logo
NSW Privacy Policy

NSW Privacy Policy

The purpose of this policy is to outline the privacy practices of the St Vincent de Paul Society NSW (the Society) including how we collect and manage personal information and how individuals may access and correct records containing their personal information or make a complaint about a breach of privacy.

Download a PDF copy of the St Vincent de Paul Society NSW Privacy Policy here. 

1. Structure of the St Vincent de Paul Society

The St Vincent de Paul Society in Australia (‘the Society’) is a member of an international confederation. In Australia, the Society governs itself using a federated model, through St Vincent de Paul Society National Council of Australia Incorporated (National Council), six State councils (including NSW) and two Territory councils.

The National Council’s Privacy Policy https://www.vinnies.org.au/national-council/privacy-policy applies to National Council and the national website at www.vinnies.org.au

When a person accesses a State or Territory website, away from the main (national) site, or interacts with a State or Territory council or any of their subsidiary entities, then the relevant jurisdictional privacy policy will apply.

The St Vincent de Paul Society NSW carries out the good works of the Society in NSW.
In this Privacy Policy, “we”, “us” or “our” refers to St Vincent de Paul Society NSW.

2. Scope of this Policy

This Privacy Policy applies when a person interacts with us or any of our members, volunteers or employees, including for in-person assistance or support, shopping in one of our retail stores, accessing a NSW-specific website (such as a fundraising portal which we have set up in relation to a charitable appeal) or accessing our online retail store at vinniesfinds.com.au.


This Policy does not apply to the Personal Information of employees. If you are an employee, please contact our People and Culture team for more information about your privacy.

3. Policy principles

We recognise the importance of, and are committed to, protecting an individual’s dignity including their rights in relation to their Personal Information.


We are subject to the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and other Federal and State laws that protect specific types of information in service delivery, to children, older people and people with disability.

We take all reasonable steps, including using appropriate language and modes of communication, to ensure that all individuals understand their rights to privacy and confidentiality and that they understand the types of, and reasons for, the collection, use, storage and disclosure of Personal Information.

4. What is Personal Information?

Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in a material form or not.


Sensitive information is a type of Personal Information and includes health information, genetics, race, political opinion or membership, religion, philosophical beliefs, union membership, sexual preference and criminal record.


Health information includes:

  • information about physical or mental health or a disability an individual has had at any time
  • an individual’s express wishes about future provision of health services to him or her
  • any health service that has been or is to be provided to an individual
  • any Personal Information collected to provide or in the course of providing a health service
  • information collected in connection with a donation or intended donation of body parts, organs or body substances
  • genetic information that is or could be predictive of health at any time of the individual or a relative of the individual and healthcare identifiers.

5. What kind of Personal Information do we collect? 

We may collect Personal Information about you when you contact us, apply for a job or volunteer position, make a donation, use our services, interact with our online store or join our mailing list.


Depending on the circumstances, the type of information we collect may include (but is not limited to):

  • your name and date of birth
  • your contact details, such as home and email addresses, and telephone number
  • information about your personal circumstances (e.g: marital status, gender, job title, household and living circumstances information, financial information and relevant information about your partner and children)
  • information about your background (e.g: ethnicity, languages spoken, professional or vocational background, medical history, health and disability information including immunisation history)
  • payment information, such as your bank or credit card details (however we do not retain these details after a transaction is complete)
  • identification numbers, should you engage us to assist you with any NDIS, Services Australia or other personal management services
  • photographs or video footage (where your identity is clear or can be reasonably ascertained from the relevant image) and, subject to applicable law, information generated by surveillance devices used in connection with our services and stores (for example, CCTV operated in our premises).
  • delivery address details for an online purchase, as well as any delivery instructions and your signature on delivery
  • profile information such as your customer ID, preferences (e.g: about your preferred size, type of clothing, designer etc)
  • information you provide in free text fields, such as reasons for returning a purchased product, or any information you enter when interacting with our online store chatbot
  • details about any consents you have provided to receive marketing communications
  • information about your use of websites operated by or for us, collected by cookies1, including behavioural information about how, and from where, you interact with our sites and what products and services you may be interested in, as well as details about the devices used to access our websites.
  • when you create an account with us, place an order with us, or visit our website, we may collect limited Personal Information from third parties that we engage to help us deliver our products and services, such as our shipping partners.

In some circumstances, we may collect sensitive information in relation to individuals, including health information. For example, we may collect sensitive information when we provide assistance such as facilitating arrangements with, or on behalf of, individuals for financial assistance, accommodation, community engagement, medical or mental health assistance. We will collect sensitive information only with your consent and where you provide such information voluntarily or otherwise as authorised by law.

