privacy policy
LAST UPDATED 1 JULY 2026
Wholesale Management Platform for Designers
This Privacy Policy explains how Engaged Sales Agency Corporation Pty Ltd [ABN 68 684 581 324] trading as "Engaged Suite Software" ("Engaged Suite Software," "we," "us," or "our") collects, uses, discloses, and protects information across our wholesale portal software, a platform connecting bridal designers with retail boutiques for order management, trunk shows, and wholesale communication. This Policy applies to Designers, Retailers, and any other user of the Engaged Suite Software platform (the "Service").
1. Who We Are & Scope
Engaged Suite Software is operated by Engaged Sales Agency Corporation Pty Ltd [ABN 68 684 581 324], an Australian company. As an Australian-based business, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Because our customers may include Designers and Retailers based outside Australia, this Policy also addresses obligations that may arise under the UK/EU GDPR, the California Consumer Privacy Act (CCPA), and comparable frameworks, where and when those apply to users we serve in those regions.
This Policy does not apply to Engaged Creative or any other business operated by our founders. Engaged Suite Software maintains its own separate legal identity, branding, and data practices.
2. Information We Collect
A. PROVIDED DIRECTLY BY DESIGNERS
Account and profile data: name, email, password (hashed and salted using bcrypt; we never store it in a readable form), brand/business name, business address
Catalogue, pricing, and wholesale terms data uploaded to the portal
Retailer relationship data: invitations sent, trading terms, order history, trunk show schedules
Payout and financial account details, collected and verified via Stripe Connect (see §5)
B. PROVIDED DIRECTLY BY RETAILERS
Designers may invite their Retailers to access the relevant Designer's portal. Where a Retailer accepts and uses the Service, we collect:
Account and profile data: name, email, boutique name, shipping and business address
Order and purchasing data: orders placed, trunk show bookings, communications with Designers
Payment method details, collected and processed by Stripe Connect. Engaged Suite Software does not store card or bank details
E-signature and contracting data: trading agreements and authorisation forms signed in-platform, including IP address and timestamp at signing
C. COLLECTED AUTOMATICALLY
Usage data: pages visited, features used, login history, session duration
Device and browser data: IP address, device type, browser version
Platform activity logs used for security, audit, and troubleshooting purposes
D. FROM THIRD-PARTY INTEGRATIONS
Stripe Connect: identity verification (KYC), payout account status, transaction records
Email delivery and calendar tools used to send platform notifications and sync trunk show dates
Accounting sync (optional): where a Designer connects Xero, we exchange the data necessary to sync invoices and related records. Xero OAuth tokens are encrypted at rest
Cloud hosting and infrastructure providers, as described in §5
3. How We Use Your Information
To operate core Service functionality: designer portals, retailer invitations, order management, trunk show scheduling, and billing
To facilitate payments and payouts via Stripe Connect
To send transactional communications: order confirmations, invoices, trunk show reminders, contract signing requests
To maintain platform security, detect fraud, and validate e-signatures
To provide customer support and respond to enquiries
To analyse aggregated, de-identified usage patterns for product improvement
To meet legal, tax, and regulatory obligations
We do not use Designer or Retailer data to train third-party AI models, and we do not sell personal information to any third party.
4. Designer & Retailer Data Roles
On the Engaged Suite wholesale platform, data responsibilities are shared between the platform and its users:
Designers act as the data controller for the Retailer data within their own portal. They decide which Retailers to invite, what trading terms apply, and how Retailer relationship data is used within their business.
Engaged Suite Software acts as the data processor for that Designer-controlled Retailer data, processing it only to operate the Service and in line with the Designer's instructions and our agreement with the Designer. Engaged Suite Software is the data controller for platform-level data: account credentials, billing records, and platform usage data.
Designers are responsible for having a lawful basis to collect and process their Retailers' data, and for their own privacy obligations toward Retailers. Where required by law (for example, for Designers based in the EU or UK), a separate data processing agreement will govern the processor relationship described above.
5. Third Party Service Providers
We rely on the following categories of service providers to operate Engaged Suite Software. Each has its own privacy policy governing how it handles data on our behalf.
