Private pilot
Privacy notice
ClientSupply is operated by Leveriano Habiyambere, ABN 99 286 419 439. This notice explains the information handled by the ClientSupply application, why it is used, and how to ask a question or make a request.
Information we handle
- Account and identity: your name, email address, password hash, email-verification state, sessions, role and workspace memberships.
- Operational records: customer and contact details, enquiries, missed calls, jobs, quotes, actions, assignments, progress notes, outcomes and workspace settings entered by your team.
- Security and audit: sign-in and session events, invitation and workspace changes, access decisions, owner alerts and bounded activity history.
- Commercial records: bounded Stripe TEST customer, checkout, subscription, webhook and entitlement references. ClientSupply does not store raw card numbers, CVCs or bank credentials.
Do not enter health information, government identifiers, payment-card data or other sensitive information that ClientSupply is not designed to hold.
Why we use it
We use this information to authenticate accounts, keep each workspace separate, operate the ClientSupply workflow, assign and audit work, provide support, protect the service, process private-pilot billing tests and investigate incidents. We do not use your workspace to create unrelated marketing profiles.
Where information flows
Your browser sends requests to ClientSupply server functions. Those functions validate the session and active membership before reading or changing your workspace data. Email verification, password-reset and invitation messages are sent through the configured transactional email provider. Stripe TEST is used only for the current private-pilot commercial test path; live Stripe mode and live payment collection are disabled.
Access and protection
Passwords and session, invitation, verification and reset tokens are stored as one-way hashes. Workspace and role checks are performed server-side on each request. Staff access is additionally limited by assignment and the application keeps bounded audit evidence. These measures reduce risk; they are not a promise that an internet service is risk-free.
Service providers
The current ClientSupply service uses Netlify for hosting/functions, Supabase for the database and Resend for transactional messages. Stripe TEST is used only for private-pilot billing events; live Stripe mode and live payment collection are disabled. The database is configured in the ap-southeast-2 region. Other provider processing locations and contractual terms should be confirmed during legal review; this page does not invent them.
Retention, closure and deletion
Operational records are kept while a workspace is active and for as long as needed for support, security, dispute, billing or other legitimate record-keeping purposes. Exact legal or accounting periods are not stated here because they require owner/legal confirmation. Closing an account, closing a workspace, deleting active records and allowing backups to expire are separate steps.
Backups may retain information after an application-level deletion until their normal expiry. Audit and suppression evidence may need to be retained to protect security or prevent unwanted contact. We will explain retained categories when responding to an approved request.
Access, correction, privacy questions and complaints
Email leveriano@clientsupply.com.au. Tell us whether the request concerns access, correction, closure, deletion, a security concern or a complaint. We verify the requester and scope before disclosing or changing information. Never send a password, MFA code, session token or payment secret.
Australian privacy-law rights and complaint avenues depend on the circumstances and should be confirmed with current authoritative legal guidance. This notice is not legal advice.
Updates
We will update this page when the product, providers or information-handling practices change. The update date above identifies the current draft.