Privacy Policy
Powour exists to convert verified everyday movement — walking, cycling, public transport — into measurable commercial, health and environmental outcomes. Doing that well requires us to collect and use personal information responsibly. This policy explains what we collect, why we collect it, who we share it with, and what rights you have. We have written it in plain language because that is what you deserve.
About us
Powour (Pelo Powr Pty Ltd, ABN 92 657 796 864, trading as Powour) is an Australian technology company headquartered in Sydney, New South Wales. We operate a verified movement platform that serves two connected audiences: patrons who use our app to earn value from their everyday movement, and institutional operators — including venue operators, sporting organisations, transport authorities, and event operators — who use our platform to derive operational and commercial insights from aggregated patron movement data.
This Privacy Policy applies to personal information we collect through our mobile application, our web application platform, and our website (together, our Services). It applies to all users — whether you are a patron using the Powour app or an individual engaging with us in a business context.
Definitions
Information or an opinion about an identified individual, or an individual who is reasonably identifiable — whether true or not, and whether recorded in a material form or not.
A higher-protection subset of personal information. Includes racial or ethnic origin, health information, biometric data, political opinions, religion, sexual orientation, and criminal records.
Locomotion and location signals used to confirm that a patron has walked, cycled, or used public transport — the core verification event underpinning the Powour platform.
Organisations that partner with Powour to access aggregated, anonymised movement insights — venue operators, sporting organisations, transport authorities, and event operators.
What personal information we collect
We collect personal information that is necessary to provide our Services. The categories below describe what we may collect depending on how you use the Powour platform.
Your name, email address, and telephone number, collected when you register for a Powour account or contact us directly.
Location and locomotion data collected via your device operating system and, where applicable, through our technology partner Sentiance. This includes real-time and historical location signals, transport mode detection (walking, cycling, public transport), step count, and movement patterns. This data is the foundation of the Powour verification engine. See Section 06 for a full explanation of why and how we collect this data.
Browser session data, device and network information, page view and session statistics, operating system type, domain name of your internet service provider, and information about your access to and use of our Services — including through cookies and similar technologies.
Where you use the Powour app in connection with an event or venue, we collect data about your arrival timing, transport mode to the venue, dwell patterns within the precinct, and app engagement during the event period.
Information you provide when you contact us — including through our website contact form, email, or our online chat — and records of those communications.
We do not actively request sensitive information. If we ever need to collect sensitive information about you, we will first obtain your explicit consent and will only use or disclose it as required or authorised by law.
How we collect personal information
Directly from you — when you register for an account, complete our contact form, or engage with us by email, chat, or telephone.
Through the Powour app — when you use the app, including movement verification events, venue check-ins, and reward redemptions.
From technology partners — including Sentiance, who provides us with location and locomotion data to support movement verification. For information on Sentiance’s privacy practices, please review the Sentiance Privacy Policy at sentiance.com.
From analytics and measurement providers — including Google Analytics, which we use to understand how our website and app are used. See Section 09 for details on cookies and analytics.
Why we collect personal information — our purposes
We collect and use personal information only for the purposes described below. We do not repurpose data collected for one purpose to serve an unrelated purpose without first obtaining your consent.
Powour uses verified movement data to support personal health outcomes. Walking, cycling, and active transport data supports the Hour of Powour reward cycle and provides patrons with a verified record of their everyday movement activity.
Powour uses verified transport mode data to generate Scope 3 emissions attribution — quantifying the carbon reduction associated with active and public transport choices. This data is supplied in aggregated, anonymised form to transport authorities and environmental programme operators.
In addition to these core purposes, we collect and use personal information for the following:
Account and service delivery — to create and manage your Powour account, provide access to the app, and deliver the Services you have requested.
Reward verification and issuance — to verify that movement qualifying events have occurred, calculate earned Powour Coins, and process reward redemptions.
Venue and event insights — to generate aggregated, anonymised operational insights for institutional operator partners.
Communications — to contact you about your account, your use of the Services, and, where you have consented, about Powour products and updates.
Safety, security and fraud prevention — to detect and prevent fraudulent or unauthorised use of the platform and to ensure the integrity of the movement verification system.
Internal administration — for record keeping, invoicing, analytics, and improving our Services.
Legal compliance — to meet our obligations under applicable law, and to establish, exercise, or defend legal claims.
Location and movement data — a specific explanation
Location and locomotion data is central to what Powour does. We are transparent about how and why we collect it. Powour collects precise location data via your device operating system when the Powour app is open — including when the app is running in the background — for the following purposes:
Movement verification. Confirming that walking, cycling, or public transport use has occurred is the core function of the platform. Without active location and locomotion sensing, movement cannot be verified, Powour Coins cannot be awarded, and the platform’s health and environmental outputs cannot be generated. Background collection is necessary because movement events — including transport boarding — occur continuously throughout the day, not only when the app is on-screen.
