Privacy Policy, Shishka Media
Effective date: 10 August 2026. Updated: 8 September 2026.
1. Who we are
Shishka Media (ABN 63 373 868 212) is a marketing agency based on the Gold Coast, Queensland, Australia, founded and operated by Callum Heathwood. We build marketing systems for Australian financial advisers, finance brokers and other professional services firms, and we provide a done-for-you social media content service, The Financial Social Engine.
This policy explains how we collect, use, hold and disclose personal information across our website (shishkamedia.com), our client portal and our services. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We hold ourselves to the full APP standard regardless of any exemption that might otherwise apply to a business of our size, because our clients expect it and so do we.
2. What personal information we collect
We collect different information depending on who you are.
Prospects and website visitors. Your name, email address, phone number, business name and role if you fill in a form, book a call or download a resource. We also collect technical data such as your IP address, device and browser type, pages visited and how you found us.
Clients. Contact details, business details, and the licence and authorisation details you give us at onboarding (such as AFSL or Australian Credit Licence numbers, representative numbers, licensee details, authorisations and product classes, and any prescribed warning wording). Billing details: subscription payments are processed by Stripe, our payment provider, and we do not store full card numbers. Your brand assets and content preferences, including photos you supply, which may include images of you and your team. Records of approvals, flags, sends for scheduling, instructions, and correspondence with us, which we keep as part of the compliance record for your content.
Client team members. Names, work contact details and portal login details for people our clients authorise to work with us.
Leads and customers of our clients ("end-leads"). When someone requests a resource through a comment-keyword flow we run on a client's Instagram or Facebook account, or otherwise interacts with a client's campaigns, we handle their details on that client's behalf. For the comment-keyword flow this means their name, email address and phone number, given by them in the direct message conversation, together with the conversation steps (their keyword comment, their confirmation that they wanted the resource, the details they shared, and delivery of the resource link). See section 10 for how that flow works.
We do not seek sensitive information (such as health, financial hardship or political details), and we ask you not to submit it through our forms or messages. Where it is lawful and practicable, you can deal with us anonymously, for example when browsing our website.
3. How we collect it
- Directly from you, when you fill in a form, email us, book a call or use the portal.
- From our clients, when they give us details of their team members or existing contacts so we can deliver services.
- Through comment-keyword direct message flows we operate on clients' Instagram and Facebook accounts, and through funnels, forms and landing pages we operate on behalf of clients.
- Automatically, through cookies and similar technologies on our website and portal (see section 12).
- From platforms our clients have authorised us to work with, such as their social media accounts.
4. Why we use it
For our own business (where we decide how information is used):
- To respond to enquiries and provide our services.
- To manage client relationships, accounts, approvals and billing.
- To send our own marketing to people who have consented, or who would reasonably expect it as an existing contact (see section 11).
- To improve our website, portal and services.
- To meet our legal obligations.
On behalf of our clients (where the client decides how information is used): When we handle end-lead information, we act on our client's behalf and under their instructions, in the way a service provider acts for the business you actually dealt with. The client decides why that information is collected and how it is used. We use it only to deliver the agreed services, for example capturing leads through the comment-keyword flow, delivering the requested resource, managing bookings and reporting to the client. We do not use end-lead information for our own marketing, and we never sell personal information.
We produce marketing content with generative artificial intelligence systems from the providers listed in section 5 (Anthropic for written copy; Flora and Google for imagery), operating under our production rules and content doctrine. Every piece of content is reviewed and approved by a human, our client, before it is published. We do not use personal information in computer programs to make decisions that significantly affect anyone's rights or interests.
5. Who we share it with, including overseas
We share personal information only where needed to run our business and deliver our services:
- Amazon Web Services (Sydney, Australia). Our content engine, its PostgreSQL database and its image render storage are hosted in the AWS Sydney region. Render images are stored privately and are accessed only through short-lived signed links; they are never publicly accessible.
- GoHighLevel. Our customer relationship management platform, which holds client sub-accounts, lead contact details and the messaging workflows behind the comment-keyword flow. It is hosted in the United States, so information handled through it is stored and processed there.
- Lovable Cloud (Supabase), Australia. The backend for our client portal, holding portal accounts and content review data. It is hosted in an Australian region. Lovable Cloud is powered by Supabase, as both providers describe publicly.
- Stripe. Our payment processor for subscription billing. Stripe handles payment card details directly, and we do not store full card numbers. Stripe may process payment information outside Australia, including in the United States.
- Anthropic. An AI provider we use to generate content copy. It may process data outside Australia.
- Flora and Google. We generate content imagery through Flora, a creative AI platform; within Flora, our image requests are processed by Google's Gemini 3 Pro Image model (known as Nano Banana Pro). These providers may process data outside Australia.
- Font services: Google Fonts and Adobe Fonts. When our engine produces content, its rendering browser loads a client's chosen fonts from Google Fonts or, where the client has supplied their own Adobe Fonts web project, from Adobe Fonts. These services receive standard technical requests (the font family or project identifier and our server's address) each time content is produced. We store only the family name or project identifier, never font files. Google and Adobe may process those requests outside Australia.
