Privacy policy

Privacy Policy

Effective date: 16 August 2026. Last updated: 16 August 2026.


The short version

We are an Australian-owned baby nappy and wipes brand. You are trusting us with your details so we can get nappies to your door, and we take that seriously. Here is what is true, in plain language:

  • What we collect: your name, contact details, delivery and billing address, payment details, the products you order, your subscription settings, and your dealings with our team.
  • Why we collect it: to send you your order, run your subscription, answer your questions, and send you the emails you have signed up to receive.
  • Your child's health: we do not ask about, record or work out any child's health condition. We do not run a clinical service and we hold no medical or clinical records. Buying nappies or wipes from us tells us you have a baby in the house, and nothing more than that. More in the health section below.
  • Children: our site is for adults. We do not market to children and we do not knowingly collect information from anyone under 18. Anything we know about your baby came from you.
  • Who we share it with: the companies that help us run the shop and get your order to you (our e-commerce platform, our payment processor, our subscription manager, our Sydney fulfilment centre, our delivery carriers). When we run advertising, we share email addresses in scrambled form so the platforms can build audiences for our ads. Full detail in the sharing section below.
  • What we do not do: we do not sell your information, and we do not build a health profile from what you buy.
  • Your rights: you can ask to see, change or delete most information we hold about you. Email us at hello@littlepuggles.com.au.
  • If something goes wrong: tell us first (hello@littlepuggles.com.au). If we cannot sort it out, you can take it to the OAIC at oaic.gov.au.

The full policy below sits underneath this summary if you want the detail.


Quick navigation


This privacy policy explains how Little Puggles collects, uses, stores and shares your information when you visit our website, buy our products, start a subscription, set up an account, or get in touch with us. We have written it in plain Australian English so you can read it in one sitting.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We collect your contact and delivery details, your subscription settings and the products you order. We do not ask you for health details about you or your child, we do not run a clinical service, and we keep no clinical records. This policy operates on the basis that the Australian Privacy Principles apply to us in full. We do not rely on any small-business exemption.

If you think we have handled your information in a way that does not match this policy, let us know at hello@littlepuggles.com.au. If we cannot resolve it together, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.


Who we are

Little Puggles is owned and run by Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), the operator of Little Puggles, based at 205 Murphy Street, East Bendigo VIC 3550. Little Puggles is an Australian-owned premium baby nappy and wipes brand launching August 2026, and is a brand of Australian First Aid Distributions Pty Ltd. This policy covers the Little Puggles website and the dealings described in it. Our other brands run their own websites with their own privacy policies.

When this policy says "we", "us" or "our", we mean Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), the operator of Little Puggles. When it says "you", we mean any person whose information we hold or who interacts with our website, our products or our team.

You can contact us about anything in this policy at:

  • Email: hello@littlepuggles.com.au
  • Phone: 03 5443 2239
  • Post: Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), the operator of Little Puggles, 205 Murphy Street, East Bendigo VIC 3550
  • Hours: Monday to Friday, 9am to 5pm Melbourne time

Privacy at Little Puggles sits with a single named role we call the Privacy Contact. The Privacy Contact is the role responsible for handling privacy enquiries and complaints, overseeing access and correction requests, and leading our response if a data breach is suspected. We are a small team, so we do not carry a dedicated Privacy Officer in the large-corporate sense, but accountability for privacy is held at director level and the Privacy Contact reports to our director. You reach the Privacy Contact at hello@littlepuggles.com.au, and we respond within reasonable timeframes.


What we collect

Different parts of your dealings with Little Puggles involve us collecting different information. We have broken it down by what we collect and when, so you can see clearly what is happening at each point.

At each point where we collect information directly from you (checkout, account creation, starting or changing a subscription, newsletter sign-up, and customer-service forms) we provide a short collection notice that links back to this policy. That notice tells you who is collecting the information and why, and this policy fills in the detail. Together, those notices and this policy are how we meet our notification obligation under Australian Privacy Principle 5. If you do not give us the information we need, for example delivery and contact details, we may not be able to fulfil your order or provide the service you have asked for. The countries to which we disclose information are set out in "Where your information is stored" below.

