Privacy Policy
Last updated: 10 February 2026
1. Introduction
Techbay Computer Specialists ABN [ABN] ("Techbay", "we", "us", or "our") is committed to protecting the privacy of your personal information. This Privacy Policy explains how we collect, hold, use, and disclose your personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Victorian Privacy and Data Protection Act 2014 (Information Privacy Principles, or IPPs).
This policy applies to all personal information collected through our website at www.techbay.net.au, our online shop, in-store interactions, service bookings, and customer support channels.
2. What Personal Information We Collect (APP 3 & IPP 1)
We may collect the following types of personal information:
- Identity information: first name, last name
- Contact information: email address, phone number, postal address
- Account information: encrypted password, marketing preferences
- Order and transaction information: products purchased, order history, payment details (processed securely by Shopify Payments — we do not store card numbers)
- Service booking information: appointment details, device descriptions, service history
- Technical information: IP address, browser type, device information, pages visited, and browsing patterns collected via cookies and Google Analytics
- Chat and support messages: messages sent through our AI customer support chat, stored locally in your browser and on our servers for service delivery
We do not collect sensitive information (such as health information, racial or ethnic origin, or biometric data) unless you voluntarily provide it in the course of describing a service request.
3. How We Collect Personal Information (APP 3 & IPP 1)
We collect personal information:
- Directly from you: when you create an account, place an order, book a service, fill out a contact form, or communicate with us via chat, email, or phone
- Automatically: through cookies, Google Analytics (GA4), and similar technologies when you browse our website (subject to your cookie consent preferences)
- From third parties: we may receive information from Shopify (order and payment data), or payment providers in connection with your transactions
Where practicable, we will collect personal information directly from you. We will not collect personal information by unlawful or unfair means.
4. Purpose of Collection — Why We Collect Your Information (APP 6 & IPP 2)
We collect and use your personal information for the following purposes:
- To create and manage your customer account
- To process and fulfil your orders and service bookings
- To provide customer support and respond to enquiries
- To send marketing communications (only with your explicit consent, and you can opt out at any time)
- To improve our website, products, and services
- To analyse website usage and performance via analytics
- To comply with legal obligations
- To prevent fraud and ensure security
We will not use your personal information for a purpose other than the purpose for which it was collected, unless you consent or the secondary use is permitted under the APPs.
5. Notice of Collection (APP 5 & IPP 1.3)
At or before the time of collection, we will take reasonable steps to notify you of:
- Our identity and contact details
- The purposes for which we are collecting the information
- The entities or types of entities to which we usually disclose information
- How you can access and correct the information
- The consequences if the information is not collected
Collection notices appear on our registration form, booking form, contact form, and chat interface. If you do not provide certain personal information, we may not be able to process your order, create your account, or provide certain services.
6. Disclosure of Personal Information (APP 6 & IPP 2)
We may share your personal information with the following third-party service providers who assist us in operating our business:
- Shopify Inc. — e-commerce platform, order processing, and payment handling
- Google LLC (Google Analytics) — website analytics (with your consent)
- Sentry (Functional Software Inc.) — error monitoring and performance tracking
- Firebase (Google LLC) — customer chat data storage
- Cloudflare Inc. — website security and bot protection
- Vercel Inc. — website hosting
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We require all third-party service providers to handle your information in accordance with this policy and applicable privacy laws.
7. Cross-Border Disclosure (APP 8 & IPP 9)
Some of our third-party service providers are based outside Australia. In particular:
- Shopify stores data in Canada and the United States
- Google (Analytics, Firebase) processes data in the United States
- Sentry processes data in the United States
- Cloudflare operates a global network with servers in multiple countries
- Vercel hosts data in multiple regions including the United States
Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it in accordance with the APPs, including through contractual obligations and assessing the recipient's privacy practices.
8. Direct Marketing (APP 7 & IPP 2)
We will only send you marketing communications (such as promotional emails, deals, and updates) if you have given us your explicit consent, for example by checking the marketing opt-in box during registration.
You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Updating your marketing preferences in your account settings
- Contacting us at privacy@techbaycomputers.com.au
We will process opt-out requests without charge and within a reasonable time.
9. Data Security (APP 11 & IPP 4)
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:
- Encryption: all data transmitted via HTTPS/TLS; passwords are hashed and never stored in plain text
- Secure cookies: authentication tokens are stored in httpOnly cookies that cannot be accessed by client-side scripts
- CSRF protection: all state-changing requests require a valid CSRF token
- Rate limiting: API endpoints are rate-limited to prevent brute force attacks
- Security headers: strict Content Security Policy (CSP), HSTS, and other security headers are applied
- Access controls: payment data is processed directly by Shopify and is never stored on our servers
We will destroy or de-identify personal information when it is no longer needed for the purpose for which it was collected, unless we are required by law to retain it.
10. Cookies and Tracking Technologies
Our website uses the following types of cookies:
- Essential cookies: required for website functionality, including authentication (
shopify_customer_token), CSRF protection (csrf-token), and cart management. These cannot be disabled. - Analytics cookies: Google Analytics (GA4) cookies that help us understand how visitors use our website. These are only set with your consent.
When you first visit our website, you will be presented with a cookie consent banner. You can choose to accept all cookies or only essential cookies. You can change your cookie preferences at any time by clearing your browser's local storage and revisiting the site.
We also use localStorage (browser-based storage) to store your cart ID, chat session data, and cookie consent preferences. This data remains on your device and is not transmitted to our servers unless necessary for functionality.
11. Access and Correction (APP 12 & 13, IPP 6)
You have the right to access the personal information we hold about you and to request corrections if it is inaccurate, incomplete, or out-of-date.
You can exercise these rights by:
- Logging into your account dashboard to view and update your name, phone number, and addresses
- Contacting us at privacy@techbaycomputers.com.au for access to other information we hold
We will respond to access requests within 30 days. In some limited circumstances, we may refuse access in accordance with the APPs (for example, if providing access would unreasonably impact the privacy of others). If we refuse, we will provide you with written reasons.
12. Deletion of Personal Information
You may request the deletion of your personal information. To request account deletion, please contact us at privacy@techbaycomputers.com.au. We will process your request within 30 days, subject to any legal obligations to retain certain records (such as transaction data for tax and consumer law purposes).
13. Anonymity and Pseudonymity (APP 2)
You have the option of not identifying yourself, or using a pseudonym, when dealing with us — unless it is impracticable. For example, you can browse our website and shop without creating an account. However, we will need your identity to process orders, manage your account, or provide repair services.
14. Complaints (APP 1.4)
If you believe we have breached the Australian Privacy Principles or handled your personal information inappropriately, you may lodge a complaint by contacting us:
- Email: privacy@techbaycomputers.com.au
- Mail: Privacy Officer, Techbay Computer Specialists, 336 Highett Road, Highett VIC 3190
We will acknowledge your complaint within 7 days and respond within 30 days. If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or the Office of the Victorian Information Commissioner (OVIC).
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated policy on this page with a revised "Last updated" date. We encourage you to review this policy periodically.
16. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
- Email: privacy@techbaycomputers.com.au
- Phone: (03) 9555 4321
- Address: 336 Highett Road, Highett VIC 3190