- n8n Cloud. An automation service we use for research automation supporting content production. It may process data outside Australia.
- Meta Platforms and LinkedIn (Instagram, Facebook, LinkedIn), when we publish approved content to a client's own connected accounts and, on Instagram and Facebook, when we operate the comment-keyword flow.
- Accounting, email and infrastructure providers that support our business.
- Our clients, who receive information about their own leads, since we hold it for them.
- Professional advisers, regulators or law enforcement, where the law requires or permits it.
Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, including choosing reputable providers, using contractual protections and limiting what we share to what the service needs. Countries currently include the United States (GoHighLevel, Stripe, Google Fonts and Adobe Fonts) and the countries in which our AI, imagery and research automation providers process data.
6. How we keep it secure
We take reasonable steps, including technical and organisational measures, to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption in transit, access controls and least-privilege access, unique logins for the portal, private image storage accessed only through short-lived signed links, and secure authorised connections to client social accounts (we never hold client passwords, and access can be revoked at any time). If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
7. How long we keep it
We keep personal information only as long as we need it for the purposes described in this policy, and to meet legal, tax and accounting obligations.
If a client cancels their subscription, the service pauses rather than being erased. We retain the client's portal account, their records of approvals and publication history (which form part of the compliance record for their content), and their CRM sub-account including their lead information, so the service can resume if they return and so the compliance record stays intact. Published content and the client's social media accounts remain the client's. End-lead information is held on our client's behalf and in line with their instructions.
If a client asks us to delete their retained information, we will delete it, other than records we are required to keep by law and the approval and publication records that form the compliance record for their published content. When information is genuinely no longer needed for these purposes, we take reasonable steps to delete or de-identify it.
8. Access and correction
You can ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete or misleading. Email hello@shishkamedia.com and we will respond within 30 days. We do not charge for making a request. If we refuse a request, we will explain why in writing and tell you how to complain.
If your information relates to your dealings with one of our clients, the client controls that information, so we may refer your request to them and will help make that handover smooth.
9. Complaints
If you think we have mishandled your personal information, please contact us first at hello@shishkamedia.com. We take complaints seriously, will acknowledge yours promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, you can complain to the OAIC:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
10. Lead capture in direct messages
On some client accounts we run a comment-keyword flow on Instagram and Facebook. If you comment a nominated keyword on a participating post, here is what happens and what it means for your information:
- An automated direct message from the client's own account asks you to confirm that you wanted the resource. Nothing else happens unless you confirm. This message, and the one before any details are requested, tell you that you can reply STOP to opt out.
- Before we ask for any details, you are sent a message explaining why and how your information will be collected, with a link to the applicable privacy policy. You then choose whether to continue; details are only requested if you do.
- If you continue, the conversation asks for your name, email address and phone number. If something looks incomplete, the conversation asks once more for the missing detail, then the resource is sent to you in the same conversation either way.
- Your keyword comment and your confirmation authorise that delivery conversation only. They are not consent to ongoing marketing. Ongoing marketing from the client requires your separate express opt-in.
- You can stop the conversation at any time by replying STOP, and no further messages will be sent in that flow. If you change your mind, replying START turns messages back on.
- The details you share are collected on behalf of the client whose account you interacted with, are stored in our CRM platform (see section 5), and are made available to that client as their lead. LinkedIn is not part of this flow; nothing is automated on LinkedIn.
11. Marketing messages, consent and opting out
We comply with the Spam Act 2003 (Cth) for all commercial electronic messages, whether sent for ourselves or on behalf of clients, and direct messages are treated as being in scope. That means:
- Consent. We only send marketing messages to people who have given express consent, or whose consent can reasonably be inferred from an existing relationship. A keyword comment in the flow described in section 10 is consent for the delivery conversation only, not for ongoing marketing; ongoing marketing requires a separate express opt-in.
- Identification. Every message clearly identifies the business that authorised it. Messages we send on a client's behalf are sent from that client's own account or in that client's name.
- Unsubscribe. Every marketing message includes a working opt-out. In the direct message flow, replying STOP opts you out and is honoured mechanically. Opt-outs are honoured promptly and in any case within 5 business days. Unsubscribing from a client's messages stops that client's messages; it does not affect other senders.
You can also opt out of our own marketing at any time by emailing hello@shishkamedia.com.
12. Cookies and analytics
Our website and portal use cookies and similar technologies to keep the sites working properly, remember your preferences and measure how the sites are used. Analytics tools may transfer data to their providers overseas, including the United States. You can control or delete cookies through your browser settings, though some features may not work without them.
13. Changes to this policy
We may update this policy from time to time. The current version will always be published on our website with its effective date, and we will let clients know about material changes.
14. Contact us
Shishka Media ABN: 63 373 868 212 Email: hello@shishkamedia.com