When you browse our website without buying:

  • Your IP address and approximate location (city or region level), via standard web analytics
  • Your browser type, device type and operating system
  • The pages you visit on our site, the time you spend on them, and where you came from (referring website)
  • Cookies and similar technologies that store small text files on your device (see the cookies section)

When you create an account or start a subscription:

  • Your name (first and last)
  • Your email address
  • Your phone number (used for delivery notifications and customer service)
  • Your delivery address and billing address
  • Your account password (stored as a hashed value, not in plain text)
  • Your subscription settings: the products on your plan, the sizes you have chosen, your delivery frequency, and your next delivery date

When you place an order:

  • The products you have bought, including quantities, sizes and any product variants
  • Your delivery instructions and any gift message
  • Your order history, subscription status and invoice records
  • Your payment confirmation. We do not see or store your full card number: this is handled by our payment processor, see the sharing section

Nappy and nappy pant sizes are weight-based, so a size choice tells us roughly how big your baby is. We use it to send the right product and to remind you when a size change is usually due. It is a fulfilment detail, not a health record, and we do not treat it as one.

When you contact our customer service team:

  • The content of your message (email, phone notes, web form or live chat)
  • Any photos or attachments you send, for example a photo of a damaged pack
  • Records of how we resolved your enquiry, including returns and refunds

When you fill out forms or surveys on our website:

  • The information you provide in those forms, for example a product enquiry, a customer satisfaction survey, product feedback or a competition entry

When you sign up for our newsletter or email program:

  • Your email address and name
  • Your engagement with the emails (opens, clicks, unsubscribes), used to send you content that is actually relevant rather than blanket-broadcasting

When you write a product review:

  • Your name (first name and last initial only are published)
  • Your email address (not published)
  • The content of your review, your rating, and any photos you submit

We do not collect more than this. If we change what we collect, this policy will be updated and you will be told (see the changes section). Importantly, we do not collect or hold medical records, clinical notes, health histories, or any record of a diagnosis or skin condition for you or your child. We do not collect government-related identifiers of any kind, including Medicare numbers.


Health information, and what we do not collect

We want to be direct about this, because it is the question parents ask us most.

We do not ask about, record or work out any child's health condition. There is no question anywhere on our site, at checkout, in our sign-up forms, or in our email programs that asks whether your baby has eczema, a skin condition, a nappy rash history, an allergy, or any other health issue. There is no tag, segment or flag in any of our systems that records one. We do not run a clinical service, we employ no clinical service in connection with your order, and we hold no medical or clinical records.

We do not build a health profile from what you buy. Nappies and wipes are ordinary household goods for families with babies. An order tells us you have a baby in the house and which sizes fit. It does not tell us anything about anyone's health, and we do not treat it as though it does. We do not infer a condition from a size, a frequency, a product choice, or a return. We do not use your purchases to target advertising about any health topic at you.

If you tell us something anyway. Parents sometimes mention a health reason in an email or a phone call, for instance when asking which product suits sensitive skin. We do not need that detail and we do not want it on file. Where we receive information we did not ask for and do not need, we assess it and destroy or de-identify it where it is not needed for our dealings with you. We will always answer your question. We will not turn your answer into a record.

Nothing on our site is health advice. Our product pages and our educational articles are general information only. They are not a substitute for advice from a qualified health professional. If you have a concern about your child's skin or health, speak to your GP, your maternal and child health nurse, or your pharmacist.

Victorian health privacy law

We are based in Victoria, so the Health Records Act 2001 (Vic) is worth naming even though we do not think it bites on what we do. We run no clinical service, we hold no medical or clinical records, and we do not collect health information. To the extent that any information we hold were ever health information, we handle it consistently with the Health Privacy Principles under the Health Records Act 2001 (Vic), which runs in parallel with the Privacy Act 1988 (Cth) for health information. We state this so the position is on the record rather than left to be assumed.


Children, babies and parental authority

Everything we sell is used on a baby or a toddler, and every customer we have is an adult. That split matters for privacy, so here is how it works.

Our site is not aimed at children. Little Puggles is written for parents and carers. We do not design our site, our products or our advertising to appeal to children as users, and we do not market to children.

Account holders and purchasers are adults. You need to be at least 18 to hold an account, start a subscription or place an order with us. We do not knowingly collect personal information from anyone under 18, and we do not knowingly accept account registrations from anyone under 18.

Anything we know about your baby came from you. Your child cannot give us information, and we never seek it from them. Any detail about a baby or child in our systems reached us from the parent or guardian: a size on a subscription, a first name in a gift message or a delivery instruction, a birth month if you chose to tell us so we could time size reminders, or a passing mention in a customer service exchange.

What we do with a detail about a child. Where the detail is part of the service you asked for, such as a size on your plan, we hold it and use it to run your subscription and nothing else. Where it is incidental, such as a name or an age mentioned in an email, we leave it in that customer service record and we do not copy it into a profile, a marketing segment, or an advertising audience. We never share a child's details with an advertising platform. We do not use a child's name or details in marketing.

