Contents
- Who we are and scope
- Australian privacy law
- Information we collect
- How we collect information
- How we use information
- Stripe checkout and payments
- Website and technical data
- Cookies and analytics
- Email and marketing
- Client websites and account access
- Disclosure and service providers
- Overseas processing
- Security and data breaches
- Data retention
- Access, correction and deletion
- Anonymity and pseudonyms
- Children's privacy
- Third-party links
- Changes to this policy
- Contact and complaints
01 Who we are and scope
Superior Sites (ABN 23 134 170 710) is a sole trader operating in Melbourne, Victoria, Australia ("Superior Sites", "we", "us", "our"). We provide website design, hosting, maintenance, and related digital services for local businesses.
This Privacy Policy explains how we collect, hold, use, disclose, and protect personal information in connection with superiorsites.com.au, checkout.superiorsites.com.au, our communications, and our website design, hosting, maintenance, domain, email, and related services.
It applies to visitors, prospective clients, clients, authorised client representatives, and people who communicate or transact with us. It does not govern a client's own handling of personal information through a website we build or host for that client; the client remains responsible for its own privacy obligations and notices.
02 Australian privacy law
The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to many Australian organisations. Some small businesses with annual turnover of $3 million or less are exempt unless an exception applies or they opt in.
Whether or not Superior Sites is legally required to comply with every APP at a particular time, we aim to handle personal information consistently with the APPs and this policy. Nothing in this policy limits any privacy right or remedy that cannot lawfully be limited.
03 Information we collect
We collect information that is reasonably necessary to operate our business, respond to enquiries, process transactions, and provide services. Depending on your dealings with us, this may include:
- Identity and contact information: your name, email address, phone number, business name, role, and business address;
- Project information: your brief, content, images, branding, feedback, approvals, domain details, service preferences, and other material supplied for a project;
- Account and access information: usernames, invitations, access tokens, or temporary credentials you provide so we can perform authorised work;
- Transaction information: selected products or services, amounts, currency, billing details, payment status, Stripe customer or transaction identifiers, subscription status, refunds, disputes, and fraud-check results;
- Communications: enquiries, emails, support requests, messages, call notes, agreements, quotes, and project records;
- Technical and usage information: IP address, approximate location derived from IP, device and browser information, timestamps, requested pages, referral information, security events, and cookie or similar identifiers;
- Records required by law: invoicing, tax, accounting, complaint, and dispute records.
We do not intentionally request sensitive information, government identifiers, or full payment-card details. Please do not send these unless we specifically request them for a lawful and necessary purpose.
04 How we collect information
We generally collect information directly from you, including when you:
- submit an enquiry, request a quote, or contact us;
- purchase a service or manage a subscription through Stripe Checkout;
- engage us and supply project materials or account access;
- request support, revisions, hosting, maintenance, or a transfer; or
- visit our websites, where technical information may be collected automatically.
We may also receive relevant information from Stripe, Cloudflare, Google, GitHub, domain registrars, hosting providers, a person authorised to act for you, publicly available business sources, or other providers involved in delivering your requested service. We do not purchase personal information from data brokers.
05 How we use information
We may use personal information to:
- respond to enquiries and prepare quotes or proposals;
- create and manage client and Stripe customer records;
- process purchases, recurring subscriptions, refunds, cancellations, and payment failures;
- verify transactions and prevent fraud, abuse, unauthorised payments, and chargebacks;
- design, develop, host, maintain, support, secure, or transfer websites and related services;
- communicate about projects, accounts, service changes, renewals, invoices, and support;
- administer our websites and improve their performance and security;
- keep business, tax, accounting, and contractual records;
- establish, exercise, or defend legal claims and resolve complaints or disputes; and
- comply with applicable law and lawful requests.
We will not use or disclose information for a materially unrelated purpose unless you consent or the use or disclosure is otherwise permitted or required by law.
06 Stripe checkout and payments
Our checkout uses Stripe. When you begin or complete a payment, Stripe may collect information including your name, email, billing address, payment-method details, IP address, device information, and information used for authentication, compliance, and fraud prevention. Stripe handles full card details; Superior Sites does not receive or store your complete card number or card security code.
We receive limited transaction information needed to confirm and administer your purchase, such as your contact details, items purchased, amount, payment status, transaction identifiers, subscription status, refunds, and disputes. Stripe may process information in accordance with its own Privacy Policy.
If you choose a recurring service, Stripe stores the payment method for future charges and manages subscription billing. You can cancel through an available Stripe customer portal or by contacting us. Payment and transaction records may still be retained where required for accounting, fraud prevention, dispute handling, or legal obligations.
07 Website and technical data
Our websites and checkout are delivered using Cloudflare services. Cloudflare may process network and technical data such as IP addresses, request headers, URLs, timestamps, device information, and security signals to deliver content, maintain availability, detect malicious traffic, and protect the service. Cloudflare's handling of information is described in its Privacy Policy.
Our source code and deployment workflow may use GitHub. Information intentionally submitted to a public website is not ordinarily stored in the public source-code repository, but GitHub may process account or technical information where its services are used.
