045 Legal Privacy
Privacy policy
Zero Four Five does not have a privacy policy yet. This page is the structure one will be written into. Every section below describes what has to be written and checked — none of it is a statement about how data is handled today.
This is a scaffold, not a policy. It was prepared alongside the site so the structure exists and the gaps are visible. It contains no policy text. No lawyer has read it. It must not be published, linked from a Shopify App Store listing, or relied on by a merchant or a customer until it has been written in full and reviewed.
The finished document will have to satisfy the Australian Privacy Principles under the Privacy Act 1988 (Cth), and Shopify’s own requirements for apps that handle merchant and customer data. Nothing on this page claims that it does. To draft
Who we are
Names the legal entity that operates Zero Four Five and its apps, its ABN, and the country it operates from. To draft
None of those details are confirmed, so none are written here. Naming an entity that turns out to be the wrong one is worse than naming none.
What we collect
Lists, category by category, the personal information that is collected. To draft
Four sources have to be separated rather than merged into one sentence: what a merchant supplies when they install an app, what an app receives from a store while it runs, what this website records, and what arrives by email. Each category has to be described in terms a merchant can check against their own store.
How we use it
States a purpose for each category listed above. To draft
The likely purposes are running the app a merchant installed, answering support requests, keeping the service working, and meeting legal obligations. The drafting rule for this section is simple: if a use is not named here, it does not belong in the product either.
Where it goes
Names every third party and sub-processor that receives data, and what each one receives. To draft
Hosting, model providers, email, error reporting, analytics, payments. Each entry needs a named provider, the data it sees, and the country it processes in. Disclosures required by law belong here too. The stack is not settled, so the list cannot be written yet.
How long we keep it
Sets a retention period for each category, and describes what happens when a merchant uninstalls an app. To draft
Shopify’s app requirements cover mandatory data deletion requests. This section has to describe what actually happens when one arrives — once that path is built, tested and observed, not before.
Where it is stored
States the regions data is stored and processed in, and names any transfer out of Australia along with the safeguard applied to it. To draft
Hosting regions are not fixed. This section gets written after they are.
Your rights
Sets out how a person asks for access to their information, asks for a correction, asks for deletion, and makes a complaint. To draft
Each route needs three things attached: who the request goes to, how long a response takes, and how to escalate to the Office of the Australian Information Commissioner. A right described without a working route to exercise it is not a right, so the route has to exist before the words go in.
Cookies and tracking
Lists what this site and the apps set in a browser, what each item is for, how long it lasts, and how it can be refused. To draft
Whatever is set at the point of publication has to be audited and listed here. Nothing should be assumed from how the site is built today, because the build can change between now and the day this page goes live.
Data from our apps
Draws the line that matters most to a merchant: what a store’s data is used for, and what it is never used for. To draft
The questions this section has to answer, in plain words, are these. Does a store’s data serve only that store? Is it used to train models? Is it pooled with other merchants’ data? Is it sold, or shared for advertising? Each answer has to be a plain yes or no with nothing hedged around it.
The answers are absent here on purpose. They are commitments, and a commitment goes in only once it is true of the product as built and has been reviewed.
Changes to this policy
Describes how a change is made, how merchants are told about it, and where earlier versions can be read. To draft
A version number and a date on every revision is the minimum this section needs.
How to contact us
Gives a working route for privacy questions, access requests and complaints — an address, a person who owns it, and a response time. To draft
The address carried on the rest of the site is info@zerofourfive.com.au.
Last updated Not yet published