Legal
Privacy Policy
What we collect, where it lives, and what we will never do with it. Last updated 28 August 2026.
Who we are
Opalry (opalry.com) is inventory and ROI software for opal cutters, gem dealers, and small lapidary businesses. It is operated from Australia by OPALRY(“Opalry”, “we”, “us”). Contact us at hello@opalry.com.
This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you are in the UK or EEA, the sections on your rights and international transfers also describe how we meet equivalent obligations.
What we collect
We collect only what the product needs to work:
- Account details — your email address, password (stored only as a bcrypt hash, never in readable form), display name, business name, and business role.
- Your inventory content — the parcels, stones, buckets, purchase records, sales, stock checks, and photos you create. This is your commercial data. We treat it as confidential.
- Workspace data — organisations you belong to, your role in them, and invitations you send or accept.
- Billing data — your subscription status, plan, and Stripe customer and subscription identifiers. We never see or store your card number. Card details go directly to Stripe.
- Product usage events — milestones such as when you first added a stone, printed a label, or completed a scan. We use these to understand where the product is confusing, not to build a profile of you.
- Security records — login attempts, password reset and verification tokens, and an audit log of significant account actions. These exist to detect brute-force attempts and to investigate incidents.
We do not collect location data, contacts, advertising identifiers, or biometric data. Camera access, when you grant it, is used to read QR codes in your browser. Scanned frames are not uploaded or retained.
How your data is protected
We want to be precise here, because vague security claims are worse than none.
- In transit: all traffic is encrypted over TLS (HTTPS). We do not serve the application over plain HTTP.
- At rest: your database records and uploaded photos are stored on infrastructure that applies AES-256 encryption at rest, managed by our hosting providers.
- Passwords: hashed with bcrypt at cost factor 12. We cannot recover your password, only reset it.
- Access control: your inventory is scoped to your organisation. Members only see what their role permits, and permissions are re-checked on the server for every request.
- Uploads: photos are validated by file signature, re-encoded before storage, and SVG uploads are rejected outright to prevent embedded scripts.
What we do not claim:Opalry is not end-to-end encrypted, and your inventory is not encrypted with a key only you hold. Your data is stored in a form our systems can read, because the product has to compute ROI, render your photos, and generate your labels. Anyone claiming a SaaS product of this kind is “zero-knowledge” while still doing those things is overstating it.
Who can see your inventory
We do not look at your inventory. This is a policy commitment backed by technical limits, and it is worth being clear about where each ends.
The technical limits:
- There is no administrative feature anywhere in Opalry that displays another customer’s parcels, stones, photos, sale prices, or ROI.
- Our internal admin view shows aggregate figures only — how many parcels an organisation has, how many members, when they joined. Never the contents.
- Our “View As” support tool can only enter two dedicated, permanently empty demo accounts. It is technically incapable of entering a real customer account, and refuses to try.
The honest limit:
- As the operator of the database, we hold credentials that could technically read stored records — as does any provider that hosts your data without end-to-end encryption. We access customer data only when you explicitly ask us to for support, where it is strictly necessary to investigate a fault or security incident, or where we are legally compelled. We do not browse it, mine it, or review it otherwise.
We never sell your data, never share it with advertisers, and never use your inventory, photos, or sales figures to train machine learning models.
Where your data lives
Your database is hosted in Sydney, Australia (ap-southeast-2). Your data stays in Australia in normal operation. Some of the service providers below process limited data (such as your email address or billing identifiers) outside Australia; where that happens we rely on their contractual data protection commitments.
Service providers
We share the minimum necessary with a small number of processors:
- Neon — database hosting (Sydney). Stores your account and inventory records.
- Vercel — application hosting and photo storage.
- Stripe — subscription billing. Receives your email and billing details directly; we never handle card numbers.
- Resend — transactional email such as sign-in links, verification, and digests. Receives your email address and the message content.
Each is bound by its own data processing terms. We add no advertising or analytics trackers.
How long we keep it
We keep your data for as long as your account is active. Note one important design decision: Opalry archives records rather than hard-deleting them, and reference numbers and QR tokens are permanent once issued. This is deliberate — a printed QR label on a physical stone has to keep resolving for years, and deleting a parcel mid-history would silently corrupt the ROI of every stone cut from it.
This means archiving an item inside the app hides it from your working views but retains the underlying record. If you want your personal data actually erased, request account deletion below; that is handled separately and does remove your data.
Your rights
You can ask us to:
- give you a copy of the personal information we hold about you;
- correct anything inaccurate;
- delete your account and personal data;
- export your inventory data;
- stop sending you digest emails (you can also unsubscribe directly).
Email hello@opalry.com and we will respond within 30 days. We are building self-service export and deletion into the product; until those ship, we handle these requests by hand and they are honoured just the same.
If you are unhappy with our response, you may complain to the Office of the Australian Information Commissioner.
Cookies
We use cookies only to keep you signed in and to remember interface preferences. There are no advertising or third-party tracking cookies, which is why you are not being asked to dismiss a consent banner.
Children
Opalry is a business tool and is not directed at anyone under 16. We do not knowingly collect their information.
Data breaches
If a breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Changes
If we change this policy materially, we will update the date at the top and notify active users by email. Continuing to use Opalry after a change means you accept the revised policy.
Questions: hello@opalry.com · See also our Terms of Service.