Privacy
Back to the siteWho we are
Constant Supply is an Australian business. We design and sell apparel under our own labels, produce licensed ranges for other brand owners, and run online stores on behalf of other businesses. In this policy “we”, “us” and “our” mean Constant Supply.
We are bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where we handle information about people in the European Economic Area or the United Kingdom, we also apply the standards in the GDPR.
What this policy covers
This policy covers this website and the online stores we own and operate. It also covers the stores we run for other businesses, except where that business publishes its own privacy policy. In those cases the store owner is the party responsible for your information and their policy governs; we handle it on their instructions.
What we collect
When you contact us
The enquiry form on this site asks for your name, and optionally your company, email address and phone number, along with the type of enquiry and whatever you write in the message. Only a name, an email address and a message are required. Everything you send us in that message is up to you, so please do not include anything sensitive that we do not need.
When you buy something
To fulfil an order we collect your name, email address, phone number, billing address, delivery address and the contents of your order. Card details go directly to our payment providers and are processed by them. We never see or store your full card number.
When you visit
Our servers and analytics tools record technical information: IP address, browser and device type, referring page, the pages you view and roughly when. On our stores this is tied to a session so the cart works. On this site it is used to understand traffic in aggregate.
When you subscribe
If you join a mailing list we keep your email address, and any name or preferences you give us, along with a record of what we sent and whether you opened it. Every marketing message we send has an unsubscribe link that works.
When you apply for a job
We keep the application, CV and any notes from the process. If you are not hired we keep it for up to twelve months in case something else comes up, and delete it after that unless you ask us to hold it longer.
What we do not collect
We do not knowingly collect information from anyone under 16. We do not buy personal information from data brokers, and we do not sell yours.
Why we collect it
- To answer you. An enquiry gets a reply from a person, and we keep the thread so the next conversation makes sense.
- To fulfil orders. Take payment, print, pack, ship, handle returns and warranty claims.
- To run the business. Accounting, tax, fraud checks and keeping the records the law requires us to keep.
- To improve what we make. Aggregate analysis of what sells, what gets returned and what people ask for.
- To market, where you have agreed to it. Email, SMS and advertising audiences, all of which you can opt out of.
Under the GDPR our lawful bases are: performing a contract with you (orders), our legitimate interests (running and improving the business, answering enquiries, preventing fraud), your consent (marketing, non-essential cookies) and compliance with legal obligations (tax and records).
Who we share it with
We share personal information with the service providers that make the business work, and only with what they need to do their job:
- Ecommerce and payments. Our store platform and payment gateways process orders and take payment.
- Production and delivery partners. The businesses that print and pack orders, and the couriers that deliver them, receive the delivery details for your order.
- Email, SMS and support tools. Used to send order notifications, respond to enquiries and send marketing you have opted into.
- Analytics and advertising platforms. Used to measure traffic and campaigns. Where this involves matching audiences, it is governed by your cookie and marketing choices.
- Professional advisers. Accountants, auditors and lawyers, where required.
- Brand owners whose stores we run. Where an order was placed on a store we operate for someone else, the store owner is entitled to that order's data.
We will also disclose information where the law requires it, or to establish or defend a legal claim. If the business is ever sold or restructured, personal information may transfer with it, subject to this policy.
We do not sell your personal information.
Where it goes
Several of the providers above are based overseas, or store data overseas, including in the United States, the European Union and Singapore. By using our services you accept that your information may be handled outside Australia. We take reasonable steps to work with providers that offer protections comparable to the Australian Privacy Principles.
Cookies and tracking
Cookies are small files a site stores in your browser. We use them for three things: keeping the site working (sessions, carts, security), measuring traffic, and advertising measurement.
Only the first is strictly necessary. You can block or delete cookies in your browser settings, and where we ask for consent you can decline without losing access to anything that matters. Blocking essential cookies will break checkout.
We do not currently respond to browser “Do Not Track” signals, because there is still no agreed standard for what a site should do when it receives one.
How long we keep it
- Enquiries. Up to two years from your last contact with us, unless you ask us to delete them sooner.
- Orders and invoices. Seven years, because Australian tax law requires it.
- Marketing lists. Until you unsubscribe, then a minimal suppression record so we do not email you again by accident.
- Analytics. Typically 14 to 26 months, depending on the tool.
How we look after it
Access to personal information is restricted to the people who need it, behind individual accounts with multi-factor authentication. Data is encrypted in transit, and our backups are encrypted and held separately from the live systems.
No system is perfectly secure, and we will not pretend otherwise. If a breach happens that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
Your rights
You can ask us to:
- tell you what personal information we hold about you;
- give you a copy of it, in a portable format where practical;
- correct anything that is wrong or out of date;
- delete it, where we are not required to keep it;
- stop using it for marketing, at any time;
- restrict or object to how we use it, where the GDPR or UK GDPR applies to you.
Email hello@constant.supply and we will respond within 30 days. We may need to verify who you are first. There is no charge for a reasonable request.
We do not make decisions that significantly affect you by automated means alone.
Complaints
If you think we have mishandled your information, tell us at hello@constant.supply and we will investigate and write back.
If our answer does not satisfy you, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au. In the EEA or UK you can complain to your local supervisory authority.
Changes
We update this policy when what we do changes. The date at the top is when it last changed. If a change materially affects how we handle your information, we will make that clear rather than quietly editing the page.
Contact
Privacy questions, requests and complaints go to hello@constant.supply. For anything else, use the enquiry form or call 1300 614 100. Our postal address is available on request.