IIIA of the Privacy Act 1988 (Cth) and our Credit Reporting Policy.
When you contact us, we collect the content of your enquiry, support ticket, complaint or call, and may record or make notes of the communication to help resolve your issue and for training and quality purposes.
When you apply for a job with us, we collect the information you submit through our application form or our recruitment service provider, including your resume, links to online profiles, and any other information you choose to provide.
If we do not collect the information described above, we may be unable to provide the Services to you or to perform our obligations under the User Agreement.
If your details change, it is your responsibility to update your Cyclio account so that our records remain accurate, complete and up to date.
Information we collect automatically
When you use the Services, we receive and record information from your browser, device and network, including through cookies and similar technologies:
device and connection information, such as IP address, unique device identifier, device type, operating system, browser type, referral URL and web log information;
usage information, such as the date and time you visit, the pages, Listings and search results you view, the searches you run, the filters you apply, time spent on pages, clickstream data, and how you interact with emails we send you (including opens and click-throughs); and
general location inferred from your IP address, and, if you enable it on a location-enabled service, more precise location information from your device.
We use this information to operate and secure the Services, to detect fraud and irregular behaviour, to understand how the Services are used, and to improve them.
Information we obtain from other sources
We also receive information about you from:
Stripe and other payment and verification providers, as described above;
business and credit information providers, including ASIC, ABN Lookup, the Personal Property Securities Register, and commercial credit reporting bodies;
sanctions and screening providers, for the purpose of complying with Australian sanctions and export control laws;
social and professional networks you connect to your account, and publicly available business directories and websites;
logistics and freight providers, where a delivery is arranged in connection with an Order;
other Users, including references, feedback and information submitted in a Dispute; and
data and marketing partners, which we may combine with other information we hold about you.
What other Users can see about you
You are not anonymous to us when you log into the Services or post content.
When you publish a Listing, Request for Quote, Quote, comment, review or feedback, or otherwise communicate in a public area of the Services, your User ID, business name, profile information and the material you post are visible and searchable by us, by other Users, and may be publicly available to other internet users, including through search engines.
Once a Sale Contract is formed, we share the information each party needs to perform it, including business name, contact name, phone number, email address, and delivery or collection address.
We strongly encourage you to use caution and discretion when posting, and to consider carefully what you publish — particularly site addresses, security arrangements, access details, serial numbers and asset registers. Cyclio does not control, and accepts no responsibility or liability for, the disclosure or use of personal information that you voluntarily post in a publicly accessible area of the Services.
2. How we use your personal information
We use the personal information we collect to:
Create and administer your account, authenticate you, and verify that you are authorised to act for the business you represent.
Provide the Services, including publishing Listings, matching Buyers and Sellers, facilitating Orders, Offers, Quotes and messaging, and enabling delivery.
Process payments and payouts, including through Stripe, and to ensure Cyclio receives the Fees due to it.
Verify identity and business credentials, including KYC, sanctions and export control screening, ABN and business registration checks, and the issue of Badges.
Assess credit applications and manage Trade Accounts, including debt recovery.
Facilitate and resolve Disputes between Users, including by sharing relevant information with the parties involved.
Detect, investigate and prevent fraud, security incidents, prohibited listings, off-platform circumvention and other breaches of the User Agreement or the law.
Comply with our legal obligations, including tax, anti-money laundering, sanctions, product safety and record-keeping requirements, and to respond to a court, tribunal, regulator or law enforcement agency, or where we reasonably believe use or disclosure is necessary for an enforcement-related activity.
Communicate with you about your account, transactions, Disputes, changes to the Services, and changes to the User Agreement or this Privacy Policy.
Provide customer support and keep a record of our communications with you.
Improve the Services and develop new features, including through research, user questionnaires, testing and feedback requests.
Personalise your experience, including recommending Listings, Requests for Quote, categories and Sellers likely to be relevant to your business.
Market to you, including sending you updates on our services, news and offers, subject to the Marketing section below.
Measure and improve our advertising, including measuring the effectiveness of campaigns and building audiences for marketing.
Produce aggregated and de-identified reporting on marketplace activity, pricing, categories and demand, for internal use and for publication or sharing with partners, advertisers and investors, provided that reporting does not identify you.
Establish, exercise or defend legal claims, and protect the rights, property and safety of Cyclio, our Users and others.
Ratings and reviews
The Services allow you to review your experience dealing with other Users, and they may in turn review you. We compile these reviews into an aggregate rating that appears publicly with your profile. Other Users may rely on that rating when deciding whether to transact with you.
Analytics and profiling
We, or our service providers on our behalf, may collect and combine information about you and your business activity on the Services to identify market segments and to conduct data analytics for marketing, ad measurement, ad targeting, product development and policy development. This may include creating look-alike audiences and measuring the performance of our advertising.