How to have a child's detail deleted. Email hello@littlepuggles.com.au with the subject line "Privacy deletion request" and tell us what you want removed. As the parent or guardian you can ask us to delete any detail about your child that we hold, including a name, an age, a birth month or a photo you sent us. We will delete it, and we will confirm when it is done. The only exception is where the detail sits inside a transaction record we are legally required to keep, and if that happens we will tell you which record and why. If you become aware that a child has given us information without your authorisation, contact us and we will delete it.

Forward-looking note. The OAIC is currently developing a Children's Online Privacy Code. Because our customers are adults buying for babies, we expect its direct application to us to be limited, but we are watching it closely. When the Code is issued and commences, we will review this policy and this section, and update them if required.


Why we collect it

We collect information for these purposes only:

To run the shop, your account and your subscription. Processing orders, sending products, scheduling and adjusting subscription deliveries, handling returns, and managing your account.

To provide customer service. Answering your questions, fixing problems, processing refunds and returns, and helping you change, pause or cancel your subscription.

To improve our products and our website. Understanding how parents use our site and which products and content help. We aggregate this data to make decisions; we do not single you out.

To send you communications you have asked for. Order confirmations, delivery updates, subscription reminders, and, only if you have opted in, marketing emails.

To comply with our legal obligations. Tax and consumer-law obligations, and responding to regulatory or law-enforcement requests where legally required.

To protect our business and your security. Preventing fraud, detecting unauthorised account access, and responding to security incidents.

We do not collect information for any purpose not listed here. We use or disclose your personal information only for the purpose it was collected for, except where you consent or you would reasonably expect a directly related secondary use. We will only use your information for a purpose you would reasonably expect, or we will ask for your consent first.

Little Puggles is a brand of Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), which also runs sibling brands. We do not share your personal information with the other brands in the group for their own marketing without your consent.


How we use automated processing

We use automated processing in some parts of our service. We are explicit about this, because we know parents care.

Where we use it:

  • Subscription scheduling. Your subscription renews and bills on the schedule you chose. That timing is automated. You can change, skip, pause or cancel it yourself at any time from your account, and a person will help if you would rather email us.
  • Size reminders. Where you have told us your baby's size or birth month, we may send an automated reminder when a size change is usually due. It is a prompt based on the size on your plan, not an assessment of your child.
  • Email content selection. Our email platform chooses which marketing email content to send based on what you have bought, what you have engaged with, and which lifecycle stage you are in, for example new subscriber, established subscriber or lapsed subscriber.
  • Email timing. Some email flows send you content at preset intervals after an order. The timing and content are chosen by rules we have set, not individually by a person.
  • Audience modelling for advertising. When we run ads on Google, Meta or TikTok, we sometimes share email addresses in scrambled (hashed) form so the platform can build audiences for us. The platform runs its own algorithms to find people with similar profiles. See the sharing section for what hashing means and which platforms are involved.

Where we do not use it:

  • Pricing. All customers see the same prices. Automation does not adjust your prices based on your data.
  • Product availability. All customers see the same products. Automation does not restrict what you can buy.
  • Subscription approval. Whether we accept your order or subscription is not decided by automation.
  • Service decisions. A real person answers customer service queries. Automation does not approve or deny refunds, returns or service decisions.
  • Health inference. Nothing we automate looks for, guesses at, or acts on a health condition. We do not build a health profile from what you buy, and we do not single you out for advertising because of the products you have bought.

Forward-looking note. From 10 December 2026, the Privacy Act will require Australian businesses to disclose specific kinds of automated decision-making that have a legal or similarly significant effect on individuals. The automated processing we currently use does not have a legal or similarly significant effect on you: it is scheduling, content selection and ad targeting, not decision-making about your access to products or services. When the new requirement commences, we will review this section and update it if anything we do falls within scope.

If you have specific questions about how automated processing applies to your data, email hello@littlepuggles.com.au.


Who we share it with

We share your information only with parties who help us run our business, and only the information they actually need. We do not sell your information. Where we share information with third parties, we do so only in line with the disclosures in this section and only for the purposes set out here.

The parties we share information with fall into these categories:

Our e-commerce platform (Shopify). Shopify hosts the store, your account, your orders and the checkout. It is based in Canada with data centres in several jurisdictions including the United States.

