amiss

Privacy Policy

Last updated 26 July 2026

This policy explains how AMISS PTY LTD (ABN 51 671 031 913), trading as amiss, handles your personal information when you use the amiss Winter Solstice Sale site at solistice.amiss.online. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

1. What we collect

  • Your email address — when you subscribe at the gate, when you sign in, and when you claim something in the egg hunt.
  • Your Instagram handle — only if you claim one of the three first-finder prizes, so we can verify and announce the win.
  • Your prize and gift records — which puzzles you solved and what you were awarded.
  • Your IP address and browser information — collected automatically when you use the site, and used to rate-limit sign-in attempts and protect the site from abuse.
  • How you use the site — the pages you view and the clicks, scrolls and mouse movements on them, recorded by our analytics tool so we can see where the sale site is confusing. What you type into a form is masked in your browser and is never recorded.
  • Order and delivery details — your name, delivery address, contact details and order contents, collected by Shopify when you check out.
  • Email engagement — whether our emails were delivered, opened or clicked.

We don't collect payment card details. Payment is handled entirely by Shopify's checkout.

We don't knowingly collect personal information from children. The sale site is intended for adults, and the egg hunt is open only to people aged 18 or over.

2. Cookies and local storage

When you sign in we set one cookie holding a signed access token. It is httpOnly, it contains no personal information — only an opaque identifier — and it expires when the sale closes.

Your browser also stores, on your device only, the email address you entered and which eggs you've found, so the site doesn't ask you twice. You can clear this at any time through your browser.

Shopify sets its own cookies during checkout, governed by Shopify's privacy policy.

We use Microsoft Clarity to see how the site is used. It sets cookies holding a pseudonymous id for your browser — two on this site, and several more on Microsoft's own domains, which Microsoft also uses for advertising and other operational purposes.

We don't run advertising on the sale site, and we never send Clarity your email address. You can opt out of Clarity everywhere it runs at optout.aboutads.info, and Clarity honours the Global Privacy Control signal if your browser sends one.

3. Why we collect it

  • To give you access to the sale and send you one-time sign-in codes.
  • To send you sale and marketing email, where you've asked us to.
  • To run the egg hunt: to check who found what first, to apply the one-major-prize-per-person rule, to verify winners and to deliver prizes and credits.
  • To take, fulfil and deliver your order, and to deal with returns and warranty claims.
  • To protect the site — rate limiting, and detecting and preventing abuse of the gate or the hunt.
  • To meet our legal obligations, including record-keeping for tax and consumer law.

If you don't give us your email address we can't give you access to the sale, and we can't run the hunt for you.

4. Automated decisions

Some decisions on the sale site are made automatically by our software using your email address — whether your address is eligible to sign in on a given day, and whether you're the first person to solve a puzzle. These decisions affect access to a retail sale and to prizes. Every prize is verified by a person before it is awarded, and if you think an automated decision got something wrong, email us and we'll look at it ourselves.

5. Who we share it with, and where they are

We use the following service providers. Most are located outside Australia, which means your personal information is disclosed overseas.

  • Klaviyo (United States) — our email platform. Holds your email address, your subscription status, the sale properties attached to your profile, and your engagement with our emails.
  • Neon (United States, Oregon) — our database. Holds your email address, your sign-in code hashes, your Instagram handle if you claimed a prize, and your prize and gift records.
  • Vercel (United States) — hosts the sale site and processes requests, including your IP address in its logs.
  • Microsoft (United States) — Microsoft Clarity, our site analytics. Holds a recording of how you used the sale site, along with your device, browser and general location.
  • Shopify (Canada and the United States) — runs checkout, payment and order fulfilment.
  • Upstash (overseas; we name the country here as soon as we have confirmed which region our rate-limit store runs in) — holds short-lived rate-limiting counters keyed to your IP address and email.

We take reasonable steps to ensure these providers handle your information consistently with the Australian Privacy Principles. We may also disclose your information where the law requires it, or to protect our rights.

We do not sell your personal information.

6. Marketing email and how to stop it

We only send marketing email to people who asked for it. Every marketing email we send identifies AMISS PTY LTD and includes an unsubscribe link that works for at least 30 days. Unsubscribing takes effect within five business days. Sign-in codes and order confirmations are not marketing — we'll still send those while you have an active order or are using the sale site.

You can also unsubscribe by emailing hello@amiss.com.au.

7. How long we keep it

  • Sign-in codes — hashed, and consumed or superseded on use; retained no longer than needed to operate the gate.
  • Rate-limiting records — a short rolling window (minutes), then discarded.
  • Analytics recordings — held by Microsoft for 30 days, with a small sample of recordings and the aggregated heatmaps kept for up to nine months.
  • Subscriber records — kept until you unsubscribe or ask us to delete them.
  • Prize and gift records — kept for the sale and for a reasonable period afterwards so we can honour, verify and account for prizes.
  • Order records — kept for at least five years, as required by Australian tax law.

When we no longer need personal information and we're not required to keep it, we delete it or de-identify it.

8. How we protect it

Access to the sale is protected by a signed, httpOnly token rather than a stored password. Sign-in codes are stored only as hashes — we never hold the code itself. Traffic to the site is encrypted in transit. Our credentials are held server-side and never sent to your browser, and sign-in is rate limited. No system is perfectly secure, but we take reasonable steps to protect your information, and if there is a data breach likely to cause you serious harm we will notify you and the OAIC as required by the Notifiable Data Breaches scheme.

9. Getting access to your information, or correcting it

You can ask us for a copy of the personal information we hold about you, and ask us to correct it or delete it. Email hello@amiss.com.au. We'll respond within a reasonable time — usually 30 days — and we may need to verify who you are first. There's no charge for asking.

10. Complaints

If you think we've mishandled your personal information, email hello@amiss.com.au and tell us what happened. We'll acknowledge your complaint and aim to resolve it within 30 days.

If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.

11. Changes to this policy

We may update this policy. The current version is dated at the top of this page.

12. Contact us

AMISS PTY LTD (ABN 51 671 031 913), PO Box 740, Wahroonga NSW 2076, Australia — hello@amiss.com.au.