Privacy Policy
Arca Lab | ABN: 87 689 773 153 | Last Updated: 9 April 2026
This Privacy Policy explains how Arca Lab ("we", "us", "our") collects, uses, discloses, and protects your personal information when you visit www.arcalab.com.au, use our services, or purchase our products. "You" and "your" refers to you as a user, customer, or any individual whose personal information we hold.
Please read this policy carefully. By using our website or services, you consent to the practices described in this policy. If you do not agree, please do not use our website or services.
1. Our Commitment to Privacy
Arca Lab is committed to protecting your privacy and handling your personal information in accordance with the
Privacy Act 1988 (Cth) (the "Privacy Act") and the
Australian Privacy Principles (APPs), as set out in Schedule 1 of the Privacy Act. This policy applies to personal information collected through our website and in connection with our services.
Where we use the term "personal information", we mean information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether recorded in material form or not.
2. What Personal Information We Collect
2.1 Information You Provide Directly
We collect personal information that you voluntarily provide to us, including:
- Contact details: name, email address, phone number, billing and shipping address
- Order information: items purchased, order history, payment confirmation details
- Account credentials: username, password, security questions
- Shopping preferences: items viewed, added to cart, or saved to a wishlist
- Customer support communications: information you share when contacting us
2.2 Information Collected Automatically
When you visit our website, we may automatically collect usage and technical data, including:
- Device and browser type and settings
- IP address and approximate location derived from IP
- Pages viewed, links clicked, and time spent on site
- Referring URLs and exit pages
This information is collected using cookies, pixels, and similar tracking technologies. See Section 6 (Cookies) for more information.
2.3 Information from Third Parties
We may receive personal information about you from third parties, including:
- Shopify Inc. (our e-commerce platform provider)
- Payment processors (who handle payment card data on our behalf)
- Advertising and analytics partners
Information received from third parties is handled in accordance with this policy.
3. How We Use Your Personal Information
3.1 Order Fulfilment. To process and fulfil your orders, arrange delivery, manage returns and exchanges, and send transactional communications (including order confirmations and shipping notifications).
3.2 Account Management. To create and manage your account, authenticate your identity, and maintain account security.
3.3 Customer Support. To respond to your enquiries, resolve disputes, and improve our services.
3.4 Marketing Communications. To send you promotional emails, SMS messages, or other marketing communications about our products and offers — but only where you have consented to receive them, or where we are otherwise permitted to do so under applicable law. You may opt out at any time (see Section 8).
3.5 Advertising Personalisation. To show you tailored advertisements on our website and third-party platforms, using data about your browsing and purchase history. This may involve sharing data with advertising partners, including through Shopify Audiences.
3.6 Analytics and Site Improvement. To analyse how users interact with our website, identify issues, and improve functionality and user experience.
3.7 Fraud Prevention and Security. To detect, investigate, and prevent fraudulent, malicious, or unlawful activity in connection with our services.
3.8 Legal Compliance. To comply with applicable laws, regulations, court orders, and legal processes, and to enforce our terms and policies.
4. Disclosure of Personal Information
We do not sell your personal information in exchange for money. However, we may share your personal information with the following categories of recipients for the purposes described in this policy:
|
Category of Personal Information |
Purpose of Collection / Use |
Categories of Recipients |
|---|---|---|
|
Identifiers: name, email, phone, billing & shipping address |
Order fulfilment, account management, customer support, and fraud prevention |
Shopify, payment processors, fulfilment/shipping partners, customer support providers |
|
Payment information: card/bank details, billing address |
Payment processing (handled by our payment processor; we do not store full card details) |
Payment processors (e.g. Shopify Payments, Stripe) |
|
Order & commercial information: items purchased, order history, cart/wishlist |
Order fulfilment, marketing personalisation, returns & exchanges |
Shopify, fulfilment partners, marketing partners |
|
Usage / technical data: IP address, browser, device, site interaction, cookies |
Site analytics, security monitoring, and advertising optimisation |
Analytics providers, advertising/marketing partners |
|
Account credentials: username, password, security questions |
Account authentication and security |
Shopify (platform provider) |
|
Customer support communications |
Resolving enquiries, improving services |
Customer support tools/providers |
4.1 Business Transactions. If Arca Lab undergoes a merger, acquisition, sale of assets, or insolvency event, your personal information may be transferred to the relevant third party as part of that transaction. We will take reasonable steps to ensure your information remains protected.
4.2 Legal Disclosures. We may disclose personal information where required or authorised by law, including in response to a court order, subpoena, regulatory request, or to protect the rights, property, or safety of Arca Lab, our customers, or others.
