Privacy policy, Wattle and Fern Nursery, effective 1 March 2027

Privacy policy template written to the Australian Privacy Principles

A privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.

Create a document with OneCraft5 A4 pages, editable, then download as a PDF

The document, page by page

Every page as it renders and as it prints, with nothing summarised. Read the wording before you reuse it.

Wattle and Fern Nursery
Privacy policy, effective 1 March 2027
Wattle and Fern Nursery
Wattle and Fern Nursery
Wattle and Fern Nursery
Wattle and Fern Nursery
Wattle and Fern Nursery privacy policy, effective 1 March 2027Page 1 of 5
Wattle and Fern Nursery privacy policy, effective 1 March 2027Page 2 of 5
Wattle and Fern Nursery privacy policy, effective 1 March 2027Page 3 of 5
Wattle and Fern Nursery privacy policy, effective 1 March 2027Page 4 of 5
Wattle and Fern Nursery privacy policy, effective 1 March 2027Page 5 of 5
1. About this policy

Wattle and Fern Nursery Pty Ltd, ABN 61 402 887 315, of 12 Banksia Lane, Thornbury VIC 3071, is bound by the Privacy Act and the thirteen Australian Privacy Principles. This policy says what personal information we collect, why, who receives it and where it is held, and how you can access it, correct it or complain.

In plain words
We sell plants online. This policy covers our website, our Thornbury store and our email, and it describes what we actually do, not what a template says.

In this policy, personal information means information about an identifiable person: your name, contact details, order history, payment records and the browsing data our site collects. It does not include the anonymous plant care questions we publish, which never carry a name.

2. What we collect
Information
When
Why
Name and address
When you order
To deliver your plants
Email and phone
When you order or subscribe
To confirm orders, and to send news if you opted in
Payment details
At checkout
Handled by the payment provider; we never store them
Browsing data
When you visit the site
To run and improve the site
Photos you send
When you ask for plant advice
To answer your question

We do not collect sensitive information such as health, racial or political information, and we ask you not to include it in messages to us.

3. How we collect it

Directly from you, when you order, subscribe or write to us, and from our website through cookies as described in section 7. We never buy personal information from third parties, and we never collect it from social media profiles or data brokers. If someone else gives us your details, for example a gift delivery, we use them only for that delivery.

4. Why we use it
4.1
Fulfilling orders
Taking payment, packing plants, delivering them, and telling you where your order is. This is the use every other purpose hangs off, and it matches the first three rows of the collection table.
4.2
Customer service
Answering questions, handling returns and replacements, and keeping a record of what we agreed so a replacement promised in March is honoured in May.
4.3
Marketing, only with consent
Sending plant care tips and offers to people who opted in. Every email carries an unsubscribe link, and unsubscribing takes effect straight away.
4.4
Improving the site
Understanding which pages are used and where the checkout loses people, using aggregated browsing data. We look at patterns, not at what one named person did.
4.5
Complying with the law
Keeping the transaction records tax law requires, and responding to lawful requests from authorities.
4.6
Preventing fraud
Checking orders that look wrong before we ship, such as a mismatched delivery suburb on a large order, to protect customers and the business.
5. Who we share it with
Who
What
Where held
Why
The payment provider
Payment details
Australia and the United States
To take payment
The courier
Name, address and phone
Australia
To deliver
The email platform
Email and order history
United States
To send news you opted in to
The analytics service
Browsing data
United States
To measure the site
The accountant
Transaction records
Australia
To keep the books

No one else receives your information, and we never sell it.

6. Overseas disclosure

Three of the services in the table hold data in the United States. Before using each one we took reasonable steps to check how it protects personal information, and we rely on its contractual commitments to handle your data to the standard this policy describes.

What that means for you
Australian privacy law makes us responsible for what happens to your information when we send it overseas. If one of those services mishandles it, that is our problem to fix, not yours to chase.
7. Cookies and analytics

A cookie is a small file our site stores in your browser so it can remember your cart and recognise a return visit. Without the cart cookie the shop does not work; everything else is optional.

We use one analytics service to count visits and see which pages are read. You can opt out with the service’s browser add on, or by blocking third party cookies in your browser, and the shop keeps working either way. We use no advertising cookies and no social media tracking pixels.

8. Security

Customer records live in our store platform and are encrypted in transit and at rest. Only the two owners and the store manager can access them, each with their own login and two factor authentication, and access ends the day a role does.

If something goes wrong, we assess the breach quickly, contain it, and fix the cause. Where a breach is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and tell you what happened, what we did and what you can do.

9. How long we keep it
Order records
7 years, because tax law requires it
Marketing list
Until you unsubscribe
Plant advice photos
12 months, then deleted
10. Access, correction and deletion

Email us to see the information we hold about you, correct it, or ask us to delete what we are not required to keep. We respond within 30 days, and we may ask you to confirm your identity first, usually by replying from the email on the order, so we never hand your information to someone else. Access is free; we only pass on a cost if you ask for something unusual, and we tell you the cost before doing anything.

