WE TAKE YOUR PRIVACY SERIOUSLY. YOU HAVE RIGHTS IN RELATION TO YOUR PRIVACY AND HOW OTHER PEOPLE USE AND HANDLE YOUR DATA.
Your privacy is important to us, which is why we’ve created this Privacy Statement. We collect Personal Information from visitors to our website located at www.thghtful.com (‘the Site’). This statement describes:
- what information we collect about you;
- how we use the information we collect;
- how we share the information we collect;
- how we transfer your information internationally; and
- how you can access and control your information.
In this Privacy Statement:
- any reference to ‘thghtful’, ‘us’, ‘we’ or ‘our’ means thghtful, ABN 20929979464
- Gift Recipient means an individual that you gift one of our products to by making a purchase through the Site;
- Personal Information means any information relating to an identified or identifiable natural person and includes both Device Information and Order Information.
How do we collect non-Personal Information?
When you visit our Site, we collect non-Personal Information from you including, without limitation, which sections of the Site are most frequently visited, how often and for how long. This data is always used as aggregated, non-Personal Information. We may analyse this non-Personal Information and release it to third parties in an aggregated form.
How do we collect Personal Information?
Like many websites, when you visit the Site, we automatically collect certain information through the use of “cookies”, web beacons, device identifiers, pixels and other technologies including information about your web browser, IP address and time zone. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site and information about how you interact with the Site. We refer to this automatically-collected information as ‘Device Information’.
We collect Device Information using the following technologies:
- “cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier;
- “log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps;
- “web beacons”, “tags” and “pixels” are electronic files used to record information about how you browse the Site.
When you make a purchase or attempt to make a purchase through the Site, we collect the following information (which includes Personal Information) from you:
- your name;
- email address;
- phone number;
- credit card information (we don’t have access to your actual credit card details and we don’t store your credit card details as this information is handled by our payment gateway);
- billing address;
- Gift Recipient’s name;
- Gift Recipient’s delivery address,
(together, the ‘Order Information’).
How do we use Personal Information?
We use the Order Information that we collect to fulfil any orders placed through the Site (including processing your payment information, arranging for shipping and providing you with invoices and/or order confirmations). Additionally, we use this Order Information to:
- communicate with you;
- communicate with the Gift Recipient to troubleshoot any delivery problems;
- screen our orders for potential risk or fraud; and
- when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
We use the Device Information that we collect to:
- screen for potential risk and fraud;
- improve and optimise our Site (for example, by generating analytics about how our customers browse and interact with the Site and to assess the success of our marketing and advertising campaigns); and
- to recognise you across different services and devices.
For Personal Information, we rely on the following legal bases to process this information:
- where you have given your consent;
- where the processing is necessary to perform a contract that we have with you, for example when you purchase our products; and
- our legitimate business interests, such as improving and developing our products and services and marketing new features or products.
You may at any time refuse to provide the Personal Information that we request. However, this may limit or prohibit our ability to provide our products and services to you. You may withdraw your consent for us to process your Personal Information at any time by contacting us in accordance with our ‘Contact us’ section below.
Who do we disclose Personal Information to?
Outside of authorised personnel employed by us, we only share your Personal Information with third parties that meet the data privacy conditions described in this Privacy Statement. These third parties help us use your Personal Information, as described above, and include:
- logistics providers, so that we can fulfil our delivery service;
- product tracking and marketing platforms, communications platforms and contractors who we engage to help process Personal Information and other data;
- government third parties, including government agencies, regulatory bodies and law enforcement agencies as required, authorised or permitted by law; and
- a third party that acquires or intends to acquire thghtful or its assets.
International transfers of Personal Information
Your Personal Information may be transferred to third parties including to persons and businesses outside Australia including in the United States of America and other countries where the privacy laws may not be as protective. These transfers are made in order to assist us to provide you with the products and services and/or to improve the products and services we offer you. When we transfer information to countries other than your own, we take reasonable steps to ensure that the recipients of such information do not breach the Australian Privacy Principles contained in the Privacy Act 1988 (Cth) in relation to that information by entering into contractual arrangements with such third parties.
