Privacy policy

Overview

RimLabs is a brand operated by WheelWork Customs PTY LTD (ABN: 66 691 875 877), a registered Australian company based in Victoria, Australia ("we", "our", "us"). We are the data controller responsible for personal information collected through our website and during the purchase of our products.

This policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the rights you have over it. We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs); the General Data Protection Regulation (GDPR) for visitors and customers in the European Economic Area and the United Kingdom; the California Consumer Privacy Act (CCPA/CPRA) for California residents; and equivalent privacy laws in other jurisdictions where they apply to us.

Information We Collect

Identity and contact information. Your name, email address, phone number, shipping address, and billing address — provided by you at checkout or when you create an account.

Order and transaction information. Order details, products purchased, order value, currency, payment method type (not full card numbers), order history, and customer service correspondence.

Account information. If you create an account, your login email and password (stored in encrypted/hashed form), saved addresses, and account preferences.

Marketing preferences. Whether you have opted in to receive marketing communications, channel preferences (email, SMS), and engagement data such as email opens and link clicks.

Technical and usage information. IP address, device type, browser type and version, operating system, referral URL, pages visited, time spent on pages, items added to cart, and approximate location derived from IP address. Collected automatically through cookies, pixels, and similar technologies.

Communications. The content of emails, chat messages, and any correspondence you send to us, including through our customer service tools.

We do not knowingly collect sensitive personal information — such as health data, racial or ethnic origin, political opinions, or biometric data — as part of normal store operations.

How We Use Your Information

To fulfil your order. Processing payment, dispatching your order to our overseas fulfilment partner, arranging carrier collection and delivery, and providing tracking updates.

To communicate with you about your order. Order confirmations, dispatch notifications, delivery updates, customer service correspondence, and post-purchase follow-up.

To send marketing communications where you have opted in. Product announcements, promotional offers, restock notifications, and brand updates. You can opt out at any time using the unsubscribe link in any marketing email or by contacting us.

To run targeted advertising. We share hashed or anonymised identifiers with advertising platforms to measure ad performance and show you relevant products on third-party websites and social media platforms. See the Cookies & Tracking section below.

To detect and prevent fraud, chargebacks, and abuse — including matching billing and shipping data, analysing order patterns, screening against known fraud signals, and contesting unjustified chargebacks.

To improve our products, website, and service quality — including analysing aggregated and anonymised usage data, customer feedback, and order patterns.

To comply with legal obligations — including tax reporting, accounting, and responses to lawful requests from authorities.

How We Share Your Information

We share your personal information with the following categories of recipients only to the extent necessary for the purposes described above.

Our overseas fulfilment partner. We share your name, shipping address, phone number, and order details with our production and fulfilment partner based in the People's Republic of China for the purpose of producing and dispatching your order. See the International Data Transfers section below.

Shipping carriers. Carriers including but not limited to DHL, FedEx, UPS, Australia Post, USPS, Royal Mail, and destination-country postal services. We share name, address, phone number, and parcel information necessary for delivery.

Payment processors. Shopify Payments, PayPal, Stripe, Afterpay, Apple Pay, and Google Pay. We do not store full card numbers; payment data is handled by these PCI-DSS-compliant processors.

Marketing and analytics platforms. Including Meta (Facebook, Instagram), Google, TikTok, Klaviyo, and similar providers. We share hashed identifiers, conversion events, and analytics data to measure advertising performance and personalise your experience.

Customer service and operations tools. Including our helpdesk software, email marketing platform, and review platform, used to manage customer correspondence and post-purchase communications.

Legal authorities and advisors. Where required by law, court order, or to protect our legal rights — including in the case of fraud investigation, chargeback dispute, or debt recovery.

Our parent operating entity, WheelWork Customs PTY LTD. As the legal operator of the RimLabs brand, our parent entity has access to RimLabs customer data for the same purposes described in this policy.

We do not sell your personal information to any third party. We do not "share" your personal information for cross-context behavioural advertising as defined under the CCPA/CPRA, except in the context of our own ad campaigns, which you can opt out of as described below.

International Data Transfers

Because our fulfilment partner is located in the People's Republic of China, personal information necessary to fulfil your order — your name, shipping address, phone number, and order contents — is transferred outside Australia, the European Economic Area, the United Kingdom, the United States, and other jurisdictions where you may reside.

