Privacy Policy

Effective 13 August 2026 · Terms of Service

PayVoy is invoicing and payment-request software for Australian small businesses. This policy explains what information we hold, why we hold it, who else touches it, and what you can ask us to do with it.

It is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

The short version. Your business data and your customers' details are stored in Sydney, Australia. We never see or store your customers' full card numbers. Card payments happen at your own payment gateway, and your money settles into your own gateway account without passing through us. We don't sell anything to anyone, and the marketing site you came from sets no cookies and runs no analytics.

1. Who we are

PayVoy is operated by [LEGAL ENTITY NAME], ABN [ABN] ("PayVoy", "we", "us"), of [POSTAL ADDRESS]. You can reach us at support@payvoy.com.au.

2. Two different groups of people

This matters, because our obligations differ:

3. What we collect

From merchants

About your customers, entered by you

Technical information

4. Card details, and what we never hold

This is the part most people want to know, so it gets its own section.

Your customers' card numbers never reach PayVoy. When a customer opens a payment link, the card is captured by your payment gateway's own hosted payment page. We receive back only the outcome: approved or declined, the amount, and the gateway's transaction reference.

If your customer chooses to save a card for future charges, we store a token issued by your gateway, plus the card brand, the last four digits, and the expiry month and year, so you and they can tell which card it is. We also keep the exact wording they agreed to and when, so a disputed charge has an answer. We never store the full card number, and the token is useless to anyone else: only that gateway, for your merchant account, can turn it back into a charge.

Your money does not pass through us. Funds settle from your gateway directly into your own bank account. We are not a payment processor and never hold your money.

5. Why we use it

We do not sell personal information, and we do not use your customers' details for our own marketing.

6. Who else touches it

We use a small number of service providers. Each is bound to handle the information only for the purpose we engage them for.

ProviderWhat forWhere
SupabaseDatabase, authentication, encrypted secrets vaultSydney, Australia
VercelApplication hosting and server functionsSydney region; global edge network
Your payment gateway
(eWAY, Global Payments ANZ, Ezidebit or similar)
Taking card payments and direct debits. You choose and connect it; your contract with them applies to the payment itselfAustralia
ResendSending invoice, receipt and reminder emailsUnited States
ClickSendSending SMS, where you use that featureAustralia

We may also disclose information where the law requires it, or to protect someone's safety or our legal rights.

7. Where it is stored, and overseas disclosure

The database holding your business data and your customers' details is hosted in Sydney, Australia.

Three exceptions, stated plainly: email delivery goes through a provider in the United States, so the contents of an invoice email are processed there in order to be sent, and that includes your customer's name, email address and the invoice itself. Our hosting provider operates a global network, so a request may be routed through infrastructure outside Australia even though the data at rest stays in Sydney. And mail you send to us at an @payvoy.com.au address passes through a forwarding service outside Australia on its way to our inbox, so anything you put in an email to us goes with it.

By using PayVoy you consent to these disclosures. Where APP 8 applies, we take reasonable steps to ensure overseas recipients handle the information consistently with the APPs.

8. How long we keep it, and deleting it

You can delete a customer from within the app at any time. When you do, we remove their email address and phone number, and remove their name where we can.

We cannot remove everything, and here is why. A tax invoice for $1,000 or more must identify the recipient in order to be a valid tax invoice, and you are required to keep those records for five years. So for invoices of $1,000 or more, the customer's name stays on the invoice record. For invoices under $1,000, the name is removed too, and the invoice then shows the buyer as "(details removed)". That reads as a record somebody asked to be removed from, rather than one that looks as though it was never filled in.

The activity log is the other thing that stays. It records what happened in your workspace and when (an invoice was sent, a payment was recorded, a client was deleted), along with which of your team members did it. It does not record your customers' contact details, and a deletion does not erase the log entries themselves: the fact that you sent an invoice on a particular day is a record of your own business activity. One caveat we would rather state than have you discover: when you record a payment or a refund by hand, the reference you type is written into that log entry, and the field suggests the name the money came in under as one thing you might put there. If you would rather a customer's name stayed out of the log, use the receipt number instead.

If you close your account, we close the workspace and stop using it. What we do not do is delete the invoices and payment records inside it, and we would rather explain that than write a promise the system will not keep: the database refuses to delete a business that holds invoices, payments or refunds, because those are the records the ATO requires to be kept for five years and deleting them would breach that as surely as keeping them too long would breach the Privacy Act. Personal details we are not required to hold are removed on the same basis as a deleted customer, described above. Anything with no financial records in it is deleted outright. Tell us if you want it handled sooner, and backups age out on their own cycle.

9. Security

No system is perfectly secure, and we won't claim otherwise. We do not currently hold a formal certification such as ISO 27001 or SOC 2, and we will not imply that we do.

10. If something goes wrong

If a data breach occurs that is likely to cause serious harm, we will notify the affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. If the breach affects your customers, we will tell you promptly so you can meet your own obligations.

11. Accessing and correcting your information

Most of it is in front of you: you can view, edit and export your invoices, clients and payment records from within the app at any time. If you want a copy of anything you can't reach yourself, or you think something we hold is wrong, contact us at support@payvoy.com.au. We will respond within a reasonable time, and we will not charge you for asking.

12. Cookies and tracking

The marketing site at payvoy.com.au sets no cookies, runs no JavaScript, and includes no analytics or advertising trackers. Nothing is loaded from a third party.

The application at app.payvoy.com.au uses browser storage for your sign-in session and a few display preferences. It sets no advertising or cross-site tracking cookies.

13. Complaints

If you think we have mishandled your information, tell us first at support@payvoy.com.au. We would rather fix it than argue about it. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

14. Changes to this policy

If we change this policy in a way that materially affects you, we will tell you by email or in the app before it takes effect. The date at the top always shows the current version.

15. Contact

[LEGAL ENTITY NAME] · ABN [ABN]
[POSTAL ADDRESS]
support@payvoy.com.au