Document 02 of 10 · MaintlyQR Legal Package v1.1

Privacy Policy

How MaintlyQR collects, uses, stores, and protects your personal information.

Effective July 2, 2026 · Revised July 2, 2026

1. Who We Are

MaintlyQR™ ("MaintlyQR", "we", "us", "our") is a technology platform providing QR-based digital identity and maintenance history tracking for physical assets. MaintlyQR is operated pending formal legal incorporation; upon incorporation, the operating entity will be MaintlyQR Pty Ltd (ACN pending), headquartered in Queensland, Australia. References to "MaintlyQR" apply equally to any successor legal entity.

This Privacy Policy explains how we handle personal information collected through www.maintlyqr.com (the Platform). We comply with the Australian Privacy Act 1988, the Australian Privacy Principles (APPs), and where applicable, the EU General Data Protection Regulation (GDPR) and UK GDPR.

2. Information We Collect

Information you provide directly:

  • Name and email address (at registration)
  • Professional details (mechanic or business name, trade registration number)
  • Asset information (type, make, model, serial number, location)
  • Maintenance and service records (dates, descriptions, mileage, hours, parts used)
  • Photos of assets and service records (optional)
  • Communications you send to support@maintlyqr.com

Information collected automatically:

  • IP address and approximate geographic location
  • Browser type, device type, and operating system
  • Pages visited, features used, and session duration
  • Authentication tokens and session identifiers

3. How We Use Your Information

We use your information to:

  • Create and manage your account
  • Display maintenance history on public QR pages
  • Generate PDF service reports
  • Operate, maintain, and improve the Platform
  • Send essential service communications (security alerts, account updates, policy changes)
  • Process Verified Mechanic applications
  • Comply with legal obligations
  • In anonymised or aggregated form: improve AI features and analyse Platform usage

We do not sell your personal information to third parties. Ever.

4. Public Information

The maintenance records you add to any asset's Maintenance Ledger are publicly visible to anyone who scans the associated QR code — this is a core feature of MaintlyQR.

By adding records, you acknowledge this information is publicly accessible. Do not include sensitive personal information in service records or asset descriptions.

5. Third-Party Providers

We share your information only with:

  • Supabase — database, authentication, and storage provider (data encrypted in transit and at rest)
  • Vercel — hosting and content delivery provider
  • Legal and regulatory authorities, when required by law

We do not use third-party advertising networks, tracking pixels, or data brokers. All providers are bound by their own privacy policies and are selected for their high security standards.

6. Data Storage and Security

Your data is stored using Supabase, which provides:

  • Encryption in transit (TLS/SSL)
  • Encryption at rest (AES-256)
  • Row-level security ensuring users can only access their own data

We apply industry-standard security practices. No system is 100% secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.

7. Artificial Intelligence

MaintlyQR may use AI to analyse patterns in anonymised, aggregated maintenance data to improve Platform features. Your personally identifiable information is not used to train external AI models. If AI features are applied directly to your records, you will be informed.

8. Retention

We retain your account data for as long as your account is active. Upon account deletion, we delete your personal information within 30 days, except where retention is legally required.

Public QR maintenance records remain accessible until the asset owner removes them.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Request deletion of your data
  • Object to or restrict how we process your data
  • Export your data in a portable format (JSON, CSV, or PDF)
  • Withdraw consent at any time where processing is consent-based

To exercise any right, contact support@maintlyqr.com. We will respond within 30 days.

Australian users: rights under the Privacy Act 1988 and Australian Privacy Principles.

EU/UK users: rights under the GDPR/UK GDPR, including the right to lodge a complaint with your supervisory authority.

10. Cookies

We use essential cookies only: to maintain your login session and enable core Platform functionality. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

Full details are in the Cookie Policy (Document 3).

11. Children's Privacy

MaintlyQR is not intended for anyone under 18. We do not knowingly collect personal information from minors. If you believe a minor has registered, contact us immediately and we will delete their account.

12. International Transfers

MaintlyQR serves users globally. Your data may be stored on servers located outside your country of residence. Where we transfer personal data internationally, we ensure appropriate safeguards are in place in compliance with applicable law.

13. Changes to This Policy

We may update this Policy from time to time. We will notify registered users by email of significant changes. Continued use constitutes acceptance.

14. Contact and Complaints

For privacy questions, requests, or complaints: support@maintlyqr.com

If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, or to your national data protection authority.

Need the full document?

Download the official PDF version of the Privacy Policy.

Download PDF