What we collect
When you buy something
- Name, email address, delivery address, phone number if you give one
- What you ordered, and what you paid
- Payment confirmation — never your card number, which goes directly to Shopify Payments and is never visible to us
When you join the members programme
- Your email address and first name, held in your Shopify customer account
- Your star balance, lifetime total, cards completed, and the IDs of orders that earned stars
- Whether we have sent you an expiry reminder, so you do not get the same one twice
There is no password. Signing in sends a six-digit code to your email.
Automatically
- Standard web server logs kept by our host, IP address, browser, pages requested, timestamps
- Advertising measurement. We run the Meta (Facebook and Instagram) pixel so we can tell which of our ads actually lead to a sale. It records the pages you view here, boxes you add to the cart, and the point you start checkout. See Advertising measurement below for exactly what is sent and how to stop it.
- Nothing else. No session recording, no heatmaps, no data brokers, and no other third-party tracker.
Not to advertisers, not to data brokers, not to anyone. There is no scenario in which your details are a product we trade.
Why we collect it
- To send you what you bought. The address is the whole point.
- To tell you what is happening — order confirmation, dispatch and tracking.
- To run the members programme, if you opted into it.
- To meet our legal obligations. Australian tax law requires sales records be kept for five years.
- To handle problems — refunds, lost parcels, disputes.
We only send marketing email if you have asked for it, and every one has a one-click unsubscribe. Transactional email about an order you actually placed is not marketing and is not optional.
Who else sees it
Only these, only for the stated job:
| Who | What they get | What for |
|---|---|---|
| Shopify | Order, account and payment details | Store platform, checkout and payment processing |
| Netlify | Request logs, session cookie | Hosting this site and the members backend |
| Resend | Your email address and message content | Sending members emails and reward codes |
| Australia Post | Name, delivery address, phone | Delivering the parcel |
| Meta | A one-way hashed form of your email, phone and name, plus the order value and what you bought | Measuring which of our ads led to a sale |
| Google Fonts | Your IP address | Serving the site's typefaces |
Some of these store data outside Australia: Shopify, Netlify, Resend and Google all operate overseas infrastructure, principally in the United States. By ordering, you consent to that transfer. Each is a substantial provider with its own published privacy commitments.
We will also disclose information if the law compels it: a court order, a regulator, or a legitimate law-enforcement request.
Advertising measurement
We advertise on Facebook and Instagram. To know whether that money is doing anything, we have to be able to connect an ad you saw to a box you bought. That is the only reason any of the following happens.
What is sent. When you browse the shop, the Meta pixel reports the page, the sets you look at, what you add to the cart and when you start checkout. When an order is paid, our server sends Meta the order total, the items, and your email, phone and name hashed first, which means converted to an irreversible string of characters. Meta compares that string against the one it already holds for your account. We never send your email address, phone number or name to Meta in readable form.
What we get back. Counts and totals. Which ad produced how many sales. We cannot see your Facebook or Instagram profile, your friends, or anything you do off this site.
How to stop it. Any of these works, and none of them affects your ability to order:
- Use an ad or tracker blocker. We deliberately do not detect or nag about them, and the site is built to work normally when the pixel fails to load.
- Turn off Activity off Meta technologies in your Facebook or Instagram settings, which cuts the link on Meta's side.
- Email us and we will exclude your customer record from the server-side reporting.
Nothing here puts you on a marketing list, and nothing here is sold. It answers one question for us: did the ad work.
Cookies and local storage
Three of the entries below are advertising cookies, described in full above. Everything else here exists to keep you signed in or to remember a preference. We do not run a consent banner, because Australian law does not require one and we would rather tell you plainly on this page than train you to click Accept.
| Name | Type | Purpose | Life |
|---|---|---|---|
| hikari_session | Cookie | Keeps you signed in. Holds a signed customer ID, nothing else. | 90 days |
| hikari_login | Cookie | Guards the sign-in handshake against forgery. Deleted the moment login finishes. | 10 minutes |
| hikari-theme | Local storage | Remembers light or dark mode | Until cleared |
| hikari-view | Local storage | Remembers your grid density choice | Until cleared |
| hikari-intro | Session storage | Stops the intro animation replaying on every page view | Until tab closed |
| hikari-goldlock | Session storage | Remembers you have opened the vault | Until tab closed |
| _fbp | Cookie | Set by the Meta pixel. A random ID for this browser, so a sale can be matched to an ad. Holds nothing about you personally. | 90 days |
| _fbc | Cookie | Set only if you arrived by clicking one of our ads. Stores that click's ID. | 90 days |
| wpr-fbc | Local storage | Our copy of the above, because Safari deletes the cookie after 7 days and a pre-order can outlive that. | Until cleared |
The two cookies are HttpOnly, Secure and SameSite=Lax — unreadable to JavaScript, sent only over HTTPS. Shopify sets its own cookies during checkout; those are covered by Shopify's privacy policy.
Our own storage entries never leave your browser and are not sent to us. The _fbp, _fbc and wpr-fbc entries are the exception: they are the advertising IDs described above, and they are the one thing here you may want to clear.
How long we keep it
- Order and tax records: 5 years from the transaction, as Australian tax law requires.
- Member accounts: until you ask us to delete them.
- Star balances: stars themselves expire 12 months after your last qualifying purchase.
- Server logs: kept short-term by our host for security and debugging.
- Advertising measurement: held by Meta under their own retention rules. We keep no separate copy.
- Marketing lists: removed as soon as you unsubscribe.
Your rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles you may:
- Ask what we hold about you, and get a copy
- Correct anything wrong
- Delete your account and personal details, except order records we are legally required to retain
- Unsubscribe from marketing at any time
- Complain if you think we have mishandled your information
Email contact@wooprtcg.com.au. We respond within 30 days, and usually within one day. There is no charge.
If our answer does not satisfy you, complain to the Office of the Australian Information Commissioner.
Security
- The whole site is served over HTTPS.
- Card details never touch our systems, Shopify Payments handles them end to end.
- Member sign-in has no password to steal or reuse.
- Session cookies are cryptographically signed; a tampered one is rejected.
- Access to the store admin is limited to the owner.
No system is perfectly secure. If a breach ever occurs that is likely to cause you serious harm, we will notify you and the OAIC as the Notifiable Data Breaches scheme requires.
WOOPR, a trading name of ABN 40 319 255 624 · Sydney, NSW
contact@wooprtcg.com.au