Skip to main content
storefrontDrop HubcollectionsCollectionsgroup_addRefer & EarnarticleBlog

Premium limited-edition drops. Made to order. Quality guaranteed.

Explore

Drop HubCollectionsEditorial

Account

Refer & EarnSettings

Policies

Shipping PolicyRefund PolicyPrivacy PolicyCookie & Storage PolicyData SecurityTerms of Service

Support

edhqsupport@exclusivedrops.com
© 2026 Exclusive Drops HQ. All rights reserved.
  1. Homechevron_right
  2. Policieschevron_right
  3. Privacy Policy
Policies & standards

Privacy Policy

How Murano Animals collects, uses, discloses, protects and provides control over personal information.

On this page

01Introduction02Organisation responsible for your information03Contact details04Scope of this Privacy Policy05Meaning of personal information06Personal information we collect07How we collect personal information08Why we use personal information09Information required to provide services10Accounts and authentication11Orders, payments and refunds12Product production, fulfilment and delivery13Email and other communications14Leaderboards and public features15Cookies and similar technologies16When we disclose personal information17Information about particular providers18Service-provider protections19Selling or sharing personal information20International transfers21Retention of personal information22Information security23Personal-data breaches24Your privacy rights25Exercising your rights26Australian privacy rights27European Economic Area and United Kingdom rights28Rights in other jurisdictions29Children’s privacy30Third-party websites and independent services31Changes to this Privacy Policy32Contact us
eventLast updated 17 July 2026Version 1.1 · GDPR & European privacy
01

Introduction

Murano Animals respects your privacy and is committed to handling personal information fairly, lawfully, transparently and securely.

This Privacy Policy explains how Murano Animals collects, holds, uses, discloses, transfers, protects and deletes personal information in connection with:

  • exclusivedropshq.com;
  • customer accounts;
  • limited product drops;
  • leaderboards and participation features;
  • purchases and payments;
  • product production, fulfilment and delivery;
  • customer support;
  • marketing communications;
  • cookies and similar technologies;
  • fraud prevention and website security; and
  • other services provided by Murano Animals.

It also explains the privacy rights that may be available to you and how to contact us about a privacy or security concern.

References to “Murano Animals”, “we”, “us” or “our” mean the organisation identified below.

02

Organisation responsible for your information

The organisation responsible for the personal information described in this Privacy Policy is:

Murano Animals ABN: 96 220 324 478 Morphett Vale, South Australia 5162 Australia

Website: exclusivedropshq.com

Where applicable, Murano Animals is the data controller, responsible organisation or business that determines why and how personal information is processed.

Some third parties involved in payments, delivery, legal compliance or other independently regulated activities may also process limited information as independent controllers under their own privacy notices.

03

Contact details

3.1 Privacy enquiries and rights requests

For access requests, correction requests, deletion requests, consent withdrawals, privacy complaints or questions about this Privacy Policy, contact:

Email: edhqprivacy@exclusivedrops.com Recommended subject line: Privacy Request

3.2 Security concerns

To report suspected unauthorised access, phishing, impersonation, a vulnerability, possible data exposure or another security concern, contact:

Email: edhqsecurity@exclusivedrops.com Recommended subject line: Security Report

Do not include passwords, full payment-card numbers, card security codes or unnecessary sensitive information in your initial report.

3.3 General customer support

For order enquiries, delivery assistance, returns, refunds, product questions or general account assistance, contact:

Email: edhqsupport@exclusivedrops.com

General customer-service enquiries should not be sent to the privacy or security addresses unless the matter specifically concerns privacy or information security.

04

Scope of this Privacy Policy

This Privacy Policy applies when you:

  • visit exclusivedropshq.com;
  • create, access or manage an account;
  • participate in a product drop;
  • use a leaderboard or participation feature;
  • place or attempt to place an order;
  • receive a product or delivery;
  • subscribe to marketing communications;
  • change your privacy or cookie settings;
  • contact customer support;
  • submit a privacy request;
  • report a security concern; or
  • otherwise interact with Murano Animals.

Depending on your location and the circumstances, our activities may be subject to:

  • the Australian Privacy Act 1988 and Australian Privacy Principles;
  • the European Union General Data Protection Regulation;
  • the United Kingdom General Data Protection Regulation;
  • the UK Data Protection Act 2018;
  • applicable electronic-marketing and cookie laws; and
  • other privacy or consumer-protection laws.

References to particular rights or legal requirements apply only where the relevant law applies to Murano Animals and the processing concerned.

We nevertheless aim to apply reasonable privacy standards consistently to all customers.

05

Meaning of personal information

“Personal information” means information or an opinion about an identified individual or an individual who is reasonably identifiable.

Where European or United Kingdom data-protection law applies, this also includes “personal data”, meaning information relating to an identified or identifiable natural person.

Information that has been effectively anonymised so that an individual can no longer reasonably be identified is not generally treated as personal information.

06

Personal information we collect

The information we collect depends on how you interact with us.

6.1 Identity and contact information

We may collect:

  • first and last name;
  • username or display name;
  • email address;
  • telephone number;
  • billing address;
  • delivery address;
  • country or region;
  • communication preferences;
  • social-media username where relevant; and
  • other contact details you choose to provide.

