2. Collection of personal information
We may collect your personal information throughout the course of your interaction with us (for example, if you obtain products or services from us, subscribe to our mailing list, fill out an online contact form, engage with our online marketing or submit an enquiry to us). The personal information that we may collect and hold about you depends on your dealings with us. Generally, we may collect:
- your name and address, email address, telephone number and fax number;
- payment details;
- business details; and
- other personal information that we require or that you volunteer to us (such as your resume, details of your qualifications, skills, education provider, work history and residency status in the event that you apply for employment or a position with us).
Generally speaking, we collect personal information so that we can provide better services to you and ensure that you have convenient access to our services.
We will collect your personal information directly from you unless it is unreasonable or impracticable to do so. If circumstances require, we may collect personal information about you from third parties (such as your employees, representatives or personal referees) or publicly available resources. All personal information we collect is limited to that which is reasonably necessary for our functions or activities.
If you fail to provide personal information requested by us, or if the personal information you supply is incorrect or incomplete, there may be a range of consequences, for example we may be unable to process or respond to your request. There will not usually be Australian laws or court/tribunal orders which require or authorise us to collect your personal information.
The type of personal information we collect will depend on your dealings with us and your use of the Services. For example:
▪ your contact details or those of individuals at your organisation (such as names, telephone numbers and email addresses) to enable the provision of services and to facilitate our relationship with you, including relevant marketing.
Prospective employees and contractors
Referees and Emergency Contacts
3. Use of personal information
We will generally only use your personal information for the purpose for which we collected it, and for related purposes we consider would be within your reasonable expectations.
We generally use personal information for the following purposes (as applicable in the circumstances):
- to provide products or services to you or for your benefit;
- to provide information that you request, to respond to your enquiries, or otherwise achieve
the purpose for which you have contacted us;
- to handle payments;
- to provide you with marketing and promotional material regarding our or users of our Services' products or services, including newsletters or other materials;
- to seek feedback from you and perform market research, so that we can gauge your satisfaction with our products or services;
- enable and assist Marketplace Owners to:
- onboard and manage vendors on our platform;
- collect specific information from vendors to determine if the vendor qualifies to join the platform;
- attributes for vendors that can be used to search, filter, find and engage that vendor on the platform;
- enable and assist to:
- facilitate sign up of customers to the marketplace;
- facilitate transactions between customers and vendors on the marketplace;
- facilitate bookings to be taken on the marketplace;
- enable transactions and fulfilment of services between vendors and customers on the marketplace;
- enable collection of payment information and processing of payment information on behalf of customers on the marketplace;
- facilitate payments, payouts and disbursements to the vendors on the marketplace;
- facilitate support, triage and other help services for both vendors and customers on the
- for our general business operations (such as maintenance of our business records and compliance with our legal and insurance obligations); and
- to engage in other activities where required or permitted by law.
By providing us with your personal information, you consent to us using your personal information
for these purposes.
You agree that we may send you marketing or promotional communications by post or by electronic means (including email and SMS). You may request not to receive such material from us by contacting us via the details below or by using the opt-out function provided for in those communications. If you do not opt-out in either of these ways you will be taken to have consented to receiving such communications from us.
There are no consequences of opting-out of receiving our marketing and promotional communications except that you will no longer receive them, and you may elect to re-join our marketing list at a later stage if you wish.
Where we propose to use your personal information for a purpose other than as outlined above, we will seek your permission (unless we are required or permitted by law to do so without seeking consent).
4. Storage of personal information
We take reasonable steps to protect your personal information from misuse, interference and loss as well as unauthorised access, modification or disclosure.
For example, information stored on our computer network is protected by security features and procedures. We undertake regular monitoring of our practices and systems to ensure the effectiveness our security policies and identify and implement improvements where appropriate.
We make use of cloud-based services for our business systems. Our data may be stored with these cloud providers in locations outside of Australia, including South East Asia, Europe and the Americas, depending on where the specific marketplace is located.
Generally, we will take reasonable steps to destroy or permanently de-identify your personal information as soon as it is no longer required by us or another user of the Services, for example Marketplace Owners or vendors. We may retain your personal information where we are required or permitted to do so by law, such as for insurance, legal or corporate governance purposes and for the prevention of fraud. Your personal information may also be retained in our IT system back- up records.
5. Disclosure of personal information
We will generally only disclose your personal information for the purpose for which we collected it, and for related purposes we consider would be within your reasonable expectations.
We may disclose your personal information to the following third parties (as applicable in the circumstances):
- Marketplace Owners and vendors. We generally require Marketplace Owners and vendors to ensure that information we disclose is only used for the purposes for which we collect it;
- certain suppliers that provide services to us (for example, subcontract product manufacturers, market research companies or other service providers). We generally ensure such organisations are contractually required to ensure that information we disclose is used only for the limited purposes for which we provide it;
- contractors that we engage as part of providing services to you; or
- members of our corporate group.
