Last Updated February 2025
We may have a funny name but there’s no funny business when it comes to dealing with your personal information; we take privacy very seriously at Who Gives A Crap. This policy explains how and why we collect, use, share and manage your personal information when you use our website or mobile site. It also explains your rights and how you can exercise them. And so much more!
Let’s be real here - we know that reading a privacy policy is not going to keep you on the edge of your (toilet) seat, but it is a very important document, and we have tried our best to keep you entertained so, please bear with us while we let you know the needful.
This website is operated by the following members of the Good Goods group:
in Australia by Good Goods Pty Ltd (ACN: 154 870 452)
in the UK/EU by Who Gives A Crap Limited (Company Number 10334484, ICO Data Protection Registration Number ZB751196)
in the US by Who Gives A Crap Inc (State File Number: 4904789)
in Canada by Who Gives A Crap Products Inc (Business number: 787615004)
You may know us as Who Gives A Crap. In this policy, we may be referred to below as “we”, “our”, “us” or “Good Goods”).
Here at Good Goods, we know how much you value your privacy while using our products at home, in your humble abode, your castle, your sanctuary (whatever you call it, you get the idea!). We want you to know that we give the same level of importance to protecting the personal information that you provide to us when purchasing our products and using our website or mobile site (whogivesacrap.org).
This Privacy Policy applies to the personal information we collect about you through our website or our mobile site or when you communicate with us.
You have rights in relation to how we use your personal information, which you can read more about below.
By using our website or mobile site, you represent that you are at least 16 years of age. We do not knowingly advertise to, or collect personal information from, any individual under the age of 16. If we become aware that we have collected personal information from you and you are under the age of 16, we will suspend any services we are providing to you and delete your personal information immediately.
For the purposes of the General Data Protection Regulation (GDPR), Good Goods is a “Data Controller”. The third parties whom we share your personal information with are “Data Processors” and in some cases “Data Controllers”. We rely on the following legal bases to process your personal information:
Processing Activity |
Lawful Basis |
Legitimate Interests |
Collecting your name, address, and contact details when you place an order |
Performance of a contract (Art. 6(1)(b)) |
N/A |
Sending you order updates and delivery information |
Performance of a contract (Art. 6(1)(b)) |
N/A |
Sharing your data with our delivery partners to fulfill your orders |
Performance of a contract (Art. 6(1)(b)) |
N/A |
Processing your payment information |
Performance of a contract (Art. 6(1)(b)) |
N/A |
Responding to your customer service enquiries |
Performance of a contract (Art. 6(1)(b)) |
We may also use some of the data related to your queries for our legitimate interests of ensuring our customer service quality standards are met |
Enabling you to partake in a prize draw or competition |
Performance of a contract (Art. 6(1)(b)) |
We may also subsequently use your entries for the legitimate interests of understanding our customer base more effectively |
Sending you marketing emails about new products or promotions (with your consent) |
Consent (Art. 6(1)(a) required under ePrivacy Directive) |
N/A |
Delivering relevant website content, advertisements and other marketing material to you and measure or understanding the effectiveness of the advertising we serve to you |
Legitimate interests (Art. 6(1)(f)) |
To study how customers use our services, to develop and grow our business, to inform our marketing strategy and to improve our offering to you (please note that where cookies are used for this purpose, this is covered separately by our Cookie Policy) |
Analysing website traffic to improve our website and user experience |
Legitimate interests (Art. 6(1)(f)) |
Improving our services, understanding customer behaviour to enhance user experience |
Using your purchase history to recommend products you might like |
Legitimate interests (Art. 6(1)(f)) |
Providing personalised recommendations, enhancing customer experience |
Analysing sales data to identify trends and develop new products |
Legitimate interests (Art. 6(1)(f)) |
Meeting customer needs, innovating sustainable solutions, furthering our mission |
Conducting customer surveys to gather feedback on existing products and identifying areas for improvement |
Legitimate interests (Art. 6(1)(f)) |
Improving product quality, enhancing customer satisfaction, developing better solutions |
Using anonymised location data to understand regional demand for specific products |
Legitimate interests (Art. 6(1)(f) ensuring appropriate safeguards for anonymization) |
Optimising product distribution, addressing regional needs for products, improving resource allocation |
Monitoring social media for mentions of our brand to assess public perception and identify areas for improvement |
Legitimate interests (Art. 6(1)(f) complying with platform terms of service and user privacy) |
Protecting our brand reputation, understanding customer sentiment, improving our products and services |
The following are the kinds of personal information we may collect from you and examples of when we might collect it. These examples don’t set out every circumstances where we might collect your personal information:
Account login and contact details such as your name, company name, email address, telephone number, shipping address, billing address (e.g., when ordering our products)
Payment or credit card information (e.g., when paying for an order).
