ReturnsTrack Orders
Brand Logo
Home
Women

Tops

  • Women's Tops

Bottom

  • Women's Bottom

Denim

  • Women's Denim

Sleepwear

  • Women's Sleepwear
Kids

Tops

  • Kids Tops

Bottom

  • Kids Bottom
Men

Tops

  • Men's Top

Bottom

  • Men's Bottom

Shorts

  • Men's Shorts

Denim

  • Men's Denim

Workwear

  • Mens Workwear

Underwear

  • Men's Underwear

Shirts

  • Men's Shirts
Brand Logo
Menu
  • Home
  • Tops

    • Women's Tops

    Bottom

    • Women's Bottom

    Denim

    • Women's Denim

    Sleepwear

    • Women's Sleepwear
  • Tops

    • Kids Tops

    Bottom

    • Kids Bottom
  • Tops

    • Men's Top

    Bottom

    • Men's Bottom

    Shorts

    • Men's Shorts

    Denim

    • Men's Denim

    Workwear

    • Mens Workwear

    Underwear

    • Men's Underwear

    Shirts

    • Men's Shirts

Login / Register

H&K Styles

Stay in the know

Sign up for our newsletter on latest styles & greatest offers.

H&K Styles

  • About Us
  • Acknowledgement of the Country

Shop

  • Kids
  • Women
  • Men

Help & Support

  • Contact Us
  • FAQ

Legal and Policies

  • Terms and Conditions
  • Privacy Policy
  • Shipping Policy
  • Returns & Refunds Policy
  • Warranty and Faulty Goods Policy
  • Spam Act & Marketing Policy
  • Cookies Policy
  • Legal Disclaimer
  • Copyright Notice
Secure payments

© 2026 H&K Styles. All Rights Reserved. ABN: 87 686 282 468

Privacy Policy

Last Updated: June 2026 

Operated by: H&K Global Trading Pty Ltd (ABN 87 686 282 468 / ACN 686 282 468) 

Trading as: H&K Styles 

Website: www.handkstyles.com.au 

Privacy Office Email: privacy@handkstyles.com.au 

 

1. Policy Overview & Commitment 

1.1 Data Protection Foundation: H&K Styles (operated exclusively by H&K Global Trading Pty Ltd) is committed to protecting the privacy, confidentiality, and integrity of our customers' and platform users' personal information. 

1.2 Statutory Compliance Standard: We collect, handle, log, and process all personal information strictly in accordance with the Privacy Act 1988 (Cth), the Privacy Regulations 2025, and the thirteen (13) Australian Privacy Principles (APPs). We adopt these rigorous statutory frameworks as our baseline operational standard across all data handling workflows, regardless of whether our corporate turnover activates mandatory regulatory thresholds. 

1.3 Monitoring Legal Reforms: We actively monitor legislative updates arising from the OAIC Privacy Act Review, the Children’s Online Privacy Code, and the APP 1.7 Transparency Standards regarding Automated Decision-Making (ADM). We continuously update our processing code and this document as required by law to maintain total compliance. 

 

2. Categories of Collected Personal Information 

We gather and process only the necessary and minimized categories of personal data required to host our retail services, manage clothing orders, and protect our systems: 

2.1 Identity & Contact Specifications: Full name, birthdate (utilized exclusively for rewards verification), telephone numbers, billing addresses, and physical shipping locations. 

2.2 Transaction & Database Profiles: Item purchase histories, garment sizes, transaction tracking numbers, digital account credentials, and loyalty program point balances. 

2.3 Communication Records: Correspondence payloads with our support staff, user-submitted product reviews, and fraud mitigation verifications. 

2.4 Marketing Array Logs: Explicit opt-in timestamps, interaction metrics, click-through paths, and opt-out/unsubscription markers. 

2.5 Technical Telemetry: Device IP addresses, browser profiles, operating system identifiers, localized language selections, network paths, session cookie parameters, and integrated tracking pixel attributes collected via our Node.js runtime environment. 

2.6 Financial Security Isolation: To protect customer financial safety, our systems never ingest, parse, process, or store raw credit card primary account numbers (PANs), expiration values, or CVV codes. All payment processing is tokenized directly via our integrated payment gateway provider, Stripe. 

