Kartable Pty Ltd ACN 679 921 209 ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and store your Personal Information when you use our online (ordering platform) platform called 'Kartable” ("Platform ") available at www.kartable.com.au

Our Platform allows a potential purchaser often referred to as (“you”) Buyer” to obtain products and services from third-party vendors known as a “Trusted Vendors”, often referred to as “Trusted Vendors (our “Service”). “You” is also used to refer to Trusted Vendors. In absence of the words “Trusted Vendor” throughout this Privacy Policy.

In this Privacy Policy:

"Personal Information" means information or an opinion about an individual whose identity is apparent or can reasonably be ascertained from the information or opinion and includes any further Personal Information that we obtain from any continuing contact or when receiving services or by the provision of services and includes Sensitive information.

"Privacy Law" means the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

"Sensitive Information" is Personal Information which includes information or an opinion about an individual’s racial or ethnic origin, political opinion or association, religious or philosophical beliefs, membership of a professional or trade association or trade union, sexual preferences or practices, criminal record, biometric information, genetic information or health information.

By accessing our Platform or using our Service, you agree to the terms of this Privacy Policy.

We encourage you to read this Privacy Policy carefully and to contact us if you have any questions about how your Personal Information is handled.

1. Information We Collect

We collect the following types of information:

1.1. Personal Information

  1. Account Information: When you or a Trusted Vendor register an account, we collect personal details, such as your name, business name, company email address, ABN, company phone number, company address and company website. A valid credit card will be required to be entered by a Trusted Vendor when creating an account, securely managed and processed by Stripe. If a Buyer elects to make a purchase via credit card, it is also securely managed and processed by Stripe (see 1.1.5 below for how credit card details are stored).
  2. In addition, we may request information such as a valid public liability certificate of currency if a service is being provided or other documentation to facilitate the administrative requirements of the Buyer or Trusted Vendor, on behalf of either party. Should a Buyer choose to undertake the process of utilising the Trade account application process, information stored on that document such as a Buyer business bank account and authorised Business representative identification information will be issued via the completed form to the Trusted Vendor/s of selection by the Buyer. This information will be viewable only by the users of the buyer ABN business and the users of the Trusted Vendor ABN business, users.
  3. Kartable will ensure third-party vendors (Trusted Vendors) disclose their management of privacy data, limited to the data they obtain through the transaction of the Kartable platform following an order placement from a Buyer. Trusted Vendors will need to do this when they list a singular or multiple product/s for sale on the platform. In most cases this will be when a Trusted Vendor is setting up their ‘Profile’ on the Kartable platform. Therefore, full disclosure of how a Trusted Vendor manages the privacy of information obtained in order receival will be available prior to the purchase of any item by a Buyer, generally via the product ‘discovery’ section, via a link to the Trusted Vendor website or upon request.
  4. Transaction Data: We collect data related to the transactions you make on our Platform with third-party vendors, including your purchase history.
  5. Payment Details:  Credit card details, transactions, and the security thereof, are securely protected by Stripe (https://stripe.com/au)

1.2 Non-Personal Information

  1. Usage Data: We automatically collect data about your interaction with our Platform, such as IP address, browser type, device information, and browsing behaviour.
  2. Cookies: Our Platform uses cookies to enhance user experience. You can manage your cookie preferences through your browser settings.

2. How We Use Your Information

We use the information we collect for the following purposes:

  1. Provide the Service: To create and manage your account, facilitate the process of transactions, and to provide you with access to products or services supplied by third-party vendors.
  2. Notify changes: To let you know about changes that may affect our Service and to notify you of changes to this Privacy Policy.
  3. Improve User Experience: To enhance the functionality of our platform, personalize content, and provide customer support and obtain feedback.
  4. Marketing and Communication: To send you marketing materials, updates, and promotional offers (subject to your opt-out preferences).
  5. Compliance and Legal Obligations: To comply with Privacy Law and other applicable laws, respond to legal requests, or protect our rights and interests.

3. How We Share Your Personal Information

3.1. We do not sell or rent your Personal Information. We may share only necessary information in the following circumstances:

  1. Third-Party Vendors: We may provide such of your Personal Information to our third-party vendors as is necessary for them to provide their goods or services to you.    
  2. Third-Party Service Providers: We may share your information with trusted third parties who provide services on our behalf, such as buyers requesting details for potential purchasing inquiries.
  3. Business Transfers: If we undergo a merger, acquisition, or sale of assets, your personal data may be transferred as part of the transaction.
  4. Legal Compliance: We may disclose your information when required by law, such as to comply with a subpoena, court order, or other legal process.

4. Data Retention

We will retain your Personal Information for as long as necessary to fulfil the purposes outlined in this Privacy Policy or as required by law. If you close your account, we may retain certain information for legal or operational purposes, such as fraud prevention or record keeping.

5. Security of Your Information

  1. We take reasonable steps to protect the Personal Information we collect from you from unauthorized access, use, or disclosure. This includes Two factor authentication, secured infrastructure, and other measures and controls.
  2. All users within the ABN of a Buyer business or the ABN of a Trusted Vendor business will ensure the safe management of personal information they are privy to throughout the operational nature of Kartable.

6. Notice of Breach of Security

We will notify you, as soon as possible, if a breach in security results in an unauthorized intrusion into our system that materially affects you and will subsequently report the corrective action taken in response to the intrusion. Specifically, we will comply with our obligations under the Privacy Law if a notifiable data breach occurs and will liaise with the Office of the Australian Information Commissioner to manage that breach.

