MalanVentures · LabStock Lite

Mobile stocktake: privacy and data handling

Updated 16 September 2026. This notice explains the current mobile stocktake connection. MalanVentures operates this companion. Your organisation manages its stock records and approves stock changes.

What travels through the service

To connect one phone to the correct stocktake, we use temporary session identifiers, pairing credentials and a device identifier. When you send your review list, the barcode, description you entered, quantity, submission identifier and time pass through the hosted relay to your desktop. The phone does not upload camera photos or video: barcode decoding happens in your browser.

The desktop inventory register, prices, suppliers, documents and backups are not uploaded by this stocktake flow. Do not enter patient information, personal details, passwords, payment-card information or confidential notes into item descriptions. A description should identify the stock item only.

Where information is held

OpenAI hosts this companion through ChatGPT Sites and its hosting providers. Hosted information is processed to operate the service under the applicable OpenAI data-processing terms. Hosting systems may also process connection and security information, such as IP addresses and request logs. We do not promise that information is held only in Australia.

Phone storage and camera permission

Your browser stores a device identifier and this session’s review list locally. These support pairing and recovery if the page reloads. We do not add advertising or analytics trackers to this companion. Camera access is requested when you choose a scanning feature; typing a barcode is an alternative.

Saved review lists remain in this browser until its site data is cleared. First confirm that the desktop has collected the counts, or download a recovery copy. Clearing browser data can permanently remove unsent work. Downloaded files are your responsibility to store and delete securely. You can revoke camera permission in your browser settings.

Retention and access

The relay stops accepting counts when the session ends or expires. Submitted counts are available for desktop collection until 24 hours after the session expiry time. Application cleanup removes expired session data when subsequent service requests trigger cleanup; this is not a guarantee of deletion at an exact time. Provider logs and backups can have separate retention rules.

Anyone with the unused pairing link may attempt to join first. Keep the QR code and link private. Only the paired phone can submit after pairing; the desktop uses a separate secret to retrieve counts. End the session if its link is exposed. A public landing page does not intentionally publish the session’s counts.

Getting help or requesting a correction

For stock corrections, contact your organisation’s stock controller. For privacy questions, access or deletion requests, contact MalanVentures through the seller contact provided with your purchase, or ask your stock controller to contact the supplier. Do not send pairing links or credentials with a support request.

A sent confirmation means the relay received the count; verify collection in desktop Pending counts. Keep LabStock Lite open during the session. If transmission fails, preserve the review list and use its recovery download.

Hosting terms · Hosting data-processing terms