Prelaunch notice. Commercial launch and legal review are incomplete. Public contact details have not yet been published.
Prelaunch privacy notice
Version prelaunch-2026-09-30-v1. Stockroom Control Brisbane is preparing this service for launch. Legal and operational review is incomplete; this notice is not a certification of compliance. Public email and mailing details are not currently published.
Information processed
Sign-in processes your account identifier, name, email, verification status and authenticator confirmation. Account email remains necessary for identity verification even though no public contact email is displayed. Google supplies basic identity/profile information; sign-in does not grant access to Gmail, Drive or contacts. Microsoft sign-in is disabled.
Authorised work records can include products, barcodes, counts, locations, suppliers, orders, sales totals, extracted docket text, notes, membership and audit attribution. Remove unnecessary personal information. Do not enter passwords, recovery codes, payment card details or sensitive personal information into business records. Original uploaded document binaries are not retained; reviewed extracted content and metadata can be stored.
Providers and locations
Supabase Auth handles identity in the configured Sydney project. Cloudflare Workers hosts the application and D1 stores application records; the database was created with an Oceania location hint. These settings are not an Australia-only processing or residency guarantee. Provider operations, network traffic and support may involve other countries. Transactional email delivery is still being configured.
Access and retention
The server enforces authenticator sign-in, verified identity and assigned business permissions. Authorised administrators and service providers can process relevant information; encryption does not hide records from the service operator. Encrypted expiring provider access proofs support ongoing session checks; refresh tokens are not retained by the application. Security events and account attribution are recorded. No advertising trackers are included.
Retention schedules, automated deletion, external backup arrangements and recovery testing remain under review. Do not assume closing an account deletes business or audit records. Downloaded reports and backups require separate protection. Where available, use your existing agreed administrator channel for access or correction requests; no new public request channel is being represented as operational.
Backups and current limitations
Owner browser snapshots are encrypted and limited to 10,000 included rows, 1 MiB of encoded rows total and 512 KiB per table. Oversized exports fail without returning a partial backup. Provider identities, MFA secrets, reusable sessions and unretained original uploads are excluded. Full operator export is a separate procedure. Restores require isolation, disabled access and reconciliation of later deletions. Live provider, email, recovery and production capacity acceptance remains incomplete.