Privacy policy, Wattle and Fern Nursery, effective 1 March 2027
Privacy policy template written to the Australian Privacy Principles
A privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.
The document, page by page
Every page as it renders and as it prints, with nothing summarised. Read the wording before you reuse it.
Section by section
What each section is for, so you can keep the ones you need and drop the rest.
- About this policy
- The business, the ABN, the Privacy Act, and the plain words callout.
- What we collect
- Five rows of information, when it is collected and why; nothing sensitive.
- How we collect it
- Directly from you and through cookies; never bought from third parties.
- Why we use it
- Purposes 4.1 to 4.6, with marketing only by consent.
- Who we share it with
- Five services with what they get, where it is held and why; never sold.
- Overseas disclosure
- The United States services, the reasonable steps, and the accountability callout.
- Cookies and analytics
- What a cookie is, the one analytics service, and how to opt out.
- Security
- Encryption, three named people with access, and the data breach steps.
- How long we keep it
- 7 years for orders, until unsubscribe for marketing, 12 months for photos.
- Access, correction and complaints
- 30 day responses, identity checks, and the OAIC as the final stop.
- Contact and version history
- Email, post and phone, then two dated versions.
Clauses in this document
Who needs a privacy policy in Australia
The Privacy Act draws its line at $3 million of annual turnover: most businesses under it are exempt, every business over it is covered. The exceptions are what catch small operators: a business of any size is covered if it provides a health service, trades in personal information, or opts in, and a clinic or an app can cross those lines without noticing. The practical answer for an online store is to write the policy as if covered: the platforms it sells through demand one, customers read it before typing an address, and the discipline of the sharing table, knowing where every byte goes, is worth having at any turnover.
How to adapt this document
A clinic collects health information, which is sensitive information under the Act, so add a consent step at collection, name your state's health records rules, and expect to be covered regardless of turnover. An app replaces the collection rows with device data, identifiers and push tokens, and adds a section on permissions. A business with employees should keep this policy customer facing, because the Act treats employee records differently; staff privacy belongs in the handbook. In every version, rebuild the sharing table from your real supplier list before publishing; it is the one section that cannot be adapted, only rewritten.
What makes this document work
The sharing table names five services and where they hold data
Section 5 lists the payment provider, the courier, the email platform, the analytics service and the accountant, with what each receives and whether it is held in Australia or the United States. That one table answers the overseas disclosure principle honestly, where most policies write "trusted partners" and hope.
Every purpose is numbered and traceable to a collection row
The six purposes in section 4 are numbered 4.1 to 4.6, and each points back to the collection table: orders to the first three rows, site improvement to browsing data, marketing only to people who opted in. When collection and use reconcile line by line, the policy reads as a record rather than a promise.
Retention has three periods, each with a reason
Section 9 keeps order records for 7 years because tax law requires it, the marketing list until you unsubscribe, and advice photos for 12 months. Most businesses cannot explain why they keep anything; three numbers with three reasons is what the retention principle actually asks for.
Questions people ask
Does a small business need a privacy policy in Australia?
Businesses with annual turnover of $3 million or less are mostly outside the Privacy Act, but the exceptions catch many: health service providers, businesses that trade in personal information, and any business that opts in are covered regardless of turnover. Even exempt stores publish one, because customers, payment platforms and marketplaces expect it.
What must an Australian privacy policy include?
APP 1 requires a clearly expressed, up to date policy covering what is collected, how, why, who it is disclosed to, whether it goes overseas, and how to access, correct and complain. This document gives each requirement its own numbered section, so the thirteen principles map onto the twelve headings.
Can I use a US privacy policy template?
The vocabulary and the rights are different, so four things go wrong: it cites laws that do not apply, it omits the overseas disclosure statement the APPs require, it promises American style rights, and it names no path to the OAIC. A policy that misdescribes what you do is worse than none.
Do I need to mention cookies?
Yes, if you use analytics, because browsing data collected through cookies is collection like any other. Section 7 does it in plain words: what a cookie is in one sentence, which service is used, how to opt out, and the statement that there are no advertising cookies, which is only written because it is true.
What about the Notifiable Data Breaches scheme?
Entities covered by the Privacy Act must notify affected people and the OAIC when a breach is likely to cause serious harm. Section 8 says what would happen: assess, contain, fix, then notify with what happened and what you can do. Writing the steps down before a breach is what makes them happen during one.
Where should the privacy policy live?
Linked from the site footer and the checkout, where the collection happens, and available on request in store. This one has no cover page for that reason; it is a public web document with a running header carrying the business name and effective date, so a reader always knows which version they have.
Build your own in about a minute
The button below opens the generator with this use case already described. Change the wording to match your own, generate, then edit anything you like.
Make my privacy policy template written to the australian privacy principlesOther document examples
Tutoring agreement template with weekly sessions and progress notes
Parents pay for tutoring and then wait months to find out whether it is working. This agreement puts a written progress note every four weeks, prices the whole school year term by term, and carries the tutor's working with children check number so a parent can verify it in a minute.
Partnership agreement template
Three physiotherapists have run one Newcastle practice together since 2024 without anything in writing. This agreement records what the handshake never covered: uneven capital sitting beside uneven hours, the six decisions no partner can make alone, and what a leaving partner is owed.
Plumbing works contract with a fixture scope table and a compliance certificate
A bathroom job goes over budget in the hour the floor comes up and somebody finds old cast iron drainage. This contract prices every fixture separately, holds a named allowance for what nobody could see, and makes the final payment wait for the compliance certificate.
Want the steps in the builder? Read Create a document with AI, then Document builder components. For everything this generator can do, see the document maker.
Written and checked by the OneCraft team. Last checked .