Personal details such as age, date of birth, gender identity, marital status, sexual orientation, ethnicity, lifestyle information, household size (e.g., voluntary disclosure when completing a post-purchase survey).
Gift card recipient and friend referral details such as name, email address, personal information you may include in any personalised message you provide (e.g., when you’re buying a gift card or making a referral).
Purchase history, purchase motivations, personal preferences such as cart contents.
Social media details such as Instagram handles, profile name.
Images, photos, user generated content.
Device information such as IP address, device ID and type, device location, website activity logs, network access, device storage information, referrer, domain, browser type, language, previously visited pages on our website or mobile site, interaction with our website through click behaviour, country, time zone.
We collect this personal information from you when you:
Access and use our website and mobile site via the use of Cookies (unfortunately, not the yummy edible kind - Rather the data files placed on your device or computer to track information, see our Cookie Policy for further information), Log Files (which track actions occurring on our website or mobile site), Web Beacons, Tags and Pixels (electronic files used to record information about how you browse our website or mobile site).
Create an account, place an order with us via your account or as a guest, and/or request a refund.
Participate in our promotions.
Refer a friend.
Rate and/or review our products.
Join our mailing list.
Contact us with an enquiry or complaint.
Engage with us on social media.
Apply for a job with us.
Respond to a survey conducted by us or a third party on our behalf.
We collect this personal information from you in order to provide you with our products (which are good for the world, good for people and good for your bum!) and also to:
Process your order for our products including verifying your credit card.
Provide you with our products including arranging delivery or a return.
Notify you regarding the status of your order, including abandoned cart notifications.
Respond to your enquiry or complaint, utilising artificial intelligence (AI) and automated systems, for example, to summarise correspondence about orders and service requests, source relevant information and summarise search results in our Help Centre and provide chatbot support.
Use your image, photo, user generated content to promote our products and services, when you provide your express consent for us to do so via direct message on social media.
Verify ratings and/or reviews when you rate or review our products.
Update you with news about our store, website and products, special events, promotions and offers when you opt-in to marketing, for example, you may opt-in when making a purchase by selecting the check box to receive news and offers from us or by signing up to our mailing list.
Personalise our communications to you based on your past purchase history and other information to make your experience more relevant.
Engage with you on social media.
Screen orders for potential risk or fraud.
Review job applications and for recruitment purposes.
Improve and optimise our website and mobile site.
Collect post-purchase survey feedback to improve products, customer experience, and business operations. This helps us understand your satisfaction and identify areas for improvement.
Market research and analytics to enhance our product offering, to assess the success of our marketing and advertising campaigns, better understand our customers to guide our strategy and decision making and market our products to you.
Accounting, audit, legal and internal business purposes.
AI and automated systems
AI-powered features are used solely to enhance your experience with our products and services, and not for any other purpose without your explicit consent.
While AI assists in our customer service interactions, our team members review these interactions to ensure accuracy and provide personalised support.
We do not broker or sell your personal information to third parties on the open market.
Some marketing cookies may be considered a “sale of personal information” under the California Consumer Privacy Act (CCPA). Our US customers can turn these cookies off through the Cookie Preference Centre via the Manage Cookies link or the Do Not Sell My Info link in the footer of our website.
Where we collect your personal information for marketing purposes, we will always give you the opportunity to opt-in or opt-out to receiving such communications via email or SMS.
At Good Goods we want to communicate with you only if you want to hear from us (we don’t want to be annoying!) so if you change your mind and no longer wish to receive communications from us, you can:
Follow the opt-out (sometimes also known as “manage subscription” or “unsubscribe”) instruction in the emails we send you.
If you have opted into receiving text messages from us and wish to opt out, you can follow the opt-out instruction in that specific text message if you wish to opt-out.
Contact us at privacy@whogivesacrap.org
If you opt out of receiving marketing communications from us, your personal information will not be used for marketing, but may still be used for the other purposes described in this Privacy Policy (such as fulfillment of orders).
Now you have made it this far, we think you deserve a joke.
Why did the toilet paper roll down the hill?…
…To get to the bottom!