6.2 Account and authentication information

When you create or use an account, we may collect:

  • account identifier;
  • email address;
  • username or display name;
  • securely hashed or encrypted authentication credentials;
  • account creation date;
  • account status;
  • login dates and times;
  • login attempts;
  • password-reset activity;
  • authentication tokens;
  • session information;
  • account preferences;
  • privacy and consent choices; and
  • security events associated with the account.

Passwords are not intended to be stored in readable plain-text form.

6.3 Order and transaction information

When you place or attempt to place an order, we may collect:

  • products selected or purchased;
  • product variations;
  • quantity;
  • price;
  • discounts or promotional codes;
  • order number;
  • order date;
  • order status;
  • billing information;
  • delivery information;
  • delivery instructions;
  • shipping method;
  • tracking information;
  • tax information;
  • payment status;
  • refund or replacement information;
  • return information;
  • chargeback or dispute information; and
  • communications relating to the transaction.

6.4 Payment information

Payments are processed through third-party ecommerce, payment and financial-service providers made available during checkout.

Murano Animals does not ordinarily receive or store:

  • complete payment-card numbers;
  • card security codes;
  • online-banking passwords; or
  • complete payment-account credentials.

We may receive limited payment-related information, such as:

  • payment status;
  • payment method type;
  • transaction reference;
  • billing address;
  • refund status;
  • fraud or risk indicators;
  • chargeback information; and
  • limited card information, such as the final digits, where supplied by the payment provider.

The relevant payment provider may be identified during checkout and may process information under its own privacy notice and legal obligations.

6.5 Product-drop information

When you register for or participate in a limited product drop, we may collect:

  • registration status;
  • customer or member status;
  • eligibility information;
  • product reservations;
  • purchase history relevant to product limits;
  • purchase attempts;
  • quantities obtained;
  • drop participation history;
  • account milestones; and
  • information required to administer limited product availability.

6.6 Leaderboard and participation information

Where a leaderboard or participation feature is offered, we may collect:

  • display name;
  • points;
  • ranking;
  • achievements;
  • qualifying activities;
  • participation status;
  • account milestones; and
  • related activity history.

We will not intentionally publish your private contact, payment, billing or delivery information through a leaderboard.

6.7 Customer-support information

When you contact us, we may collect:

  • your name and contact details;
  • the content of your message;
  • account or order references;
  • information about the issue;
  • photographs or files you provide;
  • requested outcomes;
  • customer-service notes;
  • records of our response; and
  • information required to verify your identity.

6.8 Privacy and security correspondence

When you submit a privacy request or security report, we may collect:

  • your identity and contact information;
  • the details of the request or report;
  • relevant account, transaction or device information;
  • verification information;
  • supporting documents;
  • investigation notes;
  • correspondence;
  • actions taken; and
  • the final outcome.

6.9 Marketing and consent information

We may collect:

  • whether you subscribed to marketing;
  • the date and time of consent;
  • the method by which consent was provided;
  • the wording or notice presented at the time;
  • communication preferences;
  • campaign delivery information;
  • email interaction information where permitted;
  • unsubscribe requests;
  • withdrawn consent;
  • cookie choices; and
  • records demonstrating that your choices were respected.

6.10 Device and technical information

When you use our website, we or our authorised service providers may collect:

  • Internet Protocol address;
  • approximate region derived from an IP address;
  • browser type and version;
  • device type;
  • operating system;
  • language;
  • referral source;
  • pages and features viewed;
  • dates and times of access;
  • session duration;
  • session identifiers;
  • error messages;
  • performance information;
  • security events;
  • login attempts;
  • cookie identifiers; and
  • server and application logs.

Approximate region information is not intended to identify your exact physical address.

6.11 Cookie and similar-technology information

We may collect information through:

  • browser cookies;
  • local storage;
  • session storage;
  • pixels;
  • tags;
  • scripts;
  • embedded technologies; and
  • similar technologies.

More information is provided in Section 15.

6.12 Social-media information

If you communicate with Murano Animals through a social-media service, we may receive:

  • your public profile name;
  • username;
  • profile image;
  • the content of your message or comment;
  • public interactions;
  • group or page activity; and
  • other information you choose to share.

Your use of the social-media platform is also governed by the platform’s own privacy practices.

6.13 Sensitive information

Murano Animals does not intentionally request sensitive personal information such as information concerning:

  • health or medical conditions;
  • race or ethnicity;
  • religious or philosophical beliefs;
  • political opinions;
  • trade-union membership;
  • sexual orientation;
  • genetic information;
  • biometric identifiers; or
  • criminal history.

Please do not provide sensitive information unless it is genuinely necessary and we have specifically requested it.

If sensitive information is provided without being requested, we will only use or retain it where legally permitted and reasonably necessary. Otherwise, we may delete or de-identify it.

07

How we collect personal information

7.1 Directly from you

We may collect information directly when you:

  • create or update an account;
  • complete a form;
  • register for a product drop;
  • use a website feature;
  • place an order;
  • provide billing or delivery details;
  • subscribe to marketing;
  • change cookie preferences;
  • contact customer support;
  • make a privacy request;
  • report a security concern; or
  • otherwise provide information to us.

