
Wollip Digital and Design Pty Ltd ("Wollip", "we", "our", "us") builds and operates two self-serve products:
This policy explains what personal information we collect, why we collect it, who we share it with, where it goes, and what you can do about it. It applies to our website, both products, and any other dealings you have with us.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle information about people in the European Union or the United Kingdom, we also apply the standards set out in section 12.
By using our website or our products, you agree to this policy. If you do not agree with it, please do not use them.
This distinction matters, so we have set it out plainly.
(a) Information about you. If you visit our website, book a call, or open an account, we collect information about you directly. We decide how that information is used and we are responsible for it.
(b) Information about your people. If you use Wollip Signatures, you upload details about the individuals in your organisation whose signatures you are building: their names, roles, contact details and photographs. Those individuals are usually your staff, not our customers.
(c) Information about the people you contact. If you use Wollip Outreach, the platform handles information about the prospects you choose to target, which you either supply to us or direct the platform to source.
For (b) and (c), you decide whose information enters the platform and what happens to it. We hold and process it on your instructions, for the purpose of delivering the product to you. We do not use it for our own marketing, we do not add it to any product or resale database, and we do not sell or rent it to anyone. Your obligations in relation to that information are set out in section 6.
| Category | Examples | Why |
|---|---|---|
| Identity and contact | Name, business email, phone number, company name, job title | To create and administer your account, and to contact you |
| Account credentials | Email address and password hash, or Google account identifier if you sign in with Google | Authentication and account security |
| Billing | Billing name, billing address, subscription tier, seat count, transaction history, and the last four digits and expiry of your payment card | To take payment and manage your subscription |
| Usage | Pages visited, features used, signatures generated, campaigns run, timestamps, IP address, browser and device type | To operate and improve the products, diagnose faults, and detect misuse |
| Communications | Emails, support tickets, call bookings, notes from calls | To respond to you and maintain a record of our dealings |
| Marketing | Whether you have subscribed to our mailing list, and whether you open or click our emails | To send you material you have asked for, and to stop sending it when you have not |
We do not collect your full payment card number. Card details are entered directly with our payment processor, Stripe, and we never receive or store them.
We do not collect sensitive information as that term is defined in the Privacy Act: health information, biometric information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record or union membership. Please do not send it to us.
Typically: full name, job title, email address, direct and mobile phone numbers, office location, headshot or profile photograph, social profile links, and your organisation's logo and brand assets.
We use this solely to render, host and deliver the signature assets you have asked us to produce, and to make them available for you to install and manage.
Typically: name, job title, employer, professional profile URL, business email address, and the content and status of messages sent through the platform.
We use this solely to operate the campaigns you configure and to report results back to you.
We use cookies and similar technologies on our website and in the platform for three purposes: keeping you signed in and the product working; understanding aggregate usage so we can improve it; and, where you have consented, measuring the performance of our advertising.
Strictly necessary cookies cannot be turned off without breaking the product. All others are optional and you can accept or reject them through the banner shown on your first visit, or change your mind at any time using .
We use Google Analytics for analytics.
You can also block or delete cookies through your browser settings, though this may affect how the site works.
Directly from you, when you fill in a form, book a call, create an account, upload assets, or email us.
Automatically, when you use the website or the platform, through cookies, server logs and product analytics.
From third parties, in two situations: our payment processor tells us the outcome of your transactions; and, if you use Outreach, the platform may collect information about prospects from public professional sources at your direction.
Where we collect information about an individual from a source other than that individual, and it is reasonable to do so, we take reasonable steps to make them aware of the matters set out in APP 5, including who we are, that we hold their information, and how they can contact us. That is one reason this policy is public.
We use personal information to:
We may create aggregated, de-identified statistics from usage data (for example, the average number of signatures per account) and use them to improve and describe our products. Once information is genuinely de-identified it is no longer personal information and this policy does not restrict its use.
We do not sell personal information. We do not use automated decision-making that produces legal or similarly significant effects on any individual.
