Privacy Policy
Effective date: 1ST AUGUST, 2026 | Version: 1
Privacy at a glance: We collect information needed to operate the website, fulfil orders and design projects, manage licences, communicate and keep the business secure. We do not sell customer lists. Individuals can contact us to request access, correction or make a complaint.
1. About us and this Policy
This Privacy Policy explains how QUIVER COLLECTIVE DESIGNS PTY LTD ABN 28 700 230 673 trading as QUIVER COLLECTIVE DESIGNS (we, us or our), manages personal information. It applies to quivercollectivedesigns.com.au, our online store, enquiries, orders, commissioned design projects, design licensing, marketing, events and other dealings with individuals.
Our privacy contact is Rachael Symington / Owner, available at quiverdesigns25@gmail.com, 0404 383 048 and 22 Murray Street, North Ward, Townsville 4810. We will provide this Policy in an appropriate alternative form on reasonable request.
This Policy should be read with any collection notice shown when information is collected. A collection notice provides details specific to that collection and does not replace this Policy.
2. Our Privacy Act status and commitment
We understand that we are currently a small-business operator exempt from the Privacy Act 1988 (Cth). We nevertheless choose to handle personal information as described in this Policy. If our legal status changes, we will update our practices and Policy.
Some privacy, communications, consumer, employment and records laws may apply independently of the Privacy Act. Nothing in this Policy limits a right or obligation that cannot lawfully be limited.
3. Meaning of personal and sensitive information
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true or recorded in material form.
Sensitive information includes information or an opinion about matters such as racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, health information and certain biometric information. We do not intentionally collect sensitive information unless it is reasonably necessary for our functions and we have consent or another lawful basis.
4. Personal information we collect and hold
Depending on how you deal with us, we may collect your name, pronouns, organisation, position, billing and delivery addresses, email address, telephone number and preferred communication method.
We may collect account credentials and settings; enquiry, quote, order, invoice, payment-status, refund and transaction records; delivery information; licence selections; project briefs; approvals; and communications with us.
For commissioned work we may collect contact details of client representatives and manufacturers, supplied artwork, photographs, logos, brand assets, project references, product plans, confidentiality instructions and other materials included in a brief.
We may collect marketing preferences, competition entries, survey responses, event registrations, reviews, testimonials, project photographs and social-media interactions.
When you use our website, we may collect IP address, device and browser information, cookie or advertising identifiers, pages viewed, referring source, approximate location, interactions, error logs and security events. We may also hold supplier, contractor and job-applicant information where relevant.
5. How we collect personal information
We usually collect personal information directly from you when you visit the website, create an account, place an order, request a quote, submit a project brief or file, approve artwork, contact us, subscribe, enter a promotion, provide a review or communicate through email, telephone, social media or another channel.
We may also collect information from an authorised representative, client organisation, referral source, marketplace, payment or delivery provider, manufacturer, publicly available source, analytics or advertising provider, fraud-prevention service, or another person where authorised by you or law.
Where reasonable and practicable, we will collect personal information directly from you and provide an appropriate collection notice at or before collection, or as soon as practicable afterwards.
6. Anonymity and pseudonyms
You may interact with us anonymously or using a pseudonym where lawful and practicable, such as when browsing general website content or making a general enquiry.
We may need your accurate identity and contact details to provide a quote, contract for services, process payment, deliver an order, grant a design licence, verify authority, prevent fraud, respond to an access request or comply with law.
7. Why we collect, hold, use and disclose information
We use personal information to operate the website; respond to enquiries; prepare quotes; establish and administer accounts; accept, produce, deliver and support orders; provide commissioned design services; manage approvals and licences; process payments and refunds; and maintain customer records.
We also use information to provide service messages, manage manufacturers and delivery providers, resolve complaints, prevent fraud and misuse, protect our rights and systems, maintain security, comply with law, keep financial and business records, and obtain professional advice.
With consent or where otherwise permitted, we may use information for newsletters, product launches, events, surveys, promotions, audience measurement, website improvement and relevant advertising. We may use aggregated or de-identified information for analysis and planning where individuals are not reasonably identifiable.
If we wish to use or disclose personal information for a materially different purpose, we will obtain consent or rely on another lawful basis and provide notice where required.
