Privacy Policy
Effective date: 4 August 2026
This Privacy Policy explains how Buildstate (we, our, us) collects, uses, discloses, and protects personal information across our products:
- Buildstate Invoice — our iOS app for time tracking, expenses, receipts, clients, projects and invoicing; and
- the SiteTools web platform at buildstate.com.au — including SiteSign, SiteITP, SiteDocs, SiteCapture and our free tools.
We refer to these together as our Services. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Information we collect
1.1 Buildstate Invoice (iOS app)
When you use Buildstate Invoice, we collect:
- Account details — your name, email address and the credentials used to sign in;
- Business profile — business name, contact details, ABN, GST settings, default rates, payment terms and invoice numbering that you enter;
- Client and customer records — the names, contact details and addresses of your clients that you choose to store;
- Projects — project names, descriptions and the records you associate with them;
- Time entries — timer start/stop times, manually entered hours, rates, notes and the project each entry belongs to;
- Expenses and receipts — amounts, categories, dates, notes, and receipt images you photograph or upload, together with any text extracted from those images;
- Invoices, quotes and payments — line items, totals, tax amounts, terms, invoice and quote status, the email addresses invoices are sent to, and the payment records you enter to mark an invoice as paid;
- Subscription status — whether your account has an active paid entitlement, and the associated Apple transaction identifiers. We do not receive or store your card number (see section 6);
- Device tokens — where you enable push notifications, the token needed to deliver them to your device;
- Usage and diagnostic data — see section 1.3; and
- Feedback — see section 1.4.
Buildstate Invoice does not collect your precise location. The app does not request continuous or background location access, and it does not stamp location onto time entries, expenses or invoices.
1.2 SiteTools web platform
When you use the web platform, we may collect:
- account registration details: name, email address and password;
- organisation, workspace, team and settings information you configure;
- project and site data you create or upload, including records processed through SiteSign, SiteITP, SiteDocs and SiteCapture;
- worker and visitor sign-in records captured through SiteSign, including names, phone numbers, company names, visitor type, signatures and sign-in/sign-out times;
- documents and images uploaded to the platform for processing or storage;
- Location, in specific web features only — site coordinates you set on a map, the GPS coordinates recorded when a photo is captured with the SiteCapture camera overlay, and the coordinates recorded at the moment an ITP checkpoint is signed off. Your browser asks for permission each time, we use the position only at that moment, and we never track your location in the background;
- subscription and billing status for paid plans (handled by Stripe — see section 6);
- usage and feature interaction data — see section 1.3; and
- technical information such as IP address, browser type and version, referring URL and session timestamps.
1.3 Usage analytics, session replay and crash data
In Buildstate Invoice, we use PostHog to understand how the app is used — which screens are opened, which features are used, and where people get stuck. PostHog is identified using the unique account identifier (UUID) issued by our authentication provider when you sign in, which means product interaction data is linked to your account rather than being anonymous.
Where session replay is enabled, PostHog also records a privacy-hardened replay of app screens — text inputs are masked so the content you type is not captured. Session replay is a diagnostic tool for us, not an advertising tool, and it is subject to the same opt-out below.
You can turn analytics off. Buildstate Invoice includes an in-app setting to opt out of PostHog analytics (including session replay). When you opt out, the app stops sending product interaction events. Opting out does not affect your ability to use the app.
Crash and diagnostic reporting. Where it is configured, we use Sentry to receive crash reports and error diagnostics from the app — typically the error type, the code path involved, the app version and the device/OS version. This is used to fix faults, not to profile you.
On the SiteTools web platform, analytics are first-party: events are recorded in our own database and are deliberately structural rather than content-bearing (for example, "a document was exported" — never what the document said). The web platform does not use PostHog, and does not use session replay or screen recording.
1.4 Feedback and communications
We collect the contents of support requests, feedback and other communications you send us. When you submit feedback from within Buildstate Invoice, we also store the technical context needed to act on it — a rating and category, the screen you were on, the app version and build number, your device model and OS version, and whether you asked us to reply.
