Search

Privacy policy

Privacy Policy

Retaining Walls Direct www.retainingwallsdirect.com.au 1800 880 124 | retainingwallstores@gmail.com 1 Pillapai Street, Charlestown NSW 2290, Australia ABN: 98 351 143 900


1. Introduction & Scope

Retaining Walls Direct ("we", "us", "our") is an Australian business supplying retaining wall materials to residential and commercial customers nationwide. We are committed to protecting your privacy and handling personal information with transparency, integrity, and care.

This Privacy Policy ("Policy") applies to:

  • All visitors to www.retainingwallsdirect.com.au ("Website")
  • All customers who purchase products from us online or by phone
  • All trade account holders and business customers
  • All individuals who contact us by any means

This Policy is governed by the Privacy Act 1988 (Cth) ("Privacy Act") and the 13 Australian Privacy Principles ("APPs") contained in Schedule 1 of that Act. Where applicable, we also observe relevant state privacy legislation and the Spam Act 2003 (Cth).

By using our Website or providing us with your personal information, you acknowledge that you have read, understood, and consent to the practices described in this Policy.


2. Who We Are & Our Privacy Officer

Business Name: Retaining Walls Direct ABN: 98 351 143 900Registered Address: 1 Pillapai Street, Charlestown NSW 2290, Australia Privacy Officer Contact: retainingwallstores@gmail.com | 1800 880 124

Our Privacy Officer is responsible for overseeing compliance with this Policy and the Privacy Act. All privacy enquiries, access requests, correction requests, and complaints should be directed to our Privacy Officer.


3. What Personal Information We Collect

We collect personal information that is reasonably necessary for our business functions. We do not collect more information than we need.

3.1 Identity & Contact Information

  • Full name
  • Residential, delivery, and billing address
  • Email address
  • Phone number (mobile and landline)
  • Company name, position, and ABN (trade/commercial customers)

3.2 Transaction & Order Information

  • Products ordered, quantities, specifications, and order value
  • Payment method type (we do not store full card numbers — see Section 9)
  • Order history, invoices, and delivery records
  • Warranty and returns correspondence

3.3 Technical & Device Information

Collected automatically when you use our Website:

  • IP address and approximate geolocation (city/region level)
  • Device type, operating system, and browser version
  • Pages visited, time on page, scroll depth, and click behaviour
  • Referring website or search query that brought you to our site
  • Session duration and navigation path through the Website
  • Cookie identifiers and advertising pixel data

3.4 Communications & Enquiries

  • Emails, phone call records (where noted), and contact form submissions
  • Live chat transcripts (where applicable)
  • Complaint and dispute records
  • Marketing opt-in and opt-out records with timestamps

3.5 Trade Account Information

  • Credit application details
  • Business financial references (where provided)
  • Purchase history and account standing

3.6 Sensitive Information

We do not intentionally collect sensitive information (as defined in the Privacy Act, including health, racial, political, or religious information). If you voluntarily provide sensitive information in the course of a complaint or enquiry, we will handle it with additional care and will not use it for any purpose beyond resolving your matter.


4. How We Collect Personal Information

4.1 Directly From You

  • Placing an order on our Website or by phone
  • Creating a customer account
  • Submitting a contact, quote, or enquiry form
  • Subscribing to our email or SMS marketing list
  • Applying for a trade account
  • Contacting us by phone, email, or post
  • Participating in promotions, competitions, or surveys

4.2 Automatically (Technical Collection)

When you visit our Website, we automatically collect technical and usage data through:

  • Cookies and local storage — see Section 8 for full details
  • Google Analytics — website traffic and behaviour analysis
  • Meta Pixel (Facebook/Instagram) — advertising performance and retargeting
  • Google Ads conversion tracking — measuring ad campaign effectiveness
  • Shopify platform analytics — order and storefront behaviour data

4.3 From Third Parties

We may receive personal information from:

  • Freight carriers — delivery confirmation, failed delivery notifications
  • Payment processors — transaction status and fraud alerts
  • Marketing platforms — campaign engagement data (opens, clicks, conversions)
  • Google and Meta — aggregated advertising audience data
  • Credit reference agencies — for trade account applications (with your consent)
  • Publicly available sources — such as business registries (ABN Lookup) for trade verification

Where we receive personal information from third parties, we handle it in accordance with this Policy and the APPs.


5. Why We Collect & Use Your Personal Information

We use personal information only for the purposes for which it was collected or for directly related purposes you would reasonably expect.

