Legal

Privacy Policy

What we collect, why we collect it, who else can see it, and what you can ask us to do about it.

Last updated: 9 August 2026

The short version

  • We collect what we need to run your account and nothing beyond it.
  • We do not sell your data, and we never have. We don't run ads, build advertising profiles, or share your information with data brokers.
  • The records you keep in Webrox — your clients, invoices, expenses — belong to you. We hold them on your behalf.
  • You can export everything you've put into Webrox at any time, in open formats, without asking us.
  • We use a small number of well-known providers to run the service. They're all listed below.

The rest of this page is the detail behind those points.

1. Who this policy is about

Webrox ("we", "us") provides invoicing, expense-tracking and light-accounting software for Australian sole traders and small businesses. We operate from Brisbane, Queensland, under ABN 15 471 468 055. This policy covers our marketing website at webrox.com.au and the application at webrox.au.

It's worth being clear up front that there are two different kinds of personal information involved in a service like ours, and we treat them differently:

  • Information about you, our customer. Your name, your email address, your business details, your subscription. We decide what happens to this information, and this policy explains those decisions.
  • Information you put into Webrox about other people — typically your own clients: their names, email addresses, postal addresses, and the invoices and payments attached to them. We hold this on your behalf and act on your instructions. You decide what goes in, how long it stays, and when it's deleted. We don't use it for our own purposes, we don't analyse it to build products, and we don't contact your clients except to deliver something you asked us to send (an invoice, a quote, a receipt, a payment reminder, or a client-portal invitation).

If you're a client of a business that uses Webrox and you have a question about your own information, the business that invoiced you is the right first contact — they control that record, not us. We'll help them help you.

2. What we collect about you

Information you give us directly

  • Account details: your name, email address and a password. Passwords are stored only as a one-way hash — we cannot read yours, and nobody at Webrox can tell you what it is.
  • Business details: business name, trading name, ABN, address, phone number and website, as you enter them. These appear on the invoices you issue, which is what they're for.
  • Tax and invoicing settings: GST registration status, BAS reporting frequency, payment terms, invoice numbering and similar preferences.
  • Team members: if you invite colleagues, their names and email addresses.
  • Anything you send us: support tickets, feature requests, and replies to our emails.

Information created by using the service

  • Your business records: clients, invoices, quotes, expenses, vendors, receipts you upload, and the documents generated from them.
  • Activity logs: a record of significant actions on your account — an invoice created, edited, sent, marked paid or refunded; settings changed; security events such as enabling two-factor authentication. This exists so you (and we, if you ask for help) can answer "what happened to this invoice, and when".
  • Email logs: the recipient, subject and outcome of emails sent from your account, so you can confirm whether an invoice actually went out. We log that the mail server accepted the message — that is not the same as confirming it reached an inbox, and we don't claim otherwise.
  • Billing records: your plan, subscription status and renewal date.

Technical information

  • Standard web server logs: IP address, browser type, pages requested and timestamps. These are ordinary operational records used for security, troubleshooting and abuse prevention.
  • Security records: if you use two-factor authentication or a passkey, we store what's needed to verify it. Two-factor secrets are encrypted. A passkey stores only a public key — the private key never leaves your device, and cannot be extracted from anything we hold.

What we deliberately don't collect

  • Card numbers. See section 5 — these go directly to Stripe and never touch our servers.
  • Bank login credentials. Webrox has no bank-feed integration and never asks for internet banking details. Bank reconciliation works from a CSV statement you export from your bank yourself and upload — we never connect to your bank, and never hold anything that could be used to sign in to it. If anything claiming to be Webrox asks you for internet banking details, it isn't us.
  • Sensitive information as defined in the Privacy Act — health, biometric, racial or ethnic origin, political or religious beliefs, and so on. We have no use for it and don't ask for it.

3. Why we use it

We use the information above to:

  • Provide the service — create and send your invoices, generate your reports, run your recurring billing.
  • Authenticate you and keep your account secure.
  • Take payment for your subscription.
  • Send service messages: payment failures, password resets, email verification, and important changes to the service. These aren't marketing and you can't unsubscribe from them while you have an account, because they're how we tell you something is wrong.
  • Provide support when you ask for it.
  • Detect and prevent abuse, fraud and automated attacks.
  • Understand which pages of our marketing site lead to signups, in aggregate.
  • Meet our own legal and tax obligations.