Our payment processors (Shopify Payments, which also provides Shop Pay, and PayPal). Card and PayPal payments are processed and tokenised by the payment provider you choose at checkout. We do not see or store your full card number. Where you pay with PayPal, PayPal handles your payment details under its own privacy policy and we receive only confirmation of payment and the details needed to fulfil your order.

Our subscription manager (Loop). Loop manages your subscription: the products on your plan, your delivery frequency, your next delivery date, and the billing schedule. It receives your name, contact details, delivery address, plan settings and order history so your subscription runs. Loop is operated by Loop Solutions, Inc., a United States company.

Our email and marketing platform (Klaviyo). Klaviyo sends our customer emails and stores your engagement data. It is based in the United States.

Our review platform (Judge.me). Judge.me manages product reviews on our site. It is based in Canada.

Google (Google Analytics 4 and Google Ads). Google Analytics provides aggregated and pseudonymous data about how visitors use our site, used for our reporting. Google Ads helps us deliver advertising and measure conversions. Both are operated by Google, based in the United States.

Meta (Facebook and Instagram). We use Meta to advertise, to show our ads to people who have already visited our site, and to measure ad performance through a pixel. Where we build an audience from our customer list, we share email addresses only in hashed form.

TikTok. Where we advertise on TikTok, the same applies: email addresses are shared only in hashed form, and we measure ad performance through TikTok's own measurement tools.

What hashing means in plain language: when we say "email addresses in hashed form", we mean we convert your email into a one-way scrambled value before sharing it, so we never hand over your email in readable form. The platform cannot reverse the scrambling to read your actual address. It uses that scrambled value to build advertising audiences. We do this so we can advertise without giving the platform your email address in a form it can read.

Our Sydney fulfilment centre. Our orders are packed and despatched from our Sydney fulfilment centre, which receives your name, delivery address, phone number and order details so it can pick, pack and ship your order. It is based in Australia.

Australia Post and other delivery carriers. They receive your delivery address, phone number and delivery instructions so they can deliver your parcel. Delivery carrier data is held in Australia.

Our operational systems. We use a small set of business systems that may hold personal information in the course of running the business: our inventory system, our accounting software (Xero, for invoicing and tax records), our document and email storage (Google Workspace, where customer emails are stored), our project-management tool, and our team-communications tool. These systems are located in Australia and overseas, mainly the United States; the cross-border section sets out where your information is stored.

Our developer and freelancers. Our developer and our design or content freelancers may have access to our systems while doing development or support work, which can expose personal information in the course of that work. They are bound by confidentiality.

Our accountants, lawyers and other professional advisers. Where they need access to limited information for advice or compliance work. They are bound by confidentiality.

Government and regulatory bodies. Where we are legally required to disclose information, for example tax, consumer-law enforcement, court orders or law enforcement.

We require all of these parties to handle your information securely and in line with their own privacy obligations and the Australian Privacy Principles, where applicable. We work to put written data-protection terms in place with the third parties that handle personal information for us, and we rely on the data-protection commitments in our service agreements with them (see the next section). If we add new parties that handle your information, we will update this policy.


Where your information is stored

Some of your information is stored on servers in Australia, and some is stored on servers overseas (mostly the United States and Canada, and in limited cases other countries where our developer or freelancers work).

Stored in Australia: customer service notes, our internal records, our Sydney fulfilment centre data, and delivery carrier data.

Stored overseas (mostly the United States and Canada): our e-commerce platform data, payment data with our payment processors, subscription data with Loop, email and engagement data, review data, Google analytics and advertising data, and Meta and TikTok advertising audiences (in hashed form). Our document and email storage, our project-management tool and our team-communications tool are based in the United States, and our accounting and inventory systems may store data in Australia or overseas. Where our developer or freelancers work outside Australia, their access to our systems can involve a cross-border disclosure to the countries they are based in.

What this means for you (in plain language). Storing data overseas is normal for businesses that use modern cloud-based services. When your data sits overseas it may be subject to the laws of that country, which can differ from Australian law. We remain accountable to you under Australian law (Australian Privacy Principle 8 and section 16C of the Privacy Act) for how overseas recipients handle it. Your Australian rights to access, correct and delete your information do not change.

How we manage the cross-border risk. Australian Privacy Principle 8 requires us to take reasonable steps to ensure that overseas recipients of your personal information handle it consistently with the Australian Privacy Principles. We take those steps, including by relying on the data-protection commitments in our service agreements with overseas recipients. If a recipient breaches those terms, we remain accountable to you under section 16C of the Privacy Act, and we deal with the breach through our incident-response process (see the security section).

