Privacy Policy
Privacy Policy — Pawventory
Last updated: 28 September 2026 - Under Review
This Privacy Policy explains how Pawventory (“we”, “us”, “our”), operated by Dana Willis in Australia, handles personal information when you use the Pawventory website and service.
We aim to handle personal information in a way that is consistent with the Australian Privacy Principles (APPs) under the *Privacy Act 1988* (Cth).
Contact for privacy: [email protected] General support: [email protected]
1. Who we are
Pawventory is a web application for managing pets and rescue animals. You can use it as:
- a household workspace (home pets and related care), or
- a rescue organisation workspace (managers, volunteers, fosters, and animal records).
There is no Australian Business Number (ABN) registered for this operator yet. We will update this policy if that changes.
2. What personal information we collect
2.1 About people (account holders and invitees)
Depending on how you use the service, we may collect:
- Account details: name, email address, password (stored as a secure hash, not plain text), optional date of birth, date/time display preferences
- Membership: workspace role (for example manager, volunteer, household owner/editor/viewer) and related permissions
- Invitations: email address if an invite is sent to a specific address; invite tokens and expiry
- Join requests: when you ask to join a rescue, we store your user id, the rescue id, and request status
- Animal transfers: recipient email and optional notes when transferring an animal to another household
- Ownership transfers: links between existing user accounts (no separate recipient-email field)
- Feature suggestions: title, details, type (suggestion or issue), optional photo, and (attached by us from your account) your name, email, and related workspace label — sent to our planning tool (Notion)
- Technical / session data: login timestamps and session cookies needed to keep you signed in
We do not currently collect payment card details in the app (Stripe is not currently active — see section 8).
2.2 About animals and operations (may include other people’s details)
Animal and operational records are the core of the product (identity, status, medical, diary, documents, photos, calendar events, care-share settings, and similar).
Important: free-text fields (notes, diary entries, clinic names, transfer notes, captions, uploaded documents/photos, and similar) may contain personal information about third parties (for example foster carers, vets, adopters, or family) if you type or upload it. We store what you enter; we do not separately model every third-party contact.
2.3 Information we do not systematically collect as structured fields
We do not have dedicated structured fields for adopter postal addresses, emergency contacts, or foster phone numbers as separate contact cards. Foster carers are linked as existing user accounts where used.
3. How we collect information
We collect personal information:
- directly from you when you sign up, update your profile, invite others, create records, upload files, or send a feature suggestion
- from other users in your workspace (for example a manager inviting you, or a teammate assigning you to an animal)
- automatically when you use the service (session cookies, authentication, security rate limits, and similar technical processing)
- when we send email through our email provider (Resend) for verification, password reset, invites, or transfers — the provider receives the recipient address and message content needed to deliver the email
4. Why we collect and use personal information
We use personal information to:
- create and secure accounts, verify email, reset passwords, and manage sessions
- provide household and rescue features (records, calendars, memberships, alerts, uploads)
- send transactional emails related to the service
- operate care-share links and PDFs that you choose to create
- process feature suggestions you submit
- enforce security (for example rate limiting and suspending accounts)
- administer the platform (including platform-administrator support; a super admin may temporarily view the app as your account to diagnose a fault)
- operate the service
We do not sell your personal information.
5. When we disclose personal information
We may disclose personal information to:
5.1 Other people you work with in Pawventory
Members of your household or rescue workspace can see information according to their role and the records in that workspace (for example animal records, calendar events, and member lists).
5.2 People you share with via links or transfers
- Care-share links are viewable by anyone who has the link (no login). You choose which sections are included. Shares can show selected animal information and, in some cases, assignee or foster name or email. Public care-share PDFs are not password-protected today.
- Invites and transfer links expose limited details needed to accept the invite or transfer.
- Joinable rescue search can return organisation name, id, and logo path without requiring the searcher to be logged in.
You are responsible for who you send links to and what sections you include.
5.3 Service providers (processors)
We use third parties to help run the service. Current processors include:
| Provider | Purpose |
|---|---|
| Resend | Transactional email delivery |
| Notion | Feature suggestion / planning cards (includes submitter name and email) |
| Database and object storage | PostgreSQL for app data; MinIO or other S3-compatible storage for files (configuration-dependent — may be local to the server or remote cloud storage) |
Hosting may sit behind a reverse proxy / tunnel (for example Cloudflare). Those providers process connection data as part of delivering the site.