We do not use your business records to train machine-learning models, and we do not use them to build any product other than the one you're paying for.

4. Who else is involved

Running a service like this means relying on a handful of specialist providers. Here is the complete list, what each one receives, and when.

Always in use

  • Our hosting. The application and database run on servers we administer directly, located in Australia (currently Brisbane, Queensland), rather than on a third-party platform that holds your data on our behalf.
  • Stripe — subscription billing. Receives your email address, business name and payment details when you subscribe. Stripe is a PCI-DSS Level 1 certified payment processor.
  • Cloudflare — bot protection on our signup, password-reset and administrator login forms, and delivery of some styling assets. Receives your IP address and basic browser information in order to distinguish a person from an automated script.
  • Google — website analytics (see section 6) and web fonts. Receives your IP address and browsing activity on our sites. Fonts are loaded from Google's servers, which means your browser contacts Google when a page loads, whether or not you accept analytics.
  • jsDelivr — delivery of a small JavaScript library used for interface behaviour. Receives your IP address as part of serving that file.

Only if you choose to enable them

  • Anthropic — AI receipt scanning. Only used if you turn the feature on and supply your own API key. See section 7, which explains this one in detail.
  • Your own Stripe or PayPal account — if you connect one so your clients can pay your invoices online. Those are your merchant accounts, under your agreement with the provider; we pass the payment through and record the result.
  • Microsoft 365 — if you choose to send your invoice emails through your own Microsoft account instead of ours.
  • Your own mail server — if you configure your own SMTP settings, your outgoing invoice emails go through your provider rather than ours.
  • Push notification services (Google, Mozilla or Apple, depending on your browser) — only if you switch on browser notifications. They receive an anonymous device token, not your identity or the content of the notification.

Several of these providers are based overseas, primarily in the United States, which means some information is processed outside Australia. We choose established providers with published privacy commitments, and we share only what each one needs to do its job.

We may also disclose information if we're legally required to — a court order, for example — or where it's necessary to protect someone's safety or our legal rights. We would tell you if that happened, unless we were legally prevented from doing so.

5. Payments and card details

Your card number never reaches our servers. When you subscribe, you're taken to a payment page hosted by Stripe, and your card details go directly to them. We receive back only a customer reference, the last four digits, the card brand and the expiry date — enough to show you what you're being billed on and to take the next renewal, and not enough to make a payment anywhere else.

The same is true in reverse when your own clients pay one of your invoices online: their card details go to Stripe or PayPal under your merchant account, not to us. We record that the invoice was paid, the amount, and the payment reference.

6. Cookies and analytics

We use a small number of cookies and similar technologies:

  • Essential cookies. A session cookie that keeps you signed in, and a security token that protects forms against cross-site request forgery. The application does not work without these, so they can't be switched off.
  • Preferences. Your light/dark theme choice is stored in your own browser's local storage. It never reaches our servers.
  • Analytics. We use Google Analytics to understand how people find and move through our marketing site — which pages get read, which lead to a signup. This sets cookies in your browser.
  • Bot protection. Cloudflare Turnstile may set a short-lived token when you use our signup or password-reset forms, to confirm you're a person. It's designed to work without tracking you across sites.

What analytics covers, and what it doesn't. Analytics runs on our marketing site and on the signed-out pages of the application — the sign-in and signup screens — so we can see whether people who read the pricing page go on to create an account. Because those are two different domains, we link the two visits together so they count as one journey rather than two strangers.

Analytics does not run once you are signed in. What you do inside your own books is not something we send to a third party. It also does not run on the pages your clients see — the invoice payment pages and the client portal — because those people have no relationship with us and never agreed to anything.

You can block analytics with your browser's privacy settings, a content blocker, or by enabling Do Not Track / Global Privacy Control. Nothing in Webrox stops working if you do.

