Privacy Policy

Last Updated: 23rd December 2023

This Privacy Policy describes how Once Upon a Handbag (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from onceuponahandbag.au (the "Site") or otherwise communicate with us (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.

Our shop is powered by Shopify and therefore the majority of the points below are straight from Shopify's Privacy Policy based on the information they collect. 

Please read this Privacy Policy carefully. By using and accessing any of the Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access any of the Services.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.

How We Collect and Use Your Personal Information

To provide the hire services, we collect and have collected personal information about you from a variety of sources, as set out below. The information that we collect and use varies depending on how you interact with us.

In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide  services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the services, our rights, and the rights of our users or others.

What Personal Information We Collect

The types of personal information we obtain about you depends on how you interact with our Site and use our Services. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.

Information We Collect Directly from You

Information that you directly submit to us through our Services may include:

  • Basic contact details including your name, address, phone number, email.
  • Order information including your name, billing address, shipping address, payment confirmation, email address, phone number.
  • Account information including your username, password, security questions.
  • Shopping information including the items you view, put in your cart or add to your wishlist.
  • Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.

Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.

Information We Collect through Cookies

We also automatically collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.

Information We Obtain from Third Parties

Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:

  • Companies who support our Site and Services, such as Shopify.
  • Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
  • When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.

Any information we obtain from third parties will be treated in accordance with this Privacy Policy. We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party's policies or practices. For more information, see the section below, Third Party Websites and Links.

How We Use Your Personal Information

  • Providing Products and Services: We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to you account, purchases, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, and facilitate any exchanges.
  • Marketing and Advertising: We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services. This may include using your personal information to better tailor the Services and advertising on our Site and other websites.
  • Security and Fraud Prevention: We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately.
  • Communicating with you: We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you.

Cookies

Like many websites, we use Cookies on our Site. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services). We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.

Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.

How We Disclose Personal Information

In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:

  • With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
  • With business and marketing partners, including Shopify, to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
  • When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
  • With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
  • In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

We have, disclosed the following categories of personal information and sensitive personal information (denoted by *) about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":

Category Categories of Recipients
  • Identifiers such as basic contact details and certain order and account information
  • Commercial information such as order information, shopping information and customer support information
  • Internet or other similar network activity, such as Usage Data
  • Vendors and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfillment partners, customer support partners and data analytics providers)
  • Business and marketing partners
  • Affiliates

 

We do not use or disclose sensitive personal information for the purposes of inferring characteristics about you.

User Generated Content

The Services may enable you to post product reviews and other user-generated content. If you choose to submit user generated content to any public area of the Services, this content will be public and accessible by anyone.

We do not control who will have access to the information that you choose to make available to others, and cannot ensure that parties who have access to such information will respect your privacy or keep it secure. We are not responsible for the privacy or security of any information that you make publicly available, or for the accuracy, use or misuse of any information that you disclose or receive from third parties.

Third Party Websites and Links

Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.

Children’s Data

The Services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.

As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we “share” or “sell” (as those terms are defined in applicable law) personal information of individuals under 16 years of age.

Security and Retention of Your Information

Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” In addition, any information you send to us may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.

How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.

Your Rights and Choices

Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.

  • Right to Access / Know. You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
  • Right to Delete. You may have a right to request that we delete personal information we maintain about you.
  • Right to Correct. You may have a right to request that we correct inaccurate personal information we maintain about you.
  • Right of Portability. You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
  • Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
  • Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent.
  • Appeal: You may have a right to appeal our decision if we decline to process your request. You can do so by replying directly to our denial.
  • Managing Communication Preferences: We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.

You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.

We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, You may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.

Privacy Policy as it relates to FraudJudge

Once Upon a Handbag uses a third party called FraudJudge to assess the customer's identity and collect the customer's drivers license and address to make sure the customer completing the purchase is the person who will receive the handbag. Please see the following Privacy Policy as laid out by FraudJudge:


In this policy, the Customer of Once Upon a Handbag is referred to as the "Customer", Once Upon a Handbag is referred to as the "Client", and FraudJudge is referred to as "we". 

1. Processor in charge: “PLUGINHOST” BV company (hereinafter – “FRAUDJUDGE”).

E-mail: legal@fraudjudge.com .

2. What personal data do we process within the framework of our operations? Personal data – name, surname, personal ID Code, ID document data incl. birth data, etc.;
Contact data – telephone number, e-mail, address, etc.

It should be noted that not all the above listed types of data are applicable to processing of data of all persons, who are customers of the online store, for which we provide our services.

“FRAUDJUDGE” is merely a data processor, acting on behalf of its Client (an online merchant, which is to be considered as the data controller).

3. For what purpose and on which basis does “FRAUDJUDGE” process personal data?

Personal data processing is performed for various purposes and every data processing for any purpose is performed by following valid laws and regulations (GDPR). Your personal data processing by “FRAUDJUDGE” is based on the below described principles for processing of various types of data. Data processing necessary for performance of cooperation agreements: on the basis of these rights we process your data if this is necessary for performance of the agreement signed with the online store which we provide our services for, or, possibly, for preceding processes necessary for its signing.

Data categories: personal data, contact data. Data processing necessary for performance of “FRAUDJUDGE” obligations according to the conditions of cooperation and interaction between “FRAUDJUDGE” and it’s Client (i.e., the online merchant using “FRAUDJUDGE” services): accounting processes (including storing of accounting source documents); notification of violations related to personal data to relevant state authorities and the data subject; response to information inquiries of state administration institutions and state authorities.

