Privacy Policy
Last updated: 21 July 2026
1. What we collect
- Xero OAuth tokens — stored encrypted at rest so the Service can act on the organisations you connect. We never receive your Xero password.
- Accounting data you operate on — invoice, credit note and tracking category records are read from Xero to build previews, and the items you approve are written back. Job history and audit logs (what changed, before/after) are stored so you can review and undo operations.
- Billing information — payments are processed entirely by Paddle.com, our merchant of record. We never see your card number. Paddle shares with us your subscription status and the email used at checkout.
2. What we do not do
- We do not sell or share your data with third parties for marketing.
- We do not use your accounting data for anything except the operations you request.
- We do not use advertising or cross-site tracking cookies.
3. Where data lives
The Service runs on Cloudflare's global network; application data is stored in Cloudflare D1. Payment data is held by Paddle. Xero data remains in Xero — we hold only the job history and audit records described above.
4. Retention and deletion
Disconnecting your organisation from Xero revokes our access immediately. Email support@microspear.app to have your stored tokens, job history and audit logs deleted; we complete deletion requests within 30 days.
5. Contact
support@microspear.app