Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
Running an online store in Australia is an exciting opportunity - but it also means playing by some important legal rules.
Recent regulator scrutiny of online retail has highlighted where things can go wrong: pricing claims, refund rights, delivery promises and how customer data is handled. Using Ozsale Pty Ltd’s flash-sale marketplace model as a case study, this guide breaks down the core Australian compliance lessons every online retailer should know.
If you sell online - whether you’re a boutique store, a marketplace, or a subscription brand - these are the practical steps to stay compliant and build customer trust from day one.
What Are The Big Legal Risks For Online Retailers In Australia?
Online retailers operate under the Australian Consumer Law (ACL) and other national rules that apply even if you don’t have a physical shopfront. The most common risk areas we see include:
- Misleading or deceptive conduct: Claims about price, discounts, stock levels, delivery timeframes or product features must be accurate and substantiated. Section 18 of the ACL prohibits conduct that is likely to mislead or deceive - that applies to your website, emails, socials and apps. See section 18.
- Pricing representations: Flash sales and countdowns can be effective, but be careful with savings claims, strike-through prices, and add‑on fees at checkout. “Drip pricing” and unclear advertised prices can breach the ACL. Review how you display prices against advertised price laws.
- Refunds and consumer guarantees: You can’t contract out of the ACL consumer guarantees. Your returns page and customer communications need to reflect genuine rights to repair, replace or refund. If you offer a warranty, ensure it meets the rules for a Warranties Against Defects Policy.
- Delivery claims: Promises like “express”, “next-day” or “guaranteed by Friday” must be achievable in practice across locations. Unexpected delays need clear notices and prompt remedies.
- Privacy and data handling: If you collect customer data through your store, you’ll need a clear and compliant Privacy Policy and robust data governance. Consider your retention, deletion and security practices in line with data retention laws.
- Email and SMS marketing: Consent, unsubscribe functionality and accurate sender details are essential. Make sure your campaigns align with email marketing laws.
In short, the same rules that apply in-store also apply online - plus extra obligations around data and digital communications.
Case Study Lens: What The Ozsale Model Highlights For Compliance
Ozsale’s marketplace-style flash sales, limited-time discounts and fast-moving inventory are popular ecommerce tactics. They also create specific compliance pressures that other retailers often share. Here are the lessons.
1) Limited-Time Discounts Need Real Comparators
If you’re showing “was/now” prices or percentage savings, keep records of how long the higher price was offered and where it was available. Ensure strike-through or “RRP” comparisons are genuine and not inflated.
Tip: Build an internal price substantiation log that captures product, dates, price points and evidence (e.g. screenshots or system exports). This reduces risk under the ACL’s general and specific prohibitions on false or misleading representations.
2) Stock Scarcity And Countdown Timers Must Be Accurate
Scarcity messaging drives conversions, but it must reflect reality. Only use timers and “Only 3 left!” notices if your backend inventory supports those claims. If you back-order or drop-ship, disclose expected delays clearly before checkout.
3) Delivery Claims Should Reflect Logistics Capacity
Be specific about locations and exclusions when you mention “express” or “next-day” shipping. Your courier SLAs, cut-off times and regional coverage need to match the promise on your product and checkout pages.
4) Refunds, Store Credit And Faulty Products
It’s fine to offer store credit for change-of-mind (if you choose to), but faulty or misdescribed goods trigger ACL remedies. Your policy and customer service scripts should reflect consumer guarantees, not just your internal preferences.
Consider a clear Returns and Refunds Policy within your Online Shop Terms that references ACL rights and how customers can claim them. Sprintlaw can help ensure your Online Shop Terms & Conditions and returns page are aligned with the law.
5) Data Practices Must Match Your Promises
Marketplace and flash-sale models collect large volumes of customer data. Your Privacy Policy should match the data you collect, why you collect it, who you share it with (including overseas processors), and how users can access or delete their data.
It’s also wise to prepare a Data Breach Response Plan so you can act quickly if something goes wrong.
How To Build Compliant Policies And Processes For Your Store
Compliance isn’t just legal words on your website - it’s the systems behind the scenes. Here’s how to embed good practices across your online retail operations.
Make Pricing And Promotions “Audit-Ready”
- Use a central register to store evidence for any discount or strike-through price.
- Pre-launch checklist: confirm timer logic, stock thresholds and promotion rules against your website copy.
- Post-campaign review: identify any customer complaints or anomalies and fix the underlying process.
Design A Customer-Friendly, ACL-Compliant Returns Flow
- Map out pathways for change-of-mind vs. faulty/unsafe goods and ensure the ACL path doesn’t require unnecessary steps.