When enabled / Not currently active:
| Provider | Purpose when enabled |
|---|---|
| Stripe | Subscription billing and customer portal (name, email, payment method metadata as processed by Stripe) |
| Google AdSense (or Ad Manager) | Advertising on free-tier pages only (see section 9) |
| DigitalOcean Spaces (or equivalent S3) | Object storage for media after planned production cutover |
| AI provider (vendor to be confirmed; may use Abacus or another) | Generating editable Rescue adoption write-ups from selected animal fields and your inputs (paid Rescue plans) |
We only enable these when the feature is turned on in the product. Until then, they are not currently active as live processors for that purpose.
6. Overseas disclosure
Some processors may store or process information outside Australia (for example email, Notion, and — where configured — remote S3-compatible storage). Exact production regions depend on deployment configuration and will be clearer after planned hosting cutover (including a planned DigitalOcean droplet and Spaces/S3 for media). Local MinIO storage on the same host may also be used depending on configuration. When AI or advertising features are enabled later, those providers may also process data overseas.
By using Pawventory you acknowledge that personal information may be disclosed to overseas recipients in those circumstances. We will take reasonable steps available to a small Australian operator, including reviewing provider privacy documentation where practicable.
7. Storage and security
We store account and operational data in a database and store uploaded files in object storage accessed through the app (uploads are not sent browser-direct to storage in the current design).
Security measures that exist in the product today include: password hashing, email verification before login, HttpOnly session cookies, role and membership checks, scoped file download paths, Content Security Policy and related browser headers, and in-process rate limiting on sensitive public endpoints. Automated off-site backups are not built into the application code; we aim to maintain sensible backup practices for production, but you should also keep copies of critical records where appropriate.
No method of transmission or storage is completely secure. Please use a strong unique password and protect care-share links.
8. Payments (When enabled / Not currently active)
Paid plans and Stripe billing are planned and not currently active in the live product. When enabled, Stripe will process payment and subscription data under Stripe’s terms and privacy policy. We will use billing information to provide the plan you choose, manage renewals and cancellations via Stripe’s Customer Portal, and enforce plan limits (for example warning near caps and blocking *new* adds — not locking existing files). Details of tiers and prices will appear in-product when billing is live.
Until Stripe is enabled, we do not charge through the app and do not collect card details in Pawventory.
9. Advertising and cookies
9.1 Cookies we use today
- Session / authentication cookies (NextAuth) to keep you signed in and protect forms
- Theme preference storage for light/dark (or similar) display
These are needed for the service to work as designed.
9.2 Ads (When enabled / Not currently active)
We plan optional Google AdSense (or Ad Manager) bottom banner ads on free workspaces only, on pages except animal file views, and not on paid plans. When that is enabled, advertising cookies and similar technologies from Google may apply under Google’s policies. Until enabled, we do not run AdSense in the live product.
We do not currently use separate marketing analytics pixels (for example Google Analytics) in the app code.
10. Artificial intelligence
Not currently active. There is no in-app AI chat or AI write-up feature live today.
When enabled: a planned Rescue AI adoption write-up feature would send selected animal characteristics and your inputs to an AI provider to generate editable listing text. When enabled, it will be limited to eligible paid Rescue plans and subject to generation quotas. We will not auto-post AI text to third-party adoption sites. The AI vendor (and their privacy terms) will be identified when the feature ships.
11. Access, correction, and deletion
You can view and update many account details in Settings (name, optional date of birth, display formats) and change email or password through the app’s account flows.
Export: you can create care-share links and PDFs for selected animal information. A full “download all my data” export of your account is not available yet, but may be added as a future feature. Until then, email [email protected] if you need a copy of your personal information.
Deletion: self-serve permanent account deletion is not available in the product yet, but is planned to be added soon. Until then, you may leave a workspace (subject to sole-manager/owner rules), or email [email protected] to request deletion. Platform administrators may soft-delete (suspend) accounts or workspaces, or — after suspension and further confirmation checks — hard-delete them. Suspended accounts cannot sign in.
To request access, correction, or deletion of personal information we hold about you, email [email protected]. We will respond within a reasonable time and explain if we cannot fully meet a request (for example legal retention needs or information that also belongs to another organisation’s workspace).
12. Children
Date of birth is optional and we do not currently enforce a minimum age in the product. If you believe someone under 18 has provided personal information inappropriately, contact [email protected].
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we revise it. Material changes may also be notified in-app or by email where appropriate. Continued use after an update means you accept the revised policy to the extent permitted by law.
14. Complaints
If you have a privacy concern, contact [email protected] first so we can try to resolve it. You may also have the right to complain to the Office of the Australian Information Commissioner (OAIC) — see https://www.oaic.gov.au.
15. Contact
Privacy: [email protected] Support: [email protected]
Pawventory is operated by Dana Willis (Australia).