Roll Brazilian Jiu Jitsu

Privacy Policy

Last updated 6 September 2026

Roll BJJ is a registered business name of Joel Nathan Shapcott (ABN 39 683 259 554), a sole trader in Queensland, Australia. This policy covers rollbjj.com.au and everything you can do on it. It is written in plain English on purpose — if anything here is unclear, ask and we will explain it.

Our commitment

As a small business we fall below the threshold at which the Privacy Act 1988 (Cth) applies automatically. We have chosen to handle your information as though it did apply, and to follow the Australian Privacy Principles. That is a commitment we are making to you, and the rest of this page describes how we keep it.

What we collect

Only what the store needs to work. Specifically:

  • If you order: your name, email, delivery address, phone number, what you bought, and the order’s payment status.
  • If you create an account: your email, name, saved addresses, order history, and your password stored only as a cryptographic hash — we never hold the password itself and cannot read it.
  • If you start a checkout but don’t finish: your email, the items in your cart, and your IP address. This is how the store can email you a link back to an unfinished order, and how we spot fraudulent and automated attempts.
  • If you use the contact form: your name, email, message, any order reference you give, and a one-way hash of your IP address used to limit spam. The hash cannot be turned back into your IP.
  • If you apply for a wholesale account: your gym or business name, contact name, email, phone and ABN.
  • If you subscribe to the newsletter: your email address and where you subscribed from.
  • If you leave a review: the display name you choose, your rating and your review text, all of which are published.
  • When you browse: anonymous usage statistics through Google Analytics — pages viewed, roughly where in the world you are, and what kind of device you used.

Your card details

Card numbers never reach our servers and we could not see them if we wanted to. Payments are handled entirely by Stripe, who are PCI DSS Level 1 certified. What we receive back is a payment reference, whether it succeeded, and the brand and last four digits so that you and we can tell one payment from another.

Who else sees it

We do not sell your personal information, and we do not share it for anyone else’s marketing. It goes to exactly three kinds of people:

  • Stripe — to take payment and process refunds.
  • Resend — to send order confirmations and the other emails described below.
  • Google Analytics — for anonymous usage statistics.
  • Australia Post and couriers — the name, address and phone number needed to deliver your parcel.

We will also disclose information where the law requires it — for example a court order — and we will tell you if that happens unless we are prohibited from doing so.

Where your information is stored

The store’s database and all order records are hosted on a server in Brisbane, Queensland. Your information stays in Australia except where it reaches the providers above: Stripe, Resend and Google Analytics are United States companies and process data on infrastructure outside Australia.

We do not send your information overseas for any other reason, and we have taken reasonable steps to satisfy ourselves that each of those three handles it to a standard comparable to the Australian Privacy Principles. You should know that once information is held overseas, Australian law may not be enforceable against that provider directly.

Emails we send

There are four, and you can stop all but the first:

  • Order emails — confirmations, shipping notifications, refunds. These are part of the transaction, so they are not marketing and cannot be unsubscribed from while an order is live.
  • Unfinished checkout reminders — one email if you enter your address and don’t complete the order. We do not send it if you have already bought, or if you have unsubscribed.
  • Review requests — one email a fortnight after your order arrives, asking what you thought.
  • The newsletter — only if you asked for it.

Every one of these carries an unsubscribe link that works immediately and without a login. Unsubscribing stops the marketing emails; it does not stop the transactional ones for an order already in progress.

Cookies

We do not use advertising or cross-site tracking cookies, which is why the site doesn’t ask you to dismiss a consent banner. What is set:

  • A sign-in cookie, if you have an account and are signed in.
  • Your cart, so it survives a refresh.
  • Google Analytics cookies, which measure usage.

Blocking cookies in your browser will stop the analytics ones. Blocking them all will break signing in and the cart, because those are what the cookies are for. You can opt out of Google Analytics specifically with Google’s opt-out add-on.

How long we keep it

Order and payment records are kept for at least five years, because the ATO requires business records to be retained that long. Your account, saved addresses and newsletter subscription are kept until you ask us to remove them. Unfinished checkouts and contact messages are kept while they are still useful for support and fraud prevention.

We do not delete personal information automatically on a timer. If you want yours gone, ask — see below.

Keeping it safe

The site is served over HTTPS only, and is not reachable any other way. Your password is stored as a bcrypt hash and never as text. Sign-in attempts are rate-limited so a password cannot be guessed by brute force. Access to customer data is limited to a small number of administrator accounts, and none of them can be opened with a password alone: signing in requires either a passkey, or a password together with a code from an authenticator app. An administrator who has set up neither cannot reach the admin area at all. The store is backed up nightly, and a second copy is pulled to separate hardware in a different location, so a failure of the server cannot take the backups with it. Those copies stay in Australia.

No system is perfectly secure and we will not pretend otherwise. If a breach ever occurred that was likely to cause you serious harm, we would tell you and the Office of the Australian Information Commissioner promptly.

Access, correction and deletion

You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Use the contact form and we will reply by email. We respond within 30 days, and there is no charge.

If you have an account you can see and change most of it yourself under your account. Deleting an account does not remove the order records we are required to keep, but it does remove everything else.

Complaints

If you think we have mishandled your personal information, tell us first — send it through the contact form and we will investigate and respond within 30 days. If you are not satisfied with how we handled it, you can take the complaint to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Children

We sell kids’ gis and belts, but the store is intended to be used by adults. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their details, tell us and we will remove them.

Changes

If this policy changes we will update the date at the top of this page. If a change materially affects how we use information we already hold about you, we will email you about it rather than relying on you noticing.