Free Express Shipping Australia-Wide | International Shipping Available

PRIVACY POLICY

Privacy Policy – MyTPMS Australia
Your information & privacy choices

MyTPMS Australia Privacy Policy

How personal information is used for orders, bookings and TPMS support, the choices available to you, and how to contact us about your privacy.

Springvale, VictoriaABN 53 807 701 500Access & correctionPrivacy enquiries
Last updated: 14 September 2026Scope: Website, orders & support
Registered business name
MyTPMS Australia
ABR entity name / ABN holder
The Trustee for Automate TPMS Australia Trust
Workshop & dispatch address
Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia
Privacy contact
Phone — Australia
Customer-support hours
Monday–Friday, 9 am–5 pm, Melbourne local time
Australian Business Number
53 807 701 500
View ABN record
Section 01

About This Privacy Policy

This Privacy Policy describes the personal information handled by MyTPMS Australia in connection with our website, orders, workshop bookings, TPMS compatibility assistance and customer support. The Australian Business Register records the holder of ABN 53 807 701 500 as The Trustee for Automate TPMS Australia Trust. MyTPMS Australia is the registered business name. Our workshop and dispatch address is Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia.

Our website, mytpms.com.au, uses WordPress and WooCommerce. We supply TPMS sensors, diagnostic and programming tools, DIY kits and related automotive accessories. This policy covers browsing, checkout, account registration, booking communications, technical enquiries, trade applications, returns, warranty claims and complaints.

A privacy notice, not blanket consent. Reading this policy, browsing our website or placing an order does not by itself give consent to every use of personal information. Where consent is required or we promise to seek it, it must be obtained separately for the relevant purpose. Declining optional marketing does not prevent you from ordering or seeking support.

We are committed to protecting personal information and use the Australian Privacy Principles (APPs) as a framework for the commitments in this policy. The statutory application of the Privacy Act 1988, the APPs and other privacy laws depends on the business and the processing involved. Nothing in this policy excludes a legal obligation or an individual’s applicable rights.

This policy concerns information we handle. Third-party payment services, social platforms and companion applications may have separate privacy notices. A link to an app download does not establish that MyTPMS operates the app or controls its permissions. Contact us for the relevant provider details before supplying information to an unfamiliar service.

Please also read our Cookie Policy, Payment Security Policy and Terms of Service. For a copy of this policy or assistance in another accessible format, contact our privacy contact at [email protected] or 1300 818 030.

Back to contents
Section 02

What Personal Information We Collect

The information we collect depends on the service you request and the website features you use. Our collection is limited to information reasonably needed for the stated purpose. Providing an item of information voluntarily is not, by itself, a reason to retain or reuse it indefinitely.

Customer, order & booking information

  • Identity and contact: Your name, email address, telephone number and preferred contact method; business name and contact-person details for trade enquiries.
  • Addresses: Delivery and billing address, suburb, state, postcode and country, together with delivery instructions relevant to the order.
  • Account information: Username, account authentication information, preferences, saved addresses and order history when you create an account. Do not send your account password to our team.
  • Transactions: Products ordered, order value, invoice details, payment-method type, transaction references, payment status, refunds and dispatch information. Payment references and limited transaction details are distinct from full card credentials.
  • Workshop bookings: Appointment date and time, requested service, vehicle details, booking status and related communications. A booking may be linked to the corresponding WooCommerce order.
  • Messages and case records: Enquiry details, email and SMS correspondence, call notes and messages submitted through an available contact channel.
  • Returns and warranty: Proof of purchase, reported fault, inspection details, photographs, correspondence and the outcome of the claim.

Vehicle & TPMS technical information

  • Vehicle details: Make, model, year, build information, registration details where supplied, and variant information needed for the fitment enquiry or booking.
  • VIN: A VIN or vehicle-identification photograph may help distinguish applications. It may be associated with your order, booking or support record. We do not treat vehicle information as anonymous when it can be linked to you, and we do not use VINs for marketing.
  • Sensor and tool information: OE references, sensor IDs, programming or cloning details, relevant diagnostic outputs and the steps you have already tried.
  • Photographs: Sensor, valve, dashboard, vehicle-identification and tool-display images you choose to provide. Crop unrelated people, address details and documents from images where practical; image files can also contain metadata.

Technical & website usage information

  • Website operation: IP address, browser and device information, security events and session information associated with using the site.
  • Interactions: Pages viewed, product searches, cart and purchase events, referral information and advertising click or cookie identifiers where the relevant measurement tools operate.
  • Location: Addresses you enter and approximate location associated with your connection may be relevant to delivery or website settings. This policy does not grant an app permission to collect precise device location.
  • Tracking choices: Consent records and opt-out preferences, where captured by the relevant systems. Sections 8 and 9 explain tracking categories and the disclosures that depend on active configuration.