2. How we use information
We use personal information to:
- create and manage your account, and authenticate you;
- provide the core features you have asked for — tracking time, recording expenses, storing receipts, managing clients and projects, and generating invoices and quotes;
- generate invoice and quote PDFs and email them to the recipients you nominate (see section 4);
- read text from receipt images so expense fields can be pre-filled for you (see section 3);
- determine whether your account has an active subscription entitlement, and unlock paid features accordingly;
- send push notifications you have enabled;
- understand product usage, diagnose crashes and improve the Services (see section 1.3);
- respond to support requests, feedback and service communications;
- protect the Services against misuse, fraud and abuse; and
- comply with our legal obligations and enforce our terms.
We do not sell your personal information, and we do not use it for behavioural advertising or cross-app tracking. We do not use your client lists or invoice data for marketing.
3. Receipt OCR and document processing
Buildstate Invoice — receipt OCR. When you attach a receipt to an expense, the image may be sent to Google Cloud Vision to perform optical character recognition (OCR): reading the printed text so we can pre-fill the amount, date and merchant for you. This is text recognition, not a generative AI service — your receipts are not sent to a generative AI model by the app, and we do not use them to generate content.
The extracted text and the receipt image are stored against your expense record in private storage that is not publicly accessible.
SiteTools web platform — generative AI features. Some web features (for example AI-assisted ITP checklist generation and SiteDocs document drafting) do send the content you supply to a third-party large language model provider so it can generate a draft for you. These features are optional and only run when you invoke them. Scanned PDFs uploaded to the SiteITP import flow may also be sent to Google Cloud Vision for OCR where they contain no readable text layer.
These providers act as our processors and are engaged under their standard commercial terms. We do not make any representation here about whether a given provider trains on data submitted through its API — if that matters to your business, contact us at admin@buildstate.com.au and we will tell you which provider is used for the specific feature and point you to its current terms.
4. Invoice and email delivery
When you send an invoice, quote or other document by email from Buildstate Invoice, we use Resend to deliver that email on your behalf. The recipient's email address, your business details and the document itself pass through Resend for the purpose of delivery, and delivery metadata (such as whether the message was accepted or bounced) may be retained by that provider.
You are responsible for having the right to email the people you nominate as recipients — see our Terms of Service. We also use Resend to send transactional and account emails from the web platform.
5. Service providers we use
We disclose personal information to the service providers that make the Services work. They process it on our behalf, for the purposes set out below.
Buildstate Invoice (iOS)
- Supabase — authentication, the application database, and private storage for receipt images and generated documents.
- Apple — App Store distribution, in-app purchase and auto-renewing subscription billing, and (with Expo) push notification delivery.
- RevenueCat — managing subscription state and purchase entitlements on top of Apple's in-app purchase system.
- PostHog — product analytics and, where enabled, privacy-hardened session replay — identified by your account UUID, and subject to the in-app opt-out.
- Sentry — crash and error diagnostics, where configured.
- Google Cloud (Cloud Vision) — optical character recognition of receipt images.
- Resend — delivery of invoice, quote and account emails.
- Expo — app build and update tooling, and push notification delivery services.
SiteTools web platform
- Supabase — authentication, the application database and file storage.
- Vercel — application hosting and content delivery.
- Stripe — subscription billing and payment processing for paid plans.
- Resend — transactional, invitation and lifecycle email delivery.
- Google Cloud (Cloud Vision) — OCR of scanned PDFs uploaded to the SiteITP import flow.
- Large language model providers — generating drafts in the optional AI-assisted SiteITP and SiteDocs features.
- Upstash — rate limiting to protect public endpoints from abuse.
We may also disclose information where required by law or court order, to protect the rights or safety of any person, to our professional advisers where reasonably necessary, or in connection with a merger, acquisition or sale of assets — in which case we would take reasonable steps to ensure your information continues to be protected under terms consistent with this policy.
Other than as described above, we do not disclose your client, invoice or project data to any third party.
6. Subscriptions and payment information
Buildstate Invoice offers auto-renewing subscriptions, which are sold and billed by Apple through your Apple Account. Payment is taken by Apple at the price shown in the App Store at the time you subscribe, and subscription management, cancellation and refund requests are handled through your Apple Account.
We do not receive, process or store your payment card details. What we receive — via RevenueCat and Apple — is your subscription and entitlement status (for example, whether a subscription is active, when the current period ends, and the associated transaction identifiers) so the app can unlock paid features for your account.
