Privacy policy

Last updated: 31.08.2026


1. About this policy

This Privacy Policy explains how we collect, hold, use and disclose personal information when you visit 3hlinen.com.au, place an order, contact us, or otherwise deal with our business.

We have written it to be specific. Rather than referring generally to "third parties", we name the services we use, explain what each does with your information, and tell you where that information goes.

This policy is our policy under Australian Privacy Principle 1, which requires us to manage personal information in an open and transparent way and to maintain a clearly expressed, up-to-date privacy policy.

1.1 Who we are

Entity Three Trading Group Incorporated
Incorporated in California, United States of America
Principal place of business 965 Duncan Street, San Francisco, CA 94131, United States
Australian place of business 602–612 Botany Road, Alexandria NSW 2015, Australia
ABN 87 109 963 995
Privacy contact marketing@3hlinen.com.au]

In this policy, "we", "us", "our" and "3H Linen" mean Three Trading Group Incorporated. "You" and "your" mean the individual whose personal information we handle.

Please note: we are a company incorporated in the United States, operating in Australia through our Australian place of business. This means personal information you give us will be handled both in Australia and in the United States, and by service providers in other countries. Section 8 explains this in detail, and it is important that you read it.

1.2 Which laws apply

We handle personal information in accordance with:

  • The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles in Schedule 1 of that Act
  • The Notifiable Data Breaches scheme in Part IIIC of the Privacy Act
  • The Spam Act 2003 (Cth), which governs commercial electronic messages
  • The Do Not Call Register Act 2006 (Cth), where we make marketing telephone calls
  • The Australian Consumer Law, in relation to the information we give you about our products

Because we carry on business in Australia and collect personal information here, we have an Australian link under section 5B of the Privacy Act, and the Act applies to our handling of that information regardless of where it is ultimately stored.

We are not a small business operator for the purposes of the Privacy Act, and we comply with the Australian Privacy Principles in full.

1.3 Anonymity and pseudonymity (APP 2)

You may deal with us anonymously or under a pseudonym where it is lawful and practicable. For example, you may browse our website, make a general product enquiry, or ask about delivery times without telling us who you are.

It is not practicable for us to deal with you anonymously when you place an order, because we need your name and address to make and deliver your items, and your contact details to keep you informed and to process any return.


2. What personal information we collect

2.1 Information you give us

Category Examples When we collect it
Identity information First name, last name, business name for trade customers Account creation, checkout, enquiries
Contact information Email address, telephone number, delivery address, billing address, state and postcode Checkout, account creation, newsletter signup
Account information Username, password (stored in hashed form by our platform), saved addresses, preferences When you register
Order information Products ordered, quantities, made-to-measure specifications (width, drop, heading type, lining, colour), order value, discount codes, order history When you order
Payment information Payment method type, last four digits of your card, cardholder name, billing address, transaction reference, payment status. We do not receive or store your full card number, expiry date or security code At checkout
Communications Emails, contact form submissions, live chat transcripts, and social media messages Whenever you contact us
Marketing preferences Whether you have consented to email or SMS marketing, and your later choices Signup, checkout, preference centre
Reviews and feedback Product reviews, ratings, review photographs, survey responses When you submit them
Trade account information Company name, ABN, trading address, contact person, account terms Trade account application

2.2 Information we collect automatically

Category Examples
Device and technical information IP address, browser type and version, operating system, device type, screen resolution, language and locale, time zone
Usage information Pages viewed, products viewed, search terms, time on page, scroll depth, clicks, referring website, exit pages
Session recordings Anonymised recordings of mouse movement, clicks and scrolling, and aggregated heatmaps
Basket information Items added to and removed from your basket, including abandoned baskets
Advertising identifiers Cookie identifiers, advertising identifiers, click identifiers such as Google's GCLID and Meta's FBCLID, and pseudonymous identifiers created by our server-side tracking

2.3 Information from other sources

  • Payment providers — whether a payment succeeded, was declined or was flagged as suspicious, and chargeback information
  • Advertising platforms — aggregated campaign reporting and, where you have consented, matched-audience information
  • Carriers and fulfilment partners — delivery status, tracking events, delivery confirmations, failed delivery reports
  • Review platforms — reviews you submit and the display name you choose
  • Social media platforms — the content of public posts or messages you send us
  • Other customers — if someone orders a gift for delivery to you, we receive your name, address and contact details from them

2.4 Sensitive information (APP 3.3)

Sensitive information under the Privacy Act includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal record.

