Privacy policy.
Last updated: 30 September 2026
1. Who We Are
Moltiply Web Studios ("we", "us") designs, builds, and hosts websites for Australian small businesses. This policy explains what personal information we collect across moltiply.com.au, our studio platform, and the client websites we host — and how we handle it under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Information You Give Us
When you enquire or become a client, we collect what you provide directly: your name, email address, phone number, and details about your business — services, trading hours, service area, photos, and anything else you share so we can design and run your website. Our contact form uses Cloudflare Turnstile to filter out spam.
If you sign a quote electronically, we keep a signature audit record — the signed document, the time, and the IP address and browser it was signed from — because that record is the legal evidence of the agreement.
3. Information Collected on Client Websites
The websites we host belong to our clients. When you fill in a form, request a booking, place an order, subscribe to a newsletter, or call a tracked phone number on a client's website, the details you submit — such as your name, contact details, delivery address, or the time you called — are passed to that business and stored on our platform on their behalf.
Businesses may also use our platform to contact you about your booking, order, or enquiry — confirmations, reminders, receipts, and replies — and may ask you to leave a review or send you a newsletter you subscribed to. Newsletter emails always include an unsubscribe link.
Some pages on hosted sites embed third-party content, such as Google Maps or videos. Loading an embed shares your IP address with that provider, as it would on any website.
If you have questions about how a business uses your information, contact that business first: their privacy practices are their own. We act as their website provider.
4. Website Analytics
Our hosting includes privacy-first analytics. Basic visit counting is cookieless: visits are counted using an anonymised identifier that rotates daily, and your IP address and browser details are used to compute it but are not stored — we keep only coarse derived data such as country and device type. Optional engagement analytics only run after you accept a consent banner on that site, and we honour Global Privacy Control signals as a decline. We never track anyone across different websites.
A client's site can use the same tools — Google Analytics, Google Ads or the Meta Pixel. Google's tags run in Consent Mode there too, as described above; the Meta Pixel loads only after you accept that site's consent banner. If you accept and then send a form, the site may also send Meta a one-way coded (hashed) version of your contact details from our servers to measure ad performance; if you decline, it sends nothing. Separately, when you arrive at a client's site from one of their ads, the ad click identifier can be reported back to Google or Meta with the value of a resulting sale, which does not depend on your cookie choice.
We also advertise our own studio. Where we are running ads, the same measurement applies to this site: if you arrive here from one of our ads, the click identifier in that link is stored with the enquiry you send us, along with any campaign labels in the web address and the site that referred you, and if that enquiry becomes a customer we report the conversion back to the platform that served the ad — the click identifier, when it converted, and the value we record for that work in Australian dollars — so we can tell which advertising is worth running. Google Ads is the platform we use for this; the same applies to any other we advertise on, and some, such as Meta, also require a one-way coded (hashed) version of your email address to match the conversion — they receive the code, never the address itself. When we are not advertising there is nothing to report: any click identifier stays in your browser and is never sent with your enquiry (see “Cookies” below).
On moltiply.com.au itself we use Google Analytics to understand how people find and use this site. Its tag runs in Google Consent Mode: it loads on every visit, but until you accept the cookie banner it sets no cookies and sends Google only cookieless signals — for example that a page was viewed or our enquiry form was sent, together with the IP address and browser details every web request carries — which Google uses to estimate visit numbers in aggregate. It never loads when your browser sends a Global Privacy Control signal. If you accept, Google's script sets its own cookies to recognise repeat visits and sends Google the pages you view and some of what you do on them — for example scrolling, following a link off the site, tapping a phone number or sending our enquiry form. Exactly which interactions are measured is set in our Google Analytics settings rather than in this site's code. Google may process this information overseas, mainly in the United States.
5. Payments
Payments are processed by Stripe. Card details go directly to Stripe over an encrypted connection — we never see or store full card numbers. We keep records of invoices, subscriptions, and order totals to run our business and meet Australian record-keeping requirements. Where a client sells through their website, payments go to that client's own Stripe account via Stripe Connect.
6. How We Use AI
We use AI tools — including Anthropic's Claude and OpenAI models — to help design, build, and edit websites. The business details, briefs, content, and images involved in a project may be processed by these providers to do that work, and our staff review what the AI produces before it goes live.
AI also helps behind the scenes with enquiries: on client websites it can draft a suggested reply to your message and help the business prioritise enquiries, and where a client enables a chat assistant, the assistant's responses are AI-generated. A person always makes the actual decisions — no decision with legal or similarly significant effect is made about you by automated means.
7. Who We Share Information With
We share personal information only with the service providers we rely on to deliver our services:
- Cloudflare — hosting, security, and email delivery for our platform and the sites we host
- Stripe — payments, invoicing, and subscriptions
- Google — sign-in, calendar scheduling where connected, website analytics on moltiply.com.au and on client sites that use it (only after you accept the cookie banner), and ad conversion measurement for our own Google Ads and for clients who run them
- Microsoft, Apple, and other calendar providers — calendar scheduling, where a business connects its calendar
- GitHub — staff sign-in and version-controlled storage of website files
- Anthropic and OpenAI — AI assistance, as described above
- ClickSend — SMS messages such as booking reminders and replies to enquiries, where a client enables them
- Twilio — phone call tracking, where a client enables it
- Meta — ad conversion measurement, where we or a client run Meta ads
- Sentry — error monitoring and diagnostics for our platform
- Domain registrars — registering a domain requires passing on the registrant's contact details
8. Overseas Disclosure
The providers above operate global infrastructure, so personal information is stored and processed outside Australia — mainly in the United States. We take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including choosing providers with strong, published privacy and security practices. We never sell personal information.
9. Security
All traffic to our platform and to the sites we host is encrypted — HTTPS is enforced on every hosted site. Sign-in sessions use encrypted cookies, stored credentials are encrypted, and client data is accessible only to signed-in Moltiply staff — and to each business through its own portal login.
10. Retention & Deletion
We keep personal information while we provide services to you and for as long as Australian tax and business record-keeping laws require. Ask us at any time to access or delete what we hold about you, and we will do so where the law allows.
11. Cookies
moltiply.com.au sets two cookies of our own: an encrypted session that expires after 7 days, set when you sign in (our server may also set it when you send the enquiry form), and, while you are signed in, a marker that tells the site to show you the signed-in menu. Neither is used for analytics or advertising. If you accept the cookie banner, Google Analytics also sets its own cookies (their names start with _ga, and they last up to two years) to recognise repeat visits; decline, or send a Global Privacy Control signal, and it sets none. We do not use advertising cookies on our site. If you arrive from one of our ads, the click identifier in that link is held in your browser's own session storage — not a cookie — and reaches us only if you submit the enquiry form; closing the tab discards it. On hosted client sites, basic visit counting uses no cookies at all; if you accept the consent banner for engagement analytics, the site sets a single first-party analytics cookie (expires after 13 months, never shared across sites). Where a client adds Google or Meta tags, those tags set their own cookies only after you accept the banner. Declining, or a Global Privacy Control signal, means no analytics or advertising cookie is set.
12. Access, Correction & Complaints
You can ask what personal information we hold about you, ask us to correct it, or make a privacy complaint by emailing us — we respond within 30 days. If you are not satisfied with the outcome, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). When our practices change, we update this page and the date above.
13. Contact Us
For any privacy question, request, or complaint, contact us at studio@moltiply.com.au or call 0420 297 514.