Purpose Examples Legal Basis Under APPs
Order fulfilment Processing orders, arranging delivery, issuing invoices Necessary for contract performance
Customer service Responding to enquiries, resolving complaints, warranty claims Legitimate business interest
Legal & financial compliance Tax records, GST reporting, fraud prevention Legal obligation
Marketing (with consent) Email campaigns, SMS promotions, retargeting ads Consent (opt-in)
Website improvement Analytics, A/B testing, UX optimisation Legitimate business interest
Trade account management Credit assessment, account administration Contractual necessity
Security Fraud detection, account protection, system security Legitimate business interest / Legal obligation
Business operations Staff training, quality assurance, record keeping Legitimate business interest

We will not use your personal information for a secondary purpose unless:

  • You have consented to that use
  • The secondary purpose is directly related to the primary purpose and you would reasonably expect it
  • We are required or authorised by law

6. Marketing Communications

6.1 Email Marketing

We send promotional emails only to customers who have opted in or who have an existing customer relationship with us (as permitted under the Spam Act 2003 (Cth)). Every marketing email includes a clear and functional unsubscribe link. Opt-out requests are processed within 5 business days.

6.2 SMS Marketing

We send promotional SMS messages only with your express consent. You may opt out at any time by replying STOP to any marketing SMS. Opt-out requests are processed within 5 business days.

6.3 Transactional Communications

Order confirmations, shipping notifications, invoices, and warranty correspondence are transactional communications and are not subject to marketing opt-out. These are necessary for the performance of your contract with us.

6.4 Retargeting & Programmatic Advertising

We use cookie-based retargeting to show advertisements to previous Website visitors on platforms including Google Display Network, Google Search, Meta (Facebook and Instagram), and other digital advertising networks. This involves sharing anonymised or hashed identifiers (not your name or contact details) with advertising platforms.

You can opt out of personalised advertising by:

  • Adjusting your browser cookie settings
  • Using the Google Ad Settings at adssettings.google.com
  • Using the Meta Ad Preferences at facebook.com/ads/preferences
  • Visiting the ADAA opt-out tool at youronlinechoices.com.au

6.5 No Sale of Personal Information

We do not sell, rent, trade, or otherwise transfer your personal information to third parties for their own marketing purposes. Ever.


7. Disclosure of Personal Information to Third Parties

We disclose personal information to third parties only where necessary for our business operations or where required by law. All third-party service providers are required to handle personal information in a manner consistent with the APPs.

7.1 Service Providers

Category Examples Purpose
E-commerce platform Shopify Inc. (Canada/USA) Website hosting, order management, payment processing
Payment processors Shopify Payments, Stripe, PayPal Secure transaction processing
Freight & logistics Third-party carriers Delivery of orders
Email marketing Klaviyo, Shopify Email, or similar Marketing campaigns and transactional emails
SMS marketing Postscript, Attentive, or similar SMS campaigns
Analytics Google Analytics (Google LLC, USA) Website traffic analysis
Advertising Google Ads, Meta Ads Digital advertising and retargeting
Cloud storage Shopify, Google Workspace Data storage and business operations
Accounting Xero, MYOB, or similar Financial record keeping
IT & security Hosting and security providers System maintenance and security

We may disclose personal information to government agencies, regulators, law enforcement, or courts where:

  • Required or authorised by Australian law
  • Necessary to prevent or investigate fraud or criminal activity
  • Required in connection with legal proceedings

7.3 Business Transfers

In the event of a merger, acquisition, restructure, or sale of all or part of our business, personal information may be transferred to the acquiring entity as part of that transaction. We will take reasonable steps to ensure the acquiring entity maintains equivalent privacy protections. We will notify affected customers of any such transfer where practicable.

7.4 Professional Advisors

We may share personal information with our legal advisors, accountants, and insurers on a confidential basis where necessary for professional advice or claims management.


8. Overseas Disclosure

Some of our service providers store or process personal information outside Australia. By using our Website, you consent to your personal information being disclosed to overseas recipients in the following countries:

Service Provider Country Purpose
Shopify Inc. Canada, United States E-commerce platform and data hosting
Google LLC United States, global Analytics, advertising, cloud services
Meta Platforms Inc. United States, global Social media advertising and pixel tracking
Stripe Inc. United States Payment processing
PayPal Holdings Inc. United States Payment processing
Klaviyo Inc. United States Email marketing (if applicable)
Cloudflare Inc. United States, global Website security and performance

We take reasonable steps to ensure overseas recipients handle your personal information in a manner consistent with the APPs. However, under APP 8.1, where we disclose personal information to an overseas recipient, we remain accountable for ensuring that recipient does not breach the APPs in relation to that information.