We also conduct targeted advertising or marketing communications which we believe may be of interest to you through search engines and social media platforms. This allows us to tailor our marketing to better suit your needs and to only display advertisements that are relevant to you.
Information on how to opt out of targeted advertising is available at the following websites:
Bing: https://advertise.bingads.microsoft.com/en-us/resources/policies/personalizedads
Facebook: https://www.facebook.com/settings/?tab=ads
Google: https://www.google.com/settings/ads/anonymous
Instagram: https://help.instagram.com/2885653514995517?helpref=faq_content
Pinterest: https://help.pinterest.com/en/article/personalization-and-data
Tiktok: https://www.tiktok.com/privacy/ads-and-your-data/en
YouTube: https://support.google.com/youtube/answer/9487666?hl=en
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/
Please note that we do not alter our website or mobile sites data collection and use practices when we see a Do Not Track signal from your browser.
We share your personal information with our offices around the globe and to third parties, where required, to ensure we are providing the best products and services to you. We may do this to perform a contract with you, based on your consent, or to pursue our legitimate interests in a way that might reasonably be expected (see table above) and which does not materially impact your rights, freedom or interests.
These third parties include:
Service providers or persons who perform functions on our behalf, for example:
Payment gateways, credit card transaction processors.
Cloud or other storage providers.
Analytics, product tracking and marketing platforms, communications platforms and contractors to process data.
AI and automated systems providers to respond to enquiries or complaints.
Logistics and operations technology platforms and systems to transmit order and other information within our supply chain.
Warehouse, distribution and freight companies to fulfil and deliver orders to you.
Government regulatory bodies and law enforcement agencies as required, authorised or permitted by law.
Our professional advisers.
A third party that acquires or intends to acquire Good Goods or its assets.
Anyone else to whom you authorise us to disclose it.
We may also share your information with our related companies overseas, including:
Australia - Good Goods Pty Ltd (ACN: 154 870 452)
UK/EU - Who Gives A Crap Limited (Company Number 10334484, ICO Data Protection Registration Number ZB751196)
US - Who Gives A Crap Limited (State File Number: 4904789)
Canada - Who Gives A Crap Products Inc (Business number: 787615004)
Hong Kong - Who Gives A Crap Limited (CR No: 2337394)
Crap Foundation Limited (ABN: 58649843694) an independent registered charity in Australia. The 50% of profits we donate goes to our water, sanitation, and hygiene (WASH) impact partners via The Crap Foundation. Find out more about our donations here.
We may also share or publish aggregate information that does not specifically identify you, such as statistical information about how our customers use our products or their demographic characteristics.
We operate globally which means that our processing of your personal data will involve a transfer of data to and from countries including Australia, Canada, Europe, United Kingdom, United States and the Philippines (where some of our teams and third party processors are located). We do this in order to provide our products and services to you, and also to process data and prepare it for processing in accordance with this Privacy Policy.
Whenever we transfer your personal data outside of the United Kingdom (UK) and European Economic Area (EEA), we ensure that a similar degree of protection is afforded to it by ensuring that at least one of the following safeguards is implemented:
We will only transfer your personal information to countries that have been deemed to provide an adequate level of protection for personal information by the UK Government or European Commission.
Where we use certain service providers, we may use either specific contracts approved by the UK Parliament or European Commission which give personal information the same protection it has in the UK or Europe or where available, we may use the Data Privacy Framework Program to enable transfers on the basis of the UK Parliament or the European Commission’s assessment of that programme as being adequate for lawful data transfer purposes.
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us. Where we make a disclosure to a third party, we require that the third party agree to comply with relevant privacy laws when processing your personal information.
Third-party service providers have their own privacy policies, which will apply when they are processing your personal information. For ease, we have set out our main providers in the below table together with a link to their privacy policies (if you would like a full list of our third-party providers to whom your personal information is provided please contact us on the details below).
