PROVENTRACK
Terms of Service

ProvenTrack privacy

Privacy & Cookies Policy

Effective date23 August 2026Last updated23 August 2026Version2026-08-23

This Policy describes the personal information and technical data involved when people use ProvenTrack or view product information supplied by our Customers.

It also explains essential cookies, theme storage, operational providers and how to make a privacy request.

On this page

  1. About this Policy
  2. People covered
  3. Account and profile information
  4. Company information
  5. Billing information
  6. Contact enquiries
  7. Product and supply-chain information
  8. Uploaded files
  9. Public product information
  10. Technical information
  11. QR analytics
  12. Activity logs
  13. How information is collected
  14. Why we use information
  15. Customer responsibility for publication
  16. Information about other people
  17. Cookies and browser storage
  18. Mapping and geocoding
  19. Google-hosted resources
  20. Who may receive information
  21. Overseas processing
  22. Payments
  23. Contact forms
  24. Security
  25. Data breaches
  26. Retention
  27. Account closure
  28. Access and correction
  29. Deletion and privacy requests
  30. Direct marketing and service messages
  31. Children
  32. Automated processes
  33. Aggregated and de-identified information
  34. Third-party links
  35. Privacy complaints
  36. Changes to this Policy

01

About this Policy

This Privacy & Cookies Policy explains how Arimsys Pty Ltd, operating ProvenTrack, collects, holds, uses and discloses personal information through the website, business dashboard, organisation management, public product passports and QR pages, contact forms, billing and related services. We handle personal information in accordance with the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply.

Back to top

02

People covered

This Policy covers visitors, QR scanners and public passport viewers; business representatives; organisation owners, admins, managers and viewers; pending organisation members; billing contacts; contact-form users; and people identified in product records, photographs or uploaded evidence.

Back to top

03

Account and profile information

We may collect first and last name, email and company email, password/authentication credentials in protected or hashed form, avatar, role, account type, organisation membership, approval status, and last-login information. We also record the version and server timestamp when Terms are accepted and the Privacy Policy is acknowledged.

Back to top

04

Company information

Organisation records may include company name, industry, business email, address, phone, website, country, organisation owner, memberships, roles and permissions. Some company information may also identify sole traders or individual representatives.

Back to top

05

Billing information

Billing data may include billing email, subscription plan and status, Stripe customer and subscription IDs, current billing period and payment-related metadata. Complete payment-card information entered directly into Stripe is generally processed by Stripe rather than stored by ProvenTrack.

Back to top

06

Contact enquiries

The ProvenTrack contact form collects name, company, email, optional phone and message, together with the date, time and source of the enquiry. It also processes security and rate-limit information, including an IP-derived hash, to prevent abuse and routes an internal notification through Resend.

Back to top

07

Product and supply-chain information

Product and supply-chain records are primarily business information, but may identify suppliers, certifiers, auditors, journey actors, people in photographs or people named in certificates and documents. Customers decide what they supply and are responsible for having lawful authority to do so.

Back to top

08

Uploaded files

Files can include avatars, product and gallery images, PDFs, certificates, traceability and sustainability reports, ESG material, audit reports, evidence, invoices, temperature logs and compliance records. Files may contain metadata or personal information within the file itself. Customers should inspect and redact files before upload.

Back to top

09

Public product information

Customers may publish product, organisation, journey, location, sustainability and supporting evidence through a public passport or QR link. Public material can be viewed without an account and may be copied, indexed, cached, downloaded, screenshotted or redistributed. Removal from ProvenTrack cannot guarantee removal of copies elsewhere.

Back to top

10

Technical information

We may process network address, IP-derived hashes, user-agent string, browser, device, operating system, timestamp, requested page or product, authentication/session data, and error, rate-limit or security information. The exact data varies with the feature and provider.

Back to top

11

QR analytics

When a public product passport is opened from a QR source, the current service can record the product ID/reference, product name, timestamp, source, full user-agent string and a shortened SHA-256-derived hash of the network address. The raw network address may be processed temporarily to create the hash and route the request. A hash is pseudonymised technical information and is not guaranteed to be anonymous, especially when combined with other data.

Back to top

12

Activity logs

Administrative and product activity records may identify the account and organisation, action, affected product, changed fields, timestamp and operational metadata such as import or evidence actions. We use these records for security, auditing, accountability, support and troubleshooting.

Back to top

13

How information is collected

We collect information directly from users and organisation administrators; through registration, organisation-access requests, account and product forms, CSV imports and file uploads; when QR codes and public pages are used; through billing and contact providers; and from infrastructure or security providers that help deliver the Services.

Back to top

14

Why we use information

We use information to create and secure accounts; authenticate sessions; manage organisations and RBAC; operate products, passports, QR links, public evidence and sustainability features; produce analytics; process billing; respond to enquiries; prevent abuse; maintain audit records; troubleshoot and improve the service; and comply with legal obligations or resolve disputes.

Back to top

15

Customer responsibility for publication

Business Customers control much of the content made public. They must determine that publication is lawful, proportionate and accurate, give required notices, obtain permissions and avoid publishing unnecessary personal or confidential information. ProvenTrack provides publication technology but does not replace a Customer’s privacy assessment.

Back to top

16

Information about other people

Before supplying information about employees, suppliers, contractors, auditors, certifiers or other individuals, Customers must have lawful authority, provide any required notice and limit the information to what is reasonably necessary. Sensitive or confidential details should be removed or redacted.

Back to top

17

Cookies and browser storage

ProvenTrack uses essential authentication and session cookies for sign-in, session maintenance and secure account access. The key provena-landing-theme is stored in localStorage to remember light, dark or system appearance preferences; it is not used for behavioural advertising.

Cloudflare Turnstile may use technical data for spam and bot protection. Upstash supports rate limiting where configured. Stripe may use its own cookies on Stripe-hosted pages and services. The current application is not designed around behavioural-advertising cookies or pixels, so we do not display a broad advertising-cookie consent banner. If non-essential tracking requiring consent is introduced, the consent approach will be reassessed.

Back to top

18

Mapping and geocoding

Product journey maps may use OpenStreetMap data, Nominatim geocoding and CARTO map tiles. Loading or requesting those resources can send ordinary network information, such as IP address and user-agent, to the relevant provider. Map and geocoding results may be approximate.

Back to top

19

Google-hosted resources

The application may load Google-hosted fonts or related resources. When loaded from an external provider, ordinary request information may be disclosed to that provider. Availability and processing are governed by the provider’s own practices.

Back to top

20

Who may receive information

Information may be disclosed to authorised users within the relevant organisation; viewers of Customer-selected public passports; Stripe; AWS/S3; MongoDB; Resend; Upstash; Cloudflare; OpenStreetMap/Nominatim, CARTO and Google; hosting/CDN and operational providers; professional or legal advisers; transaction counterparties where legally appropriate; and regulators, courts or authorities where required.

Back to top

21

Overseas processing

Our providers may process information in Australia, the United States and other countries where their infrastructure, personnel or subprocessors operate. Locations can change and may depend on Customer configuration. Overseas recipients may be subject to different privacy laws. We take reasonable steps appropriate to the circumstances when selecting and using providers.

Back to top

22

Payments

Stripe processes payment and checkout information and may provide ProvenTrack with subscription status, customer/subscription identifiers and billing metadata. Card details entered directly into Stripe are handled under Stripe’s privacy practices. ProvenTrack uses returned billing data to administer plan access, renewals and cancellation.

Back to top

23

Contact forms

Contact submissions are validated and may be protected by Cloudflare Turnstile and Upstash rate limiting. The server may temporarily process the network address and store a shortened hash for abuse prevention. Enquiry details are saved and a Resend email notification may be sent to an internal inbox. The internal inbox is not published as a public legal contact.

Back to top

24

Security

Measures evident in the current service include password hashing, authenticated sessions and tokens, organisation and role-based controls, upload type/size restrictions, security and activity logging, rate limiting, bot protection and restricted administrative actions. We use reasonable technical and organisational measures, but no system is immune from misuse, loss or unauthorised access.

Back to top

25

Data breaches

We assess suspected incidents and take reasonable containment, investigation and remediation steps. Where the Privacy Act’s Notifiable Data Breaches scheme applies and an eligible data breach occurs, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

Back to top

26

Retention

Retention depends on active accounts, organisation and product operations, billing, audit and security needs, disputes, backups and legal obligations. We do not promise a single fixed period where the system does not enforce one. Information no longer reasonably required will be deleted or de-identified where appropriate and legally applicable, subject to backups and required retention.

Back to top

27

Account closure

Closing an individual account is not necessarily the same as deleting organisation-owned products, public passports, billing or audit records. An organisation may need continuity of records when a representative leaves. We assess account and organisation data separately and may restrict access while retaining records lawfully required or owned by the organisation.

Back to top

28

Access and correction

You may request access to or correction of personal information we hold about you. Some profile information can be updated in account settings. For other information, submit a privacy request. We may verify identity, consult the organisation that controls a record and refuse or limit a request where permitted by law, explaining the reason where required.

Back to top

29

Deletion and privacy requests

Authenticated users can submit ACCESS, CORRECTION, DELETION or OTHER requests from Privacy & Data settings; other people can use our contact form. Requests are reviewed rather than causing instant deletion. Identity verification may be required, and legal, billing, security, dispute, audit or organisation-owned records may need to be retained.

Back to top

30

Direct marketing and service messages

Operational messages about accounts, approvals, security, billing, service changes or requests are service communications, not optional marketing. Where we send direct marketing, we will provide an appropriate way to opt out and honour applicable requirements. Opting out of marketing does not stop necessary service messages.

Back to top

31

Children

Business accounts are not intended for children. Account users should be at least 18. Public passports may be viewed generally, but Customers should avoid publishing unnecessary information about children and must obtain any authority required by law.

Back to top

32

Automated processes

Authentication, input validation, plan-limit enforcement, rate limiting and bot detection use automated technical rules. They support security and service operation and are not intended to make significant automated decisions about a person’s broader legal rights. Users can contact us if a technical control appears to have affected them incorrectly.

Back to top

33

Aggregated and de-identified information

We may use aggregated or appropriately de-identified information for service analytics, capacity planning, security and business reporting. We take care not to describe merely pseudonymised identifiers, such as an IP-derived hash, as necessarily anonymous. If information can reasonably identify a person, we continue to treat it accordingly.

Back to top

34

Third-party links

ProvenTrack may link to Customer sites, evidence issuers, maps, payment pages or other third parties. We do not control their content or privacy practices. Review the relevant third party’s notices before providing information.

Back to top

35

Privacy complaints

Please raise privacy concerns with ProvenTrack first using the contact details below so we can investigate and respond. If Australian privacy law applies and you are dissatisfied with our response, you may contact the OAIC through oaic.gov.au.

Back to top

36

Changes to this Policy

We may update this Policy when our Services, providers or legal obligations change. The current version and date are shown above. We will provide reasonable notice of material changes and may ask logged-in users to acknowledge a new version before continuing to the dashboard.

Back to top

CONTACT

Contact ProvenTrack

Arimsys Pty Ltd
ABN 62 672 927 454
Ground Floor, 470 St Kilda Rd
Melbourne VIC 3004
Australia

Please use the ProvenTrack contact form for legal or privacy enquiries.

© 2026 ProvenTrack
HomeTerms of ServicePrivacy & Cookies