THE LAW Our headquarters are in Australia and we comply with the Australian Privacy Principles Privacy Act 1988 (Cth). The EEA (“European Economic Area”) has legislation that is derived from the EU legislation, the EU Data Protection Directive 95/46/EC, the General Data Protection Regulation (GDPR), the Privacy & Electronic Communications Regulations 2003 (“the PECR”) relating to electronic communications (jointly and severally, “the Law”). We will comply with the requirements of the Law to the fullest extent required by someone operating in a different jurisdiction. We understand that we hold Personal Data for some of you that are in the EEA and comply the requirements of the Law. For the purpose of this policy, “Personal Data” and “Personal Information” are the same and refer to your information – your email, name, IP address, postal address, telephone numbers, and financial transaction information.
Section 1 - What Do We Do With Your Information?
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
Email marketing (if applicable): With your permission, we may send you emails about our store, new products and other updates.
Section 2 - Consent and Contract
Why do you need my information for fulfilling a Contract?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we gain and store your information for fulfilling our contractual obligation and recording your transaction.
How do you get my consent?
When we would like to use your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or, provide you with an opportunity to say no if you are in Australia. If you are in the EEA, we will request express consent.
By signing up to our newsletter or email list, you are giving us permission to store your information for the purposes of providing you with the requested materials.
How do I withdraw my consent?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at any time, by contacting us at email@example.com or mailing us at:
3/154 Flora Street Sutherland New South Wales AU 2232
How long do you hold my data?
We will only keep your personal information as long as we require it and in accordance with the Law and other legal requirements. Authorities may require that we keep your records for a number of years. If we no longer require your information, we will delete the information in a secure manner.
If you have requested your personal information to be erased, or you have indicated you don’t want to hear from us anymore, we will only keep the minimum information in our archives required to abide by our legal obligations and ensure we don’t contact you in the future.
Section 3 - Disclosure
We may disclose your personal information if we are required by law to do so.
If you violate our Terms of Service, we reserve the right to ban you from access to our website, including by IP blocking.
Section 4 - Shopify
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
Payment: If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored for only so long as it is necessary to complete your purchase transaction. Once complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
Section 5 - Third-party Services
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers may process your information to fulfill and deliver orders, process payments or provide support services to us. Where such details are shared, agreements restrict the use of your information for the purpose it is provided and ensure it is stored securely in accordance with the Law.
In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction to us. These include the USA, Australia, Ireland, UK, Canada, Belgium, Finland and the Netherlands. One of our main third-party providers is The Rocket Science Group in the USA d/b/a MailChimp, which provides us with email communication services, certified under the EU-US Privacy Shield Framework approved by the European Commission.
Links - When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
Section 6 - Security
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure your personal information is not inappropriately lost, misused, accessed, disclosed, altered or destroyed. If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
In the unlikely event of a Data Breach, we will determine when we are required to report it in accordance with the Law to both you or the regulating body in the territory and will initiate our Data Breach response plan.
Section 7 - Access to Information
If you would like to transfer your information elsewhere, or correct your information that we retain, you can request access to your personal information that we hold by contacting the details below under Questions and Contact. We will take all reasonable steps to ensure we correct any of your information that is inaccurate, incomplete or out of date.
Section 8 - Age of Consent
By using this site, you represent that you are at least the age of majority in your state or province of residence.
Section 9 - Cookies Policy
Cookies are small amounts of information that store information on your computer when you visit our website.
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you do not want these cookies. Some cookies are functional and you may not be able to complete your transaction if you do not allow them.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer. cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
Statistical cookies are provided by Google Analytics and are first party cookies. The data obtained is not shared with any third party. The information obtained cannot be used to identify you and is anonymous.
Cookies make it easier for you to log on to and use the site during future visits. They also help to monitor website traffic and to personalise the content of the site for you but will not store save or collect personal information.
You may set up your computer to reject cookies however, in that case, you may not be able to use certain features on our site.
How to manage your cookie settings
Many web browsers such as Internet Explorer, Google Chrome or Safari, will allow some control over cookies through their settings. To manage your cookie settings, please refer to your browser software. For more information about cookies and how to delete them, visit www.aboutcookies.org or www.allaboutcookies.org
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
Questions and Contact Information
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at firstname.lastname@example.org or by mail at:
[Re: Privacy Compliance Officer]
3/154 Flora Street
Sutherland New South Wales AU 2232
You also have the right to lodge a complaint with the Governing Authority for Data Protection and Privacy Compliance. In Australia it is:
Office of the Australian Information Commissioner
GPO Box 5218
Sydney NSW 2001
Enquiries Line 1300 363 992.