Privacy Policy | Rhimahden Plant Nursery Swan Hill

Legal · Privacy

Privacy Policy

🗓️ Last updated: March 2026 🏢 Rhimahden Plant Nursery (Swan Hill Garden Centre) 📍 Swan Hill VIC 3585
Section 1

Overview & Our Commitment

Rhimahden Plant Nursery, trading as Swan Hill Garden Centre, is a family-owned business operated by Peta-Lyn and John Nosatti at 11-15 Sea Lake-Swan Hill Road, Swan Hill VIC 3585. We are committed to protecting the privacy of everyone who visits our nursery, uses our website, or gets in touch with us.

This Privacy Policy explains what personal information we collect, why we collect it, how we use it, who we share it with, and your rights in relation to it. It applies to our website at swanhillgardencentre.com.au and rhimahdennursery.com.au, our in-store interactions, and our email and SMS communications.

🌿
The short version We collect only what we need, we use it to serve you better, we don't sell it to anyone, and you can ask us to update or delete it at any time. If you have any questions, just call, email, or pop in — we're always happy to have a chat.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where this policy refers to "personal information", that term has the same meaning as in the Privacy Act — information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Section 2

What Personal Information We Collect

We only collect personal information that is reasonably necessary for our business functions. Depending on how you interact with us, we may collect some or all of the following.

Information you give us directly

  • Contact details — your name, phone number, email address, and suburb or postcode, when you submit an enquiry form, sign up for our newsletter, or contact us directly
  • Enquiry content — the message or question you send us through our website contact form
  • Marketing preferences — whether you'd like to receive email or SMS communications from us, and what topics interest you
  • In-store visit information — notes we may make after a conversation with you about your garden, soil, or plant needs, to help us serve you better on future visits

Information we collect automatically

  • Website usage data — pages visited, time spent on the site, browser type, device type, and approximate location (city/region level), collected via Google Analytics
  • Cookie data — information stored by cookies on your browser when you visit our website. See Section 6 for full details
  • Social media interaction data — if you interact with our Facebook or Instagram pages, or if our Facebook Pixel is active on your browser, Meta may share aggregated data with us about how people interact with our website and advertisements

What we do NOT collect

  • Payment card details or bank account information — all in-store payments are processed through our EFTPOS provider directly; we never see or store your full card details
  • Sensitive information (as defined by the Privacy Act) such as health information, racial or ethnic origin, political opinions, or religious beliefs — unless you choose to volunteer it in a message to us
  • Identity documents
💳
Payments Rhimahden does not take payments online. All purchases are made in-store only. Payment card transactions are processed securely by our EFTPOS terminal provider — we do not capture, store, or have access to your card number, expiry date, or CVV.
Section 3

How We Use Your Information

We use personal information only for the purposes for which it was collected, or for directly related secondary purposes that you would reasonably expect. Specifically, we use your information to:

  • Respond to enquiries you send us through our contact form or by phone or email
  • Send you email newsletters, seasonal gardening updates, and promotions — if you have opted in to receive them
  • Send you SMS messages about time-sensitive news such as new stock arrivals or special events — if you have opted in
  • Improve our website and understand how visitors use it, using aggregated, anonymised analytics data
  • Measure the effectiveness of our Facebook and Instagram advertising campaigns
  • Maintain customer records in our CRM system to help us remember your preferences and give you better advice when you visit or contact us
  • Comply with our legal obligations
🚫
We do not sell your personal information We will never sell, rent, or trade your personal information to any third party for their own marketing purposes. Full stop.
Section 4

Third-Party Services We Use

To run our website and communicate with customers, we use a small number of trusted third-party platforms. Each is subject to its own privacy policy, which we link to below. We have chosen these providers based on their reputation for data security and their compliance with applicable privacy laws.

Service Purpose Data shared Their privacy policy
GoHighLevel Our website platform and CRM — stores customer enquiries and contact records Name, email, phone, enquiry content View policy ↗
Google Analytics Website analytics — helps us understand how visitors use our site Anonymised usage data, approximate location (city level), device type, pages visited View policy ↗
Meta (Facebook & Instagram) Advertising and social media — we run ads on Facebook and Instagram, and use the Meta Pixel to measure ad performance Website visitor behaviour (via Pixel), aggregated ad performance data. Meta may match this with your Facebook profile if you have one. View policy ↗
Email provider
(via GoHighLevel)
Sending email newsletters and marketing communications to opted-in subscribers Name, email address, email engagement data (opens, clicks) Governed by GoHighLevel's policy above
SMS provider
(via GoHighLevel)
Sending SMS notifications to opted-in subscribers Name, phone number, message delivery status Governed by GoHighLevel's policy above

We do not share your personal information with any other third parties except where required by law (for example, to comply with a court order or regulatory obligation).

🌐
Overseas data storage Some of our third-party service providers may store data on servers located outside Australia, including in the United States. We take reasonable steps to ensure these providers maintain appropriate data security standards. By using our website or providing us with your information, you consent to this possibility.
Section 5

Marketing & Communications

We love keeping in touch with our customers — seasonal planting tips, new stock arrivals, and the occasional special offer. But we only contact you if you've asked us to.

