How personal information is used for orders, bookings and TPMS support, the choices available to you, and how to contact us about your privacy.
This Privacy Policy describes the personal information handled by MyTPMS Australia in connection with our website, orders, workshop bookings, TPMS compatibility assistance and customer support. The Australian Business Register records the holder of ABN 53 807 701 500 as The Trustee for Automate TPMS Australia Trust. MyTPMS Australia is the registered business name. Our workshop and dispatch address is Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia.
Our website, mytpms.com.au, uses WordPress and WooCommerce. We supply TPMS sensors, diagnostic and programming tools, DIY kits and related automotive accessories. This policy covers browsing, checkout, account registration, booking communications, technical enquiries, trade applications, returns, warranty claims and complaints.
A privacy notice, not blanket consent. Reading this policy, browsing our website or placing an order does not by itself give consent to every use of personal information. Where consent is required or we promise to seek it, it must be obtained separately for the relevant purpose. Declining optional marketing does not prevent you from ordering or seeking support.
We are committed to protecting personal information and use the Australian Privacy Principles (APPs) as a framework for the commitments in this policy. The statutory application of the Privacy Act 1988, the APPs and other privacy laws depends on the business and the processing involved. Nothing in this policy excludes a legal obligation or an individual’s applicable rights.
This policy concerns information we handle. Third-party payment services, social platforms and companion applications may have separate privacy notices. A link to an app download does not establish that MyTPMS operates the app or controls its permissions. Contact us for the relevant provider details before supplying information to an unfamiliar service.
Please also read our Cookie Policy, Payment Security Policy and Terms of Service. For a copy of this policy or assistance in another accessible format, contact our privacy contact at [email protected] or 1300 818 030.
Back to contentsThe information we collect depends on the service you request and the website features you use. Our collection is limited to information reasonably needed for the stated purpose. Providing an item of information voluntarily is not, by itself, a reason to retain or reuse it indefinitely.
Trade-account applications may include business name, ABN or equivalent registration, business type, contact details and information relevant to trade eligibility and account administration. A contact person’s information remains personal information even when supplied for business purposes.
Please limit sensitive information. Do not send health records, identity-document copies, full card details, CVV codes, banking passwords or other sensitive information unless specifically needed for an explained process. If unsolicited sensitive information is received, we assess whether it may lawfully and reasonably be kept; unnecessary information should be deleted or de-identified where lawful and reasonable. An accessibility enquiry need only describe the assistance required.
Information may be collected directly from you, through the website, or from a service provider involved in your transaction. We aim to explain the relevant collection at or before it occurs, or as soon as practicable afterwards, rather than relying on a policy link alone.
Website servers and active security tools may record connection and technical information. Optional analytics and advertising tools may collect interaction and attribution information as described in Sections 8 and 9. Information transmitted directly to a third-party platform can still be relevant to our privacy responsibilities when we deploy its technology.
Collection notices and choice: APP 5 concerns notification of collection; APP 3 concerns collecting information. A general enquiry can often be made without identifying yourself. An order, delivery or account-specific request usually needs enough information to fulfil it or verify authority. Without essential details, we may be unable to complete that service. Technical logs may still be generated when you browse without creating an account.
We use information for the purpose for which it was collected and for other uses permitted by the applicable law. Where APP 6 applies, a secondary use needs an available basis, such as consent, a related purpose you would reasonably expect, or another applicable exception. Sensitive information attracts additional restrictions. A business benefit alone is not a general “legitimate interests” exception under the APPs.
| Purpose | Information involved | Relevant limitation |
|---|---|---|
| Order fulfilment | Contact details, address, products and transaction records | Picking, packing, dispatch, invoicing and delivery follow-up. |
| Workshop bookings and updates | Booking reference, appointment, vehicle details and contact information | Managing the requested service and communicating relevant status changes. |
| Vehicle compatibility and programming | Vehicle details, VIN where provided, part references and sensor IDs | The requested technical task and related support; no VIN-based marketing. |
| Invoices and financial administration | Billing details, amounts, applicable business identifiers and transaction references | Records needed for financial obligations and transaction administration. |
| Service communications | Email/phone, order or booking reference and the relevant message | Confirmation, reminders, dispatch, service and claim updates; not permission for unrelated promotions. |
| Returns, warranty and complaints | Purchase record, fault details, photos and correspondence | Assessment, a suitable remedy, follow-up and relevant dispute records. |
| Accounts and website security | Account details, logs, device data and payment/security results | Account operation and proportionate fraud or misuse investigation. |
| Website measurement and advertising | Events, device information and permitted identifiers | Only the enabled features, disclosures and choices described in Sections 8 and 9. |
| Opt-in marketing | Contact details, preferences and relevant purchase information where disclosed | Our express opt-in commitment and an effective unsubscribe option. |
| Legal requests and proceedings | Information relevant to the particular request | Only where disclosure or retention is required or otherwise lawfully permitted. |
| Privacy requests | Contact details, authority verification and request history | Locating records, providing a response and recording the outcome. |
We do not sell or rent customer contact lists. This promise is separate from disclosures to service providers and from any advertising-data sharing that must be accurately described and controlled. A service-provider privacy policy does not remove our own responsibilities for choosing and configuring that service.
