PRIVACY POLICY

CARS & STARS Online

PRIVACY POLICY

Last Updated 19 September 2025

In this Privacy Policy, "us", "we", "our" or "HBD" means Hawker Brownlow Digital Pty Ltd (ABN 15 629 535 548) and its divisions and related bodies corporate.

We recognise the importance of privacy and are committed to protecting your privacy when handling your personal information.

This Privacy Policy explains how we handle personal information in an open and transparent manner in accordance with the Australian Privacy Principles contained in the Privacy Act 1988 (Cth) ("Privacy Act") and other applicable privacy laws. Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable.

This Privacy Policy will be reviewed from time to time to take account of new or amended laws, new technology and/or changes to our operations and practices and the changing business environment. All personal information held by us will be governed by the most recently updated policy. This Privacy Policy addresses the following:

  • what information we collect;
  • how we collect information;
  • why we collect it;
  • how we use it;
  • how we disclose it;
  • opting in or out;
  • how we hold it – management and security;
  • accessing and updating or correcting your information and how to contact us.

What information we collect


The personal information we may collect about you includes (but is not limited to) your name, contact details (including phone numbers and addresses), gender, year of birth, transaction information and other information which may assist us in conducting our business and providing our products and services.

In certain circumstances we collect financial information (for example, invoice and billing details). Where card payments are made for CARS & STARS Online purchases—whether via Xero’s online payment facility or through our website checkout (hb-digital.com.au)—payments are processed by eWAY. Card details are entered directly into eWAY’s secure pages and are not collected or stored by CARS & STARS Online; we receive only limited transaction metadata (e.g. amount, date and invoice reference) for reconciliation.

This information, including gender and year of birth, may be stored in our secure Microsoft Azure hosting environment to operate and deliver the CARS & STARS Online program.

For our current sub-processors, see our Sub-Processors page.

We generally use this information to report statistics, analyse trends, administer our services, diagnose problems, and improve the quality of our products and websites.

Cookies and similar technologies

We use cookies and similar technologies to operate and improve CARS & STARS Online. We use analytics tools (e.g. Google Analytics, Microsoft Clarity and Statcounter) to help us understand how the service is used and to improve performance. We do not use advertising or remarketing cookies on the CARS & STARS Online application.

You can control cookies through your browser settings. You can also opt out of Google Analytics using Google’s Analytics Opt-out Browser Add-on.

We generally advise that you do not publish or communicate personal information, or at least limit the personal information that you publish or communicate, to the public via our services, such as in any forums, blogs or anywhere that user generated content can be uploaded ("Non-Confidential Information"). We cannot control any third party collection or use of your Non-Confidential Information that is publicly available.

How we collect information


We may collect your personal information from a variety of sources, including from you, advertisers, mailing lists, recruitment agencies, contractors and business partners.

We will generally collect personal information by way of forms filled out by people, face-to-face meetings, interviews, business cards, electronic communications, telephone conversations and from third parties (including representatives and agents). In addition, we collect personal information from our websites and social media web pages (e.g. Facebook and Instagram) through receiving subscription applications, job applications, competition applications, promotion entries (including posts, comments/likes, messages and votes) and other electronic documents and information.

We may collect your personal information when you request or acquire a product or service from us, register with us as a subscriber or member, provide a product or service to us, complete a survey or questionnaire, enter a competition or event, contribute in a fundraising event, participate in our services (including blogs and forums) or when you communicate with us electronically (including email and facsimile), by telephone or in writing (for example if you make a complaint or provide feedback).

If, at any time, you provide personal or other information about someone other than yourself, you must have that person's consent to provide such information for the purpose for which you provide it to us.

Why we collect it


The primary purpose for which we collect information about you is to conduct our business, provide and market our products and services or products and services of other members of the HBD to you, meet our legal or regulatory obligations, and also for the management of business transactions entered into with us and the administration of any accounts you have with us. We may state a more specific purpose at the point we collect your information (including but not limited to any law that requires or authorises the particular information to be collected).

If you do not provide us with all or some of the information that we request, we may not be able to provide you with our products or services or market our products and services or products and services of other members of the HBD to you. For example, if you do not register as a member of a website, you will not be able to access features or services that are reserved for members or subscribers only.

