Cookie Policy
What cookies and similar technologies we use on the site, what they do, and the choices available to you, wherever you are.
About This Policy
The Fabric Shop Pty Ltd (ABN: 69 693 515 687) (“The Fabric Shop”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, store, and secure your personal information when you use any of our websites:
- https://www.thefabricshop.com (our primary website)
- our regional domains, which route to the Site and support local branding where required: https://www.thefabricshop.au (Australia), https://www.thefabricshop.uk (United Kingdom), https://www.thefabricshop.eu (European Union), and https://www.thefabricshop.us (United States)
(collectively, the “Site”) and our services, including The Yard, PrintLab, and the Design Partner programme.
1.1 Data Controller / APP Entity
The Fabric Shop Pty Ltd is the data controller (for individuals located in the European Union or United Kingdom) and the APP entity (for individuals located in Australia) responsible for the personal information described in this Policy. Our registered office is in Victoria, Australia. Our contact details are set out in Section 16.
1.2 Laws We Comply With
- Australia: the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including APP 8 (cross-border disclosure of personal information) and the Notifiable Data Breaches scheme.
- European Union: Regulation (EU) 2016/679 (the EU General Data Protection Regulation, or “EU GDPR”), and the ePrivacy Directive 2002/58/EC as transposed into your national law.
- United Kingdom: the UK GDPR and the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
- United States: applicable State consumer privacy laws, including (where applicable to us) the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Utah Consumer Privacy Act. See Section 12 for US-specific disclosures.
References in this Policy to “personal information” include “personal data” under the GDPR and “personal information” under US State privacy laws.
Who We Are and Our Fulfilment Arrangements
2.1 Supplier of Record
The Fabric Shop Pty Ltd is the supplier of record for all orders placed through the Site, the data controller for all personal information described in this Policy, and the single point of contact for privacy enquiries, regardless of the country from which your order is shipped.
2.2 Fulfilment Provider
Manufacturing, printing, finishing, packing, and dispatch are performed on our behalf by a related body corporate of The Fabric Shop (within the meaning of section 50 of the Corporations Act 2001 (Cth)) located in the People’s Republic of China (the “Fulfilment Provider”). The Fulfilment Provider acts as our data processor for the purposes of the EU and UK GDPR, and as a recipient of disclosed information for the purposes of APP 8. The personal information we transfer to the Fulfilment Provider is described in Section 5 and Section 7.
2.3 EU and UK Representatives
Because we are established in Australia but offer goods and services to individuals in the European Union and the United Kingdom, we are required to designate representatives under Article 27 of the EU GDPR and the equivalent provision of the UK GDPR.
- EU Representative: [EU REPRESENTATIVE NAME AND ADDRESS, TO BE APPOINTED BEFORE EU GO-LIVE]
- UK Representative: [UK REPRESENTATIVE NAME AND ADDRESS, TO BE APPOINTED BEFORE UK GO-LIVE]
Individuals located in the European Union or United Kingdom may contact our representatives in the relevant region on any matter relating to the processing of their personal data, in addition to (or instead of) contacting our Privacy Officer in Australia.
Information We Collect
We collect the following categories of personal information.
3.1 Information You Provide
- Identity and contact information: name, shipping and billing address, email address, and phone number.
- Account information: username, password (stored as a salted hash), language and region preferences.
- Order information: a record of the products and PrintLab designs you have ordered, including order dates, amounts, fabric base selections, lengths, and delivery details.
- Customer Content (PrintLab): the digital design files you upload to PrintLab for custom printing, and any associated metadata (filename, dimensions, colour profile, AI-disclosure flag).
- Design Partner information: for Design Partners, your chosen display name, designer biography and profile image (where you have enabled them in your dashboard), uploaded Designs and associated metadata, payment details (PayPal email address; the email address linked to your Wise account, we do not collect or store your Wise bank details; or bank account details where you are located in Australia or New Zealand), and tax documentation as described in Section 3.5.
- Communications: the content of your enquiries, claims, takedown notices, counter-notifications, and support messages.
- Marketing preferences: whether you have opted in to email or SMS marketing, and your channel and frequency preferences.
3.2 Payment Information
We do not store your full payment card details. Payments from customers are processed through Shopify’s payment infrastructure (including Shopify Payments and connected payment methods such as PayPal, Apple Pay, Google Pay, and Shop Pay), which is PCI-DSS compliant. Shopify processes your payment information on our behalf in its capacity as a payment processor. Please refer to Shopify’s privacy notice for details of its own processing.