Payments — Stripe Connect: handles identity verification, payment processing, and Designer payouts. Stripe acts as the licensed financial intermediary for all wholesale transactions. Engaged Suite does not hold funds and does not take a transaction fee on wholesale orders.
Hosting & infrastructure — Render: cloud hosting and storage for application data.
Email & notifications — Resend: transactional email delivery for order confirmations, reminders, and account notices.
Accounting — Xero (optional): where a Designer connects Xero, used to sync invoices and related records.
We do not share Designer or Retailer personal information with third parties for their own marketing purposes. Data shared with each provider is limited to what is necessary for that provider's function (for example, Stripe receives payment and identity data; our hosting provider stores application data).
6. International Data Transfer
Engaged Suite Software is based in Australia. Application data is hosted with Render and stored in [data storage region: confirm with Render]. Where Designers or Retailers are located outside Australia, their information may be transferred to and processed in Australia, or in another jurisdiction where our infrastructure providers operate.
EU / UK users. We do not currently serve Designers or Retailers based in the EU or UK. If and when we do, we will put in place an appropriate cross-border transfer mechanism (such as Standard Contractual Clauses) and supplementary safeguards, including encryption in transit, access controls, and contractual commitments from our providers, and we will update this section accordingly.
US users. Where we serve US-based Retailers or Designers, their personal information is handled consistently with this Policy and, where applicable, the CCPA (see §10).
Users in other regions. We apply the same security and access-control standards described in §8 regardless of a user's location, and will update this section as region-specific obligations are confirmed.
7. Data Retention
Account & platform data: retained while an account is active; deleted or anonymised within 30 days of account closure, except where noted below. A Designer may request an export of their data before deletion (see the Terms of Service).
Order, billing, and contracting records: retained as required for tax, accounting, and legal record-keeping obligations.
Usage and log data: retained for a limited period for security and troubleshooting purposes.
8. Security
Encryption: data is encrypted in transit (TLS). Sensitive integration credentials, including Stripe keys and Xero OAuth tokens, are encrypted at rest using AES-256. Passwords are stored hashed and salted (bcrypt), never in a reversible form.
Tenant isolation: each Designer operates in a separate, isolated tenant. The platform enforces this separation on every request, so no user can access data outside their own portal relationships.
Access controls: role-based access separates Designer, Retailer, and platform-admin permissions.
Payment data: handled entirely by Stripe Connect. Engaged Suite Software never stores full card or bank account numbers.
No system is completely secure, and we cannot guarantee absolute security, but we maintain the controls above and review them as the platform grows.
9. Breach Notification
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches (NDB) scheme under the Privacy Act. For any EU or UK users we come to serve, we will notify the relevant supervisory authority within 72 hours where required under GDPR. Notification will include the nature of the breach, the data affected, and the steps we are taking in response.
10. Your Privacy Rights
To exercise any of these rights, contact us using the details in §14. We aim to respond within 30 days.
RIGHT / WHAT IT MEANS
Access - Request a copy of the personal data we hold about you
Correction - Request correction of inaccurate or incomplete data
Deletion - Request deletion of your account and personal data, subject to legal retention obligations
Portability - Request your data in a machine-readable format
Objection - Object to processing based on legitimate interests (EU/UK users)
Opt-Out of Sale - Not applicable — we do not sell personal information (CCPA, US users)
To exercise any of these rights, contact us using the details in §14. We aim to respond within 30 days.
11. Cookies & Tracking
We use a small number of essential cookies for login sessions and authentication. We do not use third-party advertising cookies. Where analytics are enabled, they are anonymised and used only in aggregate to understand platform usage.
12. Children’s Privacy
Engaged Suite is a B2B platform intended for use by business owners and their staff. It is not directed to individuals under 18, and we do not knowingly collect personal information from children.
13. Changes To This Policy
We may update this Policy from time to time. Material changes will be communicated in-app and via email, and the "Last updated" date at the top of this page will be updated accordingly. The current version always lives at engagedsuite.software/privacy-policy.
14. Contact & Complaints
Email: wholesale@engagedsalesagency.com
If you're not satisfied with our response, you can lodge a complaint with:
Australia: Office of the Australian Information Commissioner — oaic.gov.au
UK: Information Commissioner's Office — ico.org.uk
EU/EEA: your local data protection supervisory authority