← yaaarn.com

privacy policy

effective 25 may 2026 · yaaarn pty ltd

who we are

yaaarn pty ltd (abn 57 697 360 213, acn 697 360 213) is a brand studio based in melbourne, australia. you can reach us at hello@yaaarn.com for any privacy question or request.

what this policy covers

this policy explains what information we collect when you visit yaaarn.com, when you contact us, and when we use third-party services (including the pinterest api and other reference libraries) to do creative work on behalf of our clients. it complies with the australian privacy act 1988 and the thirteen australian privacy principles.

what we collect when you visit yaaarn.com

we use vercel analytics and vercel speed insights to understand how visitors use the site. these services collect anonymous information such as the pages you view, how long you spend, your approximate region, browser type, and connection speed. they do not use cookies that identify you personally, and they do not track you across other websites. you can read vercel's privacy practices at vercel.com/legal/privacy-policy.

what we collect when you contact us

if you send us a message via the contact form or by emailing hello@yaaarn.com, we keep the message and your reply address so we can answer you. we do not add you to a marketing list. we do not share your message with anyone outside the yaaarn team or our retained professional advisers (legal, accounting) unless you ask us to.

cookies

yaaarn.com uses a small number of strictly necessary cookies for site function. it does not set marketing or advertising cookies. analytics is provided by vercel, which uses anonymous identifiers rather than tracking cookies.

how we use third-party reference libraries

yaaarn builds visual concepts for client campaigns. as part of that work our internal team queries third-party reference libraries, including the pinterest api (v5), eyecandy (eyecannndy.com), and similar resources, to retrieve publicly available reference imagery that informs our briefs and storyboards. this happens behind our own authentication; no yaaarn.com visitor data is sent to these services as part of normal site use.

pinterest api specifically

  • we use the pinterest api only to retrieve public search results and public board contents that pinterest itself makes available through that api, for the sole purpose of internal creative reference.
  • we do not access, ask for, or store any pinterest user's login credentials.
  • we do not store any data returned by the pinterest api beyond the duration of a single api call. any reference image rendered from a pinterest result is fetched live from pinterest at the moment of rendering, and discarded when our team closes the reference panel.
  • we do not share, sell, or otherwise pass pinterest api data to any third party.
  • we do not use information from pinterest to target people with advertising outside of pinterest, whether directly or bundled with any third-party data, in line with pinterest's developer guidelines.
  • we comply with pinterest's developer guidelines and developer and api terms of service. if you are a pinterest user and would like a specific public pin not to appear in our internal reference searches, email hello@yaaarn.com with the pin url and we will exclude it from our queries within seven days.

ai services we use to do our work

our internal creative pipeline calls large-language and image-generation services (google gemini, anthropic claude, higgsfield) to draft copy, generate concept imagery, and analyse references. visitor data from yaaarn.com is not sent to these services. client data that we send to these services is sent under the providers' enterprise data-protection terms, which forbid the providers from training their models on our prompts.

your rights

under the australian privacy act you can ask us to:

  • tell you what personal information we hold about you;
  • correct any of that information that is wrong or out of date;
  • delete any of that information that we no longer need;
  • stop using or disclosing your information in a particular way.

email hello@yaaarn.com with the request and we will respond within thirty days. if you are not happy with our response you can complain to the office of the australian information commissioner at oaic.gov.au.

how long we keep your information

  • site analytics (vercel analytics and speed insights): retained by vercel under their stated retention windows; we do not export or warehouse this data ourselves.
  • messages you send us via the contact form or email: kept while the conversation is active and for up to twenty-four months after the last message, so we can pick up where we left off. you can ask us to delete the thread sooner by emailing hello@yaaarn.com.
  • pinterest api results: never persisted. discarded at the end of each api call.
  • records we are required to keep by law (for example tax records under the australian taxation office's five-year retention requirement) are kept for the legally required period and no longer.

data storage, security, and international transfers

yaaarn.com is hosted by vercel inc., which stores data in secure cloud infrastructure including data centres located outside australia (primarily in the united states and the european union). team correspondence and client work files are stored in google workspace and vercel blob storage. all are access-controlled and require multi-factor authentication. when we send data to a third-party service outside australia (vercel, google, anthropic, higgsfield, pinterest), we take reasonable steps to confirm that the recipient handles the data consistently with the australian privacy principles, in line with app 8.

for visitors from the european union or united kingdom

if you are located in the european union or the united kingdom, the general data protection regulation (gdpr) and the uk gdpr apply to our processing of your personal data. this section sets out the additional disclosures gdpr requires.

data controller. yaaarn pty ltd is the data controller for personal data collected through yaaarn.com. you can contact us at hello@yaaarn.com. we do not currently have a designated eu/uk representative; if you reach out to us at that address we will respond within thirty days.

legal bases for processing. we rely on the following lawful bases:

  • legitimate interests for running yaaarn.com, understanding aggregate site usage via vercel analytics, and improving the site. our legitimate interest is operating a small business website; we balance this against your interests using anonymous analytics rather than personal tracking.
  • contract or pre-contract when you contact us to discuss working together: we use your contact details to reply and to scope work.
  • consent if we ever ask you to subscribe to a newsletter or to send you marketing. you can withdraw consent at any time by replying unsubscribe or by emailing us.
  • legal obligation for tax, accounting, and other records we are required to retain.

your gdpr rights. under gdpr you have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased (right to be forgotten) where it is no longer needed; restrict our processing in some circumstances; receive your data in a portable format; object to processing based on legitimate interests; and withdraw consent at any time where consent is the lawful basis. to exercise any of these rights, email hello@yaaarn.com and we will respond within thirty days.

international transfers. your data may be transferred to and processed in countries outside the eea or uk, including the united states and australia, where some of our service providers operate. where required, transfers rely on the european commission's standard contractual clauses or an adequacy decision (for example, the uk-australia data bridge, where relevant). by contacting us you acknowledge that your data may be transferred to australia for our team to read and reply.

complaints. you have the right to lodge a complaint with your local data-protection supervisory authority. in the uk that is the information commissioner's office (ico.org.uk). in the eu, complaints go to your member state's data-protection authority; a directory is at edpb.europa.eu.

automated decision-making. we do not subject visitors to automated decision-making or profiling that produces legal or similarly significant effects.

providing data is optional. you can browse yaaarn.com without giving us any personal data. the contact form requires an email address so we can reply; if you do not provide one we cannot answer you.

changes to this policy

we will update this page when our practices change. the effective date at the top of this page tells you when it last changed. if we make a material change that affects how we handle your personal information, we will note it on this page for at least thirty days after the change takes effect.

yaaarn pty ltd · abn 57 697 360 213 · acn 697 360 213
u1803 3 yarra st south yarra vic 3141 australia
hello@yaaarn.com