This document is a draft.

It was written from what the application actually does, but the operator’s details and contact address have not been filled in, and it has not been reviewed by a lawyer. Do not rely on it yet.

Privacy Policy

The short version

  • Only what the service needs: your email address, a hash of your password, and the accounting records you enter.
  • Nothing is sold, and nothing is shared for advertising.
  • There are no analytics, no tracking pixels and no third-party advertising cookies. None. Fonts are served from this site rather than from Google, so loading a page tells no one else that you did.
  • Your books include other people’s details — clients you invoice, suppliers you buy from. You are responsible for those, and CASHew holds them on your behalf.
  • Your bank account details are stored so they can be printed on your invoices. They are stored as you typed them, not encrypted separately from everything else.

What is collected, and why

When you create an account

  • Email address — to identify the account, confirm it is yours, and send password resets.
  • Password — stored only as a one-way hash. It cannot be read back, by us or by anyone with access to the database.

What you enter

  • Your business details — trading name, address, ABN, and the bank account name, bank, BSB and account number that appear on your invoices.
  • Invoices — including your clients’ names and email addresses, the items billed and the payments you record.
  • Expenses and suppliers — amounts, dates, categories, and any supplier names, contacts, email addresses and postal addresses you add.
  • Receipts — any images or PDFs you attach to an expense.

Some of this is other people’s personal information. You decide what to record about your clients and suppliers; CASHew stores it for you and does nothing else with it.

Automatically

The hosting provider records ordinary web server logs — IP address, timestamp, and which page was requested — as part of serving the site and defending it from abuse. The mail provider records whether a message it sent was delivered.

Cookies

  • A session cookie, set when you sign in. It keeps you signed in for seven days, is marked HttpOnly and Secure so scripts cannot read it, and is confined to this site.
  • A sidebar preference, remembering whether you collapsed the navigation.

That is the complete list. There are no others.

Who else sees it

Personal information is not sold, rented, or disclosed for marketing. These providers process it in order to run the service:

  • Supabase — the database and the receipt storage, hosted in Sydney, Australia. Everything you enter lives here.
  • Vercel — hosting. Application servers are pinned to Sydney; the content delivery network that serves scripts and images is global, and sees the requests that pass through it.
  • Resend — transactional email, operated from the United States. It receives your email address and the confirmation or password-reset message being sent. It never receives your accounting records.

Sending an account email therefore involves an overseas provider. Your books stay in Australia.

How long it is kept

Your records are kept until you ask for them to be deleted. Australian tax law generally requires a business to keep its records for five years, so deleting your account here does not discharge that obligation — export what you need first.

Web server logs are kept on the hosting provider’s own schedule. Deleted records are removed from the live service immediately; encrypted backups age out under the database provider’s retention schedule.

Seeing it, correcting it, deleting it

Everything held about you is visible in the application, and you can change any of it yourself.

Getting a copy: the Reports page exports every invoice and every expense line as CSV, and each financial statement exports as CSV or PDF.

Deleting your account: there is no self-service button for this yet. Ask at the address below and the account and everything in it will be removed. Saying so plainly is more useful than implying a control that does not exist.

Keeping it safe

  • Every query is scoped to your account, so one account cannot read another’s records.
  • Receipts are held in private storage. Links to them are created on demand and expire within a minute, so a copied link stops working almost immediately.
  • Passwords are hashed, never stored in a readable form.
  • Traffic is encrypted in transit; the database is encrypted at rest.

No service can promise perfect security, and this one is operated by a very small team. Your bank details in particular are stored so they can be printed on invoices — they are protected like everything else, but they are not held to a payment-processor standard, and you should decide with that in mind.

Children

CASHew is for running a business and is not intended for anyone under 16. Nothing here asks for or verifies an age.

Complaints

Write to privacy@example.com. If a complaint is not resolved to your satisfaction, it can be escalated to the Office of the Australian Information Commissioner.

Changes

Changes are published on this page and the date at the foot is updated. Anything that materially changes what is collected or who sees it will be notified by email before it takes effect.