Legal

Privacy Policy

Last updated: 17 March 2026 · Effective date: 17 March 2026

Overview

Bush & Salt Pty Ltd ("Bush & Salt", "we", "us", or "our"), registered in Australia (ABN: 32 692 105 678), respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and share your information when you visit bushandsalt.com.au, use our mobile-optimised site, engage with our marketing communications, or purchase our products.

This policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using our website or placing an order, you agree to the practices described in this policy. If you do not agree, please do not use our services.

Our website and ecommerce platform is operated through Shopify Inc. Our email and SMS marketing is managed through Klaviyo Inc. Both are described fully in the Third-Party Service Providers section below.

We will never sell, rent, or trade your personal information to any third party for their own commercial or marketing purposes. That is an absolute commitment, not a policy position subject to revision.

Information We Collect

We collect personal information in the following ways:

Information you provide directly at checkout

  • Name, email address, billing and shipping address, and phone number.
  • Payment information — collected and tokenised directly by Shopify Payments and Stripe. We do not store, see, or have access to your full card details at any point.
  • Order notes or delivery instructions you choose to include.

Information collected through other features

  • Notify Me (back-in-stock): When you submit your email address to be notified when a sold-out product returns to stock, that email address is stored and shared with Klaviyo to trigger the notification. It is used only for that purpose unless you separately opt in to marketing.
  • Wishlist: If you save products to your wishlist, we associate that selection with your account or session. Wishlist data may be used to personalise product recommendations and, with your consent, to send personalised communications via Klaviyo.
  • Skin Quiz: When you complete our product recommendation quiz, your responses (including skin type, skin concerns, and sensitivities) are collected. These responses are health-adjacent information under Australian privacy law. They are used solely to recommend relevant products and improve our quiz logic. They are not shared with third parties except as necessary to deliver the quiz experience, and are not used for profiling outside of the quiz context.
  • Account registration: If you create an account, we store your name, email, and order history.
  • Newsletter subscriptions: Email address and your marketing preferences (subscribed, unsubscribed, category preferences).
  • Contact and support: Communications you send us via email, contact forms, or social media direct messages.
  • Reviews and feedback: Content you choose to submit, which may be published publicly.

Information collected automatically

  • IP address, browser type, operating system, and device identifiers.
  • Pages visited, time on site, scroll depth, and referring URL — collected via Google Analytics through Google Tag Manager.
  • Ecommerce events (product views, add-to-bag, checkout steps, purchase) — collected via our GTM data layer and shared with Google Analytics and, where active, advertising platforms including Meta (Facebook/Instagram).
  • Cookies and similar tracking technologies — see the Cookies & Tracking section below.
  • Purchase history and on-site browsing behaviour, used to personalise product recommendations and Klaviyo flows.

How We Use Your Information

We process your personal information only for specific, lawful purposes. The table below sets out each processing activity and the basis under which we conduct it under the Australian Privacy Principles.

Processing ActivityLegal Basis (APP)
Processing and fulfilling your order, including payment, shipping, and delivery notificationsPerformance of contract
Responding to your enquiries and support requestsPerformance of contract / Legitimate interest
Sending transactional communications (order confirmation, shipping updates, back-in-stock notifications)Performance of contract
Sending email and SMS marketing where you have opted inConsent (may be withdrawn at any time)
Personalising product recommendations based on purchase history, wishlist, and quiz responsesLegitimate interest / Consent (for quiz)
Operating our ecommerce platform and maintaining your accountPerformance of contract
Detecting and preventing fraud and maintaining platform securityLegitimate interest / Legal obligation
Analytics to improve our website, products, and customer experienceLegitimate interest
Advertising and remarketing on platforms including Meta (Facebook/Instagram)Consent (via cookie preference)
Complying with our legal obligations (tax, consumer law, regulatory requirements)Legal obligation

We do not use your personal information for automated decision-making that produces a legal or similarly significant effect on you.

Third-Party Service Providers

We share personal information only with the service providers necessary to operate our business. Each provider is bound by a data processing agreement and may only use your data for the specific purpose for which it was disclosed.

Ecommerce Platform

  • Shopify Inc. (Canada/USA) — Our ecommerce platform. Shopify stores and processes customer names, addresses, email addresses, phone numbers, order history, and payment tokenisation data on servers located in the United States and Canada. Shopify is certified PCI-DSS Level 1.

Payment Processing

  • Stripe Inc. (USA) — Processes payment card transactions. Stripe is PCI-DSS Level 1 certified. Card details are tokenised and never stored by Bush & Salt.
  • Shopify Payments (powered by Stripe) — Where Shopify Payments is selected at checkout, the same Stripe infrastructure applies.

Email & SMS Marketing

  • Klaviyo Inc. (USA) — Manages our email and SMS marketing communications, transactional notifications, back-in-stock alerts, and automated flows. Klaviyo receives your email address, name, purchase history, on-site behavioural data, and marketing preference status.

