Skip to content
KOLEINIPRIVATE BARBER STUDIO

Legal

Privacy Policy

How Koleini Private Barber Studio handles personal information, and what you can do about it.

Version 1.1 · Effective 8 September 2026


01Who this policy is about

This policy applies to Koleini Private Barber StudioSole trader — Amin Koleini, trading as Koleini Private Barber Studio, ABN 70 151 301 341. In this policy, “we”, “us” and “our” mean that business, and “you” means anyone who uses this website or contacts us through it.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what we collect, why, who else sees it, and how to get at it or have it corrected or deleted.

It covers this website only. Bookings are taken on a third-party booking system (Trybe), which handles that information under its own privacy policy.

02What “personal information” means

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable — whether or not it is true, and whether or not it is recorded in a material form. Your name, email address and phone number are personal information. An anonymous counter that records “someone clicked the booking link” is not.

03What we collect

These are the only fields this website collects, in full:

Enquiry form

Your name, your email address, your phone number if you choose to give one, and your message. If you tick the marketing box we also record the date and time you ticked it, the exact wording you were shown, and the IP address the tick came from — that record is what proves consent was given, and it is only stored if you gave it.

Offers list

Your email address, your first name if you give one, the date and time you signed up, the page you signed up from, your IP address, the exact consent wording shown to you, and the date and time you confirmed by clicking the link in the confirmation email.

Technical data used to rate-limit our forms

To stop automated abuse, our forms count how many submissions come from an address in a given window. We do not store your IP address to do this: we store a one-way SHA-256 hash of it alongside a counter. The hash cannot be turned back into your IP address by us.

Booking-link clicks

When someone clicks through to the booking page we increment a counter — for example “booking clicks, hero section, 12 August”. No identifier, no IP address and no device information is recorded against it. It is a number going up, nothing more.

Advertising measurement

Our Meta Pixel reports your visit to Meta, which is a separate thing from the counter above: Meta receives the page address, the referring page, your IP address and your browser details, and it sets a cookie in your browser. We hold none of that ourselves — what we see back is a count of how many people an ad brought. Section 9 sets out exactly what runs, on which pages, and how to stop it.

We do not collect sensitive information as defined by the Privacy Act, we do not collect payment details on this site, and there are no user accounts for visitors.

04How we collect it

We collect personal information directly from you, when you type it into a form on this site and submit it. We do not buy lists, we do not scrape, and we do not collect information about you from third parties.

You can use this website without giving us anything at all: reading the site, watching the clips and clicking through to the booking page require no personal information.

05Why we collect it (APP 6)

  • To answer your enquiry, and to contact you about it.
  • To send you the reminders, discounts and exclusive offers you asked for, if you asked for them.
  • To keep a record that you consented to marketing, which we are required to be able to produce.
  • To protect the site from automated abuse, using the rate-limit counters described above.
  • To understand, in aggregate, how many people click through to book.
  • To measure our advertising — which ads bring people to this site and to the booking page.

We do not use your information for any other purpose. We do not make automated decisions about you, and nothing on this site decides what you are shown based on who you are.

Meta is the exception worth naming plainly. Because we advertise through it, the pixel described in section 9 lets Meta count our visitors and build the audiences our ads are shown to. Meta profiles its own users for advertising; that is what Meta is. We do not receive that profile and we cannot see it, but we are the reason your visit here reached them, so we are telling you.

06Who we disclose it to

We do not sell personal information. We do not trade, rent or exchange it, and we do not disclose it for anyone else’s marketing.

We disclose personal information to the service providers that operate this site, and only so far as they need it to do that job. They are listed in section 10. We may also disclose information where we are required or authorised to by law.

One recipient is not a service provider in that sense and should not be buried in a list: Meta. We advertise on Facebook and Instagram, and the pixel described in section 9 reports your visit to them so we can measure it. That is advertising, not site operation, and section 9 says exactly what is sent and how to stop it. We are not paid for it and nothing about you is sold.

07Credit reporting

We do not collect, hold, use or disclose credit information, credit eligibility information or credit reporting information, so Part IIIA of the Privacy Act does not apply to us.

08Direct marketing, and how to stop it

We only send marketing email to people who asked for it. Signing up on this website is double opt-in: you enter your address, we email you a confirmation link, and nothing else is sent unless you click it.

We may also add contacts who gave consent somewhere else — for example when booking. In that case the consent already happened, so there is no second confirmation email; we record where and when it was given, and every message still carries a one-click unsubscribe. We do not add anyone who has not agreed to hear from this business specifically.

The wording you agree to

Yes — email me discounts, exclusive offers and return-cut reminders from Koleini Private Barber Studio. I can unsubscribe at any time.

Every marketing email carries a working unsubscribe link and identifies us as the sender, as required by the Spam Act 2003 (Cth). Unsubscribing takes one click, needs no login and no confirmation step, and is actioned immediately — not within five business days.

Emails that answer something you sent us — a reply to your enquiry, or a confirmation that we received it — are not marketing and do not carry an unsubscribe link. Unsubscribing from marketing does not stop us answering you.

We do not make marketing phone calls. If we ever did, we would first wash the numbers against the Do Not Call Register as required by the Do Not Call Register Act 2006 (Cth).

To stop marketing at any time: click Unsubscribe in any email we have sent you, use the unsubscribe page, or email admin@koleinibarberstudio.com.

09Cookies and tracking — exactly what runs

This site runs an advertising pixel. We advertise on Facebook and Instagram, and the Meta Pixel is how we tell which of those ads actually bring people to the studio. It is the only advertising tag here. There is no Google Analytics and no TikTok Pixel.

