Privacy Policy
Last updated: 14 July 2026
This policy explains how The Startup Nerds Pty Ltd ("we", "us") handles personal information in operating GalaxyCFO, consistent with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What we collect
Account information (name, email, sign-in records); business financial data you provide or authorise us to retrieve from your accounting platform (such as Xero) — accounts, invoices, bills, bank transactions and balances, payroll summaries and contacts; billing details handled by Stripe (we never see full card numbers); support requests and feedback, including screenshots you choose to attach; and standard technical logs.
How we use it
To provide the Service: building forecasts, reconciling balances, generating insights and answering the questions you ask the in-app assistant. We use AI subprocessors to process financial extracts for features you actively use; employee names and personal payroll details are masked from AI processing and from default screens — employee-level detail is only visible behind the PIN the account owner sets. We also use aggregate, de-identified usage data to improve the product. We do not sell personal information, and we do not use your business data to train AI models.
Where it lives
Data is hosted with Supabase (PostgreSQL and file storage) and our application runs on Vercel, with processing regions selected for proximity to Australia where available. Third-party processors we rely on include Xero (with your authorisation), Stripe (billing), Supabase and Vercel (hosting) and Anthropic (AI features). Each processor only receives what it needs for its function.
Xero connection
Connecting Xero uses Xero's OAuth consent — we never see your Xero password. We access only the scopes shown on the consent screen, refresh data on a schedule or when you press Sync, and you can disconnect at any time from your entity settings or from within Xero. Disconnecting stops all future access.
Security
Data is encrypted in transit and at rest, access is role-restricted per workspace, employee payroll detail sits behind an additional PIN, and access to employee data is logged. No system is perfectly secure; if a breach is likely to result in serious harm we will notify affected users and the OAIC as required by the Notifiable Data Breaches scheme.
Retention and deletion
We keep your data while your account is active. If a subscription lapses your data is retained so you can return; if you delete an entity, or close your account, associated data is deleted within 90 days except where law requires longer retention. You can request a copy or correction of your personal information at any time.
Contact
Privacy questions or complaints: hello@galaxycfo.com. If you are unsatisfied with our response you can contact the Office of the Australian Information Commissioner (oaic.gov.au).