7.2 Automatically

Information may be collected automatically through:

  • website requests;
  • authentication systems;
  • application and server logs;
  • security controls;
  • fraud-prevention systems;
  • cookies;
  • browser storage;
  • email-delivery systems; and
  • website-performance technologies.

Non-essential technologies are handled according to the cookie-consent requirements described in Section 15.

7.3 From service providers

We may receive information from third parties involved in:

  • website and application hosting;
  • database services;
  • account authentication;
  • ecommerce;
  • payment processing;
  • fraud prevention;
  • email delivery;
  • product production;
  • order fulfilment;
  • delivery;
  • returns; and
  • customer support.

7.4 From production, fulfilment and delivery partners

Organisations involved in producing or delivering an order may provide:

  • production status;
  • fulfilment status;
  • tracking numbers;
  • delivery events;
  • failed-delivery information;
  • address corrections;
  • customs information;
  • return-to-sender information; and
  • returned-parcel details.

7.5 From public sources

In limited circumstances, we may collect information from publicly available sources where reasonably necessary to:

  • investigate suspected fraud;
  • respond to a security incident;
  • verify a business or delivery issue;
  • address misuse of the website;
  • protect customers; or
  • protect our legal rights.
08

Why we use personal information

We use personal information for the purposes described below.

Where the EU GDPR or UK GDPR applies, the table also identifies the lawful basis we normally rely upon.

PurposeInformation normally usedLawful basis where applicable
Creating and managing accountsIdentity, contact, authentication and account informationContractual necessity or steps requested before entering into a contract
Authenticating usersAccount, login and security informationContractual necessity and legitimate interests
Processing password resetsEmail, account and authentication informationContractual necessity and legitimate interests
Operating product dropsAccount, participation, eligibility and order informationContractual necessity and legitimate interests
Enforcing product limitsAccount, order, transaction and technical informationContractual necessity and legitimate interests
Operating participation featuresDisplay name, points, activities and rankingProviding the requested service and legitimate interests
Processing ordersIdentity, contact, order, billing and delivery informationContractual necessity
Processing payments and refundsBilling, transaction and payment-status informationContractual necessity and legal obligations
Producing and fulfilling productsProduct, order, identity and delivery informationContractual necessity
Delivering ordersIdentity, delivery, contact and tracking informationContractual necessity
Providing customer supportContact, account, order and communication informationContractual necessity and legitimate interests
Sending account and order communicationsContact, account and order informationContractual necessity
Preventing fraud and abuseAccount, transaction, device, network and security informationLegitimate interests and legal obligations
Protecting accounts and systemsAuthentication, device, network and security informationLegitimate interests and legal obligations
Investigating security incidentsAccount, technical, communication and security informationLegititimate interests, legal obligations and legal claims
Maintaining financial and tax recordsOrder, billing, transaction and refund informationLegal obligations
Handling disputes and chargebacksAccount, order, transaction and communication informationLegitimate interests and legal claims
Responding to lawful requestsInformation reasonably required by the requestLegal obligations and legitimate interests
Sending marketing communicationsContact and marketing-preference informationConsent or another permission expressly allowed by law
Operating optional analyticsCookie, device and usage informationConsent where required by law
Remembering optional preferencesCookie and preference informationConsent where required by law
Improving website usabilityFeedback and limited usage informationLegitimate interests or consent, depending on the technology
Managing privacy requestsIdentity, contact and verification informationLegal obligations
Maintaining consent recordsContact, cookie and consent informationLegal obligations and legitimate interests
Enforcing terms and protecting legal rightsAccount, order, transaction and communication informationLegitimate interests and legal claims

Our legitimate interests may include:

  • providing a secure and reliable service;
  • administering limited product drops;
  • preventing fraud and misuse;
  • providing effective customer support;
  • improving website performance;
  • keeping appropriate records;
  • protecting customers;
  • protecting our systems; and
  • establishing, exercising or defending legal rights.

Before relying on legitimate interests, we consider whether the processing is necessary and whether our interests are overridden by your rights and interests.

09

Information required to provide services

Some information is necessary to provide the service you request.

For example:

  • an email address may be required to create and secure an account;
  • delivery information is required to send a physical product;
  • billing and payment information is required to process a purchase;
  • order details may be required to provide support;
  • verification information may be required before personal information is released; and
  • technical information may be required to maintain website and account security.

If required information is not provided, we may be unable to:

  • create an account;
  • authenticate you;
  • process an order;
  • accept a payment;
  • fulfil or deliver an order;
  • investigate an account issue; or
  • complete a privacy request.

Marketing consent and acceptance of non-essential cookies are optional.

10

Accounts and authentication

You are responsible for keeping your account credentials confidential and using a strong, unique password.

We may:

  • record security-related login activity;
  • limit repeated login attempts;
  • require additional verification;
  • require a password reset;
  • end active sessions;
  • temporarily restrict account access;
  • suspend an account where misuse is suspected; or
  • take other reasonable steps to protect accounts and customers.

