Wine Glass Digital Effective date: 14 July 2026 Last updated: 14 July 2026
1. About this Privacy Policy
Wine Glass Digital is operated by [INSERT LEGAL ENTITY NAME], ABN [INSERT ABN] (“Wine Glass Digital”, “we”, “us” or “our”).
We provide digital marketing and technology services to businesses, including:
reputation management and customer review systems;
missed-call text-back and customer communication systems;
website design, hosting and maintenance;
search engine optimisation and local SEO;
customer relationship management systems;
lead capture, appointment booking and follow-up automation;
email, SMS, telephone and online communication services; and
related consulting, reporting and support services.
We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, where applicable, the Spam Act 2003 (Cth) and other applicable Australian laws.
This Privacy Policy explains how we collect, hold, use, disclose and protect personal information.
It applies to personal information relating to:
visitors to our websites and landing pages;
prospective and current clients;
suppliers, contractors and business partners;
people who contact or communicate with us;
individuals who submit forms or book appointments;
authorised users of systems we provide; and
customers and prospective customers of our clients whose information we process while delivering services.
2. What is personal information?
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Depending on how you interact with us, personal information may include your name, telephone number, email address, business details, billing information, online identifiers and communication history.
3. Personal information we may collect
We may collect the following types of personal information.
Contact and identity information
This may include:
full name;
business or trading name;
job title;
email address;
telephone number;
postal or business address; and
social media or online profile information.
Client and account information
This may include:
account usernames and authorised-user details;
service preferences;
subscription and package information;
onboarding information;
business operating information;
Google Business Profile details;
website and domain information;
appointment and calendar information;
support requests;
account activity; and
records of services provided.
We will not normally request passwords for third-party services. Where access is required, we may use secure invitations, delegated access or authorised integrations.
Customer and lead information
When providing services to a client, we may process information about the client’s customers, leads or contacts, including:
names;
email addresses;
telephone numbers;
enquiry details;
booking or appointment information;
customer status;
dates on which services were provided;
communication preferences;
review request history;
feedback and complaint information;
call, email and SMS activity; and
other information uploaded to or generated within the client’s customer relationship management system.
Communications
We may collect records of communications made through:
email;
SMS or MMS;
telephone;
online chat;
website forms;
social media;
appointment-booking systems; and
customer relationship management platforms.
Where call recording or transcription is enabled, calls may be recorded or transcribed. Appropriate notice will be provided where required by law.
Payment and transaction information
We may collect:
billing names and addresses;
invoice details;
payment status;
transaction references; and
limited payment-related information.
Payment card information may be collected and processed directly by a third-party payment provider. We do not ordinarily store complete payment card numbers.
Website and technical information
When you use our website, forms or digital services, we may collect:
IP address;
browser type;
device type;
operating system;
referring website;
pages visited;
dates and times of visits;
approximate location based on IP address;
form activity;
advertising identifiers;
cookie identifiers; and
website usage and interaction data.
Sensitive information
We do not generally seek to collect sensitive information.
If sensitive information is provided to us, we will only collect and handle it where it is reasonably necessary for our functions or activities and where consent has been provided or collection is otherwise permitted by law.
Please avoid entering unnecessary health, financial, identification or other sensitive information into website forms, CRM notes, messages or review feedback.
4. How we collect personal information
We may collect personal information:
directly from you;
through our website, landing pages and online forms;
when you contact, call, email or message us;
when you book an appointment;
when you enter into an agreement with us;
through cookies, analytics tools and similar technologies;
through social media and advertising platforms;
from publicly available business directories and websites;
from referral partners;
from service providers and technology integrations;
from our clients when they upload or connect customer information;
from Google Business Profiles and other publicly accessible online profiles; and
when information is generated through use of our systems and services.
Where lawful and reasonable, you may interact with us anonymously or using a pseudonym. However, we may require identifying information where it is necessary to provide a service, establish an account, process payment or comply with legal obligations.
5. Why we collect, hold and use personal information
We may collect, hold and use personal information to:
respond to enquiries;
provide quotes and proposals;
establish and administer client accounts;
provide our services;
configure websites, CRM systems and automation;
send review requests and customer follow-up communications;
operate missed-call text-back services;
manage leads, appointments and customer communications;
provide technical support;
process invoices and payments;
manage client relationships;
communicate service updates;
monitor system performance and security;
improve our services and customer experience;
conduct analytics, reporting and quality assurance;
prevent fraud, misuse and unauthorised access;
comply with contracts and legal obligations;
resolve complaints and disputes; and
market our services where permitted by law.
We will not use personal information for a materially unrelated purpose unless we have consent or are otherwise permitted or required by law.
