Skip to content

Privacy policy

Privacy Policy

Swapnil Nevgi Fine Art ABN: 41 341 712 425 Website: swapnilnevgi.com

Last updated: 20 July 2026 Effective: 20 July 2026


1. About this policy

I am Swapnil Nevgi, an artist and photographer based in Brisbane, Queensland, trading as Swapnil Nevgi Fine Art ("I", "me", "my"). I sell original paintings, limited edition prints, open edition wall art, photographic prints and greeting cards through swapnilnevgi.com (the "Site").

This policy explains what personal information I collect about you, why I collect it, who I share it with, where it goes, how long I keep it, and what you can do about it. It applies to the Site, to any order you place with me, to my email list, and to messages you send me.

I have written this policy to meet:

  • the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs);
  • the Spam Act 2003 (Cth) for marketing emails;
  • the EU General Data Protection Regulation (GDPR) and the UK GDPR, because I ship to and market in Europe and the UK;
  • the Notifiable Data Breaches (NDB) scheme.

For the purposes of the GDPR and UK GDPR, I am the data controller of your personal information.

A note on scope: As a small business, some parts of the Privacy Act may not currently be compulsory for me. I have chosen to comply anyway, because it is the right way to treat your information, and because privacy law in Australia is being tightened. Where I say "I must" or "I will", treat that as a commitment I am making to you.


2. Anonymity and dealing with me pseudonymously

You can browse the Site, read my blog and look at artwork without telling me who you are.

You can also contact me under a pseudonym or an alias email address if you just want to ask a question about an artwork, a size, or a commission.

I cannot deal with you anonymously if you want to place an order, because I need a real name and address to deliver the artwork, process the payment, issue a tax invoice, and honour returns.


3. What personal information I collect

3.1 Information you give me directly

What When
Name, email address, phone number, billing address, shipping address When you place an order or ask for a shipping quote
Account username and password (hashed — I never see your password) If you create an account on the Site
Order details: items, sizes, options, order notes, gift messages At checkout
Payment confirmation (not your full card number — see §7) At checkout
Content of your emails, contact form messages, and social media messages Whenever you contact me
Commission briefs, reference photos, room photos, dimensions If you commission a piece or ask for sizing advice
Product reviews, ratings, and any photos or videos you attach If you leave a review
Wishlist contents If you use the wishlist feature to save items
Email address and marketing preferences If you subscribe to my newsletter
Name, email, and any details you give me at markets, exhibitions or events If we meet in person and you sign up or buy

Some features won't work without this information. You can always choose not to give it, but you may not be able to check out, get a quote, or receive updates.

3.2 Information collected automatically

When you visit the Site, information is collected about your device and how you use the Site ("Usage Data"), including:

  • IP address and approximate location derived from it (usually your city or region, not your street)
  • device type, operating system, browser type and language
  • referring website or advertisement, and the search terms or campaign that brought you here
  • pages viewed, products viewed, time on page, scroll and click behaviour
  • items added to cart or wishlist, carts abandoned, and checkouts started but not completed
  • date and time of your visit and how you got here
  • cookie and device identifiers assigned by me or my providers

You can add items to a wishlist without creating an account or logging in. If you do, an identifier is stored on your device and linked to the products you saved, even though I don't know your name.

Important: Under Australian law, an IP address or device identifier is personal information if it can reasonably identify you. Under the GDPR, it generally is. I treat this data as personal information.

3.3 Information from third parties

  • Shopify, which hosts my store, and the apps I run on it
  • Payment providers (Shopify Payments and PayPal), which confirm to me that your payment succeeded and pass on the billing details needed for the order
  • Shipping carriers, which give me delivery status and, occasionally, delivery exception details
  • Advertising and analytics platforms (Meta, Google, Pinterest), which give me aggregated and, in some cases, individual-level data about how people found and interacted with my ads
  • Fraud screening services used by Shopify Payments, which score orders for risk

3.4 Sensitive information

I do not seek sensitive information (health, race, religion, political opinions, sexual orientation, criminal record, biometrics). Please don't send it to me. If you volunteer it — for example, in a commission brief about a memorial piece — I will only use it for the purpose you gave it to me for, and I will delete it once that purpose is met.