If you believe your account has been accessed without permission:

  1. change your password immediately where possible;
  2. change the password on any other service where you reused it; and
  3. contact edhqsecurity@exclusivedrops.com.
11

Orders, payments and refunds

11.1 Order processing

We use order information to:

  • confirm a purchase;
  • enforce product limits;
  • process payment;
  • arrange product production;
  • fulfil the order;
  • arrange delivery;
  • provide tracking;
  • process returns, refunds or replacements;
  • prevent fraud;
  • comply with legal and accounting obligations; and
  • resolve disputes.

11.2 Payment processing

Payments are processed by authorised ecommerce, payment and financial-service providers.

The relevant payment service may be identified during checkout.

Murano Animals does not ordinarily store complete payment-card information. Payment providers are responsible for applying their own payment-security, fraud-prevention, regulatory and privacy controls.

11.3 Fraud prevention

Payment and ecommerce providers may process:

  • billing information;
  • transaction information;
  • IP addresses;
  • device information;
  • payment history;
  • account information; and
  • risk indicators

to identify suspected fraud, account misuse or unauthorised transactions.

An order may be delayed, reviewed, restricted or cancelled where fraud or misuse is reasonably suspected.

11.4 Refunds, disputes and chargebacks

Where a refund, dispute or chargeback occurs, relevant information may be shared with:

  • ecommerce providers;
  • payment processors;
  • financial institutions;
  • insurers;
  • professional advisers; and
  • dispute-resolution organisations.

Only information reasonably necessary to investigate and resolve the matter will be disclosed.

12

Product production, fulfilment and delivery

We use contracted production, fulfilment, logistics and delivery providers to complete physical orders.

Information shared for these purposes may include:

  • customer name;
  • delivery address;
  • email address where operationally required;
  • telephone number where required by a carrier;
  • product ordered;
  • product variation;
  • quantity;
  • order reference;
  • shipping method; and
  • delivery instructions.

The relevant provider may use production facilities, fulfilment centres, subprocessors, postal services or delivery carriers to complete the order.

Delivery information may also be disclosed to:

  • postal operators;
  • couriers;
  • freight providers;
  • logistics companies;
  • customs brokers;
  • customs authorities;
  • border authorities; and
  • tax authorities.

For international orders, legally required information may appear on shipping, tax or customs documents.

We cannot prevent information from being disclosed to delivery or government authorities where that disclosure is required to complete the delivery or comply with law.

13

Email and other communications

13.1 Essential communications

We may send messages necessary to provide or secure a service, including:

  • account verification;
  • password resets;
  • login and security notices;
  • product-drop administration;
  • order confirmations;
  • payment notifications;
  • refund notifications;
  • production updates;
  • shipping and tracking updates;
  • delivery issues;
  • account changes;
  • privacy-request communications;
  • security notices; and
  • customer-support responses.

These messages are not marketing communications.

You generally cannot opt out of an essential message while continuing to use the related service.

13.2 Marketing communications

We may send marketing communications where:

  • you have provided valid consent;
  • the communication is otherwise legally permitted; or
  • applicable law permits the communication within an existing customer relationship.

Marketing communications may include:

  • product-drop announcements;
  • advance release information;
  • product availability;
  • newsletters;
  • promotional offers;
  • community announcements; and
  • related Murano Animals news.

Where consent is relied upon:

  • participation will be optional;
  • consent will not be assumed from silence;
  • marketing choices will not be preselected;
  • consent will be separated from general terms where required;
  • consent records will be maintained; and
  • withdrawal will be made reasonably easy.

13.3 Unsubscribing

Marketing emails will provide an unsubscribe method.

You may also withdraw marketing consent by contacting:

edhqprivacy@exclusivedrops.com

Unsubscribing from marketing does not stop essential account, order, delivery, privacy or security messages.

13.4 Suppression records

After you unsubscribe, we may retain limited information on a suppression list, including:

  • your email address;
  • unsubscribe status;
  • date of withdrawal; and
  • source of the request.

This is necessary to ensure that your choice continues to be respected.

14

Leaderboards and public features

Some website features may display limited participation information publicly or to other registered users.

Depending on the feature, this may include:

  • display name;
  • points;
  • ranking;
  • achievement;
  • participation status; or
  • limited qualifying activity.

We will not intentionally display through these features:

  • your email address;
  • telephone number;
  • billing address;
  • delivery address;
  • payment information;
  • password; or
  • private customer-support correspondence.

You should choose a display name that does not reveal unnecessary personal information.

Where a feature is optional, information about participation and visibility will be provided through the relevant interface.

15

Cookies and similar technologies

15.1 What these technologies are

Cookies and similar technologies store information on your browser or device or access information already stored there.

They may include:

  • session cookies;
  • persistent cookies;
  • browser local storage;
  • pixels;
  • tags;
  • scripts;
  • embedded technologies; and
  • similar identifiers.

15.2 Strictly necessary technologies

Strictly necessary technologies may be used to:

  • make the website available;
  • maintain website security;
  • authenticate accounts;
  • maintain sessions;
  • remember shopping-cart contents;
  • complete checkout;
  • process payments;
  • detect fraud;
  • enforce security controls;
  • remember privacy choices; and
  • provide a feature specifically requested by you.