- Train support staff and outsource partners on ACL language and remedies.
- Publish a plain-English summary of rights in your FAQs and returns page.
Set Realistic Delivery Expectations
- Display cut-off times and excluded postcodes near the delivery claim, not buried in a footer.
- Proactively notify customers of delays and offer options (refund, credit, or continued wait).
- Align courier SLAs with peak periods and surge volumes (e.g. sales events).
Get Your Data And Privacy Settings In Order
- Ensure your Privacy Policy matches actual practice (cookies, tracking, analytics, cross-border processing).
- Implement a consent mechanism for marketing and an easy unsubscribe.
- Document retention schedules consistent with data retention laws, then automate deletion where possible.
What Legal Documents Will An Online Retailer Need?
The right documents do two jobs: they set clear expectations with customers and suppliers, and they help you meet your legal obligations under the ACL and privacy laws. Key documents include:
- Website Terms & Conditions: House rules for using your site, IP ownership, acceptable use and liability caps. Start with robust Website Terms & Conditions tailored to your store and risk profile.
- Online Shop Terms & Conditions (Terms of Sale): The ecommerce-specific terms that cover ordering, pricing, delivery, returns and consumer guarantees. Sprintlaw’s Online Shop Terms & Conditions bundle these essentials in a clear format.
- Privacy Policy: Explains what personal information you collect, how you use it and customers’ rights. A compliant Privacy Policy is essential for any online store.
- Warranties Against Defects Policy: If you offer your own warranty (in addition to ACL rights), it must include specific wording, timeframes and contact details. Use a compliant Warranties Against Defects Policy.
- Cookie Policy: If you use cookies and tracking tech, a dedicated or integrated Cookie Policy helps with transparency and consent management.
- Data Breach Response Plan: A playbook to assess, contain and notify in the event of a suspected breach. Implement a practical Data Breach Response Plan before you need it.
- Customer Communications Templates: Refund approvals, delay notices and warranty responses aligned with the ACL (helps your team stay consistent).
Not every retailer will need every document, but most online stores will need at least Terms of Sale, a Privacy Policy and clear returns wording within the sales flow. If you operate a marketplace or subscription model, you may need additional platform or subscription terms.
Step-By-Step Compliance Checklist For Your Ecommerce Business
Use this practical checklist to review your store’s compliance posture - and turn lessons from the Ozsale model into action.
- Map Your Customer Journey: Identify every point where you make a claim (product page, price, shipping, checkout, emails) and verify accuracy under the ACL. For core obligations, start with section 18 and related misrepresentation provisions.
- Tighten Pricing Governance: Create a promotions sign-off process, keep evidence for comparative pricing, and review fees to avoid problematic drip pricing. Align displays with advertised price laws.
- Refresh Returns And Refunds: Ensure your returns page, customer emails and support scripts reflect ACL guarantees. If you offer a manufacturer or store warranty, implement a compliant warranty policy.
- Right-Size Delivery Promises: Update delivery claims to match logistics capacity. Publish cut-offs, exclusions and realistic windows where customers will see them.
- Publish And Apply Core Terms: Implement tailored Website Terms & Conditions and Online Shop Terms with consistent, plain-English customer rights.
- Get Privacy And Data Practices In Sync: Ensure your Privacy Policy matches reality, set retention rules consistent with data retention laws, and prepare a Data Breach Response Plan.
- Review Email And SMS Marketing: Confirm consent, identification and opt‑out mechanisms align with email marketing laws. Audit your abandoned cart and win‑back flows.
- Train Your Team: Run short refreshers for product, marketing and customer service staff so they understand what they can and can’t say under the ACL.
- Monitor And Iterate: Track complaints and chargebacks, review sale event outcomes, and fix root causes promptly - then update your policies and templates.
Key Takeaways
- Online retailers in Australia must ensure pricing, promotions, delivery claims and returns policies align with the Australian Consumer Law.
- Flash-sale and marketplace models increase pressure on price substantiation, scarcity messaging and delivery logistics - build controls before you launch campaigns.
- Publish clear Website Terms, Online Shop Terms and a compliant Privacy Policy so customers know their rights and you meet your legal obligations.
- Your returns page and customer service scripts should reflect consumer guarantees, not only your internal preferences for store credit or exchanges.
- Back up marketing with processes: keep pricing evidence, train staff, and prepare a Data Breach Response Plan to manage incidents fast.
- A short compliance checklist and regular reviews will keep your store aligned with the law as you grow.
If you’d like a consultation on setting up compliant online retail terms and processes for your store, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.








