1. About this policy
This Privacy Policy explains how Wizfund Pty Ltd (ACN 679 815 493, ABN 99 679 815 493) ("Wizfund", "we", "us", "our") collects, uses, stores, discloses and protects personal information.
Wizfund operates Tritally, an invoice collections and review automation platform for Australian businesses. Tritally is a product of Wizfund Pty Ltd; Wizfund Pty Ltd is the entity that contracts with you and is responsible for the personal information described in this policy. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we comply with the Spam Act 2003 (Cth) and the Australian Communications and Media Authority (ACMA) requirements for commercial electronic messages.
By using Tritally, you agree to the handling of personal information by Wizfund as described in this policy.
2. Two kinds of information, two different roles
It is important to understand the distinction below, because our obligations differ in each case.
a) Information about our customers (businesses that subscribe to Tritally).
When a business signs up for Tritally, we collect information about that business and the individuals who use the account. We determine how this information is handled, and this policy governs it directly.
b) Information about our customers' customers (debtors).
When a business connects its accounting software to Tritally, we receive information about the people and businesses that owe them money. We process this information on behalf of, and under the instructions of, the business that holds the account. That business remains responsible for its own privacy obligations to its customers, including having a lawful basis to provide us with their contact details. We use this information only to deliver the service to that business, and never for our own purposes.
If you have received an email, SMS or call sent through Tritally about an unpaid invoice and you want your information corrected or removed, please contact the business that issued the invoice — their name appears in every message. You can also contact us using the details in section 15 and we will refer your request to them and assist.
3. Information we collect
3.1 Account information (from our subscribers)
- Name, business name, email address, phone number and postal or business address
- Login credentials (passwords are stored only as salted cryptographic hashes — we never store them in readable form)
- Business branding: logo, brand colours, operating hours, reply-to address
- Subscription tier, billing status and payment history
- Team member names, email addresses and assigned roles
3.2 Information received from connected accounting platforms
When you connect MYOB, Xero, QuickBooks Online or Stripe, we receive:
- Invoice data: invoice number, amount, currency, issue date, due date and payment status
- Customer (debtor) records: name, business name, email address and mobile number
- Payment events: date, amount and allocation of payments recorded against invoices
We request the minimum scope required to operate. We do not request or access payroll or employee information, banking data, general ledger data, inventory, or accounts payable information. We do not read fields we do not need.
3.3 Information we generate
- A numeric payment-behaviour score (0–100) calculated for each debtor from invoice and payment history, used to determine reminder tone, timing and channel
- Message content generated for reminders, and logs of every communication sent, including channel, timestamp, delivery status, opens, clicks and outcomes
- Feedback and star ratings submitted through review requests
3.4 Information collected automatically
- IP address, browser type, device type and operating system
- Pages accessed, actions taken within the application, and timestamps
- Security and audit logs of account activity
3.5 Payment information
Card details are collected and processed directly by Stripe. We never receive, handle or store full card numbers, CVV codes or magnetic-stripe data on our systems. We retain only a payment reference, the last four digits, card brand and expiry for reconciliation and support.
4. How we collect information
We collect personal information:
- Directly from you, when you create an account, configure settings, contact support, or submit feedback
- From your connected accounting platform, with your explicit authorisation through OAuth 2.0, which you grant at connection and can revoke at any time
- From emails you forward or BCC to your dedicated Tritally import address
- Automatically, through your use of the platform
- From your customers, when they open a message, visit a payment page, make a payment, or submit a review or feedback response
Where it is reasonable and practicable, we collect personal information directly from the individual concerned. Debtor information necessarily comes to us from our subscriber's accounting records rather than from the debtor.
