Version 1.1 — 23 September 2026
This Privacy Policy explains how Thomas James Murphy trading as Sharpened (ABN 29 739 540 545) (Sharpened, we, us) handles personal information across the Sharpened website (sharpened.com.au), the merchant admin application, and the storefronts we host for butcher shops and other retailers. It also describes the cookies we use (section 9).
We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth), whether or not the Act requires us to.
Privacy contact: privacy@sharpened.com.au
Address: Unit 1, 296 New Street, Brighton VIC 3186
1. Who you are matters
| If you are | Your relationship with us |
|---|---|
| A visitor browsing sharpened.com.au | We collect and hold your information directly. |
| A merchant (a shop using our software) | We collect and hold your business and account information directly. |
| A shopper ordering from a shop's storefront | The shop collects your information for its business. We hold and process it as the shop's service provider. The shop is responsible for how it uses your information; we are responsible for keeping it secure and handling it only as the shop instructs and this policy describes. |
If you are a shopper with a question about your order or how a shop uses your details, contact the shop first. For questions about how Sharpened hosts and protects the platform, contact us.
2. What we collect
Visitors. Contact details you submit through forms (name, email, phone, business name, message) and technical data (IP address, browser and device type, pages viewed, approximate location derived from IP).
Merchants. Business name, ABN, address, contact names, email addresses and phone numbers; admin user logins; billing details and payment status for our Fees; payment provider account identifiers you connect (never your provider login credentials in plain text); configuration and content you upload; and usage and technical data about how admin is used.
Shoppers. Name, email address, phone number, order contents, special instructions, pickup slot, deposit and balance status, and communications with the shop through the platform. Payment information is described in section 4.
Everyone. Server logs and error reports, which may include IP address, browser details, the page or action in progress, and account identifiers.
We collect information you give us, information generated when you use the platform, and information sent to us by your payment provider about the status of a payment. We do not buy personal information from third parties.
3. Why we collect it
To provide and operate the platform; to process and display orders; to communicate with merchants about their account, billing, support and service changes; to keep the platform secure, detect fraud and abuse, and debug faults; to comply with legal obligations; and, for visitors and merchants only, to tell you about Sharpened where the law allows.
We never use shopper information for Sharpened's own marketing. Shoppers receive communications from the shop they ordered from, not from us.
4. Payments
Shopper payments for goods are processed by the shop's own payment provider (for example Stripe). Card details are entered on the provider's hosted payment page or secure fields, not on our servers. Sharpened takes no cut of shopper payments and is not the merchant of record.
We store payment references and status returned by the provider (transaction and session identifiers, amount, currency, outcome, and any decline reason) so that deposits, balances and refunds can be shown correctly. We also store the card brand and the last four digits of the card, as returned by the provider, so that you and the shop can identify which card was used. We never receive or store full card numbers, expiry dates, CVV codes or provider login credentials.
Fees paid to Sharpened by merchants are processed by bank transfer or through our billing provider, Stripe.
5. Who we share it with
We do not sell personal information. We disclose it only to:
- The shop you ordered from (shoppers), so it can fulfil your order.
- Service providers that host and operate the platform on our behalf, listed in section 6.
- Payment providers connected by the shop (shoppers) or used for our billing (merchants).
- Analytics and advertising providers that a shop chooses to add to its own storefront (Google Analytics, Meta Pixel), as described in section 9. The shop controls this.
- Professional advisers, and regulators or law enforcement where required by law.
- A successor if we sell or restructure the business, on the same terms as this policy. Merchants will be notified.
6. Where your information is held
The platform's servers and primary database are hosted in Australia (Northflank, Australia south-east region). Our current service providers are:
| Provider | Purpose | Location |
|---|---|---|
| Northflank | Application hosting and database | Australia |
| Cloudflare | DNS, content delivery, network security, file storage (R2) | Australia / Oceania region, with global edge network |
| Amazon Web Services | Transactional email (SES) and encryption key management (KMS) | Australia / Oceania region |
| Sentry | Error monitoring | United States |
| Axiom | Application logs | United States |
| Stripe | Billing of Sharpened Fees to merchants | Australia / United States |
Error reports and logs sent to Sentry and Axiom may include technical data and account identifiers, and occasionally personal information present in the request that failed. We configure these tools to minimise personal information and retain logs for a limited period (section 8). By disclosing information to these providers we take reasonable steps, including contractual protections, to ensure it is handled in a way consistent with the Australian Privacy Principles. We will update this table when providers change; merchants receive notice under the Data Processing Schedule.
