Privacy Policy

We respect your privacy and have outlined how we make sure the information you submit remains safe and secure.

The information we collect

We lawfully collect personal information that is necessary for our business to function. The information we collect and hold will depend upon the products and services you request from us and may include:

  • Information you provide us when you purchase goods or services.
    • This information will include your name, address and contact details.
  • Information derived from communications between us and you.

The use of the facilities and services available through our website will determine the amount and type of information we collect. The only personal information we collect when you use our website is what you tell us about yourself, for example, by completing an online form when you request product information, or when you send us email we will record your mail address.

How we use your information

We use the information we collect for the purpose disclosed at the time of collection or otherwise as set out in this Privacy Statement. Generally we will only use your personal information:

  • To establish and maintain your relationship as a customer of Synergy Hair
  • To provide the products and services you have requested from Synergy Hair
  • To administer and manage those products and services
  • To answer your enquiry
  • For direct marketing by email, specials on products or services you have shown interest in
  • To invite you to review products post-purchase.

If you at any time receive any communication from Synergy Hair which you would not like to receive, please unsubscribe or contact us and we will remove your name from our mailing list.

Synergy Hair ensures the authenticity of product reviews using a third-party Customer Reviews Plugin. An invitation to review is sent to you post-purchase by Customer Reviews on behalf of Synergy Hair. You can choose to unsubscribe from this email at any time.


 

Windcave Security & Infrastructure Policy

Why does data security matter to your business?

It is very important to keep sensitive cardholder data away from would be criminals. The payment card ecosystem describes the relationship between you, your customers, and the rest of the payment card industry; ensuring the safety and security of your customer’s financial data is the first step in making sure that you stay compliant and trusted by the rest of the ecosystem.

If cardholder data leaks, there are ramifications throughout the payment card ecosystem; customers lose faith in your business and in other financial institutions. A loss of credibility results in customers taking their business elsewhere and ultimately affecting your profit margins.

Windcave believes in continually staying ahead of the game when it comes to data security, while your current integration may work now, if Windcave deprecates certain cipher suites or protocol versions, you will no longer be able to process payments. To ensure that your integration remains stable, secure and PCI compliant, please follow the best practice guidelines below and keep up to date with upcoming changes.

Transmission best practices

1. Secure HTTP connection

Windcave mandates the use of HTTPS. Designed to allow secure authentication and data transactions, HTTPS uses SSL/TLS to ensure data transactions are made securely. HTTPS is commonplace for online banking portals, ecommerce sites, and almost anything requiring a username and password. Using HTTPS adds a layer of security to keep your customers’ data from being sent in plain text over the internet.

Normal HTTP connections are made via port 80; secure HTTPS connections are made using port 443.

2. Use TLS 1.2 or later

TLS 1.2 is the latest in the TLS/SSL cryptographic protocols and ensures the privacy of data transmissions. Older protocol versions have known vulnerabilities and have been deprecated.

3. Don’t hardcode ciphers

Hardcoding specific ciphers exposes your website to risk in the future; some ciphers are currently considered secure, however in the coming months or years, they may be proven unfit for use. To ensure that your cipher suite is appropriate, it is recommended that ciphers are not hardcoded.

4. Automatic negotiation to the highest TLS and cipher version

It is recommended that you automatically negotiate to the highest TLS and cipher versions to account for changing protocols. Ensuring that your site can handle later versions will mitigate the need to update the site in the future.

5. Use SHA256

The use of SHA 1 is not recommended; instead, all merchants should use SHA 256. If your website is using SSL certificates that utilize SHA 1, you will need to move to the much stronger SHA 256 signing algorithm.

6. Allowing Perfect Forward Secrecy

PFS prevents a compromised long-term secret key from being used to access past or future communications. If PFS is not implemented and a single transmission is compromised, past and future communications may be at risk as well.

7. Keeping software up to date to support new TLS versions and/or ciphers

It is important to keep all software up to date and ensure that new TLS versions and/or ciphers are supported. As older versions are deprecated, your integration with Windcave may be put at risk, to ensure that your site can communicate with us please make sure that only approved versions are used.

Data storage best practices

1. Don’t physically store card data.

Storing any physical card data exposes your business to a greater level of stringent PCI requirements and opens you up to the risk of attack from criminals. To reduce the level of security mandated by PCI and remove the temptation for hackers, no financially sensitive card data should be stored in any format.

2. Ensure that no one can modify POS to read the card data.

It is important to keep an eye on all Windcave provided software to ensure that no recording devices have been attached and that there are no cameras nearby. Windcave utilizes point to point encryption, so an attack will be unsuccessful once the card data has been picked up by the terminal, however it is still possible that cardholders are exposed to risk as they input their PIN etc.

3. Tokenization

Tokenization generates a re-billable reference to a customer’s card, which can only be used by the merchant. This allows merchants to effectively store card details without needing to meet the much higher data security standards mandated by the PCI SSC.

Certification and Security at Windcave

Windcave prides itself on being able to provide merchants and cardholders alike with secure and reliable payment solutions. To guarantee the best protection of stakeholder information, Windcave is compliant to PCI DSS Version 3.2 and is a Level 1 service provider. Windcave is re-evaluated annually to ensure ongoing compliance.

The Payment Card Industry Security Standards Council established in 2006 by several leading card issuers: Amex, Discover, JCB, MasterCard, and Visa. The PCI Data Security Standards are set and enforced by the PCI SSC and ensure the secure and safe use of sensitive cardholder data.

Windcave is PCI compliant throughout our regions of operation. View our PCI DSS Compliance Certifications.

Windcave has PCI P2PE compliance; this ensures secure point-to-point encryption of sensitive data from card swipe to billing.

The Windcave e-commerce solutions, PxPay and account2account are both level AA compliant to the WCAG Accessibility Standard.

Windcave have a dedicated and purpose built development and data centre, specifically designed for payments processing. We have invested and continue to re-invest in state of the art, bank grade security and infrastructure, and are fully certified as Visa AIS and MasterCard SDP (PCI DSS) compliant at processor level; using an approved QSA for quarterly scans on systems and full onsite audits, annually. All sensitive information is encrypted with the 3DES protocol, with Atalla Network Security Processors.

To stay up to date with changes at Windcave please see our upcoming changes.


 

Afterpay Privacy Policy

Please view Afterpay’s Privacy Policy here

Please view Afterpay’s PCI DSS Policy here

 

LayBuy Privacy Policy

Please view LayBuy’s Privacy Policy here

 

Humm Privacy Policy

Please view Humm’s Privacy Policy here

 

KLARNA PRIVACY POLICY

Please view Klarna’s Privacy Policy here.

Klarna Australia Pty Ltd (“Klarna”) uses cookies to recognize the user’s device for the purpose of providing personalized advertising of Klarna products the next time the user will browse a merchant website offering Klarna products, and for analytics purposes.

These cookies contain a unique user ID which will enable Klarna to recognize the user’s device the next time that user returns to a merchant using Klarna’s services. These are persistent cookies, stored on the device for a period of up to 540 days as of the last interaction with Klarna, or until they are deleted and allow Klarna (i) to show personalized marketing of Klarna products, including credit promotions to the user, and (ii) to perform analytics of the user behaviour.

By connecting the unique user ID stored in the cookie on the device to the information Klarna has about the user, Klarna will be able to recognize the user of that device. The information Klarna collects through the cookies is not shared with any third party.

Join Waitlist We will inform you when the product arrives in stock. Just leave your valid email address below.
Email Quantity We won't share your address with anybody else.