Privacy policy

Privacy Policy

Last updated: October 2025

BOXED Fitouts (“we”, “our”, “us”) operates this website and related online store (the “Services”). We are committed to protecting your privacy and handling your personal information in accordance with the Australian Privacy Principles (APPs), as well as other applicable laws.

This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit or make a purchase from our website, join our mailing or SMS lists, or otherwise interact with us.

By using our Services, you agree to the terms of this Privacy Policy.


1. Information We Collect

We collect personal information that you provide to us directly, automatically through your use of the Services, and from third parties. The categories of information we collect may include:

Contact information: name, email address, phone number, shipping and billing address.

Account details: username, password, preferences, and saved settings.

Payment information: payment card details, transaction and billing records (processed securely by Shopify Payments or other payment gateways — we do not store full card numbers).

Order and transaction history: products viewed, purchased, returned, or exchanged.

Device and usage data: IP address, browser type, device identifiers, cookies, browsing behaviour, and interactions with our website.

Marketing and communications data: preferences for email and SMS marketing, feedback, survey responses, and communications with our team.

We may also receive information from:

Third-party service providers such as Shopify (our e-commerce platform) and Klaviyo (our marketing and email/SMS provider).

Advertising and analytics partners such as Meta (Facebook, Instagram) or Google.

Publicly available sources or social media accounts when you interact with our pages or ads.


2. How We Use Personal Information

We use your personal information to:

Provide and deliver our Services – process orders, payments, and shipping; create and manage your account; respond to enquiries; and offer customer support.

Improve and personalise your experience – remember your preferences, recommend products, and enhance our website performance and usability.

Marketing and promotions – send you marketing communications by email or SMS (with your consent), display personalised ads based on your browsing or purchase history, and notify you about offers or new products.

Abandoned cart reminders – if you start checkout but do not complete your purchase, we may send you an email or SMS reminder (only if you’ve opted in to receive communications).

Security and fraud prevention – detect and prevent fraud, secure our website, and maintain the integrity of transactions.

Legal compliance – comply with applicable laws, tax obligations, and respond to lawful requests.


3. Email & SMS Marketing (Klaviyo)

We use Klaviyo to manage our email and SMS communications.
When you sign up to our mailing list, submit your phone number at checkout, or otherwise opt in to receive marketing, you consent to us sending you messages about our products, promotions, and updates.

You can unsubscribe from email marketing at any time by clicking “Unsubscribe” in the email footer.

You can opt out of SMS by replying “STOP” to any message or contacting us directly.

We may use cookies and similar technologies to identify when you have added items to your cart and send reminders if you’ve opted in.

We will never share or sell your phone number or SMS-consent information to third parties for unrelated marketing.

Klaviyo acts as a data processor on our behalf and may store or process information in the United States or other jurisdictions under strict data-protection agreements.


4. Cookies and Tracking

We use cookies, pixels, and similar tracking technologies to:

Enable essential website functions (such as checkout and login).

Understand website performance and user interactions.

Personalise marketing and advertising across platforms (e.g., Meta, Google).

You can control cookies through your browser settings, though disabling them may limit some site functionality.


5. How We Disclose Personal Information

We may share your personal information with:

Shopify, who hosts our store and processes transactions.

Klaviyo, who manages our email and SMS marketing.

Service providers assisting with IT, analytics, fulfilment, shipping, or marketing.

Advertising partners to deliver personalised or retargeted ads (you can opt out at any time).

Authorities or legal entities if required by law, to prevent fraud or ensure compliance.

Corporate transactions, such as a sale or merger of our business.

These third parties are bound by confidentiality and data-processing agreements and are only permitted to use your data as necessary to perform their services.


6. International Data Transfers

We are based in Australia, but our website and marketing platforms (Shopify and Klaviyo) may store or process your information in the United States, Canada, the European Union, or other jurisdictions.

Where personal information is transferred outside your country, we rely on data-transfer mechanisms such as Standard Contractual Clauses (SCCs) or other legally recognised safeguards to protect your data.


7. Data Retention

We keep personal information only as long as necessary for the purposes outlined above:

Order and payment data: retained for 7 years to meet tax and record-keeping obligations.

Marketing data (email/SMS): retained while you remain subscribed or up to 3 years after inactivity.

Browsing and device data: retained for up to 2 years for analytics and security purposes.
We periodically review our retention periods and securely delete or anonymise data when no longer needed.


8. Your Rights and Choices

Depending on where you live, you may have the following rights regarding your personal information:

Access: request a copy of the personal information we hold about you.

Correction: request that we correct inaccurate or incomplete information.

Deletion: request that we delete your personal information, subject to legal retention obligations.

Portability: request that your data be transferred to another service provider.

Opt out of marketing: unsubscribe from emails or SMS, or opt out of personalised advertising.

Opt out of profiling: request that we do not use your data for automated profiling or targeted advertising.

To exercise any of these rights, contact us at info@boxedfitouts.com.au. We may ask you to verify your identity before processing your request.

We will not discriminate against you for exercising your privacy rights.


9. Security

We take reasonable steps to protect your personal information using physical, electronic, and administrative safeguards. However, no system is completely secure, and we cannot guarantee absolute security of information transmitted online.


10. Children’s Privacy

Our Services are not directed to children under the age of 18, and we do not knowingly collect personal information from minors. If you believe your child has provided personal information to us, please contact us to request deletion.


11. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised “Last updated” date. Significant changes will be communicated via our website or email notice.


12. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or how we handle your personal information, please contact us:

BOXED Fitouts

Reedy Creek, QLD, Australia
✉️ info@boxedfitouts.com.au

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.


Third-Party Links

Our website may contain links to other sites (for example, YouTube or Instagram). We are not responsible for the privacy practices or content of those external sites. We recommend you review their privacy policies.