7. AI receipt scanning

Webrox can read an uploaded receipt and pull out the vendor, date, amount and GST so you don't have to type them. This deserves a section of its own because it involves sending a document to a third party.

  • It is off unless you turn it on. The feature requires you to supply your own Anthropic API key. Until you do, no receipt is ever sent anywhere.
  • Your key, your account. Anthropic bills you directly. Your key is stored encrypted and is used only to process your own receipts.
  • What gets sent: the image or PDF of the receipt you uploaded, and a request to extract those fields from it. If the receipt contains other information, that goes too — so if a document is sensitive, don't scan it.
  • What comes back is the extracted text, which we show you before anything is saved. You can always type expenses in by hand instead.

Anthropic's own privacy terms govern what they do with API requests. At the time of writing, data submitted through their API is not used to train their models — but that is their commitment, not ours, and you should read their current terms if this matters to you.

8. How we protect information

  • Encryption in transit. All traffic to both our sites is over HTTPS.
  • Encryption at rest for credentials. Sensitive stored values — your mail password, payment provider secrets, API keys, two-factor secrets — are encrypted in the database rather than held as readable text.
  • Passwords are hashed, never stored in a readable form.
  • Separation between businesses. Every record belongs to exactly one business, and that boundary is enforced at the database query layer for every request rather than being something each screen has to remember. We audit this specifically and regularly, because it's the single most important property of a system that holds many businesses' books.
  • Two-factor authentication and passkeys are available on every account. We'd encourage using one.
  • Backups are taken so your data can be recovered after a failure.
  • Support access. We can access your account to help you when there's a problem — that access is recorded in your own activity log, so you can see when it happened, and actions that would change your account's security (such as changing your password or your two-factor settings) are blocked during it.

No system is perfectly secure, and we won't pretend otherwise. If a breach occurred that was likely to cause you serious harm, we would notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.

9. How long we keep it

While your account is open, we keep your data so the service works — your records need to be there next time you sign in, and prior years matter for tax.

If you close your account, we keep your data for 3 months before deleting it, so that an accidental or regretted cancellation can be undone. You can ask us to delete it sooner and we will. After that window your records are gone and we cannot get them back for you — so please export before you close the account, not after.

Export your data before you go. You can download everything — clients, invoices, quotes, expenses, and your stored invoice PDFs and receipts — from Settings at any time, without asking us and without a waiting period. We built that deliberately: your records are yours, and Australian tax rules generally require you to keep business records for five years, which is far longer than we hold a closed account.

Some records are kept longer where the law requires it — for example, invoices we issued to you for your subscription, which are our own tax records.

10. Your rights and choices

  • Access. Most of what we hold about you is visible in the app. Ask us for the rest and we'll provide it.
  • Export. Available to you directly, at any time, in CSV and PDF.
  • Correction. You can edit your own details in the app. If something we hold is wrong and you can't fix it yourself, tell us.
  • Deletion. You can ask us to delete your account and its data.
  • Complaints. If you think we've mishandled your information, contact us first — we'd genuinely rather know. If we don't resolve it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

We'll respond to any of these within a reasonable time, and we won't charge you for making a request. We may need to verify who you are first, particularly for deletion — which is itself a protection for you.

11. Marketing

If we send you anything promotional, every message will have a working unsubscribe link and we'll honour it. Service messages about your own account — a failed payment, a password reset, a security notice — are separate, and will keep coming while your account exists, because they're how we reach you when something needs attention.

12. Children

Webrox is business software and isn't directed at children. We don't knowingly collect information from anyone under 16. If you believe we have, contact us and we'll delete it.

13. Other sites

Our sites link to places we don't control — Stripe's payment pages, for example, or a provider's documentation. Their privacy practices are their own, and this policy doesn't cover them.

14. Changes to this policy

We'll update this page when our practices change, and the "last updated" date at the top will change with it. If a change materially affects how we handle your information, we'll tell you directly rather than relying on you noticing.

15. Contact us

Questions, requests or complaints about privacy — including access, correction or deletion — go to:

hello@webrox.com.au

Webrox — ABN 15 471 468 055 — Brisbane, Queensland, Australia.