How we use it


In addition to the primary purpose outlined above, we may use the personal information we collect, and you consent to us using your personal information:

  • to provide you with news and information about our products and services or products and services of other members of the HBD, and opportunities that we believe you may be interested in;
  • for purposes necessary or incidental to the provision of products or services to you including processing order details, tracking numbers and other transaction information;
  • to personalise and customise your experience purchasing or using our products or services;
  • to manage and enhance our products and services;
  • to communicate with you, including by email, mail or telephone;
  • to conduct competitions or promotions;
  • to verify your identity;
  • to investigate any complaints about or made by you, or if we have reason to suspect that you are in breach of any of our terms and conditions or that you are or have been otherwise engaged in any unlawful activity;
  • as part of any investigation in relation to you or your activity which we suspect to be a breach of any of our terms and conditions, serious misconduct or unlawful;
  • as part of a sale (or proposed sale) of all or part of our business; and/or
  • as required or permitted by any law or regulation (including without limitation the Privacy Act).

How we disclose it


We may disclose personal information from your order, and you consent to us disclosing your personal information, to third parties:

  • engaged by us to perform functions or provide products or services on our behalf, such technical or product support, mailouts, marketing, analytics, session tracking, content delivery, research, advertising or customer engagement. Such third parties include web hosting providers such as Microsoft Azure in Australia East and Australia Southeast, analytics and session tracking providers such as Google Analytics, Microsoft Clarity and Statcounter, content delivery networks such as Azure CDN, email and marketing platforms such as Mailchimp and Rackspace, customer support platforms such as Zendesk, and customer relationship management platforms such as Close. For a full and current list of sub-processors, please visit our Sub-Processors page.
  • that are our agents, business partners or joint venture entities or partners;
  • that sponsor or promote any competition or activity that we conduct or promote via our services;
  • authorised by you to receive information held by us;
  • as part of any investigation in relation to you or your activity which we suspect to be a breach of any of our terms and conditions, serious misconduct or unlawful (including disclosure to the police, any relevant authority or enforcement body, or your Internet Service Provider or network administrator);
  • that are our external advisers or potential or actual bidders or their external advisers as part of a sale (or proposed sale) of all or part of our business; and/or
  • as required or permitted by any law or regulation (including the Privacy Act).

Email delivery and communications: We use Mailgun (Sinch Email) to deliver service and account communications (for example, account activation, password resets, system updates and billing notices). When teachers choose to email student reports to parents or guardians from CARS & STARS Online, Mailgun processes the email and its contents/attachments (which may include the student’s name, class and assessment results), along with recipient addresses and delivery diagnostics (for example, bounces or complaints).

Some of these third parties to which we may disclose your personal information may be located in Australia, the United States or other countries.

Opting in or out


At the point we collect information from you, you may be asked to "opt in" to consent to us using or disclosing your personal information for purposes other than those that are expressly stated in this Privacy Policy. For example, you may be asked to opt-in to receive further information or communications from our advertisers or supporters.

You will be given the opportunity to "opt out" from receiving communications from us or from third parties that send communications to you in accordance with the Privacy Act and other applicable privacy laws. For example, you will be given the option to unsubscribe to emails or newsletters sent by us.

You may also opt out of Google Analytics using Google’s Analytics Opt-out Browser Add-on.

How we hold it – management and security


We have appointed a Privacy Officer to oversee the management of personal information in accordance with this Privacy Policy, the Privacy Act and other applicable privacy laws.

Other than in relation to Non-Confidential Information, we will take all reasonable steps to protect the personal information that we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure, including secure premises, locked cabinets, firewalls, password access, secure servers and TLS encryption in transit.

CARS & STARS Online purchases may be completed via Xero’s online invoice payment or through our website checkout (hb-digital.com.au); in both cases, card payments are processed by eWAY. Card details are entered directly into eWAY’s secure pages, and CARS & STARS Online does not receive, collect or store full card details; we receive only limited transaction metadata for reconciliation.

However, you acknowledge that the security of online transactions and the security of communications sent by electronic means or by post cannot be guaranteed. You provide information to us via the internet or by post at your own risk. We cannot accept responsibility for misuse, interference or loss, or unauthorised access, modification or disclosure in respect of your personal information where the security of the information is not within our control.

If you suspect any misuse, interference or loss, or unauthorised access, modification or disclosure in respect of your personal information, or any other privacy breach please let us know immediately.

Accessing and updating or correcting your information and how to contact us

Subject to the exceptions set out in the Privacy Act and other applicable privacy laws, you may request to access, update or correct the personal information we hold about you. We will require you to verify your identity and to specify the information that you wish to access, update or correct.

Subscribers or members of our websites will generally be able to access, update and correct their membership and contact details online. We request that you keep your information as current as possible so that we may continue to improve our service to you.

If you wish to access, update or correct any personal information that we hold about you, or if you have any questions or require a complaint dealt with about how we collect, use, disclose, store or otherwise handle your personal information, you can contact the department that collected your personal information in the first instance, or write to:

The Privacy Officer
Hawker Brownlow Digital Pty Ltd
U24 337 Bay Road
Cheltenham VIC 3192
Email: data.governance@hb-digital.com.au