Security Policy
We protect what you share with us. Here is how.
The Powour platform handles verified location data, personal information, and earned patron incentives. Security is not an afterthought — it is the precondition for the platform’s credibility. This policy explains the measures we have in place to protect your data, what we expect from you, what happens if something goes wrong, and how to report a security concern to us.
How personal data is collected, used, retained and protected.
Patron obligations, account security, and liability framework.
The principles behind our data practices.
Technical and organisational security measures and incident response.
Scope and purpose
This Security Policy applies to all personal information, verified movement data, and platform data handled by Powour (Pelo Powr Pty Ltd, ABN 92 657 796 864) across the Powour mobile app, web platform, and associated infrastructure. It applies to Powour employees, contractors, technology partners, and institutional operators with access to Powour systems or data.
The data Powour holds is sensitive in two distinct ways. Location and locomotion data is inherently personal — it describes where you are and how you move. Powour Coins represent earned patron value — compromising a patron’s account is a direct financial harm. Both categories demand the same response: proportionate, layered, and continuously reviewed security controls.
Our security principles
Security controls are built into the platform architecture from the ground up — not applied as a layer on top. New features are assessed for security implications before they are deployed.
Access to personal data and platform systems is granted only to the extent necessary for a specific, defined role or task. Broad access is never the default.
No single control is relied upon. Encryption, access controls, monitoring, and vendor obligations work in combination so that a failure in one layer does not expose the whole system.
Security measures are calibrated to the sensitivity of the data they protect. Location data and Powour Coins balances receive stronger controls than general usage analytics.
We tell patrons and partners what security measures we operate, what our obligations are if something goes wrong, and how to reach us if they have a concern. Security through obscurity is not our model.
How we protect your data
The following technical controls are applied across all personal information and movement data handled by Powour.
Encryption in transit. All data transmitted between the Powour app, our servers, and third-party service providers is encrypted using TLS 1.2 or higher. Unencrypted transmission of personal or location data is not permitted.
Encryption at rest. Personal information and verified movement data stored on Powour’s infrastructure is encrypted at rest using AES-256 or equivalent standards.
Data minimisation and retention. We collect only what is necessary to deliver the platform. Verified movement data is retained for 24 months; event-day engagement data for 12 months; account data for 12 months post-closure. Data no longer required is securely deleted or de-identified. Full retention schedules are in our Privacy Policy.
Separation of personal and aggregated data. Personally identified patron data is stored and processed separately from the aggregated, anonymised datasets supplied to institutional operator partners. Institutional operators cannot traverse from an insight to an individual patron record without express patron consent.
Location data handling. Verified movement data — the most sensitive category of data on the platform — is processed in a dedicated pipeline with stricter access controls, shorter operational retention windows, and additional audit logging relative to other data categories.
Infrastructure and platform security
Powour’s platform runs on enterprise-grade cloud infrastructure. The following controls govern how that infrastructure is secured.
Powour’s infrastructure is hosted on enterprise cloud providers with ISO 27001 certification and SOC 2 Type II audit reports. Physical security and availability controls are the provider’s responsibility; logical security is ours.
Production systems operate behind firewalls and network segmentation controls. Inbound access is restricted to defined service endpoints. Management interfaces are not exposed to the public internet.
We conduct regular vulnerability assessments of platform components and apply security patches on a risk-prioritised basis. Critical vulnerabilities are remediated within 72 hours of identification.
Independent penetration testing is conducted at least annually and following material platform changes. Findings are remediated before deployment to production where technically feasible.
Access to personal data systems is logged. Anomalous activity — including unusual login patterns, bulk data access, and unexpected location signals — triggers automated alerts and human review.
Critical data is backed up at regular intervals and stored with the same encryption standards as production data. Recovery procedures are tested periodically to verify recoverability.
Access controls
Access to patron data and platform systems is governed by the principle of least privilege. The following controls apply.
Role-based access. Access rights are assigned based on the specific role of each employee or contractor. Broad administrative access is restricted to a small number of named individuals with documented justification.
Multi-factor authentication. All Powour staff and contractor accounts with access to production systems or patron data require multi-factor authentication (MFA). Single-factor access to sensitive systems is not permitted.
Access reviews. Access rights are reviewed at least every six months and on role change or departure. Permissions are revoked promptly when no longer required.
Institutional operator access. Institutional operators access Powour’s platform through a dedicated operator portal with defined, scoped permissions. Operators can access only the aggregated insight data their agreement entitles them to. Cross-operator data access is architecturally prevented.
Third-party access. Technology partners with access to Powour systems are provisioned with the minimum access required for their service. All partner access is logged and reviewed in line with our vendor security obligations.
Third-party and vendor security
Powour uses third-party technology providers to deliver components of its platform, including locomotion and location processing, cloud hosting, and communication tools. The security of those providers directly affects the security of patron data. Our approach to vendor security is as follows.
