Delivery delays are expected for some locations in NSW & QLD due to bushfires.

Privacy & Cookie Policy

Updated 25 May, 2018. 

Privacy Statement

At The Chocolate Box we respect your right to privacy. When you provide The Chocolate Box with your name, e-mail address, mailing address, or telephone number for the purposes of placing and fulfilling an order, we will use that necessary information to process our customer's orders and requests. 

We may also use your information for the following legitimate interests, including:

- To provide you with our services and applications;

- To prevent risk and fraud;

- To provide reporting and analytics;

- To provide communications, marketing and advertising;

- To provide troubleshooting, support services or to answer questions;

The Chocolate Box will not use your information for marketing purposes unless you clearly agree to “opt in” to our subscriber e-mail. Our subscriber email may transmit the following information by email: store news, special offers, and updated product information, and other Chocolate Box related information.

The Chocolate Box does not offer, or allow the selling of, any user-provided information to third parties. In the event of an investigation by a law enforcement agency, The Chocolate Box will provide information as required by law. 

The Chocolate Box respects the rights users give us when opting to receive e-mail communications and enforces internal policies to preserve those rights. It is our objective to retain the long-term ability to continue to communicate with our users. If you do not want The Chocolate Box to contact you, you may opt out of this preference at any time, by clicking the 'unsubscribe' link at the bottom of the email, or contacting The Chocolate Box directly to ask for the removal of your name from the subscriber mailing list. You can contact us using the information on our Contact page.

Cookies

To make this site work properly, we sometimes place small data files called cookies on your device. 

What are cookies?
A cookie is a small text file that a website saves on your computer or mobile device when you visit the site. It enables the website to remember your actions and preferences (such as login, language, font size and other display preferences) over a period of time, so you don’t have to keep re-entering them whenever you come back to the site or browse from one page to another.

How do we use cookies?
Our store, managed by Shopify, uses cookies to let you perform authenticated actions like signing into your personal account. Additionally cookies may be used for advertising purposes.

How to control cookies
You can control and/or delete cookies as you wish – for details, see aboutcookies.org. You can delete all cookies that are already on your computer and you can set most browsers to prevent them from being placed. If you do this, however, you may have to manually adjust some preferences every time you visit a site and some services and functionalities may not work. 

This web site may use cookies as part of a search, online sale, or poll. No personal information is stored in these cookies.

Please be advised that third parties, including Google, Facebook, and Bing may use cookies, web beacons, and other storage technologies to collect or receive information from your website visit and elsewhere on the internet and use that information to provide measurement services and target ads. 

If you wish to opt-out of the collection and use of your data for marketing, you may find the following sites useful to block ads: http://www.aboutads.info/choices (Digital Advertising Alliance's Opt-Out page) or http://www.youronlinechoices.eu/. A Google Analytics opt-out browser add-on is available here.

The Chocolate Box uses a cookie warning pop-up banner on this website. Upon loading it will appear to EU visitors.

Statistical information automatically collected

When you visit the Chocolate Box website, our web host may make a record of your visit and log the following information for statistical purposes:

your server address

your top level domain name (for example .com, .gov, .au, .uk etc)

the pages you accessed and documents downloaded from this website

the previous site you visited just before coming here

the platform of computer you are using

the search engine terms you used to get here

the type of browser you are using

the type of device you are using.

The Chocolate Box will not make an attempt to identify visitors or their browsing activities. However, in the unlikely event of an investigation, a law enforcement agency or other government agency may exercise its legal authority to inspect our logs.

Forms and Email Addresses

We will only store your e-mail address if you send us a message or provide it via a form on our website. Your e-mail address will only be used for the purpose for which you have provided it and it will not be added to a mailing list or used for any other purpose without your consent (which may be given by you in the act of filling in a form and will be clearly indicated). Your email address may be used to invite you to join a mailing list directly related to an enquiry for more information about our store promotions. 

This site does not provide facilities for the secure transmission of information across the Internet or via email. Users should be aware that there are inherent risks transmitting information across the Internet.

If you contact us through our employment form, we will ask you for information which will help us evaluate you as a prospective employee. This will include your name, address, contact details, employment history and referees. Your information will be transmitted to our human resources department via email, for the purposes of assessment. 

If you contact us through our wholesale enquiries form, or corporate enquiries form, you are agreeing to receive email communications from us for the purposes of clarifying and answering your enquiry. 

Residents of the European Economic Area

The Chocolate Box Australia's website is hosted by the Shopify platform. If you are located in the EEA, your personal information is processed by Shopify's Irish affiliate, Shopify International Ltd.

If you are located in the EEA, you have certain rights under European law with respect to your personal data, including the right to request access to, correct, amend, delete, port to another service provider, or object to certain uses of your personal data.

If you are a customer of The Chocolate Box Australia, you may send your request to us using the contact methods on our contact page, and we will endeavour to assist you. Please be advised we may ask you for more information to prove that you are the legitimate owner of your account information. 

Website Hosting 

The Chocolate Box Australia's website is hosted on the Shopify platform. You can find a copy of Shopify's privacy policy, here. Shopify is working to make sure that it is compliant with the GDPR (General Data Protection Regulation) for European states by May 25, 2018. 

Third Party Apps

The Chocolate Box also makes use of a number of apps available in Shopify's app store to improve our site's functionality and add extra services to our site, including providing functionality to our inventory and shipping management, and to improve our customers' experience on our website.

Apps are software integrations that link our website at "chocolatebox.com.au" (hosted on Shopify) with other external service providers.

