Privacy policy
Privacy Policy
Last updated: 21 July 2026
1. About this Privacy Policy
Missless operates the website located at missless.com.au and provides greeting cards, card packs, personalised card services, subscriptions, scheduled card deliveries and related products and services.
In this Privacy Policy, “Missless”, “we”, “us” and “our” refer to the operator of Missless.
This Privacy Policy explains how we collect, hold, use and disclose personal information when you:
-
visit or use our website;
-
create an account;
-
place an order;
-
purchase or manage a subscription;
-
provide information about a card recipient;
-
communicate with us;
-
subscribe to marketing communications; or
-
otherwise interact with Missless.
Our online store is hosted by Shopify, which provides the ecommerce platform that allows us to offer products and services to you.
Nothing in this Privacy Policy limits any rights or obligations that apply under Australian privacy or consumer law.
2. What is personal information?
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Depending on how you interact with Missless, we may collect personal information about:
-
customers;
-
account holders;
-
subscription holders;
-
card recipients;
-
people contacting us;
-
business customers; and
-
website visitors.
Some card messages or occasion details may contain information that is personal or sensitive in nature. We ask customers not to provide more information than is reasonably necessary to prepare and deliver their order.
3. Personal information we collect
The information we collect depends on how you interact with Missless.
Customer and account information
We may collect:
-
your name;
-
email address;
-
telephone number;
-
billing address;
-
delivery address;
-
account username;
-
account preferences;
-
login and account-management information; and
-
communication preferences.
Passwords and payment credentials may be processed and stored by Shopify or another service provider rather than directly by Missless.
Order and transaction information
We may collect:
-
products viewed or purchased;
-
cart and checkout activity;
-
order numbers;
-
payment status;
-
billing information;
-
discount or gift-card usage;
-
shipping selections;
-
order history;
-
return, refund or cancellation information; and
-
subscription plan and renewal information.
Personalisation and card information
When ordering or scheduling a card, we may collect:
-
recipient names;
-
recipient addresses;
-
recipient contact details;
-
occasion types;
-
occasion dates;
-
personal messages;
-
sender names;
-
card selections;
-
photographs or images;
-
delivery instructions;
-
custom wording; and
-
other information provided for personalisation.
This information may relate to someone other than the person placing the order.
The customer providing recipient information must have a reasonable basis for providing that information to us and must only provide information reasonably required to prepare and deliver the card.
Communications
We may collect information contained in communications with us, including:
-
customer-service enquiries;
-
emails;
-
telephone communications;
-
contact-form submissions;
-
reviews;
-
complaints;
-
feedback; and
-
social-media messages.
Website and device information
When you use our website, we or our service providers may automatically collect:
-
IP address;
-
browser type;
-
device type;
-
operating system;
-
approximate location derived from an IP address;
-
website pages viewed;
-
links selected;
-
referring website;
-
dates and times of visits;
-
shopping and browsing activity;
-
cookie identifiers; and
-
information about how you interact with our website.
Marketing information
Where you subscribe to or interact with our marketing, we may collect:
-
your email address;
-
marketing preferences;
-
whether an email was opened;
-
whether a link was selected;
-
products or occasions you have expressed an interest in; and
-
information about your response to promotions.
4. How we collect personal information
We may collect personal information:
Directly from you
This includes when you:
-
create an account;
-
place an order;
-
enter recipient information;
-
personalise a card;
-
purchase or manage a subscription;
-
complete a form;
-
contact us;
-
join our mailing list;
-
submit a review; or
-
communicate through social media.
From another customer
A customer may provide your information where they arrange for a card or gift to be prepared or delivered to you.
For example, we may receive your:
-
name;
-
delivery address;
-
occasion date; and
-
information required to personalise a card.
We use recipient information primarily to prepare and fulfil the order requested by the customer. We do not add card recipients to our marketing list merely because another person purchased a card for them.
Automatically
We may collect information automatically through:
-
cookies;
-
pixels;
-
analytics tools;
-
website logs;
-
Shopify technology; and
-
similar online technologies.
From service providers and partners
We may receive personal information from organisations that assist us with:
-
ecommerce hosting;
-
payment processing;
-
subscriptions;
-
printing;
-
fulfilment;
-
delivery;
-
analytics;
-
advertising;
-
fraud prevention;
-
customer support; and
-
website functionality.
