Version 2.0 · Effective Date: August 06, 2026
1. Roles and Scope
PettyLogs provides a business operations platform. For account, security, billing, support, and analytics activities, PettyLogs determines how the relevant data is used. For customer, employee, supplier, and transaction records entered by an organisation, that organisation may be the data controller and PettyLogs provides the platform as a service provider or processor.
Organisations are responsible for providing appropriate notices and having a lawful basis for the personal data they enter into PettyLogs.
2. Data We Collect
- Account data: Name, email address, authentication identifiers, policy acceptance records, and account activity.
- Organisation data: Organisation name, email, address, phone number, country, currency, tax or registration details, timezone, roles, and invitations.
- Business and customer data: Names, email addresses, phone numbers, addresses, cities, postcodes, countries, notes, and any identification or tax details entered by an organisation.
- Transaction and repair data: Receipts, amounts, payment status, repair details, parts, labour, comments, warranties, device photos, and identifiers such as serial numbers, IMEIs, VINs, or licence plates when entered.
- Technical and usage data: Browser and device information, service activity, diagnostic information, and information that may be available to our servers or analytics providers, such as IP address.
- Notification data: If you enable push notifications, we store the browser push subscription endpoint and cryptographic keys linked to your account and device.
- Billing data: Subscription, organisation, and Stripe customer identifiers. Stripe processes payment details through its checkout and billing services.
- AI feature data: Prompts, catalogue information, URLs, and related inputs sent when you choose to use AI-assisted catalogue features.
3. How We Collect Data
- Directly from you when you register, use the service, contact support, or manage preferences.
- From an organisation when it creates or updates a customer, transaction, repair, appointment, or other business record.
- Automatically from your browser, device, session, and use of the application.
- From service providers used for authentication, hosting, billing, email, analytics, marketing, notifications, and AI features.
4. How We Use Data
- To provide, maintain, secure, and support PettyLogs.
- To create accounts, manage organisation access, and record policy acceptance.
- To process subscriptions and billing through Stripe.
- To send transactional emails and push notifications about receipts, purchases, repairs, and repair status changes. Notification preferences can be changed in Notification Settings.
- To troubleshoot, prevent abuse, improve reliability, and comply with legal obligations.
- To provide AI-assisted catalogue features when requested. Relevant inputs may be sent to OpenAI for that purpose.
- To measure product usage and support marketing where the required consent has been provided.
5. My Purchases and Customer Portal
My Purchases lets an individual view cash sales, repair jobs, and certain receipts linked to their verified email address across participating PettyLogs organisations.
- How it works: When an organisation enters a customer email, the record can appear after the person creates and verifies a PettyLogs account using that email.
- What may be shown: Organisation and branch names, receipt references, amounts, payment status, repair status, device details, parts, warranty information, and related records.
- Email matching: Email verification helps restrict access, but it does not guarantee that an organisation entered the correct email or that an inbox is controlled by only one person.
- Notifications: Notification preferences default to on for registered users and can be individually disabled. An organisation may also trigger transactional emails when it enters a customer email.
- Incorrect records: If records are not yours, contact support@pettylogs.com. We will verify the request and investigate whether the email link can be removed.
6. Service Providers and Sharing
We do not sell personal data. We may share data with providers or other parties where needed to operate the service:
- Supabase: Database, authentication, hosting, and file storage.
- Stripe: Subscription billing and payment processing.
- Resend and email providers: Transactional email delivery.
- Google Analytics and Meta Pixel: Analytics and marketing measurement after the required consent.
- OpenAI: AI-assisted catalogue processing when you use those features.
- Push services: Browser or operating-system push delivery providers when push notifications are enabled.
- With an organisation connected to a transaction or repair record, where needed to provide the customer portal.
- With authorities, advisers, or other parties where required to comply with law, protect rights, or prevent fraud or abuse.
Some providers may process data outside your country or region. We use the safeguards required by applicable data-protection law and the provider agreements in effect at the time.
7. Cookies and Similar Technologies
Essential authentication, session, and consent information is stored in browser storage or other essential technologies. With consent, we load Google Analytics and Meta Pixel for analytics and marketing measurement. These providers may use cookies or similar technologies and may collect device and usage information.
You can decline non-essential analytics and marketing through the cookie banner. Essential authentication and service storage remains active.
8. Security, Storage and Retention
- We use reasonable technical and organisational measures to protect data against unauthorised access, loss, misuse, or disclosure.
- Data is stored using cloud infrastructure and service providers described in this policy. The precise hosting region depends on the provider configuration in use.
- We retain data while it is needed to provide the service, support an organisation's records, meet legal or accounting obligations, resolve disputes, maintain security, or enforce agreements.
- Backups, logs, billing records, and other limited copies may remain for a period after deletion where necessary for security, recovery, or legal obligations.
- No online service can guarantee that deleted or unavailable data will always be recoverable.
9. Your Rights and Requests
Depending on your location and the applicable law, you may have the right to:
- Access and correct personal data we hold about you.
- Request deletion, restriction, or portability of your personal data.
- Object to processing or withdraw consent where processing relies on consent.
- Disable notification emails and push notifications in Notification Settings.
- Request investigation or removal of an incorrect My Purchases email link.
- Complain to the data-protection authority in your country or region.
Contact support@pettylogs.com for a request. We may need to verify your identity. Requests concerning records created by an organisation may also need to be directed to that organisation as the controller of those records.
10. Account Closure and Deletion
To request closure or deletion of your PettyLogs account, contact us. We will review the request and apply the deletion, retention, and legal-exception rules that apply to the relevant data. Organisation transaction records may remain under the organisation's control or legal obligations even when an individual user account is closed.
11. Children and Automated Decisions
PettyLogs is a business service and is not directed to children. PettyLogs does not make decisions about people based solely on automated processing that produce legal or similarly significant effects.
12. Changes to This Policy
We may update this Privacy Policy periodically. When a new version is released, you will be asked to review and explicitly accept the updated policy before continuing to use the application. The effective date and version will be updated when changes are published.