Privacy policy
# Privacy Policy
Last updated: May 2026
This Privacy Policy explains what personal information we collect when you interact with Novoshop, how we use it, who we share it with, and what choices you have. It is written in plain language because privacy notices that nobody reads protect nobody.
Novoshop PTY LTD is an Australian-registered company. We are bound by the Australian Privacy Act 1988 and, where it applies to your data, the EU General Data Protection Regulation (GDPR). For buyers in Greece, we also observe Greek data protection rules under HDPA oversight.
## 1. What we collect
When you request a quote or place an order, we collect:
- Your name and business name
- Your email address
- Your phone number (if you provide it)
- Your delivery address and any other addresses you ask us to ship to
- Your VAT or AFM (for EU buyers) or ABN (for AU buyers) where applicable
- The content of your communication with us (emails, WhatsApp messages, quote details)
- Your logo and design files you send us for production
- Payment confirmation details (we do not see or store your card or bank details directly. Payment is handled by our payment processor)
When you visit our website, we automatically collect:
- IP address (for spam and abuse prevention only)
- Browser and device type
- Pages viewed and time on page (anonymous aggregate analytics only)
- Cookies for site functionality (cart, language preference, session state)
We do not buy personal data from third parties. We do not run third-party advertising cookies on our site.
## 2. Why we collect it
The information we collect is used only for:
- Preparing quotes and producing the goods you ordered
- Communicating with you about your order, samples, deliveries, and reorders
- Processing payment and meeting our tax and accounting obligations under Australian and EU law
- Improving the website and our service
- Detecting and preventing spam, fraud, and abuse
- Complying with legal obligations we are subject to
We do not use your information for marketing without your consent. If you opt in to our future newsletter (when we launch one), we will say so clearly.
## 3. Who we share it with
We share the minimum necessary information with:
- Our ISO-certified factory, for the purpose of producing your order. The factory receives your design file, your label spec, your size run, and any production notes. The factory does not receive your contact details, payment details, or any unrelated information.
- Freight forwarders and customs agents, for the purpose of shipping and clearing your order. They receive your delivery address, contact name, contact phone, VAT or AFM, and any customs documents required by the destination country.
- Our payment processor, who handles your card or bank payment. They process your payment under their own privacy policy. We never see or store your card number.
- Our hosting and email providers, who process data on our behalf under data-processing agreements (Shopify for storefront, our email provider for inbox and forwarding).
- Tax authorities and other government bodies where required by law.
We do not sell, rent, or share your personal information with anyone for advertising or marketing.
## 4. International data transfers
Novoshop PTY LTD is an Australian-registered company operating internationally. Our ISO-certified factory is based outside the EU/EEA. Some of your data is therefore transferred internationally between our Australian operations, our factory, and our service providers.
For EU buyers, this involves transferring personal data outside the EU/EEA. We rely on Standard Contractual Clauses (SCCs) under GDPR Article 46 to protect transfers to Australia, our ISO-certified factory, and any other non-EU recipient. SCCs are in place with our factory, our hosting and email providers, and our freight partners.
If you want detail on the specific safeguards in place for your country, ask at sourcing@novoshop.com.au.
## 5. How long we keep your data
- Quote and order records: 7 years from the order date, to meet Australian tax and accounting record-keeping obligations.
- Design files you send us: kept indefinitely to support reorders, unless you request deletion.
- Email correspondence: 3 years after the last interaction.
- Website analytics: aggregated, retained for 26 months.
You can request deletion at any time, subject to our legal obligation to retain records for tax purposes.
## 6. Your rights
You have the right to:
- Ask what personal data we hold about you (access)
- Ask us to correct anything wrong (rectification)
- Ask us to delete data where we are no longer required to keep it (erasure)
- Restrict how we use your data
- Object to a specific use
- Receive your data in a portable format
- Withdraw consent for any use we depend on consent for
Send any of these requests to sourcing@novoshop.com.au. We respond within 30 days.
For EU buyers, you also have the right to lodge a complaint with your national data protection authority. The Greek authority is the Hellenic Data Protection Authority (HDPA, dpa.gr).
For AU buyers, you can complain to the Office of the Australian Information Commissioner (OAIC, oaic.gov.au).
## 7. Security
We use industry-standard security to protect your data:
- HTTPS encryption on the website
- Access controls on internal accounts (multi-factor authentication where supported)
- Encrypted storage of sensitive records
- Minimum-necessary sharing with the factory and freight partners
No system is perfectly secure. If we ever suffer a breach affecting your personal data, we will notify you and the relevant authorities within the timeframes required by law (72 hours under GDPR, "as soon as practicable" under the Australian Privacy Act).
## 8. Cookies
The website uses cookies for:
- Essential site functionality (cart, page state, session)
- Anonymous analytics (page views, bounce rate)
- Language and currency preferences
We do not use third-party advertising cookies. You can disable cookies in your browser settings, but parts of the website may not work correctly without essential cookies.
## 9. Children
This is a B2B website. Our service is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has submitted personal data through our site, contact us and we will delete it.
## 10. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated by email to clients with active orders.
## 11. Contact
Privacy questions: sourcing@novoshop.com.au
Mailing address (for formal requests): available on request to sourcing@novoshop.com.au.
---
Questions answered? Browse the catalogue: https://novoshop.com.au/pages/catalogue