We do not seek sensitive information and we do not need it to sell you curtains or bedding.

You may nonetheless volunteer it — for example, by telling us that you need blackout curtains because of a medical condition affecting sleep, or a particular fabric because of a religious observance. Where this happens, we treat your act of volunteering it in the context of your enquiry as your consent to us collecting it for the purpose of answering that enquiry. We do not use it for marketing, profiling or any other purpose.

If you would prefer us not to keep such information, contact us and we will remove it from our records.

2.5 Government related identifiers (APP 9)

We do not collect, use or disclose government related identifiers such as Tax File Numbers, Medicare numbers, driver licence numbers or passport numbers, and we do not adopt them as our own identifiers for you.

The only exception is where a carrier or customs authority requires identification for an international shipment, in which case any identifier is used solely for that purpose.

2.6 Unsolicited information (APP 4)

If we receive personal information we did not ask for, we assess whether we could have collected it under APP 3. If we could not, and it is not contained in a Commonwealth record, we destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

2.7 Children

3hlinen.com.au is intended for adults. We do not knowingly collect personal information from anyone under 18 and we do not direct marketing at children.

If we learn we have collected a child's personal information without appropriate authorisation, we will delete it. If you believe a child has given us personal information, contact us.


3. Why we collect, hold, use and disclose your information

Under APP 3 we only collect personal information that is reasonably necessary for our functions and activities. Under APP 6 we only use or disclose it for the purpose we collected it (the primary purpose), for a related secondary purpose you would reasonably expect, with your consent, or where required or authorised by law.

3.1 Fulfilling your order — primary purpose

Processing your order, taking payment, manufacturing your made-to-measure items, arranging delivery, handling returns, refunds and exchanges, and communicating with you about your order.

Order confirmations, dispatch notices, delivery updates and messages about your specific order are service messages, not marketing. Under the Spam Act, messages of this kind are not commercial electronic messages requiring consent. You will receive them whether or not you have consented to marketing, because we need to send them to complete your order.

3.2 Made-to-measure manufacturing

Transmitting your measurements, fabric and finishing choices to the facility that makes your items, together with your name, order reference, and delivery address where the item is dispatched directly to you.

3.3 Customer service

Responding to enquiries by email, contact form, live chat and telephone; verifying your identity; investigating complaints; and keeping records of our correspondence so we can deal with any later question about your order.

3.4 Account management

Creating and maintaining your account, authenticating you, storing your saved addresses and order history, and letting you track orders.

3.5 Direct marketing (APP 7 and the Spam Act)

We send newsletters, information about new products and collections, seasonal offers and discount codes by email, and — where you have given a mobile number and consented — by SMS.

Consent. Under the Spam Act 2003, we may send commercial electronic messages where you have given:

  • Express consent — you have actively told us you want to receive marketing, for example by ticking an unticked box or subscribing to our newsletter; or
  • Inferred consent — consent may reasonably be inferred from your conduct and our existing business relationship, for example where you have purchased from us and would reasonably expect to hear about similar products.

We do not rely on inferred consent indefinitely. Where you have not purchased from us and have not expressly consented, we do not market to you.