We do not use sensitive information for data analytics.
Automated decision-making
We use automated processes in limited circumstances, including fraud and risk scoring, sanctions and watchlist screening, automated content moderation of Listings, and search and recommendation ranking. Where an automated process could significantly affect you — for example, by suspending your account or declining a transaction — a Cyclio staff member reviews the decision before it is finalised, or you may request human review by contacting us.
[Note for Cyclio: from 10 December 2026, the Privacy Act requires privacy policies to disclose the kinds of personal information used in automated decisions that significantly affect an individual's rights or interests, and the kinds of decisions made. This section should be reviewed and expanded against the final systems in production before that date.]
5. Security and data breaches
Your account is protected by a password. We take reasonable steps to protect your personal information from misuse, interference and loss, and from unauthorised access, modification and disclosure. These steps include access controls, encryption of data in transit, network security measures, and restricting staff access to personal information on a need-to-know basis.
However, we cannot guarantee the absolute security of that information, or that our systems will be free from third party interception or incorruptible from viruses. We cannot guarantee that information you send to us over the internet will be protected by encryption. You transmit your personal information to us at your own risk, and you are entirely responsible for maintaining the security of your password and account credentials.
Notifiable data breaches. If we become aware of unauthorised access to, or disclosure or loss of, personal information that is likely to result in serious harm, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), including by notifying affected individuals and the Office of the Australian Information Commissioner where required.
6. Third parties
The Services may contain links to third party websites, including those of payment providers, logistics providers, verification providers, insurers, advertisers and affiliate partners, or may make available services obtained from third parties.
If you follow a link to one of these websites — for example, Stripe's payment interface — or use a service obtained from a third party through the Services that requires you to provide personal information directly to that third party, note that they have their own privacy policies. You will be subject to that party's terms of use, privacy policy and security statement. We strongly encourage you to review these before disclosing personal information.
Cyclio does not control, and accepts no responsibility or liability for, the privacy practices of, or use of personal information by, any party other than Cyclio, including any User, the operator of any linked website, or any third party service provider to whom you directly provide information.
7. International transfers
Some of the service providers we use store or process personal information outside Australia. This includes:
Stripe, which processes payment and verification data and may store it in the United States and other jurisdictions in which it operates;
cloud hosting and infrastructure providers, which may store data in the United States, Singapore or the European Union;
analytics, advertising, support and communications providers, which may be located in the United States, the United Kingdom, the European Union, Singapore or New Zealand.
Before disclosing personal information to an overseas recipient, we take reasonable steps in accordance with Australian Privacy Principle 8 to ensure the recipient does not breach the Australian Privacy Principles, including by entering into contractual arrangements that require the recipient to handle the information consistently with this Privacy Policy and Australian privacy law.
If you would like more detail about the countries in which your information may be stored, please contact us using the details below.
8. Marketing
When you register you may be given the opportunity to opt in or opt out of receiving updates about our services, news, category alerts and special offers, and those of our partners ("Marketing Material"), via your Cyclio account, email, post or telephone.
You may opt out of Marketing Material at any time. To do so, go to Account Settings → Notification Settings and update your preferences, click the "unsubscribe" link in any marketing email we send you, or email us using the contact details below.
We send marketing communications in accordance with the Spam Act 2003 (Cth) and, where we contact you by telephone, in accordance with the Do Not Call Register Act 2006 (Cth).
Cyclio may contact you as the result of a referral by another User who has provided us with your contact information, such as your name, business name and email address. The use of contact information received through a referral is governed by this Privacy Policy. You may opt out of Cyclio's referral system at any time by emailing us.
Cyclio reserves the right to send you administrative, transactional, safety and account-related messages — including Order notifications, Dispute correspondence, safety or recall notices, and changes to our terms — even if you opt out of Marketing Material.
9. Your rights and choices
Access and correction. You are entitled to request access to the personal information we hold about you, and to request correction of information you consider inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact us using the details below. We will respond within a reasonable period, and generally within 30 days.
We may decline a request to access or correct information in certain circumstances permitted by the Privacy Act — for example, where giving access would have an unreasonable impact on the privacy of others, where the information relates to existing or anticipated legal proceedings, or where the request is frivolous or vexatious. If we refuse, we will give you reasons in writing and tell you how to complain. If we refuse a correction request, we will, if you ask, include a statement with the information noting that you consider it inaccurate.
Deletion and account closure. You may close your account at any time. If you would like us to delete the personal information we hold about you, contact us using the details below. Note that we may be required or permitted to retain certain information — including transaction records, tax records, KYC records, Dispute records and safety-related information — to comply with our legal obligations or to establish, exercise or defend legal claims. Public content you have posted, including reviews you have left about other Users, may remain on the Services in de-identified form.