5. Why we use personal information
We use personal information only for the following purposes:
| Purpose | What this involves |
|---|---|
| Delivering the service | Syncing invoices, detecting overdue balances, sending reminders, processing payments, requesting reviews |
| Personalising communications | Generating message content and setting tone, timing and channel appropriate to the debtor's payment history |
| Payment processing | Presenting payment pages and processing payments through Stripe Connect to the subscriber's own account |
| Account administration | Authentication, billing, subscription management, and enforcing role permissions |
| Support | Responding to enquiries, investigating faults, and restoring service |
| Security and integrity | Detecting fraud, abuse and unauthorised access, and maintaining audit trails |
| Legal compliance | Meeting our obligations under Australian law and responding to lawful requests |
| Product improvement | Understanding aggregate usage patterns to improve the platform |
5.1 What we do not do
We want to be unambiguous about this:
- We do not sell, rent, licence or trade personal information to anyone, for any purpose.
- We do not use your data, or your customers' data, for advertising or marketing to third parties.
- We do not use accounting or invoice data to train artificial intelligence or machine learning models, and we do not permit our sub-processors to do so. Our AI provider is contractually bound not to train on data submitted through its API.
- We do not pool data across accounts or build combined datasets, credit-scoring products, or commercial data assets from our subscribers' information. Payment-behaviour scores are calculated per account and are visible only within that account.
- We do not disclose your data to any other subscriber, and we do not act as a credit reporting body.
6. Artificial intelligence
Tritally uses AI to draft the content of reminder emails and SMS messages, and to conduct automated voice calls to high-risk debtors on our subscribers' behalf. Wizfund selects and contracts with the AI providers involved.
- Data sent to AI providers is limited to what is necessary to generate the message: business name, debtor name, invoice details, outstanding balance and payment stage.
- Our AI providers are contractually prohibited from using this data to train their models.
- Automated voice calls identify themselves and the business on whose behalf they are calling. Calls are placed only within configurable business hours, are never placed to debtors classified as low-risk or VIP, and are checked against the Do Not Call Register.
- Human review is available: subscribers can pause any individual workflow, pause all workflows account-wide, or skip steps at any time.
7. Who we disclose information to
We disclose personal information only to the following categories of recipient, and only to the extent necessary:
Our subscribers. Debtor information is visible to the business that holds the account and to the team members it authorises.
Recipients of communications. Where a subscriber's messages are sent to their debtors, those messages contain the invoice and balance information necessary to seek payment.
Service providers (sub-processors). We engage the following categories of provider under contractual confidentiality and security obligations:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting (PostgreSQL) — invoice, customer and account records | Australia (Sydney, ap-southeast-2) |
| Vercel | Application hosting and content delivery | United States |
| Stripe | Payment processing and subscription billing | United States / Australia |
| Resend | Transactional and reminder email delivery | United States |
| Twilio | SMS delivery and automated voice calls (Australian sender IDs and numbers) | United States |
| Anthropic | AI generation of reminder message content | United States |
| Sentry | Error and performance monitoring | United States |
We maintain a current list of sub-processors and will provide it on request.
Professional advisers, insurers and auditors, where reasonably required and under obligations of confidentiality.
Law enforcement, regulators and courts, where we are required or authorised by law to do so.
A successor entity, in the event of a merger, acquisition or sale of assets — in which case this policy will continue to apply to the information transferred, or you will be notified of any change.
8. Overseas disclosure
Some of the service providers listed in section 7 are located outside Australia, principally in the United States. Where personal information is disclosed to an overseas recipient, we take reasonable steps under APP 8 to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles, including through contractual data-protection commitments.
Our primary application database is hosted in Australia (Sydney), and invoice, customer and account records are stored there at rest. However, application hosting, message delivery, payment processing, AI message generation and error monitoring are provided by the overseas providers listed above, and personal information is transmitted to and processed by them in the course of delivering the service. If you do not wish your information to be disclosed overseas, please contact us — but note that we may not be able to provide the service.