3.3 Information We Collect Automatically
- Technical data: IP address, device type and identifier, operating system, browser type and version, referring URL, timestamps, and approximate location (derived from IP).
- Usage data: the pages you view, products and Designs you interact with, items added to or removed from cart, cart-abandonment signals, and search terms used on the Site.
- Cookies and similar technologies: as described in our Cookie Policy.
3.4 Information from Third Parties
- Fraud and risk signals: we may receive fraud-risk information from Shopify, our payment processors, and similar service providers, used to detect and prevent fraudulent transactions.
- Analytics: we receive aggregated and (where you have consented to non-essential cookies) individual-level analytics from providers such as Google Analytics and any social or advertising pixels we deploy, as described in the Cookie Policy.
- Identity and KYC verification (Design Partners): we may receive identity-verification signals from PayPal, Wise, or our other payment providers as part of their AML/KYC checks before royalty payments are made.
3.5 Sensitive Information (Special Categories)
We may also collect the following information which is treated with additional care because of its sensitivity or because it is regulated as a special category under applicable law:
- Tax identifiers (Design Partners): Australian Business Numbers (ABNs), foreign Tax Identification Numbers (TINs), tax residency declarations, and (for Australian Design Partners without an ABN) ATO Statement by a Supplier forms, provided under Section 3.3 of the Design Partner Agreement. We do not collect Tax File Numbers. This information is used only for the lawful purpose of administering Australian withholding tax.
- Government identification (where required): where AML/KYC laws or payment providers require it, we may collect copies of government-issued identification documents. We use these solely for verification and retain them only as long as required by law.
Other than the above, we do not knowingly collect special categories of personal data (such as racial or ethnic origin, religious or philosophical beliefs, trade union membership, health data, sexual orientation, or genetic or biometric data) under Article 9 of the EU/UK GDPR, and we ask that you do not submit such information to us. If you do, we will only process it where we have a lawful basis under Article 9(2) GDPR.
How We Use Your Information and Our Lawful Bases
For individuals in the European Union and the United Kingdom, the table below identifies the lawful basis on which we rely under Article 6 (and, where applicable, Article 9) of the GDPR for each processing purpose. For other individuals, the purposes describe why we process your information.
| Purpose | Data Used | GDPR Lawful Basis (EU/UK) |
|---|---|---|
| Processing your order, accepting your offer, and forming a contract of sale | Identity, contact, account, order, payment, Customer Content | Performance of a contract (Art. 6(1)(b)) |
| Manufacturing, finishing, and shipping your order, including transferring your data to the Fulfilment Provider | Identity, contact, order, Customer Content | Performance of a contract (Art. 6(1)(b)) |
| Customer service, claims handling, and order-related communications | Identity, contact, order, communications | Performance of a contract (Art. 6(1)(b)) |
| Holding your Customer Content for the period needed to fulfil your order and handle any remake or fault claim | Customer Content, account data | Performance of a contract (Art. 6(1)(b)) |
| Operating the Design Partner programme and paying royalties | Design Partner identity, tax, payment details, sales records | Performance of a contract (Art. 6(1)(b)) |
| Administering Australian withholding tax on royalty payments | Tax identifiers, payment data | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention, chargeback defence, account security, and AML/KYC checks | Identity, payment, technical data | Legitimate interests (Art. 6(1)(f)) and Legal obligation (Art. 6(1)(c)) |
| Complying with tax, accounting, consumer law, and other legal obligations | Identity, order, payment, communications | Legal obligation (Art. 6(1)(c)) |
| Direct marketing by email and SMS | Contact data, marketing preferences | Consent (Art. 6(1)(a)) |
| Analytics, site improvement, and personalisation | Technical and usage data | Consent (for non-essential cookies); otherwise Legitimate interests (Art. 6(1)(f)) |
| Defending or establishing legal claims, including IP takedown processes | Any relevant category | Legitimate interests (Art. 6(1)(f)) and Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have carried out (or will carry out, before launch) a documented balancing assessment. You have the right to object to processing based on legitimate interests; see Section 11.
Privacy of Your Uploaded Designs (PrintLab)
We understand that your designs are valuable intellectual property and we take the following measures to handle them with care. This Section applies both to Customer Content (designs uploaded by customers to print on their own order) and to Library Content (designs uploaded by Design Partners to be offered to customers).
