Who we are
Invoices Solutions (“we”, “us”, “our”) operates Invoices Solutions, a business application for capturing purchases, sales and field records and syncing them with accounting systems such as MYOB AccountRight. This policy explains what we collect, why we collect it, who we share it with, and the choices you have.
It applies to invoicessolutions.com, the Invoices Solutions web application, the field app, and our supporting APIs. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
If you use Invoices Solutions as part of an organisation, that organisation controls its own records inside the product and its own privacy practices apply to them alongside ours.
Information we collect
We collect only what the product needs to do its job:
- Account information — your name, email address, a securely hashed password, multi-factor authentication settings, the organisation and businesses you belong to, and the role and rights assigned to you.
- Business records you create — purchases, sales, payments, contacts, suppliers, categories, tax rates, sites, jobs and the receipts, invoices and photos you upload.
- Connected account data — information we read from systems you deliberately connect, such as MYOB AccountRight company files and read-only mailbox connections. See Email intake below.
- Technical and security data — sign-in events, IP address, browser user agent, and an audit trail of significant actions taken in your organisation, kept so account holders can see who changed what.
- Correspondence — messages you send us for support, demos or billing.
We do not run advertising, cross-site tracking or third-party marketing analytics on the product. We may use an error-monitoring service to record technical diagnostics when something breaks.
Email intake and Google user data
Invoices Solutions can watch a mailbox you connect and turn supplier invoices that arrive there into draft purchase records. Connecting a mailbox is always optional, always initiated by an authorised user of your organisation, and always read-only.
Google accounts. When you connect a Gmail mailbox we request only these scopes:
https://www.googleapis.com/auth/gmail.readonly— read-only access to the messages and attachments in the connected mailbox, so we can find invoices and download their attachments.openidandemail— to confirm which mailbox was connected and keep that connection stable.
Microsoft accounts. The equivalent Microsoft 365 connection uses the delegated permissions Mail.Read, Mail.Read.Shared (only for a shared mailbox you explicitly select) and User.Read.
We do not request, and our systems reject at the point of authorisation, any permission that could send, modify, label, delete or move mail, or that could read your directory or manage your account. If a provider ever returns a broader permission than we asked for, the connection is refused.
What we do with mailbox data. We poll the inbox on a schedule and, for each new message, store an encrypted record of the sender, subject, received time and provider message id. A lightweight classifier decides whether the message looks like a supplier invoice or receipt. Only for messages that pass that check do we download attachments and read the message body, and only to extract invoice fields such as supplier, date, line items, totals and GST. Attachments are virus-scanned before they are stored in private object storage, and the resulting draft appears in your review queue.
What we never do. We do not store full message bodies, do not read messages outside the connected mailbox’s inbox, do not use mailbox data for advertising or profiling, do not sell it, and do not use it to train generative AI or machine-learning models — ours or anyone else’s.
Google API Services User Data Policy
Invoices Solutions’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect a mailbox at any time from the business settings screen, which immediately erases the stored access and refresh tokens and stops all polling. You can also revoke our access directly at myaccount.google.com/permissions for Google, or myapps.microsoft.com for Microsoft.
Accounting connections
When you connect MYOB AccountRight, we read and write only the records needed to keep your purchases, sales, payments, contacts, accounts and tax codes in step with the company file you select. Access is granted by you through the provider’s own consent screen, tokens are encrypted at rest, and you can disconnect at any time from the business settings screen.
AI-assisted extraction
Reading a receipt, invoice or email and turning it into a draft record uses third-party AI models, accessed through OpenRouter. The content of the document, and where relevant the email body, is sent to the model for the sole purpose of returning structured fields back to you.
Every one of those requests is sent with data collection denied and zero-data-retention required, so providers are not permitted to retain the content or use it to train models. Extraction results are always presented to you as a draft to review before anything is saved or posted to your accounting system.
How we use information
- To provide the product: authenticate you, show your organisation's records, extract invoice data, and sync with the accounting system you connect.
- To keep the product secure: detect abuse, investigate incidents, and maintain the audit trail your organisation relies on.
- To support you: answer questions, diagnose faults, and notify you about service issues or material changes.
- To meet legal and tax obligations that apply to us.
Overseas disclosure
We host your data in Australia. Some providers listed above — in particular AI model providers, Google and Microsoft — may process data in the United States or other countries. Where that happens we take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles.
How we protect information
- All traffic to and from the product is encrypted in transit with TLS.
- Mailbox access tokens, refresh tokens, mailbox addresses, message senders, subjects and attachment filenames are encrypted at rest with application-level encryption, on top of the encryption provided by our database and storage hosts.
- Every attachment is scanned by an authenticated malware scanner before it is stored, and rejected if it fails, exceeds size limits, or cannot be scanned.
- Access inside your organisation is governed by roles and rights, so people see only the businesses and functions assigned to them. Multi-factor authentication is supported and can be enforced.
- Significant actions are recorded in an audit trail with the actor, time and target.
- We request the narrowest permission a provider offers — read-only in every case where reading is all we need.
Retention and deletion
We keep your organisation’s records for as long as the account is active, and for as long afterwards as is needed to meet legal, tax and accounting obligations — which for financial records in Australia is generally five to seven years.
Disconnecting a mailbox immediately deletes its stored tokens and sync position. Deleting a document, purchase or file removes it from the product. To request deletion of your account and associated personal information, email hello@invoicessolutions.com; we will action verified requests within 30 days, except where we are required to retain specific records.
Your rights and choices
You may ask us to access or correct the personal information we hold about you, ask how it has been used, or ask us to delete it. Email hello@invoicessolutions.com and we will verify your identity before acting.
If you are unhappy with how we have handled your information, contact us first so we can try to resolve it. You can also complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
We may update this policy as the product changes. The effective date at the top of this page always reflects the current version, and we will give notice in the product before a change that materially reduces the protection of information we already hold.
Contact us
Questions, requests or privacy complaints: hello@invoicessolutions.com. We aim to respond within five business days.