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled. In particular, certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. If you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
Third Party |
Location |
Access Privacy Policy Here |
Ada – We use Ada as an answer-bot service which responds to customer queries automatically. |
Canada |
|
Amazon Redshift – We use Redshift through Amazon Web Services as an enterprise data warehouse for reporting and data analysis. |
United States |
|
Dear Systems – We use Dear Systems as our order and Inventory Management / Fulfillment system. |
United Arab Emirates |
|
Elevar – We use Elevar as a marketing signals tool to analyse user behaviour. |
United States |
|
Google Inc – We use Google to store and file our documents and we use analytics to understand how customers use our website and data analysis (information used in data analysis is anonymised). You can opt-out of Google analytics here: https://tools.google.com/dlpage/gaoptout |
United States |
|
Justuno – We use Justuno for website popups and to personalise your experience when using our website or mobile site. |
United States |
|
Klaviyo – We use Klaviyo as a segmentation and email marketing tool. |
United States |
|
Loqate – We use Loqate to assist you to enter your location and validate your address. |
United Kingdom |
|
MentionMe – We use MentionMe to power our friend referral program. |
United Kingdom |
|
Meta – We use Meta analytics to understand how customers use our website and data analysis (information used in data analysis is anonymised) |
United States |
|
MineOS – We use MineOS as a privacy platform to manage data subject rights |
Israel |
|
Oracle Netsuite – We use Netsuite as our order and Inventory Management / Fulfillment system. |
United States |
|
ReCharge – We use the ReCharge App through Shopify when you purchase a subscription for our products to auto-bill the credit card you provide and process your order. |
United States |
|
Repeat - We use Repeat to help you reorder your favourite products. |
United States |
|
Rise.ai – We use Rise.ai to provide you with our gift cards. |
Israel |
https://d1wr3t1or162si.cloudfront.net/website/Privacy%20Policy.pdf |
Shopify – We use Shopify to power our online e-commerce store and provide our products and services to you. Your personal information is stored through Shopify’s data storage, databases and the general Shopify application housed on a secure server behind a firewall. If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). |
Canada |
|
Snowflake – We use Snowflake as an enterprise data warehouse for reporting and data analysis. |
United States |
|
Stripe – We use Stripe for payment processing and secure storage of customer payment information (including encryption). |
United States |
|
Unbounce – We use Unbounce to host some of our web pages. |
Canada |
|
Yotpo – We use Yotpo to enable you to review our products. |
United Kingdom United States |
|
Zendesk – We use Zendesk as our customer service/ helpdesk platform where all customer queries are received and responded to. |
United States |
https://www.zendesk.com/company/customers-partners/privacy-policy/ |
Once you leave our website or mobile site or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our Terms of Service.
While we have set out your rights throughout this Privacy Policy, we understand that sometimes you just need quick and easy access to the relevant info (similar to when you are reaching frantically for that last emergency loo roll - don’t worry, we have all been there!)
To ensure you are fully informed and prepared for anything, here are your rights:
You may request that we disclose to you the personal information that we hold about you, including receiving a copy and also details of our processing activities such as what we collect, how we use it and any third parties with whom we share it.
You may request your personal information in a portable format (structured, commonly used and machine-readable format) so that you can transmit your personal information to another entity, or you may request that we transmit it to another data controller.
We may limit or reject your request in certain cases, including without limitation where the burden or expense of providing access would be disproportionate to the risks to your privacy in the case in question, where the rights of other persons would be violated or as required by law.
You may make a request via this Manage My Privacy link or on our website footer.
While we take reasonable measures to ensure that your personal information is complete and up to date, please notify us if your personal information held by us is inaccurate or incomplete.
You may update or correct your personal information by logging into your account or contacting us with your request via the contact details below.
You may object to all or part of your personal information being processed by us in certain circumstances, including processing for the purposes of direct marketing or market research, or where we do not have a lawful or contractual basis to process your personal information.
You may restrict the way we process your personal information in certain circumstances, including where you are contesting the accuracy of the personal information we hold, where we do not have a lawful or contractual basis for processing, to oppose erasure where we no longer need your personal information but you may have a claim or legal proceedings on foot, or if you are exploring your right to object.
You may request that we delete your personal information that we hold, that is, you can request that we forget you (but we will miss you “insert sad face emoji”!). If you make a request, we will delete your personal information that we hold except for information we are allowed or required to retain by law.
You may make a request via this Manage My Privacy link or on our website footer.
You may withdraw your consent or opt-out of receiving marketing communications from us at any time. If you withdraw your consent or opt-out, we will no longer send you marketing communications; however, we will still communicate with you where it is necessary to complete our contract with you, for example, to fulfil your order for our products.
When you exercise any of your rights in relation to your personal information, we will continue to provide you with, insofar as is possible, the same high standard of service as all our customers experience.
However, you acknowledge that where you do not supply certain information requested by us or request its deletion, we may be delayed or prevented from finalising your order or satisfying your request or enquiry. For example, if you do not provide us with a delivery address, we cannot deliver our product to you until we have an address to deliver to.
If you have a complaint about the way in which we handle your personal information, please contact us via the contact details below.
