Privacy Policy

Last updated: 15 May 2026

FarmThru Pty Ltd (ABN 79 692 444 027) ("FarmThru", "we", "us", "our") respects your privacy and is committed to handling your personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other applicable Australian privacy laws.

This policy explains what personal information we collect, how we collect, hold, use and disclose it, the choices you have, and how to contact us. It applies to our website at farmthru.com.au, any related mobile experiences, and the services we provide through them (together, the "Service").

By using the Service or providing your personal information to us, you agree to this policy. If you do not agree, please do not use the Service.

1. What personal information we collect

The types of personal information we collect depend on how you interact with us. They may include:

  • Identity and contact details — your name, email address, postal and delivery address, phone number, and date of birth where age verification is required.
  • Account details — your password (stored in hashed form), login activity, saved addresses and preferences.
  • Order and transaction details — the products you order, order history, pickup or delivery instructions, gift messages, and tax invoices.
  • Payment details — we do not store full card numbers on our servers. Payments are processed by our PCI-DSS compliant payment partner (Stripe). We may store limited payment-method metadata such as card brand, last four digits and expiry month for your saved methods.
  • Communications — emails, support messages, chat transcripts, product reviews, supplier applications and survey responses.
  • Device, usage and location data — IP address, browser type, device identifiers, referring URLs, pages viewed, search terms, recently viewed products, approximate location (city or postcode) and time spent on the site.
  • Cookies and similar technologies — see section 6 below.

2. How we collect personal information

We collect personal information:

  • Directly from you when you create an account, place an order, sign up to our newsletter, apply to become a supplier, contact our team, leave a review, or otherwise use the Service.
  • Automatically as you use the Service, through cookies, analytics tools and server logs.
  • From third parties where lawful — for example, payment processors confirming a transaction, courier and pickup partners providing delivery updates, fraud-prevention services, identity-verification providers (where required), or social platforms if you choose to connect an account.
  • From someone placing an order on your behalf (for example, a gift recipient's details supplied by the purchaser).

If you provide us with personal information about another person, you must have their consent to do so and to share it with us.

3. Sensitive information

We do not seek out sensitive information (such as health, religious beliefs or political views). If we ever need to collect it — for example, dietary or allergy notes you choose to share — we will only do so with your consent and only use it for the purpose for which you provide it.

4. Why we collect, hold and use your information

We use your personal information to:

  • Create and maintain your account;
  • Process, fulfil and deliver your orders, including coordinating pickup and delivery with our hub, courier and supplier partners;
  • Send transactional messages such as order confirmations, pickup reminders, delivery updates, refund notices and account notifications;
  • Provide customer support and respond to your questions, feedback or complaints;
  • Improve our products, services, search results and recommendations (including showing you items related to what you have viewed before);
  • Send marketing communications about FarmThru, our farmers and seasonal produce, where you have opted in (see section 7);
  • Personalise your experience on the Service, including which products and content we surface;
  • Detect and prevent fraud, abuse, security incidents and other harmful activity;
  • Comply with our legal obligations and respond to lawful requests from regulators, courts or law-enforcement agencies;
  • Operate, evaluate and improve our business.

5. Who we share your information with

FarmThru does not sell your personal information. We share it with third parties only where it is necessary to run the Service or where we are legally required or permitted to. These include:

  • Suppliers and farms we partner with — limited order information needed to prepare your goods (such as items ordered and the suburb for routing). They do not receive your full contact details unless you have agreed to be contacted directly.
  • Delivery and pickup partners — your name, the delivery address and contact phone number to complete delivery or hand over a pickup order.
  • Payment processors — Stripe, which processes payments and stores card data on our behalf under industry security standards.
  • Technology and hosting providers — including Amazon Web Services (Sydney region) for our backend and storage, Vercel for hosting the storefront, our email service provider for transactional and marketing email, our search provider for product search, and Anthropic PBC for processing chat-assistant messages (see section 11).
  • Analytics and advertising platforms — including Google Analytics and Vercel Analytics, in line with section 6.
  • Professional advisers — such as our accountants, auditors and lawyers, bound by confidentiality.
  • Government, regulators and law enforcement — where required by law, court order or to protect FarmThru, our customers or the public.
  • Successors — if FarmThru is involved in a merger, acquisition or asset sale, your information may be transferred as part of that transaction, subject to this policy.

