Preflight SafeCurrent operating notice · 22 August 2026

How information is handled during the public-page pilot.

This notice covers the current no-cost evaluation only. The pilot uses agreed public product pages and does not accept private catalogue files, evidence documents, credentials or payment information.

01

Information used

Pilot enquiry

Business name, public store URL, product categories, approximate catalogue size and ordinary email correspondence.

Public product information

Product title, public URL, brand, model, SKU or selected variant, relevant listing text, visible warnings and the outcome of a limited image check.

Review records

Dated page checks, recall-search terms, screening indicators, reviewer amendments and short workflow notes.

Website delivery

Hosting, network and security providers may process technical request data such as IP address, browser information, time and security logs.

Public availability does not make customer reviews, customer names, avatars or unrelated personal information necessary. Those details must not be copied into the workspace or report.

02

How the private workspace processes it

Product text or CSV content entered by the operator is transmitted to an authenticated server endpoint, processed and returned to the browser. The application does not intentionally write scan requests or raw catalogues to an application database.

Action Centre cases and notes are stored in the browser's local site storage. Every business is placed in a separate client workspace. Anyone able to use that browser profile may still be able to view those records. Browser, device backup and synchronisation behaviour has not been independently verified.

The workspace is intended to be owner-only and is protected by operator authentication. This does not eliminate account, browser, device or hosting risk. Evidence files are not accepted or stored.

03

Email and limited retention

Enquiries are received at productsafetypreflight@gmail.com, a Gmail account. Google processes email content and related technical information under its own practices. Google Privacy Policy (opens in a new tab)

  • An enquiry that does not proceed will be deleted within 90 days.
  • Public-page working records and local client workspaces will be deleted within 30 days after the report and any agreed factual correction are complete.
  • The final pilot report and correspondence will be deleted within 90 days after the pilot closes, unless a dispute or legal obligation requires limited longer retention.
  • A minimal do-not-contact record may be retained so an opt-out is not ignored.

These periods depend on manual deletion by the operator. Complete immediate erasure from provider backups is not promised.

04

Information that must not be sent

Do not send customer information, incident-victim details, confidential supplier reports, test reports, passwords, API keys, Shopify credentials, payment information or unpublished commercial material. A known hazard, recall or serious incident is outside this pilot and needs the appropriate urgent process.

If unrequested personal or confidential information arrives, it should not be copied into the workspace. The operator will assess whether it is needed and, where lawful and reasonable, delete or de-identify material that is not required and record that action.

05

Access, correction, deletion and complaints

Preflight Safe is an early-stage pilot project run by Yazan Almadani. To ask what information is held, correct an error, request deletion or raise a complaint, email productsafetypreflight@gmail.com. Identity or authority may need to be confirmed before business correspondence is disclosed or changed. The operational target is to respond within 30 days.

If a report transcribes a public listing incorrectly, notify the project within five business days of delivery so the single factual correction round included in the pilot can be completed.

06

Legal boundary

Privacy Act coverage is not assumed. The OAIC says most businesses with annual turnover of $3 million or less are not covered, but exceptions apply and the operator's position has not been legally assessed. OAIC privacy checklist for small business (opens in a new tab)

This operating notice records the current no-cost, public-page workflow. It must be reviewed before private files, payments, customer accounts, evidence uploads, analytics, generative-AI processing or broader commercial services are introduced.

Change control

The notice changes when the workflow changes.

New uploads, integrations, AI processing, payments or customer accounts must not be activated until the data map, security controls and notice have been reviewed again.

Read the pilot scope