TOKA AI PTY LTD — ABN 21 687 183 286

Privacy Policy

Effective date: 16 March 2026·Version 1.0 — Pre-MVP release

The short version

We collect data to make Toka work — not to sell ads or build profiles. We store your conversations to improve our services and your experience, but you can opt out or delete your data at any time. We don't share your information with anyone except the services required to run the platform. All data is stored in Australia.

1

Who we are

Toka is a secondhand marketplace operated by TOKA AI PTY LTD (ABN 21 687 183 286), a company registered in Victoria, Australia.

The Toka platform (the "Platform") consists of a mobile application and associated web services available at https://www.gettokaapp.com. When this policy refers to "Toka", "we", "us" or "our", it means TOKA AI PTY LTD.

Privacy contact: Toka Support · support@gettokaapp.com

We are subject to the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained within it. This policy explains how we handle personal information in accordance with those obligations.

2

Scope of this policy

This policy applies to all personal information we collect through:

  • The Toka mobile application (iOS and Android)
  • Our website at gettokaapp.com
  • Communications between you and Toka (including email, phone and in-app support)
  • Interactions with our AI assistant within the Platform

This policy does not apply to third-party platforms or services that you access via links from Toka. Those services have their own privacy policies.

3

Information we collect

3.1 Information you give us

When you create an account or use the Platform, you may provide:

  • Your name and email address (via Google or Apple sign-in, or email magic link)
  • Your profile information, including any photos you choose to upload
  • Listing details you submit as a seller: photos, descriptions, pricing, and location
  • Photos of your space that you share with the Toka AI assistant for style recommendations
  • Messages and conversations you have within the Platform, including with the Toka AI
  • Identity verification information submitted through our verification provider, Stripe

3.2 Information we collect automatically

When you use the Platform, we automatically collect certain technical and usage data:

  • Device identifiers and operating system information
  • App usage data: features used, screens visited, session duration, and interaction patterns
  • Location, used to show you nearby listings (not precise GPS tracking) and other product related tasks
  • Crash reports and error logs to help us identify and fix technical problems
  • Conversational data for model improvement
  • Basic fraud prevention signals derived from usage patterns

We use this information solely to operate and improve the Platform. We do not build advertising profiles or sell usage data to third parties.

3.3 Identity verification data

If you choose to verify your identity on Toka, you will be guided through a verification process operated by Stripe, Inc. During this process, Stripe may collect a government-issued identity document (e.g. driver's licence or passport) and a selfie or biometric facial comparison.

Toka does not store your identity document or biometric data. We receive only a verification result (verified or not verified) and a reference identifier from Stripe. Stripe's handling of your identity data is governed by Stripe's Privacy Policy.

4

How we use your information

To operate the marketplace

  • Create and manage your account
  • Display listings to buyers in your area
  • Facilitate connections between buyers and sellers
  • Coordinate transactions and logistics
  • Respond to your support requests

To power the Toka AI assistant

The Toka AI assistant reads listing details, your conversation history, and any photos you share to:

  • Answer buyer questions on behalf of sellers, using information already provided in the listing
  • Suggest items that match your style preferences or space requirements
  • Guide you through buying or selling steps

We store your conversations with the AI assistant in de-identified form to improve the quality and accuracy of Toka's AI models over time. See Section 6 for details on retention and how to opt out.

To maintain trust and safety

  • Verify user identities to reduce fraud and scams
  • Block non-compliant conversational data to protect users and Toka
  • Analyse usage patterns to detect suspicious or bad-faith behaviour
  • Enforce our Terms and Conditions and Community Guidelines
  • Investigate and resolve disputes

To improve the Platform

  • Analyse usage data to understand how the Platform is used
  • Diagnose and fix technical issues
  • Develop new features and improve existing ones

Legal and compliance

  • Comply with applicable laws and regulations, including the Australian Privacy Act
  • Respond to lawful requests from regulatory or law enforcement authorities

5

Who we share your information with

Toka is not in the business of selling or renting your personal information. We share data only in the following limited circumstances:

Other users of the Platform

When you list an item, your listing details (photos, description, price, and approximate location) are visible to other users. Once a sale is confirmed, precise location details are shared to complete logistics and delivery. Your profile name and verification status may also be visible. Your precise personal contact details are not shared automatically — communication between buyers and sellers happens within the Platform.

Service providers

We use a small number of third-party service providers who process data on our behalf:

Stripe, Inc

Identity verification. Stripe processes identity data under its own privacy policy.

Google Cloud Platform (Australia region)

Cloud infrastructure, storage, and AI services. All data stored on Google Cloud is held in Australian data centres.

These providers are contractually bound to use your data only for the purpose of providing services to us, and to maintain appropriate security measures.

Legal requirements

We may disclose your information if we are required to do so by law, court order, or lawful request from a government authority. Where permitted, we will notify you before making such a disclosure.

Business transfers

If Toka is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

6

Data retention

We retain your information for as long as it is necessary for the purposes described in this policy, or as required by law.

Account information

Retained while your account is active, and for up to 2 years after account closure for legal and fraud prevention purposes.

Listing data

Retained while the listing is active, plus 90 days after it is closed or removed.

Conversation data (with AI assistant)

Active conversations are retained for the duration of the relevant listings. De-identified conversation data used for AI model training may be retained indefinitely in anonymised form.

Identity verification results

Retained for up to 5 years after your last verified transaction, for fraud prevention and compliance purposes.

Usage and analytics data

Retained for up to 12 months in identifiable form, then aggregated and anonymised.

AI training opt-out

You can opt out of having your de-identified conversations used to train Toka's AI models at any time by emailing support@gettokaapp.com. Opting out does not affect your use of the Platform.

7

Your rights

Under the Australian Privacy Act, you have the right to:

  • Access the personal information we hold about you
  • Request correction of information that is inaccurate, incomplete, or out of date
  • Request deletion of your personal information (subject to legal obligations)
  • Opt out of AI model training uses of your conversation data
  • Complain about how we have handled your personal information

To exercise any of these rights, contact us at support@gettokaapp.com. We will respond within 30 days. In some cases, we may need to verify your identity before fulfilling a request.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

8

Deleting your account and data

You can request deletion of your Toka account and associated personal information at any time. To delete your account, use the in-app account deletion flow available in Settings.

Upon deletion, we will remove your personal information from our active systems within 30 days. Some information may be retained in anonymised or aggregated form, or where required by law (for example, transaction records for tax or legal compliance purposes).

9

Security

We take the security of your personal information seriously. Measures we take include:

  • All data is stored on Google Cloud Platform in Australian data centres, using industry-standard encryption at rest and in transit
  • Access to personal data is restricted to authorised team members who need it to perform their role
  • Identity verification is handled by Stripe, a PCI DSS-compliant provider
  • We monitor for unusual activity and maintain fraud detection systems

No method of electronic transmission or storage is 100% secure. If you become aware of a security concern related to your Toka account, please contact us immediately at support@gettokaapp.com.

10

Children and minimum age

Toka is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from users under 16. If you believe a user under 16 has created an account on Toka, please contact us at support@gettokaapp.com and we will take appropriate action.

11

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Post the updated policy at gettokaapp.com/privacy
  • Update the effective date at the top of this document
  • Notify you via in-app notification or email where the changes are significant

Your continued use of the Platform after the effective date of an updated policy constitutes your acceptance of the changes.

12

Contact us

For any questions, requests, or complaints relating to this Privacy Policy or our handling of your personal information, please contact:

Toka Support

Privacy Contact, TOKA AI PTY LTD