Privacy Policy
Last updated: April 2026
This Privacy Policy explains how Sankranti Australia ("we", "us", "our") collects, uses, stores, and discloses personal information about you when you visit sankrantiaustralia.com.au, dine at one of our Melbourne CBD locations, submit an enquiry, or engage us for catering. We are bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.
1. What personal information we collect
We may collect the following kinds of personal information from you:
- Contact details — your name, email address, and phone number when you submit the contact or catering form.
- Catering enquiry details — number of people, delivery requirement, delivery address, and any dietary or event notes you provide.
- Usage data — pages visited, time on site, device type, approximate location (city), and referrer, collected by Google Analytics only if you accept analytics cookies.
- Cookies — a small flag in your browser remembering whether you consented to analytics, and (for admins) a session indicator.
- Optional details — anything else you voluntarily provide in free-text fields (e.g. messages, feedback).
We do not collect sensitive information (health, religion, racial origin, political views, etc.) and we do not require you to create an account to browse the site or view the menu.
2. How we collect personal information
- Directly from you — when you fill out the contact form on the website.
- From your device — cookies and Google Analytics, only after you click “Accept all” on the cookie consent banner.
- From email replies — if you write to info@sankrantiaustralia.com.au, we receive the metadata your mail client includes (name, email, subject, timestamps).
3. Why we collect it
We collect personal information to:
- Respond to your enquiry, reservation request, or catering quote.
- Deliver catering orders to the address you provide.
- Improve the website and understand which pages are most useful.
- Comply with our legal obligations, including tax, accounting, and consumer-law records.
- Protect our legitimate business interests (fraud prevention, security, and record-keeping).
We do not use personal information for automated decision-making or profiling, and we do not sell or rent it to third parties under any circumstances.
4. Who we share it with
We only share your personal information with the following categories of recipients, and only as required to provide the service you requested:
- Email service provider (Microsoft 365 / GoDaddy) — transmits the contact form submission to our info@ mailbox.
- Google Analytics (Google LLC, United States) — if you accept analytics cookies, anonymised usage data is processed by Google under its own Privacy Policy.
- Hosting provider — server logs (IP address, timestamp, URL requested) are retained temporarily for security and debugging.
- Payment processors — not applicable at this time. We do not take online payments on this website.
- Law enforcement — only if we are legally compelled by a valid subpoena, warrant, or court order.
Some of our service providers (Google, hosting) may store data in data centres outside Australia, including in the United States and the European Union. Under APP 8.1 we take reasonable steps to ensure these providers handle your information consistently with the Australian Privacy Principles.
5. Cookies and tracking
We use two categories of cookies and browser storage on this website:
- Essential — small values stored in your browser to remember whether you accepted cookies, whether you are logged into the admin panel, and form progress. These are always active.
- Analytics — Google Analytics (measurement ID G-NE0DREP2ZG) tracks page views, session duration, and referring URL with your IP address anonymised. These are loaded only after you click “Accept all” on the consent banner.
You can withdraw analytics consent at any time by clearing the sa_consent entry in your browser's local storage and reloading the page. You can also opt out of Google Analytics globally via Google's opt-out browser add-on.
6. How we store and protect your information
We take reasonable steps, consistent with APP 11, to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Measures include:
- Encryption in transit — the website is served over HTTPS with TLS 1.2+.
- Encryption of email transport — our mail server uses STARTTLS or implicit TLS for all SMTP connections.
- Access control — only authorised staff can access the admin panel, and login requires a password stored in an environment variable, not in source code.
- Minimal retention — contact enquiries are retained only as long as needed to respond to you, plus a reasonable period for record-keeping (typically 2 years), after which they are deleted.
- No payment card storage — we never collect or store credit-card numbers or banking details on this website.
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but we will notify you and the Office of the Australian Information Commissioner (OAIC) as required under Part IIIC of the Privacy Act in the event of a notifiable data breach.
7. Your rights under the Privacy Act
You have the right, under APP 12 and APP 13, to request:
- Access — a copy of the personal information we hold about you.
- Correction — to correct information that is inaccurate, out-of-date, or incomplete.
- Deletion — to have your information deleted from our records where practical and lawful.
- Withdrawal of consent — to opt out of marketing communications or withdraw analytics consent at any time.
- Complaints — to lodge a complaint about how we have handled your information.
To exercise any of these rights, email us at info@sankrantiaustralia.com.au. We will respond within 30 days, which is the timeframe set by the OAIC. There is no charge for reasonable requests.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
8. Children's privacy
This website is intended for a general audience and is not directed at children under 15. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
9. Links to other websites
Our website may link to third-party sites (Google Maps, Facebook, Instagram, delivery platforms). We are not responsible for the privacy practices of those sites. Please review their privacy policies before providing any personal information.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent change. For material changes, we will display a notice on the homepage for at least 30 days.
11. Contact us
If you have questions about this Privacy Policy or how we handle your personal information, please contact:
Sankranti Australia — Privacy OfficerEmail: info@sankrantiaustralia.com.au
Phone: 0401 380 977
Post: B53 750 Bourke Street, Melbourne VIC 3000
This Privacy Policy was last reviewed in April 2026 and reflects our obligations under the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles.