1.About this policy
Tyreo Pty Ltd trading as Treadivo (Treadivo, Tyreo, we, us or our) operates an online tyre marketplace and coordinates tyre supply, delivery, fitting and related services through independent suppliers, fitters, alignment providers and couriers.
Treadivo is the seller and merchant of record for customer orders placed through Treadivo. We remain the primary contact for order administration, payments, refunds, warranties, complaints and privacy requests. This policy explains how we collect, hold, use and disclose personal information. Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to us, we comply with them. We otherwise handle personal information in accordance with the commitments in this policy. Applicable law prevails to the extent of any inconsistency.
2.Personal information we collect
The information we collect depends on how you use Treadivo and may include:
- your name, email address, telephone number, billing details and delivery or fitting location;
- account identifiers, authentication records, security information and information provided through an enabled sign-in provider;
- vehicle and tyre details, including vehicle make, model, year, series, variant, registration, tyre or wheel size, tyre placard information, modifications and relevant use requirements;
- enquiry, quote, order, invoice, receipt, payment-status, refund and dispute information;
- appointment, dispatch, attendance, fitting, alignment and communication records;
- photographs, measurements, condition records and other proportionate evidence needed for compatibility, safety, completion, complaints, warranties or recalls;
- website, device and network information, such as IP address, browser type, device information, pages requested, referrer, cookies, local storage, session identifiers and security logs;
- marketing preferences, consent and unsubscribe records; and
- for fitter or partner applicants, identity, contact, business, capability, service-area, licence, qualification, insurance, banking and onboarding information.
We do not intentionally collect sensitive information unless it is reasonably necessary and collection is permitted by law, including with consent where required. Please do not include health information, identity documents or other sensitive or unnecessary information in free-text fields or images unless we request it and explain why.
You may contact us anonymously or using a pseudonym where lawful and practicable. This is generally not practicable for orders, payments, fittings, safety matters, account access or individual privacy requests.
3.How we collect information
We may collect personal information:
- directly from you through our website, checkout, account registration, application forms, telephone, email, support and fitting interactions;
- from a person you authorise to place an order, communicate with us or present a vehicle for you;
- from suppliers, fitters, couriers, payment providers and other service providers involved in your order or interaction;
- automatically through cookies, local storage, server logs and similar technologies; and
- from manufacturers, regulators, recall databases, public sources or other third parties where lawful and reasonably necessary.
If we receive unsolicited personal information that we could not lawfully have collected, we will take reasonable steps to destroy or de-identify it where lawful and reasonable.
4.Why we use personal information
We may collect, hold, use and disclose personal information to:
- respond to enquiries and provide quotes, compatibility information, accounts and checkout services;
- accept payment, create and administer orders, source and dispatch tyres, arrange fitting or alignment and communicate with customers or authorised drivers;
- verify identity, prevent fraud, protect accounts and investigate security incidents;
- support safe and compatible fitting and maintain proportionate job and completion evidence;
- issue receipts, process refunds, handle complaints, administer warranties and provide remedies required by law;
- manage product-safety matters and recalls;
- assess, onboard and manage fitters, suppliers and other business partners;
- maintain, troubleshoot and improve our services;
- comply with legal, tax, accounting, regulatory, insurance and court obligations and establish, exercise or defend legal claims; and
- send marketing where permitted and subject to the choices described in section 9.
We use or disclose information for the purpose for which it was collected, a related purpose you would reasonably expect, with consent, or as otherwise required or permitted by law. We do not sell personal information.
If required information is not provided, we may be unable to create an account, process an order or payment, arrange safe fitting, assess an application, respond to a request or provide an individual remedy. Optional marketing choices do not affect an order or remedy.
5.Payments
Stripe provides our payment interface and collects full payment-method details, including card details, directly. Treadivo does not receive or store full card numbers in its systems.
We receive and retain the transaction and order information needed to administer the purchase, such as customer and order references, amount, currency, payment status, payment or session identifiers, refunds and disputes. Stripe handles payment authorisation, fraud checks, payment-method information and its own legal recordkeeping under its privacy terms. Some server-side Stripe requests may pass through Lovable's connector infrastructure.
6.Who we share information with
We may disclose relevant personal information to:
- Netlify for website hosting, content delivery, server functions, security and operational logging;
- Supabase for database hosting, authentication, session handling, application interfaces and operational data storage;
- Lovable for managed transactional email, connector services and enabled diagnostic support;
- Stripe for payments, fraud prevention, refunds, disputes and transaction records;
- Google for an enabled Google sign-in service and delivery of Google Fonts resources;
- suppliers, fitters, alignment providers, couriers, manufacturers and distributors for stock, delivery, appointments, fitting, technical support, job evidence, warranties and recalls;
- insurers, professional advisers, auditors and a purchaser or successor involved in a controlled business transaction; and
- regulators, law-enforcement bodies, courts and other persons where required or permitted by law.
We aim to provide each recipient only the information reasonably needed for its role. Suppliers, service partners and other partners must not use Treadivo customer information for their own marketing unless they independently obtain valid permission and comply with applicable law.