5.1 Confidentiality
Your uploaded design files are treated as confidential. We do not sell, licence, distribute, or otherwise make your design files available to any third party, except:
- to our Fulfilment Provider in the People’s Republic of China, to the extent necessary to manufacture orders that include your design (see Section 5.2);
- to our IT, hosting, security, and analytics service providers under appropriate confidentiality and data-protection obligations (see Section 6);
- to professional advisers, regulators, courts, or law-enforcement agencies where required by law or in connection with the defence or establishment of legal claims; and
- with your express prior written consent.
5.2 Data Minimisation on Transfer to the Fulfilment Provider
Transfers of design files to our Fulfilment Provider are limited to what is necessary to fulfil specific customer orders to which the transfer relates. When those orders have been fulfilled, the design file is removed from the Fulfilment Provider’s production systems. We do not maintain a permanent copy of your designs in the People’s Republic of China for marketing or library purposes.
5.3 No Marketing Use Without Consent (Customer Content)
We will not use Customer Content (designs uploaded by customers to print on their own order) in any marketing or promotional material, including social media, paid advertising, email, or our website, without your express prior written consent.
5.4 Marketing Use of Library Content (Design Partners)
Where you are a Design Partner and have uploaded Designs to be offered as Library Content, you grant us a marketing licence under the Design Partner Agreement. That licence is described in detail in Section 4 of the Design Partner Agreement and is summarised in Section 11.3 below. The marketing licence applies only to Library Content, not to Customer Content.
5.5 Design Storage and Deletion
We retain a copy of your uploaded Customer Content only for as long as is needed to fulfil your order and to handle any remake or fault claim. Design files are deleted within 30 days of fulfilment of the order to which they relate, or earlier on your request (via your account settings or privacy@thefabricshop.com). We do not maintain a reorder library: to reorder a design, upload the file again. Minimal records of completed orders (not including the design file itself) are retained for tax, accounting, and dispute-resolution purposes (see the retention table in Section 9). You are encouraged to maintain your own backup copies of your designs at all times.
Who We Share Information With
We do not sell or rent your personal information. We share personal information only with the following categories of recipient, under appropriate contractual and security safeguards:
| Recipient Category | Examples | Purpose |
|---|---|---|
| Fulfilment Provider (related body corporate) | Our manufacturing and dispatch arm in the People’s Republic of China | Printing, finishing, packing, dispatch |
| Shipping carriers | Australia Post, international postal carriers, courier services nominated by the Fulfilment Provider | Delivery of goods, tracking notifications |
| Payment processors | Shopify Payments, PayPal, Stripe, Wise | Payment processing, AML/KYC checks, Design Partner payouts |
| IT and hosting providers | Shopify (e-commerce platform and hosting), email service providers | Operating the Site, sending transactional communications |
| Analytics providers | Google Analytics, social-media advertising platforms (only where you have consented) | Site analytics, advertising attribution |
| Professional advisers | Lawyers, accountants, auditors | Legal advice, tax compliance, audit |
| Regulators and authorities | OAIC, ICO (UK), EU supervisory authorities, customs authorities, courts, law-enforcement agencies | Where required by law, regulatory request, or legal process |
| Successor entities | Acquirer or surviving entity in a merger, acquisition, restructure, or sale | Continuity of service following a corporate transaction |
Where we share personal information with the recipients above, we require them (by contract and where appropriate by an Article 28 GDPR data-processing agreement) to handle that information consistently with this Policy and applicable data-protection law.
International Data Transfers
7.1 Where Your Data Goes
As we operate across multiple markets, your personal information may be transferred to and processed in countries other than your country of residence. In particular:
- Australia: we are established in, and process personal information in, Victoria, Australia. Australia is not currently the subject of a European Commission adequacy decision under Article 45 of the EU GDPR.
- People’s Republic of China: our Fulfilment Provider processes order data and design files in the People’s Republic of China for the purposes described in Section 5.2.
- Other countries: our service providers (such as Shopify and Google) may process certain technical and usage data in the United States, Ireland, Singapore, and other locations where their infrastructure operates.
7.2 Australian Customers, APP 8
For Australian customers, by placing an order, creating an account, or uploading Customer Content, you acknowledge and consent to your personal information being disclosed to our Fulfilment Provider in the People’s Republic of China for the purposes described in this Policy. We take reasonable steps to ensure our Fulfilment Provider handles your information consistently with the APPs, including by contractual confidentiality and information-security obligations.
