How Bondi Paws collects, uses, stores and discloses personal information, consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Current as at September 2026.
Ordering gives us your name, delivery address, email address, phone number and order contents. Emailing us adds that correspondence, which we retain so we have history if you write again.
We never receive or store your full card number. Payment data goes directly to our payment provider and is handled under their security controls. We see a transaction result, the card type and the final four digits.
Our platform and analytics record IP address, device and browser type, referring source, and the pages you view. This is behavioural data used in aggregate to see how the store performs.
Cookies hold your cart between pages, remember settings and support analytics. Your browser can block or clear them, though the cart and checkout will not work properly without the essential ones.
To fulfil and deliver orders, communicate with you about them, process returns and warranty claims, identify fraudulent transactions, improve the store, and meet record-keeping obligations under Australian law.
Marketing email goes only to people who have opted in. Every such email carries an unsubscribe link that works immediately. Emails about an order you have already placed are transactional, not marketing, and continue regardless.
Only providers who need it to perform a function: our ecommerce platform, payment provider, the carrier delivering your parcel, and our email platform if you have subscribed. Each is subject to its own privacy obligations.
We do not sell personal information. We do not rent, trade or supply contact lists. We do not pass your details to unrelated businesses for their marketing.
We may disclose information where compelled by law, including a court order, a lawful regulatory request, or where necessary to establish or defend a legal claim.
Some providers hold data on servers overseas, including in the United States and the European Union. Where that occurs we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
Order and transaction records are held for seven years to satisfy Australian tax and business record requirements. Marketing subscriptions are held until you unsubscribe. General enquiries are cleared periodically once resolved.
The site operates over encrypted connections, access to customer records is limited to those who need it, and administrative accounts require two-factor authentication. No system is perfectly secure and we make no claim that ours is.
You may ask what personal information we hold about you and we will provide it. You may ask us to correct anything wrong, and to delete anything we are not legally obliged to keep. Requests go through the Contact Us page and are answered within thirty days.
Where a breach occurs that is likely to cause serious harm, we will notify the individuals affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
This store is intended for adults and we do not knowingly collect information from anyone under eighteen. Where we become aware that we have, we delete it.
Contact us first and we will investigate. If our response does not resolve it, you may take the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
This policy may be revised. The version published on this page is always the operative one, and the date at the top shows when it last changed.
Send the request through our Contact Us page. Access, correction and deletion requests are answered within thirty days.