Legal

Privacy Policy

Last updated: March 2026

Sarah Pirie-Nally / Wonder & Wander Pty Ltd ("we", "us", "our") is committed to protecting your privacy. This policy explains what personal information we collect, how we use it, and your rights under the Australian Privacy Act 1988 and, where applicable, the General Data Protection Regulation (GDPR).

1. Who We Are

This website is operated by Sarah Pirie-Nally trading as Wonder & Wander Pty Ltd, an Australian business. Our primary contact for privacy matters is [email protected].

2. What Information We Collect

We collect the following categories of personal information:

Account informationName, email address, login method (when you create an account via Manus OAuth)Account creation and login
Purchase informationName, email address, purchase amount, product name, Stripe customer IDProcessing payments via Stripe
Usage analyticsPage views, session duration, referring URL (anonymised)Understanding how the site is used
Session dataA signed session token stored in an httpOnly browser cookieKeeping you logged in

We do not collect or store credit card numbers, CVV codes, or full payment card details. All payment processing is handled directly by Stripe, which is PCI-DSS compliant.

3. How We Use Your Information

We use your personal information to:

  • Provide access to purchased programs and course materials
  • Send order confirmations and purchase receipts
  • Respond to enquiries submitted via the contact page
  • Improve the website based on anonymised usage analytics
  • Comply with legal obligations (e.g., tax record-keeping)

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Cookies

This website uses the following cookies:

Session cookieKeeps you logged in during your visit. Expires after 30 days.Essential — required for login functionality
AnalyticsAnonymised page view and session data. No personally identifiable information.Analytics — helps us improve the site

You can disable cookies in your browser settings. Disabling the session cookie will prevent you from logging in to access purchased programs.

5. Third-Party Services

We use the following third-party services that may process your data:

StripePayment processinghttps://stripe.com/au/privacy
Manus AIPlatform hosting, authentication, analyticshttps://manus.im/privacy
Amazon CloudFrontCDN delivery of images and static assetshttps://aws.amazon.com/privacy/

6. Data Storage & Security

Your personal information is stored in a managed cloud database (TiDB Cloud) hosted in a secure data centre. All data is encrypted in transit (TLS/HTTPS) and at rest. We implement security headers, signed session tokens, and industry-standard access controls to protect your data.

Despite these measures, no internet transmission is 100% secure. If you have concerns about a specific data security issue, please contact us immediately at [email protected].

7. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations:

Account dataUntil you request deletion, or 3 years of inactivity
Order records7 years (Australian tax law requirement)
Analytics dataRolling 24-month window (anonymised)
Session cookies30 days from last login

8. Your Rights

Under the Australian Privacy Act and GDPR, you have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that inaccurate information be corrected.
  • Deletion: Request deletion of your personal information (subject to legal retention obligations).
  • Portability (GDPR): Request your data in a machine-readable format.
  • Objection: Object to processing of your data for direct marketing.

To exercise any of these rights, email [email protected] with the subject line "Privacy Request". We will respond within 30 days.

9. Children's Privacy

This website is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the website after changes are posted constitutes acceptance of the updated policy.

11. Contact & Complaints

For any privacy-related questions or complaints, contact us at:

Sarah Pirie-Nally / Wonder & Wander Pty Ltd

[email protected]

Greater Melbourne Area, Victoria, Australia

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or, for EU residents, your local data protection authority.