Voluntary disclosure of Personal Information
We may make available on our Site, or link to, certain opportunities for our customers and other users to share information online (e.g. on message boards). Please be aware that whenever you voluntarily disclose Personal Information online, that information becomes public and can be collected and used by others. We have no control over, and take no responsibility for, the use, storage or dissemination of such publicly-disclosed Personal Information.
By posting Personal Information online in public forums, you may receive unsolicited messages from third parties.
Changing or deleting your Personal Information
You may access, review, update, rectify or delete your Personal Information by contacting us. We will respond to all requests within 30 days. Please note that deleting your Personal Information may limit our ability to provide the service to you. We may limit or reject your request in certain cases, including without limitation where the burden or expense of providing access would be disproportionate to the risks to your privacy in the case question, where the rights of other persons would be violated or as required by law. If you need further assistance regarding your access and control of your Personal Information, please contact us.
We follow generally accepted industry standards to protect the Personal Information submitted to us, both during transmission and once we receive it (including encryption and password protection). Each of our employees is aware of our security policies, and your information is only available to those employees who need it to perform their jobs. However, no method of transmission over the Internet using industry standard technology is 100% secure. Therefore, we cannot guarantee the absolute security of your information.
When you place an order through the Site, we will maintain your Order Information, and other personal information you have provided, for our records because we need this information to operate the accounts you have with us, to deliver our products and services to you and for the other purposes set out in the ‘How do we collect Personal Information?’ section. We will retain this information unless and until you ask us to delete this information.
We do not knowingly advertise or collect Personal Information from any individual under the age of 16. If we later find out that we have collected Personal Information from an individual under the age of 16, we suspend and remove this Personal Information immediately.
Changes to Privacy Statement
We reserve the right to modify this Privacy Statement at any time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons. If we make material changes to this Privacy Statement you will be notified via email (if we have your contact information) or otherwise in some manner through our services that we deem reasonably likely to reach you. Any modifications to this Privacy Statement will be effective upon our publication of the new terms and/or upon implementation of the new changes to our services (or as otherwise indicated at the time of publication). In all cases, your continued use of our services or Site after the publication of any modified Privacy Statement indicates your acceptance of the terms of the modified Privacy Statement.
Thghftful is a data controller and processor and by your consenting to this Privacy Statement thghtful is able to process your Personal Information in accordance with this Privacy Statement. In providing our products and services to you, we may make use of a number of automated processes using your Personal Information and your activity on our Site as tracked by us, in order to provide optimised services to you.
In addition to your rights set out above, you may:
- update or rectify any of the Personal Information we hold about you, in the manner described in the ‘Changing or Deleting your Personal Information’ section above;
- withdraw your consent to our use of our Personal Information as described in this Privacy Statement. This can be done by contacting us directly, using the details set out in the ‘Contact us’ section;
- request that we provide you with a copy of the Personal Information we hold about you in a portable and machine readable form or share your Personal Information with a nominated third party. This can be done by contacting us directly, using the details set out in the ‘Contact us’ section.
If you are unhappy with our data practices, you also have a right to lodge a complaint with your local supervisory authority.
If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by writing to or emailing us at email@example.com
We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so. We may use your personal information to send you promotional information about third parties which we think you may find interesting if you tell us that you wish this to happen.
You may request details of personal information which we hold about you under the Data Protection Act 1998. A small fee will be payable. If you would like a copy of the information held on you contact the Thghtful team.
If you believe that any information we are holding on you is incorrect or incomplete, please write to or email us as soon as possible, at the above address. We will promptly correct any information found to be incorrect.
Thank you for taking the time to read this. Please don’t hesitate to get in touch if you have any queries about the use of your private information – email us at firstname.lastname@example.org
Updated 11 November 2020