Privacy Policy

Last updated: 1 July 2026

1. Introduction

BuildBooks AI ("we", "us", "our") operates this application. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use BuildBooks AI.

2. Information We Collect

We collect the following types of information: • Account information: name, email address, business name, ABN. • Financial data: receipts, invoices, bank transactions, bank account details (BSB and account number, stored securely), payment records. • Usage data: how you interact with the app, features used, preferences set. • Device and technical data: IP address, browser type, device information, operating system.

3. How We Use Your Information

We use your information to: • Provide the bookkeeping and financial tracking service. • Process transactions and generate reports. • Send notifications, reminders, and summaries. • Improve our AI accuracy and feature recommendations. • Comply with legal and regulatory obligations. • Provide customer support.

4. Legal Basis for Processing

We process your personal data based on: • Your consent when you create an account and use the service. • Contractual necessity — to deliver the service you have subscribed to. • Legal compliance obligations, including ATO record-keeping requirements. • Our legitimate interests in operating and improving the service.

5. Data Storage and Security

Your data is stored in Australia where possible. We implement industry-standard security measures: • Encryption in transit (TLS 1.2+) and at rest. • Regular security reviews and vulnerability assessments. • Strict access controls — only authorised personnel can access backend systems. • Audit logging of all significant actions. • Payment processing handled by Stripe (PCI-DSS compliant) — we never store your card details.

6. Data Retention

Financial records are retained for 7 years in accordance with ATO requirements. Account data is retained while your account is active. Deleted accounts: data is removed after a 30-day grace period, during which you can recover your account. After the grace period, all data is permanently deleted except records required to be kept by law.

7. Data Sharing

We do NOT sell your data. We share your information only: • With your nominated accountant or BAS agent, when you use the Share feature. • With payment processors (Stripe) for billing purposes. • With hosting providers for infrastructure delivery. • When required by law, court order, or regulatory authority. • With your explicit consent for any other purpose.

8. Your Rights

You have the right to: • Access your data — request a copy of all information we hold about you. • Correct your data — update or fix inaccurate information. • Export your data — download your financial data at any time. • Delete your account — initiate deletion with a 30-day grace period. • Withdraw consent — disable specific data processing at any time. • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy.

9. Cookies and Local Storage

We use local storage and cookies for: • Session tokens — to keep you logged in securely. • User preferences — theme, layout, and display settings. • Offline receipt cache — receipts captured offline are stored locally and sync when online. We do NOT use third-party advertising cookies or tracking pixels.

10. Australian Privacy Principles

We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). This includes requirements for data collection, use, disclosure, storage, security, access, and correction.

11. Contact

For privacy enquiries or to exercise your rights under this policy, contact: conniewalker580@gmail.com