PRIVACY POLICY


General information

The Cheesecake Shop Pty Ltd ACN 059 134 431, its subsidiaries and affiliates, is the franchisor of The Cheesecake Shop system in Australia (collectively referred to as “TCS”, “we”, “us” or “our”). We value your privacy and are committed to managing and protecting personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and in accordance with other applicable privacy laws.

This Privacy Policy explains how we collect, use, store and disclose the personal information of our customers and members of the public.

In this Privacy Policy, ‘you’ refers to any individual about whom we collect personal information.

Please read this Privacy Policy in conjunction with any applicable terms and conditions provided to you when you interact with us, including through our stores, website and other services.

We may update this Privacy Policy from time to time, so please review it periodically to stay informed of any changes. Your continued use of our services signifies your acceptance of any updates to this Privacy Policy. All personal information we collect, use and disclose will be managed in accordance with the latest version of our Privacy Policy.

Australian Privacy Principles

This policy adheres to the Privacy Act 1988 (Cth). The Privacy Act establishes 13 key principles governing the collection, use and management of personal information, known as the APPs. A copy of the APPs can be accessed on the Office of the Australian Information Commissioner website at https://www.oaic.gov.au.

Personal Information

Personal information is information about any identifiable individual (a natural person), and includes personal data, personally identifiable information and equivalent information under applicable privacy and data protection laws.

What information do we collect about you?

TCS collects a variety of personal information, including without limitation, your name, phone number, email address, billing address and delivery address. Additionally, we gather non-personal demographic details like your postcode, birth date, gender and preferences

We collect personal information only when necessary for our business operations or activities and do so by lawful and fair means.

Where you directly interact with us, we may collect various types of personal information, including but not limited to:

when you purchase a product online via our website;
When you participate in competitions, promotions, surveys or register an account with us;
subscribing to our direct marketing or following our social media platforms such as Meta, Instagram, LinkedIn or TikTok;
by accessing our website via links in an email we have sent;
placing an order with us (either in-store, online or telephone);
if you use our ‘store locations’ feature on our website,
placing orders via our third party service providers such as Uber Eats, Menulog and DoorDash;
contacting TCS Customer Service;
applying to become a TCS franchisee;
applying for a position with TCS;
transaction details related to service use, including order preferences, dates, amount charged and payment method; and if you upload anything to our website.

Financial Transactions

All purchases that are made through our website are processed securely and externally by Tyro Payments Limited (Tyro). Unless you expressly consent otherwise, we do not see or have access to any personal information that you may provide to Tyro, other an information that is required in order to process your order and deliver your purchased items to you, for example, your name, email address and billing/postal address. Tyro’s Privacy Policy can be accessed at www.tyro.com/privacy-policy.

Automatic Collection

When you visit our website, we may use automated technologies (such as cookies, usage monitoring software and session tracking) to collect and store certain information about your visit. This may include but is not limited to:

the IP address and domain name your device uses to connect to the internet;
the operating system, browser type and search engine used to access our website;
the date, time and duration of your visit;
the pages you visit on our website;
your location (based on your device location settings); and any personal information you provide, such as your name, email address and phone number.

Cookies

Our website uses temporary cookies—small alphanumeric identifiers transferred to your device’s hard drive—to maintain active sessions after user login. These cookies assist with website administration and usability improvements by helping us recognise returning visitors and tracking user navigation patterns. These cookies do not store personal information or provide access to any information stored on your device. Additionally, they do not interact with cookies from other websites. The information collected is used solely for the purposes mentioned above and to enhance our website's functionality. Please note that some browsers allow you to block cookies, but doing so may negatively affect your user experience on our site.

Information from Third Parties

We may collect personal information from third parties, including publicly available sources or data provided by delivery partners, payment processors, marketing agencies, and customer engagement platforms. This information helps us supplement and enhance the personal data we hold about you to provide better services.

Social Media

When you interact with us through social media platforms, we may collect personal information associated with your social media account. If you contact us via email, we may store your email address and any content you share. This information will be used only as outlined in this Privacy Policy and in compliance with the Privacy Act. Please note that personal information or comments you voluntarily post on our website or social media pages become publicly accessible. Your name may be visible to other users when you post comments or messages. Content you share publicly is not covered by this Privacy Policy.

