Privacy Policy

Last updated: 1 August 2026

This page is maintained by PestGuard International (Pvt) Ltd. to explain how we handle personal and company data in the PestGuard platform. It describes our current practices and is not an independent audit or certification.

1. Data we collect

  • Account data: name, email address, password (stored only as a salted hash by our authentication provider), company name, and role (owner, admin, or user).
  • Facility and operational data: facility names, uploaded floor-plan images, bait station and insect light trap coordinates and labels, QR identifiers, inspection results, pest types, inspector names, timestamps, and notes.
  • Billing data: selected plan, billing cycle, amount in LKR, payment reference, and uploaded bank payment slips. Card details are entered on PayHere's own secure checkout — we never see or store card numbers.
  • Technical data: limited log data such as request timestamps and error reports used to keep the service reliable and secure.

2. How we use it

  • To create and operate your company workspace and user accounts;
  • To store and display your floor maps, devices, and inspection history;
  • To generate compliance reports and exports you request;
  • To process subscriptions, verify bank payment slips, and issue invoices;
  • To send transactional email such as verification, invitations, and password resets;
  • To secure the platform, investigate abuse, and meet legal obligations.

We do not use your operational data for advertising or profiling.

3. Storage and security

Application data is stored in a managed Supabase (PostgreSQL) backend with authentication, row-level security, and file storage. Data is encrypted in transit over HTTPS/TLS and encrypted at rest by the hosting provider. Access controls we have enabled include:

  • Email-verified accounts and password reset by email;
  • Row-level security policies that scope every facility, device, and inspection record to the owning company, so users of one company cannot read another company's data;
  • Role-based permissions where only owners and admins can add or remove users, facilities, and devices;
  • Administrative separation: platform administration is limited to company, user, and subscription records. Floor maps, bait station details, and inspection data are not accessible to the platform super administrator.

4. Sharing and subprocessors

We do not sell, rent, or trade your personal data to third parties. We share data only with service providers that operate the platform on our behalf:

  • Supabase — database, authentication, and file storage;
  • Cloud hosting / CDN — serving the web application;
  • PayHere — payment processing for online card payments;
  • Email delivery provider — transactional email such as verification and invites.

We may also disclose data where required by law or to protect our legal rights.

5. Retention and deletion

We keep company data for as long as the workspace is active, since inspection history is typically required as an audit record. Admins can delete facilities and devices at any time. When a company is deleted, its facilities, devices, inspections, invites, and role assignments are removed. Payment records may be retained where accounting or legal obligations require it.

6. Your rights

You may request access to, correction of, export of, or deletion of your personal data by emailing us. Where your data belongs to a company workspace, we may need to coordinate with that company's owner before acting. Requests are acknowledged within 5 business days.

7. Cookies

We use only essential cookies and local browser storage needed to keep you signed in and remember interface preferences. We do not run third-party advertising trackers.

8. Security contact

Report a suspected vulnerability or data incident to wageeshauwpe@gmail.com. Please include enough detail to reproduce the issue and allow us reasonable time to respond before public disclosure.

9. Contact

PestGuard International (Pvt) Ltd. — wageeshauwpe@gmail.com