Legal

Privacy Policy

Last updated: 19 July 2026

This Privacy Policy explains how Prepaidly Pty Ltd (ABN 19 688 065 367, ACN 688 065 367) (“Prepaidly”, “we”, “us” or “our”) collects, uses, discloses and protects your personal information when you use the Prepaidly website and application (the “Service”). We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Prepaidly Pty Ltd

ABN 19 688 065 367

ACN 688 065 367

South Australia, Australia

hello@prepaidly.io

1. Information we collect

We collect information directly from you (for example when you register, subscribe or contact support), automatically when you use the Service (through logs, cookies and similar technologies), and from third parties such as Xero and Stripe when you authorise or use those connections.

We collect the following categories of information:

  • Account information: your name, email address, password (stored in hashed form), display name and role within an organisation.
  • Xero connection data: when you connect a Xero organisation, we receive OAuth access and refresh tokens and read data you authorise, such as your chart of accounts, contacts, organisation details and manual journals. We use this data to provide the Service and for the support, operations and security purposes described below.
  • Schedule and financial data: the prepayment and unearned revenue schedules, amounts, dates, accounts and journals you create or import.
  • Billing information: subscription tier and payment status. Card payments are processed by our payment provider (Stripe); we do not store full card numbers.
  • Uploaded files and imports: files you upload or import into the Service, such as invoice attachments and CSV schedule imports, and their associated metadata.
  • Usage and technical data: log data, device and browser information, IP address and activity within the app, used for security, troubleshooting and improving the Service.

2. How we use your information

We use personal information and organisation data processed through the Service to:

  • provide, operate, maintain and secure the Service;
  • authenticate you and manage your account and organisation access;
  • connect to Xero and post manual journals you authorise;
  • process subscriptions, billing and related notifications;
  • respond to support requests and communicate service-related information;
  • detect, prevent and respond to fraud, abuse and security incidents; and
  • comply with our legal obligations.

3. AI and machine learning

Unless we expressly disclose otherwise and obtain any required consents, we do not use customer data obtained from Xero connections to train general-purpose artificial intelligence or machine-learning models. If we later introduce AI-assisted features that process your data, we will update this Policy and provide additional transparency where required.

4. Access by Prepaidly personnel

To operate Prepaidly as a hosted service, a limited number of authorised Prepaidly personnel may access account, organisation and related Service data (including schedules, journals, connection status, billing metadata and technical logs) where reasonably necessary for:

  • Customer support: investigating and resolving issues you raise, or verifying that a feature is working as expected for your organisation;
  • Operations and maintenance: deploying, monitoring, troubleshooting and improving the Service, including diagnosing outages and data integrity problems; and
  • Security and abuse prevention: detecting, investigating and responding to suspected fraud, unauthorised access, misuse or other security incidents.

Such access is limited to personnel who need it for those purposes, is subject to confidentiality obligations, and is not used to market to your clients or to disclose your organisation’s data to unrelated third parties. Customer organisations remain logically separated for ordinary end-user use; platform-level access is an operational control for the purposes above, not a right for one customer to view another customer’s data.

5. Disclosure of information

We do not sell your personal information. We disclose information only as needed to operate the Service, including to:

  • Xero: to read authorised data and post journals on your instruction;
  • Service providers: hosting, infrastructure, analytics, email and payment providers (such as Stripe) who process data on our behalf under appropriate confidentiality obligations;
  • Other users in your organisation: administrators and members of a Xero organisation you belong to may see schedules, journals and activity for that organisation; and
  • Legal and regulatory bodies: where required by law or to protect our rights, users or the public.

6. Overseas disclosure

Some of our service providers and integration partners may store or process data outside Australia. Countries in which these recipients are likely to be located include New Zealand (Xero) and the United States (Stripe and certain cloud hosting and email providers); the exact countries may vary depending on the provider and configuration in use. Where an overseas disclosure occurs, we take reasonable steps to ensure recipients handle your information consistently with the Australian Privacy Principles.

7. Data security

We protect your information using technical and organisational measures, including encryption of data in transit (HTTPS), server-side storage of Xero tokens and secrets, tenant isolation so one organisation’s data is not exposed to another during ordinary use, role-based access controls for end users, and restricted platform access for authorised Prepaidly personnel as described above. No method of transmission or storage is completely secure, but we work to protect your information.

If we suspect a data breach, we will promptly investigate, contain and assess it. Where an eligible data breach is likely to result in serious harm to affected individuals, we will notify those individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

8. Data retention

We retain personal information for as long as your account is active or as needed to provide the Service, and thereafter as required to meet legal, accounting or reporting obligations. You may request deletion of your account, after which we will delete or de-identify your information except where retention is required by law. Before deletion takes effect, you may request an export of your data by contacting us. Disconnecting a Xero organisation removes our stored tokens for that organisation and does not delete any data within Xero itself.

9. Your rights

Subject to the Privacy Act, you may request access to, or correction of, the personal information we hold about you. To make a request, or if you have a privacy concern or complaint, contact us using the details below. We will respond within a reasonable period and aim to resolve privacy complaints within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Cookies

We use cookies and similar technologies to keep you signed in, remember preferences and understand how the Service is used. You can control cookies through your browser settings, though disabling them may affect functionality.

11. Direct marketing

We may send you marketing communications about the Service where permitted by law. You can opt out at any time by using the unsubscribe link in the communication or by contacting us using the details below, and we will action your request within the time required by applicable law. Service-related messages (such as billing, security and account notices) are not marketing and will continue while you hold an account.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, notify you through the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact us

For privacy requests, questions or complaints (including access, correction and deletion requests), please contact us at privacy@prepaidly.io. For billing or technical support, contact support@prepaidly.io; for anything else, contact hello@prepaidly.io.