Before you publish this page
This draft describes how the Aux Aussie platform actually handles data, based on a review of the live system — including where information is physically stored. It is not legal advice and should be reviewed by an Australian privacy lawyer before publication.
One thing to verify first: businesses with annual turnover of $3 million or less are generally exempt from the Privacy Act 1988, though exceptions apply (for example, businesses that trade in personal information, or provide services under a Commonwealth contract). Whether or not you are technically bound, publishing and following a policy is best practice, is expected by payment partners, and is what this draft assumes.
Fields highlighted like THIS must be completed before publishing.
Aux Aussie Pty Ltd (ABN ABN TO BE INSERTED) respects your privacy. This policy explains what personal information we collect, why we collect it, who we share it with, and how you can access or correct it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Contents
1. What we collect
We collect only what we need to supply and support our products. Depending on how you deal with us, that may include:
| Category | What it includes |
|---|---|
| Enquiry details | Your name, email address, phone number and the content of your message when you contact us or request a quote. |
| Account details | Your trading name, business address, email address, phone number, preferred currency and program, plus a securely hashed password. We never store your password in readable form. |
| Order and delivery details | Contact name, email and phone for the order, the items ordered, amounts, and delivery details including carrier and tracking reference. |
| Billing records | Invoices, payment schedules, instalments, subscription details, amounts paid and outstanding, and payment dates and methods. |
| Card details | Only the card type, last four digits and expiry date — see section 2. |
| Account activity | Sign-in times, and a record of administrative actions taken on your account by our staff. |
| Technical information | Standard information sent by your browser, such as IP address and browser type, and information stored locally in your browser (see section 9). |
We do not collect sensitive information (such as health, biometric or political information), and we ask that you do not send it to us.
2. Card and payment information
We never see or store your full card number or security code.
Card payments are handled by Stripe. When you enter card details, they are captured directly by Stripe's own secure form and transmitted to Stripe — they do not pass through Aux Aussie's servers and are never written to our systems.
What we retain is only what you need in order to recognise your card: the card type, last four digits and expiry date, together with a secure reference token issued by Stripe. That token lets us request a payment against your card without ever handling the number itself, and is useless to anyone else.
Stripe is a payment processor certified to PCI DSS Level 1, the highest level of certification in the payments industry. Stripe's handling of your information is governed by its own privacy policy, available at stripe.com/au/privacy.
3. How we collect it
We collect personal information directly from you when you contact us, request a quote, create an account, place an order, save a card, or use your merchant dashboard. We also generate information about you in the ordinary course of servicing your account — for example when we raise an invoice or record a payment.
Where our sales team prepares a plan or places an order on your behalf at your request, we record the details you have given us for that purpose.
4. Why we collect it
We use personal information to:
- respond to your enquiries and prepare quotes;
- create and administer your account;
- process orders, arrange delivery and provide tracking;
- generate invoices and payment schedules, and take payments you have authorised;
- provide support, warranty service and repairs;
- keep records we are required to keep by law, including tax records;
- detect and prevent fraud and misuse; and
- send you service messages, and (where permitted) marketing you can opt out of.
If you choose not to give us the information we ask for, we may be unable to supply products or services to you.
5. Who we share it with
We do not sell your personal information. We share it only where necessary:
| Who | Why |
|---|---|
| Stripe | To process card payments and store card credentials securely. |
| Supabase (database and hosting) | To store and serve your account, order and billing records. |
| Delivery and freight partners | To deliver your devices and provide tracking. |
| Professional advisers | Our accountants, auditors and lawyers, where reasonably required. |
| Regulators and law enforcement | Where we are required or authorised by law to disclose. |
6. Where your information is stored
Some of your personal information is stored and processed outside Australia. We are required to tell you which countries this is likely to involve, and they are:
South Korea — our database is hosted by Supabase on Amazon Web Services infrastructure located in the Seoul region. Your account, order, invoice and payment-schedule records are stored there.
United States — Stripe, our payment processor, is a United States company and processes payment information there and in other countries in which it operates.
Before disclosing personal information overseas we take steps that are reasonable in the circumstances to ensure the recipient handles it consistently with the Australian Privacy Principles, including relying on the contractual protections and security certifications these providers offer. However, once information is held overseas it may also be subject to the laws of that country.
7. How we protect it
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Those steps include:
- encrypting traffic between your browser and our servers using HTTPS;
- storing passwords only as one-way hashes, never in readable form;
- never storing full card numbers or security codes anywhere in our systems;
- restricting staff access to what each role needs, with separate credentials for staff and merchants;
- keeping an audit record of administrative actions taken on customer accounts; and
- using reputable providers that maintain recognised security certifications.
No system is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and you are responsible for keeping your own account password confidential.
8. How long we keep it
We keep personal information only as long as we need it for the purposes described above, or as long as we are required to keep it by law. Financial records — including invoices and payment records — are generally retained for at least five years to meet Australian tax and record-keeping requirements. When information is no longer needed, we take reasonable steps to destroy or de-identify it.
9. Cookies and local storage
Our website stores a small amount of information in your browser to make it work properly, including your shopping cart contents, your light/dark theme preference, and — once you sign in — a secure token that keeps you signed in. This information stays in your browser and is not used to track you across other websites.
You can clear this at any time through your browser settings, though doing so will sign you out and empty your cart. If you add analytics or advertising tools, this section must be updated to disclose them.
10. Direct marketing
We may send you information about products, offers and updates where you have consented or where you would reasonably expect it, consistent with the Spam Act 2003 (Cth). Every marketing message includes an unsubscribe option, and you can also opt out at any time by emailing info@auxaussie.com.au.
Opting out of marketing does not stop service messages we need to send you — such as invoices, payment receipts, delivery updates and important account notices.
11. Accessing and correcting your information
You can view and update much of your information yourself in your merchant dashboard, including your contact details and saved cards.
You may also ask us for a copy of the personal information we hold about you, or ask us to correct it if it is inaccurate, out of date or incomplete. Email info@auxaussie.com.au and we will respond within a reasonable period, normally within 30 days. We may need to verify your identity first. If we refuse a request, we will tell you why in writing.
12. Data breaches
If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). We will tell you what happened, what information was involved, and what you can do in response.
13. Complaints
If you believe we have mishandled your personal information, please contact us first at info@auxaussie.com.au. We will acknowledge your complaint and aim to resolve it promptly.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
| Website | oaic.gov.au |
|---|---|
| Phone | 1300 363 992 |
| Post | GPO Box 5218, Sydney NSW 2001 |
14. Contact us
| Entity | Aux Aussie Pty Ltd |
|---|---|
| ABN | ABN TO BE INSERTED |
| Address | REGISTERED ADDRESS TO BE INSERTED |
| info@auxaussie.com.au | |
| Website | auxaussie.com.au |
We review this policy periodically. When we change it, we will update the date at the top of this page and, where the change is significant, tell you directly.