4. Why I collect and use your information

4.1 Purposes

  • Fulfilling your order — taking payment, printing or preparing the artwork, packing, arranging shipping, issuing a certificate of authenticity, and handling returns under my 14-day returns guarantee.
  • Talking to you — answering questions, giving quotes, discussing commissions, sending order and dispatch notifications.
  • Running my accounts — issuing tax invoices, meeting my GST and record-keeping obligations under Australian tax law.
  • Improving the Site and my range — understanding which artworks people look at, where visitors drop off, and which sizes sell.
  • Marketing — sending my newsletter, telling you about new releases and exhibitions, and showing you ads on Meta, Google and Pinterest.
  • Reviews — inviting you to review an artwork after it's delivered, and publishing reviews you choose to leave.
  • Security and fraud prevention — screening suspicious orders, preventing chargebacks, protecting my account and yours.
  • Legal — complying with the law, responding to lawful requests, and establishing or defending legal claims.

4.2 Legal bases (for visitors in the EEA and UK)

Purpose Legal basis
Processing and delivering your order, handling returns Contract (Art. 6(1)(b))
Responding to your enquiries Contract or legitimate interests (Art. 6(1)(b) / (f))
Tax records, invoices, legal obligations Legal obligation (Art. 6(1)(c))
Fraud prevention, site security Legitimate interests (Art. 6(1)(f)) — protecting my business and my customers
Essential cookies Legitimate interests (Art. 6(1)(f))
Analytics, advertising and marketing cookies Consent (Art. 6(1)(a))
Newsletters and marketing emails Consent (Art. 6(1)(a))
Abandoned cart and wishlist reminder emails Consent (Art. 6(1)(a))
Review invitations after delivery Consent, or legitimate interests where you are an existing customer and can opt out
Product reviews you choose to publish Consent (Art. 6(1)(a))

You can withdraw consent at any time. Withdrawing it doesn't undo processing that already happened.


5. Cookies and tracking

The Site uses cookies and similar technologies (pixels, tags, local storage, SDKs).

5.1 Categories

Strictly necessary — your cart, your login session, security and load balancing, checkout, and Google reCAPTCHA on forms. These can't be turned off; without them the Site won't work.

Functional — remembering your country, currency, language, wishlist contents and recently viewed items. Set by Shopify and by Wishlist Hero.

Analytics — Shopify's built-in analytics and Google Analytics 4, which tell me how people find and use the Site.

Advertising / targeting — the Meta (Facebook/Instagram) pixel, Google Ads tags and the Pinterest tag, which measure ad performance and let me show ads to people who have visited the Site or looked at particular artworks. My wishlist app may also pass wishlist events to these pixels.

5.2 What the advertising pixels share

I've set my Facebook and Instagram data sharing to Conservative, the least-sharing of the three options Shopify offers. The events shared with Meta, Google and Pinterest are broadly the same:

  • pages and products you view
  • search terms you enter on the Site
  • items you add to or remove from your cart
  • when you begin a checkout, and when you enter payment details (the fact that you did — not your card number, which never passes through my systems or theirs)
  • when you complete a purchase
  • platform identifiers, such as Meta's Click ID and Browser ID, which let a platform connect your visit to an ad you may have seen

I've also set every one of these pixels to Shopify's "Optimized" data access rather than "Always on", which means Shopify actively limits how much of your data is shared with them.

5.3 Browser tracking vs. server-side tracking — and what your cookie choice can actually stop

I want to be straight with you about this, because most privacy policies aren't.

Tracking reaches these platforms two ways. Browser-side tracking runs in your browser, so your cookie choice and your ad blocker can stop it. Server-side tracking is sent from Shopify's servers directly to the platform's servers — your browser isn't involved, which means rejecting cookies does not stop it.

Platform How it runs Does rejecting cookies stop it?
Meta (Facebook, Instagram) Browser only Yes
Google Browser and server Browser part yes; server part no
Pinterest Browser and server Browser part yes; server part no
Omnisend, Judge.me Browser only Yes

I keep Meta on browser-only deliberately, and I've disconnected the TikTok pixel entirely. Google and Pinterest are harder: Google carries my advertising and my product listings, and Pinterest's product catalogue can't be separated from its tracking — the platform doesn't offer that choice, so my options are all of it or none of it, and I've kept the catalogue.

