Last Updated: 30 August 2021
2. What information do we collect and how is it collected?
We collect Personal Information, as defined in the Privacy Act (including Sensitive Information as defined in the Privacy Act), when you access or use our Services.
2.1. Personal Information provided by you
We collect information that you provide to us via use of our Services as well as through any other means used to contact us.
The kinds of Personal Information we collect include your contact information such as your name, email address, organization, demographic information such as postcode, preferences and interests, other information relevant to customer surveys and or offers, address and phone or mobile number.
We reserve the right to maintain, store and use any information or data where we reasonably believe that such action is required to comply with any legal or regulatory obligations, to prevent criminal or other unlawful activity whether immediate or in the future, or where we have a legitimate business reason to do so, including collection of amounts owed, resolving disputes, enforcing our Terms or for record keeping integrity.
2.2. Automatically collected Personal Information
We automatically record information from your device and its software when you access our Services, including your IP address, browser and device type, internet service provider, mobile phone carrier, platform type, the website from which you came and the website to which you are going when you leave our Services, date and time stamp and cookies that may uniquely identify your browser or account.
When accessing our Services using a mobile device, we may also receive and collect identification numbers associated with your device, mobile carrier, device type and manufacturer, and, if enabled, geographical location data (including GPS). Please note that some of the information we collect, for example an IP address, can sometimes be used to approximate a device's location.
2.3. Personal Information collected via Google Analytics
We use Google Analytics, which allows us to anonymously track the use of our Services by recording the number of users who have visited, the number of pages viewed, navigation patterns, what systems users have and the date and time of visits through cookies. This information is collected for statistical purposes only and cannot be used to identify you.
We may use a range of services and functions offered by Google Analytics. We also use Google Analytics to partner with third parties and advertise online. Our third-party partner may use technologies such as cookies and third party Tracking Technologies to gather information about your activities on our website and other sites in order to provide you advertising based on your browsing activities and interests.
2.4. Third Party Payment Processor
2.5. Personal Information collected via cookies
Our Services may use small pieces of data called cookies to identify a user who engages with our Services and to compile records of a user’s history of engaging with our Services. Cookies are stored by a users’ browser while the user browses a website.
By using the Services, you grant us permission to place and store cookies on browser. Cookies may be used by us to collect personal information including but not limited to:
(a) your computer's operating system;
(b) your computer's browser type and capabilities;
(c) your computer's Internet Protocol (IP) address and geolocation;
(d) web pages visited, including how you were referred to each web page; and
(e) web page usage statistics, including the time spent on each web page.
In some circumstances, we can see information obtained from cookies with an identifiable individual. For example:
(a) if you open, read or delete a targeted email that we have sent to you;
(b) if you click a marketing e-mail you receive from us, we may be able to view content that you have viewed from our Services; or
(c) if we combine data from publicly available sources, and from our different e-mail, website, and personal interactions with you.
You may choose to adjust, reject, delete or block all or specific types of cookies on our Services by clicking on the cookie preferences or by changing your browser settings. Please note that most browsers automatically accept cookies and if you do not wish cookies to be used, you may need to actively delete or block the cookies.
If you wish to disable cookies, please be aware that some functionality of our Services will not be available to you.
By using our website without deleting or rejecting some or all cookies, you agree that we can place those cookies that you have not deleted or rejected on your device.
From the first access of our Services, these cookies allow the Services to function correctly and allow you to view content on your device by recognizing the language and market of the country from which you have chosen to connect. If you are a registered user, they will allow you to be recognized and to access the Services offered. Navigation cookies are technical cookies and are needed for the functioning of the Services.
Based on your request, these cookies allow you to be recognized for choices that you make (such as your username, language or the region in which you are located) when you subsequently access the Services, so that you do not have to enter your information each time you use the Services (for example: remember me).
For example, if you have added items into your shopping bag and closed the session without completing the purchase and without eliminating those items, these cookies may allow you to continue the shopping experience the next time you access the Services (within a limited time period), finding the same articles that were selected.
Functional cookies are not essential to the functioning of the Services, but rather improve navigation quality and experience. These cookies do not track your browsing activity on other websites. They do not gather any information about you that could be used for advertising or remembering where you have been on the Internet outside our Services.
