Privacy Policy

Last updated: 18 May 2026

Nest PM Pty Ltd (ACN 602 214 095, ABN 94 602 214 095), trading as Sit or Stand (“Sit or Stand“, “we“, “us“, “our“), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, hold, disclose and protect personal information when you visit our website at sitorstand.com.au (the “site“), request a quote, contact us, or otherwise deal with us.

We handle personal information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth).

1. About this policy

This policy applies to personal information we collect through our website and in the course of providing commercial office furniture, supply, delivery, installation, retrofitting, relocation and disposal services to our clients.

By using our website or providing personal information to us, you agree to the collection, use and disclosure of your personal information in the way described in this policy.

This Privacy Policy works together with our Terms and Conditions and our Standard Terms and Conditions of Supply, which together govern your dealings with us.

2. What personal information we collect

We collect personal information that you provide to us directly when you:

  • submit our quote-request form (`/request-quote/`) or contact form (`/contact/`);
  • email us, call us, or otherwise correspond with us about a project;
  • engage us to supply, deliver, install or remove commercial office furniture; or
  • apply for credit terms with us.

The personal information we typically collect includes:

  • your name;
  • your email address;
  • your phone number (if you choose to provide it);
  • your business or organisation name and role;
  • details about your project, including the items you have added to your quote list, the site address for delivery or installation, and any notes you write in the project notes field; and
  • any other information you choose to share with us in correspondence.

If you apply for credit terms with us, we may additionally collect: your residential or business address, your date of birth, your occupation, and your previous credit history. See section 6 (Credit reporting) below for how this information is handled.

We also collect limited information automatically when you visit the site, including your IP address, browser type and version, the pages you view, the date and time of your visit, and the website you came from. This information is collected through web server logs and cookies (see section 8 below) and is generally not used to identify you personally.

3. How we collect personal information

We collect personal information directly from you when you complete a form on our website, email us, or speak with us. We do not purchase mailing lists or obtain personal information about you from third parties for marketing purposes.

If you apply for credit terms with us, we may obtain personal credit information about you from a Credit Reporting Body — see section 6 below.

If you provide personal information about another person (for example, a colleague’s contact details for a project), you confirm that you have that person’s permission to give us their information for the purposes set out in this policy.

4. Why we collect and use your personal information

We collect and use your personal information to:

  • respond to your quote request and prepare a quote;
  • ask any follow-up questions we need in order to scope your project correctly;
  • communicate with you about your project, including pricing, lead times, delivery and installation logistics;
  • supply, deliver, install or remove furniture in accordance with an accepted quote;
  • maintain a record of our dealings with you for warranty, after-sales support and account purposes;
  • assess your creditworthiness if you apply for credit terms with us (see section 6 below);
  • issue invoices and demands for payment, and pursue overdue payments;
  • comply with our legal, tax and regulatory obligations; and
  • improve our website and the quality of our service.

We do not use your personal information for direct marketing without your consent. If we ever introduce a newsletter or similar marketing communication, you will be given a clear opportunity to opt in, and every marketing message we send will include an easy way to opt out.

5. Who we share your personal information with

We treat your personal information as confidential. We only disclose it where it is necessary to deliver our services to you, where you have given us permission, or where we are required or permitted by law.

The categories of third parties to whom we may disclose personal information are:

  • Our email infrastructure provider — Brevo (Sendinblue SAS). When you submit a form on our website, the resulting email notifications are routed through Brevo’s transactional email service. Brevo processes the contents of those emails (which include the personal information you submitted) for the limited purpose of delivering the message. Brevo is based in the European Union and may process data on servers located in the EU or the United States. Brevo’s privacy practices are available at https://www.brevo.com/legal/privacypolicy/.
  • Our website host — VentraIP Australia. Our website is hosted in Australia by VentraIP. Server logs and database backups containing personal information are stored on VentraIP infrastructure.
  • Our domain registrar and DNS provider — Crazy Domains. Crazy Domains provides DNS and (where applicable) email-forwarding services for our domain.
  • Our suppliers. Where you accept a quote and we engage one of our furniture suppliers to manufacture, supply, deliver or install the items in your quote, we will share with that supplier the information they need to fulfil the order — typically your name, your delivery address, the site contact’s name and phone number, and the relevant product details. We share only what is necessary and we ask our suppliers to handle your information confidentially.
  • Credit Reporting Bodies and other credit providers. If you apply for credit terms with us, we may share information with Credit Reporting Bodies and with related credit providers — see section 6 below.
  • Our professional advisers. We may disclose personal information to our accountants, auditors and legal advisers in the ordinary course of running our business, where confidentiality is maintained under their professional obligations.
  • Law enforcement, regulators and courts. We may disclose personal information where we are required or authorised to do so by law, including in response to a lawful subpoena, court order or warrant.