Every marketing message we send:

  • Clearly identifies us as the sender and gives our contact details, as the Spam Act requires
  • Contains a functional unsubscribe facility
  • Is honoured within 5 working days of your unsubscribe request, as the Spam Act requires (in practice we act immediately)

How to opt out:

  • Click "unsubscribe" in any marketing email
  • Reply STOP to any marketing SMS
  • Change your preferences in your account
  • Contact us at the address in Section 15

Email and SMS consent are separate. Opting in to one does not opt you in to the other. Giving us your telephone number so we can arrange delivery is not consent to marketing SMS — we only send marketing SMS where you have specifically agreed to receive it.

Telemarketing. If we make marketing telephone calls, we check numbers against the Do Not Call Register as required by the Do Not Call Register Act 2006.

Your right to ask. Under APP 7.6 you may ask us to tell you where we obtained your information for direct marketing purposes. We will tell you, free of charge, within a reasonable period.

3.6 Business-to-business marketing

We market to businesses including interior designers, hospitality buyers and trade customers. The Spam Act applies to business addresses in the same way as to personal ones, so we rely on express or inferred consent and include an unsubscribe facility in every message.

3.7 Abandoned basket reminders

If you enter your email address and add items to your basket but do not complete your order, we may send you a reminder — but only where you are an existing customer or have consented to marketing.

3.8 Personalisation and profiling

We analyse your browsing and purchase history to group customers by interest, order frequency or value, and to tailor the content of our marketing and the advertisements you see.

This does not affect the price you pay, whether we accept your order, or the terms we offer you. It affects which marketing you see.

You can ask us to stop using your information for direct marketing and profiling at any time, and we will.

3.9 Advertising and audience matching

We advertise on Google, Meta (Facebook and Instagram), Microsoft (Bing) and Pinterest. This includes:

  • Retargeting — showing you advertisements for products you viewed
  • Conversion tracking — measuring which advertisements led to sales
  • Customer Match and Custom Audiences — providing hashed (irreversibly scrambled) versions of your email address or phone number to Google and Meta so they can show our advertisements to you if you hold an account with them
  • Lookalike and similar audiences — asking those platforms to find new potential customers resembling our existing customers

About hashed uploads. Your email address or phone number is converted using a one-way SHA-256 hash before it leaves our systems. The platform compares this against hashes of its own users. We do not send your details in readable form. This is still a disclosure of your personal information, and we only make it where you have not opted out.

To be excluded from audience matching, contact us and we will suppress your details from future uploads.

3.10 Analytics and site improvement

Measuring how our website is used, identifying pages that perform poorly, diagnosing faults and testing changes, using Google Analytics 4, Microsoft Clarity, our platform's built-in analytics, and HubSpot analytics.

Microsoft Clarity records anonymised session replays configured to mask text you type into form fields, including payment and address details. Recordings show interaction patterns, not the content of what you type.

3.11 Reviews and feedback

Inviting you to review products you have purchased, and publishing those reviews through Judge.me and Trustpilot.

Reviews are published with the display name you choose. Please do not include personal details in review text — published reviews are visible to anyone.

3.12 Fraud prevention and payment security

Screening orders for indicators of fraud, verifying identity where an order is unusual, and investigating chargebacks, using order, payment, device and technical information including IP address.

Our platform and payment providers apply automated fraud scoring. Where an order is flagged, a person reviews it before any decision is made. If we decline an order, you may contact us for an explanation and to provide further information.

3.13 Legal compliance and business records

Keeping accounting and tax records, meeting our obligations under Australian and United States law, responding to regulators, courts and law enforcement, and establishing or defending legal claims.

3.14 Business transfers

If we sell or reorganise our business, customer information may be transferred to the acquiring entity. We would tell you about any such transfer and any change to how your information is handled.


4. Who we disclose your information to

We do not sell your personal information. We do not disclose your contact details to other companies so they can market their own unrelated products to you.

Everything below is a service provider acting on our instructions, an organisation handling your information for its own purposes in a way you would expect, or a disclosure required by law.

4.1 E-commerce platform

Shopify Inc. / Shopify International Ltd — hosts our store and handles accounts, orders, checkout, customer records and built-in analytics. https://www.shopify.com/legal/privacy

4.2 Payment providers

These organisations handle payment information for their own purposes and under their own privacy policies.