Wholesale & trade details

Trade-account applications may include business name, ABN or equivalent registration, business type, contact details and information relevant to trade eligibility and account administration. A contact person’s information remains personal information even when supplied for business purposes.

Please limit sensitive information. Do not send health records, identity-document copies, full card details, CVV codes, banking passwords or other sensitive information unless specifically needed for an explained process. If unsolicited sensitive information is received, we assess whether it may lawfully and reasonably be kept; unnecessary information should be deleted or de-identified where lawful and reasonable. An accessibility enquiry need only describe the assistance required.

Back to contents
Section 03

How We Collect Your Personal Information

Information may be collected directly from you, through the website, or from a service provider involved in your transaction. We aim to explain the relevant collection at or before it occurs, or as soon as practicable afterwards, rather than relying on a policy link alone.

Directly from you

  • Checkout, accounts and bookings: Details you enter to purchase, create an account, arrange a workshop service or update a booking.
  • Enquiries: Information you send by email, telephone, contact form, SMS or an available chat/social channel.
  • Technical support: Vehicle and sensor information you submit to request a compatibility check, pre-programming or troubleshooting assistance.
  • Returns, warranties and complaints: The details and evidence you provide when asking us to investigate a problem.
  • Trade registration: Information supplied through the Wholesale Registration Form.
  • Marketing choices: Contact details and the specific opt-in preferences you provide when subscribing.

Automatically through the website

Website servers and active security tools may record connection and technical information. Optional analytics and advertising tools may collect interaction and attribution information as described in Sections 8 and 9. Information transmitted directly to a third-party platform can still be relevant to our privacy responsibilities when we deploy its technology.

From third-party sources

  • Payments: The chosen payment service may return transaction references, authorisation or payment status, refund information and fraud-related results.
  • Delivery: A carrier may return tracking events, delivery status and proof of delivery relevant to the shipment.
  • Messaging: Email and SMS providers may return message-delivery information. Guni SMS is used for MyTPMS service messages.
  • Platforms: A social platform may supply the profile details and messages you choose to share. Advertising or analytics services may supply campaign results and event records according to the features configured.
  • A person acting for you: An authorised workshop, purchaser or representative may provide details needed for an order or support request. They should have authority to share them.

Collection notices and choice: APP 5 concerns notification of collection; APP 3 concerns collecting information. A general enquiry can often be made without identifying yourself. An order, delivery or account-specific request usually needs enough information to fulfil it or verify authority. Without essential details, we may be unable to complete that service. Technical logs may still be generated when you browse without creating an account.

Back to contents
Section 04

Why We Use Your Personal Information — Purposes of Collection & Use

We use information for the purpose for which it was collected and for other uses permitted by the applicable law. Where APP 6 applies, a secondary use needs an available basis, such as consent, a related purpose you would reasonably expect, or another applicable exception. Sensitive information attracts additional restrictions. A business benefit alone is not a general “legitimate interests” exception under the APPs.

Purposes for collecting and using information
PurposeInformation involvedRelevant limitation
Order fulfilmentContact details, address, products and transaction recordsPicking, packing, dispatch, invoicing and delivery follow-up.
Workshop bookings and updatesBooking reference, appointment, vehicle details and contact informationManaging the requested service and communicating relevant status changes.
Vehicle compatibility and programmingVehicle details, VIN where provided, part references and sensor IDsThe requested technical task and related support; no VIN-based marketing.
Invoices and financial administrationBilling details, amounts, applicable business identifiers and transaction referencesRecords needed for financial obligations and transaction administration.
Service communicationsEmail/phone, order or booking reference and the relevant messageConfirmation, reminders, dispatch, service and claim updates; not permission for unrelated promotions.
Returns, warranty and complaintsPurchase record, fault details, photos and correspondenceAssessment, a suitable remedy, follow-up and relevant dispute records.
Accounts and website securityAccount details, logs, device data and payment/security resultsAccount operation and proportionate fraud or misuse investigation.
Website measurement and advertisingEvents, device information and permitted identifiersOnly the enabled features, disclosures and choices described in Sections 8 and 9.
Opt-in marketingContact details, preferences and relevant purchase information where disclosedOur express opt-in commitment and an effective unsubscribe option.
Legal requests and proceedingsInformation relevant to the particular requestOnly where disclosure or retention is required or otherwise lawfully permitted.
Privacy requestsContact details, authority verification and request historyLocating records, providing a response and recording the outcome.

We do not sell or rent customer contact lists. This promise is separate from disclosures to service providers and from any advertising-data sharing that must be accurately described and controlled. A service-provider privacy policy does not remove our own responsibilities for choosing and configuring that service.

