Privacy Policy
(Last updated: 12 July 2024)
1. Heinemann Oceania
Heinemann Oceania Pty Ltd (ABN 36 159 521 338) (trading as Heinemann Oceania) is committed to managing personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) (Privacy Act) and in accordance with other applicable privacy laws (see below for further information about Heinemann Oceania).
We understand the importance of being open and transparent with you in the way in which we collect, hold, store, use and share your personal information. We take protecting your privacy very seriously.
We strongly encourage you to read this document, so that you understand and are comfortable with how we handle your personal information. If you have any questions about this document, or about Heinemann Oceania’s handling of your personal information, please contact us using the relevant contact details set out in section 17
2. About Heinemann Oceania
Heinemann Oceania operates Tax & Duty Free sites, and retail stores, across Sydney and the Gold Coast, and one Hermès boutique at Sydney International Airport. We are part of the global Heinemann Group.
Heinemann Oceania’s stores include the following:
- Hermès boutique, Sydney International Airport (Luxury retail store)
- Tax & Duty Free stores, Sydney International Airport (Tax & Duty Free retail)
- Gold Coast Airport (Tax & Duty inclusive retail)
- Sydney Domestic Airport (Tax & Duty inclusive retail)
3. When does this privacy policy apply?
This Privacy Policy applies to all Heinemann Oceania websites, subsidiaries, affiliates and businesses, unless that website, subsidiary, affiliate or business has adopted a separate privacy policy.
4. About this privacy policy
This document sets out our policies for managing your personal information and is referred to as our Privacy Policy.
In this Privacy Policy, "we", "us" and “our” refers to Heinemann Oceania and "you" and “your” refers to any individual about whom we collect personal information.
This Privacy Policy sets out how we collect, store, process, use and disclose personal information (including personal information we collect, and personal information submitted to us, whether offline or online). For example, this can include:
- information we may collect to verify your entitlement to purchase duty free goods (e.g. to ensure you are making or returning from an international flight, or your date of birth to determine if you are eligible to make age-restricted purchases);
- information we may collect when you join the Heinemann & Me loyalty program (which is administered by the parent company of the Heinemann Group, Gebr. Heinemann SE & Co. KG (Heinemann HQ)); and
- information we may collect when you interact with us (including when you visit one of our stores in person, when you visit our websites (such as https://www.heinemann.com.au/en/global/), or communicate with us via our social media channels (such as via Facebook, Instagram, TikTok, WeChat, Little Redbook, Threads, Youtube or LinkedIn), phone or online).
Other terms and conditions may apply to you such as:
- the privacy terms and conditions contained in our (as applicable to you):
- the collection notices and privacy statements which may be provided to you at the time your personal information is collected.
Heinemann & Me
References to Heinemann & Me in this Privacy Policy refer to the Heinemann Group’s loyalty program which is administered by the parent company of the Heinemann Group, Gebr. Heinemann SE & Co. KG (Heinemann HQ), and Heinemann Oceania assists in operating this program, and providing you with loyalty program benefits, in-store. Joining the Heinemann & Me loyalty program is entirely voluntary.
5. What is personal information?
Personal information” is defined in the Privacy Act, and means information or an opinion about an identified individual, or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.
In this Privacy Policy, whenever we use the term “personal information”, we are referring to this legal definition.
Personal information does not include aggregated or de-identified data.
6. What information do we collect about you and how do we collect this information?
Normally we collect your personal information from you directly or from Heinemann HQ (as applicable), however on occasion, we may also collect personal information about you from other people and organisations.
In summary, we may collect your personal information when you:
- make a purchase or complete purchase orders for our products (in person or electronically);
- create an online account with us;
- join the Heinemann & Me loyalty program (or other membership or loyalty programs we may make available to you);
- communicate with us during competitions, marketing, special events and promotional activities;
- interact with us in person (such as when you visit one of our stores), via our online contact form, by post or via social media, such as when you contact us to make an enquiry or give us feedback;
- become a partner or supplier of ours; or
- apply for a position with us (including for work experience).
We may also:
- receive personal information from another member of Heinemann Group (for example, in connection with the loyalty program); and
- collect personal information from government bodies, and enforcement and regulatory authorities.