The Chocolate Box Australia website grants the following third party applications access to user data in the following ways:

- Australia Post. The shipping carrier has access to delivery addresses, names, and contact information, in order to facilitate the delivery of orders. This information is necessary to provide the service. To view the Australia Post's privacy policy, click here

- Rewind. The Chocolate Box's backup solution "Rewind" backs up and stores encrypted data from The Chocolate Box Australia website, including customer and order information. The backup is performed to protect the assets and information on the website from accidental data loss, or the loss of functions and services due to data corruption, human error, or system errors. All communication from the app to Rewind's servers takes place using HTTPS.  Rewind is GDPR compliant and information from European customers is stored on a European server. View their privacy policy here, and the GDPR addendum to their privacy policy here.

- Campaign Monitor. If you opt-in to receive marketing communication emails, or have opted-in to receive marketing communications in the past, your name, email address, and in some cases birthdate, whether you are purchasing on behalf of a company, or the page links you have accessed through the emails, may be stored by Campaign Monitor to help The Chocolate Box Australia deliver relevant marketing content via email to our customers. You can opt-out at any time. Campaign Monitor is preparing for GDPR compliance from May 25th, 2018. You can view their GDPR overview and best practices addendum here. You will find further information about trust, transparency, anti-spam compliance and safe-sending best practices here

- Cin7 is an inventory management software that collects orders from Shopify, which by default includes customer's names, delivery and billing addresses, and may include contact details such as email addresses or phone numbers. Cin7 collects orders for the purpose of managing the company's financial data and inventory. The Chocolate Box Australia may also use Cin7 to look up orders if a customer has instigated a charge back or enquiry. Cin7 is preparing for GDPR compliance, beginning on May 25th 2018, by upating their terms and conditions and upgrading their security infrastructure. You can view Cin7's GDPR addendum here

- Google Analytics makes use of the following types of personal data: "Online identifiers, including cookie identifiers, internet protocol addresses and device identifiers; client identifiers". Google Analytics collects first-party cookies, data related to the device/browser, IP address and on-site/app activities to measure and report statistics about user interactions on the websites and/or apps that use Google Analytics, which includes The Chocolate Box Australia web site. Google uses Google Analytics data to provide the Google Analytics measurement service to customers. Identifiers such as cookies and app instance IDs are used to measure user interactions with a customer’s sites and/or apps, while IP addresses are used to provide and protect the security of the service, and to give the customer a sense of where in the world their users come from. This tool assists The Chocolate Box Australia to analyse the web site's performance so we can make better decisions about our products and services in order to provide more relevant content to our customers. A Google Analytics opt-out browser add-on is available here. You can look at a detailed Google privacy document here. As of 25 May 2018, The Chocolate Box's Google Analytics Data Retention settings have been set to keep data for a maximum of 26 months. 

- Google Adwords Customer Match. The data collected includes names, email addresses, addresses and partner-provided identifiers. The Chocolate Box is not presently utilising this service, however it looks to have been employed back in 2016/2017. We are looking into ways of removing the list. If you have any concerns please contact us and we will keep you informed of our progress. 

- EWay. EWay is one of the secure payment gateways on The Chocolate Box's website. On the secure payment page customers are asked to provide contact information (such as name, Email, and postal address) and financial information (such as credit card number, expiration date). This information is necessary to process your order. eWAY is bound by the (Australian) Privacy Act 1988 (as amended) and the Australian Privacy Principles (collectively, Privacy Law). eWay encrypts sensitive information using secure socket layer technology (SSL). eWay posts the following disclaimer: "We follow generally accepted industry standards to protect the personal information submitted to us, both during transmission and once we receive it. No method of transmission over the Internet, or method of electronic storage, is 100% secure, however. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security". 

- Paypal. Paypal is one of the secure payment gateways available on The Chocolate Box's website. If you agree to Paypal's terms and conditions for use of their service, customers signing up to Paypal are asked to provide contact information (such as name, Email, and postal address) and financial information (such as credit card number, expiration date) or some other method of payment. You may choose to process your order by choosing the Paypal payment option in The Chocolate Box store's checkout. You will then be directed to Paypal's own payment gateway, and be asked to sign in with your user name and password. You can find Paypal's Australian privacy policy here. Click here to view the UK Paypal privacy policy, which may be more relevant for UK visitors, in relation to recent EEA data protection reforms. Click here for a list of Paypal site links worldwide. If you click on the "Privacy" link in the footer of the site, you will be directed to the privacy policy.   

- StarShipIT, also known as ShipIT (New Zealand) is The Chocolate Box's shipping logistics app, which allows an automated information flow of our orders from our website to Australia Post for despatch. StarshipIT controls the shipping and tracking of parcels. It also generates shipping address labels for parcels. StarshipIT has access to names, postal addresses, billing addresses and customer contact information. This facilitates the delivery of orders, parcel tracking, and customer service, by sending an email to customers with a tracking number for their parcel. StarShipIT's privacy policy states: "Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology."

SSL Encryption

The Chocolate Box Australia uses SSL encryption on all pages of the site, not just during checkout, to protect your personal information. 

Disclaimer

All care has been taken in preparing this website but no responsibility can be taken for errors and omissions. Prices and details may be subject to amendment without notice due to price fluctuations of raw commodities. Prices listed on our website are in Australian Dollars and include GST. (The exception to this may be the corporate pricing listed on the "customised blocks" and "chocolate wraparounds" price lists; and in communications with our corporate service representative, who may supply a quote where GST must be added).

Links included in this privacy policy are provided for customer's further information. Links to external sites are active at the time of the update, but we cannot guarantee that they will remain active if the external site changes the location of the linking URL, or removes the page. If you notice that a link is missing or incorrect, please contact The Chocolate Box. 

The Chocolate Box makes no representations or warranties of any kind, express or implied, as to the operation of this site. The Chocolate Box will not be liable for any damages of any kind arising from the use of this site, including but not limited to, direct, indirect, incidental punitive and consequential damages.