Privacy Policy
This Privacy Policy describes how drgolly.com (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.
SECTION 1 – WHAT DO WE DO WITH YOUR INFORMATION?
We have your security and privacy in mind, every step of the way. When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address, and email address. Your personal information will never be forwarded to third parties without a lawful basis.
When you browse our store, we automatically receive your device’s internet protocol (IP) address in order to learn about your browser, device, and browsing behavior.
Email and SMS marketing (if applicable): With your explicit permission, we may send you emails and/or text messages about our store, new products, and updates.
SECTION 2 – CONSENT
How do you get my consent?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery, or return a purchase, you consent to our collecting and using it for that specific reason only, under applicable laws.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your explicit consent or provide you with a clear opportunity to opt out.
We may use personal information for retargeting or personalized advertising via platforms such as Meta (Facebook/Instagram), provided you have given appropriate consent via our cookie banner or consent manager (in jurisdictions like the EEA or California).
How do I withdraw my consent?
If after opting in you change your mind, you may withdraw your consent at any time by contacting us at [email protected] or writing to us at:
Dr Golly Sleep Program Pty Ltd
181/183 Wattletree Rd,
MALVERN, VIC Australia 3144
You can also withdraw cookie-related consent by adjusting your browser settings or through the cookie banner (if applicable).
SECTION 3 – LEGAL BASES FOR PROCESSING (GDPR)
If you are located in the EEA or UK, we rely on the following legal bases to process your personal data:
SECTION 4 – DISCLOSURE
We may disclose your personal information if required to do so by law or if you violate our Terms of Service.
SECTION 5 – WORDPRESS & WOOCOMMERCE
Our store is hosted on WordPress.com and WooCommerce. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through WooCommerce’s data storage, databases, and applications on secure servers behind a firewall.
Payment: If you use a direct payment gateway, WooCommerce and Stripe may store your credit card data. This information is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). We retain your payment data only as long as necessary to complete your transaction, after which it is deleted.
SECTION 6 – THIRD-PARTY SERVICES
Third-party providers (e.g. Stripe, PayPal, Meta, Afterpay) collect, use, and disclose your information only as necessary to perform the services they provide.
Each provider has its own privacy policy. If the provider is based in a different jurisdiction, your personal data may be transferred internationally and become subject to different legal requirements.
We recommend reviewing their privacy policies.
SECTION 7 – INTERNATIONAL DATA TRANSFERS (GDPR)
If you are located in the EEA or UK, your data may be transferred outside of your region, including to countries like the United States or Australia. When we do so, we rely on legal mechanisms such as:
SECTION 8 – SECURITY
We follow industry best practices to protect your personal information. Credit card information is encrypted using SSL and stored with AES-256 encryption.
No transmission method over the Internet or storage is 100% secure, but we follow all PCI-DSS and GDPR security obligations.
SECTION 9 – DATA RETENTION
We retain personal data only as long as necessary to:
Once no longer required, data is securely deleted or anonymized.
SECTION 10 – COOKIES
We use cookies to enhance your experience and support core functionality, analytics, and advertising. Some cookies are essential; others require your consent.
See our Cookie Policy for full details and options to manage or withdraw cookie preferences.
SECTION 11 – DATA SUBJECT RIGHTS (GDPR + US STATES)
Depending on your jurisdiction, you may have rights including:
To exercise any of these rights, email [email protected]. We will respond within the legally required timeframe.
If you are in the EU or UK and are dissatisfied, you may lodge a complaint with your local data protection authority.
SECTION 12 – CALIFORNIA PRIVACY RIGHTS (CCPA / CPRA)
If you are a California resident, you have the right to:
We do not sell personal data, but we may share it for targeted advertising purposes.
Submit requests by contacting [email protected].
SECTION 13 – YOUR U.S. STATE PRIVACY RIGHTS
Residents of Virginia, Colorado, Utah, and Connecticut may also have the right to:
Please email [email protected] to make a request.
SECTION 14 – DO NOT SELL OR SHARE MY PERSONAL INFORMATION
We may use your personal information for targeted advertising via platforms like Meta (Facebook/Instagram). This may be considered a “share” under California law.
You have the right to opt out. To do so: