Privacy Policy
Big Bear Marketing ("we", "us", "our") respects your privacy and is committed to protecting your personal information in accordance with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth).
This policy explains what information we collect, how we use it, and your rights.
1. Who we are
Big Bear Marketing is a sole trader operated by Brandon Connor, based in Sydney, NSW, Australia. We provide website design, development, and CRM services to small businesses.
2. Information we collect
We only collect information that is reasonably necessary for our services. This includes:
- Contact information you provide via our enquiry form: name, business name, email, phone, project type, budget, and the project details you write.
- Communications: emails you send us and notes from calls or meetings, kept so we can deliver and support your project.
- Technical information from your visit to this site: anonymised analytics (page views, referrers, device type) where enabled. We do not use third-party advertising trackers.
- Project data: any content, brand assets, or business data you provide for the work.
We do not collect sensitive information (health, racial, political, religious, etc.) and do not knowingly collect information from anyone under 16.
3. How we use it
- To respond to your enquiry and quote your project.
- To deliver, maintain, and support the work you've engaged us for.
- To send you occasional updates about your project (we do not run a marketing newsletter).
- To meet our legal and tax obligations.
4. How we store and protect it
Your information is stored on our local systems and on reputable cloud providers (such as Cloudflare, Microsoft 365, and accounting software). We use industry-standard security: encrypted connections (HTTPS), strong passwords, two-factor authentication where available, and access limited to people who need it to deliver your work.
We keep your information only as long as we need it to provide our services and meet legal record-keeping obligations (typically 7 years for tax records under Australian law), then it is deleted or de-identified.
5. Sharing your information
We do not sell your information. We may share it with:
- Service providers who help us deliver the work (e.g. hosting, email, payment processing). They are bound by confidentiality.
- Government or regulators if required by law.
Some service providers are based overseas (e.g. Cloudflare, Microsoft 365). By using our services, you consent to your information being handled in jurisdictions outside Australia where we have selected providers with appropriate privacy safeguards.
6. Cookies
This site uses minimal essential cookies. If we add analytics or session storage in the future, we will update this policy and provide a notice.
6a. Contact form submissions and IP addresses
When you fill in our contact form, we capture the standard fields you complete plus your IP address and browser user-agent. We use this information for fraud detection, rate limiting, and to respond to you. IP addresses are stored alongside the submission for up to 90 days, then purged or de-identified. You can ask for your submission to be deleted earlier by emailing us at the address below.
6b. Data submitted via enquiry forms and the Big Bear CRM
When you submit an enquiry through this marketing site, that data may be processed and stored in the Big Bear CRM, which is a separate hosted system. The Big Bear CRM has its own Privacy Policy that governs how data is handled within that system. By submitting an enquiry, you consent to your information being handled in accordance with both this policy and the CRM Privacy Policy.
7. Your rights
Under Australian law you have the right to:
- Ask what personal information we hold about you.
- Ask us to correct any information that is inaccurate, out of date, or incomplete.
- Ask us to delete your information (subject to legal retention requirements).
- Make a complaint about how we handle your information.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner: oaic.gov.au.
8. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent change. Material changes will be communicated via the website.
9. Contact
Questions about this policy? Email [email protected].
Note: This policy is provided as a starting template based on common Australian small-business practice. Have a solicitor review it before going live, especially if you process payments, run analytics, or handle data outside this scope.