Acknowledgement of APP 8.3 limitation: You acknowledge that, once your personal information has been disclosed to our Fulfilment Provider in the People’s Republic of China, the Privacy Act 1988 (Cth) may not apply to the overseas recipient to the same extent as it applies to us, and you may not be able to seek redress for a breach under that Australian law.
7.3 EU and UK GDPR Transfers
For transfers of personal data from the European Economic Area or the United Kingdom to Australia, the People’s Republic of China, or any other country not recognised as providing an adequate level of protection, we rely on one or more of the following transfer mechanisms under Chapter V of the GDPR and the equivalent UK GDPR rules:
- the European Commission’s Standard Contractual Clauses (Module 2 controller-to-processor, or such other module as applies to the transfer) (“SCCs”);
- the UK International Data Transfer Addendum to the SCCs (the “UK Addendum”), or the standalone UK International Data Transfer Agreement (IDTA), where UK personal data is transferred;
- additional technical and organisational safeguards, including encryption in transit, access controls, and contractual confidentiality;
- a documented Transfer Impact Assessment (TIA) in relation to transfers to the People’s Republic of China, as required following the Court of Justice of the European Union’s decision in C-311/18 (“Schrems II”); and
- where applicable, your explicit consent to the transfer after being informed of the possible risks under Article 49(1)(a) of the GDPR.
You may request a copy of the relevant transfer mechanism (with commercial information redacted) by contacting privacy@thefabricshop.com.
7.4 US Customers
For customers and users in the United States, your personal information is transferred to Australia and to the People’s Republic of China for the purposes described in this Policy. By using the Site or placing an order, you consent to such transfers. Where applicable State law requires additional notice or opt-in for the cross-border transfer of certain categories of personal information, we will provide that notice through this Policy or at the point of collection.
Data Security and Breach Notification
8.1 Security Measures
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure, including:
- SSL/TLS encryption for data in transit between your browser and our Site;
- use of reputable hosting and payment infrastructure (including Shopify and Shopify Payments) which maintain industry-standard security certifications;
- access controls, role-based permissions, and authentication for our staff and the Fulfilment Provider;
- contractual obligations on third-party service providers, including data-processing agreements where required;
- incident-response procedures and periodic review of our security practices.
No transmission or storage of information is completely secure, and we cannot guarantee the security of information transmitted to or stored by us.
8.2 Data Breach Notification
Where a data breach involving your personal information is likely to result in serious harm or a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by:
- the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth);
- Articles 33 and 34 of the EU GDPR and UK GDPR;
- any applicable US State data breach notification laws (which vary by state and may require notice to affected individuals, the State Attorney-General, or credit reporting agencies); and
- any other applicable breach-notification laws in your country of residence.
Notifications will be issued within the timeframes required by the relevant law (for example, without undue delay and where feasible not later than 72 hours after we become aware of a notifiable breach under the EU/UK GDPR).
Data Retention
We retain personal information only for as long as necessary for the purposes for which it was collected, or for longer where required or permitted by law. Our default retention periods are set out below. Where these periods differ, we apply the longer period.
| Data Category | Retention Period | Reason |
|---|---|---|
| Order and invoice records (including related personal and payment data) | 7 years from end of financial year of the order | Income tax and record-keeping law (s.262A ITAA 1936; equivalent UK, EU, US obligations) |
| PrintLab Customer Content (uploaded designs) | Deleted within 30 days of fulfilment of the related order, or earlier on request | Fulfilment, remakes, and fault claims only; no reorder library is maintained (data minimisation, Art. 5(1)(c) GDPR) |
| Design files held by the Fulfilment Provider | Removed from production systems on completion of the relevant order | Data minimisation (Art. 5(1)(c) GDPR) |
| Account login and profile data | While your account is active, plus 12 months after account closure | Customer service, security, dispute resolution |
| Design Partner payment and royalty records (including ABN/TIN) | 7 years from end of financial year of the relevant payment | Tax and accounting law |
| AML/KYC verification records (where collected) | 7 years from end of business relationship | AML/CTF Act 2006 (Cth) and equivalent overseas requirements |
| Marketing consent records (proof of opt-in) | Until consent withdrawn, plus 3 years | Demonstrate lawful basis under GDPR; defend against unsolicited-marketing complaints |
| Support and claims correspondence | 3 years from the last interaction | Customer service and dispute resolution |
| IP takedown notices and counter-notifications | 5 years from receipt | Defend repeat-infringer policy decisions |
| Technical logs (server, security) | 12 months | Security and incident investigation |
| Web analytics (Google Analytics or equivalent) | 13 months | Analytics retention default; configurable |
At the end of the applicable retention period, we will delete or de-identify your personal information, unless we are required to retain it for longer in connection with an ongoing legal claim, regulatory investigation, or law-enforcement request.
