Privacy Policy

As at   06 March 2020

1. About this policy

Your privacy is important to us. We recognise the trust you are placing in us and we are committed to protecting your personal information. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth) and the Information Privacy Principles in the Privacy Act 1993 (NZ).       

This Privacy Policy applies to the handling of personal information collected through the Whatsmine website and application (together the Site). The Site is owned and operated by WhatsMine Pty Ltd (ACN 625 900 576) (WhatsMine), which is a wholly owned subsidiary of Scentre Group Limited (ACN 001 671 496) (Scentre Group).

We may vary our Privacy Policy from time to time. We will notify you of any changes by publishing the latest version of the policy at and via settings within the Site.

2. Collecting your personal information

Types of personal information we collect

The personal information we collect includes: 

  • your loyalty program membership details including membership number;

  • your name, date of birth and gender;

  • your contact details including email address, phone number and address;

  • information generated when you use and access the Site such as your IP address, MAC address, your fully qualified domain name, device identifier, geolocation information, the web browser you use, the pages you accessed, and the URL of the referring website and the date and time you used the Site or any feature within the Site in connection with any third party offers or promotions.

How we collect your personal information

We collect personal information directly from you when you:

  • set up a membership on the Site;

  • upload or add details of your third-party loyalty program and benefit memberships;

  • subscribe to our newsletters or register your interest in receiving communications about goods, services and events or other marketing and offer notifications;

  • tell us about your experiences as a Site user by completing a customer service report or survey;

  • participate in any one of our offers, surveys, promotions or competitions;

  • download other mobile applications which we may develop from time to time;

  • enable email scanning functionality which allows us to scan your inbox for loyalty program details and rewards;

  • register, login to, or update the settings on your app account using our online services;

  • tell us about any other matter by contacting us directly.

We may also collect personal information about you indirectly from:

  • publicly accessible social media posts;

  • third-party social-networking sites including Facebook, Instagram, Twitter or Google+ where you have linked your account on the Site and consented to the collection of your personal information;

  • cookies which track your visits to the Site and our websites;

  • Scentre Group.

We may also collect information from you including the date and time you use the Site or any feature within the Site in connection with any third party offers and promotions.

Suppliers / providers

If you, or a company you work for, supplies goods or services to us, then we may collect personal information about you in connection with the provision of those goods or services. This information may include your name, contact information, and any other information you provide, or provided on your behalf, as part of our compliance processes. This information will be used for the purposes of managing the provision of those good or services.

3. How we handle your personal information

We collect, hold, use, and share your personal information for purposes including:

  • enabling access to the Site and the functions and services provided by the Site;

  • contacting you about events, activities, promotions, and our other activities relating to us, Scentre Group and other third parties;

  • sending you personalised deals, offers and discounts, surveys and other marketing materials based on your personal information, including location or known web usage (more information about our marketing activities is outlined below);

  • determining which membership and benefits programs are the most popular and where users spend most of their time;

  • measuring user numbers, characteristics and demographics, and analyse user behaviour in order to continuously improve the Site and otherwise in connection with our business;

  • generating business insights about the operation of the Site; and

  • enabling email scanning to easily find and upload membership details.

You may continue to use WhatsMine without setting up a user account. However, we will not be able to link your data to your profile so you may lose access to all your saved loyalty programs, barcodes, and rewards and any information in relation to any third party offers or programs which would allow you to participate in such offer or program within the app if you delete and reinstall the app or switch phones. It may also reduce our ability to serve you the most relevant and rewarding offers based on your profile. Combining the information we collect

We may combine, link and connect personal information and other information that we hold about you. If you download or otherwise access the Site, you may choose to provide other information (both personal or non-personal) that can be associated to you or the device on which you are accessing the Site. For example, we may link a device identifier with other personal information that we collect and hold about you. The combined information will be handled as described in the Privacy Policy.

How we use aggregated/anonymised data

We may use anonymised data, including user demographics, interests and behaviours, to inform our promotional and marketing strategies, for research and customer segmenting purposes, and for other purposes as described in this Privacy Policy. 

Research we compile on an aggregate basis may be shared with Scentre Group, our affiliates, agents and business partners. This aggregate information does not identify you personally. We may also disclose aggregated information in order to describe our services to current and prospective business partners, and to other third parties for other lawful purposes.

How we share your personal information

We understand how important it is to keep your personal information private. We only share personal information in ways outlined in this Privacy Policy, or where we are required or authorised to by law. We may routinely share your personal information with: 

  • Scentre Group;

  • our service providers who facilitate the operation of the Site and provide analytics and insight services;

  • third party loyalty and benefit program providers;

  • other joint venture and commercial partners; and

  • government agencies as part of our statutory obligations.

Scentre Group disclosures

As noted above, we are a wholly owned subsidiary of Scentre Group and we may share your personal information collected within the WhatsMine app with Scentre Group for the purposes of building a universal profile to better serve up more personalised and relevant offers back to you. This may occur, for example, whilst you are in one of our shopping centres. Your data will be transferred and stored securely and will be handled in compliance with both WhatsMine and Scentre Group Privacy Policies. Any direct marketing to WhatsMine customers by Scentre Group will be subject to your explicit consent. 

Third party loyalty and benefit program provider disclosures

As part of some promotions and campaigns we run with loyalty program providers, we may share your loyalty program  membership number with the relevant program provider so they can match it against their database to better understand your engagement with their loyalty program. 