If the server-side part concerns you, the platform-level opt-outs below are the effective route, because they act on the platform's side rather than yours.

5.4 Your choices

  • Cookie banner — you can accept or reject non-essential cookies on your first visit, and change your choice at any time via the cookie settings link in the footer. Rejecting stops everything described as browser-side above.
  • Global Privacy Control (GPC) — if your browser sends a GPC signal, I treat it as an opt-out of the "sale" or "sharing" of your information for that browser and device.
  • Browser controls — most browsers let you block or delete cookies. Blocking them may break parts of the Site.
  • Platform opt-outs — these are the ones that reach the server-side tracking too: Meta ad preferences (facebook.com/adpreferences), Google ad settings (adssettings.google.com), Google Analytics opt-out (tools.google.com/dlpage/gaoptout), Pinterest personalisation settings, and Your Online Choices (youronlinechoices.com.au).
  • Just ask me — email me and I'll suppress what I can from my side.

5.5 reCAPTCHA

Forms on the Site are protected by Google reCAPTCHA to stop spam and abuse. Google's Privacy Policy and Terms of Service apply to this. reCAPTCHA collects hardware and software information and behavioural data for the purpose of providing and improving its security service.


6. Direct marketing

I send marketing emails through Omnisend, and only to people who have opted in, or who have bought from me and would reasonably expect to hear about new releases. When you subscribe to my newsletter, I use double opt-in — you confirm your subscription by clicking a link in a confirmation email — so no one is added to my marketing list without actively confirming they want to be.

Every marketing email includes an unsubscribe link that works, is honoured within five working days as required by the Spam Act, and identifies me and how to contact me. You can also just reply and ask me to take you off the list.

Cart and checkout reminders. If you add items to your cart or begin a checkout and don't finish, I may send you a reminder email. I only do this for customers outside the EU and UK, because those reminders count as marketing under European law and I don't send marketing to people in those regions who haven't opted in. If you're in Australia or another country where this is permitted, you can opt out of these at any time using the unsubscribe link.

I will still send you transactional messages — order confirmations, dispatch notices, delivery problems, and replies to your questions — because those are part of our contract. You can't opt out of those while you have an open order.

I do not sell your email address or your postal address to anyone.


7. Payments

I never see, store or handle your full card number, expiry date or CVV. Payments go directly to:

  • Shopify Payments (powered by Stripe), and
  • PayPal Australia Pty Ltd,

both of which are PCI-DSS compliant. They give me a confirmation that the payment succeeded, the billing name and address, the last four digits of the card, and the card brand.

Shop Pay, Apple Pay, Google Pay, Bancontact, iDEAL and Union Pay are handled by those providers under their own privacy policies.


8. Who I disclose your information to

I disclose personal information to the following recipients. Each of them handles it under a contract with me and may only use it to provide their service.

Recipient What they get Why
Shopify Inc. (store platform, hosting, checkout, analytics) Everything you submit through the Site Running the store
Shopify Payments / Stripe, PayPal Australia Payment and billing details Taking payment, fraud screening
Australia Post and courier partners Name, delivery address, phone, email Delivering your artwork
My fine art print supplier in Brisbane Order details, and — where I arrange for a print to be sent to you direct — your name, delivery address and contact details Printing large-format work, and dispatching it to you
Omnisend (Omnisend UAB and its group companies) Name, email address, purchase history, browsing and cart events, email engagement Sending my newsletter, and cart or checkout reminders where I'm permitted to
Judge.me Ltd Name, email address, order details, and the content of any review, photo or video you submit Inviting reviews and publishing them. Judge.me acts as my sub-processor for review functionality.
Wishlist Hero — operated by Revamp Consulting (United States) The products you save to a wishlist, and a device identifier so your wishlist persists Running the "save to wishlist" feature. It stores your saved items; it does not currently send you any emails.
Meta Platforms (Facebook, Instagram) The browsing, cart, checkout and purchase events listed in §5.2, plus Meta's Click ID and Browser ID Advertising and measurement
Google (Ads, Analytics, Merchant Centre, YouTube) The same events, sent both from your browser and directly from Shopify's servers Advertising, measurement, and listing my artwork in Google's shopping results
Pinterest My product catalogue, and the same events, sent both from your browser and directly from Shopify's servers Listing my artwork on Pinterest, and measurement
Consentmo / iSenseLabs (Sofia, Bulgaria) Your cookie consent choices and the identifier they're stored against Recording and honouring your cookie preferences
My accountant and bookkeeper Invoices and order records Tax and BAS
App developers and support staff, when fixing a fault Only what's necessary to diagnose the fault, which may include your order or review record Keeping the Site working (see §10)
Professional advisers, insurers Only what's necessary Advice, claims
Government agencies, courts, law enforcement As legally required Legal obligations
A purchaser of my business Customer records Only if I ever sell or transfer the business, and I'll tell you first

