1. Introduction This Privacy Policy explains how Pottedcraft (the Data Controller, registered in Australia) collects, processes, and protects your personal data when you visit www.pottedcraft.com or make a purchase. We are committed to processing your information in strict compliance with the European General Data Protection Regulation (GDPR) and the Australian Privacy Act 1988.

2. Information We Collect To facilitate your order of our ceramic and cement succulent planters, we collect specific information, including:

  • Contact Information: Your name, email address (creative@pottedcraft.com), billing address, and shipping address.
  • Order Information: Details regarding the items you purchase and your transaction history with us.
  • Device Information: Standard web log data, including IP address, browser type, and timezone, collected automatically when you browse our website.

3. Payment Processing All payment transactions are processed directly by Stripe. When you make a purchase, your financial details are submitted directly to Stripe for processing. We do not view, process, or store your complete payment card numbers. The handling of your financial information by Stripe is subject to their own data policies and legal obligations as a regulated financial entity.

4. How We Use Your Information We use the collected data for the following purposes:

  • To process and fulfil your orders, including arranging shipping and providing order confirmations.
  • To communicate with you regarding your order status, policies, or general customer service enquiries.
  • To screen orders for potential risk or fraud, protecting both our business and our customers.
  • To comply with applicable European and Australian legal and regulatory obligations.

5. Data Retention We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy. To comply with strict Australian and European tax, accounting, and legal requirements, we retain transaction records and associated basic customer information for a period of seven years following your purchase. After this period, your data will be securely deleted or anonymised.

6. Data Sharing and International Transfers As an Australian-based entity fulfilling orders for European customers, your data is processed internationally. We share your information only with essential service providers necessary for order fulfilment, such as our shipping couriers and Stripe for payment execution. All international data transfers are conducted subject to appropriate safeguards in accordance with GDPR requirements. We do not sell or rent your personal information to any external entities.

7. Data Protection Measures We implement appropriate administrative and technical measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. While no internet transmission is entirely without risk, we continuously monitor and update our procedures to appropriately mitigate risks to your personal data.

8. Your Rights (GDPR & Australian Privacy Principles) If you are a resident of Europe or Australia, you hold specific rights regarding your personal data:

  • The Right of Access: You may request a copy of the personal data we hold about you.
  • The Right to Rectification: You may request that we correct any inaccurate or incomplete information.
  • The Right to Erasure: You may request the deletion of your personal data, subject to our overriding legal retention obligations.
  • The Right to Restrict Processing: You may request that we limit the processing of your data.
  • The Right to Data Portability: You may request the transfer of your data to another organisation.

9. Contact Us For any enquiries regarding this Privacy Policy or to exercise your data rights, please contact us at:

  • Email: creative@pottedcraft.com
  • Entity: Pottedcraft, Australia

We aim to respond to all formal privacy enquiries within 48 hours.