Cookies and Similar Technologies
Our Site uses cookies and similar technologies to operate the Site, remember your preferences, analyse Site usage, and (where you have consented) personalise content and advertising. Full details of the categories of cookies we use, their purposes, lifetimes, and how to manage them are set out in our Cookie Policy.
EU and UK users: in accordance with the ePrivacy Directive, PECR, and the GDPR, we will request your consent for non-essential cookies via a consent banner on your first visit. You may withdraw that consent at any time through the cookie-preferences link in the Site footer.
US users: certain advertising cookies and similar technologies may constitute a “sale” or “sharing” of personal information under California, Virginia, Colorado, Connecticut, and Utah State law. You may opt out of such sale or sharing as described in Section 12.
Your Privacy Rights
Depending on your country of residence, you have some or all of the following rights in respect of your personal information.
11.1 Rights
- Access: request a copy of the personal information we hold about you.
- Correction: request that we correct any information that is inaccurate, incomplete, or out of date.
- Deletion or Erasure: request that we delete your personal information and any stored PrintLab design files, subject to legal record-keeping requirements (such as the 7-year retention of tax records).
- Data Portability (EU/UK): request a copy of your personal data in a structured, commonly used, machine-readable format, and request that we transmit it to another controller where technically feasible.
- Objection and Restriction (EU/UK): object to, or request restriction of, processing of your personal data on grounds relating to your particular situation, including processing based on legitimate interests; and object at any time to processing for direct marketing.
- Withdraw Consent: where processing is based on your consent (including marketing and non-essential cookies), withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Automated Decision-Making: we do not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects on you. If we introduce such processing in future, we will update this Policy and provide the safeguards required under Article 22 GDPR and the Privacy Act 1988 (Cth), including the automated-decision-making transparency requirements introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth).
- US State Rights: if you are a resident of California, Virginia, Colorado, Connecticut, or Utah, see Section 12.
11.2 How to Exercise Your Rights
Contact our Privacy Officer at privacy@thefabricshop.com. We will respond within 30 days, or within the shorter or longer timeframe required by your local law. We may ask you to verify your identity before acting on a request. We may decline or limit your request to the extent permitted by law (for example, where the request is manifestly unfounded or excessive, or where retention is required for a legal purpose), and will explain our reasons if we do.
11.3 Marketing-Specific Note for Design Partners
Design Partners separately grant us a marketing licence under the Design Partner Agreement to promote Library Content. That licence is contractual in nature and is not based on consent within the meaning of Article 6(1)(a) GDPR; accordingly, the “withdraw consent” right does not apply to it. Design Partners who wish to remove specific deployed marketing assets should follow the request process in Section 4.2(d) of the Design Partner Agreement.
11.4 Right to Lodge a Complaint
You may lodge a complaint with a supervisory authority. We would appreciate the opportunity to address your concerns first by contacting our Privacy Officer, but you are not required to do so.
- Australia: the Office of the Australian Information Commissioner (OAIC): oaic.gov.au
- United Kingdom: the Information Commissioner’s Office (ICO): ico.org.uk
- European Union: your national data protection supervisory authority. A list is maintained by the European Data Protection Board at edpb.europa.eu
- United States: the relevant State Attorney-General, or (for California consumers) the California Privacy Protection Agency at cppa.ca.gov
US State Privacy Rights
This Section provides additional disclosures and rights for individuals located in California, Virginia, Colorado, Connecticut, Utah, and other US states with applicable consumer privacy laws. These rights are in addition to those described in Section 11.
12.1 Categories of Personal Information We Collect
In the 12 months preceding the last update to this Policy, we have collected the following categories of personal information (as defined in the CCPA/CPRA and equivalent statutes) from US-based individuals:
- Identifiers (name, postal address, email address, phone number, IP address, account login);
- Commercial information (records of products purchased, fabrics ordered, design preferences);
- Internet or network activity (browsing on our Site, interaction with advertisements);
- Geolocation data (approximate, derived from IP address);
- Visual information (uploaded Customer Content, Design Partner uploaded Designs);
- Inferences drawn from the above to create a profile of a consumer’s preferences.
For Design Partners specifically, we additionally collect tax identifiers (TIN, and for AU/NZ Partners, ABN), payment-account details, and government-issued identification where required for AML/KYC verification.