6. Cookies and analytics

We and our service providers use cookies, pixels and similar technologies to keep you signed in, remember your cart, understand how the Service is used, measure marketing performance and protect against fraud. You can manage your preferences through our cookie banner and your browser settings.

Where you accept analytics cookies, we use Google Analytics 4 (with Consent Mode v2) and Vercel Analytics to measure aggregate usage patterns. Where you decline, only strictly necessary cookies are set.

7. Direct marketing

With your consent, we will send you emails about new products, producer stories, seasonal availability and offers. Every marketing email contains an unsubscribe link, and you can also turn marketing off in your account settings or by emailing us. Transactional messages relating to orders and your account will continue regardless of marketing preferences.

8. Overseas disclosure

Some of our service providers store or process personal information outside Australia. In particular:

  • Our primary backend, storage and operational systems are hosted in Australia (AWS, Sydney region).
  • Some of our service providers (for example, payment, analytics, email, search, mapping and customer-support tools) may store or process data in the United States, the European Union, the United Kingdom or other jurisdictions.

Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.

9. How we protect your information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These include encryption in transit (HTTPS), encryption at rest, hashed password storage, role-based access controls, regular security reviews and vendor due diligence on our key processors.

No system is perfectly secure. If we become aware of a data breach likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.

10. Data retention

We retain personal information for as long as we need it for the purposes set out in this policy, including to meet legal, tax, accounting and reporting obligations (typically at least seven years for transaction records). When information is no longer needed, we will delete or de-identify it.

11. AI chat assistant

When you use the chat assistant on farmthru.com.au, we keep a record of:

  • the messages you send and the assistant's replies;
  • which information lookups the assistant performed on your behalf (for example, a delivery-zone check or product search) — we record that the lookup happened, not a duplicate of the underlying data;
  • a session identifier linking the conversation either to your FarmThru account, if you are signed in, or to an anonymous pseudonymous browser identifier we set in a cookie.

We use these records to understand what our customers are asking us for, to improve the accuracy and helpfulness of the assistant, and to investigate cases that are passed on to our support team.

Your messages are processed in real time by Anthropic PBC, the provider of the Claude AI model the assistant uses. Anthropic processes the text as a service provider under their commercial API terms and does not use it to train their models. We do not share chat data with any other third party, and we do not sell it.

Chat conversations are stored on our Australian backend (encrypted at rest) and retained for 180 days from your last message, after which they are permanently deleted. This retention period is shorter than the one for transaction records described in section 10.

To request earlier deletion of a specific conversation or your entire chat history, email hello@farmthru.com.au with the subject line "Chat deletion". You can also reset a conversation at any time using the "New chat" button in the chat panel — that clears it from your browser, though the server-side copy will be removed on the schedule above.

12. Accessing, correcting and deleting your information

You can:

  • View and update most of your information directly from your account settings;
  • Request access to, or correction of, the personal information we hold about you by emailing hello@farmthru.com.au;
  • Ask us to delete your account and the personal information we no longer need to retain.

We may need to verify your identity before acting on your request. We will respond within a reasonable time and, if we cannot grant your request in full, we will explain why.

13. Children

The Service is intended for users aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.

14. Complaints

If you have a privacy concern, please contact us first at hello@farmthru.com.au with the subject line "Privacy". We will acknowledge your complaint and aim to resolve it within 30 days.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

15. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. When we do, we will update the "Last updated" date above and, for material changes, notify you by email or through a notice on the Service before the change takes effect.

16. Contact us

For any questions about this policy or how we handle your personal information:

FarmThru Pty Ltd (ABN 79 692 444 027)
Email: hello@farmthru.com.au
Subject line: Privacy