We take privacy seriously here, so when you contact us to make an enquiry or to exercise your rights, we just want to make sure that we're talking to the right person and this means that we may ask you some additional questions. We are sorry if this causes any inconvenience, but it's an important step in making sure your account and personal information remains secure. Thanks in advance for your patience.
We take all reasonable security and organisational measures to make sure your personal information held by us is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
We use Secure Sockets Layer (SSL) technology (our online ordering system is the industry standard for encryption technology) to protect your online order information (well that’s fancy!). SSL encrypts all information including your credit card and all personal information passed from you to our checkout and we follow all PCI-DSS requirements. Encryption provides you with security and peace of mind when your browser and local network supports the use of encrypted data transmissions. While we will do our bit, we suggest that you also take appropriate security precautions, in particular when you access the internet via public Wi-Fi networks or shared computers.
We must emphasise that no method of transmission over the internet using industry standard technology is 100% secure. Therefore, we cannot guarantee the absolute security of your personal information.
If we ever experience unauthorised access, disclosure or use of your personal information, rest assured that we have processes in place and will notify you and the relevant government body in accordance with relevant laws.
We will only keep your data for as long as is necessary for the purpose for which it was collected (in order to provide you with our products and services and otherwise for the purposes set out in Why we do it above), subject to satisfying any legal, accounting or reporting requirements.
At the end of any retention period, your data will either be deleted completely or anonymised (for example, by aggregation with other data so that it can be used in a non-identifiable way for statistical analysis and business planning).
We may make available on our website or mobile site certain opportunities for you and other users to share information online such as on message boards, social media, blogs. Please be aware that whenever you voluntarily disclose personal information online, that information becomes public and can be collected and used by others. We have no control over, and take no responsibility for, the use, storage or dissemination of such publicly disclosed personal information. By posting personal information online in public forums, you may receive unsolicited messages from third parties.
Sometimes our website or mobile site may contain a link to third party websites. We are not responsible for the content or material contained in, or obtained through, any third-party website or for the privacy practices of the third-party website. We suggest that you review the privacy policy of each website or mobile site that you visit.
Privacy laws and our practices change over time and may result in changes to our Privacy Policy. We reserve the right to modify or vary this Privacy Policy at any time.
Any changes to this Privacy Policy will be effective upon our publication on our website and will replace any other privacy policy published by us to date. In all cases, your continued use of our services or our website or mobile site after the publication of any modified privacy policy indicates your acceptance of the updated Privacy Policy.
Any material changes to this Privacy Policy will be notified to you in a manner that we consider appropriate such as via email (if we have your contact information) or a pop-up when you access our website or mobile site.
If you have any enquiries or complaints about your account (including updating your personal information), you can contact our customer service team at wedo@whogivesacrap.org
If you have any questions or complaints about how we handle your personal information, you can contact our Privacy Officer via email at privacy@whogivesacrap.org
You can request a copy of your data or deletion of your data via this Manage My Privacy link or on our website footer.
Or alternatively write us a love letter and send it to:
Australia - Good Goods Pty Ltd at Suite 816, 585 Little Collins St, Melbourne, Victoria 3000
UK/EU - Who Gives A Crap Limited at c/o MHA, 6th Floor, 2 London Wall Place, London, EC2Y 5AU, UK
US - Who Gives A Crap Inc at 8605 Santa Monica Blvd, PMB 62559, West Hollywood, California 90069-4109
Canada - Who Gives A Crap Products Inc at c/o Kornfeld LLP, 1100 One Bentall Centre, 505 Burrard Street, Box 11, Vancouver, BC V7X 1M5
We always endeavour to reply to emails as soon as we can and at a minimum, within 14 days. Replies to mail will be processed slower and subject to postal delivery times and delays. We will always endeavour to resolve any query or complaint to your satisfaction.
Our Privacy Policy has been prepared in accordance with relevant legislation in the locations we operate. If you would like further information regarding privacy laws relevant to you or are not satisfied with the way in which we handle your enquiry or complaint, you can locate further information in:
Australia via the Office of the Australian Information Commissioner (OAIC)
UK via the Information Commissioner’s Office (ICO)
EU via the European Data Protection Supervisor (EDPS)
US via local data protection authority’s websites
Canada via the Office of the Privacy Commissioner of Canada (OPC)
And that’s a wrap, we know it was tough going there but we appreciate your persistence (kudos to you!) for making it to the very end of this Privacy Policy. Thank you for reading and be sure to visit us again soon!