The store will not work correctly when cookies are disabled.
Skip to Content
The Provenance
Search
Wishlist
My Cart
Sign In
Shop
  • Replicas
  • What's New
  • Specials
  • Fossils
  • Crystals
  • Rare Minerals
  • Rare Artefacts
  • Out of This World
  • Wearables
  • Artworks
  • Other Items
  • Compare Products

Privacy policy

Last updated 16 September 2026

The Provenance is operated by Lesson Planner Pty Ltd, ABN 38 669 086 337, in Victoria, Australia. This policy explains how we handle personal information through theprovenance.store and related customer and seller communications.

Personal information is information or an opinion about an identified person, or someone who can reasonably be identified. Our handling of it is subject to applicable Australian privacy law, including the Privacy Act 1988 and Australian Privacy Principles where they apply.

You can browse without an account. Orders require a confirmed account. We share enquiry and order information with the relevant seller and service providers needed to operate the marketplace. We do not sell or rent your personal information.

On this page

  • Information we collect
  • How we collect it
  • Why we use it
  • Who receives it
  • Overseas handling
  • Cookies and embedded viewers
  • Marketing choices
  • Security and retention
  • Access, correction and deletion
  • Complaints and contact

1. Information we collect

The information we handle depends on how you use the marketplace. It can include:

  • Account details such as your name, email address, password credentials, account status and saved addresses.
  • Order details such as items, prices, billing and delivery addresses, telephone number, delivery instructions, payment status, transaction references and refund records.
  • Seller information such as business and store details, listings, shipping and return policies, tax information and payout details submitted to us.
  • Enquiries, seller conversations, support messages, reviews and photographs or documents you choose to provide.
  • Newsletter subscription status and your communication preferences.
  • Technical information such as IP address, browser and device information, requested pages, timestamps, referral information, error logs and cookie or browser-storage identifiers.

Stripe receives payment details directly through its payment tools. We may receive a payment token, card brand, limited masked details and transaction results. We do not store your complete card number or card security code in the marketplace.

We do not routinely ask for sensitive information such as health details. Do not put unnecessary identity documents, financial credentials or sensitive information into enquiries or public reviews. If a particular verification process needs additional information, we will explain the request.

2. How we collect information

We collect information you provide when you register, confirm an account, order, contact a seller, apply to sell, subscribe or communicate with support. We also collect technical information automatically when your browser uses the site.

We may receive information from a seller, Stripe, a delivery provider or another person involved in an order or enquiry. This can include payment confirmation, tracking, delivery status and correspondence needed to resolve a problem.

If you provide another person's details, for example a gift recipient's address, provide them only when you have authority to do so and tell the person about the relevant use.

You may withhold optional information. Without the information needed for an account, payment, delivery or seller application, we may be unable to provide that service. You can ask general questions without identifying yourself where it is lawful and practical, although order and account requests may require identity checks.

3. Why we use information

We collect, hold and use personal information to:

  • Create, confirm and protect accounts, and provide account and seller services.
  • Process payments, fulfil orders, arrange delivery, issue transaction records and handle returns, refunds or disputes.
  • Send your enquiry to the relevant seller and support communication about the item.
  • Answer requests, investigate complaints and maintain customer and seller records.
  • Detect fraud, spam and unauthorised access, diagnose errors and maintain the website.
  • Publish the listing, store information or review you submit for publication.
  • Send newsletters or other marketing where you have subscribed or another lawful basis permits it.
  • Meet tax, accounting and other legal obligations, and establish or respond to legal claims.

We use information for these purposes, related purposes you would reasonably expect, or other purposes permitted by law. If a new use requires consent, we will seek it separately. Merely reading this policy does not provide blanket consent to every possible use.

4. Who receives information

Access is limited to the people and providers who need information for the relevant purpose. Recipients can include:

  • The seller you contact or buy from. An enquiry can include your name, email, message and listing reference. An order can include contact, address and item details needed for fulfilment or a remedy.
  • Stripe and payment or fraud-prevention partners involved in checkout. Their payment services are also governed by their own privacy notices.
  • Postal, courier, freight and customs providers involved in delivery or return transport.
  • Hosting, database, backup, website-support and email providers. We use Zoho for support and transactional email.
  • Staff, contractors and professional advisers who need access to operate the marketplace or meet legal obligations.
  • Regulators, courts, law enforcement or other recipients where disclosure is required or authorised by law.

We do not give independent sellers your account password or complete payment-card details. Sellers must use buyer information for the enquiry, transaction or related legal obligations, not unrelated marketing without an appropriate lawful basis.

Store and listing information you publish is publicly visible. Reviews can display the name or nickname you submit with them. Avoid publishing private contact details in public content. An independent seller is responsible for its own handling of information it receives, and we remain responsible for our own handling and obligations.

5. Overseas handling

Some service providers operate internationally, so information may be processed or accessed outside Australia. Relevant locations include the United States and India for Stripe's global services. Zoho's group and service arrangements include Australia, India, the United States and European Economic Area countries, including the Netherlands. The countries involved depend on the service and support arrangements.

