PRIVACY POLICY

Teafy Pty Ltd
Version 2.0, effective 1st January 2026

1. WHO WE ARE

Teafy Pty Ltd (ABN 63 658 494 010, ACN 658 494 010), referred to in this Policy as "Teafy", "we", "us" or "our".

Registered office: 470 St Kilda Road, Melbourne VIC 3004, Australia.

This Policy explains how we collect, hold, use, disclose and protect personal information, and how you can access it, correct it, or make a complaint. This Policy is not a contract and does not create rights beyond those conferred by law.

2. OUR COMMITMENT AND THE LAW THAT APPLIES

2.1 We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs 1 to 13), to the extent they apply to us.

2.2 Businesses with an annual turnover of $3 million or less are generally exempt from the Privacy Act. Whether or not that exemption applies to Teafy from time to time, we apply the standards described in this Policy as a matter of practice.

2.3 We review this Policy periodically and whenever our practices change. The current version is always published at teafy.com.au/privacy-policy and supersedes all earlier versions.

3. WHAT WE COLLECT

3.1 Information you give us

Identity: your name, and your date of birth if you choose to enter it for a Rewards birthday bonus.

Contact details: email address, phone number, delivery address and billing address.

Account information: your username and password. Passwords are stored in hashed form and we never see them.

Order information: the products you order, your order history, delivery instructions and any gift messages.

Payment information: card type, the last four digits of your card, expiry date and billing name. We do not collect or store full card numbers or CVV codes. See clause 3.4.

Subscription information: your chosen frequency, next billing date, and your pause and cancellation history.

Rewards information: your Points balance, earning and redemption history, referral links and referred accounts.

Communications: emails, phone calls, contact form messages, chat messages, and any reviews or photographs you submit to us.

Wholesale enquiries: business name, ABN, trading address and trade references.

3.2 Information we collect automatically

Your IP address and the approximate location derived from it, device type, operating system, and browser type and version.

Pages viewed, time spent on each page, the URL that referred you, and searches you run on our site.

Cookie and pixel identifiers.

Device and browser characteristics that allow us to distinguish one device from another.

3.3 Information we receive from third parties

Payment processors: transaction outcomes, fraud signals and chargeback notices.

Carriers: tracking events, delivery scans, Safe Drop photographs and delivery exceptions.

Advertising and analytics platforms: aggregated campaign and audience data.

Review platforms: review content and verification status.

Social media platforms: where you interact with our accounts or use a social login.

3.4 What we deliberately do not collect

We do not collect or store full payment card numbers, CVV codes or bank credentials. Card details are entered directly into our payment processor's systems and are tokenised. Teafy never has access to them.

We do not collect sensitive information as defined in the Privacy Act, including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record or biometric data. Please do not send this information to us. If you send it to us unsolicited, we may destroy or de-identify it.

4. HOW WE COLLECT IT

4.1 Directly from you, when you create an account, place an order, sign up to our newsletter, join the Rewards Program, complete a contact form, email or phone us, submit a review, enter a competition, or make a wholesale enquiry.

4.2 Automatically, through cookies, pixels and analytics on our website. See clause 9.

4.3 From third parties, as described in clause 3.3. Where we collect your personal information from someone other than you, we take reasonable steps to notify you where APP 5 requires it.

5. WHY WE USE IT

To fulfil your order: processing payment, picking and packing, printing labels, arranging delivery and sending you tracking information.

To manage your account: authentication, order history, saved addresses and the Customer Portal.

To manage subscriptions: recurring billing, renewal reminders, pausing and cancellation, and tracking the minimum term.

To run the Rewards Program: crediting and reversing Points, issuing reward codes and verifying referrals.

To detect and prevent misuse and fraud, as described separately in clause 6.

To provide customer service: answering enquiries, investigating carrier claims and defect claims, and handling complaints.

For marketing: email and SMS marketing where permitted, and building advertising audiences. See clause 8.

To improve our website: analytics, testing, and understanding which pages and products perform.

For legal and compliance purposes: tax and financial records, Australian Consumer Law and food safety obligations, responding to lawful requests, establishing and defending legal claims, and enforcing our Terms and Conditions.

5.1 We may also use your personal information for a secondary purpose related to a purpose above, where you would reasonably expect us to, or where the Privacy Act otherwise permits.