SiteTools web platform paid plans are billed through Stripe. Card details are entered directly with Stripe and are never stored on our systems; we retain the subscription status, plan and billing metadata Stripe returns to us.
7. Overseas storage and processing
Buildstate is operated from Australia, but the providers listed in section 5 are global cloud services. Personal information you give us is likely to be stored or processed outside Australia, in whichever regions those providers operate.
We have not independently verified, and therefore do not state here, the specific country in which each provider stores your data — that can change as a provider adds or moves regions. If you need to know the current storage region for a particular provider before you rely on the Services, email admin@buildstate.com.au and we will confirm what we know at that time.
By using our Services, you acknowledge that your personal information may be transferred to and processed in countries that may not provide the same level of data protection as Australia. Where we make an overseas disclosure, we take the steps reasonable in the circumstances under Australian Privacy Principle 8.
8. Cookies and local storage
The web platform uses cookies and browser storage to keep you signed in, remember preferences, and record the anonymous session and visitor identifiers used by our first-party analytics. You can control cookies through your browser settings; disabling them may stop parts of the platform working.
Buildstate Invoice does not use cookies. It uses on-device storage for your session and for local caching of your own data.
9. How long we keep information
- Your business records — time entries, expenses, receipts, clients, projects, quotes and invoices — are kept for as long as your account is open, because they are the records you rely on. You can delete individual records in the app at any time.
- Raw web analytics events are retained for a limited period (currently a 180-day target) and then deleted. Aggregated daily counts derived from them contain no per-event detail and are kept indefinitely so we can see long-term trends.
- Feedback is not on the analytics clock. It is retained for as long as it remains useful for product and support purposes, and is deleted on request rather than automatically.
- Analytics, crash and subscription records held by third parties (PostHog, Sentry, RevenueCat, Apple, Resend) are retained under each provider's own retention settings and policies, which may differ from ours.
- Records we are legally required to keep — for example transaction records relevant to tax or consumer law — are retained for the period the law requires, even after an account is closed.
10. Access, correction and deletion
You can ask us to:
- Access — give you a copy of the personal information we hold about you;
- Correct — fix personal information that is inaccurate, out of date or incomplete; and
- Delete — delete your account and the personal information we hold about you, subject to the limits described below.
You can delete your account from within Buildstate Invoice, or by emailing admin@buildstate.com.au.
What account deletion actually does
We want to be straight with you about this rather than promise more than our systems do:
- your account and your business records — clients, projects, time entries, expenses, receipt images, quotes and invoices — are deleted;
- some records are de-identified rather than deleted. Historical analytics rows have their link to your account removed (the user identifier is set to null) so aggregate counts of past activity remain accurate but are no longer attributable to you;
- feedback you submitted may be retained without an identifiable user, because it is often the basis for a product change months later. Any directly identifying field on the feedback record is removed;
- records we are required to keep by law (for example tax or transaction records) are retained for the required period;
- data already held by third-party providers — analytics events at PostHog, crash reports at Sentry, subscription and purchase records at Apple and RevenueCat, email delivery logs at Resend — is deleted or aged out according to those providers' processes. We will pass on a deletion request to them where we are able to; and
- deleting your account does not cancel an Apple subscription. You must cancel it in your Apple Account settings, or Apple will keep billing you. See our Terms of Service.
To make a request, email admin@buildstate.com.au. We will acknowledge it promptly and respond within a reasonable time. We may need to verify your identity first.
11. Security
We use administrative, technical and organisational safeguards designed to protect personal information against unauthorised access, modification or disclosure. Receipt images and uploaded documents are held in private storage rather than public buckets, database access is restricted by row-level security so accounts can only reach their own data, and privileged keys are used only on our servers and never shipped to a browser or an app.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your own credentials secure.
12. Children
Our Services are business tools intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact admin@buildstate.com.au and we will delete it.
13. Complaints
If you believe we have mishandled your personal information, please contact us first at admin@buildstate.com.au so we can try to resolve it.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
14. Updates to this policy
We may update this Privacy Policy from time to time — for example when we add a feature or change a service provider. When we do, we will publish the updated version on this page and revise the effective date at the top. Where a change materially affects how we handle your information, we will take reasonable steps to tell you.
15. Contact us
For any privacy question or request, contact Buildstate at admin@buildstate.com.au.