7. Data breach
7.1. If a data breach occurs, we will:

  1. take all reasonable steps to recover or otherwise secure your Personal Information;
  2. limit access to your Personal Information;
  3. minimise the risk of harm; and
  4. take such other steps as we may decide would be prudent for us to take in the circumstances.

7.2. We will also notify you of any breach if we form the view that the breach is likely to result in any serious harm.

8. Your Rights and Choices

8.1. As a user in Australia, you have certain rights regarding your personal data. These rights include:

  1. Access: You can request access to the Personal Information we hold about you.
  2. Correction: You may request that we correct or update your Personal Information if it is inaccurate or incomplete.
  3. Deletion: You may request that we delete your Personal Information, subject to legal or contractual obligations applicable to us. In the event of you wishing for your information to be deleted, once the 'delete information' request is received in writing, via email, to us, the deletion of information will be actioned as a matter of priority.
  4. Opting Out of Marketing: You can opt-out of receiving marketing communications at any time by following the instructions in the communication or contacting us directly.
  5. Data Portability: You can request a copy of your Personal Information in a structured, machine-readable format.

8.2. To exercise your rights, please contact us at the details provided below.

8.3. In some circumstances we may refuse to give you access to Personal Information and in those circumstances, we will explain why. Access may be denied for these reasons:

  1. we reasonably believe that giving the information would pose a serious threat to the life, health or safety of an individual or to public health and safety;
  2. providing access would create an unreasonable impact on the privacy of others;
  3. the request is frivolous or vexatious;
  4. the request relates to existing or anticipated legal proceedings and is not available by the process of discovery;
  5. providing access would prejudice negotiations with the individual making the request by revealing our intention;
  6. access would be unlawful;
  7. denial of access is authorised or required by law;
  8. access would prejudice enforcement related activities of an enforcement body;
  9. access would reveal evaluative information of “a commercially sensitive”, decision making process or information; or
  10. any other reason that is provided for in the Privacy Law.  

9. Cookies and Tracking Technologies

9.1. We use cookies and other tracking technologies to improve your experience on our Platform. Cookies are small data files that are stored on your device when you visit our Platform. You can manage your cookie preferences through your browser settings.

  1. Essential Cookies: These cookies are necessary for the basic functionality of the Platform.
  2. Performance and Analytics Cookies: We use these cookies to analyze how users interact with our Platform to improve the user experience.
  3. Advertising Cookies: We may use these cookies to deliver targeted ads based on your interests.

9.2. You can disable cookies in your browser settings, but please note that this may affect your ability to use certain features of our Platform.

10. Children’s Privacy

Our Service is not intended for children under the age of 16, and we do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information as a matter of priority.

11. Changes to This Privacy Policy
11.1. We may update this Privacy Policy from time to time. Any changes will be posted on our Platform with a “Last Updated” date and will become effective from that date. You accept the terms of our revised Privacy Policy when you engage with us in any manner after those changes have been made.

11.2. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your Personal Information.

12. Linked websites

  1. Our Platform may contain links to websites operated by third parties ("Linked Websites"). Those links are provided for convenience and may not be current. We do not endorse and are not responsible for the content on those Linked Websites.  
  2. Your access to Linked Websites is entirely at your own risk, and we make no representations and gives no warranties about those Linked Websites.
  3. We are not responsible for the content or privacy practices of any Linked Websites and do not control or guarantee the accuracy, relevance, timeliness or completeness of information on any Linked Websites.
  4. We do not make any representations or give any warranties with respect to Linked Websites being free from computer viruses, or non-infringement of third-party intellectual property rights subsisting in any content or material posted on Linked Websites.

13. Resolving Privacy Complaints

13.1. We have put in place an effective mechanism and procedure to resolve privacy complaints.  We will ensure that all complaints are dealt with in a reasonably appropriate timeframe so that any decision (if any decision is required to be made) is made expeditiously and in a manner that does not compromise the integrity or quality of any such decision.

13.2. If you have any concerns or complaints about the way we have collected, used or disclosed and stored your Personal Information, you can tell us by contacting us as specified below.  

13.3. To resolve a complaint, we:

  1. will liaise with you to identify and define the nature and cause of the complaint;
  2. may request that you provide the details of the complaint in writing;
  3. will keep you informed of the likely time within which we will respond to your complaint; and
  4. will inform you of the legislative basis (if any) of our decision in resolving such complaint.

13.4. We will keep a record of the complaint and any action taken in a privacy register.

13.5. Under the Privacy Law you may complain to the Office of the Australian Information Commissioner about the way we handle your Personal Information. The Commissioner can be contacted at:

The Commissioner

GPO Box 5218

Sydney NSW 2001

Phone: 1300 363 992

Email: enquiries@oaic.gov.au

www.oaic.gov.au

14. Contact Us

14.1. If you have any questions or concerns about this Privacy Policy or how we handle your Personal Information, please contact us at: contact@kartable.com.au

14.2. For more information on your privacy rights under Australian law, you can also contact the Office of the Australian Information Commissioner (OAIC).

Company Name: Kartable Pty Ltd

Website: www.kartable.com.au

Contact email details: contact@kartable.com.au

Postal Address: Level 1, 200 Mary Street, BRISBANE QLD 4000