Privacy Policy
1. What we collect
Account. When you sign in with Google or Microsoft we receive your name, email address and a sign-in identifier from that provider. We do not receive your password.
Orders. The Xero organisation you connect (its name and identifier), the size estimate, the quote, when and from which address you accepted the terms, payment status, build progress, the checksums and size of the delivered archive, and when download links were issued. This record is kept after the order closes so we can show you what was delivered and answer questions about it; it contains no copy of your accounting data.
Your Xero data. With your authorisation we read your Xero organisation through Xero's API: transactions, contacts, attachments, reports, settings and, where present, payroll. This is the data the archive is made of.
Operational logs. Our servers keep ordinary logs (timestamps, addresses, actions in the portal) for security and troubleshooting.
2. How we use it
To provide the Service: size the organisation, quote, build and verify the archive, deliver it and support you. To notify you when your order changes state — by email from [email protected], with a link to sign in; those emails never contain figures or download links. To protect the Service against abuse. We do not use your data for advertising or profiling and we do not sell it.
3. Where it is held
Archives are built on infrastructure we operate in Australia. The encrypted, packaged archive is uploaded to Cloudflare R2 object storage for delivery and held there for 90 days from delivery, after which it is deleted automatically. Sign-in is handled by Google Firebase Authentication; email is sent through Google Workspace. Those providers process data under their own policies and may store it outside Australia.
4. Who can see it
Our staff (at present, the operator of the Service) can see your account and order records and, during the build, the working copy of your Xero data on our own systems. The delivered archive is encrypted with a password only you know; once it is packaged nobody at MirrorBeans can open it. We disclose information to third parties only when the law requires it.
5. Payroll and sensitive data
Payroll records contain sensitive information. The archive always redacts tax file numbers, bank account details, dates of birth and home addresses. Our working copy of the data during the build is not redacted; it is held on encrypted storage and deleted with the rest of the working copy when the order closes.
6. How long we keep it
- Your Xero data (working copy): until the order closes — 90 days after delivery, or earlier if the order is cancelled.
- The packaged archive on Cloudflare R2: 90 days from delivery, then deleted automatically.
- Your download password: never stored.
- Account and order records: for as long as your account exists and as required for our own tax and business records (generally seven years).
- Operational logs: a rolling period of a few months.
7. Your choices and rights
You can disconnect MirrorBeans from Xero at any time from Xero's Connected Apps page. You can ask us to close your account and delete your data, subject to our obligation to keep basic transaction records. You can ask what personal information we hold about you and have it corrected. Contact [email protected]; we aim to respond within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner.
8. Cookies
The portal uses one session cookie to keep you signed in. The public website sets no cookies and runs no analytics.
9. Changes
We may update this policy. The version date at the top changes when we do, and material changes are announced in the portal.
10. Contact
EMJ Services Pty Ltd, ABN 16 626 783 551 — [email protected]