Data categories: personal data, contact data.

Data processing according to the legitimate interest of “FRAUDJUDGE”: this is needed for developing our cooperation with partners, personnel, etc., to protect our property, our customers and employees; to adopt operation related decisions by collecting statistics; to provide work organization and its efficient processes in compliance with relevant regulatory documents. As data processing according to our legitimate interest is not our mandatory duty in compliance with the legislation or by asking your consent, you have the right to ask for clarifications from us and to submit claims in you find out that processing of your data for the above purposes violates your rights. Personal data categories: personal data, contact data.

Marketing activities, the so called marketing profile development process: we may process your data for marketing purposes by using various data processing technologies which allow us using either mathematic analysis, statistics or other methods, developing marketing strategies, explaining regularities and performing marketing analysis for product development and work organization. Personal data categories: personal data, contact data; as well as information of Client’s/Customer’s business transaction history. In addition to the above referred reasons, according to legitimate interests, we may process data also for other purposes, however, this is always done in compliance with the work process and the necessity to develop it.

4. Who else processes your data in cooperation with us?

Within “FRAUDJUDGE” your personal data are only accessible to the employees who need these data for successful performance of their official duties and assignments. Outside “FRAUDJUDGE” the access to your personal data is very restricted for only below described specific cases and in cases when processing of such personal data is necessary.

For example, entities who provide services to us: your data may be accessible to entities who offer services to us (the list is not exhaustive and periodically we order services in new fields): IT and telecommunication management and technical maintenance, e-mail service maintenance, network management, development of analysis software of audit, legal, data analysis. State administration institutions and state authorities (for example, the police, court, emergency services, etc.): we will provide your data only in cases when required by the law and if “FRAUDJUDGE” receives a relevant legally substantiated and legitimate inquiry.“ FRAUDJUDGE” does not transfer your personal data to third parties outside the European Economic Area or countries where the decision on data protection compliance is not adopted according to Article 25.6 of Directive 95/46/EC or its authorities according to Article 45.1 of the General Data Protection Regulation (EU) 2016/679; unless the Client of “FRAUDJUDGE”, on behalf of which “FRAUDJUDGE” is performing the data collection, is located outside the above mentioned areas; and unless the Customer of “FRAUDJUDGE” himself/herself is from outside the above mentioned areas.

5. How long do we store the data?

“FRAUDJUDGE” stores your data for a time period during which we are obliged to do it: 3 calendar months. According to the operations of “FRAUDJUDGE” during this period it is necessary to store the data in order to implement the purposes defined in the present privacy notice.In order to receive more information on the term of storing personal data in the cases you are interested in, submit a relevant inquiry to the e-mail address legal@fraudjudge.com .

6. Data security

“FRAUDJUDGE” has approved and implements all the necessary legal, organizational, physical and technical security measures for protecting your personal information. Functions and profiles are defined for all IT system users; it is secured that access rights are closed at the moment when an employee or a responsible entity no longer cooperates with “FRAUDJUDGE”. If “FRAUDJUDGE” uses outsourced service providers who process your data, we sign a data processing and protection agreement with such entities obliging the service provider: a) to implement relevant measures for protecting data confidentiality and security and b) to process personal data in compliance with applicable legislation (GDPR).

7. Customer’s and Client’s rights in relation to personal data

The Customer has the right to know what personal data about him/her has been processed by “FRAUDJUDGE”, for what purpose we process them, to whom these data are revealed; how long they are stored; what rights you have regarding data correction, deletion and processing restriction. In order for “FRAUDJUDGE” to be able to answer you, “FRAUDJUDGE” needs to identify you first in order to prevent provision of information to a non-authorized person. “FRAUDJUDGE” has the right to answer your questions within 30 days.The Client and the Customer have the right to request correction of data if they are inaccurate or incomplete.Even considering that a Customer has submitted his information/data via the system of “FRAUDJUDGE”, the Customer’s request for the deletion of the information/data shall be lodged by the Customer with the Client (i.e., the online merchant where the Customer made the purchase), not with “FRAUDJUDGE” directly. Shall the Customer lodge such request with “FRAUDJUDGE” directly, the request will be forwarded to the Client.In specific cases the Customer has the right to request us to delete his/hers personal data; for example, this applies to cases when we process the data for purpose of personal interest or according to the Customer’s consent.Also, in specific cases the Customer has the right to cancel or restrict processing of his/hers personal data for a particular time period (for example, if the Customer has submitted complaint(s) regarding processing of the data).Upon receipt of objections, “FRAUDJUDGE” suspends processing of Customer’s data except if we can prove that Customer’s personal data are processed due to a substantiated reason.If you would like to use any of your above listed rights, we kindly ask to contact us by using the e-mail address legal@fraudjudge.com .

8. Right to lodge a complaint

If you would like to have additional information in relation to your personal data or protection of rights, you are welcome to contact us by using the e-mail address legal@fraudjudge.com .

If you consider that processing of your personal data contradicts the requirements of the General Data Protection Regulation (GDPR), you have the right to contact a relevant state authority or court for protecting your rights and interests.

Complaints

If you have complaints about how we process your personal information, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, depending on where you live you may have the right to appeal our decision by contacting us using the contact details set out below, or lodge your complaint with your local data protection authority.

Contact

Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please call email us at support@onceuponahandbag.au