Platinum Signage Pty Ltd (ABN 27 609 002 815) trading as Platinum Signs (“we”, “us”) takes your privacy seriously. This Policy explains what personal information we collect, how we use it, who we share it with, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. What we collect
We only collect information we need to quote, make, ship and support your signage orders, including:
- Identity & contact: name, company, ABN, email, phone, delivery and billing addresses.
- Order & artwork: quote details, product specifications, files you upload, proof approvals, order history.
- Payment: we do not store full card numbers. Payment is processed by Stripe, which handles card data under PCI-DSS. We store Stripe payment and checkout references needed to reconcile the order.
- Account: login credentials (passwords are hashed by Supabase — we never see or store them in plain text), notification preferences, consent records.
- Website use: IP address, browser/device info, pages viewed, referrer, basic analytics. See our Cookie & Tracking Notice.
- Support & communications: emails, chat messages and call notes with our team.
2. How we collect it
Directly from you (when you request a quote, place an order, create an account, upload artwork, contact us), automatically from your device (cookies, analytics), and in limited cases from third parties (e.g. a credit-reference check for trade-account applications, with your consent).
3. Why we use it
- To quote, produce, proof, invoice, ship and install your signage.
- To operate your account, process payments, and keep records required by tax and consumer law.
- To respond to enquiries and provide customer support.
- To improve our website, products and services (aggregated analytics).
- To send transactional emails (order updates, proofs, invoices) — you cannot opt out of these while your order is active.
- To send news and special offers by email — only where your account is set to receive them. You can opt out at any time using the unsubscribe link or in your account settings.
- To meet our legal obligations and protect our legal rights.
4. Who we share it with
We share the minimum information necessary with trusted service providers to deliver your order:
- Stripe — payment processing.
- Supabase — database, authentication and file storage (hosted in AWS Sydney,
ap-southeast-2). - Resend — transactional and marketing email delivery.
- Xero — accounting & invoicing.
- Google Workspace — authorised email and calendar workflows used to service enquiries and installations.
- Trello and Pipedrive — internal production workflow and customer relationship management.
- OpenAI and Anthropic — staff-assisted analysis of selected quote, email, invoice or artwork information. Staff remain responsible for the resulting business decision and should send only information needed for the task.
- Google Analytics, Google Tag Manager and CallRail — website and enquiry attribution where enabled and permitted by your cookie choices.
- Go Logistics, Transdirect and other couriers — to deliver your order.
- Sentry — error monitoring.
- Vercel — website hosting (global CDN).
- Installers and contractors engaged to fit your signage at site.
- Law-enforcement or regulators when legally required.
We do not sell your personal information to third parties. We do not share your information for third-party marketing without your consent.
5. Overseas storage
Our primary Supabase customer, order, authentication and file data is hosted in Australia (Sydney). Other service providers (including Stripe, Sentry, Resend, Vercel, Google, OpenAI, Anthropic, Trello and Pipedrive) may process data in Australia, the United States, Europe or other regions. Where overseas processing occurs, we rely on contractual protections that require standards substantially similar to the APPs.
6. How long we keep it
We keep records for as long as we need them for the purpose they were collected, and then for the period required by Australian tax and consumer law (typically 7 years for financial records). Consent audit trails are kept for the life of your account plus 7 years.
7. Security
We use industry-standard safeguards including TLS for data in transit, encrypted storage, access controls, password hashing, Stripe’s PCI-DSS payment vault, and restricted admin access. No system is perfectly secure — if a notifiable data breach occurs we will tell you and the OAIC in line with the Notifiable Data Breaches scheme.
8. Your rights
- Access: you can ask for a copy of the personal information we hold about you.
- Correct: you can ask us to correct anything that’s wrong or out of date.
- Delete: you can ask us to delete your account and personal information, subject to records we must keep by law (e.g. invoices).
- Opt out of marketing: use the unsubscribe link in any marketing email, or change your notification preferences in your account.
- Complain: email info@platinumsigns.com.au. If you’re not satisfied with our response you can contact the Office of the Australian Information Commissioner (OAIC).
9. Children
Our website is aimed at businesses and adults. We don’t knowingly collect personal information from children under 16. If you believe we have, contact us and we’ll delete it.
10. Changes
We may update this Policy from time to time. The current version is shown at the top of this page. Material changes will be notified via email or a website banner.
11. Contact
For privacy questions or requests, email info@platinumsigns.com.au or write to: Privacy Officer, Platinum Signage Pty Ltd, Unit 4, 7 Erith Street, Botany NSW 2019.