We are not generally likely to disclose personal information to overseas recipients, except with your consent or where we are required to or authorised to do so by law. Please see part 9 below for further information.
6. Access to and correction of personal information
You may contact us to request access to or correction of the personal information we hold about you. We may refuse to allow access or to amend your personal information if we are legally required or entitled to do so. If we do so, we will provide you with written reasons for the refusal (unless it is unreasonable to do so) together with information about the options available to complain about the refusal.
We may require you to pay certain costs in order to access your personal information held by us. We will advise the amount payable (if any) once we have assessed your application for access. We will not however charge a fee for you to lodge a request for access to or correction of your personal information.
If you lodge a request for access to your personal information, we may fulfil that request in any of a range of ways (for example, by supplying you with a copy of that personal information or providing you with the opportunity to inspect our records). We may require you to comply with certain procedures before we allow access to or amendment of your personal information to ensure the integrity and security of information that we hold. Depending on the nature of your request, this may include completing a personal information request form or otherwise verifying your identity to our satisfaction.
We will take reasonable steps to ensure that the personal information that we collect is accurate, up-to-date and complete and the personal information we use and disclose is accurate, up-to- date, complete and relevant. If we are satisfied that any personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will amend our records accordingly.
Please notify us if your personal details change so that we may keep our records current.
7. Online privacy
7.1 Automatic server logs
- Our servers automatically collect various details when you use our website and platform,
- your IP (Internet Protocol) address (generally, an identifier assigned to your computer when it is connected to the Internet);
- the operating system and Internet browser software you are currently using; and
- the data you access (such as web pages or other document files or software), and the
time that you access it.
We do not attempt to identify individuals using this information, and only use it for statistical analysis, system administration, and similar related purposes.
7.2 Cookies and similar technologies
Our website uses “cookies”, which identify your computer to our servers when you visit our website. We have also collect personal and other information using cookies. A web cookie is a small string of text sent from a website and placed on user’s hard drive by the user's web browser during data exchange that happens when a browser visits a website.
Cookies allow a website to store information on your machine or mobile device and retrieve it
later. Some cookies are managed by us (first-party cookies), while others are managed by third parties that we do not control (third-party cookies), such as Google Analytics. Personal information may also be collected or identified by other data collection or tracking technologies, such as web beacons, which imbed graphic files into our websites and online services which can be used to identify when someone visits our websites or online services, or in the case of web beacons, when an email is read or forwarded.
These small data files, cookies, and graphic files that may be on our websites, platform or systems serve various functions including:
- ▪ delivery of our Services;
- ▪ enhancement of our Services;
- ▪ targeted ads (e.g. from Google or Facebook);
- ▪ tracking performance and engagement across our website and Services;
- ▪ creation of user statistics and analytics for our website, platform or systems;
- ▪ management of transactions across multiple pages;
- ▪ authenticating you to systems and keeping you logged into those systems; and
- ▪ rememberingyourpreferences.
We do not attempt to specifically identify and track individuals using cookies.
You may choose not to accept cookies in connection with your use of our website or Services by deleting, blocking or disabling cookies via your browser settings (however, this may affect the use or functionality of some webpages or online services).
7.3 Google AdWords Remarketing
Users can usually block cookies, or remove cookies, by editing the privacy and security settings of their web browser or mobile device. Some features of our website may require cookies to function properly. If cookies are disabled or deleted, then depending on the particular cookie that is deleted or disabled, users may not be able to use such features of our website, or previous opt- outs may be undone.
By using our website, individuals consent to the storing and accessing of cookies or other information on their device for the purposes of Google AdWords and Analytics, unless they have opted out. It is possible to opt out of Google AdWords and Analytics advertising features, such as interest based advertising served by Google on its products or across the Google Display Network, as well as prevent the collection of certain data, by visiting the Google Ads Settings website or through other available means. The Google opt-outs do not stop all advertising. Google may still serve advertising that is not interest based, and the user may still receive interest based advertising that is not served by Google.
7.4 Email and messages
We may collect personal information from you (such as your name and email address, and any other personal information you volunteer) if you send us an email. We will use this to contact you to respond to your message, to send you information that you request, and for other related purposes we consider are within your reasonable expectations. We will not use or disclose any such personal information for any other purpose without your consent.
7.5 Storage and transmission of personal information online
If you provide any personal information to us via our online services (including email) or if we provide such information to you by such means, the privacy, security and integrity of this information cannot be guaranteed during its transmission unless we have indicated beforehand that a particular transaction or transmission of information will be protected (for example, by encryption).