Back to contents
Section 05

Checkout, Vehicle Details & Payment Privacy

An online purchase or TPMS support case may involve several records. Payment credentials, transaction references and vehicle details are different information categories; keeping one does not mean the others must be retained for the same period.

Checkout, vehicle and payment data flows
InformationUseRelevant record or recipient
Name, contact and addressOrder fulfilment, invoices, delivery and customer contactWooCommerce order/account records and the providers needed for that service.
Booking detailsAppointment administration and service-status messagesMyTPMS booking records and linked order or communication records.
Payment result and referencePayment confirmation, refunds and dispute investigationOrder records and the chosen payment provider; limited transaction details may be stored by both.
Full card/payment credentialsAuthorising the selected payment methodThe payment interface and provider used at checkout. Do not send these in enquiries.
Vehicle details and VINFitment, programming and related supportRelevant order, booking or support records where supplied and needed.
Sensor IDs and diagnostic photosCloning, identification and troubleshootingRelevant technical or support case; images can contain personal information.
IP, session and security informationOperating and protecting the websiteWebsite/server and configured security or measurement systems.

Payment information

Use the payment methods displayed in the live checkout. Payment services have their own privacy notices covering how they handle payment information, identity checks and transactions. Our order records may include the selected method, transaction identifiers, payment status and limited payment details returned by the provider.

We do not ask customers to send full card numbers, security codes, banking passwords or one-time banking codes by email, SMS or chat. Contact us using the published details if a message requests this information. An encrypted connection protects data in transit; it is not a certification of the seller or a guarantee that all systems are secure.

See Section 11 for retention and Section 12 for access, correction and deletion requests. A product warranty does not automatically justify retaining every photograph or technical detail for an indefinite period.

Back to contents
Section 06

Disclosure of Personal Information to Third Parties

We share information relevant to the requested service or another disclosed, lawful purpose. Access should be limited to what each recipient reasonably needs. Some providers process information on our behalf; others also have independent legal or service purposes, which their privacy terms explain.

Recipients and reasons for disclosure
Recipient categoryInformation that may be involvedPurpose / qualification
Payment providersTransaction amount, billing and payment information, payment/security resultsPayments, refunds and fraud checks; the provider is identified in the payment journey.
Delivery providers, including Australia Post where usedRecipient name, delivery address, phone, parcel references and relevant instructionsShipping labels, delivery, tracking and proof of delivery.
Guni SMS and service-email providersDestination contact details, relevant message content, order/booking links and delivery statusBooking, workshop, order and support communications. These are not a general transfer of the customer database.
Hosting, maintenance and security providersWebsite records, backups and logs within the relevant serviceRunning and protecting WordPress/WooCommerce and related systems.
Marketing delivery providers, where usedSubscriber contact details, consent/preferences and campaign data; purchase relevance only where actually disclosedSending opted-in marketing and managing unsubscribe preferences.
Google measurement/advertising services and other pixels, where enabledDevice, event, cookie/click identifiers and any separately disclosed user-provided dataMeasurement and advertising subject to the active configuration and choices in Section 9.
Chat or social platforms chosen by the customerMessage, displayed profile/contact details and attachmentsResponding through that channel; the platform can have its own privacy purposes.
Accounting and professional advisersTransaction or case details necessary for the engagementFinancial administration, legal advice or dispute handling; not unrestricted access for every adviser.
Product suppliers or technical partners where neededRelevant product, vehicle or fault informationSupport or warranty investigation; use de-identified technical details where practical.
Authorities and other lawful recipientsInformation relevant to a legal requirement or lawful requestComplying with the applicable obligation or permitted disclosure, not every informal request.

We do not sell or rent customer mailing lists or provide them to another business for its unrelated direct marketing. Optional advertising features must still be disclosed accurately; hashing or using a service provider does not automatically mean that no personal information is shared.

Back to contents
Section 07

Overseas Disclosure of Personal Information

Technology services and international deliveries can involve recipients outside Australia. The relevant locations can include where a provider stores information, where support staff have access and the destination of an international shipment. An Australian business address or a local website host does not establish that every recipient and backup is in Australia.

Cross-border safeguards

Where APP 8 applies, we must take the required reasonable steps in relation to overseas recipients unless a valid exception applies. The appropriate measures depend on the recipient, information, access and purpose. These may involve assessing the provider, contractual protections, limits on information and access, and follow-up where issues arise.

Using the site is not consent to waive APP 8 protections. The informed-consent exception is APP 8.2(b), not APP 8.2(a), and has specific requirements. No such waiver is requested by this policy. A provider’s international certification or privacy policy alone is not represented as proof of compliance with all Australian cross-border requirements.

