PCD knows the importance of online privacy and straight off the bat we are not in the business of harvesting and selling private and sensitive information. Understanding how and what information about you is stored, used and shared is key to keeping your Personally Identifiable Information safe and secure.
For additional details governing the “Privacy Act” refer to Aus Gov link: https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act
This statement governs our privacy policies with respect to those users of the Site ("Visitors") who visit without transacting business and Visitors who register to transact business on the Site and make use of the various services offered by Printer Cartridges Direct (collectively, "Services") ("Authorised Customers").
"Personally Identifiable Information" refers to any information that identifies or can be used to identify, contact, or locate the person to whom such information pertains, including, but not limited to, name, address, phone number, fax number, email address, financial profiles and credit card information. Personally Identifiable Information does not include information that is collected anonymously (that is, without identification of the individual user) or demographic information not connected to an identified individual.
We may collect basic user profile information from all of our Visitors. We collect the following additional information from our Authorised Customers: the names, addresses, phone numbers and email addresses of Authorised Customers.
We use Personally Identifiable Information to customise the Site, to make appropriate service offerings, and to fulfill buying and selling requests on the Site. We may email Visitors and Authorised Customers about research or purchase and selling opportunities on the Site or information related to the subject matter of the Site. We may also use Personally Identifiable Information to contact Visitors and Authorised Customers in response to specific inquiries, or to provide requested information.
Personally Identifiable Information collected by Printer Cartridges Direct is securely stored and is not accessible to third parties or employees of Printer Cartridges Direct except for use as indicated above.
Visitors and Authorised Customers may opt out of receiving unsolicited information from or being contacted by us and/or our vendors and affiliated agencies by responding to emails as instructed, or by contacting us here Contact Us.
PCD uses login information, including, but not limited to, IP addresses, ISPs, and browser types, to analyse trends, administer the Site, track a user’s movement and use, and gather broad demographic information.
We will disclose Personally Identifiable Information in order to comply with a court order or subpoena or a request from a law enforcement agency to release information. We will also disclose Personally Identifiable Information when reasonably necessary to protect the safety of our Visitors and Authorised Customers.
All of our employees are familiar with our security policy and practices. The Personally Identifiable Information of our Visitors and Authorised Customers is only accessible to a limited number of qualified employees who are given a password in order to gain access to the information. We audit our security systems and processes on a regular basis. Sensitive information, such as credit card numbers is outsourced to “Stripe Payment” and protected by encryption protocols. Outsourcing payment security to an established payment partner whose sole mode of business being a payment platform makes security sense. Other Personally Identifiable Information other than payment and credit card details, we take commercially reasonable measures to maintain a secure site, electronic communications and databases though can be subject to errors, tampering and break-ins, and we cannot guarantee or warrant that such events will not take place, and we will not be liable to Visitors or Authorised Customers for any such occurrences. For a more in-depth reference to Stripe Payment see section further below "What is Stripe Payment?"
We provide Visitors and Authorised Customers with a mechanism to delete/deactivate Personally Identifiable Information from the Site's database by contacting us here Contact Us. However, because of backups and records of deletions, it may be impossible to delete a Visitor’s entry without retaining some residual information. An individual who requests to have Personally Identifiable Information deactivated will have this information functionally deleted, and we will not sell, transfer, or use Personally Identifiable Information relating to that individual in any way moving forward.
We will let our Visitors and Authorised Customers know about changes to our privacy policy by posting such changes on the Site. However, if we are changing our privacy policy in a manner that might cause disclosure of Personally Identifiable Information that a Visitor or Authorised Customer has previously requested not be disclosed, we will contact such Visitor or Authorised Customer to allow such Visitor or Authorised Customer to prevent such disclosure.
Stripe is a secure online payment processing and credit card processing platform. Most notable from below information is that all card numbers are encrypted at rest with AES-256 with decryption keys being stored on separate machines.
Stripe encrypts sensitive data both in transit and at rest. Stripe’s infrastructure for storing, decrypting, and transmitting primary account numbers (PANs), such as credit card numbers, runs in a separate hosting infrastructure, and doesn’t share any credentials with the rest of our services. A dedicated team manages our CDV in an isolated Amazon Web Services (AWS) environment that’s separate from the rest of Stripe’s infrastructure. Access to this separate environment is restricted to a small number of specially trained engineers and access is reviewed quarterly.
All card numbers are encrypted at rest with AES-256. Decryption keys are stored on separate machines. We tokenize PANs internally, isolating raw numbers from the rest of our infrastructure. None of Stripe’s internal servers and daemons can obtain plain text card numbers but can request that cards are sent to a service provider on a static allowlist. Stripe’s infrastructure for storing, decrypting, and transmitting card numbers runs in a separate hosting environment, and doesn’t share any credentials with Stripe’s primary services including our API and website. It’s not just PANs that are tokenized this way; we treat other sensitive data, like bank account information, in a similar way.
For more information, refer to the following links:
https://docs.stripe.com/security#dedicated-card-technology
https://docs.stripe.com/security#https-hsts-secure-connections
Links: This web site contains links to other web sites. Please note that when you click on one of these links, you are moving to another web site. We encourage you to read the privacy statements of these linked sites as their privacy policies may differ from ours.