This section is important and forms part of our agreement with you.
When you upload information about your staff, or run campaigns against a list of prospects, you are the one deciding whose information is collected and how it is used. Accordingly, you warrant that:
If we receive a request or complaint from one of those individuals, we will generally refer it to you and assist you in responding, unless the law requires us to act ourselves.
We share personal information with the service providers that make our products work. Each is bound to protect the information and to use it only to provide services to us.
| Provider | What it handles |
|---|---|
| Supabase | Database, authentication, file storage (signature assets, uploaded images) |
| Railway | Rendering infrastructure that generates signature animations |
| Upstash | Job queue for rendering |
| Vercel | Website and application hosting |
| Cloudflare | Content delivery and security |
| Stripe | Payment processing and subscription billing |
| Resend | Transactional email (account, billing and security messages) |
| Sign-in, if you choose Google authentication; website analytics (Google Analytics), if you accept analytics cookies |
These providers may process information in Australia, the United States or the European Union. The protections in section 8 apply to any disclosure outside Australia.
We also share information:
We will update the table above when our providers change. Material changes are notified under section 13.
Some of the providers listed above store or process information outside Australia, principally in the United States and the European Union. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, including by relying on the provider's contractual data protection commitments.
By using our products, you acknowledge that information may be handled outside Australia. If you require Australian-only data residency, contact us at the address in section 15 before opening an account, as it may not be possible on all tiers.
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption of data in transit using TLS, encryption at rest with our infrastructure providers, role-based access controls so staff can only reach what their role requires, multi-factor authentication on administrative accounts, and regular review of access.
No system is completely secure, and information transmitted over the internet is transmitted at your own risk. Keep your account credentials confidential and tell us immediately if you believe your account has been compromised.
We maintain a data breach response plan. If we become aware of unauthorised access to, or disclosure or loss of, personal information we hold, we will assess it promptly.
Where a breach is likely to result in serious harm to an affected individual, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where the breach affects information you have placed in the platform, we will notify you without undue delay so that you can meet your own obligations.
| Information | Retention |
|---|---|
| Account and profile information | For the life of your account, then 90 days after closure |
| Signature assets and uploaded images | Deleted 30 days after account closure or on your request |
| Prospect and campaign data in Outreach | Deleted 30 days after account closure, or earlier on your request |
| Billing and transaction records | 7 years, as required by Australian tax and corporations law |
| Support correspondence | 2 years from last contact |
| Marketing list membership | Until you unsubscribe, then a suppression record indefinitely so we do not contact you again |
| Server and security logs | 12 months |
Signature GIF files are served from a content delivery network. Once you have installed a signature, copies of those files may persist in recipients' mailboxes and in cached copies for some time after deletion from our systems, and we cannot recall them.
You can ask us to delete your data earlier than the periods above, and we will do so unless we are required to keep it.
You may ask us to:
Write to us at the address in section 15. We will respond within a reasonable period, and in any case within 30 days. We do not charge for making a request, though we may charge a reasonable cost for providing access to a large volume of material. If we refuse a request, we will tell you why in writing and explain how to complain.
If you are in the EU or the UK, you also have the rights to object to processing, to restrict processing, and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Where we handle your information as a controller, we do so on the basis of your consent, the performance of our contract with you, or our legitimate interests in operating and securing our products. Where we handle information on a customer's instructions, we do so as a processor and that customer is the controller. You may complain to your local supervisory authority.
We may update this policy. The current version is always available at wollipdesign.com.au/privacy with the effective date at the top.
If a change materially affects how we handle your information, we will tell you by email or through the product at least 14 days before it takes effect. Continuing to use our products after that date means you accept the updated policy.
If you think we have mishandled your personal information, contact our Privacy Officer at the address below with the details and any supporting material. We will:
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or by writing to GPO Box 5218, Sydney NSW 2001.
For product support and general enquiries, write to enquiries@wollip.au instead.
This policy is governed by the laws of New South Wales, Australia.