Skip to content

Legal

Privacy Policy

How lilMONSTER collects, uses, and protects your personal information.

Effective: 22 July 2026

1. Who We Are

lilMONSTER is an Australian registered business name operated by a sole trader, ABN 59 870 881 596. We provide cybersecurity, AI consulting, product engineering, digital products, and support for lilKiTTY and the paid Horcycles mobile app.

Where the Privacy Act 1988 (Cth) and Australian Privacy Principles apply to us, we comply with them. We use the Australian Privacy Principles as our privacy baseline even where a small-business exemption may apply.

Privacy contact: shoutout@lil.business

2. Information We Collect

  • Enquiries and intake: name, work email, organisation, role, project needs, budget range, timing, and message content you submit.
  • Bookings: contact details, selected meeting time, time zone, and booking answers provided through Cal.com.
  • Purchases: order, product, billing, tax, refund, and support information provided through Polar. We do not receive or store your full card number.
  • Newsletter: email address, consent or subscription record, source, delivery status, and unsubscribe status.
  • Client and support records: correspondence, agreed scope, deliverables, account history, and app support details.
  • Technical and security data: IP address, request metadata, device and browser information, timestamps, security events, and referring page where generated by our infrastructure.

Please do not submit passwords, API keys, payment card numbers, sensitive health records, or other secrets through an enquiry form.

3. How We Collect and Use Information

We collect information directly from you, from services you choose to use with us, and from normal website and security logs. We use it to:

  • respond to enquiries and assess whether we can help;
  • schedule and deliver consultations, projects, products, and app support;
  • process purchases, tax records, refunds, and fraud prevention;
  • manage client relationships in our self-hosted CRM;
  • send a newsletter or marketing email only where we have consent or another lawful basis;
  • secure, troubleshoot, measure, and improve our services; and
  • meet legal, accounting, insurance, and dispute-resolution obligations.

We do not make decisions about you that produce legal or similarly significant effects solely by automated processing.

4. Marketing and Unsubscribe

Submitting a project enquiry does not subscribe you to marketing. Newsletter sign-up is separate and voluntary. Commercial emails identify lilMONSTER, include our contact details, and provide a functional unsubscribe option.

You can withdraw consent at any time using the unsubscribe link or by emailing shoutout@lil.business. We action unsubscribe requests within five business days and retain a minimal suppression record so we do not add the address back by mistake.

5. Service Providers and Disclosures

We disclose only what is reasonably needed for the relevant service:

  • Polar: online reseller and merchant of record for checkout, payment, tax, delivery, and refund administration.
  • Cal.com: scheduling and meeting administration.
  • Cloudflare: DNS, content delivery, hosting, bot management, and website security.
  • Stalwart Mail: self-hosted email delivery and mailbox infrastructure.
  • Twenty CRM: self-hosted relationship, intake, and client workflow records.
  • Professional advisers and authorities: where reasonably required for legal, accounting, insurance, security, or regulatory purposes.

We do not sell personal information or provide it to data brokers. We do not use personal information for behavioural advertising.

6. Overseas Processing

Some providers operate infrastructure outside Australia. Depending on routing and the service used, information may be processed in countries including the United States and other locations where Cloudflare, Polar, or Cal.com operate. We take reasonable steps appropriate to the risk and use provider contractual and security controls where available.

7. Retention

We keep personal information only for as long as reasonably needed for the purpose collected, legal record-keeping, security, insurance, or a dispute. Typical periods are:

  • newsletter records until unsubscribe, then a minimal suppression record;
  • unsuccessful enquiries for up to two years after last contact;
  • client, order, and tax records for the period required by Australian law, generally at least five years for relevant business records; and
  • security logs for a limited operational period unless needed to investigate an incident.

We may securely de-identify information instead of deleting it where the result can no longer reasonably identify you.

8. Cookies and Similar Technology

We do not use advertising cookies or third-party behavioural tracking pixels. Our services may use technically necessary cookies or browser storage for security, form integrity, checkout, booking, preferences, or abuse prevention. Cloudflare and embedded service providers may set their own necessary cookies when you use those services.

9. Access, Correction, and Complaints

You may ask what personal information we hold about you, request correction, withdraw marketing consent, or ask us to delete information that we no longer need to retain. Some requests may be limited by legal, security, or record-keeping obligations.

Email shoutout@lil.business. We may need to verify your identity before releasing or changing information. We will acknowledge privacy complaints and respond within a reasonable time.

If the Privacy Act applies and you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

10. Security and Data Breaches

We use access controls, encryption in transit, logging, backups, least-privilege administration, and other safeguards appropriate to the information and service. No internet service is risk-free.

Where the Notifiable Data Breaches scheme applies, we will assess suspected eligible data breaches and notify affected people and the OAIC when required.

11. Children

Our business services and digital products are not directed to children under 15. If you believe a child has submitted personal information without appropriate consent, contact us so we can assess and remove it where appropriate.

12. Changes and Contact

We may update this policy when our services, providers, or legal obligations change. We will publish the effective date and give additional notice where a material change requires it.