Lorna Jane Privacy Policy
We regularly update our privacy policy, with the latest update in April 2026, and any future changes will be posted on our website, so we recommend reviewing it from time to time.
1. OUR COMMITMENT TO PRIVACY
Lorna Jane Pty Ltd and its related bodies corporate (‘Lorna Jane’, ‘we’, ‘us’, ‘our’) are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose and hold personal information, and how you can access and correct that information or make a complaint. This policy applies to personal information collected through our websites, mobile applications, retail stores, customer service interactions, Wi-Fi services, and marketing activities.
Lorna Jane operates globally, including in Australia, New Zealand, China, Singapore, and the United States. This policy is designed to comply with applicable privacy laws in those jurisdictions, including the Privacy Act 1988 (Cth), the Privacy Act 2020 (NZ), the Personal Information Protection Law (China), the Personal Data Protection Act 2012 (Singapore), and the California Consumer Privacy Act of 2018 (as amended), where applicable. Additional rights and obligations may apply depending on your location.
We may collect personal information directly from you and, in some cases, from third parties such as service providers, business partners, and publicly available sources. Where we collect your personal information indirectly, we will take reasonable steps to notify you in accordance with applicable laws. Our eCommerce operations may involve the transfer of personal information across borders, including fulfilment from Australia and New Zealand and support from service providers in other countries.
1.1 Making Informed Privacy Choices
You have choices about how your personal information is collected and used.
Where required by law, we will seek your consent before collecting or using your personal information. In other circumstances, we may collect, use or disclose personal information as permitted by applicable privacy laws.
Where lawful and practicable, you may choose to deal with us anonymously or by using a pseudonym. However, in some cases we may need to collect certain personal information to provide products or services, process transactions, or comply with legal obligations.
You can manage your preferences and exercise your rights in a number of ways, including:
• opting out of marketing emails by using the ‘unsubscribe’ link
• replying ‘STOP’ to SMS or text messages
• adjusting your browser settings to manage cookies and tracking technologies
• managing interest-based advertising through your browser or third-party platforms such as Google or Meta
• requesting access to, or correction of, your personal information
If you interact with our automated systems, such as chatbots, you should avoid providing sensitive personal information unless it is necessary for your request.
For more information, see the ‘How to manage your personal information’ section of this policy.
For details, see the ‘How to Manage Your Personal Information’ section of this policy.
1.2 Children’s Privacy
Lorna Jane’s products and services are intended for adults. Purchases may only be made by individuals aged 18 years or over.
We do not knowingly collect personal information from children below the age required under applicable laws without appropriate consent. Where required, we will obtain consent from a parent or guardian before collecting or using a child’s personal information.
If we become aware that we have collected personal information from a child without the required consent, we will take reasonable steps to delete that information in accordance with applicable laws. We do not knowingly use personal information of children for marketing or profiling purposes.
If you believe that a child has provided personal information to us without appropriate consent, please contact us at privacy@lornajane.com.au.
By providing your personal information to Lorna Jane, you accept this privacy policy and any additional notices relevant to specific interactions.
If you have any questions, we are always here to help!
2. PERSONAL INFORMATION HANDLING
2.1 TYPES OF PERSONAL INFORMATION WE COLLECT
We collect different types of personal information depending on how you interact with us, including through our websites, mobile applications, retail stores, customer service channels, and marketing activities.
The types of personal information we may collect include:
Personal and contact details
Your name, age or date of birth (where provided), gender, email address, phone number, and billing and delivery addresses.
Account and transaction information
Details of your purchases, orders, returns, exchanges, wish lists, and interactions with your account.
Preferences and interests
Information about your size, fit preferences, product interests, activity level, and style preferences, including where you provide this through quizzes, reviews, or interactions with our services.
Communications and interactions
Records of your communications with us, including customer service enquiries, feedback, survey responses, reviews, and interactions through digital channels (including chatbots and call recordings where applicable).
Marketing and engagement information
Information about your engagement with our marketing communications, including email, SMS, and online advertising interactions.