9. How we protect information
We take the security of financial and contact data seriously, and apply the following controls:
- Encryption in transit using TLS 1.2 or higher for all connections
- Encryption at rest for all customer and financial data
- OAuth token protection: accounting platform access tokens are encrypted at rest using AES-256, are never written to logs, are never exposed to the browser, and are automatically rotated before expiry
- Account isolation: logical separation enforced at the database layer, so no account can access another account's data
- Role-based access control within each account, enforced at the API layer rather than only in the interface
- Signed, expiring payment links: customer payment links are cryptographically signed, scoped to a single customer and account, and expiry-enforced. Tampered or unsigned links are rejected
- No card data on our systems: all card handling is performed by Stripe, a PCI-DSS Level 1 certified provider
- Restricted internal access: access by our staff is limited to those who require it, is separately authenticated and role-limited, and every access event is logged
- Audit logging: all communications, workflow events and user actions are logged and retained for a minimum of 12 months
- Continuous monitoring of scheduled jobs and integration health, with alerting on failure
No method of transmission or storage is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security. If we become aware of an eligible data breach, we will assess and notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.
10. Retention and deletion
We retain personal information only for as long as it is needed for the purposes described in this policy, or as required by law.
- On disconnecting an accounting integration: we immediately cease synchronisation, revoke the connection, and delete the stored access and refresh tokens.
- On account closure: subscriber and debtor data is deleted or de-identified within 90 days, other than records we are required to retain for tax, audit, legal or dispute-resolution purposes.
- Communication and audit logs are retained for a minimum of 12 months to support audit, dispute resolution and regulatory compliance, and are then deleted on a rolling basis.
- Payment records are retained for the period required under Australian taxation and financial record-keeping law.
You may request deletion of your information at any time under section 12.
11. Electronic messages and opt-out
Messages sent through Tritally on behalf of a subscriber are sent in that subscriber's name, identify the sending business, and include the means to opt out.
- SMS recipients may reply with the stated opt-out keyword at any time. Opt-outs are honoured immediately and permanently across all future messages from that business.
- Email recipients may unsubscribe using the link in any message.
- Voice call recipients may request no further calls, which is recorded and honoured. We check the Do Not Call Register before placing automated calls.
- Marketing from us: we will only send you marketing about Tritally where we are permitted to do so, and every message includes an unsubscribe link. Opting out of marketing does not affect service and transactional messages relating to your account.
Note that reminders about a genuine outstanding debt are sent by the business you owe, in the course of their commercial relationship with you. Opting out of messages does not extinguish the underlying debt.
12. Accessing and correcting your information
Under APP 12 and APP 13 you may request:
- Access to the personal information we hold about you
- Correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading
- Deletion of your information, subject to our legal retention obligations
- A copy of your data in a portable format
Subscribers can access, correct and export most of their information directly within the Tritally application. For anything else, contact us using the details in section 15. We will respond within 30 days. We do not charge for making a request, though we may charge a reasonable fee for the cost of providing access in some circumstances. If we refuse a request, we will tell you why in writing and explain how to complain.
If you are a debtor who has received a message sent through Tritally: the information about you was provided by the business that invoiced you, and that business controls it. Please contact them directly — their details appear in every message. If you contact us, we will refer your request to them and assist in having it actioned.
13. Cookies and analytics
We use cookies and similar technologies that are strictly necessary to operate the application — maintaining your login session, remembering your dashboard layout, and protecting against fraud and abuse.
We use privacy-respecting analytics to understand aggregate usage of our website and application. We do not use third-party advertising cookies, and we do not permit third parties to track you across other websites through our service.
Most browsers allow you to refuse or delete cookies. Disabling essential cookies will prevent the application from functioning.
14. Children
Tritally is a business tool and is not directed at, or intended for use by, individuals under 18. We do not knowingly collect personal information from children. If you believe we have done so, contact us and we will delete it.
15. Contact us and how to complain
For any privacy question, request or complaint:
Privacy Officer
Wizfund Pty Ltd
Email: support@tritally.com.au
Post: Unit 3, 35 Wyandra Street, Teneriffe QLD 4005, Australia
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. We will tell you the outcome and the reasons for our decision in writing.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001
16. Changes to this policy
We may update this policy from time to time. The current version is always available at https://www.tritally.com.au/privacy, with the "Last updated" date shown at the top. Where changes are material, we will notify account holders by email or through the application before the changes take effect. Continued use of Tritally after the effective date constitutes acceptance of the updated policy.
Tritally is a product of Wizfund Pty Ltd (ACN 679 815 493). © 2026 Wizfund Pty Ltd. Made in Australia.