We do not sell your personal information to anyone, and we do not share it with third parties for their own marketing purposes.

6. Credit reporting

This section applies if you apply for credit terms with us. If you do not apply for credit (which is the case for most quote-request and contact-form interactions), this section is not relevant to you.

6.1 Credit information we collect

If you apply for credit terms, we may collect personal credit information about you, including your name, address, date of birth, occupation, previous credit applications and credit history.

6.2 Obtaining a credit report

We may obtain a credit report containing personal credit information about you from a Credit Reporting Body (“CRB“) in order to assess your application. We will notify you when we receive such information.

6.3 Exchanging information with other credit providers

We may exchange information about you with other credit providers and with related bodies corporate for the following purposes:

  • to assess your application for credit;
  • to notify other credit providers of a default by you;
  • to exchange information with other credit providers as to the status of your credit account with us, where you are in default with another credit provider; or
  • to assess your creditworthiness, including your repayment history in the preceding two (2) years.

6.4 Sharing information with a CRB

We may give information about you to a CRB for the following purposes:

  • to obtain a consumer credit report; or
  • to allow the CRB to create or maintain a credit information file about you, including credit history.

The information we give to a CRB may include: the personal information described in section 6.1; the name of the credit provider and that we are a current credit provider to you; whether we are licensed; the type of consumer credit; details of your application for credit; advice of consumer credit defaults, overdue accounts, loan repayments or outstanding amounts overdue by more than sixty (60) days for which written notice has been issued and debt-recovery action commenced; advice that an overdue amount has subsequently been paid or otherwise discharged and the details of that discharge; advice that, in our opinion, you have committed a serious credit infringement; or advice that the amount of an overdue payment equals or exceeds one hundred and fifty dollars ($150).

6.5 Use and retention of credit information

We may use and retain personal credit information for the following purposes (and for other agreed purposes or as required by law):

  • the provision of goods or equipment;
  • analysing, verifying and checking your credit, payment and status in relation to the supply of goods or equipment;
  • processing payment instructions, direct debit facilities or credit facilities you have requested;
  • enabling the collection of amounts outstanding in relation to the goods or equipment supplied; or
  • the collection of overdue payments on commercial credit.

The full credit-handling terms — including the specific authorisations you give us when you apply for credit — are set out in our Standard Terms and Conditions of Supply.

7. International transfers

As noted in section 5 above, our transactional email provider Brevo is based in the European Union and may process the contents of emails sent through our website on servers located in the EU or the United States. By submitting a form on our website you consent to your personal information being transferred to and processed in these jurisdictions for the limited purposes described in this policy.

Both the EU (under the GDPR) and the United States (under various sector-specific laws) provide legal frameworks for the protection of personal information. We take reasonable steps to ensure that any overseas recipient of personal information handles it in a way that is consistent with the Australian Privacy Principles.

8. Cookies and tracking

Our website uses a small number of cookies and similar technologies.

8.1 Cookies we currently use

At the time this policy was last updated, the cookies set by our website are essential and functional cookies that the site needs in order to work correctly, plus Google Analytics measurement cookies described below. We do not use Facebook Pixel, Microsoft Clarity, Hotjar or any other third-party marketing tracker.

We use Google Analytics 4 (GA4), a web analytics service provided by Google, to understand how visitors use our site — for example, which pages are viewed and how visitors found us. GA4 sets cookies to distinguish visitors and collects information such as pages viewed, approximate location (city level), device and browser type, and referring website. This information is aggregated and does not directly identify you, and we do not use it for advertising. You can opt out of Google Analytics across all websites by installing the browser add-on available at tools.google.com/dlpage/gaoptout.

The cookies our website currently sets are:

  • Essential / functional cookies set by WordPress, WooCommerce and the YITH Request a Quote plugin. These are required for core site features such as remembering the items you have added to your quote list as you browse, maintaining your session between pages, and submitting forms securely.
  • A short-lived cookie set by our quote-form basket-capture script (`sos_xx_key`) that allows us to associate the items in your quote list with the form you submit so that those items appear in our quote response to you. This cookie expires after 24 hours.
  • Security cookies set by Wordfence Security, our website firewall. These are used to detect and block malicious traffic.
  • Anti-spam cookies set by WPForms, the plugin that powers our quote and contact forms. These help us prevent automated spam submissions.

If you log in as an administrator (for example, a member of our staff), additional cookies are set by WordPress to maintain your authenticated session. These cookies are not set for ordinary visitors.

8.2 Analytics and tracking we may introduce in future

We anticipate adding a website analytics tool — most likely Google Analytics 4 — to help us understand how visitors use the site (for example, which pages are most useful, where visitors are coming from, and how the quote flow performs). Google Analytics 4 sets its own cookies and sends pseudonymous usage data to Google.

