Privacy policy
1. Collection notice
| Data | Why we collect it | APP |
|---|---|---|
| Name, email, phone | Account, order updates, delivery SMS | APP 3, 6 |
| Delivery address | Shipping, zone-based delivery promises | APP 3, 6 |
| Payment data | Processed by Stripe — we hold only last-4 and brand | APP 3, 11 |
| Order & returns history | Fulfilment, refunds, 7-year tax records | APP 6 |
| Device & browsing events | Cart recovery, analytics, fraud signals | APP 3, 6 |
| Marketing preferences | Only what you consented to, per channel | APP 7 |
2. What we collect
What you give us (account details, addresses, safe-drop notes, review text), what your orders generate (items, GST amounts, courier scans), and what your device reports (pages viewed, cart events, rough location from IP for delivery estimates). Safe-drop notes — "blue bins, small dog loud" — are stored with the order, shown only to the picker and courier, and deleted with the order record. We don't collect sensitive information (health, religion, biometrics) and never ask for it.
3. How we use it (APP 6)
Fulfilment and service first: picking, packing, delivery promises, refunds, support. Then the things we told you about when you signed up: order emails, rewards, occasional marketing if you consented (section 4). Internal analytics use aggregated numbers — cohort retention, category splits — not profiles sold or rented to anyone. Fraud scoring uses order patterns; a high score routes to two humans before any action, never to an auto-decline.
4. Marketing & consent (APP 7)
The consent checkbox is never pre-ticked — not at registration, not at checkout, not in a competition form. Guests never receive marketing email (they have no consent on record — basket reminders go to signed-in members only, once per basket, with a 30-day cool-off after purchase). Marketing messages respect quiet hours 8am–8pm; transactional messages (your receipt, your delivery scan) are not marketing and can't be unsubscribed — the footer of each says why. Unsubscribe takes effect immediately and applies to that channel; changing your mind is one click in any email.
5. Cookies
Essential (cart, session, fraud) — always on, can't be switched off, no consent needed because the site doesn't work without them. Analytics (what pages fail people) and marketing (audiences, measurement) load only after you accept in the cookie dialog. "Essential only" is a real choice, not a dark pattern — the reject button is the same size as the accept button, and your choice is honoured for 12 months.
6. Who we share with
- Carriers (AusPost, StarTrack): name, address, phone, safe-drop notes — the minimum to deliver.
- Stripe: payment processing under their own PCI-DSS obligations.
- Email & SMS providers: message content needed to send your updates.
- Nobody else. We don't sell data, don't rent lists, and don't share purchase history with brands whose products you bought — aggregate sell-through reports to suppliers contain no personal information.
7. Overseas disclosure (APP 8)
Stripe (United States) processes payments; our email provider (Australia, with US failover) and analytics tooling may process data outside Australia. Recipients are bound by contract to standards at least equal to the APPs. We remain accountable for their handling — if they breach, that's our breach in your eyes and ours under the Act.
8. Your rights & data export
Access: one click in account → privacy exports everything we hold about you as machine-readable JSON — delivered by encrypted link that expires in 24 hours, usually ready within minutes, guaranteed within 30 days (we've never needed the 30). Correction: fix addresses and details yourself any time; for anything else email privacy@apexcommerce.com.au. Deletion: close your account any time; we delete what we can and tell you exactly what tax law forces us to keep and for how long. Complaint: section 12 — and if we stuff up the answer, the OAIC is your next stop.
9. Retention
| Record | Kept for | Why |
|---|---|---|
| Orders & invoices | 7 years | Tax law (GST, BAS) |
| Payment references | 7 years | Tax + chargeback defence |
| Support conversations | 2 years | Service continuity |
| Browsing & cart events | 13 months | Analytics cohorts |
| Marketing consent record | Until withdrawn + 30 days | Proof of consent |
10. Security
TLS everywhere, cards tokenised by Stripe (we hold last-4 only), staff access by role with step-up authentication for sensitive screens, PII columns in reports consent-gated with a purpose note, exports encrypted and auto-deleting after 72 hours. We run phishing drills against our own team and tell customers in every email footer that we will never ask for a password or one-time code.
11. Children
The site isn't directed at children. If you're under 18, get a parent or guardian involved before buying. If we learn an account belongs to a child without guardian consent, we close it and delete the data except records tax law keeps.
12. Complaints
Email privacy@apexcommerce.com.au or write to the Privacy Officer, L5/120 Spencer St, Melbourne VIC 3000. We acknowledge within 2 business days and respond within 30. Not happy with our answer? The Office of the Australian Information Commissioner (oaic.gov.au) takes complaints free of charge.
13. Changes
Dated versions stay on this page. Material changes are emailed to account holders 14 days ahead — "material" means new data collected, new sharing, or new purposes. This version: 8 September 2026.