Here is everything that runs in your browser, in full:

  • Meta Pixel — loaded from Meta on the public pages of this site. It records that a page was viewed, and it records when someone clicks through to book, taps our phone number, sends an enquiry or joins the offers list. Meta receives the address of the page you are on, the page you came from, your IP address and your browser details. It sets cookies in your browser named “_fbp” and, if you arrived by clicking a link on Facebook or Instagram — an ad or an ordinary post, Meta tags both — “_fbc”. If you have a Facebook or Instagram account, Meta can connect that visit to it. We never send Meta your name, your email address, your phone number or anything you type into a form — not in the clear and not hashed.
  • Theme preference — if you use the light/dark switch, your choice is saved in your browser’s localStorage under the key “koleini-theme”. It never leaves your device and it is not a cookie.
  • Vercel Analytics — counts page views without cookies and without storing an identifier that follows you between sites.
  • Session cookie — only ever set for the site owner when signing in to the private admin panel. Ordinary visitors are never issued one.

The pixel does not run everywhere. It is switched off on the private admin panel, and on the unsubscribe and confirmation pages — those two carry a code in the address bar that identifies you, and it is not Meta’s business.

How to stop it

You can turn off ad personalisation in your Facebook or Instagram settings, which is where the control actually lives. Blocking third-party scripts in your browser, or using a content blocker or a private window, also stops it. Nothing on this site stops working if you do — the pixel measures advertising and has no part in booking, browsing or contacting us.

If we add anything else that tracks you, we will update this policy before turning it on — not after. That is what happened here: this section was rewritten in the same change that installed the pixel.

10Overseas disclosure (APP 8)

This site runs on services provided by companies outside Australia. By using the forms on this site, you consent to your information being handled by the following recipients, in the following countries:

  • Supabase — database and file storage. This project’s database is hosted in Sydney, Australia (ap-southeast-2), so the information you send us is stored in Australia. Supabase itself is a United States company.
  • Vercel (United States) — website hosting and cookieless analytics.
  • Resend (United States) — sends the emails this site generates.
  • Sentry (United States) — error monitoring. It is configured not to send personal information, and email addresses and IP addresses are stripped from error reports before they leave our server.
  • Trybe (Australia) — the booking system. Anything you enter when booking is collected by Trybe under its own privacy policy, not by this website.
  • GitHub (United States) — holds the website’s source code, and stores an encrypted-at-rest nightly backup of the database in a private repository area that only the owner can reach. The backup is a second copy kept in case the database is lost.
  • Meta (United States) — Facebook and Instagram. Two separate things happen here. First, the Meta Pixel described in section 9 reports your visit to Meta so we can measure our advertising: that means the page address, the referring page, your IP address, your browser details and the pixel cookies, but never your name, email address or phone number. Second, we link to our Instagram profile and to a direct-message thread — if you choose to message us there, that conversation happens inside Instagram under Meta’s privacy policy and is not collected, stored or handled by this website. Use the enquiry form or email if you would rather it was.

There are no other recipients.

11Security, storage and retention

These are the controls that actually exist, not a list of aspirations:

  • The site is served over HTTPS only, with HSTS.
  • The database denies access by default. Every table requires a server-side credential that exists only on the server; the key shipped to your browser can read nothing.
  • Uploaded media sits in a private bucket and is served through short-lived signed links.
  • The admin panel is invite-only, has no public sign-up, throttles sign-in attempts, and records administrative actions to an append-only log.
  • Form submissions are rate-limited and length-capped.

Retention: we keep enquiries and consent records for as long as we may need them — an enquiry so we can answer it and refer back to it, a consent record for as long as we might send you marketing plus a reasonable period afterwards to show consent existed. We do not currently delete this information automatically. If you want yours deleted, ask us and we will do it. Where we must keep a record that you unsubscribed, we keep only the address and the date, because deleting that would risk emailing you again by accident.

No online service can promise perfect security, and we do not. What we can say is what we have done, which is above.

12Data breaches

If a data breach happens that is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act: we will assess it promptly, notify affected individuals, and notify the Office of the Australian Information Commissioner (OAIC).

13Access and correction (APP 12 and 13)

You can ask us for a copy of the personal information we hold about you, and you can ask us to correct it if it is wrong. Email the Privacy Officer in section 15. We will respond within 30 days.

We do not charge for making a request. There is no fee for correcting information. If we refuse access or correction we will tell you why, in writing, and tell you how to complain.

14Complaints

If you think we have mishandled your personal information, contact the Privacy Officer first. We will acknowledge your complaint and respond within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

15Contact — Privacy Officer

Amin Koleini, Owner

admin@koleinibarberstudio.com
0491 679 969
Stud Road Service Road, Scoresby VIC 3179

The address above is street-level and deliberately omits the unit number. The exact address is given to a client once a booking is confirmed. It is still the postal address for any privacy enquiry or complaint — mail addressed to the street, suburb and postcode above reaches us.

16Changes to this policy

If we change this policy we will update the version number and the effective date at the top of this page. Material changes to what we collect, or to who we disclose it to, will be made before the change takes effect, not after.

This is version 1.1, effective 8 September 2026.

17Anonymity and pseudonymity (APP 2)

You never have to tell us who you are to use this site. Reading the pages, watching the clips and clicking through to book need no name, no email address and no account, and you can book without going through us at all. Where we need to answer you — an enquiry, or a marketing email you asked for — we need a real address to answer to, so anonymity is not practicable for those.

We will not claim more than that. Since 8 September 2026 the Meta Pixel described in section 9 reports your visit to Meta, and if you have a Facebook or Instagram account Meta may be able to connect it to you. That happens whether or not you ever tell us anything, so browsing here is anonymous as far as we are concerned, and not necessarily as far as Meta is. Section 9 says how to stop it.