Privacy policy
What we collect, why we collect it, where it lives, and how to make us delete it. Written plainly, because a policy nobody reads protects nobody.
On this page
1. Who we are 2. What we collect 3. Your files and drawings 4. Why we collect it 5. Where it's stored, including overseas 6. Who else sees it 7. How long we keep it 8. Access, correction and deletion 9. Security, and what happens if we get breached 10. Cookies and tracking 11. Marketing email 12. Complaints1. Who we are
[[ENTITY]], an individual trading as a sole trader.
[[ADDRESS]], [[SUBURB]] [[STATE]] [[POSTCODE]], Australia.
Contact: [[EMAIL]] · [[PHONE]]
In this policy "we" and "us" mean that entity; "you" means anyone who contacts us, places an order, or uses this website. The data controller is the person behind the ABN above.
Australia's Privacy Act 1988 currently exempts most small businesses with annual turnover under $3 million, and that exemption still applies to us today. The Government has committed to removing it, with a commencement date flagged for 10 December 2026. Rather than write a weaker policy now and a real one later, this policy is written to the standard of the 13 Australian Privacy Principles from the outset. We intend to honour it whether or not the law compels us to.
2. What we collect
Only what's needed to quote your job, make your part, and get it to you.
| Information | When | Required? |
|---|---|---|
| Name | When you start a job or contact us | Yes |
| Email address | Same | Yes — it's how we send your quote |
| Phone number | Same | No, optional |
| Business name | Same | No, optional |
| Job details | Material, quantity, dates, delivery choice, notes | Yes |
| Delivery address | Only if you ask us to post it | Only for postage |
| Photos you send | By email, if you're describing a part | No |
We do not collect or store payment card details. If you pay by card, you're handed to Stripe and the card number never reaches us or our systems. If you pay by bank transfer, we see only what appears on our bank statement.
We don't ask for, and don't want, sensitive information as the Privacy Act defines it — health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, or biometric data. Please don't send it.
3. Your files and drawings
This one matters more than the rest, so it gets its own section.
- Model files are measured in your own browser. When you upload an STL or 3MF to get a price, the file is read on your computer and never leaves it. Only the resulting numbers — size, weight, estimated print time — are sent to us. You can price a confidential part without transmitting it.
- Files you send us deliberately — by email, or a link to Drive, Dropbox or WeTransfer — are used solely to make your job.
- We never resell, republish or share your files, and we never use your design in our catalogue, marketing or portfolio without asking you first, in writing.
- Drawings we produce for you under the $89 drawing fee: you receive the printed part. The source CAD stays with us unless you buy it, which we're glad to sell — see the terms. We may reuse our own generic techniques and templates; we will not reuse anything that identifies your part or your business.
- Ask and we delete. Email us and your files are gone, normally same day.
4. Why we collect it
- To price your job and send you a written quote
- To make the part and get it to you
- To let you track your job using your reference and email
- To invoice you and keep the tax records the ATO requires
- To answer you if something goes wrong
That's the complete list. We don't build profiles, we don't score you, and we don't sell data.
5. Where it's stored, including overseas
Order records are held in Cloudflare Workers KV, a service run by Cloudflare, Inc. Cloudflare operates a global network, so your information may be stored and processed on servers outside Australia, including in the United States and elsewhere.
We're telling you this because Australian Privacy Principle 8 requires it before an overseas disclosure, and because you deserve to know. By placing an order you consent to that overseas storage. If you consent, we will not be accountable under the Australian Privacy Principles for how that overseas recipient handles your information, and you may not be able to seek redress under the Privacy Act in respect of their handling of it. If you'd rather your details didn't leave Australia, ring us on [[PHONE]] or email [[EMAIL]] and we'll take your job by phone and paper instead.
Email we exchange with you sits with our email provider. Invoices and tax records are kept in our accounting records in Australia.
6. Who else sees it
A short list, and it stays short:
| Who | What they get | Why |
|---|---|---|
| Cloudflare, Inc. | Order records | Hosting and storage |
| Stripe | Payment details you enter with them | Card payment, if you choose it |
| Australia Post | Name and delivery address | Only if you ask us to post it |
| Our accountant | Invoices | Tax and BAS obligations |
We do not sell your information. We do not trade, rent or swap mailing lists. We will disclose information if a law, court order or regulator compels us to, and we'll tell you unless we're legally prevented from doing so.
7. How long we keep it
- Files and drawings: kept while your job is live and for 12 months after, so a repeat or a resize is quick. Deleted sooner on request.
- Order records: 7 years, because tax law requires it.
- Enquiries that never became orders: deleted within 12 months.
8. Access, correction and deletion
You can ask us at any time to:
- tell you what we hold about you
- give you a copy of it
- correct anything that's wrong
- delete it — everything except records we're legally required to keep for tax
Email [[EMAIL]]. No form, no fee. We'll respond within 30 days and usually much sooner. If we can't do what you've asked, we'll tell you why in writing.
9. Security, and what happens if we get breached
What we actually do: the site is served over HTTPS; the admin panel is behind a password held as a server-side secret and never stored in the website's code; sessions expire after 12 hours; card details never touch our systems.
What we won't pretend: we're a one-person workshop, not a bank. No system is perfectly secure. What we hold is deliberately minimal so that a breach would be embarrassing rather than dangerous — there is no card data, no passwords of yours, and nothing sensitive.
If we ever suffer a data breach likely to cause you serious harm, we'll tell you and the OAIC, promptly and in plain language, in line with the Notifiable Data Breaches scheme.
10. Cookies and tracking
We use no advertising cookies, no analytics, and no third-party trackers. There is no Google Analytics, no Meta pixel, and nothing following you around the internet afterwards.
The site stores a small amount of data in your own browser (localStorage) to remember a job you started and, if you're us, an admin session. That never leaves your device except when you submit a job. Clearing your browser data removes it.
11. Marketing email
We don't run a mailing list. If that ever changes, we'll only email you with your consent, every message will say who it's from and carry a working unsubscribe, and we'll act on an unsubscribe within five business days — as the Spam Act 2003 requires. Job-related email about an order you placed isn't marketing and will keep coming until your job is finished.
12. Complaints
Tell us first: [[EMAIL]]. We'll acknowledge within 5 business days and give you an answer within 30.
If you're not satisfied, you can raise it with the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992. While the small business exemption applies to us the OAIC may not have formal jurisdiction over a complaint against us — but we commit to handling one the way that process would, and if we break the promises in this policy you may also have rights under the Australian Consumer Law.
If we change it we'll update the date at the top and, where the change materially affects you, tell you by email. The current version always lives at this address.