Legal
Privacy
What we collect when you use this site, why we collect it, and who else touches it. Short, because we don’t collect much.
Last updated 27 July 2026
Who we are
Blue Monk Pty Ltd(“Blue Monk”, “we”) is an Australian company at 68 Keys Road, Cheltenham VIC 3192, Australia. We are the entity responsible for the personal information described here. Reach us at hey@bluemonk.io.
We handle personal information under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the GDPR or UK GDPR applies to a visitor, we also honour the rights set out below.
What we collect
What you send us.When you submit the contact form we collect your name, work email, company, website, annual revenue band, ecommerce platform, what you’re here for, and optionally your timeline and budget, plus whatever you write in the message field.
How you got here. Campaign parameters in the URL (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid), the page you landed on, and the referring site. This tells us which marketing is working and nothing about you personally.
Technical data. Your IP address is used to rate limit form submissions and is written to our server logs. Our analytics provider collects device, browser, approximate location and page-view data.
We do not collect payment details on this site, and we do not ask for sensitive information as defined by the Privacy Act. Please don’t put anything confidential in the message field — a first call is a better place for that.
Why we collect it
To answer your enquiry, to prepare for a call, to work out whether we’re a fit, to measure which marketing produces genuine enquiries, and to keep the form from being abused. Where the GDPR applies, our legal basis is legitimate interests (responding to a business enquiry and running our own marketing) or, for analytics and advertising cookies, your consent.
We do not sell personal information, and we do not share it with anyone for their own marketing.
Cookies and analytics
This site uses Google Analytics 4 to count page views and measure which pages produce enquiries. It sets cookies in your browser. We also record a conversion event when a form is submitted, which may be passed to Google Ads and Meta so we can tell which advertising produced it — the event carries the enquiry type and revenue band, not your message.
Analytics only loads when a measurement ID is configured, and you can block it with any standard browser setting, an extension, or by declining cookies where a banner is shown.
Who else touches it
We keep the list of processors short on purpose. Currently: Vercel (site hosting and server logs), Supabase (our database, hosted in Australia), Resend (sends the notification email to us), Google (Analytics, and Ads conversion measurement), and Meta (advertising conversion measurement). Some of these store data outside Australia, including in the United States and the European Union.
We may also disclose information where the law requires it, or to establish or defend a legal claim.
How long we keep it
Enquiries are kept while there is an active conversation and for up to 24 months after the last contact, so we can pick up a thread that goes quiet. Records connected to a paid engagement are kept for seven years to meet Australian tax and record-keeping obligations. Server logs roll off within 30 days.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Where the GDPR applies you can also object to processing, ask us to restrict it, or ask for your data in a portable format, and you can withdraw consent to analytics at any time. Email hey@bluemonk.io and we will respond within 30 days.
If you’re not satisfied with how we’ve handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to your local supervisory authority in the EU or UK.
Security
Data is held in access-controlled systems, encrypted in transit, and reachable only by the two of us. No system is perfect; if a breach occurs that is likely to cause you serious harm, we will notify you and the OAIC as the Notifiable Data Breaches scheme requires.
Changes
If this policy changes we will update the date at the top. Material changes will be flagged on this page rather than made quietly.
See also our terms.