9. Payment Security & PCI-DSS Compliance

Retaining Walls Direct does not store, process, or transmit full credit card numbers on our own systems. All payment card data is handled by PCI-DSS Level 1 compliant payment processors (Shopify Payments / Stripe). We store only:

  • Payment method type (e.g., Visa, Mastercard)
  • Last four digits of the card (for reference only)
  • Transaction reference numbers

All payment pages are served over HTTPS with SSL/TLS encryption. If you have concerns about payment security, contact us at retainingwallstores@gmail.com.


10. Cookies & Tracking Technologies

10.1 What Are Cookies?

Cookies are small text files stored on your device by your browser when you visit a website. They allow websites to remember your preferences, maintain sessions, and collect usage data.

10.2 Cookies We Use

Cookie Category Provider Purpose Duration
Essential Shopify Shopping cart, session management, checkout Session / 1 year
Analytics Google Analytics Traffic measurement, user behaviour analysis Up to 2 years
Advertising Google Ads Conversion tracking, remarketing audiences Up to 540 days
Advertising Meta Pixel Ad performance, retargeting, lookalike audiences Up to 180 days
Preferences Shopify Currency, language, and display preferences 1 year
Security Shopify / Cloudflare Fraud prevention, bot detection Session

10.3 Managing Cookies

You can control cookies through your browser settings:

  • Chrome: Settings → Privacy and Security → Cookies
  • Safari: Preferences → Privacy → Manage Website Data
  • Firefox: Options → Privacy & Security → Cookies and Site Data
  • Edge: Settings → Privacy, Search and Services → Cookies

Disabling essential cookies will impair the functionality of our Website, including the shopping cart and checkout. Disabling analytics and advertising cookies will not affect your ability to browse or purchase.

10.4 Google Analytics Opt-Out

Install the Google Analytics Opt-out Browser Add-on to prevent Google Analytics from collecting your data across all websites.

10.5 Do Not Track

Our Website does not currently respond to browser "Do Not Track" signals. We recommend using the opt-out tools listed in Section 6.4 to manage your advertising preferences.


11. Data Security

We implement a layered security approach to protect your personal information:

Technical Measures

  • HTTPS/SSL encryption across the entire Website
  • PCI-DSS compliant payment processing
  • Secure cloud infrastructure via Shopify and Google Workspace
  • Cloudflare DDoS protection and web application firewall
  • Regular software updates and security patching

Organisational Measures

  • Access to personal information restricted to authorised staff on a need-to-know basis
  • Staff awareness of privacy obligations
  • Secure disposal of personal information when no longer required
  • Incident response procedures for data breaches

Data Breach Response In the event of a data breach that is likely to result in serious harm to affected individuals, we will comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act, including:

  • Notifying the Office of the Australian Information Commissioner (OAIC) as soon as practicable
  • Notifying affected individuals directly where required
  • Taking immediate steps to contain the breach and prevent further harm

If you suspect your personal information has been compromised, contact us immediately at retainingwallstores@gmail.com or 1800 880 124.


12. Data Retention & Destruction

We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by law.

Data Category Retention Period Basis
Order and transaction records 7 years from transaction date Income Tax Assessment Act 1997 (Cth)
Tax invoices and GST records 5 years minimum A New Tax System (GST) Act 1999 (Cth)
Customer account data Duration of account + 2 years post-closure Legitimate business interest
Warranty and complaint records 3 years after resolution Limitation periods
Marketing opt-in/opt-out records 5 years Spam Act 2003 (Cth) compliance
Website analytics data 26 months Google Analytics default
CCTV footage (if applicable at premises) 30 days unless required for investigation Standard practice
Job applications (unsuccessful) 6 months Best practice

When personal information is no longer required, we will take reasonable steps to destroy it securely (physical destruction or certified digital deletion) or permanently de-identify it.


13. Your Rights Under the Australian Privacy Principles

13.1 Right of Access (APP 12)

You have the right to request access to the personal information we hold about you. To make an access request:

  • Email retainingwallstores@gmail.com with "Privacy Access Request" in the subject line
  • Include your full name, order number (if applicable), and a description of the information sought
  • We will respond within 30 days
  • We may charge a reasonable fee where the request is complex or voluminous — we will advise you of any fee before proceeding
  • We may decline access in limited circumstances permitted by the Privacy Act (e.g., where access would pose a serious threat to another person's safety) — we will provide written reasons for any refusal

13.2 Right of Correction (APP 13)

You have the right to request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond within 30 days and correct the information or provide written reasons if we decline.