Provider What they handle
Shopify Payments (with Stripe as underlying processor) Card details, transaction data, fraud signals
Stripe Card details, transaction data, fraud signals
PayPal Australia Pty Limited Account identifier, transaction data, address
Klarna Identity, contact, order and payment data; Klarna conducts its own assessment for its pay-later products
Apple Pay Device payment token, transaction confirmation
Google Pay Device payment token, transaction confirmation

About Klarna. If you choose a Klarna pay-later or instalment option, Klarna acts as your credit provider, conducts its own checks and handles your information under its own privacy policy. We do not conduct credit checks and we do not receive credit reporting information about you. Nothing in this policy relates to credit reporting under Part IIIA of the Privacy Act, because we are not a credit provider.

We do not receive or store your full card number, expiry date or security code.

4.3 Manufacturing and fulfilment

Provider What they handle
Our manufacturing facility Order specifications, name, order reference, and delivery address where dispatched directly
ShipBob, Inc. Name, delivery address, contact details, order contents
SkladUSA Name, delivery address, contact details, order contents
Fulfillment Network Name, delivery address, contact details, order contents

4.4 Carriers

Provider What they handle
Australia Post / StarTrack Name, delivery address, contact details for delivery notifications
FedEx Name, delivery address, contact details, customs information

For international shipments, carriers provide your name, address and shipment contents to customs authorities as required by law.

4.5 Marketing and communications

Provider Purpose
Klaviyo, Inc. Email marketing, segmentation, campaign analytics, abandoned basket messages
Sakari SMS marketing and transactional SMS
HubSpot, Inc. Customer relationship management, contact records, forms, marketing analytics

4.6 Advertising and analytics platforms

These platforms handle information for their own purposes as well as ours, under their own privacy policies.

Provider Purpose
Google LLC Google Ads, Google Analytics 4, Google Tag Manager, Merchant Center, Customer Match
Meta Platforms, Inc. Meta Pixel, Conversions API, Custom Audiences, Lookalike Audiences
Microsoft Corporation Microsoft Advertising (Bing) UET, Microsoft Clarity
Pinterest, Inc. Pinterest Tag, conversion tracking, retargeting
Stape Server-side tag management infrastructure (see Section 7.3)

4.7 Customer service and operations

Provider Purpose
Intercom (including Fin AI) Customer service messaging and AI-assisted response drafting
Tidio Live chat
Shopify Inbox Live chat integrated with our store
Zapier, Inc. Automated transfer of information between the systems listed in this policy
Make (Celonis SE) Automated workflows between the systems listed in this policy

About AI-assisted customer service. Intercom's Fin feature uses artificial intelligence to draft or suggest responses based on the content of your message and our help content. Our staff review responses before any substantive decision is made about your order, refund or complaint. We do not permit your enquiries to be used to train third-party AI models.

4.8 Reviews

Judge.me — product reviews. Trustpilot A/S — business reviews, published on Trustpilot's own platform under its privacy terms.

4.9 Store functionality applications

We use applications installed on our store to provide specific features. They handle personal information only as needed for the feature and only on our instructions, in the following categories:

  • Product configuration — capturing your made-to-measure specifications
  • Checkout and order management — customising checkout, applying order rules, generating invoices and packing slips
  • Regional routing — directing you to the appropriate store for your country based on your IP address
  • Product recommendations — suggesting related items
  • Consent management — our cookie banner and consent records

A current list of the applications with access to personal information is available on request.

4.10 Professional advisers and authorities

We may disclose personal information to accountants, auditors, lawyers and insurers where necessary; to the Australian Taxation Office and other tax authorities as required by law; and to courts, tribunals, regulators and law enforcement where required or authorised by law, or where necessary to protect our rights or the safety of others.


5. Related companies

3hlinen.com.au is operated by Three Trading Group Incorporated. We operate related stores in the United Kingdom and the United States.

