C1. Overview
Tanoshi Michi Pty Ltd (trading as Tano Spirits) (ABN: 24 675 881 375 | ACN: 675 881 375) is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs") contained in Schedule 1 of that Act. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in connection with the operation of www.tanospirits.com and the sale of alcohol under Licence No. 32812217.
By providing personal information to us, accessing our Website, or creating an account, you consent to our collection, use, and disclosure of your personal information as described in this Privacy Policy.
C2. What Personal Information We Collect
We may collect the following categories of personal information:
Identity and Contact Information
- Full name
- Date of birth (for age verification purposes)
- Email address
- Phone number
- Delivery and billing address
Account Information
- Username and password (encrypted)
- Account preferences and settings
- Purchase history and wishlist items
- Communication preferences
Transaction and Payment Information
- Order history and details
- Payment method type (we do not store full card numbers)
- Transaction records
- Billing information
Technical and Usage Information
- IP address and approximate location
- Browser type and version
- Device type and operating system
- Pages visited and time spent on the Website
- Referring website or source
- Cookies and tracking data (see Part H)
Age Verification Information
- Date of birth declaration
- Identity document details where required for verification
- Age verification check records and timestamps
C3. How We Collect Personal Information
We collect personal information in the following ways:
- Directly from you when you create an account, place an order, contact us, or fill in forms on our Website
- Automatically through cookies, web beacons, and analytics tools when you use our Website (see Part H)
- From third-party age verification providers where applicable
- From payment processors and delivery partners in connection with order fulfilment
- From publicly available sources where permitted by law
C4. Why We Collect and Use Personal Information
We collect and use your personal information for the following purposes:
Primary Purposes
- Processing and fulfilling your orders
- Verifying your age in compliance with our licensing obligations
- Managing your account and preferences
- Communicating with you about your orders, enquiries, and complaints
- Processing payments and preventing fraud
- Complying with our legal and regulatory obligations under the Liquor Control Reform Act 1998 (Vic) and other applicable laws
Secondary Purposes (with your consent or where permitted by law)
- Sending you marketing communications about our products and promotions
- Conducting customer surveys and market research
- Improving our Website and customer experience
- Analytics and business intelligence
- Personalising your experience on our Website
You may opt out of receiving marketing communications at any time by clicking the unsubscribe link in any email or by contacting us directly.
C5. Disclosure of Personal Information
We may disclose your personal information to the following categories of recipients:
Service Providers and Business Partners
- Payment processing companies (for transaction authorisation)
- Delivery and logistics providers (for order fulfilment)
- Age verification service providers
- IT service providers, website hosting, and cloud storage providers
- Marketing and analytics platforms
- Customer service platforms
Legal and Regulatory Bodies
- Victoria Police or other law enforcement agencies where required by law or court order
- The Victorian Commission for Gambling and Liquor Regulation (VCGLR) or its successors where required under our licence
- The Office of the Australian Information Commissioner (OAIC) where required
- Other government agencies as required by applicable law
We will not sell, rent, or trade your personal information to third parties for their own marketing purposes. Where we disclose personal information to service providers, we require them to protect the information in a manner consistent with this Privacy Policy and applicable law.
C6. Overseas Disclosure
Some of our third-party service providers may be located or store data outside Australia. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information. By using our Website, you consent to the potential transfer of your information overseas in connection with the services we use, subject to our safeguards.
C7. Data Security
We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, misuse, alteration, or disclosure. These measures include:
- SSL/TLS encryption for data in transit
- Encryption of sensitive data at rest
- Password hashing using industry-standard algorithms
- Access controls and authentication requirements for staff
- Regular security assessments and updates
- Secure payment processing through PCI-DSS compliant payment providers
Despite these measures, no data transmission over the internet or electronic storage system is completely secure. We cannot guarantee absolute security of your data. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
C8. Data Retention
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:
- Transaction and order records are retained for a minimum of 7 years for tax and compliance purposes
- Age verification records are retained for 3 years or as required by our licence conditions
- Account information is retained while your account is active and for a reasonable period thereafter
- Marketing consent records are retained until withdrawn plus 3 years
- Security and access logs are retained for up to 2 years
When personal information is no longer required, we will securely destroy or de-identify it.
C9. Your Privacy Rights
Under the Privacy Act and the APPs, you have the following rights:
Right of Access
You have the right to request access to the personal information we hold about you. We will respond to access requests within 30 days. There is no fee for making a request, though we may charge a reasonable fee for providing access if the request involves significant effort.
Right to Correction
If you believe personal information we hold about you is incorrect, incomplete, or out of date, you may request that we correct it. We will take reasonable steps to correct information that we agree is inaccurate.
Right to Opt Out of Direct Marketing
You have the right to opt out of receiving direct marketing communications at any time. You can do this by clicking the unsubscribe link in any marketing email, updating your account preferences, or contacting us directly.
Right to Make a Complaint
If you believe we have breached your privacy rights, you may lodge a complaint with us using the contact details in Part J. We will investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
C10. Privacy of Minors
Our Website is not directed at children under the age of 18. We do not knowingly collect personal information from persons under 18 years of age. If we become aware that we have inadvertently collected personal information from a person under 18, we will take steps to delete that information promptly.
C11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the effective date. We encourage you to review this policy periodically. Continued use of the Website following any changes constitutes your acceptance of the updated policy.