Privacy policy
Empire Home operates this store and website, including all related information, content, features, tools, products and services, in order to provide you, the customer, with a curated shopping experience (the "Services"). Empire Home is powered by Shopify, which enables us to provide the Services to you.
This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.
1. Who we are
The Services are operated by World of Empire Pty Ltd (ABN 75 676 519 047) trading as Empire Home. References to "Empire Home", "we", "us" or "our" in this Privacy Policy are references to that entity.
Empire Home is bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) set out in that Act. We are committed to handling your personal information in accordance with the APPs.
2. Personal information we collect
When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you. Personal information does not include information that is collected anonymously or that has been de-identified so that it cannot identify or be reasonably linked to you.
Depending on how you interact with the Services, we may collect or process the following categories of personal information:
- Contact details including your name, billing address, shipping address, phone number, and email address.
- Financial information including payment card details, payment confirmation, transaction history, and other payment details. Card numbers are processed by our payment providers and we do not retain full card numbers on our systems.
- Account information including your username, password, security questions, preferences, settings, and any loyalty or VIP program membership data.
- Transaction information including items you view, add to cart, add to a wishlist, purchase, return, exchange, or cancel, and your order history across our online store and our physical stores.
- Communications including the information you include in emails, customer service requests, live chat sessions, social media messages, and other contact with us.
- In-store information including information collected at point of sale or at in-store events, where you choose to provide it.
- Device and technical information including your device type, browser, operating system, IP address, language settings, and other unique identifiers.
- Usage and analytics information including pages viewed, time on site, referral source, search queries, scroll and click behaviour, and other interactions with the Services.
- Marketing consent and engagement including whether you have opted in to email, SMS or postal marketing, which campaigns you have opened, clicked, or unsubscribed from, and your communication preferences.
We may draw inferences from this information, such as product preferences, household composition, or likely interests, to tailor the Services.
3. How we collect personal information
We may collect personal information from the following sources:
- Directly from you, including when you create an account, place an order, sign up for our newsletter or SMS list, enter a competition, complete a form, contact our customer service team, visit one of our stores, or otherwise interact with us.
- Automatically through the Services, including from your device when you use our website, through cookies and similar technologies, and through pixels embedded in our marketing communications.
- From our service providers, including the platforms listed in Section 7, when they collect or process personal information on our behalf.
- From our advertising and marketing partners, including aggregated audience data from Meta and Google.
- From other third parties, including delivery and freight providers who confirm delivery, and from publicly available sources where relevant.
4. How we use your personal information
Depending on how you interact with us and which of the Services you use, we may use personal information for the following purposes:
- Providing and improving the Services. Fulfilling your orders, processing payments, arranging delivery, handling returns and exchanges, managing your account, remembering your preferences, recommending products, operating loyalty or VIP programs, conducting analytics, and improving our website, range and customer experience.
- Marketing and advertising. Sending you marketing communications by email, SMS or post; showing you online advertising on third party sites and platforms; building lookalike and retargeting audiences; and measuring the effectiveness of our marketing. Where required by law, we will only send you direct marketing communications with your consent, and you can withdraw consent at any time (see Section 8).
- Security and fraud prevention. Authenticating your account, detecting and preventing fraud, abuse, unsafe or unlawful activity, and protecting our staff, customers and systems.
- Customer communications. Responding to your enquiries, providing customer service, conducting surveys, and maintaining our relationship with you.
- Legal and compliance. Complying with our legal obligations, including tax, consumer law and product safety obligations; responding to lawful requests from regulators, courts and law enforcement; and enforcing or defending our legal rights.
5. Marketing communications (Spam Act 2003)
We send commercial electronic messages (such as marketing emails and SMS) in accordance with the Spam Act 2003 (Cth). That means:
- We only send marketing email and SMS to people who have consented to receive them, either expressly or because they are a customer with a reasonable expectation of receiving them.
- Every marketing message identifies Empire Home as the sender.
- Every marketing email contains a working unsubscribe link, and every marketing SMS contains a reply-STOP or equivalent opt-out instruction.
- Opt-outs are actioned promptly across our email and SMS systems.
You can also opt out at any time by emailing enquiries@empirehome.com.au or calling us on the number in Section 16.
6. Cookies and similar technologies
We and our service providers use cookies, pixels, tags, local storage and similar technologies on the Services. Cookies fall into the following broad categories:
- Strictly necessary cookies that the Services need in order to function, including cart, checkout, login, and security cookies.
- Functional cookies that remember your preferences, such as language or recently viewed items.
- Analytics cookies that help us understand how the Services are used, including Google Analytics. These cookies may transfer information to servers outside Australia.
- Marketing and advertising cookies and pixels, including Meta Pixel and Google Ads tags, which we use to measure campaign performance and show you relevant advertising on other sites.
You can control cookies through your browser settings, and you can opt out of analytics and targeted advertising through tools such as the Google Ads Settings, the Meta ad preferences, and the Your Online Choices site for Australia. Blocking some cookies may affect how the Services work for you.
7. How we disclose personal information
We disclose personal information to third parties only for legitimate business purposes and in accordance with this Privacy Policy. The categories of recipients and our current key service providers include:
- Ecommerce and payments. Shopify (hosting, checkout, primary platform; Canada / United States), and the payment processors that Shopify routes transactions through.
- Inventory, POS and customer records. Retail Express ("REX") for in-store point of sale, stock and customer profile management.