There is a mechanism in the Privacy Act for the Government to approve overseas countries as having substantially similar privacy protection. As at the date of this policy no countries have been approved under that mechanism, so we rely on the contractual reasonable steps described above; if an approved-country list is published we will review this section.

If you have specific concerns about overseas data handling, please email us and we will explain how a particular provider handles your information.


Cookies, tracking and analytics

When you visit our website, we use cookies and similar technologies. Cookies are small text files stored on your device that help our site work properly and help us understand how you use it.

We run a cookie consent banner on our site. When you first arrive, the banner asks for your choice before any non-essential cookies or tags fire. You can accept all cookies, or reject all non-essential cookies, with equal prominence: the reject path is a genuine one-click choice, not buried behind extra steps. Strictly necessary cookies still run because the site cannot work without them, but our analytics and marketing cookies, and the tags that depend on them, stay off until you accept them. We record your choice and apply it on your return visits.

You can change your mind at any time. A persistent cookie-settings link sits in the footer of every page. Open it to review your choice and turn analytics or marketing cookies on or off whenever you like. Updating your choice there takes effect straight away.

Strictly necessary cookies. These are essential for the site to function. They remember your cart contents, keep you logged in, and process your purchase. We cannot operate without them, so they are not controlled by the consent banner and you cannot disable them while continuing to use the site.

Analytics cookies. These collect aggregated and pseudonymous information about how you use our site (which pages you visit, how long you spend, where you came from), used for our reporting. The main analytics provider we use is Google Analytics 4. These cookies fire only after you accept them through the consent banner, and you can withdraw that consent at any time through the footer cookie-settings link. You can also opt out of Google Analytics tracking by installing the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout).

Marketing cookies. These remember whether you have visited our site so we can show you relevant Little Puggles ads on platforms like Google, Facebook, Instagram and TikTok. They fire only after you accept marketing cookies through the consent banner, and you can withdraw that consent at any time through the footer cookie-settings link. You can also manage them using your browser's cookie controls, the Google Ads opt-out tools, and the ad-preference settings on each platform.

Account, subscription and personalisation cookies. When you log into your account, cookies remember your subscription preferences and your account settings. These are used only for the purposes you have consented to.


Marketing communications

We only send you marketing communications if you have opted in.

When you have opted in. You receive emails about new products, promotions, and content from our team. You can unsubscribe at any time using the link at the bottom of every email, by changing your preferences in your account, or by emailing hello@littlepuggles.com.au.

Order and subscription emails. You receive transactional emails about your orders, deliveries, subscription renewals and account changes regardless of marketing opt-in. These are not marketing; they are necessary for the service you have bought. If you unsubscribe from marketing, you still receive transactional emails.

Marketing and what you buy. Our marketing is based on your having opted in, and on the ordinary commerce data described in this policy: what you bought, what size you are on, and what you have engaged with. We do not build a health profile from your purchases, and we do not send you marketing based on any health condition, because we do not hold one.

Product reviews. If you write a review, we may publish it on our website. Your first name and last initial appear; your email address does not.

No marketing to children. We do not market to children, and we do not send marketing to a child's name, email address or device.

Spam Act and Do Not Call. Our email marketing complies with the Spam Act 2003 (Cth): we send it with consent, we identify ourselves, and every message has a working unsubscribe. We do not currently run SMS or telephone marketing. If we add either in the future, we will request opt-in first, comply with the Spam Act for SMS, and comply with the Do Not Call Register Act 2006 (Cth) for any phone marketing.


How we keep your information secure

We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification or disclosure. Australian privacy law expects both technical and organisational measures, and we maintain both.

Technical measures.

  • Encrypted connections across our website, checkout and account portal
  • Account passwords stored as hashed values, not in plain text
  • Payment information handled and tokenised by our payment processor; we never store full card details
  • Access controls on a least-privilege basis, so information is reachable only by those who need it for their work
  • Backups, managed through our hosting and platform providers, protected and access-controlled
  • Security reviews and patching across our systems and our integration partners
  • Logging of access to customer information

Organisational measures.

  • Access control. We give access to customer information only to team members who need it for their work, on a least-privilege basis, and we review that access when team members change roles.
  • Privacy awareness. Team members with access to customer information are made aware of their privacy obligations and are reminded of them.
  • Vendor management. We choose third parties that handle personal information with privacy in mind, and we work to put written data-protection terms in place with them.
  • Incident response. We maintain an incident-response process that engages our Privacy Contact for any suspected unauthorised access, loss or disclosure, with an assessment pathway under the Notifiable Data Breaches scheme (see the next section).
  • Governance. Privacy management is a standing responsibility of our Privacy Contact, reporting through to our director.