Technical and usage information
Information collected automatically when you interact with our digital platforms, including IP address, device information, browser type, cookies, and location data (where enabled).
Images and security information
Images or video recordings captured in our retail, warehouse, or office locations for security and loss prevention purposes. We may also collect publicly available content where you engage with our brand on social media platforms.
Financial information
Transaction details such as payment method and billing information. Payment card details are processed securely by third-party payment providers and are not stored by Lorna Jane.
Employment-related information
Personal information relating to current, prospective, and former employees, including identification, contact, and employment-related details, where relevant to our operations
Sensitive information
reasonably necessary for our functions and permitted by law. This may include certain health or employment-related information. Where required, we will obtain your consent before collecting or using sensitive personal information.
We may collect personal information directly from you or from third parties, including service providers, business partners, and publicly available sources. Where we collect your personal information indirectly, we will take reasonable steps to notify you in accordance with applicable privacy laws.
2.2 HOW WE COLLECT YOUR PERSONAL INFORMATION
We collect personal information in a number of ways, depending on how you interact with us.
Information you provide directly
We collect personal information when you interact with us, including when you:
• make a purchase or place an order
• create or use an account
• subscribe to marketing communications
• enter competitions or promotions
• submit reviews, feedback, or survey responses
• contact customer support or engage with us via phone, email, live chat, or social media
• apply for a job with us
Information collected automatically
When you use our websites, mobile applications, or in-store technologies, we may collect information automatically through cookies and similar technologies. This may include device information, browsing activity, location data (where enabled), and interactions with our digital platforms.
We use cookies and tracking technologies to support website functionality, analyse usage, personalise content, and deliver advertising. You can manage your cookie preferences through your browser settings.
Information from third parties
We may collect personal information from third parties, including service providers, business partners, social media platforms, and publicly available sources. This may include information about your interactions, preferences, or engagement with our brand.
Where we collect your personal information indirectly, we will take reasonable steps to notify you in accordance with applicable privacy laws.
We may collect personal information from third parties, including service providers, business partners, social media platforms, and publicly available sources. This may include information about your interactions, preferences, or engagement with our brand.
Where we collect your personal information indirectly, we will take reasonable steps to notify you in accordance with applicable privacy laws.
When you make a purchase, payment information is processed securely by third-party payment providers. We receive transaction details necessary to process your order and manage your account.
In-store and security collection
We may collect personal information when you visit our stores, including through CCTV systems used for safety, security, and loss prevention purposes.
Marketing and advertising interactions
We collect information about your interactions with our marketing communications and advertising, including email engagement and interactions with online advertisements.
We may engage third parties to assist with advertising and analytics. These providers may use cookies and similar technologies to collect information about your interactions with our services and other websites.
Artificial intelligence and automated systems
We may use automated systems, including artificial intelligence technologies, to support customer service, personalise experiences, and improve our operations. These systems may process personal information such as purchase history, browsing behaviour, and customer interactions.
Where required by law, you may have the right to request further information about automated decision-making or to request human review.
Social media and public information
We may collect personal information that you make publicly available when you interact with our brand on social media platforms, such as by tagging or mentioning us.
When you apply for a job
If you apply for a role at Lorna Jane, we collect personal details relevant to assessing your application, such as your resume, employment history, qualifications, and references.
When you visit a Lorna Jane store or warehouse
To ensure the safety and security of our staff, customers, and products, we may use CCTV cameras in public areas to monitor real-time activity. CCTV helps protect against theft, fraud, and safety threats. Footage is typically stored for up to 30 days before being automatically overwritten unless it captures an incident. If footage is required for an investigation, it may be retained until the matter is resolved or as required by law. All footage is securely stored and accessed only by authorised personnel. You may request access to CCTV footage featuring yourself, subject to privacy laws and the protection of other individuals’ identities.
