Version 1.1 — 23 September 2026
This Schedule forms part of the Merchant Agreement between the Merchant and Thomas James Murphy trading as Sharpened (ABN 29 739 540 545) (Sharpened). It sets out how Sharpened handles personal information about the Merchant's customers (Shopper Data) on the Merchant's behalf. On the handling of Shopper Data, this Schedule prevails over the Privacy Policy and the general terms of the Merchant Agreement.
1. Roles
1.1 The Merchant collects Shopper Data for its own business and is the primary holder of it. Sharpened holds and processes Shopper Data as the Merchant's service provider, only to provide the Services and as this Schedule permits.
1.2 Each party complies with the Privacy Act 1988 (Cth) to the extent it applies to that party. Sharpened handles Shopper Data in accordance with the Australian Privacy Principles regardless of whether the Act requires it to.
2. What Sharpened processes
| Data | Examples | Held by |
|---|---|---|
| Shopper identity and contact | Name, email, phone | Sharpened, for the Merchant |
| Order data | Items, weights, special instructions, pickup slot, deposit and balance status, order history | Sharpened, for the Merchant |
| Payment references | Provider transaction and session IDs, amounts, outcome, decline reason; card brand and last four digits as returned by the provider. Never full card numbers, expiry dates or CVV. | Sharpened, for the Merchant |
| Communications | Order confirmations and notifications sent through the platform | Sharpened, for the Merchant |
| Technical | IP address, browser details, logs and error reports | Sharpened |
| Merchant account and billing | Business details, admin users, invoices | Sharpened, for itself |
3. Sharpened's obligations
Sharpened will:
3.1 process Shopper Data only to provide, secure, support and improve the Services, to comply with law, or as the Merchant instructs through admin or in writing;
3.2 not use Shopper Data for Sharpened's own marketing, and not sell or disclose it except as this Schedule permits;
3.3 keep Shopper Data isolated from other merchants' data at the database level;
3.4 protect Shopper Data with reasonable technical and organisational measures, including encryption in transit, access controls, encrypted storage of credentials, and restricted and logged production access;
3.5 ensure personnel and sub-processors with access to Shopper Data are bound by confidentiality and privacy obligations no less protective than this Schedule;
3.6 assist the Merchant, on reasonable request, to respond to shopper access, correction and deletion requests and to privacy complaints; and
3.7 delete or return Shopper Data at the end of the relationship as set out in section 7.
4. Merchant's obligations
The Merchant will:
4.1 give shoppers appropriate notice of how it collects and uses their information, including that Sharpened hosts the storefront;
4.2 ensure its collection and use of Shopper Data is lawful, including compliance with the Spam Act 2003 (Cth) for email and SMS marketing;
4.3 keep admin credentials secure and exported data protected;
4.4 not instruct Sharpened to process Shopper Data unlawfully; and
4.5 be responsible for any third-party tools it enables on its storefront (such as Google Analytics or a Meta Pixel) and for its own privacy notices about them.
5. Sub-processors and location
5.1 Sharpened uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Northflank | Application hosting, primary database, backups | Australia (south-east region) |
| Cloudflare | DNS, CDN, network security, object storage (R2) | Australia / Oceania region; global edge network |
| Amazon Web Services | Transactional email (SES); key management (KMS) | Australia / Oceania region |
| Sentry | Error monitoring | United States |
| Axiom | Application logs | United States |
| Stripe | Billing of Sharpened Fees to the Merchant (Merchant data only) | Australia / United States |
5.2 Shopper Data at rest is held in Australia. Error reports and logs sent to Sentry and Axiom may include technical data, account identifiers, and personal information present in a failed request; Sharpened configures these tools to minimise personal information and retains logs for up to 90 days. Cloudflare's edge network may process traffic outside Australia in transit.
5.3 Where Shopper Data is disclosed to a sub-processor outside Australia, Sharpened takes reasonable steps, including contractual protections, to ensure the recipient handles it consistently with the Australian Privacy Principles (APP 8).
5.4 Sharpened may add or replace sub-processors. Sharpened will give the Merchant at least 14 days' email notice of a new sub-processor that will access Shopper Data. If the Merchant reasonably objects on privacy grounds and the parties cannot resolve the objection, the Merchant may terminate the Merchant Agreement and receive a pro-rata refund of prepaid Fees.
6. Data breaches
6.1 If Sharpened becomes aware of unauthorised access to, or disclosure or loss of, Shopper Data, it will notify the Merchant by email within 72 hours, describe what is known, and take reasonable steps to contain and remediate the breach.
6.2 The parties will cooperate in assessing whether the breach is an eligible data breach under the Notifiable Data Breaches scheme and, if so, agree which party will notify the Office of the Australian Information Commissioner and affected individuals so that only one notification is made. Where the breach occurred in Sharpened's systems, Sharpened will prepare the statement in consultation with the Merchant.
7. Retention, export and deletion
7.1 Sharpened retains Shopper Data for the life of the Merchant's account. The Merchant may ask Sharpened to delete shopper records, or Shopper Data from past campaigns, at any time.
7.2 For 30 days after the Merchant Agreement ends, the Merchant may request an export of its Shopper Data and order history in CSV format from support.
7.3 Sharpened deletes Shopper Data from production systems within 90 days after the export window ends. Backups roll off automatically within approximately 35 days after deletion. Server logs and error reports are retained for up to 90 days. Sharpened may retain invoices and records it is legally required to keep.
8. Audit and information
On reasonable written request, not more than once a year unless there has been a breach, Sharpened will provide information reasonably necessary to demonstrate compliance with this Schedule, subject to confidentiality and security. On-site audits are by agreement only.
9. Contact
Privacy: privacy@sharpened.com.au
Support: support@sharpened.com.au
Postal: Unit 1, 296 New Street, Brighton VIC 3186