Privacy Policy

1. Introduction

1.1 Purpose

This Privacy Policy explains how we collect, use, store, and disclose information when you use the platform. Our goal is to ensure you understand what data we access, how it is processed, and the rights and choices available to your organisation.

1.2 Scope

This Policy applies to all data collected through:

This Policy does not apply to:

1.3 Policy Updates

We may update this Privacy Policy from time to time to reflect changes in features, integrations, regulatory requirements, or internal practices.


2. Data We Collect

2.1 Account Information

We collect information required to create and manage organisational accounts, including:

We do not collect personal information unrelated to platform access.

2.2 POS Data (Sales, Transactions, Products)

If you connect a POS integration, we may collect:

This data is used solely to generate sales insights, forecasting, and related analytics.

2.3 Accounting Data (Invoices, Suppliers, Chart of Accounts)

If you connect Xero or another accounting platform, we may collect:

This data is used to analyse supplier costs, price changes, and spending patterns.

2.4 Supplier and Order Management Data

If you connect supplier ordering systems, we may collect:

This data supports the supplier dashboard, price tracking, and cost analysis features.

2.5 Usage Analytics and Logs

We may collect certain usage information, including:

This data helps improve platform stability and usability.

2.6 Communications and Support Interactions

If you contact support or interact with us through the platform, we may collect:

This information is used to provide customer support and service improvements.

2.7 Optional File Uploads (CSV, Product Lists)

You may upload files such as:

These files are processed solely to populate dashboards, improve accuracy, and enhance insights.


3. How We Collect Data

3.1 Direct User Inputs

We collect data you or your authorised users provide directly, including:

3.2 OAuth Integrations

When you connect third-party services such as Xero, POS systems, or supplier platforms, we collect data through secure OAuth flows or API credentials.

3.3 Automated Syncing

After an integration is authorised, data may be collected automatically on a scheduled basis or in real-time depending on the capabilities of the connected service.

3.4 Cookies and Tracking (If Used)

We may use cookies or similar technologies to:

We do not use cookies for targeted advertising or cross-site tracking.


4. How We Use Data

4.1 To Operate the Supplier Dashboard

We use your accounting, POS, and supplier ordering data to display core dashboard information such as:

This processing is essential for the functioning of the platform.

4.2 To Analyse Supplier Costs and Price Changes

We analyse invoice and order data to:

4.3 To Support Future POS Features

When POS data is connected, we may use it to:

4.4 To Generate Insights and Forecasts

We use your combined datasets to produce:

All insights are informational and depend on the completeness of your data.

4.5 To Provide Supplier Benchmarking and Comparisons

We may compare your supplier costs or product prices against:

These benchmarks never identify any individual venue.

4.6 To Improve Platform Functionality

We may use diagnostic information, usage logs, and performance analytics to:

4.7 To Communicate With Users

We may use account and contact information to:

4.8 To Create Aggregated, Anonymised Datasets

We may transform your data into anonymised or aggregated datasets that cannot identify your organisation. These datasets may be used for:

We do not use identifiable business data for commercial resale or external distribution.


5. Sharing and Disclosure

5.1 Internal, to Your Authorised Team Members

Your organisation controls user access. Authorised users may view data, insights, and dashboards depending on the permissions set within your account.

5.2 With Integrated Platforms (Xero, POS, Supplier Systems)

We only share data with integrated platforms when:

By default, integrations are read-only, and we do not modify data in your external systems.

5.3 With Suppliers (Only If You Enable It)

Certain optional features may allow suppliers to access limited insights relating to their own products or pricing. This will only occur if:

Supplier access can be revoked at any time.

5.4 With Service Providers (Hosting, Analytics)

We may share data with third-party service providers who support:

These providers are contractually restricted to using data only for the services they perform.

5.5 Legal Compliance

We may disclose data where required to comply with:

Where legally permissible, we will notify you before any such disclosure.

5.6 No Data Selling

We do not sell identifiable data to third parties. We may use aggregated or anonymised data for:

These uses never identify any individual organisation.


6. Storage and Security

6.1 Storage Locations

Data may be stored on secure cloud infrastructure located in Australia or other regions as required for performance and reliability. Storage locations may change based on platform architecture or availability.

6.2 Security Protections

We implement industry-standard security measures including:

6.3 Access Controls

Access to personal and business data is restricted to authorised personnel who require it to operate or support the platform.

6.4 Breach Notifications

If a data breach occurs that is likely to result in serious harm, we will:


7. Data Retention

7.1 Active Account Retention

While your organisation's account remains active, we retain:

Retention is required to ensure continuous functionality.

7.2 Post-Integration Disconnection Retention

If you disconnect an integration (e.g. Xero or a POS system):

7.3 Post-Account Closure Retention

If your organisation's account is closed:

7.4 User-Requested Deletion

You may request deletion of your organisation's identifiable data at any time.


8. User Rights

8.1 Access

You may request access to the data we hold about your organisation, including integration data, platform-generated outputs, and account details. We will provide access within reasonable timeframes, subject to applicable laws.

8.2 Correction

If any data held about your organisation is inaccurate, incomplete, or outdated, you may request correction. Where corrections must be made in an external system (e.g. Xero or a POS), you must update those systems directly.

8.3 Export

You may request export of your data in a commonly used format. Exports may include:

We may exclude proprietary models, algorithms, and internal system structures.

8.4 Deletion

You may request deletion of your identifiable data at any time.

8.5 Marketing Preferences

You may opt out of non-essential communications.


9. International Transfers

9.1 Australia, UK, US, Europe, New Zealand, Canada, Indonesia, South Africa, and Other Regions

Data may be processed or stored in:

By using the platform, you consent to data being transferred to, stored in, or processed in these regions for the purposes of providing the service. All international transfers are conducted in compliance with applicable data protection laws and with appropriate safeguards in place.

9.2 Safeguards Used

To protect data transferred internationally, we implement appropriate safeguards including:


10. Children's Privacy

10.1 Business Use Only

The platform is designed exclusively for use by businesses and commercial organisations.

Access to the platform must be limited to authorised personnel acting on behalf of a business.


11. Contact Information

If you have questions about this Privacy Policy, data handling practices, or wish to exercise any data rights, you may contact us at:

Email: support@thenxt.ai

Website: thenxt.ai