Privacy Policy
How we handle and protect personal data
This page explains how Avaro handles personal data across the website, backend services, and front-end applications. It is written to cover the current Django backend, supporting APIs, and connected mobile or web clients.
Last updated: 18 May 2026
1. Who this policy applies to
This policy applies to people who visit the website, join the waitlist, create an account, use the app as a service provider, are added to the system as a client, receive invoices or emails from the platform, or otherwise interact with Avaro.
2. What data we may collect
Depending on how you use the platform, we may process identity and contact data such as your name, email address, phone number, business profile details, postal address, and account role.
We may also process operational data created through use of the product, including client records, appointments, jobs, invoices, notes, uploaded files, billing addresses, subscription records, push notification device registrations, and payment-related reference data.
We also receive technical and security-related data needed to run the service, such as authentication tokens, request metadata, app subscription validation responses, and server-side logs for error handling and abuse prevention.
3. How data is used
We use personal data to provide the service, authenticate users, store client and business records, schedule appointments, manage jobs, create and send invoices, support payments and subscriptions, send product or account emails, and keep the platform secure and reliable.
Where someone joins the waitlist or marketing list, we also use their submitted contact details to send updates unless they unsubscribe.
4. Front-end and back-end data flows
The front-end apps and website collect information you enter and send it to the Django backend through authenticated or form-based requests. The backend stores business and account data in the application database and stores uploaded media files, such as profile images and client resources, in managed object storage.
Some actions also involve trusted service providers. For example, emails are sent through the configured email delivery service, files are stored in Amazon S3-compatible storage, and payment or subscription workflows may interact with Stripe, Apple, or Google depending on the feature being used.
5. How data is protected in transit
In production, the backend is configured to redirect traffic to HTTPS, send secure cookies only over HTTPS, and apply HTTP Strict Transport Security (HSTS). This helps protect traffic between users and the service against interception or downgrade attacks.
API access is protected through authenticated requests, using either session-based authentication or token-based authentication depending on the client. CSRF protections are enabled for browser-based interactions where they apply.
6. How data is protected at rest
Data is stored in the application database and in managed file storage for uploaded media. Access to stored data is controlled through application permissions, account authentication, and infrastructure credentials. Media files are not served from the app server itself; they are stored separately in managed object storage and accessed through generated URLs.
Passwords are not stored in plain text. They are stored using Django’s password hashing system. The application also applies access restrictions so authenticated users only see the data they are permitted to access through the service.
No security system can guarantee absolute protection, but we use layered technical and organisational measures intended to reduce the risk of unauthorised access, loss, misuse, or disclosure.
7. Access control and security measures
The platform uses account authentication, password validation, secure cookies in production, email verification for provider accounts, permission checks on protected API endpoints, and request handling controls designed to reduce duplicate or unsafe write operations.
We also maintain server-side error logging and operational monitoring so security or reliability issues can be identified and investigated.
8. Sharing data with third parties
We do not sell personal data. We may share data with service providers that help us operate the platform, such as hosting providers, managed storage providers, email delivery providers, payment infrastructure providers, app store subscription platforms, and notification services.
We may also disclose data where required by law, to respond to valid legal requests, or where necessary to protect the rights, safety, or security of users, customers, or the service.
9. Retention and deletion
We keep personal data only for as long as it is needed for the purposes described in this policy, including running the service, maintaining records, meeting legal or accounting obligations, resolving disputes, and enforcing agreements.
The current backend includes deletion endpoints for core records and also includes an anonymisation process for inactive client records. Where a client record is marked inactive and reaches its anonymisation date, identifying fields can be cleared or replaced and related address records removed.
Some records may need to be retained for legitimate business reasons, fraud prevention, financial reporting, tax compliance, legal obligations, or to demonstrate that a deletion request was actioned.
10. GDPR and UK data protection rights
If UK GDPR or EU GDPR applies to your data, you may have rights including the right to request access to the personal data we hold about you, request correction of inaccurate data, request erasure of your data, request restriction of processing, object to certain processing, and request a copy of your data in a portable format where applicable.
You may also request account deletion or ask us to delete data associated with your use of the service, subject to any legal or operational basis for limited retention.
To make a privacy or GDPR request, contact hello@useavaro.com. Please include enough information for us to verify your identity and locate the relevant account or records. We may need to ask for additional information before completing a request.
11. Account deletion and data deletion requests
If you want your account deleted, or want associated personal data erased where possible, contact hello@useavaro.com. We will review the request, verify identity, explain any data that must be retained, and then delete or anonymise the data we can lawfully remove.
If you are a provider using the platform, you should also consider whether data you entered about your own clients must be retained for tax, accounting, contractual, safeguarding, or other legal reasons before instructing deletion.
12. Marketing and unsubscribe choices
If you joined the waitlist or marketing list, you can unsubscribe from marketing emails using the unsubscribe link in those emails or by contacting us. Operational emails that are necessary for account, billing, or security purposes may still be sent where appropriate.
13. Children’s data
If personal data relating to minors is processed through the service, that data should only be added where there is a valid lawful basis and the relevant user is authorised to provide it. If you believe data has been collected inappropriately, contact us so we can review and address it.
14. International transfers
Depending on the infrastructure and third-party services in use, data may be processed outside your country. Where this happens, we aim to use providers and contractual protections that support lawful international transfers.
15. Changes to this policy
We may update this policy from time to time to reflect product changes, legal developments, or security improvements. When we make material changes, we will update the date shown on this page and may take additional steps to highlight the change where appropriate.
16. Contact us
For privacy, data protection, security, access, correction, deletion, or GDPR-related requests, contact hello@useavaro.com.