Summary of personal information we collect and how we collect this information
Type of personal information | What this includes | How do we collect this information? |
Personal information, contact and demographic details |
This may include your:
|
We may collect this information:
|
Travel information |
This may include your:
|
We may collect this information:
|
Payment information | This includes your full credit card details. |
We will collect your full credit card details when you make a
payment.Payments are processed by a secure third party provider.
We only store the last four digits of your credit card number, together with the expiry date and cardholder name. |
Information about your purchases and use of the Heinemann & Me loyalty program benefits (if applicable) |
If you sign up to be a loyalty program member, which is administered by
our parent company, then Heinemann HQ may collect information about:
|
If you are a member of our loyalty program, Heinemann HQ may collect
this information when you are logged into your Heinemann & Me online
account and you complete a purchase order for our products, or when you
provide your account information to make an in-store purchase that
credits your Heinemann & Me account.
If you do not want us to collect this information (i.e. you do not want your purchases to be attached to your Heinemann & Me account), you can always:
|
Workplace information |
This may include:
|
We may collect this information if you apply for a position at Heinemann Australia (including if you are applying for work experience with us). |
Information collected during our interactions | This includes details of your interactions with us, for example, information you provide us when you make an enquiry or complaint. |
We may collect this information:
|
Online and digital services information (including behavioural information) |
We may collect information from you electronically, which includes
information such as your IP address, and details about your device.
Please see section 12 for further information on the digital information we collect. |
We may collect this information when you use our website, via use of online behavioural technologies such as cookies. Please see section 12 and our Cookies Policy for further information on the digital information we collect. |
Camera surveillance information | We may collect camera surveillance information which includes photographs or video recordings of you. | We may collect this information in circumstances where we use camera surveillance (e.g. CCTV) at our stores for the safety of our staff and customers. |
Information required to be collected by law | We may collect information as required by law (such as under Australian customs legislation) which may include your name, your usual residential address, flight information (such as date of departure, flight number and airport of departure). |
We may collect information that is required to be collected by law from
your boarding pass and passport, in order to comply with our
requirements under the Customs Act 1901 (Cth), and associated
reporting obligations to the Australian Border Force. We may collect other information as required. |
Publicly available online information | We may collect information that is publicly available online, such as on online forums, websites, and social media channels (for example, information that relates to a complaint). | We may collect this directly from the publicly available source (e.g. on the online forum, website, or social media channel). |
In some cases you may provide us with personal information which relates to another person (for example, an emergency contact or a job referee). If you do so, you agree that you have received permission from these individuals for us to collect, use, and share, their personal information in accordance with this Privacy Policy. You should also let them know about our Privacy Policy (including the information in this Privacy Policy).
7. Can you deal with us without providing your name?
Some of the time, you will have the option of not providing your name, or using a fake name, when you deal with us (where it is lawful and practicable). This includes for example, when you make a general enquiry, or when you purchase products from our retail stores.
In some circumstances however, we may need your real name as it may not be practicable for us to deal with you anonymously or pseudonymously on an ongoing basis. For example, this includes when adding points to your loyalty program account, or when verifying that you may make a duty free or age-restricted purchase (as further detailed below). This means that if we do not collect your personal information, we may not be able to provide you with the products you have asked for.
Given that we have legal obligations to identify you, in order to demonstrate to the Australian Border Force that duty free sales have only been made to a person making or returning from an international flight, as required under the Customs Act 1901 (Cth), you cannot purchase duty-free goods from us without providing your nationality and flight information. Where you apply for a job with us, we also require your personal information in order to undertake background checks.
This means that if you do not provide us with your personal information, we will not be able to provide you with the duty free products you wish to purchase, or accept your job application.
8. Why do we collect, store and use your personal information?
We collect personal information that is necessary to provide you with our products, and to carry out our business.
We may use your personal information for purposes which are incidental to the sale and promotion of our products, or for other purposes which are within your reasonable expectation or permitted by law.
