Privacy Policy

Version 1.0 · Effective 28 August 2026

This policy describes the actual system, not a template. If something here is vague, it is because we have not decided it yet, and it says so.

Who we are

Supplier Check is operated by Pieter Le Roux, a sole trader resident in New Zealand, trading as Supplier Check. We are the party responsible for the information described below. You can reach us at support@suppliercheck.app.

Which privacy law applies

We are a New Zealand business, so the Privacy Act 2020 (NZ) and its information privacy principles bind us. Our customers are Australian, so we also commit voluntarily to handling information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), whether or not we are required to. Where the two differ, we apply the stricter.

What we collect

From Xero, when you connect an organisation

You sign in with Xero; we never see or hold a password. Xero tells us your name, email address and Xero user identifier. With your authorisation we then read, and store a minimal copy of:

  • Your organisation — name, country code and base currency.
  • Your suppliers — contact name, the tax number (ABN) recorded against the contact, default currency, contact status, and Xero’s contact identifier.
  • Accounts payable documents — for authorised supplier bills and supplier credit notes only: the document identifier, type, currency, status, outstanding amount, and when Xero last updated it.

We request read-only access. Supplier Check cannot create, edit, delete or pay anything in Xero. We do not request or receive bank accounts, payments, manual journals, bank transactions or attachments, and we do not store invoice line items, account codes, payment data or complete contact profiles.

From you

  • The credit limit you set for each supplier, and your warning and critical thresholds.
  • Email addresses you nominate to receive alerts.
  • Anything you write to us in a support email.

From the Australian Business Register

For each supplier ABN, we query the ABR’s ABN Lookup web service and hold the entity name, ABN status and GST registration information it returns, together with the time of the check.

From Stripe

Stripe handles payment. We receive a customer and subscription reference and the billing details you give Stripe. We never receive or store your card number.

Yes, some of this is personal information

Most of what we hold is business data, but not all of it. Your own name and email address are personal information. So are the names of suppliers who are individuals or sole traders, and an ABN belonging to a sole trader identifies a person. Alert recipients’ email addresses are personal information about people who may never have used our product. We treat all of it accordingly.

We do not collect sensitive information, we do not build profiles of individuals, and we do not use your data — or anyone’s — to train machine learning models.

Why we hold it

Solely to operate the two controls: calculating supplier exposure against the limits you set, and monitoring supplier ABN registration. We do not use your data for marketing, we do not sell it, and we do not share it with anyone except the sub-processors below.

Where it is stored, and who processes it

Your data is stored in Australia. The following third parties process some of it on our behalf:

Sub-processorWhat it doesWhere
XeroSource of your accounting data, and the identity provider you sign in with.New Zealand, Australia and the United States
Australian Business Register (ABR)ABN and GST registration lookups for the suppliers you monitor.Australia
ResendDelivery of alert and account emails.United States
SimpleLogin (Proton AG)Receiving and forwarding email you send to our support address.Switzerland and the European Union
StripeSubscription billing and card payments. We never receive your card details.United States and Australia
Onidel (Onidel Pty Ltd, ABN 67 662 357 397)Hosting this website, the application, and the database that holds your data.Sydney, Australia

Some of these are outside Australia and New Zealand. Before disclosing personal information to any of them we satisfy ourselves that it will be protected by comparable safeguards, as the Privacy Act 2020 requires. We will update this table before adding a sub-processor, not after.

How long we keep it, and how to get rid of it

Xero is the record of truth for everything we read. What we hold is a working copy, so deleting it costs you nothing.

  • Delete on request is immediate. Delete your account from Settings, or email us. We revoke our Xero connection and erase your organisation’s data as soon as you confirm — not at the end of a retention window.
  • Cancelling revokes our access. When your subscription ends we revoke the Xero connection immediately, so we stop receiving anything new. Remaining data is erased 30 days later if you have not already deleted it.
  • Registry data is cache, not record. Every field we get from the ABR other than the ABN itself and its status is treated as re-derivable cache. If the ABR notifies us that information has been withdrawn — for example to protect an individual’s privacy — we delete our copy immediately, as their terms require.
  • We keep no archive of the emails we send you. Alerts are delivered and not retained by us, so a withdrawal notice cannot leave a stale copy behind.

We keep billing records for as long as New Zealand tax law requires us to. That is invoices and payment references, not your Xero data.

Security

  • All traffic to and from the application is encrypted in transit with TLS.
  • Xero refresh tokens are encrypted at rest, which Xero requires of its developer partners and we would do anyway.
  • We hold no passwords, because we have no sign-in of our own. Xero is the sole identity provider, so your Xero security settings are ours.
  • If we suffer a privacy breach that is likely to cause serious harm, we will notify the affected people and the Office of the Privacy Commissioner, as required, and we will tell you what happened rather than what our lawyers would prefer.

Cookies and tracking

These public pages set no cookies. There is no analytics, no advertising pixel, no session recording and no third-party font or script. Nothing on this site knows you were here.

The application itself sets one strictly necessary session cookie to keep you signed in. That is all it is used for.

Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email support@suppliercheck.app; we will respond as quickly as we can and within the timeframes the Privacy Act 2020 sets.

If we get it wrong, you can complain to the New Zealand Office of the Privacy Commissioner, or, as an Australian customer, to the Office of the Australian Information Commissioner.

Changes to this policy

We will post any change here and update the version and effective date above. If a change materially affects how we handle your information, we will email you before it takes effect.