Email marketing

We send email newsletters and gardening updates to subscribers who have opted in. Every marketing email we send includes an unsubscribe link at the bottom. Click it at any time to stop receiving emails from us — we'll process your request promptly and in accordance with the Spam Act 2003 (Cth).

SMS marketing

We may send SMS messages to customers who have specifically opted in to receive them. These are used sparingly — typically for time-sensitive news like new stock arrivals or event reminders. Every SMS we send includes instructions on how to reply STOP to opt out. Once you opt out, we will not send you further SMS messages.

Facebook & Instagram advertising

We run paid advertisements on Facebook and Instagram. We may use the Meta Pixel — a small piece of code on our website — to understand whether our ads are effective, and to show relevant ads to people who have visited our website. You can manage your ad preferences through your Facebook account settings, or opt out of interest-based advertising via youronlinechoices.com.au.

✉️
To unsubscribe from all marketing Email us at [email protected] or call 0429 437 024 and we'll remove you from all marketing communications right away. You can also walk in and ask us — we're open seven days.
Section 6

Cookies & Website Tracking

Our website uses cookies — small text files stored on your device — and similar technologies to make the site work properly and to understand how it's being used.

Types of cookies we use

  • Essential cookies — required for the website to function (e.g. remembering form progress). You cannot opt out of these without disabling the site.
  • Analytics cookies (Google Analytics) — collect anonymised data about how visitors use our site: pages visited, time spent, general location. This helps us improve the site. You can opt out via the Google Analytics opt-out browser add-on.
  • Marketing cookies (Meta Pixel) — track whether visitors to our website have clicked on our Facebook or Instagram ads. Meta uses this data to help us measure ad performance and to show relevant ads to website visitors. You can manage this via your Facebook ad settings.

Managing cookies

You can control or delete cookies through your browser settings. Disabling cookies may affect the functionality of some parts of our website. For more information on managing cookies, visit allaboutcookies.org.

Do Not Track

Some browsers include a "Do Not Track" feature. Our website does not currently respond to Do Not Track signals, as there is no universally accepted standard for how these signals should be interpreted. We continue to monitor developments in this area.

Section 7

Storage & Security

We take the security of your personal information seriously. We use GoHighLevel as our website and CRM platform, which employs industry-standard security measures including data encryption, access controls, and secure data centres.

How long we keep your information

  • Enquiry form submissions — retained for up to 3 years to allow us to follow up and maintain our service records
  • Marketing subscriber records — retained for as long as you remain subscribed, plus 12 months after unsubscription
  • In-store customer notes — retained indefinitely unless you ask us to remove them, as they help us give you better ongoing advice
  • Website analytics data — retained in aggregated, anonymised form in accordance with Google's standard retention periods

When personal information is no longer required, we take reasonable steps to destroy or de-identify it securely.

🔒
Data breach notification In the event of a data breach that is likely to result in serious harm to individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme in the Privacy Act 1988.
Section 8

Your Privacy Rights

Under the Australian Privacy Principles, you have the following rights in relation to your personal information held by us. We will respond to any request within a reasonable timeframe, and in most cases within 30 days.

👁️

Access

You can ask us what personal information we hold about you, and request a copy of it.

✏️

Correction

If your information is inaccurate, out of date, or incomplete, you can ask us to correct it.

🗑️

Deletion

You can ask us to delete your personal information, subject to any legal obligations we have to retain certain records.

📵

Opt out

You can opt out of email or SMS marketing at any time, without affecting your ability to use our website or visit us in store.

Information

You can ask us to explain how we use your personal information and who we share it with.

📝

Complaints

If you're not satisfied with our response, you can lodge a complaint with the OAIC.

How to make a request

To exercise any of these rights, contact us using the details in Section 11. We may need to verify your identity before fulfilling a request. We will not charge a fee for handling a reasonable privacy request.

Complaints to the OAIC

If you are not satisfied with our handling of a privacy concern after contacting us, you have the right to lodge a complaint with the Office of the Australian Information Commissioner:

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001
Section 9

Children's Privacy

Our website is not directed at children under the age of 15. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child under 15, please contact us immediately and we will delete that information as quickly as possible.

Section 10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we do, we will update the "Last updated" date at the top of this page.

If we make material changes — particularly changes that affect how we use your personal information — we will take reasonable steps to notify you, such as by email (if you're a subscriber) or by a notice on our website.

We encourage you to review this policy periodically. Your continued use of our website or services after a policy update constitutes your acceptance of the revised policy.

Section 11

Contact Us

If you have any questions about this Privacy Policy, want to access or correct your personal information, or would like to make a privacy complaint, please get in touch with us. We'd love to sort things out for you directly.

Get in touch with Rhimahden

Business Rhimahden Plant Nursery (Swan Hill Garden Centre)
Owners Peta-Lyn & John Nosatti
Address 11-15 Sea Lake-Swan Hill Road, Swan Hill VIC 3585
Mobile 0429 437 024
Hours Mon & Sun: 10am–4pm  ·  Tue–Fri: 9am–5:30pm  ·  Sat: 9am–5pm

We aim to respond to all privacy requests within 5 business days. For formal complaints, we will acknowledge receipt within 5 days and aim to resolve the matter within 30 days. If a matter requires more time, we will let you know.

↑ Back to top