Privacy Policy

Last updated: October 8, 2026

1. Introduction

Instant Receipts Pty Ltd (ABN: 19 684 597 331) ("we", "us", "our") values your privacy and is committed to protecting the personal information of tradies, small business owners, independent contractors, and their accounting professionals. This Privacy Policy explains how we collect, use, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) when you use our AI-powered bookkeeping solution.

2. What We Collect

We may collect the following types of personal information:

Personal and Business Details

  • Your name, email address, phone number, and business address
  • ABN, business name, trading name, and industry type (e.g., electrician, plumber, builder, consultant)
  • Business structure and GST registration status
  • Account credentials and login information

Financial Information

  • Payment and billing details (processed securely via third-party providers such as Stripe/RevenueCat; we do not store complete card details)
  • Uploaded business documents including receipts, invoices, bank statements, tax invoices, and BAS records
  • Transaction data and expense categorisation information
  • Tax-related business records and financial summaries

Professional Network Information

  • Contact details for your nominated accountant, bookkeeper, or registered tax agent
  • Access permissions and data sharing preferences with your accounting professionals

Technical Information

  • IP address, device identifiers, browser type, and operating system
  • Device and app security signals, such as whether the app or device appears to have been modified, tampered with or run in an unsupported environment, where the app was installed from, and security events our protections detect
  • App usage logs, website analytics data, and user interaction patterns
  • Cookie data and session information

3. How We Use Information

We process personal information to provide and improve our Services, comply with legal obligations, and where necessary, with your consent. We use your personal information to:

Service Delivery

  • Provide, operate, and continuously improve our AI-powered bookkeeping services
  • Automatically categorise business expenses according to ATO guidelines
  • Calculate GST components and identify tax-deductible expenses
  • Generate BAS-ready reports and end-of-financial-year summaries
  • Enable secure data sharing with your authorised accountant or tax agent
  • We may use anonymised and aggregated data, and de-identified behavioural patterns derived from your use of the Services, to develop, train, and improve our machine learning models. We do not use personally identifiable financial information for model training. This does not apply to data obtained under the Consumer Data Right (CDR) via bank feed connections, which is excluded from all AI and machine learning use — see section 14.
  • You are responsible for ensuring that the information you provide is accurate and complete.
  • AI-generated outputs may be inaccurate or incomplete and should not be relied upon without verification.

Account Management

  • Process subscription payments and manage billing arrangements
  • Authenticate your identity and maintain account security
  • Provide customer support and technical assistance
  • Send service updates, feature announcements, and important notifications

Legal and Regulatory Compliance

  • Comply with Australian taxation, GST, and small business regulatory requirements
  • Assist with tax preparation and ATO reporting obligations
  • Maintain business records as required by law
  • Protect against fraud, abuse, or misuse of our services

Security and Abuse Prevention

  • Run an automated security monitoring system that analyses IP addresses, device identifiers, device and app security signals, and usage patterns to detect attempts to break, modify, tamper with or hack the Services
  • Automatically restrict, suspend or permanently block the account, device and IP address involved when a threat is detected, without prior notice, as described in our Terms of Use
  • Keep a record of each block (such as the device identifier, IP address, reason and time) so we can enforce it, investigate incidents and respond to appeals

This monitoring and blocking is carried out automatically by our systems rather than by people watching individual accounts. If you believe you have been blocked in error, contact us at support@instantreceipts.com.au and we will review the decision.

Marketing and Communication (with consent)

  • Send educational content about tax compliance and bookkeeping best practices
  • Provide industry-specific advice for tradies and small business owners
  • Share promotional offers and new feature announcements

4. Disclosure of Information

We may share your personal information with:

Authorised Representatives

Your nominated accountant, bookkeeper, or registered tax agent when you explicitly grant access through our platform. Other professional advisors you designate with appropriate permissions.

