Legal
Privacy Policy.
Last updated: July 2026
This Privacy Policy explains how Bespoke Creatives ("we", "us", "our") collects, uses, stores, and protects your personal information when you visit our website or book a consulting session. We are committed to handling your information responsibly and in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. About this policy
Bespoke Creatives is an AI consulting business operated by Bahushruth Mitte, based in Australia. This policy applies to personal information collected through our website (bespokeaucreatives.com) and the booking and contact forms embedded within it.
While Bespoke Creatives may currently qualify for the small business exemption under the Privacy Act 1988 (annual revenue threshold), we uphold the Australian Privacy Principles as a matter of standard practice. This is consistent with the scheduled December 2026 removal of the small business exemption, which will bring all Australian businesses under the Act.
If you have any questions about this policy, contact us at admin@bespokeaucreatives.com.
2. What personal information we collect
We collect only what is necessary to provide our services:
- Name and email address: collected when you book a session via Cal.com or submit a contact form via Formspree
- Session notes: information discussed during consulting sessions that we record for the purpose of delivering session recaps and tracking progress
We do not seek or solicit sensitive information (including health, racial or ethnic origin, political opinions, religious beliefs or affiliations, sexual orientation, or criminal record). However, sensitive information may arise incidentally during a consulting session if you choose to share it as part of your business context. In such cases, any information included in your session notes is recorded only where relevant to the service being delivered, and used solely for that purpose. By participating in a session, you consent to any information you voluntarily share being recorded in your session notes for this purpose.
We do not collect payment card details, as those are handled entirely by Stripe (see Section 7).
Anonymous calculator usage: when you use the revenue calculator tool on our site, we record the figures you enter (such as how many leads are in your list and the average value of a closed deal) and the resulting estimate, so we can understand demand and improve the tool. This data is anonymous. It does not include your name, email, or IP address, and it cannot be used to identify you, so it is not personal information.
Lead leak map (the /audit page): the ten questions are answered entirely in your browser and nothing is sent to us while you answer them. Your result is worked out on your own device and you can read it, print it and leave without giving us anything. If you choose to enter an email address to open the five fix guides, we then record three things: the address itself, the ten answers you gave and the result they produced, and whether you ticked the separate box asking for occasional emails. Where you did tick it, we also store the exact sentence you agreed to and the date, because under the Spam Act 2003 the burden of proving consent sits with us. We deliberately do not record your name, your business, your IP address, or anything about your device or browser, and there is no analytics or tracking of any kind on that page.
3. How we collect it
We collect personal information through the following channels:
- Cal.com booking form: when you book an AI OS Consulting Session
- Formspree contact form: when you submit an enquiry via our website contact form
- Lead leak map: when you enter an email on the /audit page to open the five fix guides
- Speed test form: when you ask us to check your response time on one of our industry pages
- Direct communication: when you email us or reply to session-related emails
3.1 Business contact details we collect from other sources
If we have contacted you and you did not give us your details yourself, this section explains exactly where they came from. It is the part most people want, so we have kept it plain.
- LinkedIn Sales Navigator: we use a paid LinkedIn Sales Navigator subscription to identify businesses that may fit what we do. From it we may record your name, your job title, your employer, and the general location shown on your professional profile. We do not take your personal contact details from LinkedIn.
- Your employer's own public website: we visit the business website and record a work email address only where that address is openly published on the site itself, for example on a contact page or in a footer. We record the exact page it appeared on, the date we read it, and how it was displayed, so we can always show you where we got it.
We do not buy contact lists. We do not use data brokers. We do not guess, generate, or construct email addresses, and we do not contact an address unless the business actually published it. If a business publishes no address, we do not email that business.
We only ever collect work contact details for the purpose of a business to business conversation relevant to your role. We do not collect personal or private email addresses for outreach, and we do not collect sensitive information from any of these sources.
If the page we found your address on asked that it not be used for unsolicited approaches, we exclude that business entirely and do not contact it.
4. Why we collect it
We use your personal information for the following purposes:
- To schedule and manage your consulting session
- To send you session-related communications: confirmation emails, session recap emails, and reminders
- To respond to enquiries submitted via our contact form
- To manage client relationships in our CRM system (GoHighLevel)
- To follow up on any proposals, audits, or builds discussed during sessions
We will not use your personal information for purposes unrelated to the above without your consent.
