Privacy policy
What we collect from grown-ups, why, and how to get it back or have it deleted.
Last updated 1 July 2026
Who we are
Olli & Waffle is a children’s entertainment and family lifestyle business based in Australia. We are the data controller for the information described here.
What we collect from adults
If you create a family account or buy something, we collect:
- Your first name and surname
- Your email address
- Your mobile number, used only to verify you are a real adult and for account security
- A hashed password — we never store the password itself
- Delivery and billing addresses
- Order history
- Your marketing and privacy preferences, and a record of the consents you have given
Payment information
We never see or store your card details. Payment is taken on Stripe’s own hosted page. We receive only a confirmation that payment succeeded, the amount, and the last four digits for your receipt.
Why we are allowed to hold it
Contract — to take and deliver your order. Legal obligation — to keep tax records. Consent — for the newsletter and for optional analytics, both of which you can withdraw at any time. Legitimate interests — to keep the site secure and prevent fraud.
How long we keep it
The full retention schedule is published in the grown-ups’ corner. In summary: order records for seven years because Australian tax law requires it; analytics for fourteen months and aggregated after ninety days; server logs for thirty days; everything else until you delete it.
Who else sees it
Only the services needed to run the business: our payment processor, our delivery partners, our email provider and our hosting provider. We do not sell data, and we do not share it with advertising networks — we do not use any.
Your rights
You can access, correct, export or delete your data, object to processing, and withdraw consent. Most of this is available instantly from your account dashboard. For anything else we respond within 30 days.
How we protect it
Encryption in transit, hashed passwords, strict content-security headers, rate limiting on sensitive endpoints, least-privilege access for staff, and an append-only audit log of every access to a family record.
Questions about any of this?
Write to us and a person will read it. We would rather explain something twice than have you uncertain.
Contact us