Back to contents
Section 08

Cookies, Tracking Technologies & Consent

Cookies, pixels and similar technologies can support website operation, preferences, measurement and advertising. See our Cookie Policy for information about cookies and your choices. The categories below explain their purposes.

Tracking categories and choices
CategoryPurpose and informationChoice and duration
Essential website operationCart/session functions, account authentication and security information needed for a requested service.Some functions may not work if these are blocked.
PreferencesSettings such as consent choices or display preferences, where that feature is present.Preference cookies support optional features rather than essential checkout functions.
AnalyticsPage and event information, device data and identifiers that help measure website usage.Consent or other applicable requirements depend on the implementation and law. Pseudonymous measurement is not automatically anonymous.
Advertising and remarketingAd-click, conversion and audience information; potentially identifiers that a platform can link to an account.Our commitment is to use optional advertising and analytics tracking only after an affirmative choice.
Third-party embedsA video, map or widget can send connection information and set storage when it loads.The provider’s privacy settings and available site controls determine how an embed behaves.

Consent controls

This policy does not treat continued browsing, silence or an order as consent to optional tracking. Our commitment is to provide a clear choice before optional analytics or advertising tracking operates, and a way to change that choice.

Additional controls

  • Browser settings: Your browser can block or clear cookies and other storage. This may affect login, cart or checkout. Clearing a cookie can also remove a saved preference, and does not necessarily undo information already received by a provider.
  • Google Analytics: Google’s Analytics opt-out browser add-on provides a browser-specific control for supported Analytics implementations; it is not a universal blocker for every website or advertising service.
  • Google advertising: My Ad Center can manage Google ad personalisation. It does not mean every form of measurement or data collection is disabled.
  • Other platforms: Use the platform’s own privacy/ad controls as relevant. Industry opt-out tools cover participating services only and do not necessarily remove all storage or prevent all tracking.
  • Assistance: Contact our privacy contact at [email protected] or 1300 818 030 if a choice is unavailable or does not work.
Back to contents
Section 09

Google Advertising, Analytics & Shopping

Google Merchant Center product data and customer measurement data are different. Product-feed information describes the goods offered for sale. Advertising and analytics tags may separately process information about people who visit or purchase.

Google Analytics

Where Google Analytics 4 is used, it can process website events, device/browser information, online identifiers and approximate location. Reports may be aggregated, but the underlying information should not all be described as anonymous. Google states that GA4 does not log or store individual IP addresses; that does not establish that no network information reaches Google, or that cookie and event identifiers cannot relate to a person.

Retention, Google Signals, advertising personalisation, User-ID, user-provided data and linked advertising services depend on the property and tag settings.

Consent Mode

Consent Mode changes Google-tag behaviour in response to consent signals; it does not obtain consent by itself. Under an advanced implementation, denied storage can still result in cookieless signals being sent. Under a basic implementation, tags can remain blocked until consent.

Merchant Center and advertising

  • Product submissions: Product catalogue fields such as title, price, availability, image and product identifiers are not permission to upload customer details. Customer information should not be included in public product titles, descriptions or images.
  • Conversion measurement: Where active, measurement may use purchase events, amounts and identifiers to associate a transaction with an ad interaction. Aggregated reports do not make every underlying event anonymous.
  • Enhanced conversions: This optional feature can send hashed customer-provided identifiers, such as an email address or phone number, to Google for matching. Hashing is not the same as anonymising data.
  • Customer Match and remarketing: We retain the commitment not to upload customer contact lists for Customer Match without separate explicit consent for that purpose. Optional website remarketing must also follow the advertised tracking choices and applicable requirements.
  • Additional Google features: Reviews, order-tracking signals and other customer-data features may involve information separate from product catalogue data. Their use is subject to the relevant disclosures and privacy choices.

For the provider’s explanation of its practices, see Google’s Privacy Policy and Google’s business privacy information.

Back to contents
Section 10

Data Security — Technical & Organisational Measures

We are committed to taking reasonable technical and organisational steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. Where APP 11 applies, both the systems and the way they are managed are relevant. No internet service or storage system can be guaranteed completely secure.

Security priorities

  • Website connections: Use HTTPS for account, checkout and other information exchanges, and investigate unexpected insecure-connection warnings.
  • Account credentials: Use the site’s password-reset process rather than asking staff to recover an existing password.
  • Access: Limit staff and contractor access to what their role requires and remove it when no longer needed.
  • Maintenance: Review software updates, security warnings, hosting controls and backup arrangements.
  • Payment security: Use the relevant payment service’s secure payment process and handle transaction information according to its purpose.