These technologies may operate without optional consent where legally permitted because the requested service cannot reasonably function without them.

Blocking these technologies through your browser may prevent the website, account or checkout from working correctly.

15.3 Preference technologies

Preference technologies may remember optional settings such as:

  • interface choices;
  • language;
  • display preferences; and
  • other customisations.

Where legally required, these technologies will not operate until you consent.

15.4 Analytics technologies

Analytics technologies may help us understand:

  • website traffic;
  • feature use;
  • navigation patterns;
  • website performance;
  • technical errors; and
  • general engagement.

Where consent is legally required, optional analytics technologies will remain blocked until consent has been provided.

Where reasonably possible, analytics information will be minimised, aggregated or de-identified.

15.5 Marketing technologies

Marketing technologies may be used to:

  • measure campaign performance;
  • determine whether a promotion resulted in a visit or purchase;
  • manage advertising frequency; or
  • provide relevant advertising.

Where legally required, marketing technologies will remain blocked until you positively consent to the relevant category.

15.6 Cookie controls

Where cookie consent is required, the website will provide options to:

  • accept optional cookies;
  • reject all optional cookies; or
  • manage individual cookie categories.

The option to reject optional cookies will be presented clearly and will not be deliberately hidden or made materially more difficult than accepting them.

Optional consent will not be inferred because you:

  • continued browsing;
  • scrolled;
  • closed the banner;
  • ignored the banner; or
  • failed to make a selection.

15.7 Changing your choices

You may change or withdraw optional cookie choices through the Cookie Settings or equivalent privacy control provided on the website.

Withdrawal does not affect processing that lawfully occurred before consent was withdrawn.

You may also manage cookies through your browser, although browser settings may not control every type of local storage or similar technology.

15.8 Consent records

We may record:

  • the choice made;
  • categories accepted or rejected;
  • date and time;
  • consent-notice version;
  • consent identifier;
  • broad device or browser information; and
  • subsequent changes.

These records are used to apply your choices and demonstrate compliance.

15.9 Detailed cookie information

The technologies used may change as our website, legal requirements and service arrangements change.

More detailed information may be provided through:

  • the website’s cookie-preference manager;
  • a separate Cookie Notice;
  • a cookie list; or
  • an on-screen notice presented before consent.
16

When we disclose personal information

We disclose personal information only where reasonably necessary for the purposes described in this Privacy Policy, where you instruct us to do so, or where disclosure is authorised or required by law.

We describe recipients by category rather than publishing a complete list of commercial suppliers and technical providers.

Recipient categories may include:

16.1 Website and infrastructure providers

Providers supporting:

  • website hosting;
  • server infrastructure;
  • network availability;
  • content delivery;
  • database hosting;
  • data storage;
  • backups;
  • logging;
  • monitoring; and
  • technical security.

16.2 Authentication and account-service providers

Providers supporting:

  • account registration;
  • authentication;
  • password resets;
  • session management;
  • identity verification; and
  • account security.

16.3 Ecommerce and payment providers

Providers supporting:

  • storefront functions;
  • shopping carts;
  • checkout;
  • payment processing;
  • refunds;
  • order administration;
  • taxation;
  • fraud prevention; and
  • payment disputes.

The relevant payment provider may be identified at checkout.

16.4 Production and fulfilment providers

Providers supporting:

  • product production;
  • printing or manufacturing;
  • order fulfilment;
  • packaging;
  • dispatch;
  • tracking; and
  • fulfilment-related support.

16.5 Delivery and logistics providers

Recipients may include:

  • postal services;
  • couriers;
  • freight providers;
  • customs brokers;
  • delivery networks;
  • logistics companies; and
  • parcel-tracking services.

16.6 Communications providers

Providers supporting:

  • transactional email;
  • account-verification messages;
  • password-reset messages;
  • order notifications;
  • security communications;
  • customer-support email; and
  • authorised marketing communications.

16.7 Security and fraud-prevention providers

Providers supporting:

  • network security;
  • account protection;
  • abuse prevention;
  • fraud detection;
  • incident investigation;
  • vulnerability management; and
  • service monitoring.

16.8 Professional advisers

Information may be disclosed to:

  • lawyers;
  • accountants;
  • auditors;
  • insurers;
  • cybersecurity specialists;
  • tax advisers; and
  • other professional advisers

where reasonably necessary and subject to professional or contractual duties.

16.9 Government and legal recipients

Information may be disclosed to:

  • courts;
  • regulators;
  • tax authorities;
  • customs authorities;
  • border authorities;
  • law-enforcement agencies; and
  • other legally authorised bodies

where required or permitted by law.

We may also disclose information where reasonably necessary to:

  • respond to valid legal process;
  • investigate suspected fraud;
  • protect a person from serious harm;
  • investigate a security incident;
  • enforce an agreement; or
  • establish, exercise or defend legal rights.

16.10 Business transfers

If all or part of Murano Animals is sold, reorganised, financed, merged, transferred or wound down, personal information may be disclosed to:

  • prospective purchasers;
  • actual purchasers;
  • financiers;
  • professional advisers; and
  • successor organisations.

Any recipient must handle personal information consistently with applicable privacy law.

