We don't track you.
We don't hold what we don't need.
This policy is written in plain English. It explains exactly what we collect, why we collect it, how long we keep it, and what your rights are — under the Australian Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs).
- No Google Analytics, no Meta Pixel, no ad cookies, no browser fingerprinting.
- The only personal data we hold is what you type into a checkout, contact, or waitlist form.
- Personal details are wiped 30 days after your device is delivered.
- We never sell, rent, or share your data with data brokers or ad networks.
- You can request a copy of, correction to, or deletion of your data any time.
This website does not run Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight, Cloudflare Web Analytics, Plausible, PostHog, Hotjar, or any similar tracker. We do not set advertising cookies. We do not fingerprint your browser. If your ad-blocker shows an empty list on this page, it's working — because there is nothing to block.
We do keep short-lived server access logs (IP address, user agent, request path, timestamp) at our hosting provider for the purpose of blocking abuse and diagnosing outages. These logs rotate out inside 14 days.
We only collect information you deliberately give us. Specifically:
- Checkout data — full name, email, optional phone number, shipping address, and any notes you attach to your order. Collected only if you complete an order.
- Order + payment metadata — what you ordered, the tier, the total, the AUD price at the moment of purchase, the order reference, and (for crypto) the wallet address shown to you plus the amount quoted at the locked-in exchange rate.
- Card payment data — if you pay by card, checkout is hosted by Stripe. We never see or store your card number, CVC, or expiry. Stripe returns to us only a payment status, an internal session ID, and a payment intent ID that we can use to issue refunds. Stripe's own privacy notice governs their handling of the card data.
- Contact-form messages — the name, email, subject and message you submit through the Contact page. Retained only for the duration of the conversation, then archived and deleted.
- Phantom X waitlist entry — the contact handle you provide (Signal number, Telegram username, email, or Session ID), the platform you want a build for, and an optional note. Used solely to notify you when the app is ready.
- Nothing else. No date of birth, no government ID, no social handles beyond what you voluntarily enter, no browsing history from other sites.
- Building, testing, and shipping your device.
- Contacting you about your order (dispatch, delays, warranty).
- Verifying that a payment has cleared (on-chain for crypto, via Stripe or your bank for card / bank transfer).
- Answering messages you send us.
- Emailing you when Phantom X launches — but only if you joined the waitlist.
- Detecting and blocking fraud or abuse of our checkout.
- Meeting our legal obligations (tax, consumer guarantees under the Australian Consumer Law, lawful requests).
We do not use your data to profile you, personalise ads, train models, or sell you upgrades you didn't ask about.
We use one first-party browser localStorage entry to remember what you put in your cart between page reloads. It never leaves your device. We use short-lived first-party cookies only for essential state (session hand-off between the shop and the checkout). We do not use any third-party cookies, and we do not need a cookie banner because we set no non-essential cookies.
We share information only with the parties strictly required to fulfil your order:
- Courier — receives your name and shipping address for that shipment only. Nothing else.
- Stripe — if you pay by card, Stripe processes the card details directly; we receive a status back but never see the card itself. Stripe is a global processor; card data may be handled on servers outside Australia (typically the United States and Europe).
- Our bank — if you pay by PayID / OSKO / bank transfer, your bank naturally sees the transfer; we see only the amount and the reference on our end.
- CoinGecko — we call CoinGecko's public price API to display the current AUD price for XMR / LTC. This call is server-to-server and contains no information about you.
- Our hosting + database provider — the servers that store the order records you've entered. Bound by data-processing agreements. No marketing access to your data.
We do not sell, rent, or share your data with data brokers, advertising networks, "analytics" companies, or any third party not listed above.
Our own database is hosted with an Australian-region cloud provider. When you pay by card, Stripe may process that payment on servers overseas (typically the US and EU). Under APP 8, we take reasonable steps to ensure any overseas recipient handles your personal data consistently with the APPs — for Stripe, this is governed by Stripe's binding data-processing terms and their compliance with GDPR / CCPA / equivalent frameworks.
- Card (Stripe) — Stripe receives your card number, name on card, expiry, CVC, and billing address. Governed by Stripe's privacy notice.
- Monero / Litecoin — we display a wallet address and an AUD-locked amount. Once you send, we verify the transaction on-chain. We do not require or store the wallet you sent from. Note that Litecoin's base chain is public; XMR is private by default.
- Bank transfer / PayID — your bank details are visible to our bank as part of any standard transfer. We store only the reference and the amount.
- Personal contact details — automatically purged 30 days after successful delivery.
- Order record — retained for 7 years in a de-identified form (product, tier, total, reference, timestamp) as required for tax and Consumer Law compliance. Your name / address / email is scrubbed from that record on the 30-day mark.
- Contact-form messages — deleted once the conversation is closed, at most 90 days.
- Waitlist entry — kept until Phantom X launches and we've notified you, then deleted. You can unsubscribe at any time by messaging us.
- Server access logs — rotate out inside 14 days.
If you ask us to delete your data sooner, we will — email us from the same address you ordered with and we'll action the request inside 7 days (see section 12).
- All traffic to this website is over TLS (HTTPS). No plain-HTTP endpoint exists.
- The database is not exposed to the public internet; access requires an authenticated internal token.
- The admin dashboard uses a token-based auth header, not username / password. That token is rotated when compromised.
- We minimise what we collect in the first place, on the principle that data we never held cannot be leaked or subpoenaed.
- Backups are encrypted at rest.
We comply with lawful Australian orders (valid subpoena, notice to produce, or court order) the same way any Australian business does. In practice, our data-minimisation posture means we typically do not hold the material sought — once your 30-day warranty window has closed, we no longer have your delivery details, and we never had your card number in the first place.
Where the law permits it, we will notify affected customers of a request that concerns their data, so you have the chance to respond.
Under the Privacy Act 1988 and the APPs, you have the right to:
- Request a copy of the personal information we hold about you (APP 12).
- Ask us to correct anything that's out-of-date or inaccurate (APP 13).
- Ask us to delete your data ahead of the 30-day auto-purge.
- Withdraw consent for any future contact (e.g. waitlist emails).
- Complain to us directly, and to the Office of the Australian Information Commissioner (OAIC) if you're not satisfied with our response.
Email your request from the same address you ordered with (so we can verify it's you) and we'll respond within 7 days. Requests to PGP-encrypted addresses are welcome.
