Privacy Policy

Last updated: 21 September 2026

Lodgio Pty Ltd (ABN 74 702 266 037) (“Lodgio”, “we”, “us”, “our”) is committed to protecting your privacy in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we collect, use, disclose and protect your personal information.

1. Information We Collect

Account information

When you create an account, we collect your email address. We use passwordless (magic link) authentication – We do not store passwords.

Financial data you upload

You may upload bank statements (CSV, OFX, QIF files) containing transaction dates, descriptions, and amounts. You may also upload receipt images. This data is stored solely to provide the Service to you. We do not access your bank accounts directly unless you explicitly enable Open Banking (CDR) integration.

Private-beta waitlist

While Lodgio is in private beta, access is limited to invited email addresses. If you sign in with an address that is not yet invited, we keep that email address so we can tell you when a place opens up and you can optionally add your business name. We use it for nothing else. It is deleted as soon as you are given access, or within six months if we have not reached you – Whichever comes first. Ask us at support@lodgio.com.au and we will remove it sooner.

Usage data

We collect basic usage analytics such as page views and feature usage to improve the Service. We do not use third-party tracking scripts or sell usage data.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the Service, including transaction categorisation and BAS record preparation
  • Authenticate your identity and secure your account
  • Process payments via Stripe (Pro plan subscribers)
  • Send transactional emails (magic links, payment receipts)
  • Improve the Service based on aggregated, anonymised usage patterns

3. Third-Party Services

Supabase

Your data is stored in Supabase, which provides our database, authentication and file storage infrastructure. Supabase encrypts data at rest and in transit. Row-level security policies ensure you can only access your own workspace data.

Stripe

If you subscribe to the Pro plan, payment processing is handled by Stripe. We do not store your credit card details – Stripe handles all payment data in compliance with PCI DSS. See Stripe's Privacy Policy.

Open Banking (CDR)

If you choose to connect your bank via the Consumer Data Right (CDR) framework, data is transferred under the CDR rules. You can revoke consent at any time through your bank or through Lodgio.

Basiq

If you connect a bank that way, the connection is operated by Basiq. To create your Basiq user, Lodgio sends your email address and nothing else – Your bank sign-in details are entered on Basiq's own consent screen, never in Lodgio. Basiq then supplies the account and transaction data Lodgio imports. When you disconnect, Lodgio asks Basiq to delete the connection. If it was your last connection, Lodgio asks Basiq to delete your user record as well.

Google Cloud Vision

When you upload a receipt, the image is sent to Google Cloud Vision to read the text on it, so Lodgio can suggest the supplier, date and amount. Only the receipt image is sent – Not your transactions, and not your account details. If receipt text recognition is not configured on this deployment, no image ever leaves it and receipts are stored without a text read.

ABN Lookup (Australian Business Register)

When you check a supplier's ABN or GST registration, we send either the ABN you typed or the transaction's own description (the payee / merchant text from your bank data, with punctuation removed) as a name search to the Australian Business Register's ABN Lookup web service. Nothing else about the transaction is sent – not the amount, the date or the account – and the check is only made when you ask for it.

Sentry

If something goes wrong, an error report is sent to Sentry so it can be diagnosed and fixed. The reports are scrubbed before they are sent: they carry the technical detail of the failure, not your transactions, amounts or file contents. We also send Sentry a performance sample of about one in ten page loads and requests – How long each step took and which page or endpoint it was – scrubbed the same way, so that we can find slow parts of the Service. Neither kind of report carries your financial data.

Email delivery (Resend or Postmark)

Emails Lodgio sends on your behalf or to you – A BAS reminder, an invoice or its reminder to your client, an accountant share invitation – Are delivered by our email provider, which receives the recipient's address and the contents of that message. Sign-in magic links are sent through Supabase Auth.

Vercel

Lodgio is hosted on Vercel, which runs the application and therefore handles the network requests your browser makes to it, including the standard server logs that come with that.

4. Data Sharing

We do not sell, rent, or share your personal information or financial data with third parties for marketing purposes. The service providers listed above are the only third parties that receive your data, each one receives only what its job needs, and none of them receives it for any purpose of their own.

We may disclose information if required by Australian law, regulation, or legal process.

5. Data Retention

We retain your data for as long as your account is active. You can delete a workspace at any time from Settings → Danger Zone: it is hidden immediately and permanently deleted after a 30-day recovery window, during which you can restore it yourself. Permanent deletion erases the workspace's transactions, receipts and receipt images, invoices, exports, its invoice logo and its bank feed connection. Keeping records for as long as the ATO requires is your obligation, so export your data before you delete a workspace. To close your account entirely and erase your personal information, email us at support@lodgio.com.au and we will action the request within 30 days – Except where we are required by law to retain certain records (e.g. payment records for tax purposes).

We keep a security audit trail of the actions taken in the Service – Which action, on what kind of record, when, by which account and from which network address, and the values that changed – for up to seven years, so that changes to financial records can be traced. When a workspace is permanently deleted, the changed values, the account that made each change, its email address and the network address are removed from its entries and only the skeleton (the action, the kind of record and the time) remains. The audit trail is available on request rather than in the self-service export.

If you are on the private-beta waitlist and have not yet been given access, we hold only your email address (and your business name if you gave us one). That entry is deleted when you are given access, or six months after your most recent sign-in attempt, whichever comes first.

You may export all your data at any time. Go to Settings → Your data → Export my data to download a ZIP of everything we hold for your account across your workspaces (transactions, categories, rules, receipts, invoices and settings) as CSV and JSON files. The Accountant Pack export also produces a period-scoped ZIP for lodgement.

6. Data Security

We protect your data through:

  • Encryption at rest and in transit (TLS 1.2+)
  • Row-level security ensuring workspace isolation
  • Passwordless authentication reducing credential-based attack vectors
  • Regular security reviews of our codebase and infrastructure

No system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.

7. Cookies and Local Storage

Lodgio uses essential cookies and browser local storage for authentication (Supabase session tokens) and user preferences (theme settings). We do not use advertising or third-party tracking cookies.

8. Your Rights Under the Australian Privacy Act

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your workspaces and their data yourself at any time and request full account closure and erasure of your personal information by contacting us
  • Export your data in standard formats (CSV, ZIP)
  • Complain to the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached

To exercise any of these rights, contact us at support@lodgio.com.au.

9. Children

Lodgio is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email or an in-app notice. The “last updated” date at the top reflects the most recent revision.

11. Contact Us

If you have questions or concerns about this privacy policy or our data practices, contact us at:

support@lodgio.com.au

You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC).