Last updated: 4 August 2026
This policy explains how Cloud Legs collects, uses, stores and discloses your personal information, and the choices you have. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
Cloud Legs ("we", "us", "our") is an Australian online apparel business trading at cloudlegs.com.au. We are the entity responsible for the personal information described in this policy — in data-protection language, we are the data controller.
Privacy enquiries: hello@cloudlegs.com.au{{ abnSentence }}
We only collect information that is reasonably necessary to run the shop. Depending on how you use the site, that may include:
We do not knowingly collect information from children under 16, and we do not collect sensitive information (such as health or racial or religious information) at all.
We use your personal information to:
We do not use your information to make automated decisions that have a legal or significant effect on you, and we do not build advertising profiles about individuals.
We never sell, rent or trade your personal information. We share it only with the parties we need to, and only for the purpose described:
| Who | Why | Where |
|---|---|---|
| Payment provider | Process your payment securely | AU / overseas |
| Australia Post | Deliver your parcel and provide tracking | Australia |
| Netlify, Inc. | Host this website and serve its pages | United States |
| Klaviyo | Send marketing emails you opted into | United States |
| Professional advisers & authorities | Where we are required or permitted by law | Australia |
If Cloud Legs is ever sold or restructured, customer information may be transferred as part of that business, and the buyer would be bound by this policy.
This website is hosted and served by Netlify, Inc., a company based in San Francisco, United States. This is the most significant overseas disclosure we make, so we want to be specific about it. APP 8 requires us to tell you.
What Netlify handles. Every page request you make to cloudlegs.com.au is served from Netlify's global content delivery network. To do that, Netlify necessarily processes technical data including your IP address, the URL you requested, your browser's user-agent string, response codes and timestamps. If you submit a form on this site, or if a checkout runs through one of our serverless functions, the contents of that request pass through Netlify's infrastructure while being handled.
Netlify's role. For this data, Netlify acts as our data processor — it handles the data on our instructions to deliver the hosting service, not for its own purposes. This is governed by Netlify's Data Processing Agreement, which is incorporated into its subscription terms and references the GDPR, the UK GDPR, and the CCPA as amended by the CPRA.
Where the data goes. Netlify's servers and CDN edge nodes are located in multiple countries, including the United States, and it uses infrastructure sub-processors such as Amazon Web Services. This means technical data about your visit is stored and processed outside Australia. Australian privacy law does not apply in the United States in the same way it does here, and you may not have the same avenues of redress. By using this site you acknowledge this overseas handling.
Netlify's own policies. Netlify publishes its privacy statement at netlify.com/privacy, its trust and security documentation (including its current sub-processor list) at its Trust Center, and can be reached on privacy matters at privacy@netlify.com. Netlify states that it does not sell, lease or exchange personal data with third parties other than as described in its own privacy statement. Note that Netlify's privacy statement covers data for which Netlify itself is the controller; the data it handles on our behalf is covered by its Data Processing Agreement and by this policy.
Other overseas recipients. Our email marketing platform (Klaviyo) and our payment provider may also store data outside Australia, including in the United States, in accordance with their own published privacy terms.
We take reasonable steps before disclosing information overseas to satisfy ourselves that the recipient handles it consistently with the APPs — chiefly by choosing established providers that publish binding data-processing terms.
We use a small number of cookies and browser-storage entries:
You can block or delete cookies in your browser at any time. If you block essential cookies and local storage, the cart and checkout will not work properly. Where your browser sends a Global Privacy Control or Do Not Track signal, we honour it for non-essential tracking.
We only email marketing to people who asked for it. Every marketing email identifies us and contains a one-click unsubscribe link that we action immediately, as required by the Spam Act 2003 (Cth). Unsubscribing from marketing does not stop transactional emails about an order you've actually placed — order confirmations, shipping notices and return instructions — because we need those to fulfil the contract.
All traffic to this site is encrypted with HTTPS. Payment details are transmitted directly to our payment provider over an encrypted connection and are never stored on our systems. Access to order records is limited to the people who need it to fulfil and support orders, protected by strong, unique passwords and multi-factor authentication. No online system is perfectly secure, but if a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
We keep order and transaction records for seven years, because Australian tax law requires it. Marketing subscriber details are kept until you unsubscribe, and then suppressed so we don't accidentally email you again. Support correspondence is kept for two years. Server logs are retained for a short period by our hosting provider. When information is no longer needed and we're not required to keep it, we delete or de-identify it.
You may ask us at any time to:
Email hello@cloudlegs.com.au and we'll respond within 30 days. There is no charge to access your information. We may ask you to confirm your identity first so we don't hand your details to someone else.
If you think we've mishandled your personal information, email hello@cloudlegs.com.au with the details. We'll acknowledge within 5 business days and aim to resolve it within 30 days. If you're not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
We may update this policy as our business changes. The "last updated" date at the top always reflects the current version. If we make a change that materially affects how we handle your information, we'll tell subscribers by email.