People and procedures

  • Staff handling: Explain appropriate access, identity checks, safe sharing and incident reporting to staff who handle personal information.
  • Provider management: Review what service providers receive, their access and their contractual/independent purposes. Do not assume every provider is prohibited from all independent processing.
  • Data minimisation: Avoid unnecessary copies of customer files, payment credentials, identification and technical photographs.
  • Review: Reassess disclosures, retention and security when adding plugins, channels or services that change the handling of personal information.

Please report a suspected account compromise or accidental disclosure promptly using [email protected] or 1300 818 030. Do not send passwords, card credentials or unnecessary identity documents in the report. Where safe, change a compromised password and review affected accounts. Nothing in this section limits an applicable legal duty.

Back to contents
Section 11

Retention, Deletion & Backup Records

Retention depends on the type of information and the reason it is still needed. We should keep information only while reasonably necessary for the service, a relevant continuing warranty or dispute, a lawful record-keeping requirement or another permitted purpose. Once that basis ends, reasonable deletion or de-identification steps should follow. This is not an instruction to erase evidence needed for an active claim.

Retention criteria by record type
Record typeRetention basisImportant distinction
Orders, invoices and accounting recordsThe applicable financial-record period and any justified continuing transaction need.Most business tax records generally need to be kept for five years under ATO guidance; some records have longer obligations. This is not a universal seven-year rule for every customer detail.
Active or closed customer accountsWhile providing the account and as reasonably needed for closure, security or retained transaction records.Closing an account does not necessarily erase lawful invoice records, but it does not justify retaining every preference indefinitely.
Bookings and service communicationsAppointment administration, support and a reasonable record of the service or dispute.Service messages, delivery logs and booking data may have different retention periods according to their purpose.
Warranty, returns and complaintsThe applicable support or claim needs, including preserving proof of promises and outcomes.An eligible lifetime warranty is not an automatic reason to keep unrelated photographs or full customer histories forever.
VIN, sensor IDs and technical photographsThe fitment, programming, support or claim purpose for which they are needed.These can be linked to an order; minimise information once its technical purpose is complete.
Marketing contacts and consentAn active subscription and a proportionate record of consent/withdrawal.An unsubscribe suppression record may need to remain so the person is not accidentally added again.
Server/security and message logsProportionate operational, security or dispute requirements.Retention depends on the operational, security or dispute purpose of the record.
Analytics and advertising recordsThe actual platform configuration and the lawful purpose.Retention periods depend on the platform settings and the type of information involved.
Backups and archived copiesA justified backup rotation and restricted restoration process.Deletion from live records and expiry from backups may occur separately; restored data must not undo a valid deletion or opt-out without a lawful reason.

Deletion requests

You may request deletion through our privacy contact at [email protected] or 1300 818 030. We aim to respond within 30 days, explain what can be deleted or de-identified, and identify any records that must remain and the reason. We will not present an internal business retention preference as a legal prohibition. We will explain the practical completion process, including any relevant backup limitations, rather than promise immediate removal from every system.

Back to contents
Section 12

Your Privacy Rights — Access, Correction & Requests

You can contact us to ask about information we hold, request access or correction, seek deletion, change marketing preferences or raise a privacy concern. Statutory rights depend on the law that applies and may have exceptions; the service commitments below do not remove those rights.

Access

Ask for information we hold about you. We aim to respond within 30 days and ordinarily provide access without charge. There is no fee for making an access request. Any exceptional permitted charge for providing access must be reasonable, explained in advance and not used to discourage a request.

Correction

Ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We will explain a refusal and, where required, associate a statement of your requested correction. No fee applies to a correction request or correction. Relevant downstream corrections will be addressed where required.

Deletion or de-identification

Ask us to remove information that is no longer needed. We will explain any lawful reason for continued retention and the available alternatives. Deletion is not an unrestricted Australian statutory right to remove all transaction and claim evidence immediately.

Marketing choices

Opt out at any time using the unsubscribe method provided or by contacting us. We will action the request within five working days. Necessary service communications remain separate, and a minimal suppression record can help honour your choice.

Automated-process enquiries

Ask for an explanation or staff review of a decision within our control. The December 2026 disclosure requirements described in Section 14 are not a blanket guarantee that every provider decision can be overridden by MyTPMS.

Privacy complaints

Raise a complaint using Section 18. You can also seek advice about independent complaint or legal avenues. Our internal process is not a waiver of your rights or a requirement to miss a filing deadline.

Making a request

Contact [email protected], 1300 818 030 or write to our privacy contact at Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia. Include enough information to identify the relevant record and explain your request. An order number may help, but is not mandatory for a person who has not placed an order.

We may check your identity or a representative’s authority in a proportionate way before releasing another person’s information. Do not send a passport or driver-licence copy unless we explain why it is needed and arrange an appropriate channel. We will assist with a request that cannot conveniently be made in writing.