Back to contentsAn online purchase or TPMS support case may involve several records. Payment credentials, transaction references and vehicle details are different information categories; keeping one does not mean the others must be retained for the same period.
| Information | Use | Relevant record or recipient |
|---|---|---|
| Name, contact and address | Order fulfilment, invoices, delivery and customer contact | WooCommerce order/account records and the providers needed for that service. |
| Booking details | Appointment administration and service-status messages | MyTPMS booking records and linked order or communication records. |
| Payment result and reference | Payment confirmation, refunds and dispute investigation | Order records and the chosen payment provider; limited transaction details may be stored by both. |
| Full card/payment credentials | Authorising the selected payment method | The payment interface and provider used at checkout. Do not send these in enquiries. |
| Vehicle details and VIN | Fitment, programming and related support | Relevant order, booking or support records where supplied and needed. |
| Sensor IDs and diagnostic photos | Cloning, identification and troubleshooting | Relevant technical or support case; images can contain personal information. |
| IP, session and security information | Operating and protecting the website | Website/server and configured security or measurement systems. |
Use the payment methods displayed in the live checkout. Payment services have their own privacy notices covering how they handle payment information, identity checks and transactions. Our order records may include the selected method, transaction identifiers, payment status and limited payment details returned by the provider.
We do not ask customers to send full card numbers, security codes, banking passwords or one-time banking codes by email, SMS or chat. Contact us using the published details if a message requests this information. An encrypted connection protects data in transit; it is not a certification of the seller or a guarantee that all systems are secure.
See Section 11 for retention and Section 12 for access, correction and deletion requests. A product warranty does not automatically justify retaining every photograph or technical detail for an indefinite period.
Back to contentsWe share information relevant to the requested service or another disclosed, lawful purpose. Access should be limited to what each recipient reasonably needs. Some providers process information on our behalf; others also have independent legal or service purposes, which their privacy terms explain.
| Recipient category | Information that may be involved | Purpose / qualification |
|---|---|---|
| Payment providers | Transaction amount, billing and payment information, payment/security results | Payments, refunds and fraud checks; the provider is identified in the payment journey. |
| Delivery providers, including Australia Post where used | Recipient name, delivery address, phone, parcel references and relevant instructions | Shipping labels, delivery, tracking and proof of delivery. |
| Guni SMS and service-email providers | Destination contact details, relevant message content, order/booking links and delivery status | Booking, workshop, order and support communications. These are not a general transfer of the customer database. |
| Hosting, maintenance and security providers | Website records, backups and logs within the relevant service | Running and protecting WordPress/WooCommerce and related systems. |
| Marketing delivery providers, where used | Subscriber contact details, consent/preferences and campaign data; purchase relevance only where actually disclosed | Sending opted-in marketing and managing unsubscribe preferences. |
| Google measurement/advertising services and other pixels, where enabled | Device, event, cookie/click identifiers and any separately disclosed user-provided data | Measurement and advertising subject to the active configuration and choices in Section 9. |
| Chat or social platforms chosen by the customer | Message, displayed profile/contact details and attachments | Responding through that channel; the platform can have its own privacy purposes. |
| Accounting and professional advisers | Transaction or case details necessary for the engagement | Financial administration, legal advice or dispute handling; not unrestricted access for every adviser. |
| Product suppliers or technical partners where needed | Relevant product, vehicle or fault information | Support or warranty investigation; use de-identified technical details where practical. |
| Authorities and other lawful recipients | Information relevant to a legal requirement or lawful request | Complying with the applicable obligation or permitted disclosure, not every informal request. |
We do not sell or rent customer mailing lists or provide them to another business for its unrelated direct marketing. Optional advertising features must still be disclosed accurately; hashing or using a service provider does not automatically mean that no personal information is shared.
Technology services and international deliveries can involve recipients outside Australia. The relevant locations can include where a provider stores information, where support staff have access and the destination of an international shipment. An Australian business address or a local website host does not establish that every recipient and backup is in Australia.