 

3. Authorized Uses of Personal Information 

We process personal data to fulfill our retail contracts and meet our statutory obligations under the following precise parameters: 

3.1 Fulfillment: Executing checkout operations, verifying transactions, and handing off packages to courier networks for delivery. 

3.2 Rewards Administration: Hosting member profiles and administering point calculations under the H&K Members Rewards Program. 

3.3 Customer Remedies: Handling returns, monetary refunds, and statutory ACL fault claims. 

3.4 Fraud Prevention & Automated Decision-Making Transparency: Deploying automated fraud prevention scanners and checking identity data to block payment exploits. 

ADM Disclosure: Our Node.js platform utilizes automated fraud scoring via Stripe to protect our business. If an algorithmic check identifies an order as high-risk or potentially fraudulent, the checkout payload may be automatically blocked or held for manual review. You have an absolute right to contest an automated transaction cancellation and request human review by contacting privacy@handkstyles.com.au. 

3.5 Service Communications: Sending out necessary transactional service notices, delivery alerts, and system security warnings. 

3.6 Consent-Based Marketing: Transmitting targeted marketing emails or SMS updates where express consumer consent has been secured. 

3.7 Optimization: Analyzing website behavior and tracking conversions to optimize our platform's speed and security. 

3.8 Corporate Compliance: Fulfilling taxation, financial reporting, corporate auditing, and law enforcement requests under Australian law. 

 

4. Children's Online Privacy & Verification Frameworks 

4.1 Collection Restrictions: H&K Styles does not knowingly or intentionally collect, store, profile, or process personal data from individuals under the age of 18 without verified parental or guardian consent. Individuals under 18 are prohibited from independently registering an account or subscribing to our marketing campaigns. 

4.2 Automated Account Purging: If our backend analytics identify that an individual under 18 has submitted data to our servers without verified guardian consent, we will instantly deactivate the account, halt all related marketing campaigns, and permanently wipe their details from our active databases. 

4.3 Parent and Guardian Identity Verification: If you are a parent or guardian and believe your minor child has submitted data to us without your authorization, contact us immediately at privacy@handkstyles.com.au. To ensure data security and comply with APP 12, we verify your identity without collecting extra high-risk documentation. We confirm your authorization by matching your request with your child's specific account identifiers, or by verifying the request against the registered billing email used for historical store checkouts. Once confirmed, we will erase the minor's data as soon as practicable. 

 

5. Commercial Marketing, Unsubscribe Mechanics & SMS Register Guidelines 

5.1 Consent Requirements: Commercial marketing communications are sent only where you have provided express or reasonably inferred consent, or where permitted by law. 

5.2 One-Click Unsubscription Process: In strict compliance with the Spam Act 2003 (Cth) and current ACMA enforcement updates, every marketing message contains a prominent, functional, and completely frictionless one-click unsubscribe mechanism. We do not require you to log in to an account, re-enter your email address, or pay any processing fees to opt out. Unsubscribe requests are handled by automated scripts within our backend code within five (5) business days of submission. 

5.3 SMS Register Compliance: In accordance with ACMA anti-scam directives, all commercial SMS marketing messages use a sender ID registered with the official Australian SMS Sender ID Register. This prevents bad actors from spoofing or impersonating the H&K Styles brand name. 

5.4 Transactional Exclusions: Opting out of marketing channels will not affect or stop vital transactional service messages regarding active orders, delivery tracking updates, or payment receipts. 

 

6. Cookies, Digital Tracking Pixels & Consent Banners 

6.1 Tracking Methods: The Website uses functional cookies, tracking pixels, analytics scripts, and advertising measurement tools provided by platforms including Google Analytics, Google Ads, Meta (Facebook/Instagram), and our integrated marketing platforms. 

6.2 Operational Purposes: These tracking scripts record your browsing habits, remember your cart selections, measure ad performance, and serve relevant product recommendations. 

6.3 User Preference Management: You can block cookies and tracking scripts through your browser settings. To ensure complete alignment with OAIC tracking guidelines and protect your privacy against data misuse claims, the Website features an automated Cookie Consent Banner and preference management tool. This tool lets you opt out of optional advertising tracking pixels before they can load or execute in your browser. 