5. Disclosure to third parties
We use the following third-party services to operate our business. Your personal information is disclosed to these services in the course of delivering our services to you:
- Cal.com: booking platform. Stores your name, email, and booking details. Cal.com Privacy Policy →
- Stripe: payment processing (via Cal.com). Handles payment card data directly. Stripe Privacy Policy →
- GoHighLevel: CRM and session management. Stores your name, email, and session-related notes. GoHighLevel Privacy Policy →
- Formspree: contact form processor. Receives and forwards contact form submissions. Formspree Privacy Policy →
- Supabase: database infrastructure. Stores session records including name, email, session dates, and session notes. Supabase Privacy Policy →
- Google Fonts: typography. When you load our website, your IP address is transmitted to Google's servers to serve the font files. Google Privacy Policy →
5.1 Services used if we contacted you first
If you did not come to us, and we emailed you as a business contact, these are the services involved and what each one holds. They are listed separately because they apply to a different group of people to the ones above.
- LinkedIn Sales Navigator (United States): where we identify businesses. We record your name, job title, employer and general location from your professional profile. LinkedIn Privacy Policy →
- Smartlead (United States): the email platform that sends and receives our business emails. Holds your work email address, your name, your employer, and any reply you send us. Smartlead Privacy Policy →
- MillionVerifier (Hungary, in the European Union): checks that a work email address exists before anything is sent to it, so we do not mail an address that is wrong. Receives the email address only. MillionVerifier Privacy Policy →
- Supabase (United States): our own database, which stores the address, where we found it published, and the date we read it.
We do not sell, rent, or trade your personal information to any third party. We may disclose personal information if required to do so by law or in response to a valid legal request.
6. Overseas recipients: APP 8
All of the third-party services listed above (Cal.com, Stripe, GoHighLevel, Formspree, Supabase, and Google) are based in the United States. By using our booking form or contact form, you consent to your personal information being transferred to and handled by these overseas recipients.
By providing this consent, the accountability provisions of Australian Privacy Principle 8 (APP 8) of the Privacy Act 1988 do not apply to these disclosures. This means that if an overseas recipient mishandles your information, we may not be liable for that breach under Australian law. We encourage you to review each provider's privacy policy (linked above) before submitting your information.
We have selected reputable, established platforms and have taken reasonable steps to satisfy ourselves that each provider maintains appropriate data security standards, but we cannot guarantee their compliance with Australian law.
The services in section 5.1, which apply if we contacted you first, are all based in the United States, except MillionVerifier which is in Hungary, in the European Union.
6A. How long we keep it
We do not keep personal information for longer than we need it.
- If you asked us to stop contacting you: we keep your email address and the date, permanently, and nothing else. We have to. It is the only way to guarantee we never contact you again, and deleting it would defeat your own request.
- If we contacted you and you did not reply: we keep the record for up to 24 months, then delete or de-identify it.
- If we decided you were not a fit: we keep a minimal record for up to 12 months so we do not approach you again by mistake, then delete it.
- Booking and session records: kept for 7 years, because business and tax records have to be.
- Lead leak map submissions: kept while they are useful to us and deleted on request. If you ticked the box asking for occasional emails, the consent record is kept for as long as we hold the address, because a consent we cannot evidence is a consent we cannot rely on. Unsubscribing removes you from the list immediately; asking us to delete removes the record entirely.
You can ask us to delete your information at any time and we will, apart from the suppression record described above, which exists to protect you.
7. Payment information
Session payments are processed by Stripe, accessed through Cal.com's booking platform. Bespoke Creatives does not store, process, or have access to your payment card details at any point. Card data is entered directly on Cal.com/Stripe's secure environment and flows to Stripe only.
If you have questions about a payment, contact Cal.com's support or refer to Stripe's Privacy Policy.
8. Website and third-party links
Our website contains links to third-party websites and services including Cal.com, GitHub, Claude.ai, and others. Clicking these links takes you to sites operated by third parties, each with their own privacy policies. We are not responsible for the privacy practices or content of those sites.
We encourage you to read the privacy policy of any third-party site you visit before submitting personal information to it.