Where APP 8 applies, we must take the required reasonable steps in relation to overseas recipients unless a valid exception applies. The appropriate measures depend on the recipient, information, access and purpose. These may involve assessing the provider, contractual protections, limits on information and access, and follow-up where issues arise.
Using the site is not consent to waive APP 8 protections. The informed-consent exception is APP 8.2(b), not APP 8.2(a), and has specific requirements. No such waiver is requested by this policy. A provider’s international certification or privacy policy alone is not represented as proof of compliance with all Australian cross-border requirements.
Cookies, pixels and similar technologies can support website operation, preferences, measurement and advertising. See our Cookie Policy for information about cookies and your choices. The categories below explain their purposes.
| Category | Purpose and information | Choice and duration |
|---|---|---|
| Essential website operation | Cart/session functions, account authentication and security information needed for a requested service. | Some functions may not work if these are blocked. |
| Preferences | Settings such as consent choices or display preferences, where that feature is present. | Preference cookies support optional features rather than essential checkout functions. |
| Analytics | Page and event information, device data and identifiers that help measure website usage. | Consent or other applicable requirements depend on the implementation and law. Pseudonymous measurement is not automatically anonymous. |
| Advertising and remarketing | Ad-click, conversion and audience information; potentially identifiers that a platform can link to an account. | Our commitment is to use optional advertising and analytics tracking only after an affirmative choice. |
| Third-party embeds | A video, map or widget can send connection information and set storage when it loads. | The provider’s privacy settings and available site controls determine how an embed behaves. |
This policy does not treat continued browsing, silence or an order as consent to optional tracking. Our commitment is to provide a clear choice before optional analytics or advertising tracking operates, and a way to change that choice.
Google Merchant Center product data and customer measurement data are different. Product-feed information describes the goods offered for sale. Advertising and analytics tags may separately process information about people who visit or purchase.
Where Google Analytics 4 is used, it can process website events, device/browser information, online identifiers and approximate location. Reports may be aggregated, but the underlying information should not all be described as anonymous. Google states that GA4 does not log or store individual IP addresses; that does not establish that no network information reaches Google, or that cookie and event identifiers cannot relate to a person.
Retention, Google Signals, advertising personalisation, User-ID, user-provided data and linked advertising services depend on the property and tag settings.
Consent Mode changes Google-tag behaviour in response to consent signals; it does not obtain consent by itself. Under an advanced implementation, denied storage can still result in cookieless signals being sent. Under a basic implementation, tags can remain blocked until consent.
For the provider’s explanation of its practices, see Google’s Privacy Policy and Google’s business privacy information.
We are committed to taking reasonable technical and organisational steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. Where APP 11 applies, both the systems and the way they are managed are relevant. No internet service or storage system can be guaranteed completely secure.
Please report a suspected account compromise or accidental disclosure promptly using [email protected] or 1300 818 030. Do not send passwords, card credentials or unnecessary identity documents in the report. Where safe, change a compromised password and review affected accounts. Nothing in this section limits an applicable legal duty.
Retention depends on the type of information and the reason it is still needed. We should keep information only while reasonably necessary for the service, a relevant continuing warranty or dispute, a lawful record-keeping requirement or another permitted purpose. Once that basis ends, reasonable deletion or de-identification steps should follow. This is not an instruction to erase evidence needed for an active claim.
| Record type | Retention basis | Important distinction |
|---|---|---|
| Orders, invoices and accounting records | The applicable financial-record period and any justified continuing transaction need. | Most business tax records generally need to be kept for five years under ATO guidance; some records have longer obligations. This is not a universal seven-year rule for every customer detail. |
| Active or closed customer accounts | While providing the account and as reasonably needed for closure, security or retained transaction records. | Closing an account does not necessarily erase lawful invoice records, but it does not justify retaining every preference indefinitely. |
| Bookings and service communications | Appointment administration, support and a reasonable record of the service or dispute. | Service messages, delivery logs and booking data may have different retention periods according to their purpose. |
| Warranty, returns and complaints | The applicable support or claim needs, including preserving proof of promises and outcomes. | An eligible lifetime warranty is not an automatic reason to keep unrelated photographs or full customer histories forever. |
| VIN, sensor IDs and technical photographs | The fitment, programming, support or claim purpose for which they are needed. | These can be linked to an order; minimise information once its technical purpose is complete. |
| Marketing contacts and consent | An active subscription and a proportionate record of consent/withdrawal. | An unsubscribe suppression record may need to remain so the person is not accidentally added again. |
| Server/security and message logs | Proportionate operational, security or dispute requirements. | Retention depends on the operational, security or dispute purpose of the record. |
| Analytics and advertising records | The actual platform configuration and the lawful purpose. | Retention periods depend on the platform settings and the type of information involved. |
| Backups and archived copies | A justified backup rotation and restricted restoration process. | Deletion from live records and expiry from backups may occur separately; restored data must not undo a valid deletion or opt-out without a lawful reason. |
You may request deletion through our privacy contact at [email protected] or 1300 818 030. We aim to respond within 30 days, explain what can be deleted or de-identified, and identify any records that must remain and the reason. We will not present an internal business retention preference as a legal prohibition. We will explain the practical completion process, including any relevant backup limitations, rather than promise immediate removal from every system.
