Privacy
How Flex Branding collects, uses and protects personal information.
Flex Branding Pty Ltd (ABN 64 632 194 971) ("Flex Branding", "we", "us") is a branded merchandise business based in Melbourne, Victoria, working Australia-wide. This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It covers flexbranding.com.au, our quoting and approval tools, and the online order portals we run for client organisations.
We do not collect payment card details. Invoicing and payment run through our accounting provider, Xero. We do not knowingly collect information from anyone under 18, and we do not collect sensitive information such as health or biometric data.
Mostly directly from you: when you fill in a form, email us, approve something online, or use a portal. Sometimes from your employer or colleague, for example when a client sets up a portal and adds staff to it. Sometimes from public sources, for example a business's own website or Google listing when we are looking for businesses we could help.
We use AI tools (from Anthropic) to help read enquiry emails and draft replies. A person reviews and sends anything that goes out. These tools do not make decisions about you.
We follow the Spam Act 2003. We may send product ideas and offers to existing customers, to people who have opted in, and to businesses whose contact details are publicly listed where what we offer relates to their business. Every marketing email says who it is from and tells you how to opt out. You can stop them at any time by using the unsubscribe option in the email, replying "unsubscribe", or contacting us. We act on opt-outs within five business days and keep a record of your choice.
Only as needed to do the things above:
We never sell personal information or share it for someone else's marketing.
Some of our providers store or process information outside Australia. In each case we choose reputable providers and require them to protect your information and use it only to provide their service to us.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database for quotes, orders, approvals and portals | Japan (Tokyo) |
| Cloudflare | Hosting, security and spam protection for our websites | Australia and worldwide (United States company) |
| Microsoft 365 | Email and documents | Australia and United States |
| Xero | Invoicing and accounts | United States |
| Resend | Sending order and approval emails | United States |
| Anthropic | AI assistance with reading and drafting emails | United States |
| Apify and Google | Looking up publicly listed business details; website fonts | United States and Europe |
We do not use advertising, social media or analytics cookies, so we do not show a cookie banner. Our sites use only what is strictly necessary: Cloudflare may set a security cookie to protect our forms from spam, and our portals and approval pages store a sign-in token and your cart in your browser so they work. Our pages load the Inter font from Google, which means Google receives your IP address when the page loads. You can block cookies and site data in your browser settings; sign-in features will not work without them.
When we run a merchandise portal or sizing form for your employer, we handle staff details on that organisation's behalf and instructions. Each portal is separate from every other client's. Staff accounts can be added and removed by the organisation's administrators, and we delete portal data when the organisation asks us to or when the portal is closed. Your employer's own privacy policy may also apply to how they use that information.
We protect personal information with encryption in transit, access controls that limit each user to their own organisation's data, multi-factor authentication for our staff, and hosting with providers that meet recognised security standards. No system is perfectly secure, so we keep the information we hold to what we need.
We keep quote, order and invoice records for at least seven years to meet tax and company record-keeping rules. Enquiries that do not become orders, and portal accounts that are closed, are deleted or de-identified once they are no longer needed.
If personal information we hold is lost or accessed without authorisation and that is likely to cause serious harm, we will tell the people affected and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email hello@flexbranding.com.au and we will respond within 30 days. We may need to keep some records where the law requires it, and we will tell you if so.
If you are unhappy with how we have handled your information, contact us first using the details below and we will look into it and reply within 30 days. If you are not satisfied with our response you can complain to the OAIC at oaic.gov.au or on 1300 363 992.
We do not use computer programs to make decisions that significantly affect people's rights or interests. If that changes we will update this policy to say what information is used and what decisions are made.
We update this policy when our practices change. The current version is always at flexbranding.com.au/privacy/.
Privacy Officer, Flex Branding Pty Ltd
ABN 64 632 194 971
Melbourne, Victoria, Australia
Email: hello@flexbranding.com.au
Phone: (03) 8804 1799
Last updated: 9 September 2026.