We may also share aggregated and de-identified data on the campaign including number of program cards added, number of times rewards favourited and number of rewards clicked. This allows the provider to optimise their campaign and offer the most relevant and compelling rewards on WhatsMine. Your data will be shared securely and personal information held by the provider will be subject to their privacy policies. 

Overseas disclosures

We may need to share your personal information with organisations or persons located outside of Australia and New Zealand. The countries in which these organisations or persons are located will depend on the circumstances, but in the course of our ordinary operations, we routinely transfer personal information to recipients in Australia, New Zealand, the United States of America and the United Kingdom. 

We also use cloud service providers that may store personal information on servers located worldwide, but only in countries that have an equivalent level of privacy protection to Australia.

4. Marketing and your personal information

We use your personal information to send you personalised deals, offers and discounts, surveys and other marketing materials. You will only receive marketing material from us if you subscribe to our notification service. We may send out email newsletters or other notifications to keep you informed of changes relating to the Site, including the latest offers, current promotions and specials in connection with third party loyalty programs or our business. 

We may contact you if a friend shares an offer from the Site. The offer will be sent to you from your friend on our behalf via a digital communication channel of their choice including email, SMS and social media. We do not record your personal contact information in these circumstances so you will not receive subsequent communication from us unless you subscribe separately.

If you contact us to request information about our services, you will not be added to a mailing list of any kind without your consent. We will only contact you in relation to the matter that you have contacted us about. 

If you no longer wish to receive email newsletters or notifications, you may unsubscribe either by clicking the “unsubscribe” link at the bottom of any email newsletter you receive, by updating your preferences in account settings, or by emailing

Advertisers and providers on our Site

From time to time, we may allow advertising or sponsored content on the Site from third parties. Please note that, if you leave the Site either by clicking on an advertisement or a link to a third-party website, the privacy policy of the third party will apply to the handling of your personal information. In addition, many business advertisements and other content may be managed and placed on our Site by third parties. These "network advertisers" collect non-personal information when you click on or scan one of their banner advertisements. The network advertisers collect this information so that they may show you ads that are more relevant or interesting to you.  

On occasion, the Site may also provide content that is created by a third-party partner website. In some instances, the third-party sites will collect information in order to facilitate the transaction or to make the use of their content more productive and efficient. In these circumstances, the information collected is shared between us and our third-party partners.

5. How we use cookies

A cookie is a text file placed into the memory of your computer by us or third parties such as those outlined above. A copy of this text file is sent by your computer whenever it communicates with (WhatsMine website). We use cookies to identify you between multiple visits, to better understand how the WhatsMine website is used, and to provide you information which may be of interest to you based on your previous visits to it. We also use cookies to provide targeted advertising to you (including through ad servers and other third party advertisers) when you visit the WhatsMine website and certain other websites where advertising is found from time to time. We may provide the information we gather from cookies to third parties for these purposes.  

If cookie information is linked with personal information we hold about you as set out above, this cookie information becomes personal information and will be treated in the same manner as the personal information to which it has been linked.  If you do not want ad servers or other third-party advertisers to use cookies to provide you with targeted advertising, we suggest you configure your browser to block cookies or use an opt out mechanism which can be found on:

You do not have to accept cookies and you can set up your browser to notify you when you receive cookies. This will give you the opportunity to decide whether to accept the cookies. If you choose to disable cookies, you may not be able to access certain features of the Site.

6. How we hold and protect your personal information

The personal information that we collect is held securely in computer systems or in a database (which may be hosted by us or a third party on our behalf). These databases are protected by a firewall and encrypted at rest and are not directly accessible from the public internet. Database access keys are encrypted and stored securely. Any transfer of personal information over the internet is done securely via SSL encryption. Personal information made available to staff, or other third parties, will only be for the purposes outlined in this Privacy Policy. 

The electronic environments are monitored by us and third-party specialist security monitoring companies. We review our security arrangements regularly and implement improvements when necessary.

We keep your personal information only as long as necessary to achieve the purpose for which we collected it. Once we no longer need your personal information, it will be securely and irretrievably destroyed or de-identified.

7. Your rights

Accessing and correcting your personal information

You have a right to request access and correction of the personal information that we hold about you. If you wish to access, update or correct your personal information held by us, please contact us on

Deactivating and deleting your account

When you delete the app from your phone, we are not notified and your account therefore remains active. This means that your personal information continues to be stored in our database. After a period of inactivity, we may deem that you are no longer an active user but will continue to store your account details in case you choose to reactivate and re-engage with your account later on. After 5 years of inactivity, we will close your account and erase your personal information from our database permanently. We will retain de-identified activity data to enable us to undertake historical data analysis. 

You may request permanent deletion of your account and personal information at any time by emailing with this request. We will action this within a reasonable time and all your personal information will be erased from our systems. We will retain de-identified activity data to enable us to undertake historical data analysis. 

Making a privacy complaint

If you would like to make a complaint about how we have handled your personal information or would like to discuss any aspect of this Privacy Policy, you can contact us at:

Phone:  +61 408 224 409


Post: Privacy Manager, Level 30, 85 Castlereagh St, Sydney, NSW, 2000

We will endeavour to investigate and provide an initial response to the complaint within 5 business days. If you are not satisfied with our response to your complaint, you may complain to the Office of the Australian Information Commissioner (OAIC) by contacting:

Phone:  1800 620 241


Post: GPO Box 5218, Sydney NSW 2001