Privacy Policy

Last Updated: July 2026

WYHEN Pty Ltd (ABN 57 688 078 999) trading as SyncMate ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy outlines how we collect, use, store, disclose, and safeguard your personal and financial information when you interact with the SyncMate application (the "Platform" or "App").

This policy is compliant with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Types of Information We Collect

To provide automated accounting and expense synchronization workflows, we collect the following categories of information:

  • Account Credentials: Name, business name, corporate email address, phone number, billing details, and encrypted login identifiers.
  • Source Financial Documentation: Uploaded financial records, including invoices, corporate receipts, purchase orders, statements, supplier information, and line-item tax details.
  • System Integration Metadata: Synchronized metadata from your integrated third-party accounting ecosystem (e.g., Xero Chart of Accounts, tracking categories, and tax rates).

2. How We Collect Your Data

  • Direct User Input: Information explicitly provided by you when creating an account, adjusting settings, configuring user seats, or uploading image/PDF receipts.
  • API Ingestion: Data securely pulled from connected accounting platforms (such as Xero) via OAuth 2.0 protocols.

3. Purpose of Data Processing

We process and use your information for the following primary operational and product development tasks:

  • To execute core software functionalities (AI-driven OCR text extraction, automated category matching, and data pushing to Xero).
  • To manage active subscriptions, track extraction usage ceilings, process billing, and offer technical support.
  • To monitor system health, audit security logs, and prevent fraudulent activity within the platform infrastructure.
  • SyncMate does not build, train, or maintain any proprietary AI model. Your uploaded documents and the extracted financial data are not used to train any AI model, are not shared with other SyncMate users, and are not sold to third parties. See our Trust & Security page for full details.

4. Third-Party Data Disclosures, Subprocessors, and Payment Processing

We do not sell, rent, or trade your personal or financial data to third-party marketers. To deliver a fully automated SaaS experience, your data is securely shared with and processed by the following essential infrastructure partners:

  • Paddle: Our order process is conducted by our online reseller and Merchant of Record, Paddle.com Market Ltd ("Paddle"). Paddle handles all payment processing, merchant invoicing, subscription billing management, and customer service inquiries related to transactions. Your payment details (such as credit card numbers or banking information) are collected directly by Paddle and are subject to Paddle's own Privacy Policy and checkout terms. Personal data necessary to manage your active subscription status is shared between Paddle and SyncMate securely.
  • GoCardless: For Australian customers who choose Direct Debit, our BECS direct-debit mandates and collections are processed by GoCardless. Your bank account details are collected directly by GoCardless under their own terms and privacy policy.
  • AI/OCR Subprocessors: Enterprise API endpoints from OpenAI and Google (Gemini API, Paid tier) used to perform OCR and data extraction on your uploaded documents. Both providers contractually do not use API submissions to train or improve their models. SyncMate does not build or train its own AI models.
  • Cloud Hosting (Supabase / Cloudflare): Database, authentication, storage, and edge compute are hosted on Supabase (Postgres) and Cloudflare in the AWS Asia-Pacific region. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).

5. Data Retention & Deletion Rights

5.1 Right to Erasure: You may request the absolute erasure of your stored historical invoices and user profile from our servers at any time by contacting support. This is subject to any overarching anti-money laundering (AML) laws or financial statutory record-keeping regulations that may compel a temporary preservation period.

6. Data Security

We implement industry-standard cryptographic practices to protect your records. All data transmitted between your device, SyncMate, and Xero is encrypted using Transport Layer Security (TLS) in transit and Advanced Encryption Standard (AES-256) at rest.

7. Contact Us

If you have any questions regarding this Privacy Policy, or if you wish to lodge a query regarding how your financial information is managed under WYHEN Pty Ltd's trading structure, please contact us at contact@wyhen.com.au

WYHEN Pty Ltd