We also destroy or de-identify personal information once we no longer need it for any purpose, subject to legal retention requirements (see "How long we keep your information").

No system is perfectly secure. If we ever discover a breach that affects your information, we will notify you and the OAIC in line with the Notifiable Data Breaches scheme (see the next section).


Notifiable Data Breaches

We take the Notifiable Data Breaches scheme seriously. Under Part IIIC of the Privacy Act, we must notify affected individuals and the OAIC if there is unauthorised access to, disclosure of, or loss of personal information that we hold, where this is likely to result in serious harm to the individual, and we have not been able to prevent that likely harm through remedial action.

How we assess. If we suspect a breach, we will:

  • Begin assessment promptly after we suspect a breach
  • Complete the assessment within 30 days (the maximum permitted under section 26WH of the Privacy Act); we will work to complete it sooner where the facts allow
  • Apply a documented assessment process: who is affected, what information was involved, what harm could result, and what remedial action is possible

Factors we consider in assessing whether a breach is eligible:

  • Whether unauthorised access, disclosure or loss of personal information has occurred
  • The kind and quantity of information involved (more sensitive categories, including payment and financial details, home addresses, and information capable of enabling identity-related harm, weigh towards eligibility)
  • Whether the information involved relates to a child, which weighs towards eligibility
  • The number of individuals affected
  • Whether the information was protected by encryption, access controls or other security measures that reduce the practical risk of harm
  • The nature of any onward access or disclosure, for example a single accidental misdirection versus systemic exposure
  • Whether remedial action has been or can be taken before serious harm occurs
  • Whether a third-party service provider that handles our customer information has experienced a breach affecting our customers

What we will do if we determine a breach is eligible:

  • Prepare a statement and notify the OAIC as soon as practicable after we form the view that an eligible breach has occurred
  • Notify affected customers as soon as practicable after that; we do not wait out the 30-day window once we have reached that view
  • Explain what happened, what information was involved, what we are doing about it, and what you can do to protect yourself
  • Provide a contact for affected customers to ask questions

For the OAIC's guidance on this scheme, see oaic.gov.au/notifiabledatabreaches.


How long we keep your information

We keep your information only for as long as we need it for the purposes set out in this policy, or for as long as the law requires.

Category How long we keep it
Active account and subscription information While your account or subscription is active
Account profile data after account closure (name, address, password hash, preferences, communication history) 24 months from account closure, then deleted
Order and transaction records (required for tax and consumer law) 7 years from the date of transaction
Customer service correspondence 3 years from the last interaction
Marketing email subscription data While you remain subscribed, plus 30 days after unsubscribe (for technical processing)
Published product reviews While the review remains published on our site, and removed on request
Aggregated and pseudonymous analytics data 14 months
Backup and archive data Up to 90 days after live deletion (for technical recovery)

On analytics: 14 months is the maximum user-level retention available in Google Analytics 4, and it is what we set. Reporting totals that no longer identify anyone may be kept for longer as aggregate figures.

Once a retention period ends, the data is deleted or de-identified. When we de-identify data, we follow current OAIC de-identification guidance, which involves stripping direct identifiers and reducing the risk of re-identification through combination.

If a legal obligation, for example an active dispute, a regulatory request or an unresolved legal claim, requires us to keep specific information longer, we keep it only as long as that obligation requires.


Your rights and how to exercise them

Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:

Access your information. You can ask us what information we hold about you. The law requires us to respond within a reasonable period, and our service commitment is to respond within 30 days. We do not charge a fee to make an access request, and that applies to your first request and every one after it. To request access, email hello@littlepuggles.com.au with the subject line "Privacy access request" and we will guide you through the process. In limited cases the law allows us to decline access, for example where giving access would pose a serious threat to someone's life, health or safety; this is rare and we would explain it.

Correct your information. If something we hold about you is wrong (a misspelled name, an outdated address, an incorrect order), let us know and we will fix it. You can also correct most account and subscription details yourself from your account page. We also take reasonable steps of our own to keep your information accurate and up to date, including prompting you to confirm delivery details at checkout, processing bounces and unsubscribes to keep our marketing lists current, and updating records when corrections are notified.

Request a statement of disagreement. If you think we hold information about you that is incorrect, out of date, incomplete, irrelevant or misleading, and we do not agree to correct it, you can ask us to attach a statement of your view to the record. This is your right under APP 13.

