Audora Fashion Privacy Policy
On this page
- 1 About this policy
- 2 Scope and privacy obligations
- 3 Your choice to provide information
- 4 Information we collect
- 5 How we collect and use information
- 6 Checkout and payment services
- 7 Cookies and browser storage
- 8 Marketing and mailing list choices
- 9 When we share information
- 10 Overseas storage and disclosure
- 11 How long we keep information
- 12 Keeping information secure
- 13 Access correction and deletion requests
- 14 Children and young people
- 15 Social media and public content
- 16 Customers outside Australia
- 17 Privacy complaints
- 18 Changes to this policy
- 19 Contact Audora
1 About this policy
Audora Fashion (Audora, we, us or our) is an Australian fashion business based in Adelaide, South Australia. This policy explains how we handle personal information when you browse our website, buy our products, join our mailing list, contact us or interact with our business. It also explains the choices available to you and how to raise a privacy concern.
Personal information means information or an opinion about an identified person, or a person who can reasonably be identified. It can include information that identifies you directly, such as your name, and information that identifies you when combined with other records, such as an order number or online identifier.
We use personal information to operate our store and provide the services described below. We do not sell our customer mailing list or other personal information for money. Disclosures to the providers that support our business are explained in sections 6, 9 and 10.
2 Scope and privacy obligations
This policy covers Audora's website, online shopping services, customer enquiries, mailing list, order fulfilment, returns and related business communications. Separate privacy notices may apply to a particular promotion or service. Where we provide an additional notice, read it together with this policy.
We seek to handle personal information consistently with the Australian Privacy Principles. The Privacy Act 1988 (Cth), the Australian Privacy Principles and other privacy laws apply to us to the extent required by law. Our commitments in this policy do not remove any rights you have under applicable law.
This policy explains our practices. Visiting our website does not, by itself, give consent to every use of personal information. Where a particular activity requires consent, that consent must be obtained for that activity.
3 Your choice to provide information
You can browse our public website without placing an order or joining our mailing list. You may make a general enquiry anonymously or using a pseudonym where it is practical for us to respond that way. Technical information may still be collected when you visit the website.
If you choose not to provide information needed to process a payment, deliver an order, verify a request or respond to an enquiry, we may be unable to provide that service. Joining our mailing list is optional and is not a condition of buying a product.
4 Information we collect
The information we collect depends on how you interact with Audora. We aim to collect information relevant to that interaction rather than requesting unrelated personal details.
Contact and order information
When you place an order or ask about a purchase, we may collect your name, email address, telephone number, billing and delivery addresses, order number, items and quantities purchased, selected sizes and colours, delivery instructions and shipping status. We also receive records of discounts, cancellations, returns, refunds, disputes and related correspondence.
If you send a gift directly to another person, we receive the recipient's name, delivery address and any contact or delivery details you provide. Please provide only what is needed to deliver the gift and ensure you are entitled to give us those details. We do not treat a gift recipient's delivery details as permission to send them marketing.
Payment and transaction information
Checkout and payment providers collect the information needed for your chosen payment method. Audora may receive payment status, transaction references, the amount paid, refund information and limited payment identifiers, such as a card brand and masked card number. Section 6 explains how checkout information is handled.
Enquiries and customer support
If you use our contact form, email us or message our social accounts, we receive the information you send. This may include your name, email address, message, social media handle and supporting material, such as a photograph of a faulty item. Please avoid including identity documents, full card details or unrelated information about yourself or another person.
Mailing list and preferences
When you join our mailing list, we collect your email address and subscription status. Our mailing platform may also hold the date and source of signup, consent records, delivery results, unsubscribe requests and email engagement information where the relevant features are enabled. We explain marketing choices in section 8.
Website and device information
Our website and service providers may receive your IP address, browser and device type, operating system, language, referring page, pages viewed, approximate location inferred from technical information, timestamps and error or security logs. Analytics tools may use online identifiers to distinguish visits and understand website activity.
Your cart, wishlist and selected region are also stored in your browser. A region selected for shopping or sizing is a preference, not evidence of your nationality or precise location.
Sensitive and unsolicited information
Our ordinary retail services do not require health records, biometric identifiers, government identity documents or information about your beliefs. Please do not send these details unless we have explained a specific need and an appropriate way to provide them. If we receive unnecessary personal information, we assess whether we can lawfully retain it and, where appropriate, delete or de-identify it.
5 How we collect and use information
We collect information directly from you through checkout, forms, email, social messages and other communications. We also receive information from checkout and payment services, delivery providers and technical systems used to operate the website. For example, a carrier may tell us whether a parcel was delivered, and a payment provider may notify us of a refund or dispute.
