freshly baked, since 2012
The CupcakeDesire
The Cupcake Desire

Privacy policy

What we collect,
and what we don’t.

A short list of data, a smaller list of who sees it, and a promise that we won’t sell or trade any of it. Written for people, not lawyers.

Last updated · 30 September 2026

Our promise

We use your information to bake your order, deliver it to your door, and stay in touch the way you want us to. We don’t sell your data. We don’t retarget you across the internet. There’s no agency on retainer harvesting your behaviour.

This policy explains exactly what we collect, why, who else sees it, and how you can ask us to remove it. It follows the Australian Privacy Principles and applies to all visitors and customers of cupcakedesires.com.

What we collect

We collect only what we need to take an order and run the bakery. Specifically:

  • Identity: name, optional date of birth (for birthday treats).
  • Contact: email address, phone number, delivery and billing addresses.
  • Order details: what you bought, when, dietary preferences, delivery notes.
  • Payment: we never see your card details — payments are handled by our payment processor and only a transaction reference is stored.
  • Account & login: if you sign in, your account is managed by our authentication provider (see “Third parties” below).
  • Site usage: anonymised page views and aggregated browser data via privacy-respecting analytics. No individual profiles.

How we use it

We use your information to:

  • Fulfil the order you placed — baking, packing, delivering.
  • Send transactional emails (order confirmation, dispatch, delivery).
  • Respond to your questions when you write to us.
  • Send the weekly bakery letter only if you opt in — one click to unsubscribe at any time, no hard feelings.
  • Improve the site — understanding which pages are useful and which need fixing, in aggregate, never tied to you personally.
  • Comply with Australian tax and consumer law (e.g. retaining invoices for the required period).

Third parties we work with

A handful of trusted providers help us run the site and process orders. They each see only the data they need:

  • Clerk — handles sign-up, sign-in and account management. Sees: name and email.
  • MongoDB Atlas — the database where orders and account details live. Encrypted at rest.
  • Stripe / EFTPOS / Apple Pay / Google Pay — payments. They see card details directly; we don’t.
  • Resend — sends transactional emails. Sees: your email and the email contents.
  • Couriers — sees the delivery address and phone number on the date of delivery.
  • Cloudinary — hosts review and product photos. Doesn’t see your personal details.

We never share your data for marketing or sell it to anyone. If a provider changes, we’ll update this list.

Cookies and tracking

We use the smallest set of cookies we can get away with. These cover:

  • Essential — keeping you signed in, remembering your cart, running the checkout. These can’t be turned off without breaking the site.
  • Analytics — aggregated page-view counts so we know what people read. No individual profile or behavioural retargeting.

We don’t use Facebook Pixel, TikTok pixel, or any other ad-network tracker. Your browser’s “Do Not Track” signal is respected.

How long we keep it

  • Account data: kept while your account is active. Delete your account and we wipe it within 30 days, save for what we’re legally required to keep.
  • Order records: retained for 7 years to meet Australian tax and warranty obligations.
  • Newsletter consent: kept until you unsubscribe.
  • Contact-form messages: retained for 2 years for our records, then deleted.

Your rights

You have the right to:

  • Access the personal information we hold about you.
  • Correct it if anything is wrong.
  • Delete your account and the data tied to it (within legal retention limits).
  • Withdraw consent for marketing emails at any time.
  • Complain to the Office of the Australian Information Commissioner if you think we’ve mishandled something.

To exercise any of these, write to info@thecupcakedesire.com.au with the email address linked to your account. We’ll respond within 14 days.

How we keep it safe

  • All traffic to and from the site is encrypted (HTTPS).
  • The database is encrypted at rest.
  • Card details never touch our servers — payment processing is tokenised.
  • Access to customer data is limited to bakery staff who need it for orders.
  • We review access logs regularly. If we ever experience a notifiable data breach, we will tell you and the regulator as required under Australian law.

Children

The site isn’t aimed at children under 16. We don’t knowingly collect information from anyone in that age group. If you think we’ve collected information from a child without parental consent, let us know and we’ll remove it.

Changes to this policy

We may update this policy from time to time. Material changes will be flagged at the top of the page for at least 30 days and, where the law requires it, notified by email to anyone affected.

Get in touch

Questions about your data, or about this policy, go to info@thecupcakedesire.com.au. A human reads every email — we’ll get back to you within a working day.

Still got a question?

A human reads every email — say hello.

Write to the bakery