Legal
Privacy Policy
Last updated: 25 July 2026
This Privacy Policy explains how VendorAlert Pty Ltd (ABN 37 698 613 268) — which operates VendorAlert (the “Service”; “we”, “us” or “our”) — collects, uses, discloses and protects personal information. VendorAlert connects to Xero to monitor contact details and alert the people you choose when they change.
We serve customers using Xero around the world. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, where it applies, the EU and UK General Data Protection Regulation (GDPR). If you are in the EEA or UK, please also read the EU/UK addendum at the end of this policy.
1. Who this policy covers
This policy applies to people who visit our website, create a VendorAlert account, or are invited as users of an organisation (our “customers” and “users”). It also covers personal information contained in the Xero data we access on a customer’s behalf - for example, the names and contact details of a customer’s Xero contacts. Where we process contact data on behalf of a customer, the customer is the controller of that data and we act as a processor following their instructions.
2. Information we collect
Information you provide
- Account and identity data - your name, email address, Xero identity information, account role and the organisation you represent.
- Configuration data - the organisations you connect, the people you authorise to use VendorAlert, and the names and email addresses of alert recipients you configure.
- Communications - the contents of messages you send us, including support requests.
- Billing data - Stripe customer and subscription identifiers, plan status, billing events and related transaction records. Card and payment details are collected and processed directly by Stripe; we do not store full card numbers.
Account identity, organisation and applicable billing information are required to create and provide a paid account. If you do not provide them, we may be unable to provide the Service. Alert-recipient choices are optional, and analytics remains optional.
Information from your Xero organisation
With your authorisation and using read-only access, we read contact and organisation records from your connected Xero organisation. This can include organisation name, country, timezone and currency; contact names, email addresses and Xero identifiers; bank account names, account numbers, BSB/sort/routing codes, payment references and currency; Xero user names, email addresses and roles; and available history identifying who changed a contact. We also keep records of detected changes and alerts. We do not collect more Xero data than is needed to provide, secure and support the monitoring and alerting Service.
Information collected automatically
- Technical and usage data - IP address, browser and device information, the time and IP address of the most recent sign-in, pages viewed, actions taken, sync and security logs, and diagnostic and error information.
- Cookies and similar technologies - strictly necessary cookies to keep you signed in and secure your session, and, only with your consent, analytics cookies (such as Google Analytics) that help us understand how the Service is used.
3. How we use information
We use personal information to:
- provide, operate and maintain the Service, including syncing with Xero and detecting changes to contact details;
- send the alerts and notifications you have configured;
- create and manage your account and authenticate users;
- process payments and manage subscriptions;
- respond to your enquiries and provide support;
- monitor, secure, troubleshoot and improve the Service;
- send service-related messages and, where permitted, product updates (you can opt out of marketing at any time); and
- comply with our legal obligations and enforce our terms.
4. Legal bases for processing
Where the GDPR applies and we act as controller, we process account, configuration and billing data as necessary to enter into and perform our contract with you. We rely on our legitimate interests to secure the Service, prevent fraud, maintain audit records, troubleshoot faults, improve reliability, provide support and send relevant service communications. We consider and balance those interests against your rights. We rely on consent for Google Analytics cookies and consent-based marketing, and on legal obligations for records and disclosures the law requires.
Where we process Xero contact, user and alert-recipient data on a customer's behalf, the customer determines the applicable legal basis and we process that data under the customer's instructions and our Data Processing Addendum.
5. How we share information
We do not sell your personal information. We share it only as needed to run the Service:
- Service providers - Vercel (hosting), Supabase (database and authentication), Inngest (background processing), Resend (email delivery), Sentry (error monitoring) and Google Analytics (consented marketing-site analytics). They process data for us under contractual and confidentiality obligations.
- Xero - we connect to Xero’s API to read your data; our access is governed by the authorisation you grant.
- Stripe - to process and administer subscription payments.
- Professional advisers and authorities - where reasonably necessary to obtain advice, comply with the law, respond to a lawful request, or protect our rights, users or the public.
- Business transfers - if we are involved in a merger, acquisition or sale of assets, information may be transferred as part of that transaction, subject to this policy.
6. International data transfers
We and our service providers may store and process personal information in countries other than the one in which you are located, including Australia, New Zealand, the United States and countries in the European Economic Area. Some providers operate global networks, so limited technical data may also be processed where their support and infrastructure teams operate. Our current providers and likely locations are listed in our Data Processing Addendum.
Before disclosing personal information overseas, we take reasonable steps to require appropriate protection. Where the GDPR applies, we use an adequacy decision or approved safeguards such as the European Commission's standard contractual clauses and, for UK transfers, the UK Addendum or International Data Transfer Agreement. You may ask us for information about the safeguard that applies to a transfer.
7. Data retention
We keep personal information for as long as your account is active and as needed to provide the Service.
When you disconnect a Xero organisation, we stop monitoring it immediately and permanently delete the data we hold for that organisation - its contacts, financial details and alert history - within 90 days, unless an authorised Xero user reconnects it or claims administration beforehand. Residual copies in our encrypted backups are removed as those backups expire.
Operational sync logs are kept for up to 90 days. Account and identity information is kept while the account is active. Security and audit records are kept for as long as reasonably needed to protect the Service, investigate misuse and establish, exercise or defend legal claims. Error-monitoring events are generally kept for up to 90 days. If analytics is enabled with your consent, Google Analytics data is configured for a 14-month retention period.
We keep billing and tax records for the period required by law, generally up to 7 years. Account closure and individual erasure requests are currently handled through support. After verifying the request and any authority needed to act for an organisation, we delete or de-identify associated data subject to the 90-day organisation deletion window and any limited records we must retain for tax, security, dispute or legal-compliance purposes.
8. Security
We use technical and organisational measures designed to protect personal information, including encryption of Xero access tokens, least-privilege access controls and read-only access to your Xero data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to respond appropriately to any incident.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, update, delete, or obtain a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. You can update much of your account information directly in the Service or by contacting us. You can opt out of marketing emails using the unsubscribe link or by contacting us.
Because we often process contact data on behalf of a customer (as a processor), if your information reached us through a customer’s Xero organisation, we may direct your request to that customer, who is the controller of that data.
To exercise a right, email us at hello@vendoralert.com.au. We will respond within the timeframe required by applicable law. If you are not satisfied, you may lodge a complaint with your local data protection authority - in Australia, the Office of the Australian Information Commissioner (OAIC).
10. Cookies
We use two categories of cookies:
- Strictly necessary cookies - always on. These keep you signed in, remember your selected organisation, protect the Xero connection flow and remember your cookie choice. They do not require consent and cannot be switched off through the cookie banner.
- Analytics cookies - set only with your consent. We use Google Analytics to understand how the Service is used so we can improve it. These cookies are not loaded until you accept them.
When you first visit, we show a cookie banner where you can accept or decline analytics cookies; strictly necessary cookies are unaffected by your choice. If you decline, no analytics cookies are set. You can change or withdraw your choice at any time using the “Cookie preferences” link in the footer, or through your browser settings. We do not use advertising or cross-site tracking cookies.
Google Analytics is provided by Google, which may process the resulting data (including in the United States) under its own terms. See Google’s privacy and cookie policies for more information.
Cookies we use
- Supabase authentication cookies - first-party, strictly necessary session cookies used to authenticate you and refresh your session. They expire with the session or according to the authentication session lifetime.
- current_org_id - first-party, strictly necessary; remembers the organisation you selected for up to 1 year.
- xero_oauth_state and connection-result cookies - first-party, strictly necessary security and flow-completion cookies that expire after approximately 5 minutes.
- va_cookie_consent - first-party, strictly necessary; remembers whether you accepted or declined analytics for up to 1 year.
- _ga and _ga_<container-id> - Google Analytics cookies used only after consent to distinguish visits and produce usage statistics; normally expire after up to 2 years. Google may also set _gid, which normally expires after 24 hours.
11. Children
The Service is intended for business use and is not directed to children under 18. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and notify account holders by email or through the Service where appropriate. The updated policy applies from the stated effective date. We will request fresh consent where a change affects processing that relies on consent.
13. EU/UK addendum
If you are in the European Economic Area or the United Kingdom, the following additional information applies. The data controller for personal information collected directly by us is VendorAlert Pty Ltd; where we process contact data on behalf of a customer, that customer is the controller and we act as their processor.
In addition to the rights described above, you have the right to data portability and the right to lodge a complaint with your supervisory authority. We rely on the legal bases set out in Section 4, and where we transfer personal data outside the EEA or UK we use appropriate safeguards such as the European Commission’s standard contractual clauses (and the UK Addendum or International Data Transfer Agreement, as applicable). You can contact us about any of these matters at hello@vendoralert.com.au.
VendorAlert is established in Australia and does not currently have an establishment in the EEA or UK. We periodically assess whether an EU or UK representative must be appointed, including as our customer base changes, and will publish representative details here if required. We do not use solely automated decision-making that produces legal or similarly significant effects about individuals.
14. Privacy complaints and contact
If you have a question, wish to exercise a right, or believe we have breached an applicable privacy law, email hello@vendoralert.com.au. Please describe the issue and provide enough information for us to identify you and the relevant account or organisation.
We will acknowledge a privacy complaint, verify identity and authority where appropriate, investigate it, and provide an outcome and any remedial steps within a reasonable period. We aim to respond within 30 days, although complex matters may take longer and we will tell you if that happens. If you are dissatisfied, you may ask us to reconsider the outcome and then complain to the Office of the Australian Information Commissioner or, where applicable, your local data protection authority.