We aim to respond within 30 days, and earlier where practical. Where another law requires a different timeframe or process, that requirement applies. We will explain any extension, refusal, partial response or necessary information request. An identity check should not be used to delay an otherwise valid request unnecessarily.

Back to contents
Section 13

Marketing Communications & Consent

Our marketing commitment is express opt-in: placing an order or requesting support does not automatically subscribe you to promotional emails or SMS. Where a law permits broader consent in particular circumstances, that does not silently replace the stricter commitment made in this policy.

Marketing choices and service messages

  • Separate choice: Marketing consent should be collected distinctly from information needed to complete a purchase or booking. We do not treat an unchecked box, an abandoned cart or possession of a phone number as express marketing consent.
  • Identification: A marketing message should clearly identify MyTPMS Australia and provide valid contact details.
  • Unsubscribe: Use the functional unsubscribe method in the message or contact [email protected] or 1300 818 030. Requests will be actioned within five working days, without a fee or a requirement to create an account.
  • Contact-list commitment: We do not sell or rent subscriber lists or provide them for another business’s unrelated direct marketing. Providers used to deliver our own messages are addressed in Section 6.
  • Service messages: Booking confirmations, reminders, workshop updates, invoice, dispatch and claim communications can be needed to provide a requested service. Calling a promotional message “transactional” does not exempt it from marketing requirements.
  • Review requests and cart follow-ups: These should be assessed for their actual content and applicable consent requirements. Any follow-up must respect the relevant consent and unsubscribe choices.
  • International recipients: We respect additional marketing requirements where applicable, including requirements relevant to Canadian recipients.

You do not need to use a particular email subject line to unsubscribe. We may keep a limited record of your opt-out to avoid contacting you again in error. Please tell us if a message continues after the processing period so we can investigate the relevant channel.

Back to contents
Section 14

Automated Processes & Decision Transparency

Some website and service functions use automated rules. These may process the information relevant to a booking, payment, delivery calculation or promotional code. Contact us to query an outcome or request staff review of a matter within our control.

Automated processes and review boundaries
ProcessRelevant informationEffect and review
Booking and service-message workflowContact details, booking/order reference, appointment and statusGuni SMS can deliver the relevant confirmation or update. Contact our team to correct a booking or message.
Checkout calculations and code validationAddress/postcode, cart, quantities and any entered codeThe configured rules calculate options or accept/reject a code. Contact us about an apparent error.
Fraud screening and payment decisionsDepends on the payment/security provider; may include transaction, device and address informationProvider rules may result in a hold, decline or other payment outcome. MyTPMS review can address matters within our control; a provider may make a separate decision.

Australian transparency requirements from 10 December 2026

From 10 December 2026, additional APP 1 disclosure obligations apply to covered entities arranging for a computer program to use personal information in decisions reasonably expected to significantly affect an individual’s rights or interests. They can also cover a program doing something substantially and directly related to making such a decision; the presence of a human does not automatically remove the requirement.

Where the requirements apply, the policy needs to describe the kinds of personal information used, kinds of decisions made solely by computer programs, and kinds of decisions substantially and directly assisted by them.

Back to contents
Section 15

Children’s Privacy

MyTPMS sells technical automotive products and its purchasing arrangements are intended for adults, or for a parent or guardian purchasing for a younger person. That is a purchasing policy, not proof that no child can visit the website or generate website logs.

  • Information minimisation: Children should not submit unnecessary personal information. A parent or guardian can contact us to arrange a purchase or request help.
  • Marketing: We do not intend to direct promotional campaigns at children. Do not use the adult focus of the catalogue as a substitute for appropriate audience settings and safeguards.
  • Unintended collection: If we become aware of information about a child that is not needed, we will assess appropriate deletion, de-identification or restricted handling, considering the child’s safety and any lawful retention needs.
  • Parental enquiries: We will assess authority and the child’s circumstances before disclosing information or notifying another person; a claimed family relationship does not automatically authorise disclosure.
  • Children’s privacy rules: We will assess applicable rules, including the scope and commencement of the Australian Children’s Online Privacy Code. Whether a service is likely to be accessed by children can matter; an “adults only” description is not itself an exemption.

To report a concern, contact our privacy contact at [email protected] or 1300 818 030. Provide only the details needed to locate the issue.

Back to contents
Section 16

Data Breach Response & Notification

We will take a suspected data incident seriously, contain it where possible, investigate the information affected and consider steps that reduce potential harm. Statutory reporting depends on the law and circumstances. The Australian Notifiable Data Breaches (NDB) scheme applies to covered entities and information; not every incident is legally notifiable.