9. Security
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Specifically:
- All website connections use HTTPS (encrypted in transit)
- Personal information held in GoHighLevel is protected by GoHighLevel's own security infrastructure, access controls, and encryption at rest
- Access to client data is restricted to authorised personnel only (currently, the sole operator of Bespoke Creatives)
No method of data transmission or storage is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and relevant authorities as required by law.
10. Direct marketing and communications
By booking a session, you may receive:
- Session confirmation and reminder emails (operational, not marketing)
- A session recap email summarising what was built and next steps
- Follow-up communications related to your session or any proposals discussed
Under APP 7, session follow-up communications may qualify as direct marketing. If you do not wish to receive these communications, you may opt out at any time by emailing admin@bespokeaucreatives.com with "Unsubscribe" in the subject line. We will process your request promptly and at no cost to you.
We will not use your personal information for unrelated direct marketing without your consent.
10.1 If you ticked the box asking for occasional emails
Some of our forms carry a separate tick box asking whether you would also like the occasional email when we publish something new. That box is never ticked for you. You have to tick it yourself, and leaving it alone has no effect on getting the thing you actually came for, whether that is a guide, an answer to your question, or your response time.
This is a deliberate design choice and it follows the ACMA Statement of Expectations on the use of consent in telemarketing and e-marketing, which asks businesses not to use pre-checked tick boxes and not to bundle several permissions into one request.
If you do tick it, here is exactly what you are agreeing to:
- What you get: an occasional email when we publish a new guide, tool, or piece of writing. It is not a scheduled newsletter and there is no automated sequence. If we have nothing worth sending, we send nothing.
- Who sends it: Bespoke Creatives Pty Ltd, and nobody else. We do not sell, rent, or share your address, and we do not send on behalf of other businesses.
- How long: until you tell us to stop. There is no fixed term.
- How to stop: every one of those emails carries a one-click unsubscribe. You can also email admin@bespokeaucreatives.com at any time, either to unsubscribe or to have your address deleted outright. Both are free and we action them promptly.
We keep a record of the consent itself: your address, the date, the form it came from, and the exact wording you agreed to. We do that because under the Spam Act 2003 it is our job to prove we have your permission, not yours to prove we do not. If we ever change that wording, existing records keep pointing at the version you actually read.
If you did not tick it, nothing changes. We use your details only to give you the thing you asked for and to reply to you about it, and you will not be added to any list.
10.1 If we sent you a cold email
If you received an email from us that you did not ask for, here is how to stop it, and what we did with your details.
- To stop hearing from us, just reply with the word stop. That is the whole process. There is no link to click, no form to fill in, no account to create, and no login. We action it immediately and it costs you nothing.
- When you reply stop, we suppress your address permanently, and we also suppress the rest of your organisation's domain so a colleague does not get the same email from us later.
- We keep a minimal record of your suppression, being your email address and the date, and nothing else. We have to keep that much, because it is the only way to guarantee we never contact you again.
- Every email we send identifies us by name and business, and carries a working reply address that a real person monitors.
You do not need to reply stop to have your details removed entirely. You can ask us to delete everything we hold about you, and we will. See Section 11.
11. Your rights: access, correction, and deletion
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of information that is inaccurate, out of date, incomplete, or misleading
- Request deletion of your personal information (subject to any legal obligations we may have to retain records)
To exercise any of these rights, email admin@bespokeaucreatives.com with your request. We will respond within a reasonable period and at no charge. In some circumstances we may need to verify your identity before processing your request.
12. Complaints
If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, we want to hear from you first.
Step 1: Contact us directly
Email admin@bespokeaucreatives.com with details of your complaint. We will acknowledge receipt within 5 business days and aim to resolve the matter within 30 days.
Step 2: Escalate to the OAIC
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
13. Children
Our services are primarily directed at business owners, founders, and professionals. Individuals under the age of 18 are welcome to use our services, but must have obtained consent from a parent or legal guardian before booking. By booking a session, individuals under 18 confirm that such consent has been obtained.
If you believe we have received a booking from a minor without appropriate consent, contact us at admin@bespokeaucreatives.com and we will address it promptly.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. The "Last updated" date at the top of this page will reflect the most recent revision.
We encourage you to review this page periodically. Continued use of our website or services after a change constitutes acceptance of the updated policy.
15. Contact us
For any privacy-related questions, requests, or concerns:
Bespoke Creatives
Email: admin@bespokeaucreatives.com
Website: bespokeaucreatives.com
← Back to main site