Pre-launch document

Privacy Notice

Version privacy-2026-07-21-prelaunch

This pre-launch notice explains the main categories of personal data PPWR Log handles while the service is tested. Verified retention periods and final controller details must be added before commercial launch.

Data PPWR Log handles

  • Account and profile details, including email address and optional name.
  • Organisation, membership, billing-plan, and connected-store details.
  • Commerce and packaging records imported or entered into a workspace.
  • Actions, confirmations, exports, and security or diagnostic events.
  • Provider references needed to process billing and connector privacy requests.

Why it is used

Data is used to authenticate users, operate workspaces and connectors, generate the records and exports users request, enforce plan and security boundaries, respond to support or privacy requests, and protect the service from misuse.

Service providers

PPWR Log uses service providers for hosting, authentication, storage, payments, and commerce connections. Current infrastructure includes Supabase, with Stripe, Shopify, and WooCommerce involved when a workspace uses the corresponding feature.

Published digital packaging records

A PPWR Log-hosted digital packaging record is public. It contains the packaging name, responsible-operator identity and contact details, publication facts, and any translations an authorised workspace user publishes. Do not publish personal contact details unless they are intended to appear publicly for this purpose.

When paid access ends or a workspace closes, the minimal already-public payload and its hosting dates are retained separately for five years so the printed address can remain read-only. The payload is removed after that period. Internal source snapshots, evidence, actors, and other workspace history are not copied into this continuity record.

Retention and deletion

Workspace closure, personal-login deletion, store-data removal, and provider customer deletion are separate workflows. PPWR Log will publish verified primary-system, storage, log, disaster-recovery, and rolling-backup periods before launch. The product will not claim a backup deletion date until those rotations have been tested.

Your choices

Account holders can review and correct profile or workspace details through the product. Additional access, correction, export, objection, restriction, or deletion requests will be handled according to the final privacy notice and applicable circumstances. Provider end-customer requests are handled separately from closing a PPWR Log workspace.