Withdraw consent for marketing. Unsubscribe at any time from any marketing email, change your marketing preferences in your account, or email us to opt out of all marketing.

Request deletion of your information. You can ask us to delete information we hold about you, and as a parent or guardian you can ask us to delete any detail we hold about your child. We will delete it where we can. There are some categories we cannot delete, such as transaction records we are legally required to retain and ongoing dispute records, and we will explain why we have kept those. To request deletion, email hello@littlepuggles.com.au with the subject line "Privacy deletion request".

Make a complaint. If you think we have handled your information incorrectly, see the complaints section.

Direct contact. For all of the above, we prefer email (hello@littlepuggles.com.au) so there is a written record. If you would rather call, our number is 03 5443 2239, Monday to Friday, 9am to 5pm Melbourne time.


How to make a complaint

If you think we have handled your information incorrectly, please tell us first. We would rather fix it than have you escalate. Telling us first is not a precondition for going to a regulator: you can always go straight to the OAIC if you prefer.

Step 1. Email hello@littlepuggles.com.au with the subject line "Privacy complaint". Tell us what you think happened, when, and what you would like us to do.

Step 2. We will acknowledge your complaint within 5 business days and respond within 30 days. If we ever need longer than 30 days, we will tell you why and keep you updated.

Step 3. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Online: oaic.gov.au/privacy/privacy-complaints
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001

The OAIC is the regulator for a privacy complaint. It can investigate, mediate and award compensation for breaches of the Privacy Act. A regulator will usually want to see that you have already raised the issue with us first, but you are not required to.


Other policies

This policy sits alongside the rest of our terms:

If you are looking for practical help rather than the legal detail, our returns page, our FAQ and our contact page are the quickest routes.


Changes to this policy

We may update this policy from time to time as our practices evolve, our services change, or the law changes. We will:

  • Update the "Last updated" date at the top of the policy
  • For material changes (changes that affect what we collect, why we collect it, or who we share it with), take reasonable steps to tell you, which may include emailing registered customers and displaying a notice on our website for a period after the change

If you do not agree to a material change, you can close your account, cancel your subscription, or unsubscribe at any time using the mechanisms in the rights section.

We keep a version log at the bottom of the page so you can see what has changed and when. We do not retire previous versions silently.


One last note

This policy is written in plain language on purpose. If something here is unclear, please email us. Privacy law is technical and we would rather explain than have you guess. We would also rather hear that something here is not working than have you stop dealing with us over a privacy concern we could have resolved.

Thanks for reading this far.

The Little Puggles team


Australian Privacy Principles compliance map (for solicitors and regulators)

