SpendLeak

⚠ Draft — pending professional legal review

This Privacy Policy is a substantive draft. It has not yet been reviewed by a qualified Australian privacy solicitor. It represents our intent to comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). We will update this page once professional review is complete.

Privacy Policy

Effective date: 23 May 2026

1. About this policy

SpendLeak (“we”, “us”, “our”) is committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what information we collect, why we collect it, how we use it, and your rights in relation to it.

This policy applies to SpendLeak's web application at spendleak.com and any related services. By creating an account or using our service you agree to this policy.

2. What information we collect

Account information

When you create an account we collect your email address and any name you provide.

Transaction data

To provide the core service, we process financial transaction records you supply. This includes CSV files you upload, or transaction data retrieved via integrations (e.g. MYOB Business). Transaction data includes dates, amounts, vendor names, and descriptions as they appear in your bank or accounting records.

Integration credentials

If you connect a third-party accounting integration (e.g. MYOB), we store OAuth access tokens necessary to retrieve data on your behalf. These tokens are encrypted at rest using AES-256 encryption.

Usage data

We collect standard server-side logs (IP address, browser type, pages visited, timestamps) for security and operational purposes. We do not currently use third-party analytics trackers.

Contact enquiries

If you contact us via our contact form or by email, we retain the content of that correspondence to respond to you and for our own records.

3. Why we collect it — purposes

We collect and use personal information only for the purposes for which it was provided or for directly related purposes, including:

  • Creating and managing your account
  • Providing the spend analysis and findings service
  • Sending transactional emails (e.g. email verification, monthly report summaries)
  • Responding to your support or contact enquiries
  • Security monitoring and fraud prevention
  • Improving and developing the product (using aggregated, de-identified data only)
  • Meeting our legal obligations

We do not use your transaction data to train machine learning models or sell it to any third party. We do not use your personal information for direct marketing without your explicit consent.

4. How we share your information

We do not sell your personal information. We disclose it only in the following circumstances:

Sub-processors

We use the following third-party services to operate SpendLeak. Each is bound by its own privacy obligations:

ProviderPurposeData location
SupabaseDatabase, authenticationAWS ap-southeast-2 (Sydney)
VercelWeb hostingGlobal CDN (edge functions in Sydney region where possible)
ResendTransactional emailUnited States (email transmission only)

Legal requirements

We may disclose your information if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect the rights, property, or safety of SpendLeak, our users, or the public.

Business transfer

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring party. We will notify you by email prior to any such transfer.

5. Data security

We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Specific measures include:

  • All data encrypted at rest using AES-256 (managed by Supabase)
  • All data transmitted over TLS (HTTPS only)
  • Row-level security policies ensuring each tenant can only access their own data
  • OAuth tokens for third-party integrations stored in encrypted form

For more detail, see our Security page.

6. Data retention

We retain your personal information for as long as your account is active, or as needed to provide services. When you close your account, we will delete or de-identify your personal information within 30 days, except where we are required to retain it to comply with our legal obligations, resolve disputes, or enforce our agreements.

Transaction records you upload remain associated with your account until you delete them or close your account.

7. Your rights (APP 12 & 13)

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Correct personal information that is inaccurate, out of date, incomplete, or misleading
  • Request deletion of your personal information (subject to legal obligations to retain certain records)
  • Make a complaint about how we handle your personal information

To exercise any of these rights, contact us at privacy@spendleak.com. We will respond within 30 days.

8. Cookies

SpendLeak uses session cookies to maintain your authenticated session. These are strictly necessary for the service to function and cannot be disabled. We do not use tracking cookies or third-party advertising cookies.

9. Cross-border transfers

Resend, our email delivery provider, processes email transmission data in the United States. We have contractual arrangements in place with Resend that require them to handle personal information in accordance with the APPs. No other significant cross-border transfers of personal data occur.

10. Complaints

If you have a complaint about how we handle your personal information, please contact us at privacy@spendleak.com. We will acknowledge your complaint within 5 business days and attempt to resolve it within 30 days.

If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC).

11. Changes to this policy

We may update this policy from time to time. We will notify registered users by email of any material changes at least 14 days before they take effect. The effective date at the top of this page will always reflect the current version.

12. Contact us

For any privacy enquiries, contact us at: privacy@spendleak.com

Governing law: New South Wales, Australia.