When an incident may be notifiable

Under the NDB scheme, an eligible breach generally involves unauthorised access to or disclosure of personal information, or loss with likely unauthorised access/disclosure, where serious harm to an individual is likely. Effective remedial action and statutory exceptions can affect whether notification is required.

Response process

  • Contain and reduce harm: Take proportionate immediate steps, preserve relevant evidence and involve the appropriate hosting or service provider.
  • Assess promptly: Where there are grounds to suspect an eligible breach, conduct a reasonable and expeditious assessment. The NDB scheme requires all reasonable steps to complete that assessment within 30 days of becoming aware of the grounds for suspicion.
  • Do not wait unnecessarily: Where there are already reasonable grounds to believe an eligible breach occurred, notification obligations arise as soon as practicable; the assessment period is not permission to wait 30 days.
  • Notify where required: Provide the required statement to the OAIC and notify relevant individuals, subject to any valid exception. If direct notification is impracticable, the applicable publication and publicity steps must be considered.
  • Give useful information: Explain the incident, kinds of information involved, contact details and protective steps people can take.
  • Review: Address the cause and relevant controls. Other jurisdictions may impose additional duties or different deadlines where their laws apply.

Report suspected account compromise or accidental disclosure through [email protected] or 1300 818 030. Avoid including payment credentials. The Australian Cyber Security Centre provides information about cyber incidents and reporting. We will consider useful protective communication even when an incident does not meet a statutory notification threshold.

Back to contents
Section 17

International Customers — Privacy Rights

International customers may have additional rights where a local law applies to MyTPMS or to a particular service provider. Applicability depends on the law’s territorial and other scope, not merely on someone opening the website from another country. Australian-law wording is not intended to remove mandatory overseas protections.

Australia

The Privacy Act and APPs apply according to their scope. OAIC guidance explains coverage and privacy rights.

Official guidance

European Union / EEA

Where the GDPR applies, rights can include access, correction, erasure, restriction, objection and portability, subject to the relevant conditions.

Official guidance

United Kingdom

Where UK data-protection law applies, the ICO explains individual rights and complaint options. Do not assume every EU and UK rule is identical.

Official guidance

New Zealand

Where New Zealand privacy law applies, access, correction and privacy complaint rights can be relevant.

Official guidance

Canada

Federal or provincial rules may apply to the handling of personal information; marketing rules are a separate consideration.

Official guidance

United States

State and sector rules can apply subject to scope and thresholds. California’s sale/sharing terminology requires particular attention.

Official guidance

Singapore

Where the PDPA applies, refer to the PDPC for current rights and requirements.

Official guidance

Japan

Where Japanese privacy law applies, the PPC provides guidance about handling personal information and individual rights.

Official guidance

EU/EEA & UK requests

Where applicable, you may request access or correction, erasure or restriction, object to relevant processing, or request portability of eligible information. These rights have conditions and exceptions. Direct-marketing objections and consent withdrawals must be handled according to the applicable law. You may also have protections relating to significant automated decisions and a right to complain to the relevant supervisory authority.

California sale / sharing and other US rights

Where California law applies, “sharing” can include cross-context behavioural advertising even where no customer list is sold for money. Applicable rights may include opting out of sale or sharing and using recognised privacy preference signals. Contact us about the information relevant to your request and the choices available.

Back to contents
Section 18

Privacy Complaints — How to Raise a Concern

Contact us if you believe information has been collected, used, retained or disclosed incorrectly, or a privacy request has not been handled properly. We will consider the concern fairly and explain the outcome. You will not be charged for lodging a privacy complaint.

Step 1 — Contact our privacy contact

Email [email protected], call 1300 818 030, use the Contact Us page, or write to Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia. Describe what happened, the relevant date or record if known, and the outcome you seek. A particular subject line or order number is helpful but not mandatory.

Our response commitment: We will acknowledge a privacy complaint within two business days and provide a written response within 30 days. We will explain the investigation, outcome and any further steps. If a matter is complex, we will communicate the reason and next steps without limiting your independent escalation rights.

Business-day calculations use Melbourne local time and exclude Victorian public holidays. The broader Complaints & Dispute Resolution Policy can provide an earlier service-response or update commitment; this privacy process does not cancel that commitment or extend a statutory deadline.

Step 2 — Independent advice or escalation

The OAIC generally expects a written complaint to the business first and a reasonable opportunity to respond, usually 30 days. It determines whether a complaint is within its jurisdiction. You may seek advice earlier, and nothing here requires you to delay urgent action or miss a legal or payment-dispute deadline.

