Privacy Policy
Last updated: 3 October 2026
Forest Remedy makes small-batch botanical skincare. This page explains what we collect when you visit forestremedy.shop or buy from us, why we collect it, and what happens to it.
We have written it in plain English on purpose. If anything here is unclear, email contact@forestremedy.shop and we will explain it properly.
The short version
- We collect what we need to take your order and get it to you. Nothing we cannot justify.
- We never see your card number. Card details go straight to Square.
- There are no third-party trackers on this site — no Google Analytics, no Facebook pixel, no social media tracking. We count visits using software that runs on our own server, sets no cookie, and identifies nobody.
- The shop itself uses a few cookies of its own: to run your cart, and to remember how you found us so we can tell which of our posts and links lead to orders. Nothing from them goes to an advertising network. Details under Cookies below.
- We do not sell your information and we do not share it for advertising.
- Our server is in Sydney, so your order details stay in Australia.
- You can ask us what we hold about you, and ask us to correct or delete it.
Who we are
Forest Remedy
Gippsland, Victoria, Australia
Email: contact@forestremedy.shop
We are the entity responsible for the personal information described on this page.
What we collect, and why
When you place an order
Your name, email address, phone number, delivery address and what you ordered. We need these to take payment, pack the right things, and get them to the right door. Your phone number is used by the courier if there is a delivery problem.
When you pay
We do not see or store your card number. Our checkout uses Square’s hosted payment fields: the card form is served by Square, and the details you type go directly to Square without passing through our site. What comes back to us is confirmation that the payment succeeded, plus the card type and last four digits, so the order record makes sense to both of us.
If you pay by direct bank transfer, we see whatever your bank sends with the payment — usually the payment reference and the name on the account.
When you contact us
Whatever you put in the message. Our contact forms are deliberately configured not to record your IP address, browser or location — those fields are switched off at the source and stripped in code before anything is saved.
When you request a session
Your name, email address, mobile number and the day and time you would like, so Leni can confirm your session. Health questions are asked on paper at your session, not on this site.
When you sign up for emails
Your email address and first name. We also record whether you opened an email or clicked a link in it, so we can tell whether what we are sending is worth reading. Every email has an unsubscribe link, and you can change your preferences at any time.
When you create an account
Your email address, name and delivery address, so you do not have to type them again. You can delete your account by emailing us.
Automatically
Our web server keeps standard access logs — the page requested, the time, and the requesting IP address. These are used to keep the site running and to investigate abuse. We also run brute-force protection on the login page, which checks the IP address of anyone attempting to log in.
How we count visits
We use Koko Analytics, which runs on our own server rather than sending anything to a third party. It records which page you looked at and, if you followed a link to get here, which site you came from. Nothing else.
It sets no cookie. To tell one visitor from another it makes a short scrambled code from your IP address and browser, using a secret that changes every day — so the same person cannot be recognised from one day to the next, and the code cannot be turned back into your details. We keep the resulting counts for three years, and they are counts, not records of people.
Cookies
Our cookies do two jobs. All of them are set by our own site and read only by our own site.
Cookies the shop needs to work
- Shopping cart and checkout — so your cart survives moving between pages, and so the checkout can tell your session from someone else’s. The main one lasts two days; the rest last while you are browsing.
- Recently viewed — remembers which products you looked at during this visit.
- Logging in — if you have an account, to keep you logged in.
- Square — when you pay by card, the payment form Square serves sets its own cookies to detect fraud.
Cookies that remember how you found us
When you arrive, our shop software notes how you got here — a link on Instagram, a search engine, an email, or typing our address — along with the page you landed on, the pages you look at, and basic details such as your browser, your time zone and whether you are on a phone. If you came from a Facebook or Instagram link, the click reference that link carries is noted too.
This is done by WooCommerce, the software our shop runs on, whose cookies last only while you are browsing, and by FunnelKit, the software behind our checkout, whose cookies last two days. If you place an order, this information is saved with your order, so we can see which of our posts and links actually lead to sales and stop spending time on the ones that do not.
It stays on our own server. It is not sent to Facebook, Google or any advertising network. If that ever changes, this page will say so first.
We do not use advertising cookies. We do not run a cookie banner — instead, everything is explained here. You can clear or block these cookies in your browser at any time; blocking the ones that remember how you found us will not stop you shopping.
Who else sees your information
Only where there is a job to do:
- Square — processes card payments and handles the card details we never see.
- Australia Post and couriers — receive the name and delivery address on the parcel.
- Proton Mail — carries our email, including your order confirmation.
- Automattic (Jetpack) — provides login brute-force protection and the connection our phone app uses to check orders. This means login attempt IP addresses and basic site data are seen by Automattic.
Some of these are overseas. Square and Automattic are United States companies, and handling your information may involve it being stored or processed there. Everything we hold ourselves stays on our own server in Sydney.
We do not sell personal information to anyone, ever.
How long we keep it
- Orders and invoices — seven years, because tax law requires us to keep records of sales.
- Marketing email lists — until you unsubscribe, then we remove you.
- Contact form messages — up to two years, then deleted.
- Server access logs — a short rolling window, then overwritten.
Your rights
Under the Australian Privacy Principles you can:
- Ask what personal information we hold about you and get a copy of it.
- Ask us to correct anything that is wrong.
- Ask us to delete information we no longer need to keep. We cannot delete order records inside the seven-year tax window, but we can remove you from everything else.
- Unsubscribe from marketing at any time, without affecting your orders.
Email contact@forestremedy.shop and we will respond within 30 days. We may ask you to confirm who you are first, so we do not hand your details to someone else.
Keeping it safe
The site runs over HTTPS, card details never touch our server, administrator access is restricted, and the software is kept patched. No system is perfect, and if something ever went wrong in a way that could seriously harm you, we would tell you and notify the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Children
This shop is for adults. We do not knowingly collect information from children under 16. If you believe we have, email us and we will delete it.
Complaints
If you are unhappy with how we have handled your information, tell us first at contact@forestremedy.shop — most things are a misunderstanding we can fix quickly. If you are still not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
If we change how we handle personal information, we will update this page and change the date at the top. Material changes will be mentioned in an email to subscribers.