4.3 Consent. We may share your information with other third parties where you have provided your express consent.
5. Cross-Border Disclosure
Some of the third-party service providers we use (including Shopify Inc., which is headquartered in Canada) may store or process your personal information outside Australia. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles your information in a manner consistent with the Australian Privacy Principles.
By using our services, you consent to the transfer of your personal information to overseas recipients as described in this policy.
6. Cookies and Tracking Technologies
6.1 What We Use. We use cookies, pixels, web beacons, and similar technologies to operate and improve our website, remember your preferences, and support advertising and analytics functions.
6.2 Third-Party Cookies. We permit third-party service providers (including Shopify and advertising partners) to place cookies on our website. For information about Shopify's cookies, see: https://www.shopify.com/legal/cookies.
6.3 Your Choices. You can manage or disable cookies through your browser settings. Disabling cookies may affect the functionality of certain parts of our website. Note that disabling cookies does not necessarily prevent all information sharing with third-party advertising partners.
6.4 Global Privacy Control. If you visit our website with a Global Privacy Control (GPC) opt-out signal enabled, we will treat this as a request to opt out of the sale or sharing of your personal information for the device and browser you are using.
7. User-Generated Content
If you submit a product review or other content to a public area of our website, that content will be publicly visible and accessible to others. We are not responsible for how third parties use information you choose to make publicly available. Please exercise caution when posting any personal information in public areas.
8. Your Privacy Rights and Choices
Under the Privacy Act and the Australian Privacy Principles, you have the following rights in relation to your personal information:
8.1 Access. You have the right to request access to the personal information we hold about you, including how we use and disclose it.
8.2 Correction. You have the right to request that we correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
8.3 Deletion. You may request that we delete personal information we hold about you. We will comply unless we are required or authorised by law to retain it (for example, for tax, legal, or fraud prevention purposes).
8.4 Opt Out of Marketing. You may opt out of receiving promotional communications at any time by clicking the unsubscribe link in any marketing email we send, or by contacting us directly. We may continue to send you non-promotional communications (such as order confirmations and account notices).
8.5 Opt Out of Targeted Advertising. You may opt out of the use of your personal information for targeted advertising purposes by contacting us or by managing your preferences through Shopify's privacy settings at https://privacy.shopify.com/en.
8.6 Restriction of Processing. In certain circumstances, you may request that we restrict the processing of your personal information.
8.7 Data Portability. Where technically feasible and required by applicable law, you may request a copy of your personal information in a structured, machine-readable format.
8.8 Withdrawal of Consent. Where we rely on your consent to process your personal information, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at info@arcalab.com.au. We may need to verify your identity before actioning your request. We will respond within a reasonable time as required by applicable law and will not discriminate against you for exercising your rights.
9. Children's Privacy
Our website and services are not directed at children under the age of 15. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at info@arcalab.com.au, and we will promptly delete that information.
10. Security of Your Personal Information
We take reasonable technical and organisational measures to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. These measures include encrypted data transmission (SSL/TLS) and access controls on systems that store personal information.
However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security. You should take care when transmitting sensitive information online and avoid using unsecured channels to communicate confidential information to us.
Data Breaches. In the event of an eligible data breach as defined under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act), we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.
11. Retention of Personal Information
We retain your personal information for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law. Factors we consider in determining retention periods include:
- Whether you have an active account with us
- Whether we are required to retain the information to comply with legal, tax, or regulatory obligations
- Whether the information is needed to resolve disputes or enforce our agreements
When personal information is no longer required, we will take reasonable steps to destroy or de-identify it securely.
12. Third-Party Websites and Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to review the privacy policies of any third-party sites you visit. Our inclusion of a link does not constitute an endorsement of the third party's privacy practices.
13. Complaints
If you have a concern about how we have handled your personal information, please contact us in the first instance at info@arcalab.com.au. We will acknowledge your complaint within a reasonable time and respond substantively.
If you are not satisfied with our response, you may lodge a complaint with the
Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated policy on our website and update the "Last Updated" date. Material changes will be communicated to you by email or via a notice on our website where required by law. Your continued use of our services after any update constitutes your acceptance of the revised policy.
15. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact our Privacy Contact:
Arca Lab — Privacy Contact
Email: info@arcalab.com.au
ABN: 87 689 773 153
Website: www.arcalab.com.au
This Privacy Policy was last updated: 9 April 2026. This document does not constitute legal advice. Arca Lab recommends seeking independent legal advice to confirm compliance with all applicable privacy obligations, particularly the Privacy Act 1988 (Cth) and Australian Privacy Principles.