Analytics & Tag Management

  • Google LLC (USA) — Google Analytics, accessed and managed via Google Tag Manager (GTM). Data is anonymised before processing where possible. IP anonymisation is enabled.

Advertising

  • Meta Platforms Inc. (USA) — Where the Meta Pixel is active on our site, Meta collects behavioural and ecommerce event data to measure advertising campaign performance and to enable retargeting on Facebook and Instagram. This is governed by your cookie consent preferences.

Shipping & Fulfilment

  • Australia Post, Sendle, and comparable carriers (Australia) — Receive your name, delivery address, and contact details to fulfil and track your order.

Reviews

  • Judge.me / Okendo (USA) — When active, our reviews platform receives your name, email address, and order details to solicit, collect, and display product reviews.

We do not authorise any third-party service provider to use your personal information for their own marketing or commercial purposes beyond what is described above.

Cookies & Tracking

Our website uses cookies and similar tracking technologies including pixels and local storage. These are used to operate the site, understand how it is used, and, with your consent, to serve relevant advertising.

Essential Cookies

Required for the website to function. These include your shopping bag state, session authentication, and security tokens. They cannot be disabled without breaking core site functionality. No consent is required for these cookies.

Analytics Cookies

Set by Google Analytics (via Google Tag Manager) to understand traffic patterns, page performance, and user behaviour. Data collected includes pages visited, session duration, device type, and general location (country/region level). IP anonymisation is enabled.

Marketing & Advertising Cookies

Where you have given consent, advertising cookies are placed by third parties including Meta (Facebook/Instagram). These enable us to measure the performance of advertising campaigns and to show you relevant Bush & Salt content when you visit other platforms. You may withdraw consent at any time via our cookie preference centre or your browser settings.

Google Tag Manager

We use Google Tag Manager to deploy and manage tracking tags on our website without modifying site code for each change. GTM itself does not collect personal information, but it manages tags that do — including Google Analytics and advertising pixels.

Cross-Border Transfers

Some of our service providers are located outside Australia, including in the United States and Canada. When your personal information is transferred internationally, it is subject to the laws of that country. We take steps to ensure that overseas recipients handle your information in a manner consistent with the Australian Privacy Principles.

The key jurisdictions to which your data may be transferred include: the United States (Shopify, Stripe, Klaviyo, Google, Meta) and Canada (Shopify). Each of these providers operates under privacy frameworks that include equivalent protections to those applicable in Australia.

Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Specifically:

  • Order data (name, address, order history) is retained for a minimum of 7 years to comply with Australian tax and consumer law requirements.
  • Marketing data (email subscriptions, communication preferences) is retained until you unsubscribe or request deletion.
  • Account data is retained while your account is active and for a reasonable period after account closure to allow for returns and dispute resolution.
  • Analytics data is retained in accordance with Google Analytics default settings (14 months).
  • Quiz response data is retained for up to 12 months for personalisation purposes, after which it is anonymised or deleted.

Your Rights

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of information that is inaccurate, out of date, or incomplete.
  • Request deletion of your information (subject to our legal retention obligations).
  • Opt out of direct marketing communications at any time via the unsubscribe link in any marketing email, or by contacting us directly.
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have handled your information improperly.

To exercise any of these rights, please contact us at privacy@bushandsalt.com.au. We will respond within 30 days. We may need to verify your identity before processing your request.

Marketing Communications

We send marketing emails and SMS messages only with your explicit consent. You may withdraw consent at any time by:

  • Clicking the unsubscribe link in any marketing email.
  • Replying STOP to any marketing SMS.
  • Contacting us at cs@bushandsalt.com.au.
  • Managing your preferences via your account settings (if you have an account).

Transactional emails (order confirmations, shipping updates, back-in-stock notifications) are not marketing emails and cannot be unsubscribed from while you are an active customer.

Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, and destruction. These measures include:

  • SSL/TLS encryption for all data transmitted to and from our website.
  • PCI-DSS compliant payment processing via Shopify Payments and Stripe.
  • Access controls limiting employee access to personal information to those with a business need.
  • Regular security assessments and updates.

No method of transmission over the internet or electronic storage is 100% secure. While we take all reasonable precautions, we cannot guarantee absolute security.

Our website may contain links to third-party websites. These links are provided for your convenience and do not constitute an endorsement of those sites. We have no control over the privacy practices of third-party websites and are not responsible for their content or privacy policies. We encourage you to read the privacy policies of any third-party sites you visit.

Children's Privacy

Our website and products are not directed at children under 16 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at privacy@bushandsalt.com.au and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify active customers by email. Your continued use of our website after any changes constitutes your acceptance of the updated policy.

Contact Us

For any questions, requests, or complaints regarding this Privacy Policy, please contact:

Bush & Salt Pty Ltd
Privacy Officer
Email: privacy@bushandsalt.com.au
Postal: M Centre, 11 Palmerston Lane Suite #1029, Manuka ACT 2603, Australia

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.