Skip to content

Privacy policy

Last updated: May 19, 2026

Privacy Policy Tribal Sport Pty Ltd 


1. About this Privacy Policy

Tribal Sport Pty Ltd (ABN 38 981 017 861, "Tribal Sport", "we", "us", "our") operates the website at tribalsport.com.au and the online team stores hosted on that domain (together, the "Services").

This Privacy Policy describes how we collect, hold, use and disclose your personal information when you visit our website, place an order, register an account, contact us, or interact with one of our team stores. It applies to all customers, website visitors, parents, players, club and school administrators, and other individuals whose personal information we handle.

This Privacy Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For European Economic Area and United Kingdom residents, additional rights are set out in Section 11.

By using the Services, you acknowledge that you have read and understood this Privacy Policy.


2. Personal information we collect

The personal information we collect depends on how you interact with us. We do not collect more information than we need.

Information you provide to us directly:

  • Contact details — name, postal address, email address, phone number
  • Order and shipping details — delivery address, billing address, items ordered, order history
  • Account details — username (your email), password (stored securely by Shopify; we do not have access to your password), saved preferences
  • Garment customisation details — where a team store offers customised garments (e.g. name or number on a jersey), the parent or purchaser enters the player's first name (or surname/initial) and number as line-item attributes on their order
  • Communications — the content of any email, phone call or written correspondence you have with our customer service team

Information collected automatically through the Services:

  • Device and network information — IP address, browser type, operating system, device identifiers
  • Usage information — pages visited, items viewed, items added to cart, time and date of visit, referring website
  • Cookies and similar technologies — see Section 5

Information we collect from third parties:

  • Payment confirmation details from our payment processor. We do not collect, store or process your credit or debit card numbers — these are handled directly by a PCI DSS Level 1 certified payment service.
  • Order routing and delivery status updates from freight providers

We do not knowingly collect sensitive information (including health information, racial or ethnic origin, religious beliefs, sexual orientation, biometric data or criminal record information). If you provide sensitive information voluntarily, we will only use it for the purpose for which you provided it and will not retain it longer than necessary.


3. How we use your personal information

We use your personal information only for the following purposes:

  • To fulfil your order — process payment, arrange manufacturing where customisation is required, arrange shipping, process returns and exchanges
  • To operate your account — authentication, password reset, order history, saved preferences
  • To provide customer service — answer your enquiries, process complaints, manage returns
  • To send transactional communications — order confirmations, shipping notifications, return updates. These are sent to fulfil your order and are not subject to marketing opt-in
  • To send marketing communications — only to subscribers who have opted in via the newsletter signup at checkout or on our website. You can unsubscribe at any time using the link in any marketing email
  • To improve the Services — aggregated and de-identified analytics about how the website is used
  • For security and fraud prevention — detecting and preventing fraudulent transactions, abuse and unauthorised access
  • To comply with legal obligations — Australian taxation, consumer law, and record-keeping requirements

We do not use your personal information for any other purpose without first obtaining your consent or unless permitted under the Privacy Act.


4. How we disclose your personal information

We disclose your personal information only to the following categories of service providers, and only to the extent necessary for them to perform their function:

  • E-commerce and hosting platform — hosts our website, team stores, customer accounts, and order records
  • Payment processor — processes card payments via a PCI DSS Level 1 certified service; we do not receive or store card numbers
  • Content delivery and security — DNS, content delivery network, and web application firewall services
  • Team store framework — multi-vendor plugin enabling school and club stores
  • Freight providers — receives your name and delivery address to fulfil your order
  • Manufacturing suppliers — receives customisation attributes (e.g. name, number, size) and order quantities to produce your garments
  • Internal operations — email, document management, and order processing platforms used by Tribal Sport staff when handling your order

Each provider is engaged under terms that require them to handle your personal information consistently with the Australian Privacy Principles.

We do not sell your personal information. We do not share it with advertising networks, data brokers, or social media platforms for audience-building purposes, except that, where you have consented via our cookie consent banner, we may share limited identifiers (such as cookie and pixel data) with third-party advertising platforms — including Meta (Facebook/Instagram) — to measure the effectiveness of our marketing and to serve relevant advertisements to you on those platforms. See Section 5 for details on how to manage your cookie preferences.

Other circumstances we may disclose your personal information:

  • Where you have consented to the disclosure
  • Where required or authorised by Australian law or a court/tribunal order
  • Where reasonably necessary for an enforcement-related activity by an enforcement body
  • Where reasonably necessary to protect the safety of any individual
  • In connection with a sale, merger or restructure of our business, subject to confidentiality protections

5. Cookies and tracking technologies

We use cookies and similar technologies on the Services. Some are necessary for the Services to function (for example, keeping you signed in and remembering your cart). Others support analytics and improvements to the Services. For further information about how our e-commerce platform uses cookies, see the Shopify Cookie Policy.