17

Information about particular providers

We do not publish a complete list of suppliers, subprocessors, infrastructure providers or commercial partners in this Privacy Policy.

This is because:

  • service arrangements may change;
  • not every provider handles personal information;
  • publishing detailed infrastructure relationships may create commercial or security risks; and
  • applicable privacy laws generally permit recipients to be described by category.

Where legally required or reasonably necessary, information about a particular recipient may be:

  • displayed at the point where you interact with that provider;
  • shown during checkout;
  • included in a cookie-preference tool;
  • included in a transaction or delivery notice;
  • provided in response to a valid privacy request; or
  • provided to a regulator or supervisory authority.

A request for information about recipients may be sent to:

edhqprivacy@exclusivedrops.com

We may withhold confidential commercial or security information where the law permits, while still providing the information required for you to understand how your personal information is handled.

18

Service-provider protections

Where another organisation processes personal information on our behalf, we seek to maintain appropriate contractual and organisational protections.

Depending on the service and applicable law, these may include:

  • data-processing terms;
  • confidentiality obligations;
  • limitations on permitted processing;
  • security requirements;
  • breach-notification obligations;
  • subprocessor controls;
  • assistance with privacy requests;
  • deletion or return requirements;
  • assurance or audit provisions; and
  • international-transfer safeguards.

Service providers acting on our instructions are not authorised by Murano Animals to use customer information for unrelated marketing.

A third party may independently process limited information where it acts as a separate controller and applicable law permits that processing.

19

Selling or sharing personal information

Murano Animals does not sell personal information in exchange for money.

We do not authorise processors acting on our behalf to sell customer information or use it for unrelated advertising.

Some privacy laws define “sale” or “sharing” more broadly and may include certain advertising, analytics or cross-context tracking arrangements.

Where an activity is legally classified as a sale, sharing or targeted-advertising activity, we will provide any consent, opt-out or browser-signal controls required by applicable law.

20

International transfers

Murano Animals is based in Australia and uses service providers and commercial arrangements that may operate internationally.

Personal information may be:

  • stored outside your country;
  • accessed by authorised personnel outside your country;
  • transferred through international technical infrastructure;
  • sent to a production or fulfilment location in another country;
  • processed through international payment networks; or
  • disclosed to a carrier or customs authority in connection with an international delivery.

Depending on the service and transaction, personal information may be processed in:

  • Australia;
  • the United States;
  • the United Kingdom;
  • Switzerland;
  • countries in the European Economic Area;
  • countries where hosting or technical infrastructure is located;
  • countries where production or fulfilment facilities operate;
  • countries where authorised subprocessors operate; and
  • the destination country of an international order.

The exact country may depend on the product, customer location, payment method, delivery destination and service architecture.

Privacy protections may differ between countries.

Where required by applicable law, international transfers are supported by measures such as:

  • adequacy decisions;
  • approved standard contractual clauses;
  • approved United Kingdom transfer arrangements;
  • binding corporate rules;
  • recognised privacy frameworks;
  • processor contractual obligations;
  • transfer-risk assessments;
  • encryption;
  • access controls; and
  • other legally approved safeguards.

For Australian personal information, we take reasonable steps where required to ensure overseas recipients handle information consistently with applicable Australian privacy requirements.

You may contact edhqprivacy@exclusivedrops.com for further information about safeguards relevant to your personal information.

21

Retention of personal information

We keep personal information only for as long as reasonably necessary for:

  • the purpose for which it was collected;
  • another legally permitted purpose;
  • fulfilling an order;
  • tax and accounting requirements;
  • fraud prevention;
  • dispute resolution;
  • security investigations;
  • legal claims;
  • regulatory requirements; or
  • enforcing your privacy choices.

Our general retention schedule is:

InformationGeneral retention period
Active account informationWhile the account remains active
Closed or inactive account informationUsually up to 24 months after closure or last meaningful activity
Order, transaction, tax and accounting recordsFor the period required by applicable tax, accounting and business-record laws
Fulfilment and shipping recordsUsually retained with the associated order record
Customer-support recordsUsually up to 24 months after the matter is resolved
Refund, complaint, chargeback and dispute recordsUntil resolution and for the applicable legal limitation period
Marketing subscription informationUntil consent is withdrawn or the information is no longer required
Marketing suppression recordsFor as long as reasonably necessary to continue respecting the opt-out
Cookie-consent recordsUsually up to three years after the relevant consent or preference event
Routine security and access logsUsually up to 12 months
Confirmed security-incident recordsFor as long as required to investigate, remedy and meet legal obligations
Incomplete registrationsUsually up to 90 days
Abandoned transaction informationUsually up to 90 days unless needed for fraud prevention or legal purposes
Privacy-request recordsUsually up to three years after the request is completed
Information subject to a legal holdUntil the hold, investigation, claim or proceeding ends

These periods are general guidelines. A shorter or longer period may apply depending on:

  • the nature of the information;
  • legal requirements;
  • an active dispute;
  • fraud risk;
  • security requirements;
  • an unresolved order; or
  • a valid deletion request.

When information is no longer required, we will take reasonable steps to:

  • delete it;
  • securely destroy it; or
  • de-identify it.