Compliance map for solicitors and regulators

Australian Privacy Principle Where addressed in this policy
APP 1: Open and transparent management of personal information Whole policy; contact details and the Privacy Contact role in "Who we are"; no reliance on the small-business exemption, stated in the intro; the subscription manager is named as Loop, matching the live integration
APP 2: Anonymity and pseudonymity You can browse the site and make a general enquiry without identifying yourself. Little Puggles has no retail counter and no local pickup, so there is no anonymous over-the-counter purchase pathway; a delivered order necessarily requires a name and address. Browsing analytics are pseudonymous, not anonymous, and are dealt with under the notification and cookies sections (APP 1 and APP 5) rather than relied on for APP 2
APP 3: Collection of solicited personal information "What we collect" (commerce data only: contact and delivery details, subscription settings, and the products ordered). "Health information, and what we do not collect" records the categorical position: Little Puggles solicits no sensitive information, asks no question anywhere about any child's health condition, holds no tag, segment or flag recording one, and does not infer a condition from a size, a frequency, a product choice or a return. Nappies and wipes are ordinary household goods for families with babies, so an order does not reveal a health condition and the health-information-by-inference analysis that applies to a retailer whose products themselves disclose a condition does not apply here. Weight-based size data is a fulfilment attribute, not health information. There is accordingly no APP 7.4 consent dependency anywhere in this policy
APP 4: Dealing with unsolicited personal information "Health information, and what we do not collect" (where a parent volunteers a health reason we did not ask for, it is assessed and destroyed or de-identified where it is not needed for our dealings with them, and it is not turned into a record) and "Children, babies and parental authority" (an incidental detail about a child stays in the customer service record and is not copied into a profile, a marketing segment or an advertising audience)
APP 5: Notification of the collection of personal information "What we collect" (a short collection notice at each collection point links back to this policy; consequence of not providing information stated) and "Why we collect it"; overseas disclosure set out in "Where your information is stored"
APP 6: Use or disclosure of personal information "Why we collect it" (purpose limitation; use only for the purpose collected or a reasonably expected directly related secondary use; no cross-brand marketing within the group without consent); "How we use automated processing"; "Who we share it with" (sharing limited to the listed parties)
APP 7: Direct marketing "Marketing communications" (opt-in only; unsubscribe in every message; account-level preferences; Spam Act and Do Not Call alignment; no marketing to children; no health profile built from purchases and no marketing based on a health condition, because none is held). APP 7.4 does not engage: no sensitive information is collected, so no sensitive-information consent is relied upon for any marketing
APP 8: Cross-border disclosure of personal information "Where your information is stored" (overseas storage disclosed by recipient category; reasonable steps via the data-protection commitments in service agreements; section 16C accountability; offshore developer and freelancer access noted; no approved-country list relied upon)
APP 9: Adoption, use or disclosure of government-related identifiers Not applicable. Little Puggles collects no government-related identifiers of any kind, including Medicare numbers. Stated in "What we collect"
APP 10: Quality of personal information "Your rights" (correction, plus the proactive data-quality statement that we take reasonable steps of our own to keep information accurate, including checkout confirmation, bounce and unsubscribe processing, and record updates); "Marketing communications" (list hygiene); account and subscription self-service
APP 11: Security of personal information "How we keep your information secure" (technical and organisational measures, engaging the post-Tranche 1 clarification); "Notifiable Data Breaches"; "How long we keep your information". Technical measures are stated at a level that reflects verified practice; specific cryptographic and authentication standards are held pending verification rather than represented
APP 12: Access to personal information "Your rights" (access request mechanism, no fee on the first or any subsequent request; 30-day response framed as a service commitment within the statutory reasonable-period requirement, not as the statutory deadline; limited statutory exceptions noted, such as a serious threat to life, health or safety). Because we hold no clinical records, a health-specific access exception is unlikely to apply
APP 13: Correction of personal information "Your rights" (correction mechanism and statement of disagreement)

Notifiable Data Breaches scheme (Part IIIC of the Privacy Act): the Notifiable Data Breaches section addresses the 30-day assessment window, the serious-harm threshold, and OAIC plus affected-individual notification, on a factors-based assessment rather than a categorical commitment. Information relating to a child is expressly listed as a factor weighing towards eligibility.

Children's privacy: "Children, babies and parental authority" is the load-bearing section for this business, because every product is used on an infant and every customer is an adult. It records that the site is not aimed at children as users, that no marketing goes to children, that account holders and purchasers must be 18 or over, that no information is knowingly collected from anyone under 18, that any detail about a child reaches Little Puggles from the parent or guardian rather than the child, what is done with a service-necessary detail (a size, used to run the subscription) versus an incidental one (left in the customer service record, never copied into a profile or an advertising audience), that a child's details are never shared with an advertising platform or used in marketing, and the parent-initiated deletion pathway with its single legally-required-retention exception. A forward-looking note covers the Children's Online Privacy Code in OAIC development.

Health Records Act 2001 (Vic) and Health Privacy Principles: Little Puggles runs no clinical service, holds no medical or clinical records, and does not collect health information. It holds commerce data only: contact and delivery details, subscription settings, and the products ordered. Nappies and wipes are ordinary household goods, so an order does not reveal a health condition and no health-information-by-inference treatment is engaged. To the extent that any information held were health information, it is handled consistently with the Health Privacy Principles under the Health Records Act 2001 (Vic), which runs in parallel with the Privacy Act 1988 (Cth) for health information. The OAIC is the regulator named for privacy complaints.

Privacy Act Tranche 1 reforms: the security section's technical-and-organisational split engages the post-Tranche 1 APP 11 clarification (in force 11 December 2024). The organisational measures (privacy awareness, vendor management, least-privilege access, incident response, governance) are the practical mitigation for the statutory tort of serious invasion of privacy (in force 10 June 2025); because no sensitive information is collected, tort exposure sits at the level applicable to any APP entity holding personal information. The automated-processing section includes a forward-looking note on the automated decision-making transparency commencement (10 December 2026). The cross-border section notes the approved-country mechanism exists but is not relied upon. The children's section includes a forward-looking note on the Children's Online Privacy Code in OAIC development.

Section 6D(4) exclusions: Little Puggles applies the APPs in full and does not rely on the small-business exemption, regardless of any potential exemption availability.

Version history

This policy was last updated 16 August 2026.

  • Version 1.0 (effective 16 August 2026): Initial publication for Little Puggles.