Your cart is currently empty!

Privacy Policy
Effective Date: September 29, 2026
GIVONI PTY LTD (“we”, “us”, or “our”), located at Virginia Park, Suite 1, Level 1, 2 North Drive, Bentleigh East, VIC 3165, Australia, operating the e-commerce website www.givonishop.com, is committed to protecting the privacy of all visitors, customers, and users (collectively, “you”) of our services. This Privacy Policy explains how we collect, use, disclose, store, and safeguard your personal information when you access or use our website, place orders, interact with our customer support, or engage with any of our related services (collectively, the “Services”). It also outlines your rights regarding your personal data under applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By continuing to browse, register an account, or use our Services, you acknowledge that you have read, understood, and agree to the collection, processing, and sharing practices described in this policy.
For any privacy-related inquiries, you may contact us at:
- Email: vdrtb@givonishop.com
- Telephone: +61 3 9570 5866
- Postal Address: Virginia Park, Suite 1, Level 1, 2 North Drive, Bentleigh East, VIC 3165, Australia
1. Definitions
For the purposes of this Privacy Policy:
- Personal Information: Means any information or opinion about an identified or identifiable individual, recorded in any form, whether true or not, that can be used to directly or indirectly identify a specific person. This does not include de-identified or anonymous information that cannot be linked back to a natural person.
- Sensitive Personal Information: A subset of personal information that includes details related to your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, sexual practices, criminal records, health status, genetic data, and biometric identifiers. This category of information receives enhanced protection under Australian law.
- Processing: Means any operation or set of operations performed on personal information, including collection, storage, use, access, modification, disclosure, transmission, archiving, and deletion.
- Eligible Data Breach: An incident where unauthorised access, unauthorised disclosure, or loss of personal information held by us is likely to result in serious harm to any affected individual, as defined under the Notifiable Data Breaches scheme of the Privacy Act 1988.
2. Types of Information We Collect
We only collect personal information that is reasonably necessary for the delivery of our e-commerce Services, in compliance with the data minimisation requirements under APP 3.2. The categories of information we may gather include:
2.1 Information You Provide Directly to Us
This is all information you actively submit when interacting with our platform, including:
- Account registration details: your full name, email address, contact phone number, and password when you create a user account on www.givonishop.com.
- Order and transaction information: your delivery address, billing address, payment method details (we do not store full credit card or debit card numbers on our internal servers; all payment processing is handled via PCI DSS certified third-party payment providers), and order preference notes when you complete a purchase.
- Customer support communications: the content of your messages, feedback, enquiry details, and contact information you share when you reach out to our team via email, website contact forms, or telephone.
- Marketing preference data: your explicit consent status for receiving promotional emails, SMS alerts, or direct mail, as well as any self-reported product interests you share with us.
- Participation records: information you submit when joining our loyalty program, entering competitions, completing surveys, or leaving product reviews on our website.
2.2 Information We Collect Automatically
When you visit www.givonishop.com, we automatically gather certain technical and usage information to optimise our website performance, troubleshoot errors, and improve your shopping experience, including:
- Device metadata: your IP address, browser type and version, operating system, device model, unique device identifiers, language preference, and time zone setting.
- Usage behaviour data: pages you view on our website, links you click, search terms you enter, time spent on specific product pages, access timestamps, exit pages, and navigation paths across our platform.
- Cookie and tracking data: we use first-party and authorised third-party cookies, web beacons, and similar tracking technologies to remember your saved cart items, personalise product recommendations, analyse website traffic patterns, and measure the effectiveness of our marketing campaigns. You may adjust your browser settings to refuse cookies, but this may limit your ability to access certain full functionalities of our website.
3. How We Use Your Personal Information
All processing activities of your personal information are conducted only for lawful, transparent, and necessary purposes directly related to our e-commerce operations. We use your information for the following stated purposes:
- Service Delivery and Order Fulfilment: To process your purchase transactions, verify your identity, arrange product shipment to your nominated delivery address, send order confirmation emails and tracking updates, handle payment verification, and resolve any delivery or post-delivery product issues.