CCTV

TCS locations may use CCTV surveillance to monitor and investigate incidents, ensuring the safety, security, and wellbeing of staff, customers, and visitors. We take all reasonable measures to safeguard this information against loss, tampering, misuse, and unauthorised access.

Combining and Using Your Information

We may combine information collected from cookies, third parties, social media interactions, and other sources with personal data we already hold. This helps us personalise your experience, improve our services, and ensure the security and functionality of our website and app.

Financial and Sensitive Information

We may collect additional personal and sensitive information, such as financial details when you apply for a position with TCS or apply to become a franchisee. This information is handled in accordance with applicable privacy laws and used only for the purposes specified.

Can you deal with us anonymously?

We will provide individuals with the opportunity of remaining anonymous or using a pseudonym in their dealings with us where it is lawful and practicable (for example, when making a general enquiry). Generally, it is not practicable for us to deal with individuals anonymously or pseudonymously on an ongoing basis. If we do not collect personal information about you, you may be unable to utilise our services or participate in our promotions or activities we manage or deliver.

How we manage and use your personal information

We may use your personal information to (without limitation) to:

process customer orders and providing customer support;
conduct direct marketing, sales and promotion of TCS products;
improve our product offerings and services;
administer our loyalty program;
assess your eligibility and purchase and operate a TCS franchise;
fulfilling our obligations under the Franchising Code of Conduct, which includes the storage and disclosure of personal information about former franchise directors (such as their name, location and contact details) with their written consent;
assessing and managing employment applications; and;
supporting our internal operations, including meeting legal and regulatory requirements, such as those related to our franchise network disclosure obligations.

We use, hold and disclose your personal information primarily for the purpose for which it was collected, or as required by relevant privacy laws, for example, disclosure to law enforcement agencies if required.

Where your personal information is stored

We store your personal information in both physical and digital formats, employing a range of safeguards – physical, electronic and procedural – to ensure its protection. This information may be stored in various systems, including:

customer databases for processing orders, inquires or feedback
marketing communications databases
databases for managing our franchise network administration

How your personal information is protected

We hold personal information both electronically and in hard copy form at our offices, on our servers and, in some cases, on third party could storage servers in Australia and overseas.

We take reasonable steps to safeguard your personal information from loss, interference and misuse and from unauthorised access, modification and disclosure. Our website does not necessarily use encryption or other technologies to ensure secure transmission of information via the internet. Users of our website are encouraged to exercise cade in sending personal information via the internet.

In the event of a significant data breach, we will inform you and the Office of the Australian Information Commissioner as required by law. We will retain your personal information only as long as necessary for its intended purpose or as mandated by legal requirements and will securely destroy and de-identify it when it is no longer needed.

Disclosure of your personal information to third parties

We may disclose your personal information to:

related companies, contractors and agents of TCS for purposes related to our business operations;
marketing providers, market research and data analytics companies to perform direct marketing activities;
franchisees for handling inquiries or complaints; and others with your consent or as required by law.

When engaging third-party contractors to manage personal information, we will take reasonable measures to ensure that the third party use the information solely for the intended purpose for which it was provided.

How we use your personal information for direct marketing

With your consent, we may periodically send you direct marketing communications about our products and services, or other opportunities that may interest you. These communications may be delivered via email, SMS, mail or other channels, in compliance with the Spam Act 2003 (Cth) and the Privacy Act.

You can opt out of receiving these materials at any time by using the opt-out options provided (such as an unsubscribe link) or by contacting us using the details provided at the end of this Policy

If you opt-out of receiving marketing material from us, we may still contact you in relation to our ongoing relationship with you.

Franchise Applications

We collect personal information from franchise applicants for purposes including evaluating franchise suitability, conducting due diligence and meeting our franchisor disclosure obligations. This information may be shared with our related entities, prospective franchisees, referees, financial institutions, law enforcement, educational institutions (to verify qualifications, if needed), and other relevant authorities.

In compliance with Item 6.5 of Schedule 1 of the Franchising Code of Conduct (Code), we may list the names, locations and contact details of franchisees in our disclosure document if they are involved in events outlined under Item 6.4 of Schedule 1 of the Code. This may include personal details of both current and former franchisees.

