Privacy policy

Effective 2026-09-02

About this policy

ApprovalScribe is a service provided by Patrick Dela Plana (ABN 58 737 963 643), Queensland, Australia.

This policy explains what personal information we handle and why. It is written to the Privacy Act 1988 and the Australian Privacy Principles. A separate section covers the General Data Protection Regulation, for people it applies to.

"We", "us" and "our" mean the supplier named above. "You" means the person who holds an account. "Reviewer" means a person an account holder invites to review a document — reviewers never create an account and never sign in.

The two are treated differently throughout. For your own account information we decide what is collected and why. For information about a reviewer, the account holder who invited them chose them, holds the relationship with them and decided the purpose; we handle that information to run the workflow they asked for.

The effective date of this version is shown at the top of this page.

What we collect

Account details. Your full name, your company name and your email address, given when you sign up. Your name is shown to the reviewers you invite, as the sender of the request. Your password is passed straight to our hosting provider’s authentication service, which holds it. We do not store it.

Profile details, all optional. A job title, a phone number, a standing note added to the requests you send, and a profile picture. The phone number is for the account and is never shown to reviewers.

Workspace settings. The time zone and the date and time formats every date is displayed in, including on the pages your reviewers see.

The documents you upload, and what you enter about a request — its name, your message to reviewers, and how the review is routed.

Reviewer details you supply. A reviewer’s email address, and optionally their name and their language. You choose these; we do not obtain them from anywhere else.

Activity records. When a request was sent, when a reviewer opened their link, and each decision and comment, against the reviewer’s email address.

Payment records. We use Stripe to take payment, on a page Stripe hosts. We never receive or hold your card details. What we keep is Stripe’s identifiers for the payment, the amount, the currency and what was bought.

Waitlist details. Before the service opens, this website offers a waitlist. If you use it we keep the name and the email address you enter and the date you entered them. Nothing else is collected from that form, and it does not create an account.

Diagnostics. When something fails we send an error report to Sentry so we can fix it. Review tokens, email addresses and file names are removed from those reports before they leave the application, and we have turned off the collection of IP addresses, cookies and request bodies.

How we use it

To run the service: to store your documents, to give each reviewer their own view of the request, to send the emails the workflow needs, and to record each decision and comment.

To manage your account: to verify your email address, to sign you in, and to let you reset your password.

To meter and bill: to count the documents you send against your allowance and your credits, and to record a purchase.

To keep the service working and secure: to diagnose faults.

Email is sent through Postmark, our email provider. It goes only to your own address and to the reviewer addresses you supply.

To run the waitlist: to keep a record of who registered interest before the service opened. We use waitlist details for nothing else.

We do not sell personal information. We do not use it for advertising, and we do not build profiles from it.

Recording when a reviewer opens their link

We record the moment a reviewer first opens their review link, and we show that time to the account holder who sent the request. This section explains how that is done and on what basis, because it concerns people who never signed up to anything.

It is recorded on our server, when the reviewer’s link is loaded. There is no tracking pixel, and there will not be one. That is a deliberate design choice rather than an implementation detail: nothing is read from or written to the reviewer’s device to record an open, so the recording sits outside the stricter rules that govern access to information stored on a person’s own device — rules which would require genuine consent.

What is recorded is a time, against the email address the account holder supplied. No IP address, no device or browser details and no location are recorded with it.

Under the General Data Protection Regulation the basis for this is our legitimate interests, under Article 6(1)(f). It is not consent, and we do not claim consent. Consent has to be given by a clear affirmative action, and opening the link fails that test twice over: opening it is the action needed to do the review, not a separate act of agreement, and a reviewer who refused could not review the document at all, so there is no genuine choice. Naming a basis that would not hold up is worse than not naming one.

The legitimate interests are these. Someone who sends a document for approval has an evident interest in knowing whether it was seen. The processing is minimal — one timestamp against an address they already had. And it is within what a person would reasonably expect of a document review they were asked to take part in.

Reviewers are told. The review page says that the sender will be able to see when the link was opened, names them, and states that no IP address, device or location is recorded. It also says how to object: reply to the invitation email from the person who sent the request, since it is their request and they decide how the information is used.

Cookies

The public site you are reading now sets no cookies of its own. It reads no data and holds no credential.

The application you sign in to sets session cookies. They exist to keep you signed in and to let the server recognise your session on the next request. They are strictly necessary — without them the application cannot work.

There are no analytics cookies, no advertising cookies and no third-party tracking of any kind. We do not run an analytics package in either application.

There is therefore no cookie banner. Nothing here would be improved by asking you to agree to tracking that does not happen.

Who else handles it

We use five providers to run the service. Each receives only what it needs for its part.

Supabase — our database, authentication and file storage. It holds your account details, your requests and their history, and the documents you upload.