The purpose for which we usually collect, store, and use your personal information depends on how you interact with us (for example, whether you are part of our loyalty program), but may include the following purposes:
Purpose | Explanation |
To provide you with our products when you are a customer |
We may collect, store and use your personal information to:
|
To promote our products to you | Where you have opted in to receive promotional offers, we may collect, store and use your personal information to promote products to you that we think you may be interested in. |
To manage the Heinemann & Me loyalty program |
Heinemann HQ administers the loyalty program, and we assist them with
this. In doing so, Heinemann AU and Heinemann HQ may collect, store and use your personal information to:
|
To manage your working relationship with us (including when you are a contractor) |
We may collect, store and use your personal information to assess your
suitability for a position with us, and, if you successfully join us, to
manage your working relationship with us. We may collect, store and use your personal information for administration and management purposes (including if you are a contractor). |
To do business with you | We may collect, store and use your personal information if you interact with us on a commercial basis (such as if you are a service provider, contractor, supplier or partner), or if you otherwise interact with us on a commercial basis. |
To manage and improve our operations and business |
We may collect, store and use your personal information to:
|
To create de-identified or aggregate data for data analytics activities |
We may collect, store and use your personal information to create
de-identified or aggregate data sets (which is no longer personal
information). We do this by de-identifying or aggregating your
information such as combining your information with information we have
about our other customers, for example purchasing information, and with
data we obtain from other sources. We use this de-identified or
aggregate data to assist with our business decisions, such as to:
We also collect the nationality code of our customers and provide this in anonymised and aggregated format to Sydney Airport Corporation Limited for statistical purposes. |
To assist with any business, share sale or corporate restructure | We may collect, store and use your personal information for the purpose of facilitating or implementing a transfer or sale of all or part of our assets or business or if we undergo any other kind of corporate restructure, acquisition or sale. |
Other purposes | We may collect, store and use your personal information for any other purpose that you have provided your express or implied consent to. |
9. Who do we share your personal information with and why?
We may also share your information with other third parties:
- for the reasons for which we collect, store and use that information (see above in section 8
- for other purposes explained at the time we collect your personal information; or
- where we are otherwise allowed or required to do so under law.
We will never sell your personal information.
Some of the third parties we may share your information with include the following:
Recipient | Explanation |
Other members of Heinemann Group |
We may share your personal information with other members of our company
group (as appropriate). For example, we share personal information with members of Heinemann Group located in Germany and Singapore, including to receive backend services and loyalty program services administered by our parent company. |
Sydney Airport Corporation Limited and Gold Coast Airport Pty Ltd | We share the nationality code of our customers in anonymised and aggregated format to Sydney Airport Corporation Limited and Gold Coast Airport Pty Ltd |
Australian Border Force | We share the nationality and flight number of our customers with the Australian Border Force, to demonstrate that duty free sales have only been made to a person making or returning from an international flight, as required under the Customs Act 1901 (Cth). |
Our partners and other entities we do business with | We may share your personal information with our partners and other entities we do business with to assist in providing our products, and to ensure that any orders you place via our website are fulfilled. The kinds of third parties to whom we may disclose personal information to include manufacturers, suppliers and distributors. |
Our service providers and advisors |
We may share your personal information with a variety of our service
providers to assist us with providing, promoting, and managing our
products. These may include our:
|
Corporate restructure | We may share your personal information with third parties, whether affiliated or unaffiliated, for the purpose of facilitating or implementing a transfer or sale of all or part of our assets or business or if we undergo any other kind of corporate restructure, acquisition or sale. In this context, your personal information may be transferred to another entity (or if such a sale, transfer, acquisition or corporate restructure is being contemplated by us). |
Government and law enforcement agencies | We may share your personal information with regulatory bodies, government agencies and law enforcement bodies to comply with our legislative or regulatory obligations (such as to assist with police investigations). |
10. Do we share your personal information overseas?
We generally collect your personal information in Australia. However, it is likely that we will share your personal information with other members of the Heinemann Group who are located in Germany and Singapore.
We may share your personal information with service providers who assist us with storing our data on secure data storage servers, or with improving our products and services (by analysing sales information and trends, and conducting customer satisfaction enquiries).
We only ever share your personal information outside of Australia where we are permitted to do so under the Privacy Act. Generally this means we will take reasonable steps to ensure your personal information is treated securely and in accordance with applicable privacy laws.
There are other circumstances where we may disclose your personal information to an overseas recipient. For example, where you have provided your consent or we are otherwise permitted to do so under other relevant laws.
11. Do we use or share your personal information for direct marketing?
When you provide your personal information to us, we may use that personal information to send you direct marketing communications to keep you informed about products that we offer which we think might be of interest to you based on your interactions with us.
For example, if you have opted in to receive marketing communications upon sign up of your user account and/or Heinemann & Me member account, we may send you direct marketing communications and information about our products and the Heinemann & Me loyalty program (including special offers and promotions from both us and our partners) that we consider may be of interest to you, or as otherwise allowed under applicable privacy laws.