08 Cookies and analytics
Our websites, Cloudflare, and Stripe may use cookies, local storage, or similar technologies that are necessary for security, checkout functionality, session continuity, fraud prevention, and service delivery. Stripe may set its own cookies when its embedded checkout loads.
If we use optional analytics or advertising technologies, we will update this policy and provide any consent controls required by applicable law. You can restrict cookies through your browser, but blocking necessary cookies may prevent checkout or other features from working correctly.
09 Email and marketing
We use email accounts associated with superiorsites.com.au, with email routing and storage provided through services such as Cloudflare and Google. Messages may therefore be processed by those providers.
We may send communications necessary to provide a quote, complete a project, administer a payment or subscription, maintain a service, provide support, or meet legal obligations. These service messages are not marketing and may continue while you have an active service.
We will only send direct marketing where permitted by law. Marketing emails will identify Superior Sites and include a functional way to unsubscribe. You can opt out at any time, although we may still send necessary transactional or service communications.
10 Client websites and account access
To perform authorised work, you may give us access to a domain registrar, hosting platform, content management system, email account, Google Business Profile, social platform, or another business system. We use that access only to perform the agreed services, provide support, protect the account, or comply with your lawful instructions.
You should use invitations, delegated access, or temporary credentials where available and avoid sending passwords by ordinary email. You remain responsible for ensuring you are authorised to provide any personal information, content, or account access supplied to us.
Where we process personal information on a client's behalf through a client website, the client generally determines why that information is collected and remains responsible for its privacy notice, consent settings, lawful use, and instructions to us.
12 Overseas processing
Some providers we use operate global infrastructure or store and process information outside Australia. Countries may include the United States and other locations in which Stripe, Cloudflare, Google, GitHub, or a project-specific provider operates.
Privacy protections in another country may differ from Australian law. Where required, we take reasonable steps in relation to overseas disclosures, but some providers may process information under their own terms as independently responsible organisations. Contact us if you would like information about providers relevant to your dealings with us.
13 Security and data breaches
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Measures may include access controls, strong passwords, multi-factor authentication, encrypted connections, software updates, secure provider settings, backups, and limiting access to what is necessary.
No internet transmission or storage system is completely secure. If we become aware of a suspected breach, we will assess and respond to it. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required.
If you believe information or an account connected with Superior Sites has been compromised, contact us promptly at support@superiorsites.com.au.
14 Data retention
We keep personal information only for as long as reasonably needed for the purposes described in this policy, active services, dispute and fraud prevention, backup cycles, or legal requirements. Generally:
- unsuccessful enquiry records are reviewed for deletion or de-identification after approximately 12 months;
- project and support records may be kept for the service period and a reasonable period afterwards for continuity, warranty, dispute, and record-keeping purposes;
- account credentials should be removed or access revoked when no longer required, subject to backups and active-service needs; and
- financial and transaction records are generally kept for at least five years, or longer where law or a dispute requires it.
When information is no longer required, we take reasonable steps to delete or de-identify it. Copies may remain temporarily in secure backups until overwritten in the ordinary backup cycle.
15 Access, correction and deletion
You may ask us to:
- confirm whether we hold personal information about you;
- provide access to personal information we hold about you;
- correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading;
- delete or de-identify information where it is no longer needed; or
- withdraw consent where our handling relies on your consent.
We may need to verify your identity and authority before acting. Access or deletion may be limited where another person's privacy, security, fraud prevention, legal privilege, record-keeping duties, an active dispute, or another legal exception applies. We aim to respond within 30 days and will explain any refusal where appropriate.
16 Anonymity and pseudonyms
You may browse our public website without identifying yourself. You may make a general enquiry using a pseudonym where practicable. We will need accurate identifying and contact information where it is necessary to prepare a binding agreement, process payment, prevent fraud, comply with law, or provide an account-based or ongoing service.
17 Children's privacy
Our website and services are directed to businesses and people authorised to purchase business services. They are not designed to collect personal information from children. If you are under 18, a parent, guardian, or authorised adult should enter into any paid service on your behalf where required by law.
If you believe a child has submitted personal information without appropriate authority, contact us so we can assess and take appropriate action.
18 Third-party links
Our websites may link to external websites or services. Their privacy practices are controlled by their operators, not Superior Sites. You should review their privacy information before providing personal information.
19 Changes to this policy
We may update this policy when our services, providers, practices, or legal obligations change. The fixed date and version at the top show when it was last revised. If a change materially affects how we handle information already collected, we will take reasonable steps to notify affected clients or obtain consent where required.
20 Contact and complaints
For a privacy question, request, or complaint, contact:
- Business: Superior Sites, Privacy Contact
- Email: info@superiorsites.com.au
- Phone: 0432 923 429
- Location: Melbourne, VIC, Australia
Please explain your concern and provide enough information for us to investigate. We aim to acknowledge complaints within five business days and respond within 30 days. More complex matters may take longer, in which case we will provide an update.
If the Privacy Act applies to the matter and you are dissatisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner. Visit oaic.gov.au/privacy/privacy-complaints or call 1300 363 992.