Cookie categories used by Tribal Sport:

  • Strictly necessary cookies — required for the Services to operate (set automatically; cannot be disabled)
  • Functional cookies — remember your preferences and saved cart
  • Analytics cookies — help us understand how the Services are used (set only with your consent)
  • Marketing cookies — used to measure the effectiveness of our marketing campaigns and, where you have opted in, to support remarketing on third-party advertising platforms including Meta (Facebook/Instagram). These cookies work by sharing limited identifiers (such as pixel data) with those platforms so that we can show relevant advertisements to people who have previously visited our Services. These cookies are set only with your consent and can be withdrawn at any time via the cookie consent banner or the "Cookie settings" link in the website footer.

You can manage your cookie preferences via the consent banner displayed when you first visit the Services and via the "Cookie settings" link in the website footer. You can also control cookies through your browser settings. Blocking cookies may affect the functionality of the Services.


6. Storage, security and retention

Your personal information is stored on infrastructure operated by our service providers, including cloud infrastructure located primarily in the United States and Canada, and our content delivery provider's global edge network.

Our primary platform providers encrypt data in transit (TLS 1.2 or higher) and at rest (AES-256), and hold independent security certifications including SOC 2 Type II, ISO/IEC 27001 and PCI DSS Level 1.

Tribal Sport access to your personal information is restricted to staff and contractors who require it for their role, protected by multi-factor authentication, and reviewed periodically. Staff are bound by confidentiality obligations.

If we become aware of a data breach that is likely to result in serious harm to any individual, we will notify the Office of the Australian Information Commissioner and affected individuals in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).

Retention periods:

  • Order records — retained for at least 7 years to comply with Australian taxation and consumer law
  • Customer account records — retained while your account is active; inactive accounts are reviewed and anonymised after 36 months of inactivity
  • Customer service correspondence — retained for 24 months
  • Marketing subscriber records — retained until you unsubscribe

We will delete or de-identify your personal information when we no longer require it, unless we are required by law to retain it longer.


7. Overseas transfers

Some of your personal information is transferred to or processed by service providers located outside Australia, including in the United States, Canada, India, and China. Some service providers (such as content delivery networks) operate across a global edge network and may process data in multiple countries.

Where we engage overseas recipients, we take reasonable steps to ensure they handle your information consistently with the Australian Privacy Principles, including by relying on the contractual terms of those providers and their independent certifications. We remain accountable under s 16C of the Privacy Act for how overseas recipients handle your information.

If you have specific questions about overseas transfers, please contact us using the details in Section 13.


8. Your rights

Under the Privacy Act 1988 (Cth), you have the right to:

  • Access the personal information we hold about you — we will respond to access requests within 30 days
  • Correct personal information that is inaccurate, out of date, incomplete or misleading — we will respond to correction requests within a reasonable period and aim to do so within 30 days
  • Request deletion of your personal information, where we are not required by law to retain it
  • Object to certain uses of your personal information, including direct marketing
  • Withdraw consent at any time where we rely on your consent (for example, marketing or non-essential cookies)
  • Opt out of direct marketing — every marketing email contains an unsubscribe link; you can also email us
  • Manage cookies via the cookie consent banner or your browser

To exercise any of these rights, please contact us using the details in Section 13. We do not charge a fee. We may need to verify your identity before responding.


9. Children

The Services are not directed at children. Parents and guardians may use the Services to order garments and customised apparel for their children — in this case, the parent's account holds the order and any customisation details (such as a player's name or number on a jersey). Tribal Sport does not create accounts for children, does not contact children directly, and does not use children's information for marketing.

If you believe a child has provided personal information directly to us, please contact us at mytribe@tribalsport.com.au and we will delete it.


10. Complaints

If you believe we have breached this Privacy Policy or the APPs, please contact our Privacy Officer using the details in Section 13. We will acknowledge your complaint within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992

11. Additional rights for EEA, UK and other jurisdictions

If you are a resident of the European Economic Area, the United Kingdom or another jurisdiction with applicable data protection law, you may have additional rights, including:

  • The right to restrict processing
  • The right to object to processing
  • The right to data portability
  • The right to lodge a complaint with your local data protection authority

Where GDPR or UK GDPR applies, we process your personal information on the following legal bases: contract performance (to fulfil your order and operate your account), legitimate interests (fraud prevention and service improvement), and consent (marketing communications and non-essential cookies).

For overseas transfers to or from the EEA or UK, we rely on Standard Contractual Clauses or equivalent mechanisms where applicable.


12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this Privacy Policy and post the revised policy on tribalsport.com.au.


13. Contact us

Privacy Officer Tribal Sport Pty Ltd 45 Clarence Street, Coorparoo QLD 4151, Australia Email: mytribe@tribalsport.com.au Phone: 1300 880 666

For the purposes of the Privacy Act 1988 (Cth), Tribal Sport Pty Ltd is the entity responsible for the personal information described in this Privacy Policy.

x