When you visit a Lorna Jane store or warehouse
To ensure the safety and security of our staff, customers, and products, we may use CCTV cameras in public areas to monitor real-time activity. CCTV helps protect against theft, fraud, and safety threats. Footage is typically stored for up to 30 days before being automatically overwritten unless it captures an incident. If footage is required for an investigation, it may be retained until the matter is resolved or as required by law. All footage is securely stored and accessed only by authorised personnel. You may request access to CCTV footage featuring yourself, subject to privacy laws and the protection of other individuals’ identities.
2.3 HOW WE USE YOUR PERSONAL INFORMATION
We use your personal information for the purposes for which it was collected, for related purposes that you would reasonably expect, where you have provided consent (where required), and as otherwise permitted or required by applicable laws.
We may use your personal information for the following purposes:
Providing our products and services
To process purchases, payments, refunds, and deliveries, manage your account, provide customer support, and administer promotions, competitions, and loyalty activities.
Personalisation and customer experience
To tailor your experience across our websites, mobile applications, and stores, including providing product recommendations, preferences, and relevant content.
Marketing and communications
To send you marketing communications and promotional offers, where permitted by law. You can opt out of marketing communications at any time.
Security, fraud prevention and legal compliance
To verify identity, prevent and detect fraud, protect our systems and customers, comply with legal obligations, and respond to regulatory requirements or disputes.
Business operations and improvement
To operate, maintain and improve our business, including analytics, research, product development, and internal reporting. We may also use de-identified information for these purposes.
Business operations and improvement
To support our digital platforms and services, including the use of automated systems to enhance customer service, personalise experiences, and improve operational efficiency. Where required by law, you may have rights in relation to automated decision-making.
If Lorna Jane undergoes a merger, acquisition, or business restructure, your personal information may be transferred as part of that process, in accordance with applicable laws.
2.4 DISCLOSURE (SHARING) OF YOUR PERSONAL INFORMATION
We may disclose your personal information to third parties where reasonably necessary for our business operations, to provide our products and services, for related purposes that you would reasonably expect, or as otherwise permitted or required by law.
We may disclose personal information to:
• our employees, contractors, and service providers who assist in operating our business
• related entities and affiliated companies
• payment processors, financial institutions, and fraud prevention providers
• logistics, delivery, and fulfilment partners
• technology and IT service providers, including hosting and cybersecurity providers
• marketing, advertising, and analytics providers
• customer service providers, including contact centres and support platforms
• professional advisers such as lawyers, accountants, auditors, and insurers
• regulators, law enforcement agencies, and government authorities where required or authorised by law
We take reasonable steps to ensure that third parties who receive personal information handle it in accordance with applicable privacy laws.
Overseas Disclosure
As part of our operations, we may disclose personal information to recipients located outside your country. This may include Australia, New Zealand, the United States, China, Singapore, and other countries where our related entities or service providers operate. Where we transfer personal information internationally, we take reasonable steps to ensure that appropriate safeguards are in place to protect your information in accordance with applicable privacy laws. Depending on your location, this may include contractual protections, security measures, or other mechanisms required under applicable laws.
3. SECURITY OF PERSONAL INFORMATION
We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, in accordance with applicable privacy laws. Personal information is stored in secure systems and facilities, including electronic systems and, where relevant, physical records. These systems may be located in Australia, New Zealand, or other countries where our service providers operate. We use a range of technical and organisational measures to protect personal information, including:
access controls to restrict access to authorised personnel
physical security measures to protect our premises and systems
information security technologies such as encryption, firewalls, and secure networks
staff training and internal policies to support the appropriate handling of personal information
staff training and internal policies to support the appropriate handling of personal information
While we take reasonable steps to protect personal information, no method of transmission over the internet or electronic storage is completely secure. If a data breach occurs that is likely to result in serious harm, we will take steps to investigate and respond in accordance with applicable laws, including notifying affected individuals and relevant regulators where required. We may communicate with you electronically about security, privacy, and administrative matters, where permitted by law.
4. LINKS TO OTHER WEBSITES
This Privacy Policy applies only to Lorna Jane’s collection, use, and handling of personal information. It does not apply to third-party websites, platforms, or services that may be linked from our websites or applications. We do not control and are not responsible for the privacy practices of those third parties. If you access a third-party website or service, we recommend that you review their privacy policy to understand how your personal information will be collected and used.
