Privacy Policy
Gantry is barcode stocktaking software for hospitality venues. This policy explains what we hold, why we hold it, who else touches it, and how to get rid of it.
Two things are worth saying at the top, because they are the questions operators actually ask:
- We never see your card details. Payments run entirely through Stripe. Card numbers do not pass through Gantry and are not stored in our database.
- Your stock counts belong to your organisation, not to us. We do not sell them, and we do not use one venue's counts to do anything for another.
1. Who we are
Gantry is operated from Australia. For questions about this policy, or to make a request about your data, email support@gantrystocktake.com.
2. What we collect
Only what the product needs to work. There is no analytics package, no advertising pixel and no third-party tracking script on this website or in the app.
| What | Why we have it |
|---|---|
| Email address and password | To create and secure your login. Passwords are stored hashed by our authentication provider; we cannot read them. |
| Your name | So stocktake records and the activity log can say who did what. This is the main reason it is collected, and it is why the field is labelled "shown on stocktake records". |
| Organisation name, venues, locations | To group counts and control who can see them. |
| Billing country | To decide which currency you are charged in. |
| Stocktake contents — barcodes, quantities, timestamps, and who scanned each line | This is the product. Attribution exists so a disagreement about a count has an answer. |
| Activity log | A record of significant actions (deleting a stocktake, changing a role, exporting) with the person's name at the time. Kept so an owner can see what happened to their data. |
| Session and device records | To enforce one login per device and, on Multi-venue, how many people can count at the same time. |
| Marketing preference, and the date you set it | So we can prove what you agreed to, and honour it when you change your mind. See section 5. |
Your camera
Scanning uses your device's camera. Images are decoded on your device and are never uploaded. What leaves your device is the decoded barcode number, nothing else. No photo or video is stored by Gantry at any point.
3. Who else processes it
Gantry is a small operation and relies on two established providers. Both are processors acting on our instructions:
Supabase — authentication, database and hosting for your account
and stocktake data. Gantry's database is hosted in Singapore
(ap-southeast-1), so your data is stored outside Australia.
Stripe — subscriptions, payments and invoices. When you check out, Stripe collects your payment details and billing address directly. Stripe holds those; we see only the subscription status and a customer reference.
The website and app are served by GitHub Pages. Sending marketing or notification email uses an email delivery provider.
We do not sell personal information, and we do not share it with anyone else except where we are legally required to.
4. Who can see your stocktake data
Access is enforced in the database itself, not only in the app:
- People in your organisation see your organisation's data, according to their role (owner, manager or staff).
- People outside your organisation cannot see it at all.
- We can access it as the operators of the service, and do so only to fix a fault or where we must for legal reasons.
5. Marketing email
When you sign up there is a tick box offering tips and updates about Gantry. It starts ticked, and you can untick it before creating your account. Whichever way you leave it is what we record, along with the date.
You can change your mind at any time in the app under Account → Email, or by asking us. Turning it off does not affect email about your own account or subscription — confirming your address, resetting a password, or a receipt — which we send because you have an account with us, not because you opted in.
6. How long we keep it
Your account and its stocktake data are kept while your account exists.
Deleting your account deletes the data with it. The app has a Delete account action which cancels any subscription immediately and removes your profile, your organisation's stocktakes and their contents. This is not a soft delete or a flag — the records are removed. It cannot be undone, so export anything you need first.
Two things deliberately survive: entries in the activity log keep the name recorded at the time (without a link to the deleted account), so an organisation's history does not become unreadable when someone leaves; and Stripe keeps invoice records for as long as tax law requires.
7. Your rights
You can ask us to give you a copy of your personal information, correct it, or delete it. Deleting is usually fastest to do yourself in the app; email us for anything else and we will respond within a reasonable time.
If you are unhappy with how we have handled a privacy matter, contact us first. In Australia you can then complain to the Office of the Australian Information Commissioner.
8. Security
Connections are encrypted in transit. Access to your organisation's data is restricted at the database level by row-level security, so a bug in the app cannot expose another organisation's counts. Passwords are hashed and never visible to us. No system is perfect; if we discover a breach affecting your data we will tell you.
9. Children
Gantry is a tool for businesses and is not intended for anyone under 16.
10. Changes
If this policy changes materially we will update the date above and, where the change affects you, tell you in the app or by email.