We use personal information for the following purposes:
- Processing purchases, confirming payment, preparing orders, arranging delivery and keeping you informed about an order.
- Responding to questions, locating transactions, resolving delivery problems and handling returns, refunds, complaints or payment disputes.
- Remembering shopping preferences and supporting features such as the cart, wishlist and selected region.
- Sending mailing list updates about launches, restocks, products and offers when we have the consent required to do so.
- Understanding how people use the website, diagnosing errors and improving its performance, navigation and product information.
- Detecting suspicious transactions, investigating misuse, securing business systems and protecting customers and our business.
- Keeping necessary accounting and business records, meeting legal obligations and establishing, exercising or defending legal claims.
We may combine information relating to the same enquiry or purchase so that we can resolve it accurately. For example, we may link a support email to its order and delivery record. We do not need unrelated personal information to do this.
Where we want to use information for a materially different purpose, we will consider whether that use is permitted and provide further notice or obtain consent where required. Information that has been properly de-identified may be used to understand general sales or website trends.
6 Checkout and payment services
Audora's website uses Snipcart to support cart and checkout services. Information entered into checkout is handled by Snipcart and the payment service used for the transaction. Those services may collect additional information for payment authentication, fraud prevention, legal compliance and their own account services.
Audora uses transaction records to fulfil purchases and manage refunds or disputes. Our ordinary order handling does not require us to receive or store your complete card number or card security code. Please do not send those details to us through email, social messages or our contact form.
Some checkout or payment providers act on our instructions for particular activities and make their own decisions about other processing, including fraud checks or regulatory reporting. Their privacy notices explain those activities. The providers available to you depend on the payment options actually offered at checkout.
If a payment provider declines or flags a transaction, contact us about your order. A payment provider may need to address questions about its own assessment or records directly.
7 Cookies and browser storage
Cookies are small records stored by a browser. Local storage is another browser feature that can retain information between visits. Our website uses local storage for the cart, wishlist and region preference. These records can remain on the device until you remove them, the website updates them or the browser clears them.
Checkout and hosting services may use additional cookies or similar technologies for functions such as maintaining a checkout session, preventing misuse and operating the service. Disabling storage needed for these functions can prevent parts of the store from working correctly.
Google Analytics
Our website includes Google Analytics to measure visits and understand website use. It can collect page activity, device and browser information, traffic source information and online identifiers. Google Analytics cookies commonly include names beginning with _ga. Cookie expiry and analytics retention depend on the settings in use and are separate from the retention of order records.
Google describes its handling of information from sites that use its services at https://policies.google.com/technologies/partner-sites. Its browser opt-out add-on is available at https://tools.google.com/dlpage/gaoptout. The add-on is specific to supported browsers and Google Analytics; it does not disable every website technology.
Managing your choices
You can use your browser settings to block or remove cookies and clear local storage. Removing local storage may clear your cart, wishlist and region preference. Choices may need to be repeated on each device or browser. Blocking remote images in email can also reduce some email open tracking, although it may not prevent tracking of links you choose to click.
Where applicable law requires consent for non-essential tracking, that tracking requires a valid consent mechanism or must be disabled. This policy does not itself provide consent, and browser controls do not replace a consent mechanism where one is legally required. Contact us if you need help understanding the choices available on our website.
8 Marketing and mailing list choices
When you subscribe, we use your email address to send the updates described at signup. Our mailing list is supported by MailerLite, and the signup form also sends a backup submission to Netlify Forms. Depending on the email settings in use, MailerLite may record delivery failures, opens and link clicks to help administer and evaluate messages.
We send commercial electronic messages with the consent required by Australian spam law. A purchase or support enquiry does not automatically subscribe you to unrelated marketing. We identify Audora in our marketing messages and provide a way to unsubscribe.
You can unsubscribe using the link in a marketing email or by emailing hello@audorafashion.com. We will honour unsubscribe requests within five working days, without a fee or a requirement to create an account. We may retain a limited suppression record so that we do not accidentally add you back to the list.
Unsubscribing from marketing does not stop necessary messages about a purchase, refund, delivery, security issue or privacy request. Those messages are sent for the relevant service purpose.
9 When we share information
Access to personal information is limited to people and organisations that need it for the purposes described in this policy. Depending on your interaction, recipients can include:
- Snipcart and the payment providers offered at checkout, for transactions, authentication, refunds and disputes.
