Introduction
A business website may collect more information than its owner initially realises.
Some information is deliberately supplied through a contact form, online order or newsletter signup. Other data may be collected automatically by analytics, security systems, embedded services and server logs.
Understanding these flows is an important part of responsible website management.
For businesses planning website design in Wanneroo, privacy should be considered while the website is being designed. It should not be treated as a generic policy added after every form, tracking script and integration is already in place.
This article provides practical website guidance rather than legal advice. Businesses should obtain appropriate advice about their own legal obligations and activities.
What counts as personal information?
Personal information generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
On a typical business website, this may include:
- a person’s name
- email address
- phone number
- residential or delivery address
- workplace and job title
- information included in an enquiry
- account details
- order history
- appointment information
- photographs
- device or usage information where it can identify a person
- IP addresses in some circumstances
The context matters.
A business email address may still identify an individual. A free-text enquiry field may contain far more personal or sensitive information than the form was designed to request.
Contact and quotation forms
A form should collect only the information the business genuinely needs at that stage.
A first enquiry often does not require:
- date of birth
- identity documents
- detailed health information
- financial information
- an extensive questionnaire
- several forms of contact information
Collecting unnecessary information creates additional responsibility without necessarily improving the customer experience.
Review every field and ask:
- Why do we need this?
- Who will access it?
- Where will it be stored?
- How long will it be retained?
- Is the visitor expecting us to collect it?
- Could the question be asked later in a more appropriate system?
Our guide to why contact forms fail can support the usability side of this review once that article is published.
WordPress form storage
Many WordPress form plugins can store submissions in the website database as well as sending an email notification.
This may be useful when an email fails, but it means the information remains inside WordPress until it is deleted.
Website owners should know:
- whether form entries are stored
- which user roles can view them
- whether old submissions are deleted
- whether backups contain them
- whether information is copied into a CRM
- whether plugin support staff could access the system
- whether exports have been downloaded to staff computers
Removing an entry from the live site does not necessarily remove it immediately from historical backups.
Retention decisions should therefore be practical and documented.
Analytics and usage data
Analytics tools may collect information about how visitors use the website.
Depending on the tool and configuration, this can include:
- pages viewed
- referral sources
- approximate location
- device and browser information
- events such as form submissions
- campaign identifiers
- session behaviour
- user identifiers
- ecommerce activity
A business should understand what is being measured and why.
Tracking should not be added merely because a plugin offers it. The information should support a legitimate business purpose such as improving content, measuring campaigns or identifying usability problems.
Our article on what Google Analytics is and why it matters explains how website measurement can support better decisions.
Ecommerce websites
WooCommerce websites process more customer information than a typical brochure site.
Information may include:
- billing and shipping details
- order contents
- customer account information
- payment status
- notes
- coupon usage
- transaction identifiers
- shipping tracking details
Payment card information should generally be handled by an appropriate payment provider rather than stored directly within WordPress.
Store owners should also understand which extensions receive order data. Shipping tools, email marketing services, accounting integrations and fulfilment platforms may all process some customer information.
Each integration expands the information flow and should be reviewed before installation.
Third-party embeds
A website may load external services such as:
- YouTube videos
- Google Maps
- booking systems
- social-media feeds
- chat widgets
- review platforms
- fonts
- payment forms
- analytics scripts
These tools can create connections between the visitor’s browser and the external provider.
That does not necessarily make an embed inappropriate. It means the website owner should understand what is happening rather than treating the embed as a purely visual feature.
Where alternatives are available, consider whether the benefit justifies the additional scripts, privacy implications and performance cost.
Privacy policies should describe the real website
A privacy policy should not be copied from an unrelated business.
It should reflect:
- the organisation
- the information it collects
- how the information is collected
- why it is used
- how it may be disclosed
- how people can contact the business
- how access or correction requests are handled
- relevant overseas disclosures where applicable
- how complaints are managed
The Office of the Australian Information Commissioner explains that a privacy policy may be displayed on a website and should explain how an organisation manages personal information.
Not every Australian small business is covered by the Privacy Act in the same way. The OAIC provides guidance about when small businesses may have obligations, including circumstances in which certain smaller organisations are covered.
A legal adviser can determine the requirements applying to a particular business.
Make privacy information easy to find
A privacy policy should normally be linked from the website footer so it is available throughout the site.
Forms may also include a concise statement near the submission button, particularly when the way information will be used may not be obvious.
For example:
“We will use the details you provide to respond to your enquiry. Please read our privacy policy for more information.”
Do not place a long legal statement between the visitor and the submit button when a clear short explanation and policy link will do.
The objective is informed clarity, not visual clutter.
Protect the information collected
Privacy and security are closely connected.
Appropriate controls may include:
- HTTPS
- strong administrator access
- multi-factor authentication
- regular software updates
- restricted form-entry permissions
- secure backups
- malware monitoring
- carefully selected integrations
- staff access procedures
- deleting information no longer required
Our article on website security for small businesses explores the broader security foundation.
Information should not be collected through a well-designed form and then left indefinitely in an insecure or forgotten system.
Review the website when tools change
A website’s information collection can change when someone:
- installs a new plugin
- adds analytics
- embeds a booking tool
- creates a customer portal
- introduces ecommerce
- changes email marketing providers
- adds advertising pixels
- replaces a contact form
- enables live chat
The privacy policy and internal understanding of data flows should be reviewed alongside these changes.
For businesses using website design in Wanneroo as part of a long-term digital strategy, privacy should be part of the ongoing website review process.
Read why your website should be reviewed regularly for a wider maintenance checklist.
Build trust through responsible website practices
Most visitors do not expect a small business website to explain every technical detail on every page.
They do expect the business to:
- collect information for a sensible reason
- protect it appropriately
- explain its practices clearly
- avoid unnecessary tracking
- respond responsibly if something goes wrong
PrimeSites Digital helps small businesses plan forms, WordPress systems, ecommerce, privacy links, integrations, hosting and ongoing website maintenance.
For help reviewing how your website collects and handles information, contact PrimeSites Digital or book a free chat.
