TGToken Gesture

Governance

Legal, Privacy & Compliance

How Token Gesture operates, the terms that apply to merchants and to this site, and the disclosures a high-risk payments gateway owes the people it underwrites.

Privacy Policy

Due nowBlocked on entityDraft — never published

Gallantree Pty Ltd, trading as Token Gesture, handles personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy describes what we collect when you apply for underwriting, what we do with it, and who else sees it.

We never hold card numbers. Card entry happens on the processor’s hosted payment page, not on our infrastructure. No cardholder data is stored, processed or transmitted by us, which is also why our PCI scope is SAQ-A.

1. What we collect, and when

When you apply

As the application proceeds

Automatically

Server logs — IP address, user agent, the paths requested — retained for retention period to confirm. The public site sets no cookies, uses no analytics and embeds nothing from a third party; the merchant portal and the admin console set a session cookie so you stay signed in. If that changes we will say so here on the day it changes.

2. Two things we do not do

3. Your prior processor

When you continue past the first step of the application, you agree that we may contact your previous processor for a reference. We ask them what they saw: volumes, dispute ratio, and why the relationship ended. We do this because a high-risk file cannot be underwritten on self-reported numbers alone, and because finding out later is what actually ends applications.

We will tell you who we intend to contact. If you would rather we did not, say so — it does not end the application, but it changes what we can conclude from the file.

4. MATCH

MATCH — Mastercard’s Member Alert to Control High-risk Merchants — lists merchants whose processing relationship was terminated for cause, and a listing persists for five years. Where we act as a sub-merchant sponsor under an acquirer, we may be required both to query MATCH before boarding and to report a termination to it.

We will not report you to MATCH without first telling you in writing what we intend to report and why, and giving you notice period to confirm to respond. An entry that already exists against you is a fact in the file. It changes which rate card you land on, not whether we read the rest.

5. Who else sees it

RecipientWhat they receiveWhere
Acquiring bankUnderwriting file, identity documents, processing historyTo confirm
Verotel International B.V.Transaction and subscription data while Verotel is merchant of recordNetherlands
MongoDB AtlasAll application and subscription recordsRegion
RailwayApplication hosting, server logsRegion
Your prior processorA reference request naming your entityVaries

Several of these are outside Australia, so APP 8 applies: before disclosing your information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles. We do not sell personal information, and we do not disclose it for marketing.

6. How long we keep it

7. Security

Access to merchant data is restricted to staff who need it, and administrative actions are written to an audit log. API keys authenticate a service rather than a person and belong on a server; if one is exposed in a browser bundle, rotate it and tell us. Processor postbacks are signature-verified before they are processed and deduplicated by processor event ID.

8. Access, correction and complaints

You can ask for a copy of what we hold about you and ask us to correct it. Write to privacy officer and address to confirm. We respond within 30 days.

If you are not satisfied with how we handled it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

9. Data breaches

If a breach is likely to cause you serious harm we will notify you and the OAIC as soon as practicable, as the Notifiable Data Breaches scheme requires, and tell you what happened, what was exposed and what to do about it.