We may also collect Personal Information, including sensitive information, in relation to visitors to our offices or other business premises, but only as permitted or required by law.
If you do not provide certain Personal Information to us, then we may not be able to provide some or all of the requested services to you (or information about those services) or engage with you in connection with the good works that we do.

From time to time, we may also receive unsolicited information, being information that we have not taken active steps to collect. Examples include misdirected mail, unsolicited employment applications and promotional flyers containing Personal Information.

When we receive such information, we will decide within a reasonable period whether we could have collected it pursuant to the requirements in the APPs. If we determine that we could not have collected the information, we will destroy or de-identify it as soon as practicable. Alternatively, if we determine that we could not have collected the information and wish to retain it, we will deal with this information in accordance with our obligations under the APPs.

6. How do we collect Personal Information?

We collect Personal Information directly from the individual unless it is unreasonable or impracticable to do so. We may also collect Personal Information from publicly available sources.


Subject to the individual providing consent, or where permitted under applicable law, Personal Information may sometimes be collected from third parties such as a carer, guardian, advocate or other representative. If this is the case, then we will take reasonable steps to notify you of the circumstances for collection, as soon as practicable.


We may receive Personal Information from third parties who are engaged to provide limited information for marketing and fundraising purposes. Individuals may opt out of further contact by these third parties at any time.


Where possible, individuals may choose to interact anonymously with us, or use a pseudonym, however this may not always be possible, in particular when seeking certain assistance or support services from us.


If we seek Personal Information from an individual who requires assistance to provide the information directly, we will take the necessary steps to explain the individual’s right to privacy and to obtain consent in an accessible format.

7. How do we use and disclose Personal Information?

The purposes for which we collect, use and disclose Personal Information are to:

  • provide, administer, improve and personalise our services and goods
  • process donations and payments for the purchase of products
  • identify and verify the identity of individuals
  • assess applications for support or assistance
  • provide support and assistance to those in need
  • assess employee or volunteer applications
  • conduct surveys and research
  • protect our lawful interests or to comply with relevant law, for example workplace health and safety laws or our reporting obligations in relation to funding of our services
  • allow you to create a customer account
  • arrange for the delivery or returns of products
  • respond to your queries or concerns, including about returns and refunds

In addition, where you opt in to receiving marketing or other communications from us, we will use your Personal Information to send you emails or SMS with our monthly newsletter, letting you know about other products, services or opportunities that may be of interest to you. You can unsubscribe from these communications at any time.

We may also collect, use and disclose Personal Information in connection with lawful information requests from courts, government agencies and lawyers and in connection with legal proceedings or suspected fraud, misconduct or unlawful activity.

The Society’s national website uses geographical directing when website users wish to make a monetary donation. When people donate money to the Society, they are directed to the various web-based donation platforms that are offered by each State and Territory. When donating money in NSW, the Personal Information entered on the website is collected and stored by us in accordance with this Privacy Policy.

8. How do we hold and secure personal information?

We handle and store Personal Information electronically and in hard copy form, with data secured either at our own premises or remotely.


We may contract third parties to carry out services in connection with the primary purpose for which we collect Personal Information and, in doing so, those third parties may collect Personal Information, including through external software, and save Personal Information at their own physical premises or off-site.


In all instances, a range of measures are implemented to protect the Personal Information from misuse, interference, loss and unauthorised disclosure. Personal Information in electronic form is stored in electronic databases that require passwords and logins. Personal Information in hard copy is kept physically secure.


We take reasonable steps to destroy or de-identify Personal Information where it is no longer needed for a permitted purpose.

9. How do we disclose personal information?

Depending on the nature of your relationship with us, your Personal Information may be disclosed to certain third parties for the purposes outlined in section 7 above, including the following:

  • Contactors, service providers and suppliers which provide goods or services to us
  • Funders
  • Regulators
  • Other charities, not-for-profit organisations and data co-ops in connection with fundraising activity, and
  • Affiliated entities, for example in connection with the Society’s national fundraising campaigns.