Security due diligence. Before engaging a technology provider with access to patron data, Powour assesses the provider’s security posture — including certifications, audit reports (SOC 2, ISO 27001), and data handling practices.
Contractual obligations. All third-party providers with access to personal information are engaged under contracts that include data protection obligations, security standards, breach notification requirements, and data return or destruction obligations on exit.
Data processing agreements. Where a provider processes personal data on Powour’s behalf, a Data Processing Agreement (DPA) is in place consistent with the obligations set out in our Privacy Policy. Providers may not sub-process patron data without Powour’s prior written consent.
Overseas transfers. Some providers store or process data outside Australia. Powour takes reasonable steps to ensure overseas providers handle data to a standard consistent with the Australian Privacy Principles. Current processing locations include the United States of America and Germany.
Ongoing monitoring. Third-party security obligations are reviewed at contract renewal and when a provider notifies Powour of a material change to their infrastructure or data handling practices.
Account security — your responsibilities
Powour’s security measures protect your data at the platform level. Account-level security depends on both Powour and you. Your Powour account provides access to your personal information, movement history, and earned Powour Coins balance. Keeping it secure matters.
Use a strong, unique password. Choose a password you do not use for other services. A password manager makes this practical. Powour will never ask you for your password by email, chat, or phone.
Enable device security. Secure the device on which the Powour app is installed with a PIN, biometric lock, or equivalent. The app accesses your location continuously — a compromised device means compromised location data.
Report unauthorised access immediately. If you believe your Account has been accessed without your authorisation, contact us immediately at security@powour.io. We will investigate promptly, suspend the Account if warranted, and advise you on next steps.
Be alert to phishing. Powour will never send unsolicited messages asking you to verify your account credentials, click an unannounced link, or transfer Powour Coins to another account. If you receive a message that appears to be from Powour but asks for any of these things, do not respond — report it to security@powour.io.
Keep your app updated. App updates frequently include security patches. Keeping the Powour app updated is the simplest thing you can do to ensure you have the latest protections in place.
Incident response and breach notification
Despite best efforts, security incidents can occur. What matters is how quickly and transparently they are handled. Powour operates a documented incident response process aligned to our obligations under the Notifiable Data Breaches (NDB) Scheme in Part IIIC of the Privacy Act 1988 (Cth).
Security events are identified through automated monitoring or manual report. The affected system or data is isolated to prevent further exposure. An incident record is opened.
The nature, scope, and likely impact of the incident is assessed. Incidents are classified as: contained (no personal data exposed); potential breach (personal data may be at risk); or eligible data breach (likely to cause serious harm — NDB Scheme triggered).
Senior leadership and legal counsel are notified. If an eligible data breach is confirmed or likely, preparation of OAIC notification and patron communications begins.
For eligible data breaches, Powour notifies the Office of the Australian Information Commissioner (OAIC) and directly contacts affected individuals as soon as practicable and no later than 30 days after becoming aware.
A post-incident review identifies root cause, corrective actions, and any policy or control updates required. Findings are documented and remediation is tracked to completion.
Patron notifications for eligible data breaches will include: a description of the breach; the types of information involved; what Powour has done in response; what steps affected patrons can take; and contact details for further assistance. Notifications will be sent to the email address associated with the affected Account.
Vulnerability disclosure
If you discover a security vulnerability in the Powour app or platform, we want to hear from you. We commit to the following in return.
Report to us first. Contact security@powour.io with a clear description of the vulnerability, the steps to reproduce it, and the potential impact you have identified. Encrypt sensitive details if possible.
We will acknowledge within 48 hours. We will confirm receipt of your report and provide an initial assessment of severity within two business days.
We will keep you informed. We will notify you when the vulnerability has been investigated and, where a fix is deployed, when it has been remediated.
We will not take legal action. Powour will not pursue legal action against researchers who report vulnerabilities in good faith, act within the scope of this policy, and do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability.
Out of scope. Social engineering, physical attacks, and denial of service testing against Powour’s production systems are outside the scope of this policy. Please do not conduct these activities.
Compliance and legal framework
Powour’s security practices operate within the following regulatory and contractual framework.
APP 11 requires Powour to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. This policy documents those steps.
Powour is subject to mandatory breach notification under Part IIIC of the Privacy Act. Eligible breaches are notified to the OAIC and affected individuals within 30 days.
Institutional operators accessing Powour data are bound by Data Processing Agreements that incorporate security obligations equivalent to those in this policy.
All technology providers with access to personal data are contractually required to maintain security standards consistent with ISO 27001 or equivalent, and to notify Powour of any breach within 24 hours.
Policy updates
This Security Policy will be reviewed at least annually and following any material change to the platform, our infrastructure, or the regulatory environment. Updated versions will be published at powour.io. Material changes will be communicated through the Powour app. The version date above tells you when this policy was last reviewed.
Contact
For security incidents, vulnerability reports, or any questions about this policy, please contact us: