This Privacy Policy explains how Friarun Pty. Ltd. (“we”, “us”, “our”), trading as InvoiceDeX, collects, uses, discloses, and protects personal information in connection with the InvoiceDeX platform and websites (including https://invoicedex.ai and related subdomains).
We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), where applicable, and other laws that apply to us.
1. Who we are
Legal entity: Friarun Pty. Ltd.
Product brand: InvoiceDeX
Privacy / support: [email protected]
Security: [email protected]
2. What we collect
Depending on how you use the Service, we may collect:
2.1 Account and identity
- Name, email address, phone number, username
- Business details (company name, ABN, store addresses)
- Authentication data (password hashes, passkeys/WebAuthn credentials, session tokens)
- Role and permission assignments within a Customer organisation
2.2 Business and operational content (Customer Data)
- Invoices, statements, purchase orders, and related documents (including PDFs and images)
- Supplier, product, pricing, inventory, and promotional data
- POS-related records, layouts, and configuration
- Store media (images, videos, logos) and schedule settings
- Support tickets, chat messages, and feedback you send us
2.3 Integration data
- Tokens and identifiers for connected services (e.g. accounting, email, Canva OAuth tokens)
- Content you choose to import (e.g. exported Canva designs for store media)
2.4 Technical and usage data
- IP address, device/browser type, approximate location derived from IP
- Log files, diagnostic data, performance metrics
- Cookies and similar technologies for session management and security
We do not intentionally collect government-related identifiers beyond what you provide for business verification (such as ABN) or payment processing via third parties.
3. How we collect information
- Directly from you or your Users when creating accounts, uploading documents, or configuring stores
- Automatically through use of the Service (logs, cookies, diagnostics)
- From Integrations you connect, as authorised by you
- From service providers that help us operate the platform (hosting, email delivery, payments)
4. Why we use personal information
We use personal information to:
- Provide, maintain, and secure the Service
- Authenticate Users and manage multi-tenant access controls
- Process invoices, documents, and operational workflows you request (including OCR/AI features)
- Enable Integrations and store media / POS features you configure
- Bill subscriptions, send service notices, and provide support
- Detect abuse, fraud, and security incidents
- Improve product quality and reliability (including aggregated analytics)
- Comply with legal obligations
5. AI and document processing
Document extraction and related AI features process Customer Data to return structured results to your account. We use subprocessors and model providers as needed to deliver those features. We do not sell Customer Data. Where model providers process content, we do so under contractual arrangements and only for providing the Service.
6. Canva and other integrations
If you connect Canva (or other Integrations), we receive OAuth tokens and only the data needed for the features you use (for example listing designs and importing exports into Store Media). Tokens are stored on our backend for your company tenant. You can disconnect at any time in InvoiceDeX; we then stop new access and delete or invalidate tokens as described below.
7. Disclosure of personal information
We may disclose personal information to:
- Service providers who host infrastructure, email, payments, monitoring, or AI processing under contract;
- Integration partners you explicitly connect;
- Professional advisers (legal, accounting) under confidentiality;
- Authorities when required by law or to protect rights, safety, or security;
- Successors in a merger or business transfer, with appropriate notice where required.
We do not sell personal information.
8. Overseas disclosure
Some service providers or cloud infrastructure may process data outside Australia. Where we disclose personal information overseas, we take reasonable steps to ensure recipients handle it in a way that is consistent with the APPs, including contractual safeguards where appropriate.
9. Storage and security
- Data is hosted on secured cloud and/or dedicated production servers controlled by us.
- Access is restricted by authentication, company tenancy isolation, and role-based permissions.
- We use encryption in transit (TLS) and industry-standard protections for secrets and credentials.
- No method of transmission or storage is 100% secure; please protect account credentials and report issues promptly.
10. Retention
- Account and Customer Data are retained while your organisation uses the Service and as needed for backups, dispute resolution, and legal compliance.
- OAuth access and refresh tokens for Integrations are retained while the connection is active. After disconnect, we revoke/delete tokens and do not keep them longer than 30 days except where required for security logs or law.
- Media and documents you upload remain until you delete them or your account is closed, subject to backup cycles.
11. Cookies
We use essential cookies for login sessions, security (including CSRF protection), and load balancing. You can control cookies in your browser; disabling essential cookies may prevent login.
12. Your rights and choices
Subject to the Privacy Act and exceptions, you may request to:
- Access personal information we hold about you
- Correct inaccurate information
- Ask questions about our handling of personal information
- Withdraw consent where processing is based on consent (this may limit features)
Contact [email protected]. We may need to verify your identity. If you are a User of a Customer organisation, some requests may need to go through your company administrator.
13. Children
The Service is directed to businesses and authorised adult Users. We do not knowingly collect personal information from children under 16 for marketing the Service.
14. Security contact
To report a security vulnerability or concern, email [email protected] (or [email protected] with subject “Security”).
15. Changes to this Policy
We may update this Privacy Policy by posting a revised version on this page and updating the Effective date. Material changes will be communicated where reasonable.
16. Complaints
If you have a privacy complaint, contact us first at [email protected]. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
17. Contact
Friarun Pty. Ltd. trading as InvoiceDeX
[email protected] ·
https://invoicedex.ai