We have not yet enabled this or any other analytics or marketing tracker. If and when we do, we will:

  • update this section of the policy with the specific tool in use, the cookies it sets, and a link to the provider’s own privacy notice;
  • update the “Last updated” date at the top of this policy;
  • where appropriate, display a notice on the website before the new tracking begins; and
  • where appropriate, provide a cookie-consent control that lets you accept or decline non-essential cookies.

We do not currently plan to install Facebook Pixel, Google Ads conversion tags, or other advertising / remarketing trackers. If our marketing plans change, we will update this policy and notify visitors before any such tracker is enabled.

8.3 Managing cookies

You can configure your web browser to refuse or delete cookies. Doing so will not prevent you from browsing the site, but some features — including the ability to build a quote list — may not work correctly without the essential cookies described above.

We do not use cookies or any other technology to track you across other websites.

9. How long we keep your personal information

We keep the personal information you provide through the quote-request and contact forms for 24 months from the date of our last contact with you, after which we will destroy or de-identify it in accordance with APP 11.2, unless we are required to keep it for longer to comply with a legal obligation (for example, financial records that we are required to retain under tax law).

If you become a customer, we keep the personal information associated with your account and projects for as long as our commercial relationship continues, and for a reasonable period afterwards to support warranty claims, after-sales support and our legal record-keeping obligations.

We will destroy personal information upon your request, or where it is no longer required for the purpose for which it was collected, unless we are required to retain it by law or to fulfil the obligations of a contract with you.

10. Your rights under the Australian Privacy Principles

You have the right to:

  • Access the personal information we hold about you (APP 12). We will respond to access requests within a reasonable time and, in most cases, without charge.
  • Correct any personal information we hold about you that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13).
  • Make a privacy complaint (APP 1.4) about how we have handled your personal information. We will acknowledge your complaint within seven (7) days of receipt and will take all reasonable steps to make a decision on the complaint within thirty (30) days of receipt.
  • Opt out of direct marketing communications from us, and request that we do not disclose your personal information to a third party for the purpose of direct marketing. We do not currently send direct marketing communications, but if we begin to in future, every message will include a clear unsubscribe option.

To exercise any of these rights, please contact us using the details in section 14 below.

If you are not satisfied with our resolution of a privacy complaint, you can complain to the Office of the Australian Information Commissioner (OAIC):

  • Phone: 1300 363 992
  • Web: https://www.oaic.gov.au
  • Post: GPO Box 5288, Sydney NSW 2001

11. Children’s privacy

Our website is intended for use by businesses, government departments and other organisations sourcing commercial office furniture. It is not directed at children and we do not knowingly collect personal information from anyone under the age of 16. If you believe that a child has provided personal information to us, please contact us and we will delete it.

12. How we protect your personal information

We take reasonable steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification and disclosure. These steps include:

  • serving the website over HTTPS using a TLS certificate, so that data transmitted between your browser and our website is encrypted;
  • running a web application firewall (Wordfence Security) that monitors and blocks malicious traffic;
  • restricting administrative access to our website to authorised staff with strong, unique passwords;
  • keeping our website software, plugins and server infrastructure up to date;
  • routing transactional emails through a reputable email provider (Brevo) that maintains its own security and deliverability infrastructure; and
  • limiting access to personal information within our business to those staff members who need it to do their jobs.

We also take reasonable steps to ensure that the personal information we hold is accurate, up to date, complete and relevant.

While we take privacy seriously, no method of transmitting or storing information over the internet is completely secure. We cannot guarantee absolute security, but we will comply with our obligations under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988). In the event of a data breach that is likely to result in serious harm to you, we will notify you as soon as practicable and provide a statement to the Australian Information Commissioner. If it is not practicable to notify you directly, we will publish a copy of the statement on our website and take reasonable steps to inform you of its contents.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our website, or the law. The current version is always available at https://sitorstand.com.au/privacy-policy/, with the “Last updated” date at the top of the policy showing when it was most recently revised.

If we make a material change that affects how we handle your personal information, we will take reasonable steps to bring the change to your attention — for example, by displaying a notice on the website or, where appropriate, by emailing customers we have an ongoing relationship with.

14. How to contact us about privacy

If you have any questions about this Privacy Policy, would like to access or correct your personal information, or wish to make a privacy complaint, please contact:

Sit or Stand (Nest PM Pty Ltd) ACN: 602 214 095 · ABN: 94 602 214 095 Privacy enquiries: rob@sitorstand.com.au Post: PO Box 130, Macedon VIC 3440

We will acknowledge your enquiry within seven (7) days and aim to respond fully within thirty (30) days.


This Privacy Policy is governed by the laws of Victoria, Australia, and works together with our Terms and Conditions and our Standard Terms and Conditions of Supply.