I do not disclose your information to data brokers, and I do not trade in personal information.

Reviews stay on my site. I've turned off Judge.me's syndication features, so the reviews you leave appear on my website only. They are not pushed out to Google Shopping, the Shop app, or my social media accounts. Your star ratings may appear in ordinary Google search results for my product pages, because I use structured data ("rich snippets") — but that shows the rating and review count, not your name or review text.

On "selling" and "sharing": Shopify's default policy text states that personal information has been "sold" or "shared" for advertising in the past 12 months. Under Californian and similar laws, running the Meta, Google and Pinterest advertising pixels can meet that definition even though no money changes hands and I don't sell customer lists. To be plain about it: I do not sell your data. I do run advertising pixels, and if you opt out of advertising cookies or send a GPC signal, that stops.


9. Overseas disclosure

Most of the services I use are based overseas. Before I disclose your information to an overseas recipient, I take reasonable steps to ensure they handle it consistently with the APPs, as required by APP 8.

Your personal information is likely to be disclosed to recipients located in:

Country / region Who
Canada and the United States Shopify, Stripe, Google, Meta, Pinterest — note that Google's and Pinterest's server-side feeds send from Shopify's servers directly, not via your browser
Lithuania and the EEA Omnisend, which processes email marketing data primarily within the EEA
United Kingdom Judge.me Ltd
United States Judge.me's hosting (AWS/Heroku); Judge.me's professional advisers
Ireland and other EU member states Shopify's and Meta's European infrastructure
Singapore Shopify regional infrastructure
Bulgaria iSenseLabs, which operates the Consentmo consent banner
United States (and possibly Egypt) Revamp Consulting, which operates the Wishlist Hero wishlist feature — the company is US-based with engineering operations in Egypt
The country you're having your artwork delivered to, if outside Australia Carriers and customs authorities

For transfers of EEA or UK personal information out of Europe, I rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or on an adequacy decision where one applies. You can ask me for a copy of the safeguards in place.


10. Security

I take reasonable steps to protect your information:

  • The Site runs entirely over HTTPS/TLS.
  • Payments are handled by PCI-DSS compliant processors; card data never touches my systems.
  • My Shopify admin account and email have multi-factor authentication enabled.
  • I am the only person with standing access to my Shopify admin. I have no staff.
  • From time to time I grant an app developer temporary access so they can fix a fault. I limit that access to what the job needs, and revoke it when the work is done. Support staff at the app companies I use (Shopify, Omnisend, Judge.me, Wishlist Hero) may also be able to see records within their own systems in the course of supporting me.
  • My accountant sees invoices and order records for tax purposes.
  • Devices and backups are encrypted and password-protected.
  • Apps are reviewed and removed when no longer used.

No system is perfect, and information you send me over email is not encrypted end-to-end. Please don't email me card numbers, ID documents or anything sensitive. If you need to send something confidential, ask me and I'll arrange a safer way.


