Privacy Policy
This policy describes the actual system, not a template. If something here is vague, it is because we have not decided it yet, and it says so.
Who we are
Supplier Check is operated by Pieter Le Roux, a sole trader resident in New Zealand, trading as Supplier Check. We are the party responsible for the information described below. You can reach us at support@suppliercheck.app.
Which privacy law applies
We are a New Zealand business, so the Privacy Act 2020 (NZ) and its information privacy principles bind us. Our customers are Australian, so we also commit voluntarily to handling information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), whether or not we are required to. Where the two differ, we apply the stricter.
What we collect
From Xero, when you connect an organisation
You sign in with Xero; we never see or hold a password. Xero tells us your name, email address and Xero user identifier. With your authorisation we then read, and store a minimal copy of:
- Your organisation — name, country code and base currency.
- Your suppliers — contact name, the tax number (ABN) recorded against the contact, default currency, contact status, and Xero’s contact identifier.
- Accounts payable documents — for authorised supplier bills and supplier credit notes only: the document identifier, type, currency, status, outstanding amount, and when Xero last updated it.
We request read-only access. Supplier Check cannot create, edit, delete or pay anything in Xero. We do not request or receive bank accounts, payments, manual journals, bank transactions or attachments, and we do not store invoice line items, account codes, payment data or complete contact profiles.
From you
- The credit limit you set for each supplier, and your warning and critical thresholds.
- Email addresses you nominate to receive alerts.
- Anything you write to us in a support email.
From the Australian Business Register
For each supplier ABN, we query the ABR’s ABN Lookup web service and hold the entity name, ABN status and GST registration information it returns, together with the time of the check.
From Stripe
Stripe handles payment. We receive a customer and subscription reference and the billing details you give Stripe. We never receive or store your card number.
Yes, some of this is personal information
Most of what we hold is business data, but not all of it. Your own name and email address are personal information. So are the names of suppliers who are individuals or sole traders, and an ABN belonging to a sole trader identifies a person. Alert recipients’ email addresses are personal information about people who may never have used our product. We treat all of it accordingly.
We do not collect sensitive information, we do not build profiles of individuals, and we do not use your data — or anyone’s — to train machine learning models.
Why we hold it
Solely to operate the two controls: calculating supplier exposure against the limits you set, and monitoring supplier ABN registration. We do not use your data for marketing, we do not sell it, and we do not share it with anyone except the sub-processors below.
Where it is stored, and who processes it
Your data is stored in Australia. The following third parties process some of it on our behalf:
| Sub-processor | What it does | Where |
|---|---|---|
| Xero | Source of your accounting data, and the identity provider you sign in with. | New Zealand, Australia and the United States |
| Australian Business Register (ABR) | ABN and GST registration lookups for the suppliers you monitor. | Australia |
| Resend | Delivery of alert and account emails. | United States |
| SimpleLogin (Proton AG) | Receiving and forwarding email you send to our support address. | Switzerland and the European Union |
| Stripe | Subscription billing and card payments. We never receive your card details. | United States and Australia |
| Onidel (Onidel Pty Ltd, ABN 67 662 357 397) | Hosting this website, the application, and the database that holds your data. | Sydney, Australia |
Some of these are outside Australia and New Zealand. Before disclosing personal information to any of them we satisfy ourselves that it will be protected by comparable safeguards, as the Privacy Act 2020 requires. We will update this table before adding a sub-processor, not after.
How long we keep it, and how to get rid of it
Xero is the record of truth for everything we read. What we hold is a working copy, so deleting it costs you nothing.
- Delete on request is immediate. Delete your account from Settings, or email us. We revoke our Xero connection and erase your organisation’s data as soon as you confirm — not at the end of a retention window.
- Cancelling revokes our access. When your subscription ends we revoke the Xero connection immediately, so we stop receiving anything new. Remaining data is erased 30 days later if you have not already deleted it.
- Registry data is cache, not record. Every field we get from the ABR other than the ABN itself and its status is treated as re-derivable cache. If the ABR notifies us that information has been withdrawn — for example to protect an individual’s privacy — we delete our copy immediately, as their terms require.
- We keep no archive of the emails we send you. Alerts are delivered and not retained by us, so a withdrawal notice cannot leave a stale copy behind.
We keep billing records for as long as New Zealand tax law requires us to. That is invoices and payment references, not your Xero data.
Security
- All traffic to and from the application is encrypted in transit with TLS.
- Xero refresh tokens are encrypted at rest, which Xero requires of its developer partners and we would do anyway.
- We hold no passwords, because we have no sign-in of our own. Xero is the sole identity provider, so your Xero security settings are ours.
- If we suffer a privacy breach that is likely to cause serious harm, we will notify the affected people and the Office of the Privacy Commissioner, as required, and we will tell you what happened rather than what our lawyers would prefer.
Cookies and tracking
These public pages set no cookies. There is no analytics, no advertising pixel, no session recording and no third-party font or script. Nothing on this site knows you were here.
The application itself sets one strictly necessary session cookie to keep you signed in. That is all it is used for.
Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email support@suppliercheck.app; we will respond as quickly as we can and within the timeframes the Privacy Act 2020 sets.
If we get it wrong, you can complain to the New Zealand Office of the Privacy Commissioner, or, as an Australian customer, to the Office of the Australian Information Commissioner.
Changes to this policy
We will post any change here and update the version and effective date above. If a change materially affects how we handle your information, we will email you before it takes effect.