Service Providers

  • Cloud hosting and infrastructure providers (AWS, Azure, Cloudflare, Supabase, Fly.io)
  • Payment processing companies (Stripe, RevenueCat). Payments processed via Apple App Store, Google Play, Stripe, or RevenueCat are subject to their respective privacy policies.
  • AI processing and machine learning service providers.
  • Customer support and help desk platforms.
  • Analytics and performance monitoring services.

We engage trusted third-party service providers, including cloud infrastructure providers, payment processors, and AI technology providers, to support the delivery and operation of our Services. These providers may include services such as AWS, Azure, Cloudflare, Supabase, Fly.io, Stripe, RevenueCat, and AI processing providers. These providers are contractually required to implement appropriate security and privacy protections. We only engage third-party providers that comply with applicable privacy and security standards.

Legal and Regulatory Authorities

Australian Tax Office (ATO), Australian Securities and Investments Commission (ASIC), law enforcement agencies, courts, or regulatory bodies when required by law, and government authorities where disclosure is legally mandated.

Third-Party Integrations and Authorised Services

We may share information with third-party services you explicitly connect or authorise within the platform, such as accounting software, cloud storage providers, or other integrations you choose to enable. Where you connect a bank account for automated transaction feeds, your data is shared with Fiskil Pty Ltd, our Consumer Data Right (CDR) data intermediary — see section 14 for how CDR data is handled.

We do not sell, rent, or trade your personal information.

5. Data Storage and Security

Storage Location

Primary data is stored on secure cloud servers located in Australia, using reputable providers with robust security certifications. Some non-CDR data and services may involve trusted international data centres, as described in section 6. Consumer Data Right (CDR) data obtained via Fiskil is stored exclusively in Australia — see section 14.

Security Measures

  • Data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
  • Multi-factor authentication for account access
  • Regular security audits and vulnerability assessments
  • Secure backup and disaster recovery procedures
  • Access controls limiting employee access to personal information

Security Limitations

Despite our comprehensive security measures, no method of electronic storage or transmission is 100% secure. We continuously update our security practices to protect against evolving threats.

6. Overseas Transfers

Some of our trusted service providers may process or store your personal information outside Australia, including in:

  • United States (cloud infrastructure and AI processing services)
  • Singapore (regional data centres)
  • European Union (analytics and support services)

When transferring personal information overseas, we:

  • Ensure all providers meet or exceed Australian Privacy Principles
  • Implement contractual safeguards requiring equivalent privacy protection standards
  • Regularly audit overseas processing arrangements for compliance
  • Maintain the ability to recall or delete data as required under Australian law

Consumer Data Right (CDR) data obtained via Fiskil is not included in any of the above — it is never transferred, stored, or processed overseas. See section 14.

Despite these safeguards, overseas recipients may not be subject to Australian privacy laws and you may not be able to seek redress under the Privacy Act 1988 (Cth) in those jurisdictions.

7. Access and Correction

You have the right to:

  • Request access to the personal information we hold about you
  • Ask us to correct any inaccurate or outdated information
  • Request deletion of your personal information in certain circumstances
  • Obtain a copy of your data in a portable format when technically feasible

To exercise these rights, contact us at support@instantreceipts.com.au. We will respond within 30 days and may charge a reasonable fee for complex access requests.

8. Retention and Deletion

Retention Period

We retain your personal information while your account is active and you continue to use our services. Business and financial records are retained for 7 years in accordance with Australian tax record-keeping requirements. Marketing preferences and communication logs are retained until you opt out. Consumer Data Right (CDR) data is subject to separate, stricter rules and is not covered by the retention periods in this section — see section 14 and our Data Retention and Deletion Policy.

Account Cancellation

Upon account cancellation or service termination:

  • We may retain essential data for 12 months for backup, dispute resolution, and legal purposes
  • Tax-related business records are retained for the full 7-year period as required by law
  • Records of security blocks (such as device identifiers, IP addresses, the reason and time) may be kept after cancellation or deletion for as long as needed to keep the block in place and to protect the Services and our users

After the retention period, data will be securely deleted or anonymised. You may request deletion of your personal data, subject to our legal retention obligations.

