1. Who we are
Blanc9 operates blanc9.shop and is responsible for the personal information described in this policy. “We”, “us” and “our” refer to Blanc9. Privacy enquiries, access and correction requests, and complaints may be sent to info@blanc9.shop.
This policy is intended for visitors and customers in Australia. It is written with reference to the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme and the Spam Act 2003 (Cth). Some small businesses are exempt from parts of the Privacy Act, depending on turnover and activities; we intend to follow the transparent practices described here whenever we handle personal information, subject to applicable law.
2. Information we collect
Depending on how a person uses the store, we may collect:
Identity and contact information: name, billing and delivery address, email address, telephone number and account details.
Order and transaction information: products ordered, amounts, currency, discounts, refunds, delivery status, correspondence and payment confirmation. Full payment-card details are normally handled by the payment provider rather than stored by us.
Technical and usage information: IP address, browser and device information, approximate location, timestamps, referral pages, pages viewed, interactions, cookie identifiers and security logs.
Preference and marketing information: communication preferences, consent records and responses to marketing.
Customer-service information: messages, photographs, reviews, return reasons, complaint details and any other information voluntarily supplied.
Fraud and compliance information: risk indicators, chargeback information and records needed to meet legal, tax, accounting or regulatory obligations.
We ask customers not to send sensitive information, government identifiers or other unnecessary high-risk data. If such information is received, we will assess whether it is reasonably necessary, permitted and appropriate to retain. Unsolicited personal information that could not lawfully have been collected may be destroyed or de-identified where lawful and reasonable.
3. How we obtain information
We collect information directly when a customer visits the website, creates an account, places an order, joins a mailing list, submits a review, contacts us or requests a return. We also receive information from service providers involved in payments, ecommerce hosting, fulfilment, delivery, fraud prevention, analytics, advertising and customer support, and from publicly available sources where lawful.
4. Why we collect, hold, use and disclose information
Orders and requested services: to take steps requested before purchase; accept and fulfil orders; process payments, delivery, returns and refunds; provide customer service; and administer accounts.
Legal and regulatory purposes: to keep tax and accounting records, respond to lawful requests, honour consumer guarantees, manage product-safety issues and comply with Australian law.
Reasonable business purposes: to secure and improve the store, prevent fraud and misuse, understand performance, manage stock and operations, establish or defend legal claims, and maintain accurate records where these activities are reasonably necessary and consistent with the APPs.
Consent and reasonable expectation: to send commercial electronic messages where express or inferred consent is valid, and to use optional tracking or personalisation technologies where consent is required or offered. Consent can be withdrawn for future use.
Commercial electronic messages are sent only with express consent or where consent may lawfully be inferred from a provable ongoing relationship and reasonable expectations. A single purchase does not automatically establish inferred consent. Each marketing message identifies the sender, provides valid contact details and contains a functional unsubscribe facility. We honour unsubscribe requests within five working days. We do not use address-harvesting software or harvested lists.
5. Cookies and similar technologies
Strictly necessary technologies may be used to operate the basket and checkout, maintain security, remember privacy choices and provide services requested by the user. These do not ordinarily require consent, but information about them should still be provided.
Analytics, advertising, personalisation and other non-essential technologies may collect identifiers and usage information. We provide notice and choices appropriate to the technology, sensitivity, reasonable expectations and applicable Australian law. Where consent is required or requested, it must be meaningful and can be withdrawn for future use. Browser controls, website privacy settings and opt-out tools may also be used. The actual cookie notice and settings presented on the website provide current operational details.
6. Sharing information
We may disclose only the information reasonably necessary to:
ecommerce, cloud-hosting, payment, fraud-prevention and IT-security providers;
warehouses, suppliers, manufacturers, delivery carriers and return processors;
customer-support, email, analytics and advertising providers, subject to the required choices and safeguards;
professional advisers, auditors, insurers and financial institutions;
courts, regulators, tax authorities, law enforcement and other bodies where disclosure is required or permitted by law; and
a buyer, investor or successor in connection with a genuine business reorganisation, sale or transfer, under appropriate confidentiality protections.
