Privacy Policy: The Cake Pod
Last updated: 10 August 2026
Who we are
Our website address is: https://thecakepod.com.au
THE CAKE POD, ABN 28620000535. Our annual turnover is below the $3 million threshold that determines coverage under the Privacy Act 1988 (Cth). While this may mean we are not strictly required to comply with the Act, we have chosen to handle your personal information in line with the Australian Privacy Principles (APPs) as a matter of good practice.
If you have any questions about this policy or want to exercise any of the rights below, contact us at in**@************om.au.
Online orders and payments
When you place an order, we collect the information necessary to fulfil it, which may include:
- Name, email address, phone number
- Delivery or pickup address
- Order details (products and customisation notes)
- Payment information
We do not collect or store health-related information (such as allergy or dietary details) as part of order fulfilment.
Payment processing: We offer three payment methods: direct debit, PayPal, and SecurePay (provided by Fat Zebra). Direct debit is a transaction between you and your own bank, and we don’t share your data with a third-party processor for this method. For PayPal and SecurePay, we do not store your full card or bank details on our servers; payments are processed directly by these providers under their own privacy policies:
- PayPal: https://www.paypal.com/au/webapps/mpp/ua/privacy-full
- SecurePay: https://www.securepay.com.au/privacy-policy
We retain order records for 7 years to meet our tax and accounting obligations under Australian law.
Back-in-stock notifications
If you request to be notified when an out-of-stock product becomes available, we collect your email address and the product you’re interested in. This is stored locally in our website’s database and used only to send you that notification; it is not shared with or processed by any third-party service. Records are cleared from our system manually on a regular basis, typically within a few weeks.
Newsletter / email marketing
We do not currently operate an email newsletter or marketing list. If we introduce one in future, this policy will be updated to describe what we collect, which platform we use, and how you can unsubscribe.
Comments
When visitors leave comments on the site, we collect the data shown in the comments form, plus the visitor’s IP address and browser user agent string, to help with spam detection.
An anonymised string created from your email address (a hash) may be sent to the Gravatar service to check whether you use it. Gravatar’s privacy policy is available at https://automattic.com/privacy/. If your comment is approved, your profile picture is publicly visible alongside it.
Comments and their metadata are retained indefinitely so we can automatically recognise and approve genuine follow-up comments rather than holding them in moderation.
Media
If you upload images to the site, avoid uploading images with embedded location data (EXIF GPS). Visitors can download and extract location data from images published on the site.
Cookies and analytics
We use cookies for the following purposes:
- Comment cookies: if you comment, you can opt in to saving your name, email, and website in a cookie for convenience. These last one year.
- Login cookies: if you log in (staff/admin only), cookies save your login and display preferences. Login cookies last two days (two weeks with “Remember Me”); screen option cookies last one year.
- Post-edit cookies: contain no personal data, just the post ID of an article you edited, expiring after one day.
- Analytics: We use Google Analytics to understand how visitors use our site. This sets cookies (such as _ga and _gid) and collects information such as IP address, browser type, and pages visited. See Google’s privacy policy here: https://policies.google.com/privacy
Embedded content from other websites
Articles or pages on this site may include embedded content (e.g. videos, images). Embedded content behaves exactly as if you had visited the other website directly; it may collect data about you, use cookies, embed third-party tracking, and monitor your interaction with that content, including if you’re logged in to that site.
Who we share your data with
We share data with:
- Our payment providers (PayPal and SecurePay), to process orders
- An automated spam detection service, for comment moderation
- If you request a password reset, your IP address is included in the reset email
We do not sell your personal information to third parties.
Overseas data transfers
Some of the third-party services above (e.g. PayPal and Google Analytics) may store or process data on servers located outside Australia. Where this occurs, we take reasonable steps to ensure your data is handled in line with the Australian Privacy Principles.
How long we retain your data
- Comments: retained indefinitely (see Comments section)
- Orders: retained for 7 years for tax/accounting purposes
Data breach notification
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC), in line with the Notifiable Data Breaches (NDB) scheme.
What rights you have over your data
You can request:
- An export of the personal data we hold about you
- Correction of inaccurate data
- Erasure of your personal data (subject to data we’re legally required to retain, e.g. tax records)
To make a request, contact in**@************om.au.
If you’re unhappy with our response, you can lodge a complaint with the OAIC: https://www.oaic.gov.au