6. FRAUD, MISUSE AND ACCOUNT LINKING

6.1 To protect the integrity of our pricing, promotions and Rewards Program, and to enforce our Terms and Conditions, we collect and analyse:

(a) account details, including email addresses and variants of them;

(b) delivery and billing addresses;

(c) tokenised payment instrument identifiers, which allow us to identify that two orders used the same card without us seeing the card number;

(d) device and browser identifiers;

(e) IP addresses; and

(f) patterns in order, discount code, referral and Points activity.

6.2 We use this information to identify where two or more accounts are likely to be controlled by the same person, and to detect duplicate welcome discount claims, self referrals, shared or leaked reward codes, and subscription cycling. By creating an account or placing an order, you consent to this collection and analysis.

6.3 Where this analysis leads us to propose action against your account, a person at Teafy makes the decision. We do not close accounts or charge amounts solely on the basis of an automated process. We will notify you and provide an opportunity to respond before acting, except where we reasonably suspect fraud, unauthorised use of a payment instrument, or a risk to the safety of any person.

6.4 We retain the evidence supporting any such decision for at least 12 months and may provide a summary of it on request.

7. WHO WE SHARE IT WITH

7.1 We do not sell your personal information.

7.2 We disclose personal information to the following categories of recipient, and only as reasonably necessary:

Ecommerce platform and hosting, to run our website and store: Webflow (United States).

Payment processing, to take payment, manage recurring billing and run fraud checks: Stripe and PayPal.

Subscriptions and rewards, to manage recurring orders, Points and referrals: Monto.

Email and SMS, to send marketing campaigns, automated flows and transactional messages: Klaviyo (United States).

Carriers, to deliver your order: Australia Post, and other carriers we use from time to time.

Analytics, to understand website performance and behaviour: Google Analytics, Google Search Console and Microsoft Clarity.

Advertising, to deliver and measure campaigns: Google Ads, Google Merchant Center and Meta.

Reviews, to collect, verify and display customer reviews.

Accounting and tax, to maintain our books, lodge BAS and keep statutory records.

Professional advisers: our lawyers, accountants, auditors and insurers.

Purchasers: where we sell or transfer all or part of our business or assets, to the purchaser and its advisers.

Government and regulators, where required or authorised by law, including the ATO, courts, police, the Office of the Australian Information Commissioner and the ACCC.

7.3 The providers named above may change from time to time. We may substitute a provider of the same category without amending this Policy.

7.4 We disclose personal information where required or authorised by law, including to comply with a subpoena or court order, or a request from a regulator or law enforcement agency acting within its powers, and where reasonably necessary to establish, exercise or defend a legal claim.

8. MARKETING AND YOUR CHOICES

8.1 We send marketing emails and SMS where you have consented, or where you are an existing customer and the message relates to products of the kind you have bought from us, as permitted by the Spam Act 2003 (Cth).

8.2 Every marketing email contains a working unsubscribe link, and every marketing SMS contains an opt out instruction. We action opt out requests within 5 working days. The unsubscribe facility in any message remains functional for at least 30 days after that message is sent.

8.3 Opting out of marketing does not stop transactional messages, including order confirmations, shipping notifications, subscription renewal reminders, Points expiry notices and service messages. These are not marketing, and you cannot opt out of them while you hold an account or have an active order.

8.4 We may build advertising audiences by supplying hashed email addresses to advertising platforms, so that ads can be shown to, or withheld from, existing customers. You can opt out of this by emailing info@teafy.com.au.

8.5 You can update your marketing preferences at any time in the Customer Portal, or by emailing us.

9. COOKIES AND TRACKING

9.1 We use cookies and similar technologies for four purposes:

Essential: your cart, login session, checkout and site security. These cannot be disabled without breaking the site.

Analytics: understanding how the site is used.

Advertising: measuring campaigns and showing relevant ads.

Functional: remembering your preferences.

9.2 You can block or delete cookies in your browser settings. Blocking essential cookies will prevent checkout from working, and we are not responsible for any loss of functionality that results.

9.3 You can opt out of certain tracking directly. For Google Ads, visit adssettings.google.com. For Google Analytics, visit tools.google.com/dlpage/gaoptout. For Meta, use the ad preferences in your Facebook or Instagram account.

9.4 We honour Global Privacy Control signals where the platforms we use support them.

10. SECURITY

10.1 We take reasonable steps to protect personal information using TLS and SSL encryption in transit, encryption at rest with our platform providers, access controls and role based permissions, hashed password storage, tokenised payment data, and multi factor authentication on administrative accounts.

10.2 No system, and no method of transmission over the internet, is completely secure. We cannot guarantee absolute security, and we do not warrant that our systems or those of our providers will be free from unauthorised access. You transmit information to us at your own risk.