7. Security
All state is stored in managed databases and storage with access controls. Each shop's data is isolated at the database level. Traffic is encrypted in transit. Payment provider credentials are encrypted at rest with AWS KMS, and each encrypted credential is bound to its shop. Access to production systems is restricted and logged. No system is perfectly secure; if we become aware of a data breach likely to result in serious harm, we will notify affected merchants promptly and comply with the Notifiable Data Breaches scheme.
8. How long we keep it
| Information | Retention |
|---|---|
| Shopper order data | For as long as the shop's account is active. Shops can ask us to delete shopper data from past campaigns at any time. After a shop leaves, we delete its shopper data within 90 days after the 30-day export window. |
| Merchant account and configuration | For the life of the account, then deleted within 90 days after the export window. |
| Visitor enquiries | Up to 2 years after the last contact. |
| Server logs and error reports | Up to 90 days. |
| Database backups | Roll off automatically within approximately 35 days. |
| Invoices and tax records | 7 years, as required by law. |
9. Cookies
Cookies are small text files stored on your device by your browser. Similar technologies include local storage and tracking pixels.
What Sharpened sets. Only strictly necessary cookies and storage, on the website, admin and storefronts alike. We do not set analytics, advertising or session-replay cookies, and no session-recording tool is used anywhere on the platform. Because these cookies are necessary for the platform to work, we do not ask for consent to set them and there is no consent banner. Blocking them in your browser will stop login and checkout from working.
| Name | Purpose | Surface | Lifetime |
|---|---|---|---|
| Session cookies | Keep you signed in to admin, or to a storefront after you sign in with an email link, and protect the session | Admin, storefront | Admin: 7 days. Storefront: 90 days. Each visit extends the session. |
| Cart | Remembers the items in your cart on a storefront | Storefront | Until you place the order, or 14 days after your last change to the cart |
Cloudflare security cookies (for example __cf_bm) | Bot protection and network security, set by our content delivery provider | All | Up to 30 minutes |
Error monitoring and logs. We use Sentry (error monitoring) and Axiom (server logs) to keep the platform reliable. They operate on our servers and in the page's error handler; they do not set tracking cookies or record your session.
Analytics and advertising tools added by a shop. A shop may choose to add Google Analytics, a Meta Pixel, or both to its own storefront. Where a shop adds Google Analytics, Google sets cookies (for example _ga, _ga_*) on that storefront under Google's privacy policy (policies.google.com/privacy). Where a shop adds a Meta Pixel, Meta sets cookies (for example _fbp) and receives data about your visit and your actions on that storefront, which Meta can use for advertising, under Meta's privacy policy (facebook.com/privacy/policy). The shop, not Sharpened, decides whether to use these tools and is responsible for its own notices about them. Shops cannot add other third-party tags in the current version of the platform. You can opt out of Google Analytics across all sites with Google's browser add-on (tools.google.com/dlpage/gaoptout). You can control how Meta uses this data for advertising in your Meta account settings and by blocking third-party cookies in your browser.
Marketing cookies. Sharpened does not use marketing or advertising cookies or pixels on the website, in admin, or on storefronts by default. A shop can add a Meta Pixel to its own storefront, as described above.
Future changes. If we introduce product experimentation (A/B testing) or first-party analytics, we will update this section before doing so and describe the cookies involved.
10. Access, correction and complaints
You can ask us for access to, or correction of, the personal information we hold about you by emailing privacy@sharpened.com.au. We will respond within 30 days. Shoppers may also contact the shop directly, which can update your details in admin.
If you have a complaint about how we have handled your information, email us and we will investigate and respond within 30 days. If you are not satisfied you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
11. Marketing to merchants and visitors
We may email merchants and visitors who have enquired about Sharpened, in accordance with the Spam Act 2003 (Cth). Every marketing email includes an unsubscribe link, and you can opt out at any time by emailing support@sharpened.com.au. Account, billing and service emails are not marketing and cannot be unsubscribed from while you hold an account.
12. Children
The platform is for businesses and adult purchasers. Shoppers must be 18 or older. We do not knowingly collect personal information from children.
13. Changes
We may update this policy from time to time. The version date above will change. Merchants receive email notice of material changes; shoppers and visitors will see the updated policy on the site or storefront.
14. Contact
Privacy: privacy@sharpened.com.au
Support: support@sharpened.com.au
Postal: Unit 1, 296 New Street, Brighton VIC 3186