6. Information handled on behalf of clients
In some circumstances, we process personal information on behalf of our business clients.
For example, a client may provide or connect a customer list so that review requests, appointment reminders, missed-call responses or other communications can be sent.
When we handle personal information on behalf of a client:
the client generally determines why the information was originally collected;
we use the information to provide the agreed services;
we follow the client’s lawful instructions;
we do not use the information for unrelated marketing by Wine Glass Digital unless separately permitted;
we apply reasonable security measures; and
we may assist the client with privacy enquiries, access requests, corrections and deletion requests.
Our clients are responsible for ensuring they have provided appropriate privacy notices and have any permissions or consents required to provide personal information to us and to send communications through our services.
Where your information was originally collected by one of our clients, you should ordinarily contact that business first about its collection or use of your information. You may also contact us if you believe Wine Glass Digital is directly responsible for the relevant handling.
7. Reputation management and review requests
Our reputation management services may be used to:
request feedback from genuine customers;
invite customers to provide an honest review;
send reminders relating to a review request;
monitor publicly available reviews;
assist businesses to respond to reviews;
display published reviews on websites; and
provide reporting about review activity.
We do not sell or create fake reviews.
We do not require individuals to leave a positive review. Individuals should provide honest feedback based on their genuine experience.
Reviews submitted directly to third-party platforms such as Google are also governed by the privacy policies and terms of those platforms. Publicly posted reviews may be visible to other users and may be indexed by search engines.
8. Missed-call text-back and communication automation
Where a client uses a missed-call text-back service, the telephone number associated with an incoming call may be recorded and used to send an automated follow-up message on behalf of that client.
Automated communications may also be triggered by events such as:
an unanswered call;
submission of a website form;
an appointment booking;
completion of a service;
a change in lead or customer status; or
another action configured by the client.
These messages may be operational, customer-service or commercial in nature.
Where a communication is a commercial electronic message, the sender must have the consent or other lawful authority required by the Spam Act 2003 and must provide an appropriate method to unsubscribe.
Recipients may opt out by following the unsubscribe instructions in the message, replying STOP where that option is available, or contacting the relevant business.
9. Direct marketing
We may use personal information to communicate with current or prospective clients about services that may be relevant to them where permitted by law.
Commercial electronic messages will identify the sender and include a functional unsubscribe method where required.
You may opt out of marketing communications at any time by:
using the unsubscribe link in an email;
replying STOP to an eligible SMS;
contacting us using the details below; or
asking us directly to stop sending marketing communications.
We will process unsubscribe requests within the period required by law.
Opting out of marketing will not prevent us from sending necessary service, billing, security or administrative communications.
We do not sell personal information to third parties for their independent direct marketing.
10. Cookies and analytics
Our websites and client websites we manage may use cookies, pixels, tags, local storage and similar technologies.
These technologies may be used to:
operate website functionality;
remember settings and preferences;
understand website traffic;
measure form submissions and bookings;
analyse how users interact with a website;
improve website performance;
measure advertising effectiveness;
prevent fraud or misuse; and
support remarketing or advertising campaigns where enabled.
Some cookies are necessary for website functionality. Other cookies may be optional.
You may be able to control cookies through your browser settings or through a cookie-consent tool where one is provided. Disabling cookies may affect website functionality.
Third-party analytics and advertising providers may collect information under their own privacy policies.
11. Automation and artificial intelligence
We may use automated workflows, software and artificial intelligence tools to support services such as:
routing enquiries;
classifying communications;
generating suggested responses;
summarising calls or messages;
identifying appointments or follow-up tasks;
personalising communications;
analysing website or campaign performance; and
assisting with customer service.
Automated tools may process personal information supplied by clients or individuals.
Unless clearly disclosed, our systems are not intended to make decisions that produce legal effects or otherwise significantly affect an individual’s rights or interests without appropriate human involvement.
Where we use personal information in automated decision-making that may significantly affect an individual, we will provide further information about the kinds of personal information used and the kinds of decisions made, as required by applicable law.
12. When we disclose personal information
We may disclose personal information to:
employees and authorised contractors;
CRM and marketing automation providers;
cloud hosting and data-storage providers;
website hosting and domain providers;
email and SMS delivery providers;
telephone, call-recording and communications providers;
payment processors and financial institutions;
analytics and advertising providers;
website developers, SEO specialists and other service providers;
professional advisers, including lawyers and accountants;
insurers;
government agencies, regulators, courts and law-enforcement bodies where required or authorised by law;
a purchaser or prospective purchaser in connection with a business sale, restructure or acquisition; and
other parties where you have consented or where disclosure is otherwise permitted by law.
