OvaraTradeOvaraTrade

Privacy Policy

Last updated 17 September 2026

This policy explains what personal information OvaraTrade (“OvaraTrade”, “we”, “us”) collects through the OvaraTrade platform (the web app, and the iOS/Android apps that wrap it), why, who we share it with, and the choices you have. It applies to trade businesses who sign up for OvaraTrade (“you”, a “business”), the staff they invite, and the customers those businesses serve, whose information a business may enter into or receive through OvaraTrade on their behalf.

[Legal entity name and ABN], of [registered address], operates OvaraTrade. Questions about this policy can be sent to [privacy contact email].

1. Information we collect

Account & business information — your name, email, password (stored as a salted hash, never in plain text), business name, ABN, trade type, address, phone, logo, and the team members you invite.

Customer information you manage in OvaraTrade — names, phone numbers, emails, addresses, and job/quote/invoice history for the customers your business serves. You control this data as the business; OvaraTrade processes it on your behalf to provide the service (a data processor relationship, not one where OvaraTrade decides how your customers’ data is used).

Content you upload — job photos, voice notes, customer signatures, and business assets (logo, brand imagery), stored in tenant-isolated cloud storage.

Payment information — subscription payments (your business paying OvaraTrade) and invoice payments (your customers paying you) are both processed by Stripe. OvaraTrade never receives or stores full card numbers — Stripe handles that directly and shares back only what’s needed to display a receipt or manage a subscription.

Communications — SMS and voice call content sent or received through the AI Receptionist and job-reminder features (via Twilio), and emails sent through the platform (via Resend).

Usage & device data — standard web/app request logs, error reports (via Sentry — see Section 4), session cookies, and, if you enable them, push notification tokens (a browser Web Push subscription or, in the iOS/Android app, a device token) used only to deliver the notifications you’ve opted into.

2. How we use it

  • To provide the core service — quoting, invoicing, scheduling, customer records, and the features built on top of them.
  • To power AI features (quote drafting, the AI Receptionist, marketing content generation) — see Section 3 for which providers process this content.
  • To process payments and manage subscriptions.
  • To send transactional communications you’ve configured — job reminders, review requests, invoice notices — never unsolicited marketing to your customers without your own opt-in mechanism.
  • To detect and fix errors (Sentry), and to prevent abuse (rate limiting on login and signup, keyed by IP address).
  • To comply with legal obligations, such as retaining financial records.

3. Who we share it with

We don’t sell personal information. We share it only with the sub-processors that make the service work, and only the data each one needs:

  • Stripe — payment processing (subscriptions and customer invoice payments).
  • Twilio — SMS and voice calls (each business gets its own dedicated number and regulatory registration, never shared across businesses).
  • Resend — transactional email delivery.
  • Anthropic (Claude) and OpenAI — AI features send the relevant business/quote/conversation content to these providers to generate a response; neither is used to train their models on your data under our commercial terms with them.
  • Google (Maps, Calendar, Ads), Meta (Ads/Instagram/Facebook), Xero, ServiceM8, Jobber — only if you connect these integrations yourself; each receives only the data that integration needs (e.g. an address for route optimisation, a contact for accounting sync).
  • Cloudflare R2 / AWS S3-compatible storage — file storage for uploaded photos, voice notes, and documents.
  • Sentry — error and performance monitoring. No screen recording (session replay) is ever enabled, and no personal data is deliberately included in error reports.
  • Vercel — application hosting.

Several of these providers are based in, or process data in, the United States. By using OvaraTrade you acknowledge your information may be processed outside Australia as a result.

4. Security

Passwords are hashed, never stored in plain text. Third-party integration credentials (e.g. Twilio, Xero, Google tokens) are encrypted at rest. Every business’s data is isolated from every other business’s at the database level. Sessions use httpOnly, signed cookies. No system is perfectly secure, and we can’t guarantee absolute security, but we design for it deliberately rather than as an afterthought.

5. Data retention & deletion

We keep your data for as long as your account is active, plus a reasonable period after for legal, accounting, and dispute-resolution purposes. You can permanently delete your business account and all its data at any time from Settings — see Settings > Delete Account. This is irreversible: it removes your business, its customers, jobs, quotes, invoices, and every other record tied to it.

6. Your rights

Under the Australian Privacy Principles (and equivalent rights if you’re elsewhere), you can ask us for access to, correction of, or deletion of your personal information. Account owners can do most of this themselves directly in the product; for anything else, contact us at [privacy contact email].

7. Children

OvaraTrade is a business tool and isn’t directed at, or knowingly used by, children.

8. Changes to this policy

We’ll update the date at the top of this page when this policy changes, and, for material changes, make a reasonable effort to notify account owners directly.

9. Contact

Questions about this policy: [privacy contact email].

Terms of Service