045 Legal Privacy

Privacy policy

Zero Four Five does not have a privacy policy yet. This page is the structure one will be written into. Every section below describes what has to be written and checked — none of it is a statement about how data is handled today.

This is a scaffold, not a policy. It was prepared alongside the site so the structure exists and the gaps are visible. It contains no policy text. No lawyer has read it. It must not be published, linked from a Shopify App Store listing, or relied on by a merchant or a customer until it has been written in full and reviewed.

The finished document will have to satisfy the Australian Privacy Principles under the Privacy Act 1988 (Cth), and Shopify’s own requirements for apps that handle merchant and customer data. Nothing on this page claims that it does. To draft

Who we are

Names the legal entity that operates Zero Four Five and its apps, its ABN, and the country it operates from. To draft

None of those details are confirmed, so none are written here. Naming an entity that turns out to be the wrong one is worse than naming none.

What we collect

Lists, category by category, the personal information that is collected. To draft

Four sources have to be separated rather than merged into one sentence: what a merchant supplies when they install an app, what an app receives from a store while it runs, what this website records, and what arrives by email. Each category has to be described in terms a merchant can check against their own store.

How we use it

States a purpose for each category listed above. To draft

The likely purposes are running the app a merchant installed, answering support requests, keeping the service working, and meeting legal obligations. The drafting rule for this section is simple: if a use is not named here, it does not belong in the product either.

Where it goes

Names every third party and sub-processor that receives data, and what each one receives. To draft

Hosting, model providers, email, error reporting, analytics, payments. Each entry needs a named provider, the data it sees, and the country it processes in. Disclosures required by law belong here too. The stack is not settled, so the list cannot be written yet.

How long we keep it

Sets a retention period for each category, and describes what happens when a merchant uninstalls an app. To draft

Shopify’s app requirements cover mandatory data deletion requests. This section has to describe what actually happens when one arrives — once that path is built, tested and observed, not before.

Where it is stored

States the regions data is stored and processed in, and names any transfer out of Australia along with the safeguard applied to it. To draft

Hosting regions are not fixed. This section gets written after they are.

Your rights

Sets out how a person asks for access to their information, asks for a correction, asks for deletion, and makes a complaint. To draft

Each route needs three things attached: who the request goes to, how long a response takes, and how to escalate to the Office of the Australian Information Commissioner. A right described without a working route to exercise it is not a right, so the route has to exist before the words go in.

Cookies and tracking

Lists what this site and the apps set in a browser, what each item is for, how long it lasts, and how it can be refused. To draft

Whatever is set at the point of publication has to be audited and listed here. Nothing should be assumed from how the site is built today, because the build can change between now and the day this page goes live.

Data from our apps

Draws the line that matters most to a merchant: what a store’s data is used for, and what it is never used for. To draft

The questions this section has to answer, in plain words, are these. Does a store’s data serve only that store? Is it used to train models? Is it pooled with other merchants’ data? Is it sold, or shared for advertising? Each answer has to be a plain yes or no with nothing hedged around it.

The answers are absent here on purpose. They are commitments, and a commitment goes in only once it is true of the product as built and has been reviewed.

Changes to this policy

Describes how a change is made, how merchants are told about it, and where earlier versions can be read. To draft

A version number and a date on every revision is the minimum this section needs.

How to contact us

Gives a working route for privacy questions, access requests and complaints — an address, a person who owns it, and a response time. To draft

The address carried on the rest of the site is info@zerofourfive.com.au.

Last updated Not yet published