We may communicate with you (and send these electronic messages and tailored advertising) through various channels, such as via regular mail, Direct Mail Out, email, SMS, telephone, push notifications or social media (including through targeted advertisements on certain websites and social media channels).
We will only send these communications in accordance with applicable privacy and marketing laws (such as the Privacy Act (including Australian Privacy Principle 7) and the Spam Act 2003 (Cth)), and only where you have not opted out from receiving such communications from us.
If you have indicated a preference for a method of communication, we will endeavour to use that method wherever practical to do so.
How can you opt out?
You are always in control of the direct marketing communications which you receive and can opt-out at any time. Generally you can opt-out by following the relevant opt-out or unsubscribe instructions in the relevant communication (such as email or SMS message).
You can also contact us using the detail set out in section 17 to tell us you would like to stop receiving direct marketing communications from us.
For cookies which use your personal information for website function and direct marketing (such as targeted advertising) you can only opt-out by switching off Functional Cookies and Marketing Cookies in the “Cookie Settings” page which can be found at the bottom of each of our pages device setting and online privacy settings (for advertising on certain websites and social media channels).
Important points regarding opting out
Receiving other communications
Importantly regardless of whether you opt out from receiving any or all direct marketing communications, we will still communicate with you if we are required by law to provide you with information, or in relation to the products we are providing you with (for example, in relation to collection information for products purchased online, sending you an invoice in relation to a transaction).
Heinemann & Me loyalty program
If you are a member of the Heinemann & Me loyalty program and you are not opted-in to receive marketing communications (for example, you choose to opt-out of receiving such marketing communications):
- we will not send you marketing communications (including communications regarding any coupons or birthday vouchers); and
-
your membership will continue and you can:
- redeem your Heinemann & Me coupons and birthday vouchers in your account profile through the Heinemann & Me App and/or our website; and
- check your Heinemann & Me loyalty points in your account profile through the Heinemann & Me App and/or our website.
12. How do we interact with you via the internet?
Third party links and sites
When you use our website or receive communications from us, links to websites which belong to other third parties may be included (and are provided for your convenience). You should make your own enquiries as to the privacy policies of these parties. We are not responsible for information on, or the privacy practices of, any third party websites.
In addition, when you make online payments using our website, we encrypt your credit card details and transfer these securely to our third party payment service provider.
Website use and cookies
You may visit our websites without identifying yourself. If you identify yourself (for example, by creating an online account or making an enquiry), any personal information you provide to us will be managed in accordance with this Privacy Policy.
Our website also uses secured cookies (and we share personal information we collect between members of Heinemann Group). A 'cookie' is a small file stored on your computer's browser, which assists in managing customised settings of the website and delivering content. A secured cookie is a cookie with a secured flag which can only be transmitted over an encrypted connection. This makes the cookie less likely to be exposed to cookie theft.
The cookies used by our website are created per session and expire at the end of the session. They do not include any information about you other than your session key (usually removed as your session ends but sometimes can be kept in your device for no more than 6 months) and the ability to log in again quickly. Credit card information is never stored in a cookie.
At a high level, cookies can be used for a variety of reasons, such as to personalise your browsing experience (for example, by remembering your preferences and recognising you as a repeat visitor to our websites), and to track statistics about the usage of our website. This allows us to better understand our users, enable automatic activation of certain features, make your experience more convenient and effortless, improve the layout and functionality of our websites, and understand if anything needs fixing.
If you do not wish to receive any cookies (other than those that are strictly necessary which we refer to as essential cookies) you can use the settings in the “Cookie Settings” page which can be found at the bottom of each of our pages to control the types of cookies you receive. However, in doing so, you may be unable to access certain pages or content on our websites.
Please see our separate Cookie Policy for further information about what cookies we use and information we collect online and through digital services.
13. How do we store and protect your personal information?
We are committed to protecting your personal information, and ensuring that we securely store any personal information we collect (in accordance with applicable privacy laws). We may hold your personal information in hard copy (paper) or electronic form.
We take all reasonable steps to ensure that any personal information we collect, use or disclose is accurate, complete, up-to-date and stored in a secure environment protected from misuse, interference and loss, and from unauthorised access, modification or disclosure.