Privacy complaint contacts
AuthorityRelevant scopeContact
Office of the Australian Information CommissionerAustralian privacy matters within its jurisdictionOAIC privacy complaints · 1300 363 992
Office of the Privacy Commissioner (NZ)New Zealand privacy matters within its jurisdictionprivacy.org.nz
Information Commissioner’s OfficeUK data protection and related privacy mattersICO complaints
National data protection authorityEU/EEA supervisory authority appropriate to the caseEDPB member authorities
Office of the Privacy Commissioner of CanadaFederal Canadian privacy matters; provincial routes may also be relevantpriv.gc.ca
California Privacy Protection AgencyCalifornia privacy matters within its jurisdictioncppa.ca.gov

Other complaint, court or legal rights may be available. This page neither waives those rights nor guarantees that no privacy claim could arise. Seek independent advice where needed.

Back to contents
Section 19

Changes to This Privacy Policy

We may revise this policy when our services, data handling, legal obligations or privacy controls change. The date shown on this page identifies the latest revision.

  • Material changes: Give appropriate notice of material changes through the website and, where appropriate, direct communication. An important privacy or service notice is not limited to customers who subscribed to advertising.
  • Consent and existing information: Publishing new wording does not retrospectively authorise a different use of existing information or turn continued browsing into consent. Obtain fresh consent or another valid basis where required.
  • Previous promises: Do not use an update simply to withdraw a privacy commitment already made or to avoid an existing request. Retain a record of policy versions and consider the information and notices applicable at collection.
  • Previous versions: Contact [email protected] for an earlier policy version; we will make reasonable efforts to provide it.
  • Upcoming requirements: Review the actual automated-decision disclosures before the applicable 10 December 2026 requirements, and assess children’s privacy rules as they develop.

We review this policy when introducing a payment, marketing, support, hosting or customer-data service that changes how personal information is handled.

Back to contents
Section 20

All 13 Australian Privacy Principles — Reference Guide

The following guide summarises the 13 Australian Privacy Principles. Their application depends on legal coverage, relevant exceptions and the circumstances in which personal information is handled.

APP 1

Open & transparent management

A covered entity needs appropriate privacy practices and a clear, current policy describing its actual information handling.
APP 2

Anonymity & pseudonymity

Provide anonymous or pseudonymous interaction where required and practical. A general enquiry may not need a name; delivery and account-specific access usually need identifying details. Anonymous browsing cannot be inferred merely from not logging in.
APP 3

Collection of solicited information

Collect by lawful, fair means and limit collection to what is reasonably necessary. Sensitive information has additional consent and exception requirements. Collection notices are dealt with separately by APP 5.
APP 4

Unsolicited information

Assess whether unsolicited information could properly have been collected. Where the conditions require it, destroy or de-identify it as soon as practicable when lawful and reasonable.
APP 5

Notification of collection

Take reasonable steps to explain the relevant collection, purpose, usual recipients, consequences and overseas disclosures at or before collection, or as soon as practicable. A policy link alone is not always enough.
APP 6

Use & disclosure

A secondary use needs an applicable basis under the APPs. General commercial “legitimate interests” are not a standalone APP 6 ground. Sections 4 and 6 describe the purposes and recipient categories.
APP 7

Direct marketing

Direct marketing has specific limits and opt-out duties, with separate electronic-message rules where applicable. Our marketing commitment is express opt-in.
APP 8

Cross-border disclosure

Where APP 8 applies, required steps or a valid exception must support the disclosure. This policy does not seek a blanket waiver of APP 8 protection.
APP 9

Government-related identifiers

Do not adopt or use government-related identifiers contrary to APP 9. Avoid unnecessary identity-document collection. Business-registration information requested for trade verification is not permission to collect other identifiers.
APP 10

Quality of information

Take reasonable steps relevant to the purpose to keep information accurate, complete, current and, for use/disclosure, relevant. Contact us to correct an address or another record.
APP 11

Security & retention

Reasonable technical and organisational protections are needed where APP 11 applies. Remove or de-identify information when the applicable conditions require it.
APP 12

Access

Consider access requests under the applicable rules and explain any refusal or alternative form of access. A request itself must not incur a fee under APP 12; our ordinary free-access commitment is in Section 12.
APP 13

Correction

Consider correction requests and provide reasons and complaint information where required. A statement of the requested correction may need to be associated with a disputed record. Correction and related required steps are not chargeable.

For more information, see the OAIC’s Australian Privacy Principles guidance.

Back to contents

Privacy Questions or Requests?

Contact our team about access, correction, deletion, marketing choices or a privacy concern. Customer-support hours are Monday–Friday, 9 am–5 pm, Melbourne local time.

© 2026 MyTPMS Australia · ABN 53 807 701 500

Workshop and dispatch: Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia.

[email protected] · 1300 818 030

Terms of Service · Cookie Policy · Returns & Refunds · Shipping · Contact Us page

0