- Website Operation and Experience Optimization: To maintain the normal operational stability of www.givonishop.com, diagnose technical faults, prevent unauthorised login attempts, customise your browsing experience, populate your saved shopping cart across login sessions, and provide you with relevant product recommendations tailored to your past browsing and purchase history.
- Customer Support and Dispute Resolution: To respond to your enquiries, process your return, refund or exchange requests, address product complaints, resolve transaction disputes, and provide after-sales assistance in a timely and efficient manner.
- Compliance and Legal Obligations: To comply with our statutory obligations under Australian federal and state laws, including tax record-keeping requirements, consumer protection regulations, and mandatory data breach reporting rules set out in the Privacy Act 1988.
- Marketing and Promotional Communications: With your explicit, opt-in consent (in full compliance with the Spam Act 2003), we may send you promotional emails or SMS alerts about new product launches, exclusive discounts, flash sales, and loyalty program updates. You retain the right to unsubscribe from all marketing communications at any time, free of charge, by clicking the “unsubscribe” link included at the bottom of every marketing email, or by sending a removal request to our contact email listed above. We will never process your marketing preferences via pre-ticked consent checkboxes, as this practice is prohibited under Australian anti-spam regulations.
- Fraud Prevention and Security Risk Mitigation: To detect, investigate, and prevent fraudulent payment activities, unauthorised account access, scam attempts, and other malicious behaviours that may threaten the security of our platform, our customers, or our business operations.
- Product and Service Improvement: To conduct anonymised statistical analysis of customer purchasing trends, identify high-demand product categories, optimise our inventory management system, and develop new features for our website that better align with the needs of our user base.
4. When We Disclose Your Personal Information
We will never sell, rent, or lease your personal information to unrelated third parties for their independent marketing purposes without your explicit written consent. We may only share your personal information with carefully selected third parties under the following strictly limited circumstances:
- Authorised Service Providers: We disclose necessary information to trusted third-party vendors who perform critical operational functions on our behalf, including:
- Courier and logistics partners, who require your delivery name, address, and contact phone number to complete product shipment.
- PCI-compliant payment processing providers, who handle your transaction details to process payments securely.
- Cloud hosting service providers, who store our website and customer data on secure servers located in jurisdictions that meet Australian privacy protection standards.
- Website analytics and marketing automation platforms, who process de-identified or pseudonymised usage data to help us analyse website performance.
- IT maintenance and cybersecurity service providers, who access limited system data to resolve technical faults and protect our platform from cyber threats.
All our third-party service providers are bound by strict data protection agreements that require them to uphold the same level of privacy protection as required by Australian law, and prohibit them from processing your personal information for any purposes outside the scope of the services they deliver to us.
- Legal and Regulatory Requirements: We may disclose your personal information if we are required to do so by a valid court order, government regulatory direction, or other legally binding request from an Australian law enforcement, tax, or regulatory authority. We may also disclose your information to enforce our website Terms and Conditions, protect our legal rights, property, or safety, as well as the rights, property, and personal safety of our staff, customers, or members of the general public.
- Business Transfer Transactions: In the event of a merger, acquisition, full or partial sale of our business assets, or corporate restructuring, your personal information may be transferred to the successor entity as part of the business transaction. We will give you reasonable advance notice of any such change of ownership that would materially alter the terms of this Privacy Policy.
5. Cross-Border Transmission of Personal Information
As an Australian-based e-commerce business, we take reasonable steps to ensure that any personal information of Australian customers that is transmitted outside of Australian territory receives a level of protection that meets the standards set out in the Australian Privacy Principles. Before transferring your personal information to an overseas jurisdiction, we will conduct a full risk assessment of the data protection laws and practices in that destination country, to verify that they provide an adequate level of privacy protection comparable to Australia’s regulatory requirements.
