Website privacy policy
Last updated
This policy covers boxmaxxing.com, our link pages (boxmaxxing.com/ig, /tt, /links and /go/…) and the contact form.
Using the app? The Boxmaxxing app privacy policy covers the app itself. Buying merch? Shopify processes your order under the store’s privacy policy and Shopify’s own privacy policy.
Who we are
Boxmaxxing is made by METATENSOR PTY LTD (“Metatensor”, “we”, “us”), North Tce, Adelaide SA 5000, Australia. We decide how the information described here is used. Under the GDPR and UK GDPR, we are the controller.
We don’t sell your personal information, and we don’t use it for ad targeting.
What we collect
Visiting the website
Our host, Cloudflare, sees the pages you request, the site that sent you, your device and browser type, and your IP address (which gives an approximate location, such as your country) when it delivers the site. It keeps short-lived server logs, which include IP addresses, for security and debugging.
Opening a Boxmaxxing link
When you open one of our links (boxmaxxing.com/ig, /tt, /links or /go/…, for example from Instagram, TikTok or a QR code), we record the visit and which buttons you tap on that page:
- the time, which link, and any post code or campaign tags (UTM parameters) in the URL
- where you came from: the app you opened the link in (such as Instagram or TikTok) or the referring website
- your device type (iPhone, Android or computer) and your browser’s language
- your approximate location: country, region, city and time zone, worked out from your IP address by our host, Cloudflare. We never use GPS or ask for your location.
- a random ID for that page visit, and your IP address and browser type hashed together with a secret key that changes every day, so we can count unique visitors per day. We never store the raw IP address or the full browser user agent, and these pages set no cookies.
The store buttons carry a campaign tag (which link or post you came from) to the App Store or Google Play, so Apple and Google can report installs by campaign; the tag doesn’t identify you. When a link sends you to the app stores through AppsFlyer OneLink, your browser goes through AppsFlyer on the way, and AppsFlyer records that click (including your IP address and user agent) so the app can tell which link led to an install.
Buying merch
The merch store is run by its own operator, named in the store’s Legal notice, which is responsible for your order data. Checkout runs on Shopify. It collects your name, email, shipping address, phone number if you give one, the items you order and what you paid, under the store’s privacy policy and Shopify’s privacy policy. We never see or store your full card number. Printful makes and ships your order, so it receives your name, address and order details.
Support requests
What you send us by email or on the contact form: your email address, your message, and any details you include, such as an order number.
How we use it
- To provide the merch store and support: take and fulfil orders, send order emails and answer your requests. (Legal basis: contract.)
- To measure and improve our links: count link visits and taps, and see which posts, platforms and places bring people to the app. (Legal basis: legitimate interests. These counts use no cookies.)
- To keep things secure: stop spam, bots and fraud, rate-limit forms and keep audit logs. (Legal basis: legitimate interests.)
- To meet legal duties: tax records, consumer law, and responding to lawful requests. (Legal basis: legal obligation.)
We don’t make automated decisions that have legal or similarly significant effects on you.
International transfers
We’re based in Australia, and our providers may process data in the USA, the EU and elsewhere. Where the law requires, we rely on recognised safeguards such as the EU Standard Contractual Clauses and the UK Addendum.
How long we keep it
| Data | Kept for |
|---|---|
| Link visits and taps (/ig, /tt, /links, /go) | 400 days. IP addresses are stored only as a daily-rotating hash; no raw IP or user agent. |
| Server logs | Days to weeks, depending on our hosting plan |
| Shop orders and invoices | Kept by the store’s operator as tax and accounting law requires (see the store’s privacy policy) |
| Support requests (contact form and email) | Up to 24 months after the request is closed |
| Cookie choice | 180 days |
Your rights
Depending on where you live (including under the Australian Privacy Principles, the GDPR and UK GDPR, and US state privacy laws), you can ask to access, correct, delete or get a copy of your personal information, object to or restrict some processing, and withdraw consent at any time. For information from the website, our links, the contact form or a shop order, email sup@boxmaxxing.com and we’ll reply within the time the law requires. We may need to confirm it’s you first.
For your Boxmaxxing app account, including deleting it, see the app privacy policy, or email sup@metatensor.net.
You can complain to the Office of the Australian Information Commissioner (OAIC), your local EU data protection authority, or the UK Information Commissioner’s Office (ICO). Please contact us first so we can try to help.
Children
Boxmaxxing isn’t directed to children. You must be at least 16 (or the age of digital consent where you live) to buy from the shop. The app has its own age rules in its privacy policy. If we learn we hold a child’s personal information, we delete it.
Security
Data is encrypted in transit. Access to our analytics and accounts is limited to the people who need it, with two-factor sign-in. No system is perfectly secure, but we design for least access.
Changes
We’ll update this policy when our services change and revise the date at the top. We’ll flag material changes on the site.
Contact
Email sup@boxmaxxing.com, or write to METATENSOR PTY LTD, North Tce, Adelaide SA 5000, Australia.