Deleted information may remain temporarily in protected backups until it is overwritten or removed under the relevant backup cycle.

Backup information is not intended to be restored to active use except where necessary for disaster recovery, system integrity or legal compliance.

We may retain aggregated or anonymised information where it can no longer reasonably identify an individual.

22

Information security

We use technical and organisational safeguards intended to protect personal information against:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised disclosure;
  • alteration; and
  • destruction.

Our safeguards may include:

  • encrypted transmission;
  • secure password handling;
  • multifactor authentication for privileged access;
  • role-based access controls;
  • least-privilege access;
  • database access restrictions;
  • secure hosting;
  • network protections;
  • logging and monitoring;
  • software updates;
  • vulnerability remediation;
  • protected backups;
  • data minimisation;
  • service-provider due diligence;
  • confidentiality requirements;
  • incident-response procedures; and
  • access reviews.

Access to customer information is limited to authorised persons who require it for a legitimate operational purpose.

We do not publicly disclose detailed infrastructure diagrams, credentials, internal security configurations, vulnerability information or other information that could weaken our security.

No website, internet transmission or electronic-storage system can be guaranteed to be completely secure.

You should:

  • use a strong and unique password;
  • protect access to your email account;
  • log out of shared devices;
  • avoid sending sensitive information through unsecured channels; and
  • report suspicious activity promptly.
23

Personal-data breaches

Murano Animals maintains a documented data-breach response and escalation process.

Where a suspected breach occurs, we will take reasonable steps to:

  1. identify and contain the incident;
  2. protect affected systems and accounts;
  3. investigate what occurred;
  4. determine what information was involved;
  5. identify affected individuals where possible;
  6. assess the likelihood and seriousness of harm;
  7. preserve relevant evidence;
  8. involve relevant service providers;
  9. notify regulators where required;
  10. notify affected individuals where required;
  11. remedy identified weaknesses; and
  12. document the incident and response.

23.1 Australian notification

Where the Australian Notifiable Data Breaches scheme applies, we will notify the Office of the Australian Information Commissioner and affected individuals where an eligible data breach is likely to result in serious harm and no applicable exception applies.

23.2 European and United Kingdom notification

Where the EU GDPR or UK GDPR applies, we will notify the appropriate supervisory authority without undue delay and, where required, within 72 hours after becoming aware of a reportable personal-data breach.

Where a breach is likely to result in a high risk to affected individuals, we will notify those individuals without undue delay unless a legal exception applies.

23.3 Breach notifications

Where legally required and reasonably available, a notification may explain:

  • the nature of the incident;
  • categories of information involved;
  • possible consequences;
  • actions we have taken;
  • steps you should consider;
  • how to contact us; and
  • where to obtain further assistance.

To report a suspected security incident, contact:

edhqsecurity@exclusivedrops.com

24

Your privacy rights

The rights available to you depend on your location, the law that applies and the circumstances of the processing.

Subject to applicable exceptions, you may have the following rights.

24.1 Access

You may request:

  • confirmation that we process personal information about you;
  • access to that information; and
  • information about how it is processed.

24.2 Correction

You may request correction of information that is:

  • inaccurate;
  • incomplete;
  • out of date; or
  • misleading.

Some account information may be corrected through your account settings.

24.3 Deletion

You may request deletion of personal information.

Deletion is not an absolute right. We may retain information where reasonably necessary to:

  • complete an order;
  • comply with tax or accounting obligations;
  • prevent fraud;
  • maintain a marketing suppression record;
  • resolve a dispute;
  • protect account or system security;
  • investigate an incident;
  • establish, exercise or defend a legal claim;
  • respond to a regulator; or
  • comply with another legal obligation.

24.4 Restriction

Where applicable, you may request that processing be restricted while:

  • accuracy is reviewed;
  • an objection is considered;
  • the lawfulness of processing is reviewed; or
  • information is required for a legal claim.

24.5 Data portability

Where applicable, you may request information you provided to us in a structured, commonly used and machine-readable format.

Where legally required and technically feasible, you may also request transmission to another controller.

24.6 Objection

Where we rely on legitimate interests, you may object to processing based on your particular circumstances.

We will consider the objection and stop the processing unless:

  • compelling legitimate grounds override your interests and rights; or
  • processing is required for a legal claim.

You may object to direct marketing at any time.

24.7 Withdrawal of consent

Where processing relies on consent, you may withdraw consent at any time.

Withdrawal does not affect processing that lawfully occurred before consent was withdrawn.

24.8 Automated decision-making

You may have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.

Murano Animals does not currently use solely automated processing to make decisions that produce legal or similarly significant effects about customers.

Automated systems may assist with:

  • account security;
  • fraud-risk indicators;
  • product limits;
  • stock availability;
  • product-drop administration;
  • account verification; and
  • leaderboard calculations.

These operational functions do not ordinarily produce a legal or similarly significant effect by themselves.

24.9 Privacy complaints

You may complain about how we handle personal information.

Send complaints to:

edhqprivacy@exclusivedrops.com

Include:

  • your name;
  • contact information;
  • a description of the concern;
  • any relevant order or account reference;
  • relevant dates; and
  • the outcome you are seeking.

We aim to acknowledge a privacy complaint within seven business days and provide a substantive response within 30 days.

Complex matters may require additional time. Where reasonably possible, we will explain any delay.

25

Exercising your rights

Send a privacy request to:

edhqprivacy@exclusivedrops.com

Use the subject line:

Privacy Request

Please identify:

  • the right you wish to exercise;
  • the relevant account or email address;
  • any relevant order number; and
  • enough information for us to locate the relevant records.

25.1 Identity verification

Before releasing, correcting or deleting information, we may take reasonable steps to verify your identity.

Verification may include:

  • confirming access to the registered email address;
  • confirming an order reference;
  • confirming limited account details; or
  • requesting another proportionate form of identification.

Do not send identity documents unless we specifically request them.

We will not request more verification information than is reasonably necessary.

25.2 Authorised representatives

An authorised representative may submit a request where permitted by law.

We may request:

  • evidence of the representative’s authority;
  • confirmation directly from the individual; and
  • identity verification.

25.3 Response times

Where the EU GDPR or UK GDPR applies, we will generally respond within one month, subject to any legally permitted extension.

Under other laws, we will respond within the legally required period or within a reasonable time.

25.4 Fees and excessive requests

Privacy requests are normally handled without charge.

Where legally permitted, we may charge a reasonable fee or refuse to act where a request is:

  • manifestly unfounded;
  • excessive;
  • repetitive; or
  • intended to interfere unreasonably with our operations.

We will explain a refusal where legally required.

25.5 No unlawful discrimination

We will not unlawfully discriminate against you because you exercised a privacy right.

26

Australian privacy rights

Where the Australian Privacy Act applies, you may:

  • request access to personal information we hold about you;
  • request correction of inaccurate, incomplete, out-of-date or misleading information;
  • complain about a suspected breach of applicable Australian privacy requirements; and
  • ask how your complaint will be investigated.

If you are dissatisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.

27

European Economic Area and United Kingdom rights

Where the EU GDPR or UK GDPR applies, you may have rights to:

  • receive privacy information;
  • access personal data;
  • correct personal data;
  • request erasure;
  • restrict processing;
  • receive portable data;
  • object to legitimate-interest processing;
  • object to direct marketing;
  • withdraw consent;
  • challenge qualifying automated decisions; and
  • complain to a supervisory authority.

You may lodge a complaint with a supervisory authority in:

  • the country where you live;
  • the country where you work; or
  • the country where you believe an infringement occurred.

Individuals in the United Kingdom may complain to the UK Information Commissioner’s Office.

27.1 EEA and UK representatives

Murano Animals is established in Australia.

At the effective date of this Privacy Policy, Murano Animals has not appointed a formal representative in the European Economic Area or United Kingdom because its relevant processing is presently assessed as limited and occasional.

This assessment will be reviewed as:

  • the European or UK customer base changes;
  • marketing activities change;
  • transaction frequency increases;
  • monitoring practices change; or
  • legal requirements change.

If appointment of a representative becomes legally required, the representative’s contact information will be added to this Privacy Policy.

28

Rights in other jurisdictions

Privacy rights vary between countries and states.

Where another applicable law provides additional rights, including rights to opt out of certain targeted advertising, sale, sharing or profiling, we will process valid requests and provide controls as required by that law.

Requests may be sent to:

edhqprivacy@exclusivedrops.com

29

Children’s privacy

The website and product-drop services are not directed to children under 16.

We do not knowingly create accounts for or collect personal information directly from children under 16 without appropriate parental or guardian involvement where required by law.

A parent or guardian should supervise purchases by a person who has not reached the age at which they may independently enter into a binding purchase contract.

If you believe a child has provided information without appropriate permission, contact:

edhqprivacy@exclusivedrops.com

We will investigate and, where appropriate:

  • delete the information;
  • restrict the account;
  • request parental or guardian confirmation; or
  • take another action required by law.
30

Third-party websites and independent services

The website may contain links to:

  • payment services;
  • social-media platforms;
  • delivery services;
  • external websites; or
  • other independent services.

Murano Animals does not control the independent privacy practices of an external service.

You should review the relevant third party’s privacy information before providing personal information directly to it.

31

Changes to this Privacy Policy

We may update this Privacy Policy where:

  • the website changes;
  • a new feature is introduced;
  • service arrangements change;
  • processing activities change;
  • retention periods change;
  • legal requirements change;
  • security practices change; or
  • clarification is required.

The current version will be published on exclusivedropshq.com with its updated effective date or revision date.

Where a material change affects existing personal information, we will provide additional notice or request new consent where legally required.

Previous versions may be retained for legal, compliance and audit purposes.

32

Contact us

Privacy matters

Murano Animals ABN: 96 220 324 478 Morphett Vale, South Australia 5162 Australia

Email: edhqprivacy@exclusivedrops.com Website: exclusivedropshq.com Recommended subject line: Privacy Request

Security matters

Email: edhqsecurity@exclusivedrops.com Recommended subject line: Security Report

General support

Email: edhqsupport@exclusivedrops.com

verified_user

Questions about this policy can be sent to edhqsupport@exclusivedrops.com.