These cookies allow us to utilize data analytics to measure and improve the performance of our Services. These first party cookies are our property and are used to collect data to prepare statistical analyses on the navigation methods of our Service’s users. These cookies do not collect information that identifies a visitor down to an individual level that is available to us.
Social Network Cookies
These cookies (including web beacons and other tracking and storage technologies) are necessary to allow your social media account to interact with our Services. For example, they are used to express your appreciation and to share it with your social networking friends. The social network cookies are not needed for navigation.
Our own and third party marketing and profiling cookies
These cookies are aimed at creating user-related profiles to send commercial messages that meet the preferences shown during the visit, or to improve your navigation experience. While you navigate our Services, these cookies are useful for showing you products of interest to you or which are similar to those you have viewed. Third party cookies are those that have been sent by our trusted third-party companies. These cookies allow you to be provided with our commercial offering on other affiliated websites (retargeting). With third party cookies, we do not have control of the information provided by the cookie and we do not have access to this data. This information is entirely controlled by third party cookies and you can inform yourself on their respective policies and knowingly manage your consent or refusal.
The association with your shopping cart.
Stores the category info on the page, that allows to display pages more quickly.
The items that you have in the Compare Products list.
Your preferred currency
An encrypted version of your customer id with the store.
An indicator if you are currently logged into the store.
An encrypted version of the customer group you belong to.
Stores the Customer Segment ID.
A flag, which indicates whether caching is disabled or not.
Your session ID on the server.
We collect data on page views, first visits and return visits.
Allows guests to edit their orders.
The last category you visited.
The most recent product you have viewed.
Indicates whether a new message has been received.
Indicates whether it is allowed to use cache.
A link to information about your cart and viewing history if you have asked the site.
The ID of any polls you have recently voted in.
Information on what polls you have voted on.
The items that you have recently compared.
Information on products you have emailed to friends.
The store view or language you have selected.
The products that you have recently viewed.
An encrypted list of products added to your Wishlist.
The number of items in your Wishlist.
3. For what purposes do we collect and use Personal Information?
(a) for provision of the Services;
(b) for communication with you and to provide messaging and/or communications to you in association with the functions and features of the Services;
(c) for communicating to you any announcements and updates, updated terms, conditions and policies, security alerts, technical notices, support and administrative messages;
(d) for analysis, monitoring, development and improvement of our Services, including other products or services;
(e) for analysis of trends, buyer behavior and the development of marketing offers and promotions;
(f) for security purposes, including to protect the Services and our property from abuse, fraud, malicious, unauthorized access or potentially illegal activities, and to protect our rights, safety and property and that of our other users;
(g) for sending marketing communications to you, including notifying you of promotional or advertising offers, contests and rewards, upcoming events and other news about products and services offered by us and use of our Services;
(h) to comply with relevant laws and regulations where applicable; and
(i) for the performance of other functions described at the time of collection or as consented to in relation to our Services.
4. How do we store and protect your information?
4.1. Storage of Personal Information
4.2. Who can access your Personal Information?
Please note that no method of electronic transmission or storage is 100% secure and we cannot guarantee the absolute security of your Personal Information. Transmission of Personal Information over the Internet is at your own risk and you should only enter, or instruct the entering of, Personal Information to the Services within a secure environment. It is your responsibility to ensure that you keep your Personal Information safe, including keeping your software up to date to prevent security breaches.
We reserve the right to maintain and store any information or data where, we reasonably believe, in our sole discretion, that such action is required to comply with any legal or regulatory obligations, to prevent criminal or other unlawful activity whether immediate or in the future, or where we have a legitimate business reason to do so, including collection of amounts owed, resolving disputes, enforcing our Terms or for record keeping integrity.
We destroy or de-identify your Personal Information after 2 years where it is no longer needed for the purposes outlined in this Policy. However, we may also be required to keep some of your personal information for specified periods of time, for example under certain laws relating to corporations, money laundering, and financial reporting legislation.
5. To whom your Personal Information is disclosed?
Your Personal Information may be disclosed to individuals and companies, for the purposes described in this Policy, as outlined below:
5.1. Nip Tuck Swimwear and Related Bodies Corporate
Your Personal Information may be accessed by us, including our directors, employees, officers and contractors. You consent to us providing your Personal Information, including Sensitive Information to our Related Bodies Corporate (as defined in the Corporations Act 2001 (Cth)).