Back to contentsYou can contact us to ask about information we hold, request access or correction, seek deletion, change marketing preferences or raise a privacy concern. Statutory rights depend on the law that applies and may have exceptions; the service commitments below do not remove those rights.
Contact [email protected], 1300 818 030 or write to our privacy contact at Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia. Include enough information to identify the relevant record and explain your request. An order number may help, but is not mandatory for a person who has not placed an order.
We may check your identity or a representative’s authority in a proportionate way before releasing another person’s information. Do not send a passport or driver-licence copy unless we explain why it is needed and arrange an appropriate channel. We will assist with a request that cannot conveniently be made in writing.
We aim to respond within 30 days, and earlier where practical. Where another law requires a different timeframe or process, that requirement applies. We will explain any extension, refusal, partial response or necessary information request. An identity check should not be used to delay an otherwise valid request unnecessarily.
Our marketing commitment is express opt-in: placing an order or requesting support does not automatically subscribe you to promotional emails or SMS. Where a law permits broader consent in particular circumstances, that does not silently replace the stricter commitment made in this policy.
You do not need to use a particular email subject line to unsubscribe. We may keep a limited record of your opt-out to avoid contacting you again in error. Please tell us if a message continues after the processing period so we can investigate the relevant channel.
Some website and service functions use automated rules. These may process the information relevant to a booking, payment, delivery calculation or promotional code. Contact us to query an outcome or request staff review of a matter within our control.
| Process | Relevant information | Effect and review |
|---|---|---|
| Booking and service-message workflow | Contact details, booking/order reference, appointment and status | Guni SMS can deliver the relevant confirmation or update. Contact our team to correct a booking or message. |
| Checkout calculations and code validation | Address/postcode, cart, quantities and any entered code | The configured rules calculate options or accept/reject a code. Contact us about an apparent error. |
| Fraud screening and payment decisions | Depends on the payment/security provider; may include transaction, device and address information | Provider rules may result in a hold, decline or other payment outcome. MyTPMS review can address matters within our control; a provider may make a separate decision. |
From 10 December 2026, additional APP 1 disclosure obligations apply to covered entities arranging for a computer program to use personal information in decisions reasonably expected to significantly affect an individual’s rights or interests. They can also cover a program doing something substantially and directly related to making such a decision; the presence of a human does not automatically remove the requirement.
Where the requirements apply, the policy needs to describe the kinds of personal information used, kinds of decisions made solely by computer programs, and kinds of decisions substantially and directly assisted by them.
Back to contentsMyTPMS sells technical automotive products and its purchasing arrangements are intended for adults, or for a parent or guardian purchasing for a younger person. That is a purchasing policy, not proof that no child can visit the website or generate website logs.
To report a concern, contact our privacy contact at [email protected] or 1300 818 030. Provide only the details needed to locate the issue.
Back to contentsWe will take a suspected data incident seriously, contain it where possible, investigate the information affected and consider steps that reduce potential harm. Statutory reporting depends on the law and circumstances. The Australian Notifiable Data Breaches (NDB) scheme applies to covered entities and information; not every incident is legally notifiable.
Under the NDB scheme, an eligible breach generally involves unauthorised access to or disclosure of personal information, or loss with likely unauthorised access/disclosure, where serious harm to an individual is likely. Effective remedial action and statutory exceptions can affect whether notification is required.
Report suspected account compromise or accidental disclosure through [email protected] or 1300 818 030. Avoid including payment credentials. The Australian Cyber Security Centre provides information about cyber incidents and reporting. We will consider useful protective communication even when an incident does not meet a statutory notification threshold.
International customers may have additional rights where a local law applies to MyTPMS or to a particular service provider. Applicability depends on the law’s territorial and other scope, not merely on someone opening the website from another country. Australian-law wording is not intended to remove mandatory overseas protections.
