Skip to main content
Shopping as
Showing the consumer viewOpen a business account

Security

What we actually do to protect your information — and what we do not claim.

Your card details never reach us

Card numbers go straight from your browser to our payment provider. We receive only a token — a reference that lets us take the payment you authorised and refund it later, and that is useless to anyone else.

This is not just a policy. Our checkout is built so that card data cannot be sent to our servers: the code that talks to the payment provider will refuse anything that looks like a card number.

Your data inside our systems

  • All traffic to this site is encrypted in transit.
  • Staff access is granted by role. Someone who processes returns does not thereby get to change prices, and someone who manages the catalogue cannot open a credit account.
  • Actions that move money, change an order, or decide a return or an account are recorded with who did them and why. Those records are append-only.
  • Looking up your own order, return or support case requires both the reference and the email address it was created with. A reference alone is not enough, because references can be guessed.

What we are not claiming

We hold no security certification, and we are not going to imply one with a badge. If that changes, this page will say which certification, issued by whom, and when it expires.

No system is perfectly secure. If a breach ever occurs that is likely to cause you serious harm, we will tell you and notify the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.

Reporting a security issue

If you have found a vulnerability, please tell us at info@gazaltech.com.au before disclosing it publicly, and give us a reasonable chance to fix it.

We will acknowledge your report, keep you posted, and we will not pursue action against anyone who reports a genuine issue in good faith without accessing other people’s data or degrading the service.

We do not currently run a paid bug bounty. We will credit you if you would like us to.

What you can do

  • Use a password you do not use anywhere else.
  • Be wary of any message asking you to “confirm” card details. We will never ask you for your full card number, and never by email or phone.
  • If something looks wrong on your account, tell us straight away.