We also need to prevent information in our systems from being accidentally or maliciously destroyed. Where you delete information from the Services, residual copies on our active servers and corresponding information on our backup systems may not be immediately deleted.
Withdrawing consent. Where we process your information with your consent, you may withdraw that consent at any time. In some circumstances we may still process your information where required or permitted by law, or to exercise or defend legal rights.
Anonymity. Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym where lawful and practicable. It is not practicable for us to provide the Services anonymously, because we must verify Users, process payments and enable Users to transact with one another. You may browse public Listings without an account.
Location information. You can prevent your device from sharing precise location information at any time through your device's operating system settings.
Do Not Track. There is no accepted standard for responding to Do Not Track signals, and we do not respond to them.
10. Retention
We retain your personal information for as long as necessary for the purposes for which it was collected or lawfully further processed, or for as long as necessary in light of our legal obligations or to allow us to pursue, defend or exercise legal claims.
In deciding how long to retain information, we take account of:
legal and regulatory requirements and guidance, including tax, anti-money laundering and corporations law record-keeping obligations;
limitation periods that apply to taking legal action;
our ability to defend ourselves against legal claims and complaints;
the potential for product safety, defect or recall issues to arise years after a transaction;
good practice; and
the operational requirements of our business.
As a general guide, we retain transaction and Sale Contract records for 7 years after the transaction, KYC and verification records for 7 years after the account is closed, and marketing and analytics data for shorter periods.
When we no longer require your personal information, and in accordance with applicable law, we will take steps to delete, destroy or de-identify it.
11. Children's privacy
The Services are for business use only. We do not knowingly collect, maintain or use personal information from anyone under 18 years of age, and no part of the Services is directed at children. If you learn that a person under 18 has provided us with personal information in breach of this Privacy Policy, please alert us using the contact details below.
12. Contact us
If you have any questions about this Privacy Policy or the way we handle your personal information, please contact:
Privacy Officer Cyclio Pty Ltd ACN [ACN] [Registered office address] Email: privacy@cyclio.io
Appendix A. Country specific terms
1. Australian privacy terms
If you are a User whose Cyclio Platform account is in Australia, or the Services are provided in Australia, the following terms also apply to, and may vary, this Privacy Policy to the extent specified.
a. A reference to "personal information" has the meaning given in the Privacy Act 1988 (Cth).
b. A reference to "sensitive information" has the meaning given in the Privacy Act 1988 (Cth).
c. A reference to "credit information", "credit eligibility information" and "credit reporting body" has the meaning given in Part IIIA of the Privacy Act 1988 (Cth).
d. Sensitive information. We do not generally collect sensitive information. Where we collect, use or disclose information that is sensitive information — for example, information relating to a background or police check, or health information provided in the context of a workplace incident or Dispute — we will seek your consent at the time, including for any direct marketing purpose. We will not use or disclose sensitive information for any other purpose unless that purpose is directly related to the primary purpose for which it was collected, or we are required or authorised by law to do so.
e. Credit information. Where you apply for a Trade Account, we handle credit information in accordance with Part IIIA of the Privacy Act 1988 (Cth), the Privacy (Credit Reporting) Code, and our Credit Reporting Policy, which is available on request and sets out the credit reporting bodies we deal with, the information we may disclose to them, and your rights to access, correct and complain about credit information.
f. Access and correction. You are entitled to request access to any personal information we hold about you. To make a request, contact us using the details above. We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, complete and up to date — you can help by telling us if you notice an error and by keeping your account details current. If you consider information we hold is inaccurate, out of date, incomplete, irrelevant or misleading, you are entitled to request correction, and we will take reasonable steps to correct it. We may decline a request to access or correct in the circumstances permitted by the Privacy Act, and if we do, we will give you our reasons. If we refuse a correction request, we will include a statement about your request with the information we hold.
g. Complaints. If you have a question, concern or complaint about this Privacy Policy or how we have handled your personal information, please contact our Privacy Officer using the details above. If you make a privacy complaint:
We will first consider whether there are simple or immediate steps that can resolve it.
If your complaint requires more detailed consideration or investigation, we will acknowledge receipt within one week and endeavour to complete our investigation promptly. We may ask you for further information about your complaint and the outcome you are seeking.
We will then gather the relevant facts, locate and review the relevant documents, and speak with the individuals involved.
In most cases we will respond within 30 days of receiving your complaint. If the matter is more complex or the investigation will take longer, we will let you know.
If you are not satisfied with our response, or you believe we have breached the Australian Privacy Principles, you may complain to the Office of the Australian Information Commissioner (OAIC). The OAIC can be contacted on 1300 363 992 or through the complaint form at www.oaic.gov.au.
h. Notifiable data breaches. We comply with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), as described in section 5 above.

