1. Who we are and this policy
Audara Pay (“Audara Pay”, “we”, “us”, or “our”) provides non-custodial business software for invoicing, payment instructions, on-chain payment verification, receipts, and reconciliation.
This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) (the “Privacy Act”) and the Australian Privacy Principles (“APPs”). It covers what we collect and why, who we disclose it to, when information may be sent overseas, how long we keep it, how we secure it, and how you can access, correct, or complain about our handling of your information.
We are non-custodial: we do not hold customer or payer funds, manage or have access to private keys, or operate as a custodian of digital assets. We store only public blockchain information (such as public wallet addresses and public transaction data) and the business records you create — we never collect or store private keys, seed phrases, or wallet credentials.
2. Information we collect (APP 3 & 5)
Depending on how you use the service, we may collect:
- Account and business details — such as your name, email address, phone number, business name, ABN, billing address, logo, and role;
- Authentication data — handled through our third-party authentication and wallet provider (Privy), such as your email or login identifier and an associated wallet identifier;
- Customer and invoice data — such as customer names, contact details, invoice line items, amounts, GST, due dates, notes, and payment references you enter;
- Payment instruction data — such as public wallet addresses, preferred network, and displayed payment amounts (we do not collect private keys or seed phrases);
- On-chain transaction records — public blockchain transaction hashes, amounts, timestamps, and network information used for payment verification and reconciliation;
- Usage and technical data — such as log data, device and browser type, IP address, and interactions with the service; and
- Communications — such as support requests and account correspondence.
We generally collect personal information directly from you. Where you enter information about your customers or payers, you are responsible for ensuring you are entitled to provide it to us for these purposes.
3. How and why we use information (APP 6)
We use personal information to:
- provide, operate, and maintain the service;
- authenticate users and protect account security;
- create and display invoices, receipts, and payment instructions;
- read and verify public blockchain data to detect and reconcile payment status;
- generate exports and reconciliation records;
- communicate with you about the service;
- comply with legal obligations and enforce our Terms; and
- improve the reliability, security, and functionality of the service.
We do not use your information to take custody of funds, execute payments on your behalf, or provide financial product advice. We do not sell personal information, and we do not use it for direct marketing without a lawful basis and an opt-out.
4. Disclosure to third parties (APP 6)
We disclose personal information to the service providers we rely on to run the service, under confidentiality and security obligations. These currently include:
- Privy — third-party authentication and embedded (self-custodial) wallet provider;
- Railway — application hosting and infrastructure;
- Neon — managed PostgreSQL database hosting;
- Blockchain RPC and indexing providers — such as Stellar Horizon and Solana RPC providers — used to read public on-chain data for payment verification;
- Xero — where you choose to connect your accounting software, we push your invoices, payments, and customer contact details to your Xero organisation at your instruction;
- professional advisers (such as lawyers or accountants) where reasonably necessary;
- regulators, courts, or law enforcement where required or authorised by law, or to protect rights, safety, and security; and
- a successor entity in connection with a merger, acquisition, or asset sale, subject to this Privacy Policy.
Public invoice and receipt pages may display business and payment-instruction information that you choose to publish to your customers or payers. Public blockchain data is, by its nature, visible to anyone on the relevant network.
[PLACEHOLDER — the list of processors above should be confirmed and kept current by legal/operations before launch; add or remove providers as the stack changes (for example, email or analytics providers).]
5. Overseas disclosure (APP 8)
Some of our service providers are located, or process data, outside Australia. In particular, several providers we use (which may include our authentication/wallet provider and infrastructure providers) are based in or process data in the United States, and some blockchain RPC/indexing providers may operate in other countries. As a result, your personal information may be disclosed to, and stored or processed in, overseas jurisdictions.
Blockchain networks are global and decentralised. Public on-chain data (such as public wallet addresses and transaction records) is replicated across nodes worldwide and is not confined to any single country.
Where we disclose personal information overseas, we take reasonable steps, as required by APP 8, to ensure recipients handle it consistently with the APPs, or otherwise rely on a permitted exception. You consent to these overseas disclosures by using the service.
[PLACEHOLDER — the specific overseas countries and the APP 8 basis relied on for each provider should be confirmed by legal counsel before launch.]
6. Data retention (APP 4.2 & 11.2)
We retain personal information only for as long as it is needed for the purposes described in this policy, including to provide the service, meet legal and accounting obligations, resolve disputes, and enforce our agreements.
Some records — such as invoices, payment records, and receipts — relate to financial transactions. Australian businesses are generally required to keep financial and tax records for a number of years (commonly around five (5) years under Australian tax law). Because of this, and to support your record-keeping and reconciliation, we may retain certain transaction and invoice records for a comparable period even after an account is closed.
When personal information is no longer required and we are not legally obliged to keep it, we delete or de-identify it where practicable.
[PLACEHOLDER — the specific retention period(s) and the precise legal basis (for example, the relevant tax record-keeping requirement) should be confirmed by legal/accounting before launch.]
7. Security of information (APP 11)
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These steps include access controls, encryption in transit, and use of reputable infrastructure providers.
Because we are non-custodial, we never hold the most sensitive material in a crypto context — your private keys, seed phrases, or wallet credentials. You remain responsible for safeguarding your account credentials, authentication factors, and wallet security.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Access and correction (APP 12 & 13)
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading. To make a request, contact us using the details below. We may need to verify your identity before responding, and we will respond within a reasonable period.
If we decline a request for access or correction, we will tell you why (except where it would be unreasonable to do so) and how you can complain. Note that some records may be subject to the retention obligations described above.
9. Cookies and analytics
The service uses cookies and similar technologies that are necessary for authentication, security, and core functionality. We may also use limited analytics to understand and improve how the service is used.
[PLACEHOLDER — confirm the actual cookies and analytics/tracking tools in use (if any) before launch, and update this section and any cookie banner/consent mechanism accordingly.]
10. How to complain
If you have a concern about how we have handled your personal information, please contact us first using the details below so we can try to resolve it. We will acknowledge your complaint and aim to respond within a reasonable period.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified through the service or by email where practicable. The “Last updated” date at the top of this page indicates when the policy was most recently revised.
12. Contact us
Privacy enquiries and access/correction requests may be directed to Audara Pay at privacy@audarapay.com.au. Audara Pay is based in Melbourne, Victoria, Australia.
DRAFT — this Privacy Policy is provided for operational use during product development and has not yet been reviewed by a qualified Australian lawyer. It is not legal advice. Formal legal and compliance review is required before commercial launch.