Scope 3 transport attribution. Verified transport mode data — distinguishing between walking, cycling, public transport, and private vehicle use — is the underlying data that supports carbon emission calculations supplied to transport authorities and environmental programme operators.
Venue arrival and precinct signals. Where you attend an event or venue at which Powour operates, location data is used to detect arrival timing and movement within the venue precinct, enabling the match-day unlock and providing aggregated arrival insights to the venue operator.
Platform integrity. Location data is used to detect anomalous patterns that may indicate fraudulent movement claims or unauthorised use of the reward system.
If you do not want Powour to collect your location data, you can disable location services in your app settings or in your device settings. If you do this, we will not be able to verify your movement or provide the core features of the Powour platform to you.
Disclosure of personal information — third parties
We may disclose personal information to the following categories of third parties.
Third parties who help us deliver our Services, including: locomotion and location technology providers (including Sentiance); cloud hosting and data storage providers; CRM and communication platforms; payment systems operators; professional advisers including lawyers, accountants, and auditors; and IT maintenance and security providers. These providers are engaged under contracts that require them to handle personal information in accordance with Australian privacy law.
Powour partners with institutional operators to deliver our platform. We do not provide institutional operators with raw individual patron data. Operators receive aggregated, anonymised insights — patterns about collective patron behaviour, not personal profiles. Where an institutional operator requires access to personally identified data for a specific purpose, that access is permitted only where the affected patron has expressly consented to it. All institutional operator data relationships are governed by written data processing agreements.
Access aggregated arrival timing, dwell, and F&B engagement insights across their venue estate.
Receive mode-shift and patron flow data for their event portfolio as commercial buyers of attribution data.
Access verified Scope 3 transport data and mode-shift attribution under regulated data supply agreements.
Use arrival pattern and engagement data to manage congestion, timing, and commercial activation at multi-use precincts.
In respect of the personal information you provide directly to Powour through the app or website, Powour acts as a data controller. In respect of patron behavioural data that Powour processes on behalf of institutional operator partners, Powour acts as a data processor — operating under the instructions and accountability of the operator. For operator-commissioned processing, the operator retains primary responsibility for ensuring that the underlying data collection is lawful.
We use Google Analytics to understand how our website and app are used. You can opt out via the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.
We may disclose personal information to courts, tribunals, regulatory authorities, and law enforcement agencies where required or authorised by law. If Powour’s business or assets are transferred to another entity, personal information may be disclosed to that entity subject to appropriate confidentiality obligations.
Overseas disclosure
Some of our third-party service providers store, transfer, or access personal information outside of Australia, including in the United States of America and Germany. Where personal information is disclosed overseas, we take reasonable steps to ensure that the recipient handles it in a manner consistent with the Australian Privacy Principles. By using our Services, you consent to the disclosure of your personal information to overseas recipients in the circumstances described in this policy.
Cookies and analytics
We use cookies and similar technologies on our website and app. Cookies are small text files placed on your device by your browser. They help us recognise returning users, understand how our Services are used, and deliver relevant content.
We use first-party cookies for essential site functions and analytics. We use Google Analytics, which may place first-party and third-party cookies to measure usage patterns. We do not use advertising cookies, retargeting pixels, or third-party tracking technologies for the purpose of targeting commercial advertising at individual patrons.
You can control cookies through your browser settings. For mobile devices, you can manage location-based and app tracking permissions through your device operating system settings.
Children and young people
Powour’s platform is designed for adults aged 16 and over. We are aware that the events, venues, and sporting occasions at which Powour operates attract significant numbers of children and young people. We do not knowingly collect personal information from individuals under the age of 16 without verifiable consent from a parent or legal guardian.
If you are a parent or guardian and believe that Powour has collected personal information relating to a child under 16 without appropriate consent, please contact us immediately at privacy@powour.io. We will investigate promptly and take steps to delete the information if we cannot verify that consent was properly obtained. Venue and event operators who partner with Powour at events likely to attract minors are required under our operator agreements to ensure appropriate consent and age-verification processes are in place.
