Privacy Policy
Last updated: June 2026
Who we are
This Privacy Policy describes how Performance Works (Aust) Pty Limited (“OOHLA”, “we”, “us”) collects, uses, holds, and discloses your personal information when you visit oohla.world (the “Site”) or buy from us. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and — where it applies to you — the EU and UK General Data Protection Regulation (GDPR).
By using the Site, you agree to this policy. If you don’t agree, please don’t use the Site. We may update this policy from time to time; the “last updated” date above will always reflect the current version.
The information we collect
We collect information you give us directly, including your name, email address, shipping and billing address, phone number, order details, and any messages you send us. When you create an account, we store the details you provide so you can access your room, your saved stories, and your order history.
We do not store your full payment card details. Payments are processed by Shopify; your card information is handled and secured by Shopify and its payment partners, not held by us.
We also collect some information automatically when you visit — your device and browser type, IP address, the pages you view, and how you arrived at the Site — through cookies and similar technologies. This helps the Site work and helps us understand what’s useful.
The companies that help us run OOHLA
We keep our list of partners deliberately small. We share only what each one needs to do its job:
Shopify — our e-commerce platform and payment processor. It handles checkout, payments, and order data. See Shopify’s privacy policy at shopify.com/legal/privacy.
Resend — sends our emails (order confirmations, account messages, and, if you’ve opted in, updates from the house).
Supabase — securely stores account, library, and order-related data.
Vercel — hosts the Site.
Our shipping carriers — receive your name and delivery address solely to deliver your order.
We do not sell your personal information, and we do not share it with third parties for their own marketing.
How we use your information
We use your information to process and deliver your orders; to manage your account; to provide customer support and respond to you; to send order and account messages; to send marketing emails where you’ve opted in (you can unsubscribe at any time); to improve the Site and our products; to detect and prevent fraud; and to meet our legal obligations.
Where the GDPR applies, we rely on these legal bases: performing our contract with you (to fulfil orders and run your account), your consent (for marketing), our legitimate interests (to improve and secure the Site), and compliance with the law.
Cookies
We use cookies to keep the Site working (for example, to remember your cart and session), to remember your preferences, and to understand Site usage. You can control or disable cookies in your browser settings, though some features of the Site may not work properly if you do.
Marketing & how to opt out
If you join our list or opt in at checkout, we’ll send you occasional emails. You can opt out any time using the unsubscribe link in any email, or by writing to us. Order and account messages aren’t marketing, so you’ll continue to receive those while you have orders or an account with us.
Discretion
We understand the sensitivity of what we sell. Orders ship in plain, unmarked packaging, and we treat your purchase and reading history as private. We don’t disclose what you buy or read except as needed to provide the service or as required by law.
How long we keep it
We keep personal information only as long as needed for the purposes above, to meet legal, tax, and accounting requirements, and to resolve disputes or enforce our agreements. When it’s no longer needed, we delete or de-identify it.
Where your information is held
Our service providers (including Shopify, Resend, Supabase, and Vercel) may store and process data outside Australia, including in the United States and other countries. Where information is transferred overseas, we take reasonable steps to ensure it’s handled consistently with this policy and applicable law.
Your rights
You have the right to ask for a copy of the personal information we hold about you, to have it corrected, and — subject to legal exceptions — to have it deleted. You can access and update much of it by logging into your account. For anything else, write to us and we’ll respond within a reasonable time.
If you’re in the EU or UK, you also have rights to object to or restrict certain processing, to data portability, and to withdraw consent at any time. If you’re in Australia and have a privacy concern, you may also contact the Office of the Australian Information Commissioner (oaic.gov.au).
Children
OOHLA is strictly for adults. The Site and our products are intended for people aged 18 and over, and we do not knowingly collect information from anyone under 18. If you believe a minor has given us information, contact us and we’ll remove it.
Security
We take reasonable steps to protect your information from loss, misuse, and unauthorised access, and we work with reputable providers who do the same. No method of transmission over the internet is completely secure, so we can’t guarantee absolute security — but if a breach affecting your information occurs, we’ll act and notify you as required by law.
Contact
For any privacy question or request, write to us at hello@oohla.world. A person reads it.
Performance Works (Aust) Pty Limited · oohla.world