Security and storage of personal information
Form | Explanation |
Paper-based files |
We store personal information in paper-based files in secure storage
(generally at our head office, or at the relevant store). Personal
information may be collected in paper-based documents and converted to
electronic form for use or storage (with the original paper-based
documents either archived or securely destroyed).
We maintain physical security measures to ensure that personal information in paper-based files is protected, such as physical locks and security systems at our premises. |
Electronic records |
We store electronic records in secure databases in controlled
facilities, using trusted third party storage providers based in
Germany. We also maintain physical security measures in relation to
storage of our electronic records (such as through locks and security
systems at our electronic data stores).
Using technical methods, we also maintain computer and network security. For example, we use firewalls (security measures for the internet) and other security systems such as user identifiers and passwords to control access to our computer systems. |
Our websites (including for making payments) |
Our websites use firewalls, encryption and other technologies to ensure
that your personal information is securely transmitted via the internet
(including to protect any payments you make).
User identifiers, passwords and other access codes may also be used to control access to your personal information on our websites. Your order details are only stored and transmitted in encrypted form on our internet servers. This means that communication between your browser and our order system cannot be read by others on the internet. We encourage you to exercise care when sending your personal information via the internet (for example, when communicating with us online, we ask that you do not include your full account or card details). |
How long do we keep your personal information?
We will only keep your personal information for as long as is necessary for the purposes set out in this Privacy Policy or as required to comply with any applicable legal obligations.
When we no longer require your personal information (and in accordance with any applicable laws), we will take steps to destroy or de-identify that information.
14. How can you access or seek correction of your personal information?
You are entitled to request access to any of your personal information that we have (except in limited circumstances in which it is permitted by law for us to withhold the information). To make such a request, please contact us using the relevant contact details set out below in section 17
We will take reasonable steps to ensure that the personal information we collect, use or disclose is accurate, complete and up-to-date. You can help us to do this by letting us know if you notice errors or discrepancies in information we hold about you and informing us of any change in your personal details (for example, if your email address changes).
If you consider any personal information we have about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, you are also entitled to request correction of the information (again, please contact us). After receiving a request from you, we will take reasonable steps to correct your information.
We may decline your request to access or correct your information in certain circumstances in accordance with the applicable privacy laws. If we do refuse your request, we will provide you with a reason for our decision. In addition, in the case we refuse your request for correction, we will include a statement about your request with the personal information we store.
15. How can you make a complaint about the handling of your personal information?
If you have any questions or concerns about this Privacy Policy or how we have handled your personal information, you may contact us at any time using the relevant contact details set out below in section 17
Please also contact us if you have a complaint about privacy. If you make a complaint about privacy, the following will occur:
- We will first consider your complaint to determine whether there are simple or immediate steps which can be taken to resolve the complaint. We will generally acknowledge your complaint within a week.
-
If your complaint requires more detailed consideration or investigation:
- we will acknowledge receipt of your complaint within a week and endeavour to complete our investigation into your complaint promptly; and
- we may ask you to provide further information about your complaint and the outcome you are seeking.
- We will then typically gather relevant facts, locate and review relevant documents and speak with the individuals involved.
- In most cases, we will respond to your complaint within 30 days from when we receive your complaint. If the matter is more complex or our investigation may take longer, we will let you know.
If you are not satisfied with our response to a complaint, or you consider that we may have breached the Privacy Act (including the Australian Privacy Principles), you are entitled to make a complaint to the Office of the Australian Information Commissioner (the Australian privacy regulator).
The Office of the Australian Information Commissioner can be contacted by telephone on 1300 363 992, or you can fill out this form to make a complaint about our handling of your personal information. Full contact details for the Office of the Australian Information Commissioner can be found online at www.oaic.gov.au.
16. How are changes made to this privacy policy?
We may make changes to this Privacy Policy, with or without notice to you. However, where we make a material change to the Privacy Policy, we will provide notice to you (including by updating our websites, and, where appropriate, notifying you directly). We recommend you visit this Privacy Policy regularly to keep you up to date with any changes we make.
17. How can you contact us?
You can contact us using the details below:
Opening Hours:
- Customer Service Team operates between 9:00 am – 5:00 pm, Australian Eastern Standard Time (AEST), Monday – Friday (excluding Public Holidays)
E-mail:
Telephone:
- 1800 46 46 66 (Australia toll-free)
- +61 9667 6800 (International)
Postal Address:
Heinemann Oceania
PO Box 3027
Sydney International Airport
Mascot 2020 NSW