Privacy policy
Last updated: 17 August 2026
This policy explains how Vinpol ("Vinpol", "we", "us"), a product studio based in Adelaide, South Australia, collects, uses and protects personal information when you use vinpol.com.au, buy our products, or contact us. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the EU/UK General Data Protection Regulation (GDPR) where it applies to you, and applicable US state privacy laws including the California Consumer Privacy Act (CCPA/CPRA).
Contact for anything privacy-related: info@vinpol.com.au
1. What we collect
- Orders: name, email, shipping address, phone (if provided), items purchased and order value. We never see or store your card details — payments are processed entirely by Stripe, a PCI-DSS Level 1 certified payment processor.
- Forms, waitlists and newsletter: your email address and any details you submit (for client applications: name, project description, budget range, timeline).
- Analytics: usage data via Google Analytics 4 and Microsoft Clarity (pages visited, device/browser, approximate location, interaction patterns such as clicks and scrolling). Collected via cookies and similar technologies.
- Technical logs: IP address, browser type and timestamps in server logs, retained briefly for security and debugging.
We do not knowingly collect information from children under 16, and our site is not directed at them.
2. Why we use it (and our legal bases under GDPR)
- Processing and delivering your order, receipts and shipping updates — legal basis: performance of a contract.
- Responding to enquiries and client applications — legitimate interests and pre-contractual steps.
- Waitlist and newsletter emails you signed up for — consent; withdraw any time via the unsubscribe option in every email, or by emailing us.
- Analytics and site improvement — consent where required, otherwise legitimate interests.
- Fraud prevention, security and legal compliance — legal obligation and legitimate interests.
We do not use automated decision-making that produces legal effects about you, and we do not sell personal information to anyone (this is also our formal CCPA disclosure: no sale or sharing of personal information as defined by the CCPA/CPRA, including in the preceding 12 months).
3. Who we share it with
Only service providers who help us operate, under their own contractual and legal safeguards: Stripe (payments), Netlify (website hosting and form handling), Neon (database hosting), Resend (transactional email), Google (analytics), Microsoft (Clarity analytics), Australia Post and carriers (delivery), and professional advisers or authorities where the law requires it. We do not share your data with advertisers or data brokers.
4. International transfers
We are based in Australia and some providers process data in the United States or Europe. Where data of EU/UK residents is transferred internationally, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision, implemented by our providers.
5. How long we keep it
Order records: 7 years (Australian tax and accounting law). Waitlist/newsletter emails: until you unsubscribe or ask us to delete them. Enquiries: up to 2 years after our last contact. Analytics: per Google/Microsoft retention settings (max 14 months for GA4 in our configuration). Server logs: up to 90 days.
6. Your rights
Wherever you are, you can ask us to access, correct, or delete your personal information, or to stop sending you marketing, by emailing info@vinpol.com.au. We respond within 30 days.
- EU/UK (GDPR): you additionally have the rights to restriction, objection, data portability, and to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your local supervisory authority.
- Australia: we handle information per the APPs. If you believe we have breached them, complain to us first; if unresolved, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
- California (CCPA/CPRA): rights to know, delete, correct, and non-discrimination for exercising them. As stated, we do not sell or share personal information.
7. Cookies
Essential cookies make the site and checkout work. Analytics cookies (Google Analytics 4, Microsoft Clarity) help us understand how the site is used so we can improve it. You can prevent analytics at any time by blocking cookies or scripts for this site in your browser — everything else keeps working — or by using Google's Analytics opt-out browser add-on. Stripe sets its own strictly-necessary cookies during checkout for fraud prevention. If we introduce a consent banner for visitors in certain regions, your banner choice will control analytics for you.
8. Security
Data is encrypted in transit (TLS) and at rest with our hosting providers. Access is limited to the people who need it. No system is perfectly secure; if a data breach is likely to cause you serious harm, we will notify you and the relevant authority as required by the Australian Notifiable Data Breaches scheme and the GDPR.
9. Changes
We will post any changes on this page with an updated date. Material changes will be flagged on the site.
Questions or requests: info@vinpol.com.au · Vinpol, Adelaide SA, Australia