11. How long I keep your information

Information Retention
Order and tax records (invoices, payments, addresses) 7 years from the end of the financial year, to meet ATO record-keeping requirements
Customer account details While your account is open, plus 12 months, unless you ask me to delete it sooner
Certificate of authenticity and provenance records for original paintings and limited editions Indefinitely — provenance is part of the artwork's value, and I keep a record of who owns each numbered edition. You can ask to be recorded pseudonymously or removed from the public-facing record.
Marketing list Until you unsubscribe, plus a suppression record so I don't re-add you
Enquiries and quotes that don't become orders 2 years
Commission reference photos and briefs 2 years after the commission completes, unless you ask me to delete them sooner
Reviews Until you ask me to remove them
Wishlist data 12 months after your last activity
Usage Data and analytics Per my providers' retention settings, typically 14–26 months
Abandoned cart data 12 months

When information is no longer needed, I delete it or de-identify it.


12. Data breaches

If a data breach happens that is likely to result in serious harm to you, I will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in line with the Notifiable Data Breaches scheme. For EEA and UK residents, I will notify the relevant supervisory authority within 72 hours where required.

I assess suspected breaches within 30 days.


13. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information I hold about you (APP 12; GDPR Art. 15)
  • Correct it if it's wrong or out of date (APP 13; GDPR Art. 16)
  • Delete it (GDPR Art. 17; and I'll honour deletion requests from Australian customers too, except where I'm legally required to keep records)
  • Port it — get a copy in a machine-readable format (GDPR Art. 20)
  • Object to processing based on legitimate interests, including direct marketing (GDPR Art. 21)
  • Restrict processing in certain circumstances (GDPR Art. 18)
  • Withdraw consent at any time
  • Opt out of "sale", "sharing" or targeted advertising
  • Not be discriminated against for exercising any of these rights

How to exercise them: email info@swapnilnevgi.com with what you want. I'll ask you to verify your identity — usually by replying from the email address on your order. I aim to respond within 30 days (Australia) or one month (GDPR/UK). Access is free; I'll only ever charge for access if a request is genuinely excessive, and I'll tell you the cost before I do anything.

If your request concerns a review, you can also contact Judge.me directly at support@judge.me.

If I refuse a request, I'll tell you why in writing and how to challenge it.

You can appoint an authorised agent to act for you. I'll ask for proof of the authorisation.


14. Automated decision-making

I do not make automated decisions that produce legal or similarly significant effects about you.

The one exception is that my payment processors run automated fraud scoring on orders. A high-risk score may cause an order to be flagged or cancelled. If your order is cancelled on that basis, you'll be refunded in full, and you can email me and I'll look at it personally.


15. Children

The Site is not intended for children and I don't knowingly collect personal information from anyone under 16. If you're a parent or guardian and believe your child has given me their information, email me and I'll delete it.


16. Reviews and user-generated content

If you post a review, it's public on my website. Your display name, your review text and any photo or video you attach will be visible to anyone who visits the page. I don't syndicate reviews to other platforms (see §8), so they stay on my site — but anything on a public web page can be seen, copied or indexed by search engines, so don't include anything in a review you wouldn't want on the open internet. You can ask me — or Judge.me — to remove your review at any time.


17. Third-party links and social media

The Site links to my Facebook, Instagram, LinkedIn, Pinterest and YouTube profiles, and to other sites. Those platforms have their own privacy policies and their own tracking. Interacting with me on those platforms means your information is handled under their rules, not mine. I have no control over what they do with it.


18. Complaints

If you're unhappy with how I've handled your personal information, email me at info@swapnilnevgi.com with "Privacy complaint" in the subject line. I'll acknowledge it within 5 business days and give you a substantive response within 30 days.

If you're not satisfied with my response:


19. Changes to this policy

I may update this policy if my practices, the apps I use, or the law changes. The current version is always at swapnilnevgi.com/policies/privacy-policy, and the "Last updated" date at the top tells you when it changed. If a change materially affects how I use your information, I'll tell you by email or a notice on the Site before it takes effect.


20. Contact

Swapnil Nevgi Fine Art ABN 41 341 712 425 Brisbane, Queensland, Australia

Email: info@swapnilnevgi.com

Email is the best and fastest way to reach me about anything in this policy, and I read every message myself. If you need to send me something by post, email me first and I'll give you a postal address.

Privacy contact: Swapnil Nevgi.

For the purposes of applicable data protection law, and unless stated otherwise, I am the data controller of your personal information.

Search

Back to top

Shopping Cart

Your cart is currently empty

Shop now