12.2 Sources, Purposes, and Disclosures
Sources of collection, purposes of use, and categories of recipient are described throughout Sections 3, 4, and 6 of this Policy.
12.3 “Sale” and “Sharing” of Personal Information
We do not sell personal information in exchange for money. Where you have consented to non-essential advertising cookies on our Site, certain disclosures of identifiers and internet-activity data to advertising and social-media platforms may constitute a “sale” or “sharing for cross-context behavioural advertising” under California, Virginia, Colorado, Connecticut, and Utah State law.
Right to opt out: you may opt out of any such sale or sharing at any time by:
- clicking the “Do Not Sell or Share My Personal Information” link in our Site footer;
- changing your cookie preferences via the cookie-preferences link in the Site footer; and
- for Global Privacy Control (GPC) signals, our Site honours GPC signals as a valid opt-out request where required by applicable State law (including California and Colorado).
12.4 Sensitive Personal Information
We collect categories of sensitive personal information under the CCPA/CPRA (specifically, tax identifiers and government identification, where applicable to Design Partners) only for the purposes described in Section 3.5 and Section 4. We do not use or disclose sensitive personal information for purposes other than those reasonably necessary to provide the service, and you have the right to limit our use of sensitive personal information under Section 1798.121 of the CCPA/CPRA.
12.5 Non-Discrimination and Verification
We do not discriminate against you for exercising any of your US State privacy rights. We will not deny goods or services, charge different prices, or provide a different level of service because you exercised a right under this Section, except where permitted by law. To verify a rights request, we may ask you to provide information sufficient to match against our records (typically name, email address, and order number).
12.6 Authorised Agents
California, Virginia, Colorado, and Connecticut residents may use an authorised agent to submit a rights request, subject to verification of the agent’s authority.
12.7 Shine the Light (California)
California Civil Code Section 1798.83 permits California residents to request information regarding the disclosure of certain categories of personal information to third parties for the third parties’ direct marketing purposes. We do not disclose personal information for those purposes.
Marketing Communications
We will only send you marketing emails or SMS messages where you have expressly opted in or where we are otherwise permitted to do so under applicable law (for example, the limited “soft opt-in” for existing customers under PECR in the United Kingdom and the equivalent rules in the European Union and Australia under the Spam Act 2003 (Cth)).
Every marketing email contains an unsubscribe link. Every marketing SMS contains opt-out instructions (such as replying STOP). You can also update your marketing preferences in your account or by contacting hello@thefabricshop.com.
US TCPA note: for SMS marketing to US numbers, we obtain prior express written consent as required by the Telephone Consumer Protection Act, and we do not send marketing SMS to mobile numbers in the United States outside the hours of 8am to 9pm in the recipient’s local time zone.
Children’s Privacy
The Site and our services are not directed at children. You must be at least 18 years of age (or the age of legal majority in your jurisdiction, if higher) to create an account or place an order, as required by Section 4.1 of our Terms of Service.
We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact our Privacy Officer at privacy@thefabricshop.com and we will take steps to delete that information.
US users: for the avoidance of doubt, we do not knowingly collect personal information from children under 13 (the age threshold under the US Children’s Online Privacy Protection Act, or “COPPA”), and we comply with applicable State laws (such as California’s SOPIPA and the CCPA’s age-related provisions) regarding the personal information of minors.
Changes to This Policy
We may amend this Privacy Policy from time to time. The revised version will be posted on the Site with an updated “Last Updated” date. Where a change materially reduces your rights or expands the way we use your personal information, we will use reasonable endeavours to notify you in advance by email (where you have provided one) or by a prominent notice on the Site before the change takes effect.
Your continued use of the Site following the effective date of any change constitutes your acceptance of the revised Policy.
Contact Our Privacy Officer
If you have any questions about this Privacy Policy, wish to exercise your rights, or wish to make a complaint, please contact our Privacy Officer:
- Email: privacy@thefabricshop.com
- Post: The Fabric Shop Pty Ltd, 17 Coleman Parade, Suite # XX, Glen Waverley, VIC 3150, Australia
We will respond to all privacy enquiries within 30 days, or within the shorter or longer timeframe required by your local law.
EU and UK Representatives: see Section 2.3. Individuals located in the European Union or United Kingdom may contact our representatives in the relevant region in addition to (or instead of) our Privacy Officer.
© 2026 The Fabric Shop Pty Ltd (ABN: 69 693 515 687). All rights reserved.