Privacy Notice
Version 1.0 · Last updated:
This Privacy Notice describes what personal data we process about the people who operate the Araguaney platform (coordinators, volunteers and administrators), for what purposes, and how you can exercise your rights. Araguaney is designed NOT to collect personal data of donors or final beneficiaries: we only process the minimal data of the users who operate the system.
1. Data controller
The controller of your personal data is the Araguaney project ("Araguaney", "the platform", "we"), a non-profit initiative to coordinate humanitarian aid collection centers.
As of the date of this notice there is no legal entity associated with the project: the data controller is Antony Delgado Casanova, the project's owner, who personally handles privacy requests through the email listed below and in the Data Subject Rights section. If a legal entity is constituted in the future, this notice will be updated with its legal name and registered address.
For any matter related to your personal data or this notice, contact us at: privacidad@araguaney.lat
2. Personal data we collect
We only collect the data needed to register and operate your account within a collection center. These are:
| Data | Purpose |
|---|---|
| Name and username | Identify you within the platform and in activity records. |
| Email address | Authentication, invitations and operational communications (e.g. password reset). |
| Password | Stored only in encrypted (hashed) form; never in clear text and never known to us. |
| Profile photo (optional) | Only if you choose to upload one; shown in your profile and in the app menu. |
| IP address | Security, abuse prevention, rate limiting and audit logs. |
| Activity logs | Actions you perform on the platform (create/seal boxes, close pallets, shipments, etc.), with date, time and user, for traceability and audit. |
| Role, center and campaigns | Determine what you can see and do within the platform (access control). |
3. Purposes of processing
We process your personal data for the following primary purposes, necessary to provide the service:
- Create and manage your user account.
- Authenticate you and control your access based on your role and center.
- Enable platform operations: donation intake, box sealing, pallets, shipments and manifests.
- Ensure platform security: fraud and abuse prevention, rate limiting and detection of unauthorized access.
- Keep audit and traceability records of operations.
- Send you operational and service communications (invitation, password reset, system notifications).
We do not use your data for marketing purposes, nor do we sell it to third parties.
4. IP addresses and audit logs
Because this is a platform coordinating humanitarian aid in a sensitive context, we apply reinforced security measures. In particular, we record your IP address and the actions you perform, associated with your user, date and time.
These records are used exclusively for security, abuse prevention and audit. They are not used to build commercial profiles.
Audit and event records are retained for as long as necessary to guarantee the traceability and security of platform operations. When you request the cancellation of your account, we will delete or anonymize your personal data except for what we must retain for legal or security reasons, for the strictly necessary period.
5. Transfers and processors
To operate the platform we rely on technology providers acting as data processors on Araguaney's behalf. These providers process data solely to provide their service to us and under confidentiality obligations. Some are located outside Mexico (mainly in the United States):
| Provider | Service | Data processed |
|---|---|---|
| Vercel | Website hosting (frontend) | IP address, access logs |
| Railway | Backend and database hosting | All account and operational data |
| Cloudflare | Content delivery, security (WAF/DNS), anti-abuse challenge (Turnstile) and file storage (R2) | IP address, traffic, exports and message attachments |
| Resend | Transactional email delivery | Email address and name |
| Cloudinary | Profile photo storage (only if you upload one) | Profile image |
| Google (optional) | Sign-in (OAuth) and analytics on public marketing pages only — never inside the panel | Authentication data / anonymous public-browsing metrics |
| Sentry (optional) | Error logging for technical diagnostics | Technical error context, possibly IP address |
Queries to reference catalogs (WHO, UNSPSC, IFRC/ICRC, IOM, GS1, COFEPRIS, RxNorm, Open Food Facts) are performed only with product data (e.g. a barcode) and do not include personal data.
We do not transfer your personal data to third parties other than these processors, except where required by a competent authority under the law.
6. Cookies and session technologies
Within the application panel we only use cookies strictly necessary for it to function:
- Session cookie (authentication) — keeps you signed in.
- CSRF protection cookie — prevents cross-site request forgery attacks.
- Language cookie — remembers your language preference (Spanish/English).
We do not use tracking or advertising cookies in the authenticated panel. On public marketing pages we may use web analytics to measure visits in aggregate; this analytics is never loaded inside the panel or the studio.
7. Retention periods
We keep each type of data only for as long as the purpose that originated it requires. These are the current periods:
| Data | Period | What happens when it expires |
|---|---|---|
| Account data (name, email, photo) | While the account exists | Removed when you delete your account or when your center deactivates it |
| Audit records (IP, action, date) | 90 days | Automatically deleted every night |
| Message attachments | 90 days | The file is automatically removed from storage |
| Export files (manifests, reports) | 1 hour | Deleted after download; 24 hours if generation failed |
| Email delivery failure records | 90 days | Automatically deleted |
| Inventory events (who sealed a box, closed a pallet or dispatched a shipment) | Indefinite | Not deleted: they sustain the traceability of the aid that was shipped |
Inventory events deserve an explanation. They are the reason the platform exists: they make it possible to know what each box contained and who prepared it, which is what a humanitarian shipment must be able to demonstrate to customs authorities. That is why they are not deleted. When you delete your account, those events are kept but stop identifying you: your name and email disappear, and only an identifier remains that no longer allows you to be recognized.
We do not automatically delete accounts for inactivity. Humanitarian volunteering is intermittent, and a person may come back months later, facing a new emergency, and need their access. It is up to each center's coordination to deactivate people who are no longer part of it, and up to each person to delete their account whenever they wish.
8. Data subject rights (ARCO) and consent withdrawal
As the owner of your personal data, you have the right to Access it, Rectify it when inaccurate, Cancel it when you consider it is no longer required for the stated purposes, and Object to its processing (ARCO rights). You may also withdraw any consent you have given us.
You can exercise cancellation yourself at any time from Settings in your dashboard: the "Delete my account" option permanently removes your name, email, photo and credentials. The record of which boxes you sealed or which shipments you dispatched is kept without your name, because inventory traceability cannot be broken; it remains as an identifier that no longer allows you to be recognized.
To exercise any of these rights, or if you prefer that we do it for you, send your request to:
Some data —such as certain audit records— may be retained for legal or security reasons even after a cancellation request, for the strictly necessary time. We will inform you if that is the case.
9. Information security
We apply reasonable administrative, technical and physical security measures to protect your data: encryption in transit, encrypted password storage, role-based access control, rate limiting, anti-abuse challenges and audit logs. No system is infallible; in the event of a breach that significantly affects your data, we will notify you as required by law.
10. Changes to this notice
We may update this Privacy Notice to reflect changes in the platform, our providers or applicable regulations. Each version carries a number and a last-updated date shown at the top of this document.
When a change is substantial, we will notify you through available means (e.g. at sign-in or by email) and, where applicable, ask you to accept the terms again. The current version will always be published on this page.