# Privacy policy

> This policy explains the limited personal information collected by the StewArt Media website and the controls available to visitors.

- Canonical URL: https://stewartmedia.com.au/privacy-policy/
- Policy type: privacy
- Effective date: 2026-09-18
- Last reviewed: 2026-09-18
- Review status: review
- Owner: Search Global Pty Ltd trading as StewArt Media

## Who we are

StewArt Media is a business of Search Global Pty Ltd in Victoria, Australia. In this policy, **StewArt Media**, **we**, **us** and **our** refer to Search Global Pty Ltd trading as StewArt Media.

This policy covers personal information handled through `stewartmedia.com.au`, including the contact form and newsletter signup. A separate client agreement may apply when we provide services to a client.

## What we collect

### Contact enquiries

When you send an enquiry, we collect the information you enter: your name, email address, company, description of the recurring work, optional system information, consent and the page from which you submitted the form.

We store the enquiry in a first-party Cloudflare D1 database. We also send an operator notification and an acknowledgement email. We do not add contact-form enquiries to the newsletter unless the person separately subscribes.

Please do not include passwords, API keys, payment-card details, health information or other sensitive information in the contact form.

### Newsletter subscriptions

When you subscribe to the newsletter, Buttondown receives your email address and manages the subscription, delivery and unsubscribe process. Buttondown's own privacy terms also apply to its service.

### Technical and security information

Our hosting and security providers may process request information such as IP address, browser and device details, timestamps, requested URLs and security signals. Cloudflare Turnstile processes technical information to distinguish legitimate visitors from abusive automated traffic. We do not store your IP address in the contact enquiry record.

The site serves its fonts from our own domain. Loading those fonts does not send a request to Google Fonts.

### Website analytics

We use Google Analytics 4 to understand visits, pages viewed and interactions with the website. We retain the existing StewArt Media analytics property when changing website platforms. Cloudflare's Google tag gateway delivers the Google tag and routes measurement requests through our domain. This remains Google Analytics, not an anonymous first-party-only service.

Analytics information can include cookie identifiers, page addresses, referring pages, approximate location and browser or device information. We do not deliberately send names, email addresses or contact-form field values to Google Analytics. Do not include personal information in page addresses or query parameters.

We also retain Cloudflare Web Analytics to measure website performance and usage without analytics cookies. Cloudflare may process technical request and performance information to provide that service.

This migration does not add separate Meta, LinkedIn or Google Ads remarketing tags. New advertising or remarketing implementations require a separate review, any required consent controls and an updated policy.

## Why we use personal information

We use personal information to:

- receive, assess and respond to enquiries;
- deliver requested newsletter emails and manage subscriptions;
- operate, secure, diagnose and improve the website;
- keep appropriate business and compliance records;
- prevent spam, fraud, misuse and security incidents; and
- comply with legal obligations and resolve disputes.

The normal delivery of a public page does not require a runtime large language model. If authorised staff or supervised automation assists with an enquiry, it remains subject to the same purpose, access and confidentiality limits described in this policy. We do not use contact-form or newsletter data to train public AI models.

## Who receives information

We disclose information only where reasonably needed for the purposes above, with consent, or where required or authorised by law. Relevant service providers include:

- **Cloudflare**, for website delivery, security, Turnstile, D1 storage, transactional email delivery, the Google tag gateway and Web Analytics;
- **Google Analytics**, for website usage measurement;
- **Google Workspace**, for the operator mailbox that receives enquiry notifications; and
- **Buttondown**, for newsletter subscriptions and delivery.

These providers may process information in Australia and other countries in which they or their subprocessors operate. We do not sell personal information.

## Cookies and browser storage

Google Analytics uses analytics cookies to distinguish browsers and visits. You can block or delete cookies through your browser settings, or use [Google's Analytics opt-out browser add-on](https://tools.google.com/dlpage/gaoptout). Blocking analytics does not prevent you from reading the site or submitting an enquiry. Cloudflare Web Analytics does not use analytics cookies.

Essential security services, including Turnstile, may use cookies or similar browser storage where necessary to prevent abuse. Links to external services are governed by those services' own policies. Google explains its handling of analytics data in its [privacy policy](https://policies.google.com/privacy).

## Security and retention

We use access controls, managed infrastructure, transport encryption and operational safeguards appropriate to the information we hold. No internet transmission or storage system is completely secure.

We retain information only while it is reasonably needed for the purpose for which it was collected, business records, dispute resolution, security or legal obligations. We then delete or de-identify it where practical. Newsletter data remains with Buttondown until the subscription is removed or retention is otherwise required.

If a data incident occurs, we will assess and respond to it, including notifications required by applicable law. The OAIC describes a data breach as personal information being accessed or disclosed without authorisation, or being lost.[3]

## Access, correction and complaints

The Australian Privacy Principles form part of the privacy framework under the *Privacy Act 1988* for organisations the Act covers.[1] Australian privacy law provides rights to request access to personal information, subject to lawful exceptions.[2]

You may ask us to access, correct or delete personal information we hold about you, or make a privacy complaint. Use the [contact form](/contact/) and begin the work-description field with **Privacy request**. Include enough information for us to identify the relevant record, but do not send identity documents or secrets unless we request them through an appropriate channel.

We will acknowledge and assess the request within a reasonable period. If you are not satisfied with our response, you may contact the [Office of the Australian Information Commissioner](https://www.oaic.gov.au/).

## Changes to this policy

We may update this policy when our website, service providers or legal obligations change. The effective date and last-reviewed date identify the current version. Material changes will be published at this same URL.

## Agent-readable versions

This policy is also available as [Markdown](/policies/privacy-policy.md) and through the [policy JSON index](/policies/index.json). Those representations are generated from this source. The canonical HTML page at `/privacy-policy/` takes precedence if a delivery or formatting fault creates a mismatch.

## Sources

[1] https://www.oaic.gov.au/privacy/australian-privacy-principles — Australian Privacy Principles | OAIC
[2] https://www.oaic.gov.au/privacy/your-privacy-rights/your-personal-information/access-your-personal-information — Access your personal information | OAIC
[3] https://www.oaic.gov.au/privacy/notifiable-data-breaches — Notifiable data breaches | OAIC