As per the Code, former franchisees have the right to request in writing that their personal information not be included in the disclosure document.

Employment Applications

We collect personal information from employment applications to evaluate candidates for positions, conduct reference checks and retain information for future openings. Information such as your name, contact details, qualifications and work history. Generally, we will collect this information directly from you.

We may also collect personal information from third parties in ways which you would expect (for example, from recruitment agencies or referees you have nominated). Before offering you a position, we may collect additional details such as your tax file number and superannuation information and other information necessary to conduct background checks to determine your suitability for certain positions.

Franchisees

Multiple TCS stores are independently owned and operated by franchisees. As a franchisor, we emphasise the importance of protecting customer data and adhering to privacy regulations throughout our franchise network.

Please note that this Privacy Policy does not cover the practices on franchisee’s independent social media accounts.

Disclosure of your personal information

TCS operates a network of stores across Australia and New Zealand. Due to the scale of our operations, it is occasionally necessary to share your personal information with our related companies and third-party service providers. It is likely that your personal information will be disclosed to overseas recipients.

Unless we have your consent, or an exception to the APPs applies, we will only disclose your personal information to overseas recipients where we have taken reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to your personal information.

Our privacy practices may differ depending on the country of operation. We will take all appropriate and reasonable measures to ensure that your information is collected, stored and used in compliance with the applicable legal requirements and in accordance with this Policy.

Third party websites

Our website may contain links to third party websites. We are not responsible for the privacy practices or policies of these third parties. Privacy policies on other websites may differ significantly from ours. We encourage you to review their policies before using those sites.

International Users

If you access our website or services from a region with data protection laws different from those in Australia, please note your personal information will be transferred and managed in accordance with Australian privacy laws. By using our services, you consent to this transfer and the processing of your information in Australia.

Accessing or correcting your personal information

You are entitled to access your personal information held by TCS on request. To request access to your personal information please contact our Privacy Officer using the contact details set out below.

You will not be charged for making a request to access your personal information, but you may be charged for the reasonable time and expense incurred in compiling information in response to your request.

We will take reasonable steps to ensure that the personal information we collect, use or disclose is accurate, complete and up to date. You can help us to this by letting us know if you notice errors or discrepancies in the information we hold about you and letting us know if your personal details change.

However, if you consider any personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading you are entitled to request correction of the information. After receiving a request from you, we will take reasonable steps to correct your information.

We may decline your request to access or correct your personal information in certain circumstances in accordance with the APPs. If we do refuse your request, we will provide you with a reason for our decision and, in the case of a request for correction, we will include a statement with your personal information about the requested correction.

Questions and Complaints

You may contact TCS at any time if you have any questions or concerns about this Privacy Policy or about the way in which your personal information has been handled.

You may make a complaint about privacy to the Privacy Officer at the contact details set out below.

The Privacy Officer will first consider your complaint to determine whether there are simple or immediate steps which can be taken to resolve the complaint. We will generally respond to your complaint within a week.

If your complaint requires more detailed consideration or investigation, we will acknowledge receipt of your complaint within a week and endeavour to complete our investigation into your complaint promptly. We may ask you to provide further information about your complaint and the outcome you are seeking. We will then typically gather relevant facts, locate and review relevant documents and speak with individuals involved.

In most cases, we will investigate and respond to a complaint within 30 days of receipt of the complaint. If the matter is more complex or our investigation may take longer, we will let you know.

If you are not satisfied with our response to your complaint, or you consider that TCS may have breached the APPs or Privacy Act, a complaint may be made to the Office of the Australian Information Commissioner (OAIC). The OAIC can contacted using the details on the OAIC website at https://www.oaic.gov.au.

How changes are made to this Privacy Policy

We may amend this Privacy Policy from time to time, with or without notice to you. We recommend that you visit our website regularly to keep up to date with any changes.

Our contact details

The contact details for TCS are:

Mail The Privacy Officer
The Cheesecake Shop Pty Ltd
2 Lisbon Street
Fairfield East NSW 2165
Telephone (02) 9723 1011
Email privacy@cheesecake.com.au

Effective Date

This Privacy Policy was last updated in April 2025.