Privacy Policy

Where’s Nick (trading as Goblin Wine Shop)
Last updated: 11/01/2026

Where’s Nick (trading as Goblin Wine Shop) and its related bodies corporate (as defined in the Corporations Act 2001 (Cth)) (we, us, our) is committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy explains how we collect, hold, use and disclose personal information, including through our website www.goblinwineshop.com.


What is personal information?

“Personal information” has the meaning given in the Privacy Act. It is information or an opinion about an identified individual, or an individual who is reasonably identifiable.


What personal information we collect

We may collect and hold the following types of personal information:

  • your name, phone number, email address and postal address;

  • demographic information such as postcode and date of birth (where required for age-restricted sales);

  • details of products and services you purchase from us and any enquiries you make;

  • your preferences, feedback and marketing interactions;

  • information about how you access and use our website; and

  • if you apply for a role with us: your employment history and qualifications.

Payment information:
We use Shopify and its integrated payment providers to process transactions. We do not store your full credit card or debit card details. Card data is handled securely by Shopify and its payment gateways in accordance with their security and PCI-DSS standards.

We may also collect other personal information where permitted or required by law.


How we use your personal information

We collect, hold, use and disclose personal information for purposes including:

  • to provide and deliver our products and services;

  • to process orders, payments, refunds and customer support;

  • to communicate with you, including responding to enquiries;

  • for analytics and business improvement;

  • for direct marketing (where permitted by law);

  • to understand how our website is used;

  • to comply with legal obligations; and

  • to assess employment or contractor applications.

You may opt out of direct marketing at any time using the unsubscribe function in our communications or by contacting us.


Who we disclose personal information to

We may disclose personal information to:

  • Shopify (our e-commerce platform and hosting provider);

  • payment processors used by Shopify for transaction processing;

  • Klaviyo (for email and SMS marketing, customer segmentation and analytics);

  • service providers who assist our operations (e.g. couriers, IT providers, website hosts);

  • professional advisers (accountants, insurers, lawyers);

  • marketing and analytics providers;

  • any third party you authorise us to disclose information to;

  • potential buyers and advisers in connection with a business sale or restructure; and

  • regulators or law enforcement where required or authorised by law.

We take reasonable steps to ensure third parties handle personal information in a manner consistent with the Privacy Act.

We may also use and share aggregated or de-identified data that does not identify individuals.


Overseas disclosure of personal information

Shopify, Klaviyo and some analytics and advertising providers store or process data outside Australia (including in the United States and other jurisdictions).

Where personal information is disclosed overseas, we take reasonable steps to ensure it is handled in accordance with the Australian Privacy Principles or as otherwise permitted by law.


How we collect personal information

We collect personal information when you:

  • place orders or interact with us through our Shopify website;

  • subscribe to communications, promotions or loyalty programs (including via Klaviyo);

  • contact us by phone, email or in person;

  • apply for employment or contracting roles; or

  • interact with us through third parties (e.g. when someone orders a product for you).

We may also collect information from publicly available sources where lawful.


Cookies and tracking technologies

We use cookies and similar technologies to operate our website and improve marketing and analytics. This may include tools integrated with Shopify and Klaviyo, as well as services such as Google Analytics and advertising pixels.

Cookies do not usually identify you personally but may identify your device or browser. You can manage cookies through your browser settings. Disabling cookies may affect website functionality.


Data security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. This includes:

  • using secure systems and reputable service providers (including Shopify); and

  • limiting access to personal information to authorised staff and service providers.

No system is completely secure. If you believe your information has been compromised, please contact us immediately.


Data breaches

We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act.
If we become aware of a suspected data breach, we will assess it promptly and, where required, notify affected individuals and the Office of the Australian Information Commissioner (OAIC).


Retention of personal information

We retain personal information only for as long as necessary for the purposes for which it was collected or as required by law. When no longer required, we take reasonable steps to destroy or de-identify the information.


Access and correction

You may request access to personal information we hold about you and request corrections if you believe it is inaccurate, out of date or incomplete. We will respond in accordance with the Privacy Act and may require verification of identity.


Complaints

If you have a complaint about how we handle your personal information, please contact us. We will investigate and respond in a timely manner. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).


Employee records

Where applicable, we rely on the employee records exemption under the Privacy Act in relation to personal information about current and former employees. This exemption does not apply to job applicants, contractors or customers.


Contact details

Where’s Nick (Goblin Wine Shop)
Address: 234 Marrickville Road, Marrickville NSW
Email: julian@wheresnick.com.au


Changes to this policy

We may update this policy from time to time. The current version will always be available on our website.