Optional media services can also operate overseas. KIRI Engine's operator is based in Hong Kong. Video and other 3D services may use international systems. If you buy from an overseas seller or request international delivery, information needed for that transaction can be received in the seller's or delivery destination's country.

We are responsible for meeting the Australian privacy obligations that apply to our overseas disclosures. Where Australian Privacy Principle 8 applies, this generally includes taking reasonable steps to ensure an overseas recipient does not breach the relevant principles, unless a lawful exception applies. This policy does not ask you to waive those protections.

Current provider notices give more detail about their processing locations and safeguards:

  • Stripe privacy policy
  • Zoho privacy policy and group locations
  • KIRI Engine privacy policy

Contact support if you need more specific information about a recipient or location associated with your enquiry or order.

6. Cookies, browser storage and embedded viewers

The site uses cookies and browser storage for sessions, sign-in, request security, cart contents, cached account information and preferences. These are not all tracking or advertising tools. Their names and lifetimes can change with Magento or provider updates.

Sessions and request security
Examples include PHPSESSID and form_key. They connect browser requests to a session and help prevent forged form submissions.
Cart, account content and preferences
Examples include private_content_version, section_data_ids, mage-cache storage and related local-storage entries. They keep cart and account displays current and remember site preferences.
Payments and fraud prevention
Stripe tools can use identifiers such as __stripe_mid and __stripe_sid, and device or connection information to support secure payments and assess fraud risk.
Optional 3D and video content
Activating a hosted viewer connects your browser to its provider. The provider can receive your IP address, device details and information about the viewed content, and may use its own cookies or storage.

Listings can include viewers from KIRI Engine, Sketchfab or YouTube. The homepage 3D viewer loads when you choose to open it. Other listing media loads when its viewing controls activate it. Review the provider's policy before using an optional viewer. Sketchfab privacy information and Google and YouTube privacy information are available from those providers.

You can delete or block cookies and site storage through your browser settings. Doing so may prevent sign-in, checkout or cart features from working. You can choose not to activate an optional viewer. Newsletter choices are separate from browser cookie settings.

7. Marketing choices

Creating an account or placing an order does not automatically subscribe you to our newsletter. You can subscribe separately and unsubscribe through a marketing email, your account preferences where available, or support@theprovenance.store.

We honour opt-out requests as required by law. Necessary account, order, safety and support messages may still be sent because they are not newsletter marketing. We may keep a limited suppression record to avoid sending further unwanted marketing.

8. Security and retention

Information is held in our website databases, email systems, operational records and backups, and by relevant service providers. We use measures such as HTTPS, access controls and administrator authentication to reduce unauthorised access, loss, misuse, modification or disclosure. No internet service can guarantee absolute security.

We retain information for as long as reasonably needed for the purposes above and applicable legal obligations. Order and financial records may need to remain after an account closes. Support or dispute records may need to remain while an issue or legal claim is unresolved.

When information is no longer needed and retention is not required by law, we take reasonable steps to delete or de-identify it. Backup copies may remain until normal backup expiry and are not intended for unrelated active use.

If we become aware of a data breach, we assess it and make notifications required by applicable law. Tell support promptly if you suspect your account or information has been compromised.

9. Access, correction and deletion requests

You can update account details and saved addresses through your account. For a copy of information we hold, a correction, account closure or a deletion request, email support@theprovenance.store with enough detail to identify the information and the action requested.

We may reasonably verify your identity before releasing or changing personal information. Do not email a password, complete card number or unnecessary identity document. We will explain any verification information actually needed.

We do not charge for making an access or correction request. We aim to respond within a reasonable time, generally within 30 days. If the law permits us to refuse access or retain information, we will explain the reason and available complaint options where required. Deletion is subject to records we need or are required to retain and is not an absolute right in every case.

If another seller or service provider separately holds the information, you may also need to contact it. We can help identify the relevant recipient where practical.

10. Complaints, changes and contact

For a privacy question or complaint, email support with what happened, when it happened and the outcome you seek. We will review it, seek any further information reasonably needed and aim to respond within 30 days. If more time is needed, we will explain why.

If you are dissatisfied with our response, or have not received a response within a reasonable time, you may contact the Office of the Australian Information Commissioner. The OAIC can explain whether a complaint falls within its jurisdiction. Other legal rights and complaint avenues are not excluded.

Orders and seller accounts are intended for adults. If you believe a child has provided information that should not be held, contact us so we can assess it.

We update this page when our practices or applicable requirements change. The last-updated date identifies the current version. For a material change affecting how existing personal information is handled, we will provide an appropriate notice and seek separate consent where required.

Privacy enquiries, The Provenance
Lesson Planner Pty Ltd
ABN 38 669 086 337
Victoria, Australia
support@theprovenance.store

Read our terms and conditions

The Provenance
Melbourne, Australia

Subscribe to newsletter

  • About Us
  • Sell with us
  • Authenticity Promise
  • Contact Us
  • FAQs
  • Orders and Returns
© 2026 The Provenance. All rights reserved
T&Cs Privacy Policy