 

7. Shared Personal Information Categories 

We share personal data only where necessary to manage our retail operations or fulfill legal obligations. Data transfers are limited to the following categories of external entities:


Recipient Category: Payment Gateways 

Integrated Examples & Platforms: Stripe, Afterpay, Zip 

Core Operational Purpose: Processing secure tokens to complete checkouts.


Recipient Category: Logistics Carriers

Integrated Examples & Platforms: Australia Post, local courier networks

Core Operational Purpose: Generating shipping labels and delivering physical orders.


Recipient Category: Marketing Suites 

Integrated Examples & Platforms: Klaviyo, Meta Audiences, Google Ads

Core Operational Purpose: Deploying targeted marketing campaigns and managing unsubscribes.


Recipient Category: Analytics Suites 

Integrated Examples & Platforms: Google Analytics

Core Operational Purpose: Measuring website performance and analyzing drop-off rates.


Recipient Category: Fraud Screening  

Integrated Examples & Platforms: Third-party fraud mitigation networks

Core Operational Purpose: Scanning transactions for stolen cards or identity exploits. 


Recipient Category: Infrastructure Hosting 

Integrated Examples & Platforms: Hostinger Cloud Hosting Infrastructure 

Core Operational Purpose: Storing data securely within our Node.js stack.


Recipient Category: Professional Advisors

Integrated Examples & Platforms: Legal counsel, corporate accountants, auditors 

Core Operational Purpose: Ensuring statutory compliance and auditing tax records. 


Recipient Category: Regulators & Courts  

Integrated Examples & Platforms: OAIC, ACCC, state law enforcement agencies

Core Operational Purpose: Fulfilling mandatory data disclosures required by law.


8. Cross-Border Disclosures & Overseas Server Locations (APP 8) 

8.1 Disclosure of Overseas Hosting Nodes: By using the platform and transacting with H&K Styles, you explicitly acknowledge that your personal information is transmitted outside of Australia. 

8.2 Storage Locations: Our server architecture is deployed via Hostinger, utilizing primary cloud storage nodes located in Malaysia and secondary backup/replication hosting clusters located in Singapore. 

8.3 Corporate Protections: H&K Global Trading Pty Ltd takes reasonable operational and contractual steps to ensure that these overseas hosting entities handle your personal data with the equivalent privacy safeguards required under the Australian Privacy Principles. 

 

9. Data Security and Notifiable Data Breaches (NDB) Scheme 

9.1 Safeguard Frameworks: We execute industry-standard security protocols, encryption pathways, and server access-control restrictions to shield personal data stored within our databases from unauthorized entry, alteration, disclosure, loss, or destructive extraction. 

9.2 The Notifiable Data Breaches Scheme: In full alignment with Part IIIC of the Privacy Act 1988 (Cth), H&K Global Trading Pty Ltd maintains a comprehensive data breach response plan. In the rare event that an eligible data breach occurs that is reasonably likely to result in serious harm to your privacy, security, or identity, we will instantly: 

  • 9.2.1 Isolate and patch the security vulnerability within our Node.js and Hostinger environment. 
  • 9.2.2 Lodge a formal statement detailing the breach parameters with the Office of the Australian Information Commissioner (OAIC). 
  • 9.2.3 Notify all impacted consumers directly via their registered email address with specific advice on how to mitigate personal identity risks. 


10. Access, Correction, and Complaint Rights (APPs 12 & 13) 

10.1 Requesting Data Logs: Under APPs 12 and 13, you hold an absolute statutory right to request access to the personal information logs we hold about you, or to demand the immediate correction of outdated or inaccurate data records. 

10.2 Lodgement Pathway: To execute these rights, or to lodge a formal complaint regarding our data processing methods, you must submit a written request directly to our privacy officer at privacy@handkstyles.com.au. We will review your identity and respond to your request within thirty (30) calendar days. 

10.3 Regulatory Escalation: If you are dissatisfied with our internal privacy evaluation or believe we have breached the APPs, you maintain an absolute right to lodge a formal statutory escalation with the Office of the Australian Information Commissioner (OAIC) online at www.oaic.gov.au.