7.Overseas processing and disclosure
Some service providers and their subprocessors use infrastructure or support teams outside Australia. Depending on the service configuration, support activity and transaction route, personal information may be stored in or accessed from Australia, the United States, countries in the European Economic Area or the United Kingdom, India, and other countries in which the relevant provider or its subprocessors operate. This may include Netlify, Supabase, Lovable, Stripe and Google. Not every interaction involves every provider or country, and provider locations may change. Current provider information is available from:
- www.netlify.com/privacy/
- supabase.com/docs/guides/platform/regions
- lovable.dev/privacy
- stripe.com/legal/service-providers
- policies.google.com/privacy
Where APP 8 applies, we take reasonable steps to address an overseas recipient's handling of personal information unless a statutory exception applies. This section is not consent to avoid APP 8 accountability and does not waive any statutory right.
8.Cookies, local storage and website logs
Our website uses cookies, local storage, authentication tokens and server logs for sign-in, session continuity, security, fraud prevention, checkout, preferences and core operation. These technologies may collect IP address, browser and device information, requested pages, referrer, timestamps and session or security identifiers.
Our website requests Inter font resources from Google Fonts. A visitor's browser therefore sends Google the network and request information needed to return those resources.
You can use browser controls to block or delete some technologies, but blocking technologies required for account security or checkout may prevent those functions from working.
9.Marketing
We send commercial electronic marketing only with consent or another basis permitted by the Spam Act 2003 (Cth). Marketing choices are optional and do not affect an order, refund, complaint or other remedy. Marketing messages will identify Tyreo Pty Ltd trading as Treadivo, include current contact details and provide a functional unsubscribe method. We will action unsubscribe requests within the period required by law. Necessary order, appointment, receipt, safety, recall, complaint and account-security messages are not marketing messages.
10.Job photographs and service records
Service Partners may create proportionate photographs, measurements and other service records for safety, quality, handover, payment validation, complaints, warranties, recalls and legal records. Service Partners should avoid faces, personal belongings, documents, precise background locations and unrelated vehicle areas where reasonably practicable.
We will not use identifiable job photographs in advertising, social media or promotional material without separate permission. Refusing promotional use does not affect an order, complaint or remedy. A completion record does not waive a right relating to a latent defect, unsafe or negligent fitting, vehicle damage or the Australian Consumer Law.
11.Security
We take reasonable technical and organisational measures appropriate to the circumstances to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, authentication, encryption where appropriate, data minimisation, logging, provider controls, staff procedures, secure deletion and incident response.
No internet transmission or storage system can be guaranteed completely secure. Where the Notifiable Data Breaches scheme applies, we will assess a suspected eligible data breach and notify affected individuals and the Office of the Australian Information Commissioner when required.
12.Retention and deletion
We retain personal information only for as long as reasonably needed for the purposes described in this policy, subject to any longer period required by law or reasonably needed for an active safety, recall, support, complaint, dispute, investigation, insurance, legal or regulatory matter.
Our general retention approach is:
- order, payment-metadata, tax, accounting, receipt, refund, warranty, complaint, safety and recall records: generally seven years after the transaction is completed or the record is closed;
- unsuccessful or withdrawn fitter applications: generally 12 months after the final decision or withdrawal;
- ordinary enquiries that do not become an order, complaint or active support matter: generally 24 months after the last substantive contact;
- account-profile and saved-vehicle information not subject to another retention requirement: deleted or de-identified within a reasonable period after a valid account-closure request; and
- marketing consent, withdrawal and minimum suppression records: retained for as long as reasonably needed to evidence and honour the choice.
When information is no longer needed for a permitted purpose and is not required to be retained, we take reasonable steps to destroy it or ensure it is de-identified. If we cannot fulfil a deletion request because a record must or may lawfully be retained, we will explain the applicable reason.
13.Access and correction
You may ask for access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also request account closure or ask us to delete or de-identify information, subject to lawful retention requirements.
Contact us using the details in section 16. We will ask only for information reasonably needed to verify identity and protect information from unauthorised access. We will respond within a reasonable period. If we refuse access, correction or deletion, we will provide reasons where required and explain how to complain. We do not charge for making an access or correction request or for correcting information. Any lawful charge for providing access will be limited to reasonable costs and explained in advance.
14.Privacy complaints
Send a privacy complaint using our Contact Us form or email info@treadivo.com.au. Describe the issue and provide enough information for us to investigate. We will acknowledge the complaint within two business days and aim to provide a substantive written response within ten business days. If we reasonably need more time, we will explain why and provide an expected response date and reasonable updates.
If the Privacy Act applies and you remain dissatisfied after giving us a reasonable opportunity to respond, you may complain to the Office of the Australian Information Commissioner at
www.oaic.gov.au/privacy/privacy-complaints
15.Changes to this policy
We may update this policy to reflect changes in law, providers, technology, services or information-handling practices. Each published version identifies its version number and effective date. We will give reasonable notice of a material change where practicable and obtain consent where required. A new version does not retrospectively authorise an incompatible use of information already collected or remove an accrued right.
16.Contact us
Tyreo Pty Ltd trading as Treadivo
ACN 700 631 849 | ABN 64 700 631 849
3 Keevil Lane, Brookdale WA 6112
Website: treadivo.com.au/
Contact form: treadivo.com.au/contact
Email: info@treadivo.com.au
Telephone: +61 410 000 039