5. Why we collect and use personal information
We may collect, hold and use personal information for the following purposes.
Processing and fulfilling orders
We use personal information to:
-
receive and process orders;
-
process payments;
-
prepare personalised cards;
-
write or print customer messages;
-
address and package products;
-
arrange shipping;
-
communicate order updates;
-
manage returns or refunds; and
-
provide customer support.
Providing scheduled card services
We may use occasion dates, recipient details and card selections to:
-
remind customers of upcoming occasions;
-
schedule card preparation;
-
prepare recurring or future cards;
-
arrange timely dispatch; and
-
manage card allowances or subscription inclusions.
Managing subscriptions
We may use personal information to:
-
establish a subscription;
-
process recurring payments;
-
manage subscription entitlements;
-
provide renewal or payment notices;
-
allow subscriptions to be paused, changed or cancelled;
-
manage failed payments; and
-
provide customer support.
Managing customer accounts
We may use personal information to:
-
create and maintain accounts;
-
remember saved preferences;
-
display order history;
-
manage saved recipient information;
-
authenticate users; and
-
protect accounts from unauthorised access.
Communicating with you
We may use your contact information to:
-
answer enquiries;
-
provide customer support;
-
send transactional notices;
-
provide order and delivery updates;
-
notify you about account or subscription matters;
-
respond to complaints; and
-
communicate important policy or service changes.
Improving our products and website
We may use information to:
-
understand how customers use our website;
-
improve website navigation;
-
identify popular products;
-
improve card designs and services;
-
troubleshoot technical problems;
-
measure website performance; and
-
develop new products or features.
Where practical, we use aggregated or de-identified information for these purposes.
Security and fraud prevention
We may use information to:
-
verify transactions;
-
detect suspected fraud;
-
protect customer accounts;
-
prevent misuse of our website;
-
investigate security incidents; and
-
enforce our Terms of Service.
Legal and administrative purposes
We may use information to:
-
maintain financial and tax records;
-
comply with legal obligations;
-
respond to lawful requests;
-
establish, exercise or defend legal claims;
-
investigate suspected misconduct; and
-
resolve disputes.
6. Card-recipient information
Customers may provide personal information about friends, relatives, employees, clients or other recipients.
We treat this information differently from customer marketing information.
Recipient information is used primarily to:
-
personalise the selected card;
-
prepare the recipient’s envelope;
-
arrange delivery;
-
resolve delivery issues; and
-
fulfil the customer’s instructions.
We do not ordinarily:
-
create a customer account for a recipient;
-
contact a recipient for unrelated marketing;
-
sell recipient contact information; or
-
use the contents of a private card message for advertising.
Recipient information may be accessed by service providers only where reasonably necessary to print, prepare, fulfil or deliver the order.
7. Personal messages and sensitive information
A customer may choose to include personal details in a card message.
Messages could potentially reveal information concerning matters such as:
-
health;
-
bereavement;
-
religion;
-
cultural background;
-
family relationships;
-
pregnancy;
-
personal beliefs; or
-
other private circumstances.
Missless does not require this information unless the customer chooses to include it as part of the requested card message.
We use the contents of personal messages only as reasonably necessary to:
-
prepare the card;
-
print or write the message;
-
provide customer support;
-
correct an error;
-
investigate a complaint; or
-
comply with a legal obligation.
We do not use private card-message content to build advertising profiles.
Customers should avoid including highly confidential information that is not necessary for the card.
8. Payments
Payments are processed through Shopify Payments or other payment providers made available at checkout.
Payment providers may collect:
-
cardholder names;
-
card numbers;
-
expiry dates;
-
security codes;
-
billing addresses;
-
bank or payment-account information; and
-
transaction details.
Missless does not ordinarily receive or retain your complete payment-card number.
Payment providers process information under their own privacy policies and security practices.
9. Marketing communications
We may send marketing communications where you:
-
consent to receive them;
-
subscribe to our mailing list;
-
would reasonably expect to receive them; or
-
where otherwise permitted by law.
Marketing may include:
-
product announcements;
-
card and occasion reminders;
-
seasonal promotions;
-
special offers;
-
abandoned-cart messages; and
-
information about Missless services.
You may unsubscribe at any time by:
-
selecting the unsubscribe link in an email;
-
updating your communication preferences where available; or
-
contacting us.