8. Website cookies, analytics and tracking technologies
Our website and authorised providers may use cookies, pixels, tags, software development kits, local storage and similar technologies. These can support essential website functions, security, preferences, checkout, analytics, campaign measurement and advertising.
The technologies and choices actually used are described in https://quivercollectivedesigns.com.au/cookienotice. Where required by applicable law or platform rules, we will request consent before activating non-essential technologies. You may also control cookies through browser or device settings, although blocking essential technologies may affect website functions.
We do not permit tracking technologies merely because a plug-in is available. We assess the information collected, purposes, disclosures, retention, security and available controls before implementation.
9. Payments and financial information
Payments are processed by ETSY if products are purchased via the Etsy website. Payment of services will be processed by direct debit. We receive transaction references, payment status, billing details and limited payment information needed for accounting, refunds, fraud management and support.
We do not receive or store complete payment-card numbers or card security codes. Payment providers handle information under their own privacy policies and security obligations.
10. Customer content and design-project materials
Files, photographs, artwork, logos, product plans, reference images and approvals submitted for a project may contain personal information about you or other people. You should provide only information reasonably required for the project and have authority to provide personal information about another person.
We use project materials to prepare designs, proofs, production files, licences and related services. We do not publish confidential project information, identifiable customer content or pre-launch work except as authorised by the applicable agreement, consent or law.
Project materials may be shared with authorised staff, contractors, printers or manufacturers only to the extent reasonably necessary for the project and subject to appropriate confidentiality and information-handling controls.
11. Direct marketing and promotional communications
We send commercial electronic messages only where we have consent or another lawful basis. Marketing consent is separate from acceptance of website terms and is not required to complete an ordinary purchase unless the communication is necessary for that transaction.
Our marketing messages identify the sender, include current contact details and provide a clear unsubscribe method. We keep reasonable consent records and action electronic-marketing unsubscribe requests within 5 working days.
You may opt out at any time by using the unsubscribe facility or contacting quiverdesigns25@gmail.com. We may still send non-marketing communications reasonably necessary for an order, account, security issue or legal obligation.
12. When we disclose personal information
We may disclose personal information to authorised staff and contractors; website, e-commerce, hosting, cloud, email, CRM and IT providers; payment, accounting and fraud-prevention providers; printers, manufacturers, fulfilment partners and couriers; analytics, advertising and social-media providers; professional advisers; insurers; and government, regulatory, law-enforcement or dispute-resolution bodies where authorised or required.
We disclose only information reasonably required for the purpose and seek appropriate contractual, technical and organisational protections. We do not sell customer lists or personal information.
A business transfer, restructure or due-diligence process may involve controlled disclosure to advisers and a prospective purchaser where lawful, necessary and subject to confidentiality.
13. Overseas recipients
Some providers or recipients may be located outside Australia or may access personal information from overseas. Based on our current provider register, likely countries are UNITED STATES, UNITED KINGDOM, NEW ZEALAND, CANADA, SINGAPORE OR EUROPEAN UNION COUNTRIES.
Before an overseas disclosure, where APP 8 applies, we take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles unless an exception applies. Depending on the arrangement, we may remain accountable for the recipient's handling.
Provider locations and subcontractors can change. We review the register and update this Policy when our likely overseas disclosures materially change.
14. Security
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, multi-factor authentication, encryption in transit where appropriate, software updates, secure backups, staff and contractor controls, vendor review and incident-response procedures.
No online or storage system is completely secure. You should use a strong unique password, keep account credentials confidential and tell us promptly about suspected unauthorised activity.
We do not describe security controls in a way that would undermine them. We review safeguards having regard to the amount, sensitivity and consequences of mishandling the information.
15. Retention, destruction and de-identification
We retain personal information only for as long as reasonably needed for the purposes described in this Policy, including providing services, maintaining licence and approval records, resolving disputes, meeting tax and accounting requirements, enforcing rights and complying with law.
Indicative retention periods are recorded in a business computer protected by antivirus software. Confirmed financial and transaction records may need to be retained for periods required by tax, corporations or other laws. Project files and licence records may be retained for the applicable licence, limitation and archive periods.
When personal information is no longer needed and no law or order requires retention, we take reasonable steps to destroy it or ensure it is de-identified. This includes considering copies held in archives, backups and third-party systems.
16. Data breaches
We maintain a data-breach response process to identify, contain, assess and remediate suspected incidents. If the Notifiable Data Breaches scheme applies and we suspect an eligible data breach, we will take reasonable steps to complete the assessment within 30 calendar days.
