This policy explains what personal information Perfume Gang collects, why we collect it, who we share it with, and what you can ask us to do about it. We have written it in plain language rather than legal boilerplate, because a policy you cannot understand protects nobody.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and we honour the marketing consent and unsubscribe obligations in the Spam Act 2003 (Cth). Where you contact us from the European Union or the United Kingdom, we also respect the rights described in the GDPR and UK GDPR.
Who we are
Perfume Gang is a fragrance studio and membership operating from South Australia, trading at perfumegang.com. In this policy, “we”, “us” and “our” mean Perfume Gang. We are the entity responsible for the personal information described here.
For anything in this policy, write to [email protected].
What we collect
Information you give us
- Your name and email address, when you join the membership, register in the member portal, enter the founding-perks wheel, or ask to be told when something opens.
- A password, if you create a portal account. We never store your password itself — only a salted cryptographic hash of it (PBKDF2-SHA256, 100,000 iterations), which cannot be reversed back into your password.
- Your founding perk, if you spun the wheel, and who referred you, if you arrived through another member’s invitation link.
- Anything you write to us by email.
Information created by your membership
- Your member number, the date you joined, your membership status and level, and whether the Composer is open to you.
- How many members you have referred, so referral rewards can be credited.
Information you create in the Composer
- Your formulas — ingredient names, weights, dilutions, versions and bench notes — along with your personal ingredient list, any IFRA limits you load, and your practice exercises.
- Most of this is stored in your own browser and never leaves your device. If you are signed in as a member, your formula library and ingredient memory are also saved to your account so they follow you between devices. IFRA limits and practice records currently stay on the device only.
- Your formulas are yours. We do not read them, mine them, sell them, or use them to make our own perfumes.
Information collected automatically
- Campaign information — where a link brought you from, such as an advertisement identifier or campaign tag in the web address, so we can tell which advertising is worth continuing.
- Technical information handled by our hosting provider in the ordinary course of serving the site, including your IP address, browser type and the pages you requested.
- Analytics and advertising events through the Meta Pixel, described below.
Cookies and similar technologies
Our own cookie. When you sign in, we set a single cookie named pg_member. It holds a signed token that keeps you logged in for thirty days. It is marked HttpOnly, Secure and SameSite=Lax, meaning it cannot be read by scripts and is not sent to other sites. It contains no personal information beyond the identifier of your session. It is strictly necessary for the member area to work.
Browser storage. We keep some things in your browser’s local storage rather than in cookies — your Composer drafts and library, your ingredient memory, IFRA limits, practice records, bench theme, referral credit and signup details. You can clear all of it at any time through your browser’s settings, though doing so will delete any Composer work not synced to your account.
Meta Pixel. We use the Meta (Facebook) Pixel to measure our advertising. It records when you view a page, when you join, when you complete a registration, and when you choose to follow us on a social platform. Meta may set its own cookies and may combine this with information it already holds about you if you have a Meta account. We do not send Meta your name, email address or any Composer content. You can limit this through your Meta ad preferences, your browser settings, or a tracking blocker.
Fonts. Our pages load typefaces from Google Fonts, which means Google receives your IP address when a page loads.
Why we use your information
- To create and run your membership, including striking your member number and opening the Composer to you.
- To send you the monthly reveal, membership news, and messages about your account.
- To credit referrals and honour founding perks.
- To measure and improve our advertising, our site and our writing.
- To keep the service secure and to prevent misuse.
- To meet our legal obligations.
Where the GDPR applies, our lawful bases are your consent (marketing), performance of a contract (running your membership), and our legitimate interests (security, and measuring our own advertising).
Who we share it with
We do not sell your personal information. We never have and we will not. We do rely on a small number of service providers to operate, and your information passes through them:
- Cloudflare — hosts the site and stores member records.
- GoHighLevel (LeadConnector) — our customer relationship system, which stores your contact record and delivers our emails. It records when our emails are opened and when links in them are clicked.
- Meta Platforms — advertising measurement, as described above.
- FormSubmit — relays signup notifications to our own studio inbox.
- Google — serves the typefaces used on the site.
We may also disclose information where the law requires it, where it is necessary to protect our rights or someone’s safety, or to a purchaser if the business is ever sold — in which case this policy would continue to apply to information collected before the sale.
Information sent overseas
The providers listed above are based in, or store data in, the United States and other countries. This means your personal information is disclosed outside Australia. We take reasonable steps to use established providers who commit to appropriate protections, but the laws of those countries may differ from Australian law, and by using the site you consent to this disclosure.
Marketing, and how to stop it
We only send marketing email to people who asked for it by joining. Every marketing email we send identifies us and carries a working unsubscribe link, as the Spam Act requires. Unsubscribing takes effect promptly and costs you nothing.
You can also simply reply to any email, or write to [email protected], and ask to be removed. We will still send you essential messages about your account, such as a password reset you requested.
How we protect it
The site is served entirely over an encrypted connection. Passwords are salted and hashed and are never stored or transmitted in readable form. Session cookies are signed, so they cannot be forged. Access to member records and to our administrative tools is restricted to the studio and protected by secret keys held outside the codebase.
No system is perfectly secure, and we cannot guarantee absolute security. We do commit to acting quickly if something goes wrong.
How long we keep it
We keep your membership information for as long as you are a member, and for a reasonable period afterwards to meet record-keeping and tax obligations. If you ask us to delete your account, we will remove your personal information within a reasonable time except where we are legally required to retain it. Anonymous or aggregated information that cannot identify you may be kept.
Your rights
You may ask us to:
- Show you the personal information we hold about you.
- Correct anything inaccurate or out of date.
- Delete your account and personal information.
- Stop sending you marketing.
- Give you a copy of the information you provided, in a portable form, and (in the EU and UK) restrict or object to certain processing.
Write to [email protected]. We will respond within a reasonable time, ordinarily within 30 days. We may need to confirm who you are first. There is no charge for making a request.
Children
Perfume Gang is not intended for children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, tell us and we will delete it.
If something goes wrong
If a data breach occurs that is likely to result in serious harm, we will notify affected members and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Other sites
Our pages link to places we do not control — social platforms, the IFRA Standards Library, and others. Their privacy practices are their own, and we encourage you to read them.
Changes to this policy
We will update this policy as the studio grows, particularly once we begin selling and shipping. The date at the top always shows the current version. If a change materially affects how we handle your information, we will tell members by email rather than quietly editing the page.
Questions and complaints
Write to [email protected] and we will do our best to put things right.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in the EU or UK, you may complain to your local data protection authority.