How long we keep your information
We retain personal information only for as long as it is necessary for the purposes described in this policy, or as required by law. The table below describes our standard retention periods. Note the distinction between raw location traces (deleted at 60 days) and verified movement records (retained for Scope 3 and audit purposes). See Section 14 for what happens to each data category when you delete your account.
| Data category | Retention period |
|---|---|
| Account and identity data | Duration of active account, plus 12 months following account closure or last active use. On account deletion, personal identifiers are permanently de-identified — see Section 14. |
| Raw location data (detailed GPS traces) NEW | 60 days from collection, after which raw location logs are permanently deleted. Verified movement records derived from these traces are retained separately. |
| Verified movement data (processed records) | 24 months from the date of collection, to support annual Scope 3 emissions reporting cycles and reward verification audits. Retained in de-identified form after account deletion. |
| Event and venue engagement data | 12 months from the relevant event date, after which data is deleted or de-identified for use in longitudinal aggregate analysis. |
| Communications and support records | 3 years from the date of the communication, or longer where required for dispute resolution or legal compliance. |
| Analytics and usage data | 14 months, consistent with Google Analytics default retention settings, unless de-identified earlier. |
| Scope 3 and transport attribution data | Retained in de-identified, aggregated form for up to 7 years to support longitudinal emissions reporting. No personally identified data is retained beyond 24 months. |
| Transaction, reward and audit records NEW | Retained for as long as required by law or for legitimate business purposes, including Powour Coins transaction records and reward redemption audit trails. |
When personal information is no longer required, we take reasonable steps to destroy it securely or to de-identify it so that it can no longer be associated with you.
Storage and security
We are committed to keeping your personal information secure. We have implemented physical, electronic, and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These include access controls and the principle of least privilege across our systems, encryption of data in transit and at rest, and contractual security obligations on all third-party service providers. Our Security Policy, available at powour.io, sets out the technical and organisational measures in full.
Despite these measures, no internet-based platform can guarantee absolute security. The transmission of information over the internet is at your own risk. If you become aware of any security concern relating to your Powour account, please contact us immediately at privacy@powour.io.
Your rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights in relation to personal information we hold about you. To exercise any of these rights, contact us using the details in Section 17. We will respond in writing within 30 days.
You may request access to the personal information we hold about you. An administrative fee may apply. We will respond within 30 days. In limited circumstances, we may be legally permitted to withhold access.
If information we hold is inaccurate, out of date, or incomplete, you may ask us to correct it. We will take reasonable steps to do so promptly.
You may ask us to delete your personal information. See Section 14 for the full account deletion process and what happens to each data category.
You may withdraw consent to data collection at any time through the app settings or by contacting us. Withdrawing location consent will limit core platform features.
You may unsubscribe from marketing communications at any time using the opt-out link in any communication we send, or by contacting privacy@powour.io.
Account deletion and data retention on closure
You can delete your Powour account at any time. Account deletion is permanent and cannot be reversed. The following explains how to delete your account and exactly what happens to each category of your data when you do.
Your name, email address, phone number, home location, and other personal identifiers in your account record are permanently de-identified so that the record can no longer be linked to you. This process is irreversible.
Your login credentials are permanently removed and you are immediately unsubscribed from all Powour marketing systems and communications.
Detailed GPS location traces are permanently deleted within 60 days of your account deletion request. This is the most granular location data the platform holds and it is not retained in any form after this window.
Verified movement records — trip summaries, mode-shift data, and Hour of Powour activity records derived from your movement — are retained in permanently de-identified form for analytics, service improvement, and Scope 3 reporting purposes. Once de-identified, this data is no longer personal information about you and cannot be re-linked to your identity.
Records of Powour Coins transactions, reward redemptions, and platform audit trails are retained for as long as required by law or for legitimate business purposes including fraud prevention, financial reconciliation, and regulatory compliance. These records are held in compliance with our legal obligations and are not used for any purpose unrelated to those obligations.
Where we are required by law to retain specific records — including under tax, financial services, or regulatory obligations — those records are retained for the legally required period regardless of account deletion. They are stored with access controls that prevent use for any purpose beyond legal compliance.
Account deletion requests made by email are processed within 30 days. You will receive a confirmation email when your account has been deleted and your personal identifiers have been de-identified. If you do not receive confirmation within 30 days, please follow up at support@powour.io.
Complaints
If you have a complaint about the way Powour has handled your personal information, please contact our Privacy Officer at privacy@powour.io with full details of your complaint. We will investigate promptly and respond in writing, setting out the outcome of our investigation and any steps we will take in response.
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC). The OAIC handles complaints about breaches of the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can contact the OAIC at oaic.gov.au or by calling 1300 363 992.
Powour is subject to the Notifiable Data Breaches (NDB) Scheme under Part IIIC of the Privacy Act. In the event of an eligible data breach that is likely to result in serious harm, we will notify both the OAIC and affected individuals as soon as practicable.
Updates to this policy
We may update this Privacy Policy from time to time to reflect changes to our platform, our data practices, or applicable law. We will publish the updated policy on our website and, where changes are material, we will notify you through the Powour app. The version date at the top of this page tells you when the policy was last updated. We recommend reviewing it periodically.
Continued use of our Services after a policy update constitutes acceptance of the updated policy.
Contact
For any privacy questions, access requests, corrections, account deletion requests, or complaints, please contact our Privacy Officer: