Privacy Policy

Effective date: 02/10/2026
Last updated: 02/10/2026

1. About this policy

At Honey Bunny Wardrobe, we respect your privacy.

This Privacy Policy explains how we collect, hold, use and disclose personal information when you:

  • visit honeybunnywardrobe.com;

  • purchase or return a product;

  • create an account;

  • contact us or subscribe to marketing;

  • interact with our social-media accounts;

  • visit our store or pop-up location; or

  • supply products to us for purchase or consignment.

Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to us, we handle personal information in accordance with those requirements. Where they do not apply, we intend to follow the practices described in this policy.

2. Personal information we collect

The personal information we collect depends on how you interact with us. It may include:

  • your name, username and contact details;

  • billing, delivery and return addresses;

  • account login and preference information;

  • products purchased, viewed, saved or returned;

  • order, payment and transaction information;

  • correspondence, complaints and customer-service records;

  • marketing preferences and competition entries;

  • reviews, photographs or other content you submit;

  • IP address, browser type, device identifiers and website activity;

  • approximate location information derived from your IP address;

  • fraud-prevention and transaction-risk information; and

  • any other information you voluntarily provide.

We generally do not receive or store complete payment-card details. Payments are processed by [payment processors, such as Shopify Payments, Stripe, PayPal or Afterpay], subject to their own privacy policies.

Sellers and consignors

If you sell or consign products to us, we may also collect:

  • bank-account or payment details;

  • identification information;

  • proof of address;

  • signatures;

  • information concerning ownership, provenance and authenticity;

  • photographs and descriptions of products;

  • transaction and payout records; and

  • tax or compliance information where required by law.

We may ask to sight or record identification where reasonably necessary to verify identity, ownership, prevent fraud or meet legal obligations.

3. Sensitive information

We do not ordinarily need sensitive information, such as health information, biometric information, political opinions or racial or ethnic origin.

Please do not provide sensitive information unless it is reasonably necessary. Where the Privacy Act requires consent to collect sensitive information, we will seek that consent unless another legal exception applies.

4. How we collect information

We may collect personal information:

  • directly from you when you order, register, contact us or visit our store;

  • through our website, cookies and similar technologies;

  • from payment, e-commerce, delivery and fraud-prevention providers;

  • from social-media platforms when you communicate with us through them;

  • from a person purchasing or arranging delivery for you;

  • from authentication providers where a product is assessed;

  • from publicly available sources; and

  • from third parties where you have authorised disclosure or where collection is otherwise permitted by law.

If you provide personal information about another person, you should have their permission and inform them about this policy.

You may interact with us anonymously or using a pseudonym where practical and lawful. However, we need certain identifying information to process orders, arrange delivery, issue payments, prevent fraud and provide remedies.

5. Why we use personal information

We may collect, hold, use and disclose personal information to:

  • process payments, orders, deliveries, returns and refunds;

  • create and administer customer accounts;

  • assess, purchase, authenticate or sell consigned products;

  • communicate with customers, sellers and consignors;

  • provide customer service and resolve complaints;

  • detect and prevent fraud, theft, counterfeit goods and misuse;

  • verify identity or ownership where reasonably necessary;

  • administer promotions, loyalty programs and gift cards;

  • improve our products, website, services and customer experience;

  • analyse website performance and customer preferences;

  • send marketing where consent or another lawful basis exists;

  • maintain business, accounting and taxation records;

  • enforce our Terms and Conditions;

  • comply with legal obligations and respond to lawful requests; and

  • protect our customers, business, staff and legal rights.

We will not use personal information for an unrelated purpose unless permitted by law or we obtain any required consent.

6. Cookies and analytics

Our website may use cookies, pixels, local storage and similar technologies to:

  • keep the website functioning;

  • remember cart contents and preferences;

  • maintain account sessions;

  • measure traffic and performance;

  • understand how visitors use the website;

  • personalise content or advertising; and

  • detect fraud or security incidents.

We may use services such as [Google Analytics, Meta Pixel, Shopify Analytics or other services actually used]. These providers may collect device, browsing and interaction information under their own privacy policies.

You can manage cookies through your browser or our cookie-preference tool, where available. Blocking necessary cookies may prevent parts of the website from functioning correctly.

Do not state that customers can reject all non-essential cookies unless your website genuinely provides that functionality.

7. Marketing communications

With your consent, or where otherwise permitted by law, we may send offers, product updates and other marketing by email, SMS or similar channels.

You can unsubscribe at any time by:

We will process unsubscribe requests within the period required by law. Transactional messages relating to orders, deliveries, account security or customer service may continue after you unsubscribe from marketing.

Australian commercial electronic messages are subject to consent, sender-identification and functional-unsubscribe requirements. ACMA unsubscribe guidance.

8. Who receives personal information

We may disclose personal information to:

  • payment processors and financial institutions;

  • e-commerce and website-hosting providers;

  • delivery, courier and fulfilment providers;

  • authentication, valuation, cleaning or repair providers;

  • customer-support and communications platforms;

  • analytics, advertising and marketing providers;

  • fraud-prevention, identity-verification and cybersecurity providers;

  • accountants, insurers, auditors, lawyers and other advisers;

  • government agencies, courts or regulators where required or authorised;

  • a purchaser or adviser involved in a proposed sale or restructuring of our business, subject to appropriate safeguards; and

  • other parties you authorise us to deal with.

We do not sell or trade personal information as a business activity.

Service providers are permitted to access personal information only as reasonably necessary to perform their services, subject to their contracts and applicable law.

9. Overseas disclosure

Some service providers may store or process personal information outside Australia.

The countries in which recipients are likely to be located include [list countries—for example, the United States, New Zealand, Singapore, Ireland and Canada].

The locations used by cloud and technology providers may change. Where required by the Privacy Act, we will take reasonable steps to ensure an overseas recipient handles personal information consistently with the Australian Privacy Principles, unless an exception applies.

If you do not disclose personal information overseas, replace this section with a statement accurately reflecting that practice.

10. Automated processing and fraud screening

We or our service providers may use automated tools to assess transactions for fraud, payment risk, account misuse or security threats. These tools may use information such as transaction history, device information, IP address, delivery details and payment-risk indicators.

An order may be flagged, delayed or declined based on this assessment. Where appropriate, you may contact us at [email] to request further information or human review.

From 10 December 2026, additional Australian transparency requirements apply where computer programs use personal information to make decisions that could reasonably be expected to significantly affect an individual’s rights or interests. This section should be reviewed if your business uses automated eligibility, account, pricing or fraud decisions of that kind. OAIC APP 1 guidance.

11. Security

We take reasonable technical and organisational steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.

Depending on our systems, these measures may include:

  • access controls and staff permissions;

  • secure payment providers;

  • multi-factor authentication;

  • encryption where appropriate;

  • software updates and security monitoring;

  • staff privacy and security procedures; and

  • secure document disposal.

No internet transmission or storage system is completely secure, and we cannot guarantee absolute security.

Customers are responsible for maintaining the confidentiality of their account credentials and should contact us promptly if they suspect unauthorised account activity.

12. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this policy or to meet legal, accounting, taxation, fraud-prevention and dispute-resolution requirements.

When personal information is no longer required, we take reasonable steps to delete it or permanently de-identify it, unless retaining it is required or authorised by law.

Transaction records may need to be retained for several years. Backup copies may remain temporarily until they are securely overwritten under our normal backup cycle.

13. Accessing and correcting your information

You may ask to access personal information we hold about you or request that inaccurate, incomplete or outdated information be corrected.

Send requests to [privacy email]. We may need to verify your identity before responding.

We will respond within a reasonable period. If we refuse access or correction where the Privacy Act applies, we will generally provide written reasons and explain available complaint options, unless the law permits otherwise.

We will not charge for making a request. We may charge reasonable costs for providing access where permitted by law, but we will tell you about any proposed charge beforehand.

14. Privacy complaints

If you believe we have mishandled your personal information, contact:

Privacy Officer
Honey Bunny Wardrobe
Melbourne, Australia
honeybunnywardorbe2026@gmail.com

Please describe your concern and include relevant details. We will acknowledge the complaint within 3 business days and aim to provide a response within 5 days.

If you are dissatisfied with our response and the Privacy Act applies, you may complain to the Office of the Australian Information Commissioner.

15. Data breaches

If we become aware of a suspected data breach, we will investigate and take reasonable steps to contain and remediate it.

Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.

16. Children’s information

Our products and website are intended for a general audience and are not directed specifically at children under [16/18].

A child should use the website and make purchases only with the involvement of a parent or guardian. If we learn that personal information has been collected from a child inappropriately, we will take reasonable steps to delete it.

17. Third-party websites

Our website may link to third-party websites, payment services and social-media platforms. Those services operate under their own privacy policies, and we are not responsible for their privacy practices.

18. Changes to this policy

We may update this policy when our practices, service providers or legal obligations change. The current version will be published on our website with its effective date.

Material changes may also be communicated by email, website notice or another appropriate method.

19. Contact us

Questions, requests and complaints can be directed to:

Privacy Officer
Honey Bunny Wardrobe
Melbourne, Australia
honeybunnywardorbe2026@gmail.com