We do not routinely share Australian customer information with those operations for marketing purposes. Where information is shared for operational reasons — for example, where an item is manufactured or dispatched from an overseas facility — it is limited to what is necessary for that purpose.


6. Cookies and tracking technologies

6.1 How cookies work on this website

Cookies are small files placed on your device when you visit a website. We also use related technologies — pixels, tags and software development kits — which work in similar ways.

Australian law does not require us to obtain your consent before setting cookies, and we do not display a cookie consent banner on this website. Cookies are set when you visit. This section explains what they do, and Section 6.4 explains how you can control them.

Where information collected through cookies is personal information under the Privacy Act, we handle it in accordance with the Australian Privacy Principles and this policy, including the overseas disclosure arrangements described in Section 8.

6.2 What we use cookies for

Strictly necessary — session management, shopping basket contents, checkout state, security and bot protection, load balancing, language and region preference. Without these the website cannot function, and blocking them will prevent checkout from working.

Analytics — measuring how the website is used, so we can identify pages that perform poorly and diagnose faults. We use Google Analytics 4, Microsoft Clarity, HubSpot analytics, and our platform's built-in analytics.

Advertising — measuring which advertisements lead to sales, and showing you advertisements for products you have viewed. We use Google Ads conversion and remarketing tags, the Meta Pixel, Microsoft Advertising UET, the Pinterest Tag, and marketing attribution built into our platform.

Functional — live chat and review widgets.

6.3 Server-side tracking — important disclosure

We use Stape to operate a server-side tag management container on a subdomain of our own website.

What this means. Instead of your browser sending tracking data directly to Google, Meta and other platforms, it sends data to our own subdomain first. Our server then forwards that data to the advertising platforms.

Why we are telling you. Server-side tracking is less visible than ordinary cookies. Because the requests go to a subdomain of our own site, they may not appear in browser privacy tools or third-party cookie scanners as advertising activity, and cookies set this way are first-party cookies with longer lifespans that browsers do not automatically restrict.

What you should know:

  • The information still reaches Google, Meta, Microsoft and Pinterest, and it is still your personal information.
  • Information forwarded may include pseudonymous identifiers, page addresses, product identifiers, order values, click identifiers, IP address and browser type, and — for completed purchases — hashed contact details.
  • Because this tracking operates from our server rather than from your browser, browser-based blocking tools may not prevent it. If you want us to stop, contact us using the details in Section 17 and we will exclude you.
  • Server-side event data passes through our systems in transit and is not stored beyond technical logs kept for up to 30 days.

6.4 How you can control tracking

You have the following options.

Browser settings — every major browser lets you block or delete cookies, and most offer a tracking protection or "do not track" setting. Blocking strictly necessary cookies will prevent our checkout from working.

Device advertising settings — mobile operating systems let you reset or limit your advertising identifier.

Platform opt-outs — you can control how the advertising platforms we use handle your information directly with them:

Ask us directly — contact us using the details in Section 17 and we will:

  • exclude you from server-side tracking, which browser tools cannot block
  • suppress your details from Customer Match and Custom Audience uploads to Google and Meta
  • stop using your information for direct marketing and profiling

We will confirm when we have done so.


7. Data quality (APP 10)

We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant.

You can help by keeping your account details current and telling us when something changes. If you believe our records are wrong, see Section 11.


8. Sending information overseas (APP 8)

This section is important. Please read it.

We are incorporated in the United States, and most of our service providers are based outside Australia. Your personal information will be disclosed to, and stored in, countries other than Australia.