China's data protection regime may not be equivalent to the regime that applies in your country of residence. We take reasonable steps to ensure your information is handled securely by our fulfilment partner, including contractual obligations restricting the use of your data to order fulfilment.

By placing an order with us, you provide your informed consent to this transfer for the purpose of fulfilling the contract between you and us. This transfer is necessary for the performance of that contract. Where you do not consent to this transfer, we are unable to fulfil your order.

Where additional safeguards are required by law in your country of residence — such as Standard Contractual Clauses under the GDPR — we will take reasonable steps to implement them.

Cookies & Tracking Technologies

Our website uses cookies and similar technologies (pixels, web beacons, local storage) to enable site functionality, analyse site performance, and personalise advertising.

Essential cookies are necessary for the website to function — cart contents, login session, checkout flow. These cannot be disabled.

Analytics cookies measure how visitors use our site. We use Shopify analytics and Google Analytics.

Marketing and advertising cookies allow us and our advertising partners to measure ad performance and show you relevant products on third-party websites. We use the Meta Pixel, Google Ads tag, TikTok Pixel, and similar technologies.

You can manage cookies through your browser settings or, where available, through our on-site cookie banner. Disabling marketing cookies will not stop you from seeing ads, but the ads you see may be less relevant. Disabling essential cookies will prevent the website from functioning correctly.

Marketing Communications

If you have opted in to receive marketing communications from us, we will send you emails about new products, restocks, promotional offers, and brand updates. You can unsubscribe at any time using the link at the bottom of any marketing email, by adjusting your account preferences, or by contacting us at support@wheelworkcustoms.com.

Transactional emails — order confirmations, dispatch notifications, delivery updates, customer service responses — are not marketing communications and are sent regardless of your marketing preferences, as they are necessary for the performance of your order.

Data Retention

We retain personal information for as long as necessary to provide our service, comply with legal obligations, resolve disputes, and enforce our agreements.

In practice: order data is retained for at least 7 years to comply with Australian tax and accounting record-keeping requirements; account data is retained while your account is active and for a reasonable period after closure; marketing data is retained until you unsubscribe or request deletion; and fraud-prevention data may be retained longer where required to defend against repeat fraudulent activity.

After the retention period expires, we will delete, anonymise, or securely archive your personal information.

Security

We use commercially reasonable safeguards to protect your personal information, including TLS/SSL encryption of data in transit, PCI-DSS-compliant payment processors, access controls limiting who can access customer data internally, and secure password storage. Our website is hosted on Shopify, which provides enterprise-grade security infrastructure.

No method of transmission over the internet or method of electronic storage is 100% secure. While we use commercially reasonable means to protect your information, we cannot guarantee absolute security.

Your Rights

Subject to applicable law, you have the following rights in relation to your personal information.

Right of access. You may request a copy of the personal information we hold about you.

Right to correction. You may request that we correct inaccurate or incomplete personal information.

Right to deletion (right to be forgotten). You may request that we delete your personal information, subject to our legal obligations to retain certain data (such as order records required for tax purposes).

Right to data portability. Where processing is based on consent or contract, you may request a copy of your data in a structured, commonly used, machine-readable format.

Right to restrict processing. You may request that we limit how we process your personal information in certain circumstances.

Right to object. You may object to processing of your personal information for direct marketing purposes at any time.

Right to withdraw consent. Where we rely on your consent to process your personal information, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Right to lodge a complaint. You may lodge a complaint with the privacy regulator in your country of residence. In Australia, this is the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. In the United Kingdom, this is the Information Commissioner's Office (ICO) at ico.org.uk. In the European Union, this is your national data protection authority. In California, this is the California Privacy Protection Agency.

To exercise any of these rights, contact us at support@wheelworkcustoms.com. We will respond within 30 days. We may need to verify your identity before processing your request to protect against unauthorised access.

Children's Privacy

Our products are not directed at children under 14, and our website is not designed for children under 16. We do not knowingly collect personal information from anyone under 16. If you believe we have inadvertently collected personal information from a child, please contact us at support@wheelworkcustoms.com and we will delete it.

Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, legal requirements, or service offerings. The most recent version will always be posted on our website with the effective date noted at the top. Material changes will be communicated by email to active customers where appropriate.

Contact

Privacy enquiries, requests, and complaints: support@wheelworkcustoms.com

Please include "Privacy enquiry" in the subject line for faster handling. We aim to respond to all privacy-related enquiries within 30 days, or sooner where required by law.