Privacy Policy
How we collect, use, store and protect your personal information.
Last updated: 2 May 2026
The Sweet Creative ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains every type of personal information we collect, how we use it, who we share it with, where it's stored, and your rights as a customer or website visitor. It applies to www.thesweetcreative.com.au and to any contact you have with us by phone, email, SMS, or through our social channels.
We comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and the Spam Act 2003 (Cth).
How we collect personal information
We collect personal information directly from you in the following ways:
- When you place an order through our website (the BYO builder, a bundle, or a product page).
- When you fill in our contact form, send us an email, or call/text us.
- When you message us on Instagram (@thesweetcreativeau) or Facebook.
- When you upload reference photos as part of a custom order.
- Automatically as you use the site (cookies, server logs, analytics — see the Cookies section below).
If you give us personal information about a third party (for example, the recipient's name and address for a gift delivery), you confirm that you've checked with them and they're comfortable with us using that information to deliver the order.
What we collect
- Identity and contact info: your full name, email address, phone number.
- Recipient info: the recipient's name, delivery address (street + suburb), and any delivery instructions you provide.
- Order details: finish choice, palette or ribbon colour selection, custom palette descriptions, ribbon colour custom descriptions, foil topper requests, bubble vinyl text, gift tag messages, occasion notes, gift contents, photo tags, reference photos you upload, bundle selection, addon selections, and anything else you write in the order form's free-text fields.
- Payment information: we do not see, store, or process credit/debit card numbers, CVCs, or expiry dates. Payments are processed entirely by Stripe, Inc. We receive only the Stripe transaction reference (a session ID), the amount, the currency, the payment status, and any optional metadata (your name + email if you supplied it at checkout). For Afterpay and Klarna ("Pay in 4") payments, those providers process the transaction; we receive equivalent reference + status info.
- Technical data: IP address, browser type and version, operating system, device type, referring URL, pages viewed, timestamps, and approximate location (country + region) as inferred from the IP. Collected automatically by Netlify (our host) and our analytics tools.
- Communications: the content of emails, SMS messages, social media messages, phone call notes (if you've called and we've made a record), and any photographs we've received from you.
Why we collect it
- To process and confirm your order, deliver or arrange pickup, source the items in your bundle, and source any specific foil topper or custom request you've asked for.
- To send order-related communications (transactional, not marketing): order confirmations, delivery time confirmations, "your order is ready for pickup" notifications, refund confirmations.
- To respond to enquiries, complaints, refund requests, or follow-up questions.
- To meet our record-keeping obligations under the Australian Tax Office requirements (we must keep orders + invoices for seven years) and the Australian Consumer Law (we must be able to evidence transactions in the event of a dispute).
- To run aggregate analytics on our website usage, identify which pages convert and which don't, and improve the customer experience over time. Aggregate analytics never identify you individually.
- To run advertising on Meta platforms (Facebook + Instagram) when we choose to. The Meta Pixel measures whether visits/orders came from our ads and helps us optimise spend.
- To prevent fraud, abuse, and chargebacks (Stripe runs its own fraud screening on every transaction).
We do not use your contact details for marketing emails or SMS without your express consent first. Any marketing communications we ever send will include an unsubscribe link as required by the Spam Act.
Who we share it with
We share limited personal information only with the third-party service providers listed below, only to the extent each provider needs to perform its function. Each is bound by its own privacy obligations and we don't grant them any wider use of your data.
- Stripe, Inc. (USA + Australia) — payment processing. They see your name, email, billing address, card details (which they store, not us), order amount, IP address. Stripe Privacy Policy
- Afterpay + Klarna (when used at checkout) — only see what's needed to set up your "Pay in 4" plan: order total, currency, your name, email. Afterpay · Klarna
- Netlify, Inc. (USA) — website hosting + form submission storage. They store every order form submission (including reference photos), serve the website, and record server logs. Netlify Privacy Policy
- Google LLC (USA) — provides three separate services we use: (1) Google Analytics 4 for anonymised website usage measurement (IP addresses are masked, we don't link analytics to your identity); (2) Google Workspace hosts the email inbox at
Jade@thesweetcreative.com.au, so any email you send us or we send you passes through Google's mail servers and is stored in Google Workspace; (3) Google's standard infrastructure (anti-spam, anti-malware) for email security. Google Privacy Policy - Meta Platforms, Inc. (USA) — Meta Pixel measures conversions on any Facebook/Instagram ads we run. Meta receives the URL of the page you're on, your interaction events, and a hashed identifier; you can opt out via your Facebook ad preferences. Meta Privacy Policy
- Australia Post / local courier services — for deliveries outside our hand-delivery zones. They receive the recipient's name, delivery address, and contact phone number for delivery notifications. Australia Post Privacy
- Bathurst-region hand-delivery — we personally hand-deliver within Bathurst and nearby towns. The delivery address travels only with us on the day.
We do not sell your personal information. We do not share it with third-party advertisers, data brokers, or anyone other than the providers listed above. We may disclose information when required by Australian law (e.g., a court order, law-enforcement request, or tax-audit request from the ATO).
Cross-border data transfers
Several of the service providers above are located in the United States. By placing an order or using the site, you acknowledge that your personal information may be transferred to, stored in, and processed in the US under their respective privacy frameworks. The transfers occur through the necessary contractual and technical safeguards each provider has in place.
Specifically, the following providers transfer data outside Australia:
- Stripe — payment data (USA + Australia)
- Netlify — website + form submissions (USA)
- Google Analytics — usage data (USA)
- Google Workspace — email content (USA)
- Meta Pixel — ad-attribution data (USA)
If you'd prefer your personal information not be transferred outside Australia, please contact us before placing an order — we may be able to take the order over the phone instead.