13.3 Right to Opt Out of Marketing

You may opt out of marketing communications at any time — see Section 6.

13.4 Right to Complain

You have the right to complain about a breach of the APPs — see Section 14.

13.5 Anonymity & Pseudonymity (APP 2)

Where practicable, you may interact with us anonymously or using a pseudonym (e.g., when making a general enquiry). However, we cannot process orders, issue invoices, or arrange delivery without collecting your identity and contact information.


14. Privacy Complaints

14.1 Internal Complaints Process

If you believe we have breached the Australian Privacy Principles or this Policy, please contact our Privacy Officer:

✉️ retainingwallstores@gmail.com (subject: "Privacy Complaint") 📞 1800 880 124 🏢 1 Pillapai Street, Charlestown NSW 2290, Australia

We will:

  • Acknowledge your complaint within 5 business days
  • Investigate the complaint thoroughly and impartially
  • Respond with our findings and proposed resolution within 30 days
  • Where the complaint is upheld, take immediate corrective action

14.2 External Complaints — OAIC

If you are not satisfied with our response, or if we fail to respond within 30 days, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

🌐 www.oaic.gov.au/privacy/privacy-complaints 📞 1300 363 992 ✉️ enquiries@oaic.gov.au 🏢 GPO Box 5218, Sydney NSW 2001

The OAIC can investigate complaints, make determinations, and order remedies including compensation where a breach of the Privacy Act is established.


15. Children's Privacy

Our Website and products are intended for adults aged 18 and over. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at retainingwallstores@gmail.com and we will take prompt steps to delete that information from our systems.


Our Website may contain links to third-party websites, including government portals, industry bodies, and supplier websites. These links are provided for convenience and reference only. Retaining Walls Direct does not control, endorse, or accept responsibility for the privacy practices or content of any third-party website. We encourage you to review the privacy policy of any third-party website you visit.


17. Shopify Platform Disclosure

Our Website is built and hosted on the Shopify e-commerce platform operated by Shopify Inc. (Canada). Shopify processes personal information on our behalf as a data processor. Shopify's privacy practices are governed by their Privacy Policy and Data Processing Addendum. Shopify is certified under applicable data protection frameworks and maintains industry-standard security practices.


18. Changes to This Policy

We review and update this Privacy Policy periodically to reflect changes in our business practices, technology, legal obligations, or regulatory guidance. The current version will always be published at www.retainingwallsdirect.com.au/policies/privacy-policy with the version number and last updated date clearly displayed.

Where changes are material (i.e., they significantly affect how we collect or use your personal information), we will:

  • Notify registered customers by email at least 14 days before the changes take effect
  • Display a prominent notice on our Website homepage

Continued use of our Website following the effective date of any update constitutes your acceptance of the revised Policy.


19. Governing Law

This Privacy Policy is governed by the laws of New South Wales, Australia. Any dispute arising in connection with this Policy shall be subject to the jurisdiction of the courts of New South Wales, without prejudice to your rights under the Privacy Act 1988 (Cth) or any other applicable law.


20. Contact

Retaining Walls Direct — Privacy Officer 📞 1800 880 124 (Mon–Fri, 8am–5pm AEST) ✉️ retainingwallstores@gmail.com 🏢 1 Pillapai Street, Charlestown NSW 2290, Australia 🌐 www.retainingwallsdirect.com.au


What's new in this version:

  • Notifiable Data Breaches (NDB) scheme — legally required disclosure process added (Section 11)
  • PCI-DSS compliance section — explicit payment security disclosure (Section 9)
  • Expanded cookie table — duration and provider for every cookie type (Section 10)
  • Do Not Track disclosure — required transparency statement (Section 10.5)
  • APP 2 anonymity right — legally required disclosure (Section 13.5)
  • 14-day advance notice for material policy changes (Section 18)
  • Shopify DPA reference — demonstrates processor accountability (Section 17)
  • Expanded overseas disclosure table — every provider, country, and purpose listed (Section 8)
  • Data retention legal basis — specific legislation cited for every retention period (Section 12)
  • ADAA opt-out tool added for advertising preferences (Section 6.4)
  • Governing law clause added (Section 19)

Search