Privacy Policy Australia Tasting Room & Buy the Box
-
Who we are & scope
- This Privacy Policy explains how Mullholland Pty Ltd (ABN 13 131 922 008) trading as Australia Tasting Room (ATR) and Buy the Box (BTB) (together, “we”, “us”, “our”) collects, uses, discloses and protects your personal information across our websites, customer accounts, marketing, and customer support channels.
- It applies to visitors, customers, gift card purchasers/recipients, producers/vendors and business contacts interacting with ATR and BTB globally.
- We comply with the Australian Privacy Act and Australian Privacy Principles (APPs), and where applicable the GDPR/UK GDPR and California CCPA/CPRA.
- By using our services, you agree to this policy.
-
Personal information we collect
- Identity & contact: name, email, phone, billing/shipping addresses, country.
- Account: login details, preferences, saved addresses, marketing subscriptions.
- Order & fulfilment: items purchased, gift messages, order notes, bottle limits, delivery instructions, proof-of-age (where required), customs information and declarations for international shipments.
- Payments: payment method, transaction IDs and status from payment providers (we do not store full card numbers).
- Producer/vendor: winery contact details, store profiles, product and stock information, fulfilment and settlement history.
- Device & usage: IP address, device identifiers, browser/OS, pages viewed, referring URLs, session logs, cookie IDs, advertising IDs.
- Communications: emails, chat messages, support cases, survey responses, reviews (including any images you upload).
- Special cases: documents needed to comply with import rules in certain countries (e.g., tax IDs, permits). We collect only what is legally required to process your order.
-
How we collect information
- Directly from you: during checkout, account creation, forms, emails, support tickets, reviews and surveys.
- Automatically: via cookies, pixels and analytics when you browse our sites.
- From third parties: payment processors, fraud-prevention services, logistics partners (e.g., couriers and customs), marketing platforms, social sign-ins where used.
-
Why we use your information
- Provide & improve services: process orders, deliver goods, customer support, returns/credits, site performance and personalisation.
- Legal & compliance: age verification, customs and import/export declarations, tax and accounting, fraud and security.
- Communications: transactional emails (order/invoice/shipping/credit), service notices, and—if you opt in—newsletters, recommendations and promotions.
- Analytics & ads: understand usage, measure campaigns, prevent abuse.
- Legal bases (EU/UK): performance of contract, legitimate interests (running and securing our services), consent (marketing/cookies), legal obligation.
-
Sharing your information
- Producers/Vendors: only what’s needed to fulfil your order (items, recipient details, delivery info, gift messages).
- Logistics & customs: couriers, consolidators and customs authorities (e.g., Get Freighted for ATR USA consolidations; DHL for Rest of World), including required customs data.
- Payments: PCI-compliant processors and anti-fraud providers.
- Service providers: IT hosting, email and marketing platforms, analytics and support tools under data processing agreements.
- Legal: where required by law, to protect our rights, or for fraud prevention.
- We do not sell your personal information.
-
International transfers
- Your data may be processed in Australia and other countries where we or our partners operate (including the US, UK/EU, New Zealand, Singapore, Hong Kong, Japan and others).
- Where required, we use approved safeguards (e.g., Standard Contractual Clauses, UK Addendum) and contractual protections.
-
Retention
- Orders, invoices and financial records: kept for statutory periods (typically up to 7 years).
- Accounts: for as long as your account remains active or as needed to provide services.
- Marketing preferences: until you unsubscribe or your request is actioned.
- Support records: retained per our operational/legal requirements.
- Cookies: per cookie type and tool, as disclosed in our Cookie section.
-
Your choices & rights
- All users: access/update your details via “My Account”; unsubscribe links in marketing emails; contact us to exercise privacy rights.
- Australia (APPs): request access and correction; lodge complaints with the OAIC.
- EU/UK (GDPR): rights to access, rectification, erasure, restriction, portability, objection; withdraw consent; complain to your Data Protection Authority.
- California (CCPA/CPRA): rights to know/access, correct, delete, and limit use of sensitive personal information; opt-out of “sharing” for cross-context behavioural advertising (we do not “sell” personal information).
- We will verify requests and respond within applicable timeframes.
-
Cookies, analytics & ads
- We use essential cookies (site functionality and security) and, with consent where required, performance/analytics and marketing cookies/pixels.
- You can manage cookies via your browser settings and, where available, our cookie preferences tools. Blocking some cookies may affect site functionality.
-
Marketing preferences
- You’ll only receive marketing if you opt in or where otherwise permitted by law. You can unsubscribe anytime via the link in our emails or in your account preferences.
- Transactional emails related to your orders and account will continue regardless of marketing preferences.
-
Security
- We implement administrative, technical and physical safeguards appropriate to the nature of the data, including encryption in transit, access controls and monitoring.
- We notify authorities and/or affected individuals of data breaches as required by applicable law.
-
Children & age restrictions
- Our services are intended for persons of legal drinking age in their jurisdiction. We do not knowingly collect data from minors.
-
Links to other sites
- Our websites may contain links to third-party sites. We are not responsible for their privacy practices. Review their policies before providing personal information.
-
Changes to this policy
- We may update this policy from time to time. The latest version applies. Effective date: August 2025.
-
Contact & complaints
- Data Controller: Mullholland Pty Ltd (Australia Tasting Room & Buy the Box), L2/100 Cubitt St, Cremorne VIC 3121, Australia.
- Email: support@australiatastingroom.com (or use the contact form on our websites).
- Australia (OAIC): You may lodge a complaint with the Office of the Australian Information Commissioner if you’re unsatisfied with our response: oaic.gov.au/privacy/privacy-complaints.
- For EU/UK/California residents, you may also contact your local authority as outlined in “Your choices & rights”.