Unsubscribing from marketing does not prevent us from sending necessary transactional communications relating to:
-
an order;
-
a subscription;
-
a payment;
-
an account;
-
a delivery;
-
a refund; or
-
a customer-service enquiry.
We do not add a card recipient to our marketing list solely because a customer provided their delivery information.
10. Cookies and similar technologies
Our website and service providers may use cookies, pixels and similar technologies.
These technologies may be used to:
-
keep the website functioning;
-
remember account or cart preferences;
-
maintain website security;
-
understand website usage;
-
measure advertising performance;
-
personalise website content; and
-
show relevant advertising.
Some cookies are necessary for the website to operate. Other cookies may be used for analytics or advertising.
You may be able to manage cookies through:
-
your browser settings;
-
the cookie controls displayed on our website; or
-
applicable privacy or advertising controls.
Disabling some cookies may affect website functionality.
11. How we disclose personal information
We may disclose personal information where reasonably necessary to operate Missless and provide our services.
Shopify
Our store is hosted by Shopify.
Shopify processes information about your access to and use of our store to:
-
host the website;
-
operate the checkout;
-
process transactions;
-
maintain website security;
-
provide ecommerce features; and
-
improve its services.
Shopify may process information in Australia and other countries.
Payment providers
We disclose relevant information to payment providers to:
-
process payments;
-
manage recurring subscription charges;
-
prevent fraud;
-
process refunds; and
-
resolve payment disputes.
Printing and fulfilment providers
Where we use third parties to print, write, package or prepare cards, they may receive information necessary to complete the order, including:
-
the selected design;
-
personalisation details;
-
card messages;
-
recipient names; and
-
delivery details.
These providers are only given information reasonably necessary to provide the requested service.
Delivery providers
We may disclose recipient names, delivery addresses, contact details and delivery instructions to postal and courier providers.
Technology and support providers
We may disclose information to providers that assist us with:
-
website hosting;
-
cloud storage;
-
subscription management;
-
email communications;
-
analytics;
-
customer service;
-
fraud prevention;
-
cybersecurity;
-
database management; and
-
business administration.
Marketing and advertising providers
Where permitted, we may disclose website and customer activity information to providers that assist with:
-
email marketing;
-
advertising measurement;
-
audience creation;
-
campaign reporting; and
-
relevant online advertising.
We do not disclose private card-message content for targeted advertising.
Professional advisers
We may disclose information to accountants, lawyers, insurers, consultants or other professional advisers where reasonably necessary.
Legal and regulatory disclosures
We may disclose information where:
-
required or authorised by law;
-
required by a court or tribunal;
-
reasonably necessary to respond to a valid government request;
-
required to investigate suspected fraud or unlawful activity;
-
required to protect our legal rights; or
-
necessary to protect the safety of another person.
Business transactions
If Missless is sold, merged, restructured or transferred, personal information may be disclosed as part of that transaction, subject to reasonable confidentiality protections and applicable law.
12. We do not sell card-recipient information
Missless does not sell or rent customer or recipient contact information in exchange for money.
Some digital advertising arrangements may be described as “sharing” or “selling” under the laws of certain overseas jurisdictions, even where no money is exchanged.
Where an applicable law gives you a right to opt out of this type of advertising disclosure, you may use any privacy controls made available on our website or contact us.
13. Overseas processing and disclosure
Shopify and some of our technology, payment, marketing, printing, analytics or cloud-service providers may process or store personal information outside Australia.
The countries involved may vary depending on:
-
the provider;
-
the customer’s location;
-
the location of data centres; and
-
the services being used.
These countries may include the United States, Canada and other locations in which Shopify or our service providers operate.
Where reasonably practicable, we take steps to use reputable providers and require information to be handled securely and consistently with applicable contractual and legal requirements.
Privacy protections in another country may differ from those available in Australia.
14. Data security
We take reasonable administrative, technical and organisational steps to protect personal information from:
-
misuse;
-
interference;
-
loss;
-
unauthorised access;
-
unauthorised modification; and
-
unauthorised disclosure.
These steps may include:
-
using reputable ecommerce and payment providers;
-
limiting access to information;
-
account authentication;
-
encryption where supported;
-
secure hosting;
-
access controls;
-
software updates; and
-
internal handling procedures.
No online system, storage system or transmission method is completely secure.