9. Cookies and Analytics

9.1 Website Tracking Technologies

Our website and mobile applications use cookies and similar technologies to:

  • Enable essential functionality and maintain user sessions
  • Remember your preferences and account settings
  • Analyse website traffic through Google Analytics and similar services
  • Improve our AI-powered features through usage pattern analysis
  • Provide personalised content and recommendations

Cookie Management

You can control cookie settings through your browser preferences. Disabling certain cookies may limit website functionality. Essential cookies required for account access cannot be disabled. You can opt out of analytics cookies while maintaining service access.

9.2 Mobile App Analytics

We may collect limited analytics data from our mobile applications to improve performance, stability, and user experience. This may include crash reports, usage patterns, and feature interaction data. This data does not directly identify you.

10. Marketing Communications

Communication Types

With your consent, we may send:

  • Product updates and new bookkeeping feature announcements
  • Educational content about GST compliance and tax obligations for tradies
  • Industry-specific tips for contractors and small business owners
  • End-of-financial-year reminders and BAS lodgement notifications
  • Special promotional offers and service upgrades

Opt-Out Options

Click the unsubscribe link in any marketing email, update your communication preferences in your account settings, or contact us directly at support@instantreceipts.com.au. Opt-out requests are processed within 5 business days.

11. Data Breach Notification

In accordance with the Notifiable Data Breaches (NDB) scheme:

Our Obligations

  • We will assess suspected data breaches as soon as practicable, and in any case within 30 days.
  • Notify the Office of the Australian Information Commissioner (OAIC) of eligible breaches likely to result in serious harm
  • Notify affected individuals as soon as practicable after becoming aware of an eligible breach
  • Maintain detailed records of all breach assessments and responses

Eligible Data Breaches

An eligible data breach occurs when there is unauthorised access, disclosure, or loss of personal information that would likely result in serious harm to affected individuals, such as identity theft, financial fraud, or significant emotional distress.

12. Children's Privacy

Our bookkeeping services are designed for business use and are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will take immediate steps to delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes in our business practices or services
  • Updates to Australian privacy legislation
  • Improvements to our security and data protection measures

We will notify you of significant changes by:

  • Email notification to your registered account
  • Prominent notice on our website and mobile application
  • In-app notifications when you next log in

14. Consumer Data Right (CDR) Data (Open Banking)

If you choose to connect a bank account for automated transaction feeds, we receive that data under the Consumer Data Right (CDR) through Fiskil Pty Ltd, an Accredited Data Recipient under the CDR framework administered by the ACCC. Instant Receipts Pty Ltd acts as a CDR Representative of Fiskil for this purpose — we are not ourselves accredited under the CDR.

CDR data (the bank account and transaction data obtained this way) is treated differently to the other information described in this Privacy Policy:

  • It is stored exclusively on infrastructure located in Australia. It is never transferred, stored, or processed overseas, and the overseas transfers described in section 6 do not apply to it.
  • It is never used to train, fine-tune, or improve any AI or machine learning model, and is excluded from the anonymised/aggregated data use described in section 3.
  • Consent to share CDR data is time-limited (up to 6 months) and CDR data is permanently and irretrievably deleted — not de-identified or archived — when your consent is withdrawn, expires, or your account is closed. You can withdraw consent at any time within the app. Full detail is set out in our Data Retention and Deletion Policy, which takes precedence over section 8 of this Privacy Policy for CDR data.
  • Fiskil's own CDR Policy — which explains how Fiskil collects, holds, uses and discloses CDR data, and how Instant Receipts operates as its CDR Representative — is publicly available at fiskil.com/legal/cdr-policy.

15. Contact Us and Complaints

Privacy Enquiries

For questions about this Privacy Policy or our privacy practices, contact our Privacy Officer:

Instant Receipts Pty Ltd

Email: support@instantreceipts.com.au

Address: Office 3807, Ground Floor, 470 St Kilda Rd, Melbourne Vic 3004

Phone: 1800 595 520