Privacy Policy
Your privacy matters to us. This policy explains how Café Grato collects, uses, and protects your personal information.
Last updated: July 2026. By using our website and services, you agree to the practices described in this policy.
Information We Collect
We collect information you provide directly, such as your name, email address, shipping address, and payment details when you place an order or create an account. We also collect information automatically, including your IP address, browser type, device information, and browsing behaviour on our website through cookies and similar technologies.
How We Use Your Information
We use your personal information to process and fulfil orders, manage subscriptions, communicate with you about your purchases, improve our products and services, send marketing communications (with your consent), and comply with legal obligations. We will never sell your personal information to third parties.
Information Sharing
We may share your information with trusted service providers who assist us in operating our business, including payment processors, shipping carriers (such as Australia Post), email marketing platforms, and website analytics providers. These partners are contractually obligated to protect your data and use it only for the purposes we specify.
Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. All payment transactions are encrypted using SSL technology. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Cookies
Our website uses cookies to enhance your browsing experience, remember your preferences, and analyse site traffic. You can control cookie settings through your browser preferences. Disabling cookies may affect some functionality of our website.
Your Rights
Under the Australian Privacy Act 1988, you have the right to access, correct, or delete your personal information. You may also opt out of marketing communications at any time by clicking the unsubscribe link in our emails or contacting us directly. We will respond to all requests within 30 days.
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on this page with a revised date. We encourage you to review this policy periodically.
Security & Compliance
Platform Security
HighLevel holds SOC 2 Type II attestation and ISO/IEC 27001:2022 certification, which are independently audited standards for how customer data is secured, kept confidential, and kept available.
Payment Security (PCI DSS)
Card details are never stored or processed on our website or in the CRM. Payment is handled entirely by Stripe and PayPal, which are PCI DSS Level 1 certified, the highest level. Card data goes directly from your browser to the payment provider, which is the structure PCI DSS recommends for businesses of our size.
Privacy Act 1988
Customer data is encrypted, access-controlled, and only collected where needed for orders and communications you have set up. We comply fully with Australian privacy laws and your rights to access, correct, or delete your information.
Spam Act 2003
Every automated email and SMS includes clear sender identification and a working unsubscribe. All marketing sequences run only on consent-based lists (customers and people who opted in). Transactional messages such as order and shipping confirmations are permitted under the Act.
Contact Us
If you have any questions or concerns about this privacy policy or how we handle your data, please contact us at [email protected]. We are committed to resolving any issues promptly and transparently.