Service providers handling personal information on our behalf are required to follow agreed instructions, keep information secure and use it only for authorised purposes. Some recipients handle information independently under their own privacy notices and legal responsibilities.
7. Overseas disclosures
Some technology, payment, support, analytics, manufacturing or fulfilment providers may be located outside Australia, potentially including the United States, Canada, the United Kingdom, countries in the European Economic Area and Singapore. The actual countries depend on the providers used for a transaction and may change as service locations change.
Where APP 8 applies, we take reasonable steps before disclosing personal information overseas to ensure that the recipient handles it consistently with the APPs, unless an exception applies. Depending on the arrangement, measures may include provider due diligence, contractual privacy and security obligations, access controls, data minimisation and incident cooperation. In some circumstances, we may remain accountable for an overseas recipient’s handling of the information.
8. Retention
We retain personal information only for as long as reasonably necessary for the purpose collected, including order fulfilment, customer support, fraud prevention, legal compliance and claims. Retention periods depend on the type of record and legal requirements. Core transaction and tax records are normally retained for up to six years after the end of the relevant relationship or accounting period, unless a longer or shorter period is required. Marketing records are retained until opt-out and for a limited suppression period so that the preference can be respected. Security and routine website logs are retained for shorter periods unless needed to investigate an incident. Information is deleted, anonymised or securely isolated when no longer required.
9. Personalisation files and user-supplied artwork
If a customer orders a personalised product, we may process names, dates, messages, photographs, logos, artwork, measurements and production instructions supplied for that order. We use this information to prepare proofs, manufacture the product, deal with quality questions and defend or resolve claims. Customers should provide only information they are authorised to use and should avoid including unnecessary personal or sensitive information.
Production files may be shared with a carefully selected printer, engraver, manufacturer or fulfilment provider solely to complete the order. We retain working files only for as long as reasonably required for production, reprints, customer support and legal claims, after which they are deleted or de-identified in line with our retention process.
10. Payment information and fraud prevention
Payments are processed by the payment methods displayed at checkout. Payment providers generally receive card or account details directly; we normally receive confirmation, limited transaction identifiers and fraud-screening results rather than full card credentials. Providers may handle information independently under their own privacy notices.
We and our providers may evaluate device, transaction, address and order information to prevent fraud, account misuse and chargebacks. A flagged order may be paused for proportionate manual review. We will not use a solely automated decision with a serious adverse effect unless it is lawful, reasonably necessary, transparent where required and supported by appropriate safeguards.
11. Security
We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, access, disclosure or destruction. Measures may include access controls, encryption in transit, provider due diligence, backups, monitoring and incident procedures. No internet service is completely secure, so users should protect account credentials and contact us promptly if they suspect misuse.
12. Access, correction and privacy choices
Subject to the Privacy Act and applicable exceptions, an individual may request access to personal information we hold about them and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Individuals may also withdraw marketing consent, unsubscribe from commercial messages and ask questions about how their information is handled.
To make a request, email info@blanc9.shop. No special form is required. We may ask for information reasonably needed to confirm identity, protect another person’s privacy and understand the request. We will respond within a reasonable period. Access is generally provided in the requested manner if reasonable and practicable. If a lawful access or correction request is refused, we will provide written reasons where required and explain available complaint mechanisms. We do not charge for making a correction request and charge for access only where a reasonable lawful amount is permitted and disclosed in advance.
13. Automated decisions and children
We may use automated tools to flag potentially fraudulent transactions, but significant adverse action is subject to proportionate review where appropriate. The store is not directed at young children, and customers must have legal capacity to make a purchase. If we learn that personal information has been collected from a child in circumstances that are unfair, unnecessary or otherwise contrary to applicable law, we will take reasonable corrective steps.
14. Complaints and changes
Please raise privacy concerns first with info@blanc9.shop so we can investigate. We will acknowledge the complaint, assess the facts, seek further information where reasonably needed and communicate an outcome within a reasonable time. If the complaint is not resolved, the individual may complain to the Office of the Australian Information Commissioner. The OAIC generally expects a person to give the organisation a reasonable opportunity, commonly 30 days, to respond first.
