Privacy Policy
Last updated: September 2026 · Compliant with Privacy Act 1988 (Cth) and Australian Privacy Principles
Entity: Occupation Force Callsign GSW Pty Ltd (t/a 22nd Survey Division)
ABN: 50 692 429 397 · ACN: 692 429 397
Contact: [email protected]
1. Information We Collect
We collect personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). The types of information we collect include:
Information You Provide
- Contact information (name, email address) when you contact us
- Payment information when you make a purchase (processed securely by Stripe)
- Communication records when you correspond with us
Information Collected Automatically
- Device and browser information
- IP address and approximate location
- Pages visited and interaction data
- Referral source
2. Payment Processing
We use Stripe as our payment processor. When you make a payment:
- Your payment card details are collected and processed directly by Stripe
- We do not store your full card number on our servers
- Stripe is PCI-DSS Level 1 certified (the highest level of certification)
- Stripe's privacy policy applies to payment data: stripe.com/privacy
We receive only transaction confirmations, last 4 digits of your card, and billing address for record-keeping and fraud prevention.
3. How We Use Your Information
We use collected information to:
- Process transactions and send related information
- Respond to your inquiries and provide customer support
- Send administrative information (service updates, security alerts)
- Improve our website and services
- Comply with legal obligations
- Detect and prevent fraud or abuse
4. Disclosure of Information
We may share your information with:
- Service providers: Stripe (payments), GitHub (hosting), Cloudflare (security)
- Legal compliance: When required by Australian law, court order, or government request
- Business transfers: In connection with any merger or acquisition
We do not sell your personal information to third parties.
5. Security Research & Honeypot Data
Our infrastructure includes honeypot systems that collect data from automated scanners and potential attackers. This data:
- Is used solely for threat intelligence and security research
- Does not contain personal information from legitimate visitors
- May be shared with security researchers and law enforcement
- Is retained for research purposes and may be published in anonymized form
6. Cookies and Tracking
We use minimal cookies:
- Essential cookies: Required for site functionality
- Preference cookies: Remember your theme preference
We do not use third-party advertising or tracking cookies.
7. Data Retention
- Transaction records: 7 years (Australian tax law requirement)
- Contact inquiries: 2 years or until request for deletion
- Honeypot/security data: Indefinitely for research purposes
- Analytics data: 26 months
8. Your Rights
Under the Privacy Act 1988 and APPs, you have the right to:
- Access your personal information we hold
- Request correction of inaccurate information
- Request deletion of your information (subject to legal retention requirements)
- Complain to the Office of the Australian Information Commissioner (OAIC)
9. International Data Transfers
Some of our service providers operate outside Australia (primarily USA). We ensure appropriate safeguards are in place and that overseas recipients comply with the APPs or equivalent protections.
10. Changes to This Policy
We may update this policy periodically. Significant changes will be notified via our website. Continued use of our services after changes constitutes acceptance.
11. Contact Us
For privacy inquiries, access requests, or complaints:
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner.