Privacy Policy

Last updated: 31 July 2026

1. Who we are

AccountMD is operated by Propte Pty Ltd (ABN 42 636 400 765), an Australian company. In this policy, "we", "us" and "our" mean Propte Pty Ltd, and "the service" means AccountMD and the related websites, applications and APIs we operate.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. Two kinds of information

The service holds information about two different groups of people, and our obligations differ for each.

  • Information about you — the person who signs up, signs in and pays for the service. We decide how this information is handled, and this policy governs it.
  • Information inside your accounting records — the names, contact details and payment details of your own customers, suppliers and employees that already exist in the accounting system you connect. We hold this on your behalf, and only to provide the service to you. You remain responsible for having the right to give it to us and for your own privacy obligations to those people.

3. Information we collect

Account information. Your name, email address, and the authentication details you choose — a password (stored only as a one-way hash), a passkey, or a linked sign-in provider. If you enable two-factor authentication we store the secret needed to verify your codes. If you enable API access we issue and store an API token.

Billing information. Your subscription and plan status, and an identifier linking you to our payment processor. Card numbers are entered directly with our payment processor and never reach our systems.

Accounting data. Where you connect an accounting system, we retrieve and store the financial records you authorise us to access. Be aware that this is a full copy of the relevant records, not a summary. It typically includes your chart of accounts, general-ledger journals and postings, transactions and their line-level detail, invoices and bills, contacts, and the raw API responses we received. Depending on what your accounting file contains, those records can include names, email addresses, phone numbers, tax file or business numbers and bank account details belonging to your organisation and to the people and businesses you deal with.

Content you enter. Notes, memos and any messages you send to in-product assistant features. These are free text, so they contain whatever you put in them.

Technical information. Server and request logs including IP address, browser type, pages accessed, timestamps and error diagnostics, used to operate, secure and debug the service.

4. How we use your information

We use the information above to:

  • present your financial position, reporting and analysis to you;
  • deliver your data to the destinations you choose, such as a spreadsheet you control;
  • operate, secure, support, troubleshoot and improve the service;
  • process payments and administer your subscription;
  • communicate with you about your account and about service changes;
  • meet our legal, tax and regulatory obligations.

We do not sell your information. We do not use your accounting data for advertising, and we do not use it to train machine-learning models for our own or anyone else's benefit. Where you use an assistant feature, your data is processed to answer the question you asked and for no other purpose.

5. Connecting an accounting system

Connections are authorised by you through the provider's own OAuth flow. We never ask for, receive or store your username or password for that system — we hold only the access and refresh tokens the provider issues.

We request the permissions the connection requires in order to read your records. We use that access to read only: we do not create, amend or delete anything in your accounting file.

You can disconnect at any time from within the application, or by revoking our access in the provider's own settings. On disconnection we stop retrieving new data. Financial records already synchronised are retained, so that your historical reporting continues to work and so that we meet the record-keeping obligations described in section 8 — you can ask us to delete them at any time under section 10.

6. Data you send elsewhere

A core purpose of the service is to put your own financial data where you want to work with it — for example, a spreadsheet in your Microsoft or Google account. When you export or connect data to a destination you control, that copy leaves our systems and is governed by your agreement with that provider and by your own settings, including any AI features that provider offers. We are not able to control or retrieve data once it is in your environment.

7. Who we disclose information to

We do not sell personal information, and we do not disclose your information to third parties for their own purposes. We disclose it only to the service providers who help us operate the service, where you direct us to, or where we are required to by law.

Our service providers, and what each of them receives:

  • Google Cloud — hosting, database and logging. Our production systems and database run in Google's Sydney region (australia-southeast1).
  • Stripe — payment processing. Receives your billing contact and payment details; we never see your full card number.
  • Resend — transactional email. Receives your email address and the contents of messages we send you.
  • Inngest — background job orchestration. Receives internal record identifiers, not your financial records.
  • The accounting provider you connect — receives our authenticated requests to read your data, under the access you granted.

Some of these providers store or process data outside Australia. Where that occurs we take reasonable steps to ensure the information remains protected to a standard consistent with the Australian Privacy Principles.

8. How long we keep it

Financial records. Australian tax law requires business records to be kept for at least five years. We therefore do not unilaterally delete synchronised financial data, and we retain it for as long as your account is active, unless you ask us to delete it.

Account information. Retained while your account is active, and afterwards only as long as we need it to meet legal, accounting or reporting obligations.

Sessions and verification codes. Short-lived, and discarded on expiry.

Technical logs. Retained for a limited period — ordinarily 30 days for operational logs, and longer for logs we keep for security investigation.

Backups. We take routine encrypted backups of our database so we can recover from failure. When we delete your data from the live system, a copy remains in those backups until they rotate out in the normal cycle. This is a deliberate resilience measure and, we consider, a reasonable step under APP 11.2 — but it does mean deletion is not instantaneous. Backups are not used to restore individual records, only to recover the service.

9. Security

We take reasonable technical and organisational steps to protect information against loss, misuse and unauthorised access, including encryption in transit and at rest, private-network-only database access, row-level access controls within the application, and multi-factor authentication on administrative accounts. Our practices are described in our Security Policy.

No system is perfectly secure. If an eligible data breach occurs we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

10. Accessing, correcting and deleting your information

You can view and correct most of your account information directly in the application. You may also ask us to:

  • give you a copy of the personal information we hold about you (APP 12);
  • correct information that is inaccurate or out of date (APP 13); or
  • delete your account and its associated data.

Contact us at the address below. We aim to respond within 30 days. We may need to verify your identity first, and we may decline a deletion request to the extent we are required by law to retain the information — we will tell you if that applies and why.

11. Cookies

We use cookies that are necessary for the service to function, such as keeping you signed in, protecting against cross-site request forgery, and remembering display preferences such as theme. We do not use third-party advertising cookies and we do not sell tracking data.

12. Children

The service is a business product and is not directed at, or intended for use by, children.

13. Complaints

If you are not satisfied with how we have handled your personal information, please contact us first using the details below so we can try to resolve it. You may also complain to the Office of the Australian Information Commissioner at oaic.gov.au.

14. Changes to this policy

We may update this policy from time to time. We will post any changes on this page and update the "Last updated" date above. Where a change materially affects how we handle your information, we will tell you before it takes effect.

15. Contact us

Propte Pty Ltd (ABN 42 636 400 765) — privacy questions, access and deletion requests, and complaints can be sent to privacy@propte.com.

AccountMD