Privacy policy
Last updated: 5 November 2025
GFRC Australia Pty Ltd, trading as Concrete Studio (“Concrete Studio”, “we”, “us”, or “our”) operates this website and store and provides related information, content, features, tools, products and services (the “Services”). We use Shopify to host and power our store.
This Privacy Policy explains how we collect, use, disclose and protect your personal information when you visit, use, or make a purchase via the Services, or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy regarding personal information, this Privacy Policy prevails.
By using the Services, you acknowledge you have read and understood this Privacy Policy.
1) Who we are & scope
We are the data controller for the personal information we collect via the Services. This policy applies to information we collect through our website, online store, products, services and business operations, and it is designed to comply with:
- Australia’s Privacy Act 1988 and Australian Privacy Principles (APPs)
- GDPR (EU/EEA) and UK GDPR
- Applicable US state privacy laws (e.g., CCPA/CPRA) where relevant
2) Personal information we collect
“Personal information” means information that identifies, relates to, or can reasonably be linked to an individual. We may collect:
- Contact details: name, billing/shipping address, email, phone
- Account details: username, password, preferences
- Transaction details: items viewed, cart, wish-list, purchases, returns, exchanges
- Payment & financial details: processed securely by our payment providers
- Device & usage data: IP address, browser, device identifiers, pages viewed, interactions
- Communications: customer support messages and forms
- Marketing preferences and related engagement
- Professional details: role, company (where relevant)
- Optional special category data: e.g., accessibility needs (with consent)
Sources: Directly from you; automatically via cookies/SDKs; from service providers (e.g., payment, delivery, analytics); partners or third parties as permitted by law.
3) How we use your information & legal bases
We use personal information to:
- Provide & improve the Services: process orders, fulfil and ship, manage returns/warranties, remember preferences, maintain your account, recommend products
- Customer support & communications
- Security & fraud prevention: authenticate accounts; detect, investigate and act on fraudulent or illegal activity
- Marketing & advertising: send lawful promotional emails/SMS/post; show online ads based on your activity
- Legal & compliance: tax, accounting, regulatory and contractual obligations
GDPR legal bases (where applicable): contract, legal obligation, legitimate interests (e.g., operations, security, limited direct marketing), and consent (e.g., certain marketing/cookies/special categories).
4) Sharing & disclosures
We may disclose personal information to:
- Shopify (hosting, store platform, analytics and privacy tooling)
- Service providers (payments, shipping/logistics, IT/hosting, analytics, marketing, professional advisers)
- Business & marketing partners (for advertising and measurement, where lawful)
- Affiliates / corporate group
- Authorities or third parties where required by law or to protect rights/safety
- Business transfers (e.g., merger, acquisition)
We do not sell personal information for monetary consideration. Depending on your location, certain sharing for targeted advertising or cross-context behavioural advertising may be deemed a “sale”/“share” under local law—see Your rights & choices below.
5) Our relationship with Shopify
The Services are hosted and powered by Shopify, which processes personal information to provide, secure and improve the platform. Shopify may combine data about your interactions with our store, other merchants, and Shopify to deliver enhanced features and advertising tools. For those Shopify-led uses, Shopify is responsible for handling requests to exercise rights. Learn more in the Shopify Consumer Privacy Policy and use Shopify’s privacy portal where available.
6) Cookies, analytics & ads
We use cookies and similar technologies to:
- Operate the site (strictly necessary)
- Measure performance (analytics)
- Enhance functionality
- Personalise/market (with consent where required)
You can manage preferences via our cookie banner and your browser settings. If you visit with the Global Privacy Control (GPC) signal enabled, we will treat it as an opt-out where legally required.
7) Your rights & choices
Depending on your location, you may have rights to:
- Access/Know the personal information we hold about you
- Delete personal information
- Correct/Rectify inaccurate data
- Portability (receive a copy in a portable format)
- Object/Restrict certain processing (EEA/UK)
- Withdraw consent (where processing relies on consent)
- Opt-out of “sale”/“sharing”/targeted advertising (US and other regions)
How to exercise your choices: Use the Privacy choices / Opt-out link in our footer or cookie banner (where enabled, including Shopify’s Privacy/Opt-out portal), or contact us at admin@concrete.studio.
We may need to verify your identity and will respond within timeframes required by law. You may authorise an agent to act on your behalf where permitted. We will not discriminate against you for exercising your rights.
8) International transfers
We may transfer, store and process your information outside your country (including Australia, the EU/UK and the US). Where required, we use Standard Contractual Clauses or other recognised safeguards for EEA/UK transfers, unless an adequacy decision applies.
9) Security
We implement appropriate technical and organisational safeguards (encryption, access controls, staff training, secure payments, backups). No method is 100% secure; if a material breach occurs, we will notify as required by law.
10) Retention
We keep personal information only as long as necessary for the purposes set out above, including to provide the Services, comply with law, resolve disputes and enforce agreements.
- Customer & transaction records: 7 years after last transaction
- Financial/tax records: 7 years (AU law)
- Warranty data: warranty term + 1 year
- Marketing data: until you opt out or ~3 years of inactivity
11) Children
Our Services are not directed to children. We do not knowingly collect personal information from individuals under 16 (or under the age of majority in your jurisdiction). If you believe a child has provided personal information, contact us to delete it.
12) Third-party links
Our Services may contain links to third-party sites or features. Their privacy practices are not governed by us. Review their policies before providing personal information.
13) Complaints
If you have a concern, please contact us first. You may also have the right to lodge a complaint with your local authority (e.g., OAIC in Australia; an EU/UK supervisory authority; relevant US state authority).
14) Changes to this policy
We may update this policy to reflect operational, legal or regulatory changes. We will post updates here, adjust the Last updated date, and provide additional notice where required.
15) Contact us
Email: admin@concrete.studio
Governing law: Australian law governs this policy. For EEA/UK residents, GDPR/UK GDPR protections apply where they provide greater protection. US residents’ state/federal laws apply as relevant.