8.1 Where your information goes

Country Recipients
United States Three Trading Group Incorporated (our own operations), Shopify, Google, Meta, Microsoft, Pinterest, Klaviyo, Sakari, HubSpot, Stripe, PayPal, Intercom, Zapier, ShipBob, SkladUSA, Fulfillment Network, FedEx, Judge.me
Canada Shopify (data centres)
Ireland and other EU Member States Google, Meta, Microsoft (regional operations), Trustpilot (Denmark), Make (Germany), Stape
United Kingdom and Poland Our related operations, where an item is manufactured or dispatched from those facilities

8.2 What this means for you

Under APP 8.1, before we disclose your personal information to an overseas recipient we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles. We do this through written contracts requiring the recipient to protect your information to a standard consistent with the APPs, assessment of providers before we engage them, and restricting what each provider receives to what it needs.

Under section 16C of the Privacy Act, we generally remain accountable to you for what an overseas recipient does with your information, as if we had done it ourselves. If an overseas recipient mishandles your information, you may complain to us, and to the Office of the Australian Information Commissioner.

However, you should understand: the countries listed above may not have privacy laws equivalent to Australia's, and you may not be able to seek redress in those countries under Australian law. In particular, information held in the United States may be accessible to United States authorities under United States law, including in circumstances where Australian law would not permit access.

By providing us with your personal information and proceeding with an order, you acknowledge these disclosures.


9. How long we keep your information (APP 11.2)

Under APP 11.2 we must destroy or de-identify personal information once we no longer need it for any purpose for which it may be used or disclosed, unless we are required by law to keep it.

Information Retention Reason
Order and transaction records 5 years from the transaction Income Tax Assessment Act and GST record-keeping requirements
Financial and tax records 5 years Australian Taxation Office requirements
Customer account information Until you close your account, then 30 days, except where order records must be kept Account closure
Made-to-measure specifications 5 years Kept with order records; also needed for warranty and repeat orders
Marketing consent records Duration of consent plus 3 years Evidence of compliance with the Spam Act
Marketing contact information Until you unsubscribe, or 24 months of inactivity, whichever is sooner Minimising what we hold
Live chat and email correspondence 3 years from last contact Complaint and claim periods
Cookie consent records 12 months Demonstrating consent
Website analytics 14 months Platform configuration
Server-side tracking logs 30 days Technical troubleshooting
Reviews Indefinitely while published, unless you ask us to remove them Ongoing publication
Access and correction request records 3 years from completion Demonstrating compliance
Complaint records 6 years from closure Legal claim periods

Where we no longer need information but cannot delete it immediately — for example in backups — we isolate it from active use and delete it when the backup cycle completes.


10. Accessing your information (APP 12)

You may ask us for access to the personal information we hold about you.

How to ask. Contact us at the address in Section 15 with "Privacy — Access Request" in the subject line. Tell us your name, the email address associated with your account or orders, and what information you are seeking.

Identity verification. We will ask you to verify your identity before we release information, so that we do not disclose your information to someone else. We ask for the minimum necessary — usually confirmation from the email address on your account, or details of a recent order. We do not require identity documents for routine requests.

Timeframe. We respond within 30 days.

Fees. We do not charge for making a request. We may charge a reasonable fee for giving access where a request requires substantial work — for example, retrieving archived records. Any fee will not be excessive, we will tell you what it is before we do the work, and you may withdraw your request at that point.

If we refuse. We may refuse access in the limited circumstances set out in APP 12.3 — for example, where giving access would unreasonably affect another person's privacy, where the request is frivolous or vexatious, or where access would be unlawful. If we refuse, we will give you written reasons, tell you how to complain, and consider whether we can give access in another way, such as through a mutually agreed intermediary.


11. Correcting your information (APP 13)

If the personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it. You can update most account details yourself by logging in.

How to ask. Contact us at the address in Section 15 with "Privacy — Correction Request" in the subject line.

Timeframe. We respond within 30 days, and correction is free.

Notifying others. If we have disclosed the incorrect information to another organisation, you may ask us to tell them about the correction, and we will take reasonable steps to do so unless it is impracticable or unlawful.

If we refuse. We will give you written reasons and tell you how to complain. You may also ask us to attach a statement to the information noting that you consider it inaccurate, incomplete, out of date, irrelevant or misleading, and we will take reasonable steps to make that statement apparent to anyone who accesses the information.