10.3 You are responsible for protecting your own account, including by using a unique password, never sharing your credentials, and signing out on shared devices. We are not responsible for loss arising from your failure to do so.

10.4 If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

11. HOW LONG WE KEEP IT

Order and transaction records: 7 years from completion of the transaction. The Corporations Act 2001 (Cth) requires a company to keep financial records for 7 years. The ATO's separate general requirement is 5 years, so the longer period governs.

Account and profile data: while your account is active, then up to 24 months.

Rewards Points and history: while your account is active, then up to 24 months, for program administration and dispute resolution.

Marketing consent records: for as long as consent stands, plus 2 years, as proof of consent under the Spam Act.

Fraud and misuse evidence: at least 12 months from the date of the decision, and longer where reasonably necessary to protect our legal position.

Carrier claim and defect evidence: up to 24 months.

Website analytics: up to 26 months.

Contact form and email correspondence: up to 24 months.

11.1 We may retain personal information for longer where reasonably necessary to comply with a legal obligation, to resolve a dispute, or to establish, exercise or defend a legal claim.

11.2 When personal information is no longer needed for any purpose for which it may lawfully be used, and we are not required by law to retain it, we destroy it or de-identify it. We may retain and use de-identified and aggregated data indefinitely.

12. YOUR RIGHTS

12.1 Access. You may request access to the personal information we hold about you. There is no charge to make a request. We may charge a reasonable cost based fee for giving access where a request is extensive. We will tell you the amount before proceeding.

12.2 Correction. You may ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We will correct it, or explain in writing why we have not.

12.3 Deletion. You may ask us to delete your personal information. We will do so unless we are required or entitled to retain it, including under clauses 11 and 11.1. We will tell you what has been retained and why.

12.4 Marketing opt out. See clause 8.

12.5 Anonymity. You may deal with us anonymously or under a pseudonym for general enquiries. We cannot fulfil an order without a name and a delivery address.

12.6 We may refuse a request for access or correction where the Privacy Act or another law permits or requires us to do so. Where we refuse, we will give you written reasons and tell you how to complain.

12.7 How to exercise these rights. Email info@teafy.com.au. We will verify your identity before acting on a request, acknowledge your request within 5 business days, and respond within 30 days.

13. OVERSEAS DISCLOSURE

13.1 Some of our service providers store or process personal information outside Australia. The countries in which recipients are likely to be located are the United States, in respect of Webflow, Klaviyo, Stripe, PayPal, Google, Meta and Monto.

13.2 Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual terms and by selecting providers with recognised security certifications.

13.3 By providing your personal information to us and using our website, you consent to the disclosure of your personal information to overseas recipients of the kinds and in the countries described in this clause. Where you give that consent, APP 8.1 does not apply and we are not required to ensure that the overseas recipient does not breach the Australian Privacy Principles.

13.4 Clause 13.3 does not limit any obligation we have under the Privacy Act that cannot lawfully be excluded.

14. THIRD PARTY WEBSITES

14.1 Our website may contain links to third party websites, plug ins and applications. We do not control those third parties and we are not responsible for their privacy practices or content.

14.2 We encourage you to read the privacy policy of every website you visit.

15. CHILDREN

15.1 Our website is not directed at children under 18, and we do not knowingly collect personal information from a person under 18.

15.2 If we become aware that we have collected personal information from a child under 18 without parental consent, we will delete it.

16. COMPLAINTS

16.1 If you believe we have breached the Australian Privacy Principles, please contact our Privacy Officer:

Privacy Officer, Teafy Pty Ltd
470 St Kilda Road, Melbourne VIC 3004, Australia
privacy@teafy.com.au

16.2 We will acknowledge your complaint within 5 business days and respond within 30 days.

16.3 If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:

Online: oaic.gov.au/privacy/privacy-complaints
Phone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001

17. CHANGES TO THIS POLICY

17.1 We may update this Policy at any time. The effective date at the top shows when it last changed.

17.2 Where a change materially affects how we handle your personal information, we will notify you by email at least 14 days before it takes effect.

17.3 Your continued use of our website or services after a change takes effect constitutes acceptance of the updated Policy.

17.4 Previous versions are available on request.

18. GOVERNING LAW

18.1 This Policy is governed by the laws of Victoria, Australia.

Teafy Pty Ltd, ABN 63 658 494 010, ACN 658 494 010
470 St Kilda Road, Melbourne VIC 3004, Australia
privacy@teafy.com.au, 1300 986 888

Version 2.0, effective 1st January 2026.