7.6 Other online services
8. Third Party applications
Our platform Shopify’s platform allows Marketplace Owner, vendors and other third parties to connect stores with third party applications, including, for example, to alter their store or provide new functionalities. We ae not responsible for and have no control over how these applications function. Marketplace Owners and vendors ultimately can control which applications they choose to use with their stores, and are responsible for making sure that they do so in compliance with relevant privacy and data protection requirements.
9. Overseas transfers
Generally we do not disclose personal information to recipients outside of Australia, other than to our services providers (such as cloud and storage providers), any vendors or Marketplace Owners located outside of Australia. Generally, these counties include Australia, South East Asia, Europe and Americas. This includes where, for example, you provide us with your contact details in order to process a purchase you make, and we transfer and remit this personal information to one of our vendors or Marketplace Owners, who may be located in another jurisdiction, country or state, in order to execute your order or otherwise.
By using and accessing our websites or Services and submitting your personal information you consent to any disclosure of your personal information by us overseas.
While we have privacy rules in place to protect your personal information, recipients outside Australia may not be subject to privacy obligations or to any principles similar to the Australian Privacy Principles. Overseas recipients may also be subject to foreign laws which could compel disclosure of personal information to a third party, for example an overseas authority. If you consent to the disclosure and the overseas recipient mishandles the information, you may not be able to seek redress under the relevant laws and regulations of your jurisdiction or elsewhere, and we will not be accountable under any acts or regulations, to the extend permitted by law.
If we transfer your personal information to a person, company, office, branch, organisation, service provider or agent in another country, we will take steps which are reasonable in the
circumstances to make sure that we have appropriate security and privacy measures in place with such third parties covering how they hold and maintain any personal information on our behalf.
We use Model Contractual Clauses for the international transfer of personal information collected in the European Economic Area and Switzerland unless the country to which the transfers occurs has been determined to be a Country with Data Protection Adequacy as determined by the European Commission.
10. Our commitment
We are committed to ensuring that your personal information is secure, accurate, current and up- to-date. We communicate our privacy and security guidelines to our employees and strictly enforce privacy safeguards within our company.
11. Your rights
In certain circumstances, including if you are a citizen of or are located in the European Economic Area, you may have rights in relation to your personal information including:
- Access: the right to obtain details as to what personal information is held by us on you and how it is used and to whom it is disclosed. You are also entitled to a copy of any personal information that is held.
- Correction and deletion: a right to challenge the accuracy of personal information held about you, and right to request that we correct or delete (in certain circumstances) personal information.
- Restrict use: the right to request that your personal information not be processed (used) for certain purposes.
- Data portability: the right to request a copy of your personal information in an accessible and machine-readable format (such as a CSV file) and to request that your personal information be transferred to another organisation (if technically feasible).
- Withdrawing consent: if we are processing your personal data based on your consent, you have the right to withdraw that consent at any time.
You also have the right to object or raise a concern in relation to how we collect, process or otherwise deal with your personal information. If you wish to exercise any of these rights, please contact us using our details below. Although we hope that we can resolve any issues for you, you also have the right to lodge a complaint with the relevant data protection authority in your jurisdiction at any time.
For more information about these rights, visit here.
As we wish to avoid taking action in respect of your personal information at the direction of someone other than you, we may ask you for information to verify your identity. We will respond to your request within a reasonable time.
Please note that, in certain cases, we may continue to process your personal information after you have withdrawn consent and/or requested the deletion of personal information, where we are required to comply with any relevant legal obligation, if we require the personal information for lawful purposes for which the personal information was obtained or if it is necessary to pursue our legitimate interest in keeping our Services and operations safe and secure.
12. Data breach
If a data breach or suspected data breach occurs, we will undertake a prompt investigation, which will include an assessment of whether the incident is likely to result in serious harm to any individuals. In such a situation we will comply with the requirements of the Act and General Data Protection Regulation (GDPR), which may require notification to the Office of the Australian Information Commissioner (OAIC), relevant European Data Protection Authority and affected individuals. Please contact us if you have reason to believe or suspect that a data breach may have occurred, so that we can investigate and, if necessary, undertake appropriate containment, risk mitigation and notification activities as required.
If you have a complaint about the way in which we handle your personal information, or you believe that a breach of your privacy has occurred, please contact us using the details below.
Your complaint will be considered and dealt with by our nominated representative, who may escalate the complaint internally within our organisation if the matter is serious or if necessary to resolve it.
Please allow us a reasonable time to respond to your compliant. If you are not satisfied with our resolution, you may make a complaint to the OAIC whose contact details can be found here.
15. Contact details
If you would like further information about the ways we manage your personal information, please contact us by email firstname.lastname@example.org or as below.
Attn: Privacy Officer
PO Box 216 Fitzroy VIC 3065