We require service providers to access personal information only to the extent reasonably necessary to provide their services.
13. Overseas storage and disclosure
Some technology providers used by Wine Glass Digital are located outside Australia or use overseas infrastructure.
Our principal CRM and automation platform, HighLevel, currently hosts its product infrastructure in the United States.
Personal information may therefore be stored, processed or accessed in the United States.
Other service providers may process information in the United States and in other countries in which they or their subcontractors operate. The countries involved may vary depending on the particular:
communications service;
website or cloud provider;
analytics provider;
payment provider;
integration selected by a client; and
location of authorised support personnel.
Where practicable, we will identify likely overseas locations in this Privacy Policy, a collection notice, service agreement or other communication.
Where the Australian Privacy Principles apply, we will take reasonable steps in the circumstances to ensure overseas recipients handle personal information consistently with applicable Australian privacy requirements, unless an exception applies.
Overseas recipients may also be subject to the laws of their local jurisdiction.
14. Security of personal information
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Depending on the circumstances, these steps may include:
role-based access controls;
password-management requirements;
multi-factor authentication;
restricting access to authorised personnel;
encryption in transit and, where supported, at rest;
secure cloud systems;
confidentiality obligations;
staff and contractor training;
system logging and monitoring;
backups and recovery procedures;
security updates and software maintenance;
vendor security reviews; and
incident-response procedures.
No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.
You are responsible for keeping your account credentials secure and notifying us promptly if you suspect unauthorised access.
15. Data retention and deletion
We retain personal information only for as long as reasonably necessary to:
provide services;
maintain business and transaction records;
comply with tax, accounting and legal obligations;
resolve disputes;
enforce agreements;
maintain system security; and
support legitimate business operations.
Retention periods may vary according to the type of information, the services provided, client instructions, contractual requirements and applicable law.
When personal information is no longer required, we will take reasonable steps to delete it or de-identify it, subject to legal requirements and reasonable backup, archival and system-recovery processes.
Client data may be deleted or returned following termination in accordance with the applicable client agreement and technical capabilities of the relevant platforms.
16. Accessing your personal information
You may request access to personal information we hold about you.
To make a request, contact us using the details below. We may ask you to verify your identity before providing access.
We will respond within a reasonable period.
In some circumstances, we may refuse access where permitted by law. If we refuse a request, we will generally explain the reasons for the refusal and available complaint mechanisms.
We may charge a reasonable fee for the administrative cost of providing access, but we will not charge a fee merely for making a request.
17. Correcting personal information
We take reasonable steps to ensure personal information is accurate, up to date, complete, relevant and not misleading.
You may ask us to correct personal information we hold about you.
Where appropriate, we may also notify relevant third parties of the correction.
If we do not agree that information should be corrected, you may ask us to associate a statement with the information indicating that you believe it is inaccurate, out of date, incomplete, irrelevant or misleading.
18. Privacy complaints
If you have a question or complaint about how we have handled personal information, please contact our Privacy Officer using the details below.
Please provide:
your name and contact details;
a description of the issue;
relevant dates or communications; and
the outcome you are seeking.
We will acknowledge and investigate the complaint and aim to provide a response within a reasonable period.
If you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.
Information about making a privacy complaint is available at the OAIC website at oaic.gov.au.'
19. Data breaches
We maintain procedures for identifying, assessing and responding to suspected data breaches.
Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.
Notifications may include:
the nature of the breach;
the types of information involved;
recommended steps individuals should take; and
our contact details.
20. Third-party websites and platforms
Our websites and communications may contain links to third-party websites, applications or platforms.
We are not responsible for the privacy practices of third parties. You should review the privacy policies of those third parties before providing personal information.
This includes platforms such as Google, Facebook, Instagram, payment providers and other websites linked from our services.
21. Children’s privacy
Our services are designed primarily for businesses and adults.
We do not knowingly seek to collect personal information directly from children under 18 unless this is reasonably necessary, appropriate consent or authority has been obtained, and the collection is lawful.
If you believe a child has provided personal information to us without appropriate authority, please contact us.
22. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
changes to our services;
changes to technology providers;
changes to our information-handling practices; or
legal and regulatory developments.
The current version will be published on our website with the date it was last updated.
Material changes may also be communicated through email, client accounts or another reasonable method.
23. Contact us
Questions, access requests, correction requests and complaints should be directed to:
Privacy Officer Wine Glass Digital Operated by: [INSERT LEGAL ENTITY NAME] ABN: [INSERT ABN] Email: [INSERT PRIVACY EMAIL] Telephone: [INSERT TELEPHONE NUMBER] Address: [INSERT BUSINESS OR POSTAL ADDRESS] Website: https://wineglassdigital.com