Where there are reasonable grounds to believe an eligible data breach has occurred and no exception applies, we will notify the Office of the Australian Information Commissioner and individuals at likely risk of serious harm as soon as practicable, and provide practical response steps.
If you believe personal information connected with us has been compromised, contact quiverdesigns25@gmail.comimmediately.
17. Access to personal information
You may request access to personal information we hold about you by contacting quiverdesigns25@gmail.com, 22 Murray Street, North Ward, Townsville, QLD 4810 / 0404 383 048. You do not have to use a particular form, although enough detail will help us locate the information and verify identity.
Where the Privacy Act applies, we respond within a reasonable period and provide access in the requested manner where reasonable and practicable. We do not charge for making a request and will disclose any permitted access charge before proceeding.
If we refuse access or part of a request, we will provide written reasons and available complaint mechanisms where required, subject to any lawful exception.
18. Correction of personal information
Please contact quiverdesigns25@gmail.com if you believe personal information we hold is inaccurate, out of date, incomplete, irrelevant or misleading. We may ask for information reasonably necessary to verify the requested correction.
Where the Privacy Act applies, we take reasonable steps to correct information and, on request, to notify relevant third parties of the correction where required. If we refuse a correction, we will provide written reasons and available complaint mechanisms where required and may associate a statement with the record.
19. Privacy enquiries and complaints
Send a privacy enquiry or complaint to Rachael Symington / Owner at quiverdesigns25@gmail.com 0404 383 048 or 22 Murray Street, North Ward, Townsville, QLD 4810 Describe the issue, relevant dates and the outcome you seek, and provide supporting information where available.
We will acknowledge a complaint within [5] Business Days, investigate it fairly, keep you informed where appropriate and aim to provide a substantive written response within 30 days. If more time is reasonably needed, we will explain why and provide an updated timeframe.
If the Privacy Act applies and you are not satisfied after giving us a reasonable opportunity to respond, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au. Other complaint bodies or legal rights may also be available.
20. Children and young people
Our website and ordinary design services are not directed primarily to children under 18. A person under 18 should use purchasing or project services only with the involvement of a parent or guardian.
If we knowingly collect personal information from a child or young person, we take age, capacity, transparency and the nature of the information into account and seek parent or guardian involvement where appropriate. Contact us if you believe a child has provided information without appropriate authority.
21. Job applicants, contractors and suppliers
If you apply for work or offer services, we may collect identity and contact details, work history, qualifications, portfolio material, references, right-to-work information, tax or payment details and other information reasonably necessary to assess or administer the relationship.
Employee records directly related to a current or former employment relationship may be treated differently under the Privacy Act. Other laws and contractual confidentiality obligations may still apply.
22. Third-party websites, marketplaces and social media
Third-party websites, marketplaces, payment services and social platforms have their own privacy policies and controls. This Policy applies to our handling of personal information, not the independent practices of another organisation.
Information posted publicly or shared through a social platform may be visible to others. Use privacy settings and avoid publishing information you do not want to be public.
23. Automated decision-making
We do not currently arrange for a computer program to use personal information to make decisions, or do things substantially and directly related to decisions, that could reasonably be expected to significantly affect an individual's rights or interests.
If we introduce such an arrangement, we will assess it before use and update this Policy to describe the kinds of personal information used and the kinds of decisions involved, including the additional APP 1 requirements commencing on 10 December 2026 where applicable.
Routine website functions such as fraud screening, spam filtering, product recommendations or audience selection may involve automated tools. They must be accurately described here if they significantly affect an individual's rights or interests.
24. Changes to this Policy
We may update this Policy when our practices, providers or legal obligations change. The current version and effective date will be published at https://quivercollectivedesigns.com.au/Privacy Policy.
If a change is material, we will take reasonable steps to provide notice appropriate to the circumstances. We review the Policy at least annually and before introducing a material new information-handling practice.
25. Contact us
Privacy contact: Rachael Symington / Owner]
Email: quiverdesigns25@gmail.com | Phone: 0404 383 048
Postal address: 22 Murray Street, North Ward, Townsville, QLD 4810
Website: https://quivercollectivedesigns.com.au | Privacy Policy URL: https://quivercollectivedesigns.com.au/Privacy Policy.