Vercel — our hosting. Every request to the applications passes through it, and it stores waitlist signups.

Stripe — payments. You give your card details to Stripe directly, on a page it hosts. It returns to us the identifiers, amount, currency and description of what you bought.

Postmark — email delivery. It receives the recipient address and the contents of the message, which for a review invitation includes the request name, your name and the reviewer’s link.

Sentry — error diagnostics. It receives the redacted error reports described above.

We disclose personal information to no one else, except where the law requires it of us.

Where your data is stored

Your account records and the documents you upload are stored in Sydney, Australia (AWS ap-southeast-2).

Some of the providers listed above operate outside Australia, so using ApprovalScribe involves disclosing personal information to overseas recipients. Australian Privacy Principle 8 governs that disclosure. We keep the list of providers short for that reason, and we choose providers that publish their own privacy and security commitments.

Waitlist entries are held in our hosting provider’s file storage rather than in the database that holds account records, and outside Australia. The region named above does not describe them; the overseas disclosure below does.

If you want to know where a particular provider holds what it holds, email us and we will tell you.

How long we keep it

We keep your account, your requests, their history and the documents you uploaded for as long as your account exists.

You can remove a document from a request while the request is still a draft. That deletes the file. Once a request has been sent, its documents stay until the account is removed.

To have everything removed, email us from the address on the account. We remove the workspace, its approval requests and its stored documents. Open review links stop working immediately. Deleting the account yourself from within the application is not available yet.

Waitlist entries are kept until the service opens and removed once it has. If you want yours removed sooner, email us.

Export first if you need a record. From your account settings you can ask for an archive of your data; when it is ready you get a download link that stops working after a short time.

We do not currently offer automatic deletion when a workflow finishes, and there is no configurable retention window. Some pages on this site describe those controls. They are not built, and this policy describes what the service actually does today.

Access, correction and deletion

You can see and change most of your own information in the application: your name, your company, your profile details and your workspace settings are all editable there, and your requests are listed with their history.

For anything you cannot reach yourself — access to what we hold, a correction, or deletion — email us. We do not charge for this.

If you are a reviewer rather than an account holder, contact the person who sent you the request first. They chose to send it, they hold the relationship with you, and the information about you is there because they gave it to us. You can also write to us and we will help.

Security

Documents live in a private storage area. No file can be fetched by its storage path alone: a request for one is checked first, and only then is a link issued that works for a minute and no longer. Our storage provider encrypts what it holds at rest.

Each reviewer gets their own link, carrying a 256-bit random token. It cannot be guessed, and holding one reviewer’s link gives no access to another reviewer’s view of the same request. Links stop working at their expiry date. Once a reviewer has recorded a decision, their link can no longer be used to approve, reject or comment.

The reviewer-facing application is deployed separately and holds no database credential, no payment credential and no email credential. It reaches data only through a small set of database functions that each check the token, its expiry and whether a decision has already been recorded. It cannot read anything else.

Within the application, every query is scoped to the workspace of the person making it, enforced by the database rather than by the page.

Links we email you to confirm your address or reset your password are single-use and short-lived.

No service is completely secure. If we become aware of a breach that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, as the Privacy Act 1988 requires.

If the GDPR applies to you

This section applies if you are in the European Economic Area or the United Kingdom, whether you hold an account or were invited as a reviewer.

For account information we are the controller. For information about a reviewer, the account holder who invited them is the controller and we act on their behalf as a processor: they chose the reviewer and decided the purpose.

Our lawful bases are performance of the contract we have with you, for everything needed to run your account and your requests; and legitimate interests, for recording when a reviewer opened their link, for keeping the service secure and for diagnosing faults. The open-tracking basis is set out in full in its own section above.

You have the right to ask for a copy of the personal information we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable form. Email us to exercise any of them.

Your information is stored in the region named above and handled by the providers named above, which means it is transferred outside the European Economic Area and the United Kingdom.

We make no automated decisions about you that produce legal effects or similarly significant effects.

You have the right to complain to a supervisory authority — in the country where you live, where you work, or where you think the problem arose.

Complaints

If you think we have mishandled your personal information, email us and tell us what happened. We will look into it and write back with what we found and what we are doing about it.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner, the regulator for the Privacy Act 1988. Its complaint process is at oaic.gov.au.

If the GDPR applies to you, you can instead complain to your supervisory authority, as described in the section above.

Changes to this policy

We may change this policy. Each version carries an effective date, shown at the top of this page, and the version published here is always the current one.

If we change it in a way that materially affects how we handle your information, we will say so on this page.

Contact

Email patrick@approvalscribe.com.

That address reaches us about this policy, about the information we hold, to ask for a correction, to ask for an account and its documents to be removed, and to make a complaint. Write from the address on the account when the question is about the account itself.