- Postal and delivery providers, including Australia Post where used, and their delivery partners, for shipping, tracking, delivery issues and returns.
- Netlify, for website hosting, serverless functions, technical logs and form submissions, including backup mailing list records.
- Resend, for sending contact form messages to Audora, and the email services used to receive and respond to those messages.
- MailerLite, for administering the mailing list and sending subscribed email updates.
- Google Analytics and providers of website fonts, images, scripts or other hosted content, which may receive technical connection information when your browser requests their resources.
- People authorised to help operate Audora, and professional advisers such as accountants, insurers or lawyers, where their work requires the relevant information.
We aim to disclose information relevant to the recipient's task. A delivery company, for example, needs recipient and parcel details rather than our complete mailing list. Providers' use of data may also be governed by their own privacy notices, particularly where they provide a service directly to you or have independent legal obligations.
We may disclose information where required or permitted by law, in response to a valid legal request, to protect a person's safety, or to investigate fraud or enforce legal rights. We assess requests before disclosing information and limit disclosure to what is appropriate.
If Audora is sold or restructured, relevant records may be disclosed to advisers or a prospective or actual purchaser, subject to applicable law and appropriate confidentiality arrangements. We will provide any notice required by law. Information will not be disclosed merely because someone asks for it.
10 Overseas storage and disclosure
Some providers operate outside Australia or use staff and infrastructure in several countries. Personal information may therefore be stored, accessed or processed overseas, including in the United States and the Netherlands. MailerLite's current service uses Netherlands hosting, and its terms describe processing through its United States entity for customers outside the EEA, United Kingdom and Switzerland.
Further locations can depend on a provider's subcontractors, the services enabled, support arrangements and an international delivery destination. For an overseas order, recipient information may be disclosed to postal operators, delivery partners and customs authorities in the destination and transit countries.
Where Australian Privacy Principle 8 applies, we take the steps it requires before disclosing personal information overseas, unless a lawful exception applies. These steps may include considering the recipient's privacy protections and relevant contractual arrangements. Overseas laws may differ from Australian law. We do not treat your use of our website as a blanket waiver of protections for overseas disclosures.
You can contact us for further information about the providers and overseas locations relevant to your interaction. Where another applicable law requires a particular transfer safeguard, that requirement must also be met.
11 How long we keep information
We retain personal information for the period reasonably needed for the purpose for which it is held, including any applicable legal, accounting, dispute or fraud prevention requirements. There is no single retention period that applies to every type of record.
Order, payment and refund records are kept for fulfilment, after-sales support and the applicable tax, accounting and legal recordkeeping periods. If a dispute, investigation or legal hold applies, relevant records may need to be kept until that matter is resolved and the associated retention requirement ends.
Contact form submissions, email correspondence and support attachments are kept while needed to respond to the enquiry and manage related issues. We aim to avoid keeping unnecessary copies or unrelated attachments once their purpose has ended.
Mailing list details are used while the subscription remains active or there is another valid basis to retain them. Following an unsubscribe, limited consent and suppression records may remain so that we can respect the request and demonstrate how the subscription was handled. A backup form record is separate from the active mailing list and must be considered when a deletion request is assessed.
Technical logs and analytics information are subject to the retention settings and operational requirements of the relevant services. Browser storage can remain on your device until it is cleared. These periods can differ from the periods for customer service and transaction records.
When information is no longer needed and no lawful retention requirement applies, we take reasonable steps to delete or de-identify it. Copies in backups may remain until the relevant backup is replaced or expires. If a backup is restored, applicable deletion or suppression instructions should be reapplied. Contact us to ask about the retention of a particular record.
12 Keeping information secure
We take reasonable steps appropriate to the information and our business to protect personal information from misuse, interference, loss and unauthorised access, alteration or disclosure. Our approach includes limiting access to relevant business purposes, using the security controls available in the services we use and protecting devices and accounts used to handle customer information.
Information may be held in provider systems, business email, business records and associated backups. Printed records, such as shipping labels or return documents, also require appropriate handling and disposal. Public shipping labels should contain only the details needed for the shipment.
No internet transmission or storage system can be guaranteed completely secure. Please keep your own devices and email account secure, take care on shared devices, and contact us promptly if you suspect that information connected with an Audora order has been compromised.
If we become aware of a suspected data breach, we will assess the circumstances and take appropriate steps to contain it and reduce harm. Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will notify the relevant regulator and affected individuals as required. We will provide practical information about the incident and steps people can take to protect themselves where appropriate.
