1.2 SLH agrees to notify you of:
1.2.1 the organisation collecting information from you and with whom the information may be shared;
1.2.2 what information is collected from you and how it is used;
1.2.3 what choices are available to you regarding collection, use and distribution of the information;
1.2.4 the kind of security procedures that are in place to protect the loss, misuse or alteration of information under SLH’s control; and
1.2.5 how you can correct any inaccuracies in the information.
2. The organisation collecting information from you and with whom the information may be shared
2.1 Collection. SLH is the sole entity which holds the information collected from you on the Site. We will not sell, share, or rent this information to others in ways different from what is disclosed in this statement. We may disclose or share your information with third parties in the following circumstances:
2.1.1 Website orders. We may share your information with the relevant retail store selected by you when you purchase goods (excluding gift cards) on the Website.
2.1.2 With your consent. We may share your information with third parties when you have provided your consent or requested us to do so. For example:
(a) if you participate in one of our promotions and agree to have your picture/video taken, we may use it to promote our business together with information about our business by sharing it on our Social Media Pages and Website, and/or we may use it in our marketing materials; and
(b) if you participate in one of our social media activities by providing us with a picture, video and information we may re-share this on our Social Media Pages.
2.1.3 Third party service providers. We may share your information with companies who provide us services (such as information processing and promotion registration) so that we can administer the Site.
2.1.4 Commercial partners. We may disclose your personal details to our commercial partners where you have consented or requested us to do so. For example, when we organise promotions jointly with a partner, where you have entered a competition or requested to receive marketing communications. You will be given clear information in each circumstance.
2.1.5 Legal purposes. Where it is legally required by a third party or law enforcement authority in any jurisdiction (in which case we will generally require a production order or similar court order unless necessary to prevent or lessen a serious threat to public health or public safety or the life or health of you or someone else), and including reporting data breaches to affected individual(s) and the Privacy Commissioner where required by the Act.
2.1.7 To protect the Site. Where it is needed to detect, prevent or address fraud, security or technical issues.
2.1.8 Business sale. In the event we sell our business we may disclose your information to the prospective buyer. If substantially all of our assets are acquired by a third party, your information will be one of the transferred assets.
2.1.9 Aggregated or de-identified information. We may disclose or use aggregated or de-identified information for any purpose. For example, we may share aggregated or de-identified information with business prospects or partners.
3. What information is collected from you and how it is used
3.1 Information. We collect information from our users at several different points on our Site, including information you provide to us on the Site.
3.2 Registration. No registration is required in order to use the Website, however you will be asked to confirm that you are 18 years of age or over before accessing the Website.
3.3 Ordering Gift Cards. If you purchase a gift card through the Website you must provide a valid email address and contact information (like name and delivery address) and financial information (credit or debit card number, expiration date, billing address, and billing phone number). If we have trouble processing an order, this contact information is used to get in touch with you. This information is taken in a secure area, is encrypted for your protection, and is not sold or shared with anyone else under any circumstances.
3.4 Website orders. If you purchase goods from a retail store through the Website you must provide a valid email address, contact information (like name and delivery address) and financial information (credit or debit card number, expiration date, billing address and billing phone number). This information is taken in a secure area, is encrypted for your protection, is not sold but is shared with the relevant retail store selected by you. All purchases made from a retail store are made in accordance with our sale terms, which you can view here [sale terms].
3.5 Cookies. A cookie is a piece of data stored on the end-user's hard drive containing information that relates directly to the end-user's visit to our Website. Any information placed in the cookie is accessible only to SLH, and will not be sold or shared with anyone else under any circumstances. We use a cookie to store a unique session identifier, and this allows us to maintain your shopping cart and state selection from one page request to the next. We are also able to maintain your session information from one visit to the next. By setting a cookie on the Website, the user would not have to log in more than once, thereby saving time while on the Website. If a user rejects the cookie, they may still browse the Website, but the user will be unable to log in or make a purchase. Cookies also enable us to track and target the interests of our users to enhance the experience on the Website and show you the products that your order history indicates you prefer.
3.7 Log Files. We use IP addresses to analyse trends, administer the Website, track user's movement, and gather broad demographic information for aggregate use. IP addresses are not linked to personally identifiable information.
3.8 Promotional emails. If a user wishes to subscribe to our promotional emails, we ask for contact information such as name and email address. Every email that we send provides you with the opportunity to unsubscribe from the promotional emails service.
3.9 Surveys & Competitions. From time-to-time our Site requests information from users via surveys or competitions. Participation in these surveys or competitions is completely voluntary and the user therefore has a choice whether or not to disclose information. Information requested may include contact information (such as name and delivery address), and demographic information (such as geographic region, age level). Contact information will be used to notify the winners and award prizes. SLH may use this information for marketing opportunities if authorised by the registrant, and will also be used for purposes of monitoring or improving the use and satisfaction of the Site.
3.10 Information about minors. Our services do not address, and we do not knowingly collect information from, people under the age of 18.
3.11 Retention. We retain your information for as long as it is needed to be able to provide our services to you.
3.12 Personal information. If you do not wish to provide us with personal information, we will be unable to properly provide our services to you.
4. Security procedures
4.1 Security of data. We have taken and will take steps to ensure personal information we hold about you is protected from risk such as loss, unauthorised access, or use, destruction, modification or disclosure. No data transmission over the internet is totally secure. As a result any personal information you send to us over the Internet (including via email) is sent at your own risk.
4.2 Sensitive information. When our order form asks users to enter sensitive information (such as a credit card number), that information is encrypted and is protected with – Payment Express, security software provided by Windcave. While on a secure page such as our payment page, the lock icon on the bottom of Web browsers such as Chrome, Firefox, Safari and Microsoft Edge becomes locked, as opposed to unlocked, or open, when you are just 'surfing'.
4.3 Access to information. While we use DPI encryption to protect sensitive information online, we also do everything in our power to protect user-information offline. All of our users' information, like the sensitive information mentioned above, is restricted in our offices. Only employees who need the information to perform a specific job (for example, a customer service representative) are granted access to personally identifiable information. If one of these people leaves their workstation, they are required to lock their station until they return. Furthermore, all employees are kept up to date on our security and privacy practices. Finally, the servers that we store personally identifiable information on are kept in a locked and secure environment.
4.4 Questions. If you have any questions about the security at our Website, [click here].
5. Privacy Breaches
5.1 What is a privacy breach? A privacy breach occurs where there is an unauthorised or accidental access to, or disclosure, alteration, loss, or destruction of, personal information held by us or an action that prevents us from accessing personal information on either a temporary or permanent basis.
5.2 Notifiable privacy breach. If we learn of a privacy breach involving personal information we hold, we will assess whether the privacy breach is likely to cause serious harm to an affected individual or individuals. If our assessment finds that the privacy breach has caused serious harm to an affected individual or individuals, or is likely to do so, we will notify the individual or individuals and the Privacy Commissioner within the timeframes prescribed by the Act.
6. How you can correct any inaccuracies in the information
6.1 Correction of information. Subject to certain grounds for refusal set out in the Act, you have the right to request confirmation from us that we hold information about you, and a copy of such information. You are also entitled to request the correction of the information we hold about you.
6.2 Request for correction. If you would like to exercise either of these rights, please contact us at [contact us] on the Website. Your request should provide evidence of who you are and the details of your request (e.g. the information, or the correction, that you are requesting).