Where it's stored
- Order records — on our business computer in Bathurst, NSW (an encrypted SQLite database inside our inventory app).
- Order form submissions + reference photos — Netlify's submission storage (USA).
- Payment + transaction records — Stripe (USA + Australia).
- Email correspondence — Google Workspace mailbox infrastructure (USA).
- Stocktake spreadsheet — on our business computer (no customer data; just product inventory).
- Backups — periodic local backups of the inventory database, stored only on our computer or an offline drive.
We rely on HTTPS encryption for all data in transit, encrypted-at-rest infrastructure provided by Stripe and Netlify, and password-protected access on our local computer. Card details never reach our infrastructure.
How long we keep it
- Order records (name, email, phone, address, items, totals) — at least seven years from the order date, to comply with ATO and consumer-law obligations.
- Reference photos and free-text fields (gift messages, custom palette descriptions, foil topper requests) — deleted within 30 days of delivery unless you ask us to keep them on file (e.g., for a repeat order).
- Email correspondence — retained for the period our email provider's standard retention applies, typically until manually deleted.
- Server logs and aggregate analytics — retained for the period defined by our hosting and analytics providers (Netlify ~30 days; Google Analytics 14 months by default).
- Cookies on your device — see the Cookies section for per-cookie expiry.
Cookies and tracking
Our website uses cookies to make the site work and to help us understand how it's used. The full list:
- Essential / functional cookies — needed for the site to function (your session during checkout, draft-order persistence in your browser's local storage so you don't lose work if you refresh). These cannot be disabled.
- Google Analytics 4 — anonymous usage measurement (which pages visitors view, how long they stay, what device they use). IP addresses are anonymised. Cookies prefixed with
_gaand_gid, expiry up to 2 years. You can opt out by installing Google's GA Opt-out Browser Add-on. - Meta Pixel (Facebook + Instagram) — measures the effectiveness of any ads we run on Meta platforms. Cookies prefixed with
_fbp, expiry 90 days. You can manage Meta's tracking through your Facebook Ad Preferences. - Stripe cookies — when you reach Stripe's payment page, Stripe sets cookies for fraud prevention, session continuity, and 3DS authentication. Set per Stripe's own privacy policy.
If your browser sends a "Do Not Track" header or similar privacy signal, we honour it: analytics + Pixel scripts will not load. You can also clear cookies in your browser settings at any time without affecting your ability to use the site.
Security
We take reasonable steps to protect your personal information:
- The website uses HTTPS encryption end-to-end.
- Card details are processed entirely by Stripe (PCI-DSS Level 1 compliant). We never see, store, or transmit raw card numbers.
- Form submissions are encrypted in transit to Netlify and stored on their secure infrastructure.
- Our local inventory database is on a password-protected computer; access is restricted to our team.
- Reference photos are stored only as long as needed and then deleted.
- Email correspondence sits behind Google Workspace's enterprise mailbox infrastructure with two-factor authentication on the account.
No system is perfectly secure. If we ever have reason to believe your personal information has been compromised, we will follow the next section.
Notifiable data breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If a data breach occurs that is likely to result in serious harm to affected individuals, we will:
- Notify the affected individuals as soon as practicable.
- Notify the Office of the Australian Information Commissioner (OAIC).
- Take steps to contain the breach and prevent recurrence.
Marketing communications
We send transactional communications (order confirmations, delivery notifications, refund confirmations, replies to enquiries) without needing your separate consent — these are necessary to fulfil your order and aren't classed as marketing under the Spam Act.
We do not send marketing emails or SMS without your express prior consent. If we ever introduce a newsletter or promotional list, joining will be opt-in only, every email will contain an unsubscribe link, and your contact details will not be shared with third-party marketers.
Children's privacy
The Sweet Creative is not intended for use by children under 16. We don't knowingly collect personal information from children. If you believe a child has submitted personal information through our site, please contact us and we'll delete it.
Your rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Correct any information that's inaccurate, out of date, or incomplete.
- Request deletion of information we no longer need (subject to our legal record-keeping obligations — e.g., we must keep order records for seven years for tax purposes).
- Withdraw consent for any optional processing (e.g., to opt out of any marketing list you've joined).
- Lodge a complaint about how we've handled your information.
- Be anonymous or pseudonymous in dealings with us where it's lawful and practicable (e.g., a general enquiry by phone). For orders, we need real identity + contact info to fulfil the order.
To exercise any of these rights, email Jade@thesweetcreative.com.au with your request. We'll verify your identity (typically by reference to a previous order) and respond within 30 days.
Complaints
If you have a complaint about how we've handled your personal information, please email Jade@thesweetcreative.com.au first so we can try to resolve it directly. We'll acknowledge your complaint within 5 business days and provide a substantive response within 30 days.
If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner: www.oaic.gov.au, GPO Box 5288 Sydney NSW 2001, or 1300 363 992.
Changes to this policy
We may update this Privacy Policy from time to time as our services evolve or to reflect changes in legislation. The "Last updated" date at the top of the page tells you when we last made changes. Material changes (anything that meaningfully expands what we collect or how we use it) will be highlighted on the home page for at least 30 days, and existing customers may be notified by email.
Contact
Questions about this policy or how we handle your data, or to exercise any of the rights listed above:
The Sweet Creative
Bathurst, NSW Australia
Email: Jade@thesweetcreative.com.au
Phone: 0478 754 480