01
About this Policy
This Privacy & Cookies Policy explains how Arimsys Pty Ltd, operating ProvenTrack, collects, holds, uses and discloses personal information through the website, business dashboard, organisation management, public product passports and QR pages, contact forms, billing and related services. We handle personal information in accordance with the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply.
02
People covered
This Policy covers visitors, QR scanners and public passport viewers; business representatives; organisation owners, admins, managers and viewers; pending organisation members; billing contacts; contact-form users; and people identified in product records, photographs or uploaded evidence.
03
Account and profile information
We may collect first and last name, email and company email, password/authentication credentials in protected or hashed form, avatar, role, account type, organisation membership, approval status, and last-login information. We also record the version and server timestamp when Terms are accepted and the Privacy Policy is acknowledged.
04
Company information
Organisation records may include company name, industry, business email, address, phone, website, country, organisation owner, memberships, roles and permissions. Some company information may also identify sole traders or individual representatives.
05
Billing information
Billing data may include billing email, subscription plan and status, Stripe customer and subscription IDs, current billing period and payment-related metadata. Complete payment-card information entered directly into Stripe is generally processed by Stripe rather than stored by ProvenTrack.
06
Contact enquiries
The ProvenTrack contact form collects name, company, email, optional phone and message, together with the date, time and source of the enquiry. It also processes security and rate-limit information, including an IP-derived hash, to prevent abuse and routes an internal notification through Resend.
07
Product and supply-chain information
Product and supply-chain records are primarily business information, but may identify suppliers, certifiers, auditors, journey actors, people in photographs or people named in certificates and documents. Customers decide what they supply and are responsible for having lawful authority to do so.
08
Uploaded files
Files can include avatars, product and gallery images, PDFs, certificates, traceability and sustainability reports, ESG material, audit reports, evidence, invoices, temperature logs and compliance records. Files may contain metadata or personal information within the file itself. Customers should inspect and redact files before upload.
09
Public product information
Customers may publish product, organisation, journey, location, sustainability and supporting evidence through a public passport or QR link. Public material can be viewed without an account and may be copied, indexed, cached, downloaded, screenshotted or redistributed. Removal from ProvenTrack cannot guarantee removal of copies elsewhere.
10
Technical information
We may process network address, IP-derived hashes, user-agent string, browser, device, operating system, timestamp, requested page or product, authentication/session data, and error, rate-limit or security information. The exact data varies with the feature and provider.
11
QR analytics
When a public product passport is opened from a QR source, the current service can record the product ID/reference, product name, timestamp, source, full user-agent string and a shortened SHA-256-derived hash of the network address. The raw network address may be processed temporarily to create the hash and route the request. A hash is pseudonymised technical information and is not guaranteed to be anonymous, especially when combined with other data.
12
Activity logs
Administrative and product activity records may identify the account and organisation, action, affected product, changed fields, timestamp and operational metadata such as import or evidence actions. We use these records for security, auditing, accountability, support and troubleshooting.
13
How information is collected
We collect information directly from users and organisation administrators; through registration, organisation-access requests, account and product forms, CSV imports and file uploads; when QR codes and public pages are used; through billing and contact providers; and from infrastructure or security providers that help deliver the Services.
14
Why we use information
We use information to create and secure accounts; authenticate sessions; manage organisations and RBAC; operate products, passports, QR links, public evidence and sustainability features; produce analytics; process billing; respond to enquiries; prevent abuse; maintain audit records; troubleshoot and improve the service; and comply with legal obligations or resolve disputes.
15
Customer responsibility for publication
Business Customers control much of the content made public. They must determine that publication is lawful, proportionate and accurate, give required notices, obtain permissions and avoid publishing unnecessary personal or confidential information. ProvenTrack provides publication technology but does not replace a Customer’s privacy assessment.
16
Information about other people
Before supplying information about employees, suppliers, contractors, auditors, certifiers or other individuals, Customers must have lawful authority, provide any required notice and limit the information to what is reasonably necessary. Sensitive or confidential details should be removed or redacted.
18
Mapping and geocoding
Product journey maps may use OpenStreetMap data, Nominatim geocoding and CARTO map tiles. Loading or requesting those resources can send ordinary network information, such as IP address and user-agent, to the relevant provider. Map and geocoding results may be approximate.
19
Google-hosted resources
The application may load Google-hosted fonts or related resources. When loaded from an external provider, ordinary request information may be disclosed to that provider. Availability and processing are governed by the provider’s own practices.
20
Who may receive information
Information may be disclosed to authorised users within the relevant organisation; viewers of Customer-selected public passports; Stripe; AWS/S3; MongoDB; Resend; Upstash; Cloudflare; OpenStreetMap/Nominatim, CARTO and Google; hosting/CDN and operational providers; professional or legal advisers; transaction counterparties where legally appropriate; and regulators, courts or authorities where required.
21
Overseas processing
Our providers may process information in Australia, the United States and other countries where their infrastructure, personnel or subprocessors operate. Locations can change and may depend on Customer configuration. Overseas recipients may be subject to different privacy laws. We take reasonable steps appropriate to the circumstances when selecting and using providers.
22
Payments
Stripe processes payment and checkout information and may provide ProvenTrack with subscription status, customer/subscription identifiers and billing metadata. Card details entered directly into Stripe are handled under Stripe’s privacy practices. ProvenTrack uses returned billing data to administer plan access, renewals and cancellation.
23
Contact forms
Contact submissions are validated and may be protected by Cloudflare Turnstile and Upstash rate limiting. The server may temporarily process the network address and store a shortened hash for abuse prevention. Enquiry details are saved and a Resend email notification may be sent to an internal inbox. The internal inbox is not published as a public legal contact.
24
Security
Measures evident in the current service include password hashing, authenticated sessions and tokens, organisation and role-based controls, upload type/size restrictions, security and activity logging, rate limiting, bot protection and restricted administrative actions. We use reasonable technical and organisational measures, but no system is immune from misuse, loss or unauthorised access.
25
Data breaches
We assess suspected incidents and take reasonable containment, investigation and remediation steps. Where the Privacy Act’s Notifiable Data Breaches scheme applies and an eligible data breach occurs, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.
26
Retention
Retention depends on active accounts, organisation and product operations, billing, audit and security needs, disputes, backups and legal obligations. We do not promise a single fixed period where the system does not enforce one. Information no longer reasonably required will be deleted or de-identified where appropriate and legally applicable, subject to backups and required retention.
27
Account closure
Closing an individual account is not necessarily the same as deleting organisation-owned products, public passports, billing or audit records. An organisation may need continuity of records when a representative leaves. We assess account and organisation data separately and may restrict access while retaining records lawfully required or owned by the organisation.
28
Access and correction
You may request access to or correction of personal information we hold about you. Some profile information can be updated in account settings. For other information, submit a privacy request. We may verify identity, consult the organisation that controls a record and refuse or limit a request where permitted by law, explaining the reason where required.
29
Deletion and privacy requests
Authenticated users can submit ACCESS, CORRECTION, DELETION or OTHER requests from Privacy & Data settings; other people can use our contact form. Requests are reviewed rather than causing instant deletion. Identity verification may be required, and legal, billing, security, dispute, audit or organisation-owned records may need to be retained.
30
Direct marketing and service messages
Operational messages about accounts, approvals, security, billing, service changes or requests are service communications, not optional marketing. Where we send direct marketing, we will provide an appropriate way to opt out and honour applicable requirements. Opting out of marketing does not stop necessary service messages.
31
Children
Business accounts are not intended for children. Account users should be at least 18. Public passports may be viewed generally, but Customers should avoid publishing unnecessary information about children and must obtain any authority required by law.
32
Automated processes
Authentication, input validation, plan-limit enforcement, rate limiting and bot detection use automated technical rules. They support security and service operation and are not intended to make significant automated decisions about a person’s broader legal rights. Users can contact us if a technical control appears to have affected them incorrectly.
33
Aggregated and de-identified information
We may use aggregated or appropriately de-identified information for service analytics, capacity planning, security and business reporting. We take care not to describe merely pseudonymised identifiers, such as an IP-derived hash, as necessarily anonymous. If information can reasonably identify a person, we continue to treat it accordingly.
34
Third-party links
ProvenTrack may link to Customer sites, evidence issuers, maps, payment pages or other third parties. We do not control their content or privacy practices. Review the relevant third party’s notices before providing information.
35
Privacy complaints
Please raise privacy concerns with ProvenTrack first using the contact details below so we can investigate and respond. If Australian privacy law applies and you are dissatisfied with our response, you may contact the OAIC through oaic.gov.au.
36
Changes to this Policy
We may update this Policy when our Services, providers or legal obligations change. The current version and date are shown above. We will provide reasonable notice of material changes and may ask logged-in users to acknowledge a new version before continuing to the dashboard.
CONTACT
Contact ProvenTrack
Arimsys Pty Ltd
ABN 62 672 927 454
Ground Floor, 470 St Kilda Rd
Melbourne VIC 3004
Australia
Please use the ProvenTrack contact form for legal or privacy enquiries.