Our third-party service providers who may handle Personal Information in connection with our online retail store are described below:

  • Shopify: your Personal Information may be handled by our online store partner. You can access their Privacy Policy at https://www.shopify.com/au/legal/privacy
  • Shipping partners: we may share your Personal Information with our shipping partner, Australia Post to help fulfill your order and process returns. Their Privacy Policies, are available at https://auspost.com.au/privacy and https://www.shippit.com/privacy-policy
  • Chatbot service provider: when you use Chatbot service in our online store, any Personal Information you provide will be handled by our Chatbot service provider, Gorgias. You can access their Privacy Policy at https://www.gorgias.com/legal/privacy
  • Marketing partner: when you opt in to receive marketing communications, we will share your Personal Information with our marketing service partner, who helps us send our communications. You can access their Privacy Policy at https://www.klaviyo.com/legal/privacy/privacy-notice
  • Order management provider: when you place an order, we will share your Personal Information with the provider of our order management system, SKUSavvy. You can access Privacy Policy at https://www.skusavvy.com/privacy-policy

If you pay by credit card to purchase an item from us or donate to us, your payment information is not held by us. It is collected and handled by our third-party payment processors who specialise in the secure online capture and processing of credit and debit card transactions

See also section 10 in relation to our online presence, below.

Overseas Disclosures:

Some of the third parties that we use to help us provide you with our products and services are located or have data storage facilities overseas. This means your Personal Information may be transferred to or held in overseas locations, including the USA, UK, European Union and Canada.

We will ensure that any disclosure of Personal Information to third parties overseas, is done in compliance with Australian privacy laws.

10. Our online presence

We engage external data aggregators including Facebook and Google Analytics to identify individuals who may be interested in our campaigns, activities and retail store based on their interaction with our websites. We use Google Analytics to inform and optimise content based on an individual’s past visits to our websites. Google Analytics provides us with information about how visitors use our websites based on their browsing habits, so that we can improve our websites, and make it easier to find information. Google also receives this information as individuals browse our websites and other websites on the Google Display Network using Remarketing. Individuals can opt-out of customised Google Display Network services and Google Analytics for Display Advertising using ad settings and can use the Google Analytics Opt-out Browser Add-on to not be tracked by Google Analytics.

Subscribers to mailing lists will be given an option to opt out of receiving further information or correspondence in accordance with the Spam Act 2003 (Cth).
Information on visitors to our websites, such as IP addresses, date and time of visit, pages accessed and any information downloaded, may be recorded and used for statistical, reporting, website administration, security and maintenance purposes.

Any Personal Information sent through our websites or by other electronic means may be insecure in transit, particularly where no encryption is used (for example email or standard HTTP) and is transmitted at the individual’s own risk.

When we send emails or other electronic messages, we may record where the message was opened and what links were clicked to better understand what information is of interest to the viewer.

Where our websites allow individuals to make comments, give feedback or make a credit card payment, we may collect email addresses and other contact details. We may use email addresses provided to respond to feedback and, on occasion, to make direct contact for surveying purposes and ongoing communication.

Our websites may contain links to other sites operated by third parties. Third party websites are responsible for informing you about their own privacy practices and we are not responsible for the privacy practices or policies of those third-party sites.

11. How to request access or an amendment to your personal information, or make a complaint

An individual may formally request access to their Personal Information held by us at any time.

An online store account holder can make a request to access their data directly from Shopify here: https://privacy.shopify.com/en/dsr_submission/subject_types?selected=access

If an individual has any queries or concerns about the Personal Information that may be stored by the Society or they wish to access or correct any of the Personal Information that may be held about them, they can make a request using the contact details below:

Privacy Officer

St Vincent de Paul Society NSW
Email: privacy@vinnies.org.au  
Post: PO Box 5, Petersham NSW 2049
Telephone: (02) 9568 0262

We will need to verify an individual’s identity before a response can be prepared.

When making an access or correction request, individuals are asked to provide details of the particular information being sought, to assist in locating the information.

We may also charge a fee in certain circumstances however, if this is the case, we will first notify you of the fee and provide an explanation for it.

We take privacy concerns very seriously. Where an individual expresses any concerns that we have interfered with their privacy, we will respond to let them know who will be handling their complaint and when they can expect a further response (generally within 30 days after a complaint has been received and acknowledged). Complaints will be handled in accordance with our Feedback and Complaints Policy https://www.vinnies.org.au/media/nudl4atg/feedback-and-complaints-policy.pdf

For information about privacy generally, or if an individual has any concerns about how we have resolved a complaint regarding their Personal Information, individuals can contact the Office of the Australian Information Commissioner:

Website: www.oaic.gov.au
Post: GPO Box 5218, Sydney NSW 2001
Email: enquiries@oaic.gov.au 

 

12. Amendments to this Policy

We will publish and update this Policy on our website (www.vinnies.org.au/nsw and www.vinniesfinds.com.au) and will make available a copy of this Policy on request.

 

Share this page