5.2. Parties required by law
Your Personal Information may be disclosed by us to any party to whom we are required by law to provide your Personal Information and to any party to whom disclosure is permitted under the Australian Privacy Principles, or where we reasonably believe that disclosure is required to comply with any court orders, subpoenas, or other legal process or investigation including by tax authorities, if such disclosure is required by law. Where possible and appropriate, we will notify you if we are required by law to disclose your Personal Information.
5.3. Direct marketing
You agree and expressly and indefinitely consent to us using or disclosing Personal Information (other than Sensitive Information) to keep you informed about our promotions, products and services and other products and services that we consider may be of interest to you. For this purpose, disclosure may be made to our third-party service providers. We may communicate with you via phone, email, social media, SMS, or regular mail. If you have indicated a preference for a method of communication, we will endeavor to use that method wherever practical to do so.
You can opt-out of direct marketing communication activities undertaken by us at any time by clicking the “unsubscribe” or “opt-out” link on email communications from us, replying ‘Stop’ to a promotional SMS or by contacting us by phone or email.
5.4. Other third parties
We may share your Personal Information with third parties if it is reasonably related to the provision of our Services, including digital strategy and SEO companies. The third parties that we may share your Personal Information with includes consultants, contractors, credit agencies, debt collection agencies and our other service providers. Such services we procure may include identifying and disseminating advertisements, enforcement of our Terms, providing fraud detection and prevention services, processing payments or providing analytics services. We may also share your Personal Information with our business partners who offer goods or services to you jointly with us (for example, contests or promotions).
We may share your Personal Information where we have reason to believe that doing so is necessary to identify, contact or bring legal action against anyone damaging, injuring, or interfering (intentionally or unintentionally) with our rights or property, users, or anyone else who could be harmed by such activities.
We may also share your Personal Information with third parties, in connection with any company transaction (such as a merger, sale of assets or shares, reorganization, financing, change of control or acquisition of all or a portion of our business by another company or third party) or in the event of bankruptcy, dissolution, divestiture or any related or similar proceedings.
Note that we reserve the right to share your Personal Information with other third parties where, in our sole discretion, it is required to:
(a) investigate and defend ourselves against any third party claims or allegations;
(b) protect against harm to the rights, property or our safety, our users or the public as required or permitted by law; and
(c) detect, prevent or otherwise address criminal (including fraud or stalking), security or technical issues.
5.5. Overseas disclosure
Please note that some of the parties listed above to whom your Personal Information may be disclosed, may be located overseas, including countries such as Sri Lanka.
We use reasonable steps to ensure that these parties are either governed by substantially similar, accessible and enforceable laws to the Australian Privacy Principles or adhere to the Australian Privacy Principles, however to the maximum extent permitted by law, we are not liable for the privacy practices of such parties.
Please note that the transfer of your Personal Information to such overseas parties may pose risks to the security of your Personal Information as these countries may not have been issued with an adequacy decision as set out in the GDPR (see paragraph 11) or have appropriate safeguards in place, however by providing your Personal Information to us, you acknowledge and consent to disclosure of Personal Information to such overseas recipients.
6. Third party websites and social media
]Social Media Platforms also allow public access to your public social media profile, which may include your username, age range, country/language, list of friends or other information that you make publicly available and you understand that such information may therefore be accessible by us if you interact with its social media pages.
We may from time to time, have access to statistics regarding the number of views, navigation patterns, posts that you like, comment on or share and any user interactions with our social media pages and may use such information for the purpose of its marketing and promotion strategies.
7. How can you access or update your Personal Information?
At any time, you may request access to Personal Information we hold about you. We may refuse to provide access if the law allows us to do so, in which case we will provide reasons for our decision as required by law.
We take reasonable steps to keep your Personal Information accurate, complete and up-to-date. If, at any time, you discover that information held about you is incorrect, you may contact us to have the information deleted or corrected.
You may request access to the information we hold about you, or request that we delete, update or correct any Personal Information we hold about you, by setting out your request in writing and sending it to us in accordance with paragraph 10.