Customers are responsible for:
-
keeping passwords confidential;
-
using secure devices and networks;
-
signing out of shared devices; and
-
notifying us of suspected unauthorised account access.
Please do not send complete payment-card details or other highly sensitive information through ordinary email.
15. Data retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or as required by law.
Retention periods may depend on:
-
whether you maintain an account;
-
whether you have an active subscription;
-
scheduled future occasions;
-
order and transaction history;
-
customer-service requirements;
-
fraud-prevention needs;
-
accounting and tax requirements;
-
legal claims; and
-
contractual obligations.
Order and financial records may be retained for the period required by taxation, accounting and other applicable laws.
Personalised card content and recipient information may be retained for a shorter or longer period depending on whether:
-
the card has been fulfilled;
-
the information is saved in your account;
-
the information is required for future scheduled cards;
-
a customer-service issue is unresolved; or
-
retention is legally required.
When personal information is no longer reasonably required, we may delete it, de-identify it or securely dispose of it.
16. Customer accounts and saved recipient information
Where account functionality allows you to save recipient details or occasion dates, the information may remain associated with your account until:
-
you remove it;
-
you close your account;
-
it is no longer required; or
-
we remove it under our retention practices.
You should keep saved recipient information current and remove details you no longer need.
You may contact us if you require assistance accessing, correcting or deleting saved information.
17. Access and correction
You may contact us to request access to personal information we hold about you or to request that inaccurate information be corrected.
Before responding, we may need to verify your identity.
In some circumstances, we may be unable to provide access to all requested information, including where:
-
access would unreasonably affect another person’s privacy;
-
the request is frivolous or vexatious;
-
information relates to existing or anticipated legal proceedings;
-
providing access would be unlawful; or
-
another legal exception applies.
Where appropriate, we will explain why access has been refused or limited.
We may ask you to update account or subscription information directly through the website where that functionality is available.
18. Deletion requests
You may ask us to delete personal information that we hold about you.
We will assess the request and delete or de-identify information where reasonably possible.
We may need to retain some information where required for:
-
taxation or financial reporting;
-
fraud prevention;
-
subscription or transaction records;
-
resolving disputes;
-
legal compliance;
-
enforcing agreements; or
-
establishing or defending legal claims.
Deleting information may affect our ability to:
-
maintain your account;
-
remember future occasions;
-
manage a subscription; or
-
provide scheduled services.
19. Information about another person
A customer may request access to or correction of information they supplied about a recipient.
However, we may need to consider the recipient’s privacy before disclosing:
-
private correspondence;
-
support communications;
-
information supplied by another customer; or
-
information that identifies another individual.
A recipient may contact us regarding personal information that Missless holds about them.
We may require sufficient information to identify the relevant order and verify the requester’s identity.
20. Children’s privacy
Our website and services are intended to be used by adults.
Customers may purchase cards for children or include a child’s first name, birthday or delivery information where reasonably necessary for the order.
We do not knowingly create marketing profiles for children or invite children to create accounts without appropriate adult involvement.
A parent or guardian who believes a child has directly provided personal information to us without appropriate permission may contact us to request its review or deletion.
21. Third-party websites
Our website may contain links to third-party websites, social networks or services.
Missless does not control the privacy practices of those third parties.
You should review their privacy policies before providing information to them.
A link from our website does not necessarily mean that we endorse or accept responsibility for that third party’s privacy or security practices.
22. Shopify privacy rights
Shopify may process information independently for certain platform and ecommerce purposes.
Requests relating specifically to Shopify’s independent processing may need to be made through Shopify’s privacy portal.
Information about Shopify’s practices is available in the Shopify Consumer Privacy Policy.
23. Privacy complaints
Contact us if you have a question or complaint about how we have handled personal information.
Please include:
-
your name;
-
your contact details;
-
a description of the concern;
-
relevant order or account information; and
-
the outcome you are seeking.
We will acknowledge and investigate the complaint within a reasonable period.
We may contact you for further information or to verify your identity.
Where the Privacy Act applies and you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.
24. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
-
our products and services;
-
technology;
-
Shopify functionality;
-
service providers;
-
business practices; or
-
applicable laws.
The updated version will be posted on our website and the “Last updated” date will be changed.
Where required, we will provide additional notice of material changes.
25. Contact us
For privacy enquiries, requests or complaints, contact:
Missless
www.missless.com.au/contact
ABN: 31 265 645 863