We may update this policy when our practices or legal obligations change. Material changes will be highlighted through the website or another appropriate channel. The date at the top shows the latest revision.
15. Reasonable necessity and secondary uses
We seek to collect only personal information reasonably necessary for our functions or activities. We use or disclose information for the primary purpose communicated at collection, for a related secondary purpose that an individual would reasonably expect where permitted, with consent, or as otherwise authorised or required by Australian law.
Examples of related operational purposes may include protecting the checkout against fraud, maintaining service logs, analysing aggregated store performance, responding to reviews, pursuing legitimate debts, defending claims and improving packaging or delivery performance. Direct marketing is separately controlled by APP 7 where applicable and by the Spam Act.
16. Service communications and marketing
Order confirmations, proof requests, dispatch notices, safety communications, refund updates and responses to enquiries are service messages and may be sent where necessary to perform a contract or meet legal obligations. A customer cannot opt out of essential messages while an order is active, although they may choose not to place future orders.
Promotional email or text messages are separate. Where express consent is required or used, marketing is sent only after a clear affirmative choice. Inferred consent is relied on only where there is a provable ongoing relationship and it is reasonable to expect directly related marketing. An opt-out is offered in every commercial electronic message. We do not make marketing consent a condition of buying goods where it is unnecessary for the purchase.
17. Reviews, photographs and public content
If a customer chooses to publish a review, username, photograph or comment, the selected content may be visible publicly. We may associate it with the relevant product and indicate whether the reviewer’s purchase was verified. We do not publish private order details, addresses or payment information as part of a review.
A reviewer may ask us to correct or remove personal information contained in their contribution, subject to applicable rights, freedom-of-expression considerations, recordkeeping and legal claims. Removing a public review does not necessarily require deletion of a limited internal moderation or transaction record.
18. Accuracy and account responsibilities
Customers should keep delivery and contact details accurate and tell us promptly if they change. Account holders are responsible for keeping credentials confidential and should use a unique password. We may temporarily restrict an account or request verification where unusual activity indicates a security risk.
We take reasonable steps to correct information that we know is inaccurate. Some transaction records cannot simply be overwritten because accounting or fraud-prevention rules require an audit trail; in those cases, a correction or explanatory record may be added.
19. Detailed retention considerations
We decide retention by considering statutory limitation periods, tax requirements, product lifespan, recall needs, complaint history, fraud risk and whether data can be anonymised. Basket and browsing information may be held for a shorter period than completed order records. Proofs and manufacturing instructions may be held long enough to resolve production questions, manage a lawful reprint and establish what the customer approved.
Backups are protected and overwritten on a managed cycle. Information scheduled for deletion may remain in a restricted backup until that cycle completes, unless restoration is necessary. If restored, the deletion instruction will be reapplied where appropriate.
20. Data breaches
We assess suspected personal-data breaches promptly, take containment and recovery steps, document the facts and evaluate the likelihood of serious harm. If the Notifiable Data Breaches scheme applies and remedial action does not prevent the likely serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, subject to lawful exceptions.
21. Requests made through an authorised representative
An individual may authorise another person to make a privacy request. We may ask for evidence of authority and verify the identity of the person whose information is involved. We will communicate only the information within the representative’s authority and may contact the individual directly where necessary to prevent fraud or clarify instructions.
22. Limits and exemptions affecting requests
Access and correction rights are important but subject to exceptions. A request may be limited where access would unreasonably affect another person’s privacy, reveal evaluative commercially sensitive information, prejudice enforcement activity or legal proceedings, be unlawful, or fall within another statutory ground. Where we cannot comply fully, we will explain the relevant reason unless it would be unreasonable or unlawful to do so and will inform the person about complaint rights.
23. Privacy by design
When introducing a new provider, feature or higher-risk information-handling activity, we consider necessity, transparency, access restrictions, retention, security, individual expectations and overseas disclosure. We conduct an appropriate privacy impact assessment where warranted. Contracts with service providers address confidentiality, security, sub-providers, assistance with access and correction, incident response and deletion or return of information.
Thanks for subscribing!
This email has been registered!