AUX AUSSIE

Privacy Policy

Last updated: 30 July 2026 · Version 1.0

Before you publish this page

This draft describes how the Aux Aussie platform actually handles data, based on a review of the live system — including where information is physically stored. It is not legal advice and should be reviewed by an Australian privacy lawyer before publication.

One thing to verify first: businesses with annual turnover of $3 million or less are generally exempt from the Privacy Act 1988, though exceptions apply (for example, businesses that trade in personal information, or provide services under a Commonwealth contract). Whether or not you are technically bound, publishing and following a policy is best practice, is expected by payment partners, and is what this draft assumes.

Fields highlighted like THIS must be completed before publishing.

Aux Aussie Pty Ltd (ABN ABN TO BE INSERTED) respects your privacy. This policy explains what personal information we collect, why we collect it, who we share it with, and how you can access or correct it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. What we collect

We collect only what we need to supply and support our products. Depending on how you deal with us, that may include:

We do not collect sensitive information (such as health, biometric or political information), and we ask that you do not send it to us.

2. Card and payment information

We never see or store your full card number or security code.

Card payments are handled by Stripe. When you enter card details, they are captured directly by Stripe's own secure form and transmitted to Stripe — they do not pass through Aux Aussie's servers and are never written to our systems.

What we retain is only what you need in order to recognise your card: the card type, last four digits and expiry date, together with a secure reference token issued by Stripe. That token lets us request a payment against your card without ever handling the number itself, and is useless to anyone else.

Stripe is a payment processor certified to PCI DSS Level 1, the highest level of certification in the payments industry. Stripe's handling of your information is governed by its own privacy policy, available at stripe.com/au/privacy.

3. How we collect it

We collect personal information directly from you when you contact us, request a quote, create an account, place an order, save a card, or use your merchant dashboard. We also generate information about you in the ordinary course of servicing your account — for example when we raise an invoice or record a payment.

Where our sales team prepares a plan or places an order on your behalf at your request, we record the details you have given us for that purpose.

4. Why we collect it

We use personal information to:

If you choose not to give us the information we ask for, we may be unable to supply products or services to you.

5. Who we share it with

We do not sell your personal information. We share it only where necessary:

6. Where your information is stored

Some of your personal information is stored and processed outside Australia. We are required to tell you which countries this is likely to involve, and they are:

South Korea — our database is hosted by Supabase on Amazon Web Services infrastructure located in the Seoul region. Your account, order, invoice and payment-schedule records are stored there.

United States — Stripe, our payment processor, is a United States company and processes payment information there and in other countries in which it operates.

Before disclosing personal information overseas we take steps that are reasonable in the circumstances to ensure the recipient handles it consistently with the Australian Privacy Principles, including relying on the contractual protections and security certifications these providers offer. However, once information is held overseas it may also be subject to the laws of that country.

7. How we protect it

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Those steps include:

No system is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and you are responsible for keeping your own account password confidential.

8. How long we keep it

We keep personal information only as long as we need it for the purposes described above, or as long as we are required to keep it by law. Financial records — including invoices and payment records — are generally retained for at least five years to meet Australian tax and record-keeping requirements. When information is no longer needed, we take reasonable steps to destroy or de-identify it.

9. Cookies and local storage

Our website stores a small amount of information in your browser to make it work properly, including your shopping cart contents, your light/dark theme preference, and — once you sign in — a secure token that keeps you signed in. This information stays in your browser and is not used to track you across other websites.

You can clear this at any time through your browser settings, though doing so will sign you out and empty your cart. If you add analytics or advertising tools, this section must be updated to disclose them.

10. Direct marketing

We may send you information about products, offers and updates where you have consented or where you would reasonably expect it, consistent with the Spam Act 2003 (Cth). Every marketing message includes an unsubscribe option, and you can also opt out at any time by emailing info@auxaussie.com.au.

Opting out of marketing does not stop service messages we need to send you — such as invoices, payment receipts, delivery updates and important account notices.

11. Accessing and correcting your information

You can view and update much of your information yourself in your merchant dashboard, including your contact details and saved cards.

You may also ask us for a copy of the personal information we hold about you, or ask us to correct it if it is inaccurate, out of date or incomplete. Email info@auxaussie.com.au and we will respond within a reasonable period, normally within 30 days. We may need to verify your identity first. If we refuse a request, we will tell you why in writing.

12. Data breaches

If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). We will tell you what happened, what information was involved, and what you can do in response.

13. Complaints

If you believe we have mishandled your personal information, please contact us first at info@auxaussie.com.au. We will acknowledge your complaint and aim to resolve it promptly.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):

14. Contact us

We review this policy periodically. When we change it, we will update the date at the top of this page and, where the change is significant, tell you directly.