We will process your request as soon as reasonably practicable, provided we are not otherwise prevented from doing so on legal grounds. If we are unable to meet your request, we will let you know why.
8. How can you make a complaint about our privacy practices?
You may submit a written complaint about how we handle your Personal Information to our Privacy Officer via the details below. If you are not satisfied with our handling of your complaint or we have not replied to you within a reasonable period of time, then you are entitled to make a complaint to the Office of the Australian Information Commissioner or, if you are in the EU, a data protection authority or supervisory authority.
10. Contact us
All requests for access or corrections to your Personal Information and complaints should be directed to our Privacy Officer. If submitting a complaint, please provide our Privacy Officer with full details of your complaint and any supporting documentation:
(a) by e-mail at firstname.lastname@example.org; or
(b) by letter to The Privacy Officer, Unit 2b / 32 Ralph Street, Alexandria, NSW, Australia 2015.
If you are not satisfied with our handling of your complaint or we have not replied to you within a reasonable period of time, then you are entitled to make a complaint to the Office of the Australian Information Commissioner.
11. Application of GDPR
For the purpose of clarity, data processing of individuals in the European Union (EU) is carried on only occasionally and as such, no EU representative has been designated, however the General Data Protection Regulation (GDPR) (EU) 2016/679 may apply to you if you are resident of, reside in or are located in the EU.
If the GDPR applies, this paragraph applies in addition to the above paragraphs to the extent that we are acting as a “Data Controller” with respect to your Personal Information.
11.1. Consent and right to withdraw consent
To the extent that our legal basis for processing your Personal Information is consent, you have a right to withdraw consent to the collection of your Personal Information at any time by sending us a written request to do so via the contact details above.
11.2. Legal Basis
Our legal bases for collecting and processing your Personal Information for the purposes listed above may be:
(a) your express consent;
(b) for our legitimate interests in providing information about the Services to you or providing the Services to you and improving and developing the Services; and/or
(c) in order to perform a contract (whether verbal or written) for you in order to provide paid Services to you.
11.3. Your rights
We have summarized your rights under the GDPR, but please note that not all of the details of your rights have been included in these summaries. Please ensure to read the relevant laws and guidelines for a full explanation of these rights.
You may exercise these rights by contacting us to notify us of the rectification or provide information to complete your Personal Information.
(a) Right of access
You have a right to obtain confirmation as to whether or not your Personal Information is being processed and, if so, you may request access to that Personal Information and further information including the purposes of the processing, the categories of Personal Information concerned and the recipients of the Personal Information. The first copy of such information will be provided free of charge, but additional copies may be subject to a reasonable fee.
(b) Right of rectification
You have the right to obtain the rectification of inaccurate Personal Information concerning you and you have the right to have incomplete Personal Information completed.
(c) Right to erasure
You have the right to obtain the erasure of your Personal Information without undue delay if:
(i) the Personal Information is no longer necessary in relation to the purposes for which they were collected or otherwise processed;
(ii) you withdraw consent to consent-based processing;
(iii) you object to the processing under certain rules of the GDPR; or
(iv) the Personal Information has been unlawfully processed.
However, there are exclusions of the right to erasure such as where processing is necessary to exercise the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defense of legal claims.
(d) Right to restriction of processing
You have the right to restrict the processing of your Personal Information if:
(i) you contest the accuracy of the Personal Information;
(ii) processing is unlawful but you oppose erasure;
(iii) we no longer need the Personal Information for the purposes of our processing, but you require Personal Information for the establishment, exercise or defense of legal claims; or
(iv) you have objected to processing, pending the verification of that objection.
Where processing has been restricted on this basis, we may continue to store your Personal Information, however we will only process it with your consent, for the establishment, exercise or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest.
(e) Right to data portability
To the extent where your Personal Information has been provided based on consent, under a contract, or where processing is carried out by automated means, you have a right to receive Personal Information concerning you in a structured, commonly used and machine-readable format and you have a right to transmit that data to a Data Controller, except where this would adversely affect the rights and freedoms of others.
(f) Right to object
You have the right to object to our processing of your Personal Information for direct marketing purposes. If you make such an objection, we will cease to process your Personal Information for this purpose.