Privacy Policy
How Olive & Ivory Gifts collects, uses, secures, and retains personal information.
Information We Collect
We collect personal information you provide when you place an order or contact us, including your name, email address, phone number, billing and delivery details, and order details. We also collect limited technical and usage information (such as IP address, browser/device details, and interaction logs) for security, fraud prevention, service reliability, and performance improvement.
How We Collect and Use Information
We collect information directly from you (for example, checkout forms, account actions, and support enquiries) and from website interactions. We use personal information to process and deliver orders, provide customer support, communicate service updates, prevent fraud and abuse, maintain security controls, and meet legal, tax, accounting, and audit obligations. We do not sell personal information.
Analytics and Session Recording
We use PostHog (operated by PostHog Inc., based in the USA) to understand how the site is used and to improve it. PostHog records pseudonymous events such as pageviews, product views, cart actions, and checkout steps, along with technical context (IP address, approximate location derived from IP, browser, device). We also use PostHog Session Replay to record interactions with the page (clicks, scrolls, navigation) so we can see where users encounter friction. Session recordings mask form inputs by default, including passwords, emails, phone numbers, and any credit card details — Stripe handles payment fields directly, so card numbers are never visible to us. Recordings are linked to a pseudonymous identifier; if you sign in, your email may be associated with subsequent activity. You can opt out of analytics by enabling Do Not Track or Global Privacy Control in your browser, or by emailing [email protected] to request deletion of your recorded data.
Overseas Disclosure
Some service providers we rely on (such as infrastructure, payments, email, analytics, and support tools) may process or store data outside Australia. Where this occurs, we take reasonable steps to ensure appropriate contractual and technical safeguards are in place.
Data Retention and Deletion
We keep personal information only for as long as reasonably necessary for business and legal purposes. In practice: order records are generally retained for at least 5 years (and longer where required for disputes, chargebacks, or legal obligations); marketing list data is retained until you unsubscribe or withdraw consent; suppression-list data (for example, a minimal email identifier) may be retained to ensure we do not contact unsubscribed recipients again; and web/device analytics are retained for shorter periods where practical. We only keep order details where required to process orders and meet legal obligations. When information is no longer required and not legally required to be retained, we delete or de-identify it.
Access, Correction, and Deletion Requests
You may request access to or correction of your personal information. If you request deletion, we will remove or de-identify information where we can; however, we may retain records we are legally required to keep, including required order/accounting records.
Marketing and CRM
You can unsubscribe from CRM and marketing communications at any time using the unsubscribe link in our messages. Unsubscribe requests are processed promptly in line with applicable spam laws. We may retain minimal suppression data so we can honour your unsubscribe preference.
Security and Logging
We treat your data with strong security practices, including layered access controls, encryption in transit, environment controls, monitoring, and security/event logging to detect and respond to suspicious or unauthorised activity.
Data Breach Response
We maintain incident response procedures aligned with the Notifiable Data Breaches scheme. Where required, suspected eligible data breaches are assessed and, if serious harm is likely, notifications are made to affected individuals and the OAIC.
Complaints
If you have a privacy concern or complaint, contact us first so we can investigate and respond. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
Contact
For privacy requests, corrections, or complaints, email [email protected].