12. What we cannot do — please read

Australian privacy law is different from European and United Kingdom law in ways that matter to you.

There is no general right to erasure under the Privacy Act. You may ask us to delete your information, and we will do so where we no longer need it and are not required to keep it. But unlike under the European General Data Protection Regulation, you do not have a general legal right to demand deletion, and we cannot delete records we are required by tax and business law to retain.

There is no general right to data portability under the Privacy Act, although you may request access to your information under APP 12 and we will provide it in a usable form where practicable.

What you can always do: stop receiving marketing, access your information, correct your information, and complain.


13. Data breaches (Notifiable Data Breaches scheme)

If we suspect a data breach may have occurred, we assess it within 30 days.

If we determine there has been an eligible data breach — unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to any affected individual, and we have not been able to prevent that harm — we will:

  • Notify the Office of the Australian Information Commissioner as soon as practicable
  • Notify you directly, if you are affected or at risk, telling you what happened, what information was involved, and what you should do in response

Where direct notification is not practicable, we will publish a statement on our website and take reasonable steps to publicise it.


14. Security (APP 11.1)

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including:

  • Encryption in transit — TLS across our website and administrative systems
  • Encryption at rest — applied by our platform and hosting providers
  • Access control — role-based access on a least-privilege basis, individual staff accounts, and multi-factor authentication for staff with access to customer information
  • Payment security — PCI DSS compliance through our payment providers; we never handle full card numbers
  • Provider due diligence — assessment before engagement, and written agreements
  • Bot and abuse protection across our infrastructure
  • Backups — regular encrypted backups with tested restoration
  • Incident response — a documented procedure for detecting, assessing and reporting breaches

No system is completely secure. Please use a strong, unique password and tell us immediately if you suspect unauthorised access to your account.


15. Complaints

If you think we have breached the Australian Privacy Principles or mishandled your personal information, please tell us. We would like the chance to put it right.

How to complain

Contact us with "Privacy Complaint" in the subject line:

Email: marketing@3hlinen.com

Post: Privacy Officer Three Trading Group Incorporated 602–612 Botany Road Alexandria NSW 2015 Australia

To help us investigate, please include your name and contact details, a clear description of what happened, relevant dates and order numbers, and what outcome you are seeking.

What happens next

  1. Within 5 working days — we acknowledge your complaint in writing.
  2. Investigation — we review what happened and may contact you for more information.
  3. Within 30 days — we give you a full response setting out our findings, any action we are taking, and what you can do if you remain dissatisfied. If the matter is complex we will tell you within the 30 days and give a revised timeframe.

We keep records of complaints for 6 years from closure.

If you are not satisfied

You may complain to the Office of the Australian Information Commissioner:

GPO Box 5218, Sydney NSW 2001 Phone: 1300 363 992 Online: https://www.oaic.gov.au/privacy/privacy-complaints

The OAIC generally expects you to complain to us first and to allow us 30 days to respond, but you may contact the OAIC at any time for advice.

Spam and telemarketing complaints may also be made to the Australian Communications and Media Authority at https://www.acma.gov.au


16. Changes to this policy

We review this policy at least annually and update it when our handling of personal information changes.

The "Last updated" date at the top shows when it was last revised. For significant changes — new purposes, new categories of recipient, or changes affecting your rights — we will tell you by email or a prominent notice on our website before the change takes effect.

Previous versions are available on request.


17. Contact us

Privacy enquiries, access and correction requests, and complaints:

Email: marketing@3hlinen.com

Post: Privacy Officer Three Trading Group Incorporated 602–612 Botany Road Alexandria NSW 2015 Australia

Registered office: 965 Duncan Street, San Francisco, CA 94131, United States

ABN: 87 109 963 995

You may also obtain a copy of this policy in an alternative format on request.


This document was prepared for Three Trading Group Incorporated in respect of 3hlinen.com.au. It is not legal advice and should be reviewed by an Australian legal practitioner before publication.