We do not transfer your personal information to overseas entities without putting in place enforceable and legally binding data protection safeguards, which may include standard contractual clauses approved by the Office of the Australian Information Commissioner (OAIC), or other recognised certification frameworks that ensure secure data handling. You retain all your statutory rights under Australian privacy law even when your personal information is processed by an overseas third party, and you will still be able to submit access, correction, or deletion requests for your personal information as outlined in this policy.
6. Data Security Measures
In compliance with the requirements of the Privacy Act 1988, we implement all reasonable technical and organisational security measures to protect your personal information against unauthorised access, modification, disclosure, loss, destruction, or misuse. Our security framework includes:
- Industry-standard end-to-end encryption for all data transmitted between your browser and our website, using TLS 1.3 protocols, alongside AES-256 encryption for all stored personal information held on our secure servers.
- Strict role-based access control policies, where only a limited number of authorised staff members who require access to your information to perform their job duties are granted permission to access your personal data, and all access activities are logged and audited on a regular schedule.
- Regular cybersecurity vulnerability assessments, penetration testing, and security awareness training for all our staff who handle customer personal information.
- A documented, regularly tested data breach response plan that sets out clear procedures for identifying, containing, investigating, and remediating any potential data security incident.
In the event that we experience an Eligible Data Breach that is likely to cause serious harm to you, we will immediately notify the OAIC as required under the Notifiable Data Breaches scheme, and provide prompt notification to all affected individuals with clear guidance on the steps they can take to protect themselves from potential harm.
7. Data Retention Period
We will only retain your personal information for as long as it is strictly necessary to fulfil the legitimate purposes for which the information was originally collected, including to complete any ongoing transactions you have with our website, meet our legal tax and commercial record-keeping obligations, resolve disputes, and enforce our contractual agreements. Once your personal information is no longer required for these stated purposes, we will securely delete, anonymise, or permanently destroy the information in a manner that prevents any unauthorised reconstruction or re-identification of the associated individual. For standard e-commerce transaction records, we typically retain relevant information for a period of 7 years following the completion of your order, to comply with Australian federal tax record-keeping requirements.
8. Your Rights Under Australian Privacy Law
Under the Privacy Act 1988, you hold a set of enforceable rights in relation to your personal information that we hold, including:
- Right of Access: You may submit a formal request to us to receive a copy of all personal information we currently hold about you, at no cost for standard access requests. We will respond to your access request within 30 calendar days of receiving your request, and verify your identity before releasing any personal data to you.
- Right to Correction: If you find that any personal information we hold about you is inaccurate, incomplete, out of date, or misleading, you may request that we correct the relevant data without unreasonable delay.
- Right to Withdraw Consent: You may withdraw any previously provided consent for us to process your personal information at any time. The withdrawal of consent will not affect the lawfulness of any processing activities that we carried out with your consent prior to the date of withdrawal.
- Right to Data Erasure: You may request that we delete your personal information in circumstances where the information is no longer necessary for the original purposes for which it was collected, or where you have validly withdrawn your consent to the processing, and no overriding legal obligation requires us to retain the relevant information.
- Right to Lodge a Complaint: If you believe that we have not handled your personal information in compliance with this Privacy Policy or Australian privacy law, you may submit a formal complaint to our privacy officer via the contact details listed earlier in this document. We will respond to your complaint within a maximum of 30 days. If you are not satisfied with the outcome of our internal complaint resolution process, you may escalate your complaint directly to the Office of the Australian Information Commissioner (OAIC).
9. Updates to This Privacy Policy
We may revise and update this Privacy Policy from time to time to reflect changes to our business operations, new legal or regulatory requirements, or updates to our data processing practices. When we make material changes to this policy, we will update the “Effective Date” at the top of this document, and publish a clear notice on the homepage of www.givonishop.com to inform you of the upcoming changes before they come into effect. Your continued use of our Services after the revised policy takes effect will constitute your acknowledgement and acceptance of the updated terms.