5. PERSONAL INFORMATION RETENTION
We retain personal information only for as long as necessary for the purposes for which it was collected, including to provide our products and services, meet legal and regulatory obligations, resolve disputes, and enforce our rights. The length of time we retain personal information depends on a range of factors, including:
• the nature of our relationship with you and whether we continue to provide services
legal, regulatory, and accounting requirements
the need to retain information for dispute resolution, enforcement, or compliance purposes
In general: • marketing information is retained until you opt out of receiving marketing communications, after which we may retain limited information to manage your preferences to comply with legal obligations; • transaction records are typically retained for up to 7 years to meet tax, accounting, and legal requirements; • CCTV footage is generally retained for a limited period (for example, approximately 30 days), unless it is required for an investigation, legal proceeding, or regulatory purpose. When personal information is no longer required, we take reasonable steps to securely destroy or de-identify it in accordance with applicable laws.
6. BUSINESS TRANSFERS AND CHANGE IN OWNERSHIP
We may transfer personal information as part of a business transaction, such as a merger, acquisition, sale of assets, or corporate restructure. If such a transaction occurs, personal information may be disclosed to a prospective or actual purchaser, or transferred to a new owner or related entity, in accordance with applicable privacy laws. We will take reasonable steps to ensure that any recipient of personal information continues to handle it in a manner consistent with applicable privacy requirements. If there are material changes to how your personal information is handled as a result of a business transfer, we will update this Privacy Policy.
7. HOW TO MANAGE YOUR PERSONAL INFORMATION
You have a number of choices about how your personal information is used. You can:
opt out of marketing communications by using the ‘unsubscribe’ link in emails or by contacting us at privacy@lornajane.com.au
• stop receiving SMS messages by replying ‘STOP’
manage cookies and tracking technologies through your browser settings
• adjust your preferences for interest-based advertising through your browser or third-party platforms
Disabling certain technologies may affect the functionality of our websites or services. You may also request access to, or correction of, the personal information we hold about you. We will respond to such requests in accordance with applicable laws. In some circumstances, we may decline a request where permitted by law, and we will provide reasons where required.
8. QUESTIONS, CONCERNS OR COMPLAINTS
If you have any questions, concerns, or complaints about how Lorna Jane collects or handles your personal information, or if you wish to request access to, correction of, or deletion of your personal information, you can contact us at: Email: privacy@lornajane.com.au These contact details can be used for Australian, New Zealand, and international enquiries. We will respond to privacy requests and complaints within a reasonable timeframe in accordance with applicable laws. If additional time is required to respond to your request, we will inform you of the reason and the expected timeframe. If you are not satisfied with our response, you may contact the relevant privacy regulator in your jurisdiction.
Australia
Office of the Australian Information Commissioner (OAIC)
Phone: 1300 363 992
Website: www.oaic.gov.au
New Zealand
Office of the Australian Information Commissioner (OAIC)
Phone: 0800 803 909
Website: www.privacy.org.nz
General Data Protection Regulation (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, additional rights and protections may apply to your personal information under the General Data Protection Regulation (GDPR) or equivalent laws. We process your personal information where we have a lawful basis to do so, including where it is necessary to perform a contract with you, to comply with legal obligations, to support our legitimate business interests (such as improving our products and services, preventing fraud, and operating our business), or where you have provided your consent. Where we rely on consent, you may withdraw your consent at any time. This will not affect the lawfulness of processing carried out before withdrawal. Subject to applicable law, you may have the right to request access to, correction of, or deletion of your personal information, to object to or restrict certain processing, and to request the transfer of your personal information to another organisation. We will respond to requests relating to your personal information within the timeframes required by applicable law. If we are unable to comply with your request, we will provide reasons where required. If you have concerns about how your personal information is handled, you may also have the right to lodge a complaint with a relevant data protection authority in your jurisdiction. To exercise your rights or request further information, please contact us at privacy@lornajane.com.au.