The Privacy Act and APPs apply according to their scope. OAIC guidance explains coverage and privacy rights.
Official guidanceWhere the GDPR applies, rights can include access, correction, erasure, restriction, objection and portability, subject to the relevant conditions.
Official guidanceWhere UK data-protection law applies, the ICO explains individual rights and complaint options. Do not assume every EU and UK rule is identical.
Official guidanceWhere New Zealand privacy law applies, access, correction and privacy complaint rights can be relevant.
Official guidanceFederal or provincial rules may apply to the handling of personal information; marketing rules are a separate consideration.
Official guidanceState and sector rules can apply subject to scope and thresholds. California’s sale/sharing terminology requires particular attention.
Official guidanceWhere the PDPA applies, refer to the PDPC for current rights and requirements.
Official guidanceWhere Japanese privacy law applies, the PPC provides guidance about handling personal information and individual rights.
Official guidanceWhere applicable, you may request access or correction, erasure or restriction, object to relevant processing, or request portability of eligible information. These rights have conditions and exceptions. Direct-marketing objections and consent withdrawals must be handled according to the applicable law. You may also have protections relating to significant automated decisions and a right to complain to the relevant supervisory authority.
Where California law applies, “sharing” can include cross-context behavioural advertising even where no customer list is sold for money. Applicable rights may include opting out of sale or sharing and using recognised privacy preference signals. Contact us about the information relevant to your request and the choices available.
Back to contentsContact us if you believe information has been collected, used, retained or disclosed incorrectly, or a privacy request has not been handled properly. We will consider the concern fairly and explain the outcome. You will not be charged for lodging a privacy complaint.
Email [email protected], call 1300 818 030, use the Contact Us page, or write to Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia. Describe what happened, the relevant date or record if known, and the outcome you seek. A particular subject line or order number is helpful but not mandatory.
Our response commitment: We will acknowledge a privacy complaint within two business days and provide a written response within 30 days. We will explain the investigation, outcome and any further steps. If a matter is complex, we will communicate the reason and next steps without limiting your independent escalation rights.
Business-day calculations use Melbourne local time and exclude Victorian public holidays. The broader Complaints & Dispute Resolution Policy can provide an earlier service-response or update commitment; this privacy process does not cancel that commitment or extend a statutory deadline.
The OAIC generally expects a written complaint to the business first and a reasonable opportunity to respond, usually 30 days. It determines whether a complaint is within its jurisdiction. You may seek advice earlier, and nothing here requires you to delay urgent action or miss a legal or payment-dispute deadline.
| Authority | Relevant scope | Contact |
|---|---|---|
| Office of the Australian Information Commissioner | Australian privacy matters within its jurisdiction | OAIC privacy complaints · 1300 363 992 |
| Office of the Privacy Commissioner (NZ) | New Zealand privacy matters within its jurisdiction | privacy.org.nz |
| Information Commissioner’s Office | UK data protection and related privacy matters | ICO complaints |
| National data protection authority | EU/EEA supervisory authority appropriate to the case | EDPB member authorities |
| Office of the Privacy Commissioner of Canada | Federal Canadian privacy matters; provincial routes may also be relevant | priv.gc.ca |
| California Privacy Protection Agency | California privacy matters within its jurisdiction | cppa.ca.gov |
Other complaint, court or legal rights may be available. This page neither waives those rights nor guarantees that no privacy claim could arise. Seek independent advice where needed.
Back to contentsWe may revise this policy when our services, data handling, legal obligations or privacy controls change. The date shown on this page identifies the latest revision.
We review this policy when introducing a payment, marketing, support, hosting or customer-data service that changes how personal information is handled.
Back to contentsThe following guide summarises the 13 Australian Privacy Principles. Their application depends on legal coverage, relevant exceptions and the circumstances in which personal information is handled.
For more information, see the OAIC’s Australian Privacy Principles guidance.
Back to contentsThese pages explain other aspects of shopping and support. They do not turn this privacy notice into blanket consent or remove applicable privacy rights.
Contact our team about access, correction, deletion, marketing choices or a privacy concern. Customer-support hours are Monday–Friday, 9 am–5 pm, Melbourne local time.
© 2026 MyTPMS Australia · ABN 53 807 701 500
Workshop and dispatch: Unit 5–6, 44–50 Westall Road, Springvale VIC 3171, Australia.
[email protected] · 1300 818 030
Terms of Service · Cookie Policy · Returns & Refunds · Shipping · Contact Us page