Privacy Policy
How we handle the information you share with us. Aligned to the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Last updated · 22 April 2026
Who we are
This privacy policy applies to All Out Fishing & Tackle (ABN 74 686 262 975) trading as All Out Fishing & Tackle, of 105 Shannon Ave, Manifold Heights VIC 3218 ("we", "us", "our"). We are bound by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
What personal information we collect
We collect information that's reasonably necessary to run a retail fishing tackle business. That typically includes:
- Order information — name, email, phone, shipping and billing address, the items you bought, and how much you paid.
- Account information — if you create an account, an email address and password (stored hashed; we never see the plaintext).
- Payment information — handled by Stripe; we receive a transaction reference and the last four digits of the card, never the full card number or CVV.
- Communications — emails and call logs when you contact us.
- Site usage — anonymised page views, device type, browser, and broad geography via Google Analytics 4 (with consent) and Vercel Analytics.
- Marketing preferences — if you opt in, your subscription status for our newsletter or fishing reports.
How we use it
- To process and ship your orders, and respond to enquiries.
- To run our business — accounting, fraud prevention, returns and warranty claims, GST and BAS reporting.
- To improve the site — understand what works, fix what doesn't, plan stock based on what people are looking for.
- To send you transactional email (order confirmations, shipping notifications, refund notices). These can't be opted out of while you have an active order — they're part of fulfilling the order.
- To send marketing communications when you opt in. You can unsubscribe at any time using the link in any marketing email.
Who we share it with
We don't sell your information. We share it only with service providers we use to run the business, under contracts that require them to protect it:
- Stripe (payment processing) — name, billing address, card details
- Australia Post (shipping) — name, shipping address, phone
- Resend (transactional email) — name, email
- Supabase (database hosting, AU region) — everything stored in your account or order
- Vercel (site hosting) — site logs, anonymised
- Cloudinary (image hosting) — site assets only, no personal data
- Sentry (error monitoring) — incidental personal data only when an error trace contains it
- Google Analytics 4 (with consent) — anonymised site usage
We may also disclose information where required by law (e.g. a court order, a tax audit, a fraud investigation).
Where we store it
Operational data is stored in Australia (Supabase, Sydney region). Some service providers (Stripe, Resend, Sentry, Vercel) operate globally and may process data outside Australia. We only use providers with privacy frameworks comparable to the APPs.
How long we keep it
- Orders and tax records — at least 5 years from the end of the financial year, in line with ATO requirements.
- Account information — until you ask us to delete it.
- Marketing data — until you unsubscribe or unsubscribe automatically through 24 months of inactivity.
- Anonymous analytics — 14 months in GA4, 30 days in Vercel Analytics by default.
Your rights
You can ask us to:
- Show you the personal information we hold about you (a copy of your account profile and your order history).
- Correct it if it's wrong or out of date.
- Delete it where we're not required by law to keep it (we can't delete completed-order records inside the ATO retention window).
- Stop using it for marketing.
Email info@alloutfishing.com.au and we'll respond within 30 days.
Cookies and tracking
We use a small number of cookies for the site to work (cart state, login session, CSRF protection). These can't be turned off without breaking the site. We use Google Analytics 4 cookies only when you consent through the cookie banner — your choice is remembered for 12 months and you can change it at any time from the footer.
Children
Our site is not directed at children under 16 and we don't knowingly collect personal information from children under that age. If you believe we have, contact us and we'll delete it.
Security
We use HTTPS site-wide, hashed passwords, payment tokenisation through Stripe, and access controls on our admin systems. No system is perfectly secure — if we detect a notifiable data breach, we'll notify you and the OAIC in line with the Notifiable Data Breaches scheme.
Complaints
If you're not happy with how we've handled your privacy, email info@alloutfishing.com.au with "Privacy complaint" in the subject line. If we can't resolve it, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
We'll update this policy from time to time. The date at the top is when we last reviewed it. Material changes will be flagged on the homepage or by email if you have an account.