- Email and SMS marketing. Klaviyo (United States) for email and SMS campaigns and flows; Cellcast for SMS gateway delivery in Australia.
- Customer service. Gorgias for helpdesk, ticket management and live chat.
- Analytics and advertising. Google (Analytics, Google Ads, Merchant Center; United States) and Meta (Pixel, Facebook Ads, Instagram Ads; United States), and our paid media agency partners (currently Ranked AI for Google Ads).
- Fulfilment, freight and logistics. Australia Post, courier and freight providers, and shipping software providers, who receive name, address and contact details to deliver your order.
- Professional services. Our accountants, lawyers, auditors, IT consultants and contractors (including offshore administrative support) where they need access to perform their role and are bound by confidentiality obligations.
- Business transactions. Acquirers, investors and their advisers in connection with a proposed sale, restructure or financing of our business, subject to confidentiality.
- Legal and regulatory. Courts, tribunals, regulators (such as the Australian Taxation Office and the OAIC) and law enforcement, where we are required or permitted by law.
We do not sell your personal information.
8. Your rights and choices
Under the Privacy Act and Australian Privacy Principles, you have rights in relation to your personal information, including:
- Access to the personal information we hold about you (APP 12).
- Correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13).
- Withdrawal of marketing consent at any time, as described in Section 5.
- Anonymity or pseudonymity when dealing with us where it is lawful and practicable to do so (APP 2).
Depending on where you live, you may also have rights to request deletion or portability of your personal information. We will respond to requests within a reasonable time and in accordance with applicable law. We may need to verify your identity before we can action a request.
To make a request, contact us using the details in Section 16.
9. Relationship with Shopify
The Services are hosted by Shopify Inc. and its affiliates, which collect and process personal information about your access to and use of the Services in order to provide and improve the Services for us and for you. Information you submit to the Services will be transmitted to and shared with Shopify and its sub-processors, which may be located in countries other than where you reside.
To help protect, grow and improve our business, we use certain Shopify enhanced features that incorporate data and information obtained from your interactions with our store, along with other merchants and with Shopify. In these circumstances Shopify acts as a controller of your personal information for those purposes, and is responsible for responding to your requests to exercise rights in relation to that processing.
To learn more about how Shopify uses your personal information and any rights you may have, you can read the Shopify Consumer Privacy Policy. You can also visit the Shopify Privacy Portal to exercise certain rights.
10. International data transfers (APP 8)
Because we use service providers based outside Australia (including the United States, Canada, and the Philippines), your personal information may be transferred to, stored in, or accessed from countries other than Australia.
Where we disclose personal information to overseas recipients, we comply with our obligations under APP 8. That means we take reasonable steps to ensure those recipients handle your personal information consistently with the APPs, including by entering into appropriate contractual arrangements with them. You acknowledge that, by providing personal information to us, you consent to that information being transferred and processed overseas for the purposes described in this Privacy Policy.
11. Security and data retention
We take reasonable steps to protect your personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include the use of secure (TLS / HTTPS) connections, access controls, role-based permissions, audit logging and supplier due diligence.
No security measures are perfect or impenetrable. We cannot guarantee absolute security, particularly of information you send to us over the public internet. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.
We keep personal information only for as long as we need it for the purposes set out in this Privacy Policy, or for as long as we are required to keep it by law. As a guide:
- Transactional and tax records (orders, invoices, refunds, payment records) are retained for at least 7 years from the end of the financial year to which they relate, in line with Australian Taxation Office requirements.
- Account information is retained for the active life of your account and for a reasonable wind-down period after closure.
- Marketing consent and engagement data is retained for the duration of your subscription and for a reasonable period after you unsubscribe so that we can demonstrate consent and honour your opt-out.
- Customer service records are retained for as long as needed to resolve your enquiry and for a reasonable period afterwards for quality, training and dispute resolution purposes.
- Analytics data is retained in line with the default settings of the relevant analytics platform, unless we shorten that period.
When we no longer need personal information, we will take reasonable steps to destroy or de-identify it.
12. Notifiable data breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach involving your personal information that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in accordance with the NDB scheme.
13. Third party websites and links
The Services may provide links to websites or other online platforms operated by third parties. If you follow links to sites that are not affiliated with or controlled by us, you should review their privacy and security policies and other terms and conditions. We are not responsible for the privacy or security of such sites or for the accuracy, completeness or reliability of information found on them. Information you provide on public or semi-public platforms, including third party social networks, may be viewable by other users without limitation as to its use by us or by a third party. Our inclusion of such links does not by itself imply any endorsement.
14. Children's privacy
The Services are not directed at children, and we do not knowingly collect personal information from children under 16 years of age. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us using the details in Section 16 and we will take reasonable steps to delete it.
15. Complaints
If you have a complaint about how we have handled your personal information, please contact our Privacy Officer using the details in Section 16. We will acknowledge your complaint promptly and respond within a reasonable period, usually within 30 days.
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
16. Contact us
For any questions about this Privacy Policy, to exercise your rights, or to make a privacy complaint, contact our Privacy Officer:
Privacy Officer, Empire Home World of Empire Pty Ltd (ABN 75 676 519 047) 25 Port Kembla Drive, Bibra Lake WA 6163, Australia Email: enquiries@empirehome.com.au Phone: 1300 615 840
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal or regulatory reasons. When we make changes, we will post the revised Privacy Policy on this website, update the "Last updated" date at the top, and where the changes are material we will provide additional notice as required by law (for example, by email or by a notice on the Services).