11. Complaints

If you think we have mishandled your information, email the owner at privacy@wattleandfern.example. We will respond within 30 days. If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

12. Changes

When this policy changes, the new version is posted on our website with a new effective date. Significant changes are also noted in our email news.

Contact
Email
privacy@wattleandfern.example
Post
12 Banksia Lane, Thornbury VIC 3071
Phone
03 9484 2210
Version history
Version
Effective
Change
1.0
1 August 2025
First policy published
2.0
1 March 2027
Added the sharing table with locations and the retention periods

Section by section

What each section is for, so you can keep the ones you need and drop the rest.

About this policy
The business, the ABN, the Privacy Act, and the plain words callout.
What we collect
Five rows of information, when it is collected and why; nothing sensitive.
How we collect it
Directly from you and through cookies; never bought from third parties.
Why we use it
Purposes 4.1 to 4.6, with marketing only by consent.
Who we share it with
Five services with what they get, where it is held and why; never sold.
Overseas disclosure
The United States services, the reasonable steps, and the accountability callout.
Cookies and analytics
What a cookie is, the one analytics service, and how to opt out.
Security
Encryption, three named people with access, and the data breach steps.
How long we keep it
7 years for orders, until unsubscribe for marketing, 12 months for photos.
Access, correction and complaints
30 day responses, identity checks, and the OAIC as the final stop.
Contact and version history
Email, post and phone, then two dated versions.

Clauses in this document

Who needs a privacy policy in Australia

The Privacy Act draws its line at $3 million of annual turnover: most businesses under it are exempt, every business over it is covered. The exceptions are what catch small operators: a business of any size is covered if it provides a health service, trades in personal information, or opts in, and a clinic or an app can cross those lines without noticing. The practical answer for an online store is to write the policy as if covered: the platforms it sells through demand one, customers read it before typing an address, and the discipline of the sharing table, knowing where every byte goes, is worth having at any turnover.

How to adapt this document

A clinic collects health information, which is sensitive information under the Act, so add a consent step at collection, name your state's health records rules, and expect to be covered regardless of turnover. An app replaces the collection rows with device data, identifiers and push tokens, and adds a section on permissions. A business with employees should keep this policy customer facing, because the Act treats employee records differently; staff privacy belongs in the handbook. In every version, rebuild the sharing table from your real supplier list before publishing; it is the one section that cannot be adapted, only rewritten.

What makes this document work

The sharing table names five services and where they hold data

Section 5 lists the payment provider, the courier, the email platform, the analytics service and the accountant, with what each receives and whether it is held in Australia or the United States. That one table answers the overseas disclosure principle honestly, where most policies write "trusted partners" and hope.

Every purpose is numbered and traceable to a collection row

The six purposes in section 4 are numbered 4.1 to 4.6, and each points back to the collection table: orders to the first three rows, site improvement to browsing data, marketing only to people who opted in. When collection and use reconcile line by line, the policy reads as a record rather than a promise.

Retention has three periods, each with a reason

Section 9 keeps order records for 7 years because tax law requires it, the marketing list until you unsubscribe, and advice photos for 12 months. Most businesses cannot explain why they keep anything; three numbers with three reasons is what the retention principle actually asks for.

Questions people ask

Does a small business need a privacy policy in Australia?

Businesses with annual turnover of $3 million or less are mostly outside the Privacy Act, but the exceptions catch many: health service providers, businesses that trade in personal information, and any business that opts in are covered regardless of turnover. Even exempt stores publish one, because customers, payment platforms and marketplaces expect it.

What must an Australian privacy policy include?

APP 1 requires a clearly expressed, up to date policy covering what is collected, how, why, who it is disclosed to, whether it goes overseas, and how to access, correct and complain. This document gives each requirement its own numbered section, so the thirteen principles map onto the twelve headings.

Can I use a US privacy policy template?

The vocabulary and the rights are different, so four things go wrong: it cites laws that do not apply, it omits the overseas disclosure statement the APPs require, it promises American style rights, and it names no path to the OAIC. A policy that misdescribes what you do is worse than none.

Do I need to mention cookies?

Yes, if you use analytics, because browsing data collected through cookies is collection like any other. Section 7 does it in plain words: what a cookie is in one sentence, which service is used, how to opt out, and the statement that there are no advertising cookies, which is only written because it is true.

What about the Notifiable Data Breaches scheme?

Entities covered by the Privacy Act must notify affected people and the OAIC when a breach is likely to cause serious harm. Section 8 says what would happen: assess, contain, fix, then notify with what happened and what you can do. Writing the steps down before a breach is what makes them happen during one.

Where should the privacy policy live?

Linked from the site footer and the checkout, where the collection happens, and available on request in store. This one has no cover page for that reason; it is a public web document with a running header carrying the business name and effective date, so a reader always knows which version they have.

Build your own in about a minute

The button below opens the generator with this use case already described. Change the wording to match your own, generate, then edit anything you like.

Make my privacy policy template written to the australian privacy principles

Other document examples

Want the steps in the builder? Read Create a document with AI, then Document builder components. For everything this generator can do, see the document maker.

Sources

Written and checked by the OneCraft team. Last checked .