13 Access correction and deletion requests
You can contact hello@audorafashion.com to ask what personal information we hold about you, request access, correct inaccurate or outdated details, ask us to delete information, or raise a concern about a particular use. Include enough information to help us locate the relevant records, such as the email address used for a purchase and an order number if available.
We may need to verify your identity or a representative's authority before releasing or changing information. We will seek verification proportionate to the request. Please do not send identity documents unless we explain why they are needed and provide an appropriate way to submit them.
We aim to respond to access and correction requests within 30 days. Where a different legal deadline applies, we will follow it. If a request needs clarification or more time, we will explain what is needed and provide an update. We do not charge for making a request or asking for a correction. If a lawful, reasonable access charge is proposed, we will explain it before proceeding.
Access, correction and deletion can be subject to legal exceptions. For example, we may need to protect another person's privacy or retain transaction records required for legal or accounting purposes. A deletion request does not automatically remove records we must lawfully keep. Where we cannot comply in full, we will explain the reason where permitted and identify available complaint options.
If we decline to make a correction, you may ask us to record a statement of your disagreement where applicable law provides that right. Where a correction needs to be passed to a provider or another recipient, we will take the steps required by law.
For information held by providers on Audora's behalf, we will assess the request across the relevant services. Providers may need to respond directly about records they hold for their own purposes. Clearing information stored only in your browser generally requires you to use that browser's controls.
14 Children and young people
Our retail services are not designed to collect sensitive information about children. Young people should involve a parent or guardian when providing information for an order, particularly where payment details or another person's delivery information are involved.
Where consent is needed from a young person, their capacity to understand the proposed handling of information and any applicable age requirements must be considered. We do not treat a fixed age as a universal rule for every country or every privacy right.
A parent or guardian who believes a child has provided personal information inappropriately can contact us. We will assess the circumstances and take appropriate steps, including deletion where required or appropriate, subject to legitimate retention obligations.
15 Social media and public content
Social platforms handle information under their own privacy policies. Public comments, tags and reviews may be visible to other people. Avoid posting order details, addresses or other private information publicly. If we wish to use an identifiable customer photograph or testimonial in our own marketing, we will obtain appropriate permission. You can contact us about content under our control.
16 Customers outside Australia
Additional rights may apply depending on where you are located and whether the relevant law covers Audora's activities. We will assess requests under the law that applies to the particular processing. International shipping does not, by itself, mean every overseas privacy law applies to every interaction.
Where the EU or UK GDPR applies, the grounds for relevant processing may include fulfilling a purchase contract, complying with applicable legal obligations, pursuing legitimate interests such as responding to enquiries or securing the store, and consent for activities that require it. Legitimate interests must be assessed against your rights and interests; they do not replace consent where consent is required.
Depending on the applicable law and circumstances, you may have rights to access or correct information, request erasure, restrict processing, receive certain information in a portable format, object to processing, withdraw consent and complain to a supervisory authority. An objection to direct marketing will be respected. Withdrawing consent does not change the lawfulness of earlier processing based on that consent.
Any applicable requirements for notices, response deadlines, children's information, tracking consent and international transfers must also be met. Contact us to exercise a right or to ask which safeguards apply. We will not penalise you for making a lawful privacy request.
17 Privacy complaints
If you believe we have mishandled personal information, email hello@audorafashion.com with the subject "Privacy complaint". Explain what happened, when it occurred, the records or order involved, and the outcome you are seeking. You may appoint a representative; we may need evidence of their authority.
We will acknowledge the complaint, review the relevant records and practices, and contact you if more information is needed. We aim to provide a substantive response within 30 days. If we need more time, we will explain the reason and expected timing. Our response will explain our findings and any action we propose to take.
If Australian privacy law covers the matter and you are dissatisfied with our response, or have not received a response within 30 days, you can complain to the Office of the Australian Information Commissioner. The OAIC explains eligibility and how to submit a written complaint at the OAIC privacy complaints page. Its enquiries line is 1300 363 992. Other regulators or complaint rights may be available where another law applies.
18 Changes to this policy
We may update this policy when our services, providers, practices or legal obligations change. The current published version will show its latest revision date. Where a material change requires an additional notice or new consent, we will provide that notice or seek consent as required. An update does not automatically authorise a new use of information collected earlier.
19 Contact Audora
For privacy questions, access or correction requests, deletion requests and complaints, contact Audora Fashion at hello@audorafashion.com. Our business is based in Adelaide, South Australia, and our website is https://audorafashion.com.
You can request a copy of this policy without charge. If you need it in another accessible form or need an alternative way to contact us, let us know so that we can discuss a practical option.