Privacy Policy
Last updated: 21 August 2026
1. Scope
This policy explains how ELab collects, uses, stores, and shares personal information when you use the ELab Xero integration (the “Service”). ELab is responsible for the personal information described in this policy.
2. Information we collect
We may collect:
- Your email address (for authentication via one-time codes)
- Your name or operator identity when supplied
- Client, user, and Xero organisation identifiers you are authorised to access
- Xero OAuth tokens and connection metadata required to maintain the integration
- Encrypted Xero application credentials supplied by an authorised administrator
- Security and audit metadata, including the tool used, organisation, operator, outcome, and timing
- Billing contact details, company name, plan, subscription status, and invoice records
- Payment method details processed by Stripe. We do not store full card numbers
- Support communications and other information you choose to provide
The Service processes Xero financial and business data when carrying out your requests. We do not intentionally retain that content as application records after completing the request, although limited information may be retained where needed for security, troubleshooting, legal compliance, or reliable operation.
3. How we use information
We use information to:
- Authenticate users and enforce client access rules
- Connect to Xero and carry out authorised requests
- Detect and prevent abuse or unauthorised access
- Operate, maintain, troubleshoot, and improve the Service
- Provide support and audit visibility to the organisations we serve
- Comply with legal obligations and enforce our terms
- Process payments, invoices, failed-payment recovery, tax, and payment disputes
We do not use Xero API data to train or fine-tune artificial intelligence or machine-learning models.
4. Storage and security
Xero client credentials are encrypted (AES-256-GCM) before being stored. Encryption keys are held in the platform infrastructure and are never stored in the database. OAuth tokens are stored securely and are scoped to the specific client and user.
We use reasonable technical and organisational safeguards designed to protect personal information, including access controls and encryption in transit and at rest where appropriate. No internet-based service is completely secure.
5. Sharing and overseas processing
We do not sell personal information or share it for third-party marketing. We disclose information only as needed to provide the Service, including to Xero, the AI platform through which you access the Service, Stripe for payment processing, and providers supporting authentication, database, hosting, monitoring, and email delivery; to your organisation’s authorised administrators; where you direct or authorise us; or where required by law or necessary to protect rights, security, and users.
Stripe processes payment information under Stripe’s privacy policy. Card numbers and payment credentials are handled by Stripe, not stored by ELab.
Some providers may store or process information outside New Zealand. Where required, we take reasonable steps to ensure appropriate privacy safeguards apply. Xero, AI model providers, AI client software, and other providers process information under their own terms and privacy policies when acting independently. ELab does not control how those tools present, store, or reuse prompts, results, or conversation history on their side.
6. Retention and deletion
We retain account and connection information while needed to provide the Service and then delete or de-identify it when it is no longer reasonably required, subject to legal, security, backup, dispute, and operational requirements. Audit and security logs may be kept for a reasonable period to protect users and investigate incidents.
You may disconnect Xero at any time. You may also request deletion of your personal information and associated connections by contacting us, subject to any information we are legally permitted or required to retain.
7. Your rights
You may ask us to confirm whether we hold personal information about you and request access to or correction of that information. Depending on your location, you may also have rights to request deletion or restriction and to object to certain processing. Contact us to exercise a right; we may need to verify your identity.
8. Privacy breaches
If a privacy breach is likely to cause serious harm, we will notify affected individuals and the New Zealand Privacy Commissioner as required by the Privacy Act 2020.
9. Changes to this policy
We may update this policy as the Service, our providers, or legal requirements change. We will publish the revised policy with a new effective date and give reasonable notice of material changes where practicable.
10. Contact
For privacy requests, complaints, or questions, contact our Privacy Officer at hello@elab.co.nz. You may also make a complaint to the Office of the Privacy Commissioner.
ELab
Auckland, New Zealand
elab.co.nz
