Galaxy CFO — Privacy Policy
Version 1.0 · Last updated 6 September 2026
Jack and the Beanstalk Pty Ltd (ABN 67 661 466 397) trading as Galaxy CFO
Level 1, 53–55 Sydney Road, Manly NSW 2095, Australia
Introduction
This policy explains how we handle personal information when you use Galaxy CFO — the website, the application, our onboarding and support channels, and our marketing.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We do this as a matter of policy, and we treat the commitments in this document as binding on us.
Like our Terms of Use, this policy is written to be read. Each section starts with a short summary in italics. The summaries are there to help — the numbered clauses are the ones that count.
Two principles govern how the product is built, and they carry through this policy:
- We read; we do not decide for you. Where Galaxy CFO uses AI to read a document or propose a figure, it proposes a value for a person to review. Where we can write to your Xero at all, we create drafts for you to approve — we never approve or pay anything.
- We do not sell personal information, and we do not use your business's data to train AI models.
Questions or concerns? Email privacy@galaxycfo.com.
Two kinds of information
Galaxy CFO holds information about you, and information about your business — which usually includes information about other people, like your employees and customers. We treat the two differently, and this section explains the split.
1. Account information is information about you — the person who signs up, logs in, pays and asks for support. We decide how it is used, and this policy governs it in full.
2. Business information is what we read from your connected Xero organisation, the documents you upload, and the records you keep in Galaxy CFO (such as your company register). It is your business's information. We hold it to run the product for you, and for no other purpose. We do not use it for marketing, we do not sell it, and we do not pool it with other customers' data. The only exception is described in clause 26 (aggregated statistics).
3. Other people in your business information. Your business information will usually include personal information about other people — your employees, customers, suppliers, shareholders and directors. You are responsible for having the right to give it to us (see clause 38 of our Terms of Use). We handle it on your behalf and on your instructions. If you are one of those people — say, an employee or customer of a business that uses Galaxy CFO — and you have a question about information about you, contact that business first; it controls the workspace the information sits in. We will help them answer you.
4. What this policy does not cover. Xero's own handling of personal information is governed by the Xero privacy notice, not this policy. If an accountant, bookkeeper or fractional CFO uses Galaxy CFO across several clients, that firm's handling of its clients' information is governed by the firm's own policies. Sites we link to have their own policies too.
What we collect, and why
The categories of information we hold, where each comes from, and every purpose we use them for. Notably absent: advertising trackers, third-party analytics, and tax file numbers.
5. What we collect directly from you: your name, business email, phone number, business name and ABN when you create an account or book a demo; sign-in and security records (including multi-factor authentication status); billing details when you subscribe — handled by our payment processor eWAY, which gives us a token rather than your card number, so we never see or store full card details; support requests and feedback, including screenshots you choose to attach; and your marketing preferences.
6. What we collect automatically: standard technical logs — IP address, browser and device type, pages requested, errors. We do not run third-party analytics tools, session recording, or advertising pixels — in the app or on this website. The only usage data we hold is our own server logs and feature-level counts.
7. What we collect from your Xero organisation, once you authorise the connection: your chart of accounts and organisation settings; invoices and bills, which can include your customers' and suppliers' names and contact details; payments and bank transactions, which can include counterparties; financial reports (profit and loss, balance sheet, bank summary); and payroll summaries — described in clauses 27 to 30.
8. What we collect from documents you upload: supplier bills and invoices (if you use Bills & Payments), loan and finance contracts (if you use the debt schedule), ASIC company statements (if you use the company register), and screenshots attached to support requests. These documents can contain personal information about third parties — for example, an ASIC company statement lists shareholder names and addresses. Uploaded documents are stored in private storage in Australia and are readable only by the people in your workspace. ASIC company statements are the exception: we read them to propose register entries for your review, and do not keep the file itself.
9. What we collect from third parties: confirmation of your ABN details from the Australian Business Register when you enter an ABN, and payment results from eWAY. We do not buy data about you, and we do not use sales "enrichment" tools.
10. Why we use it. We use personal information to:
- provide the product — connect Xero, build forecasts and the cash flow grid, maintain your company register, run the health score, valuation and reporting modules;
- set up and support your account, and answer your questions;
- bill you and manage your subscription;
- send service messages — outages, changes, billing and security notices;
- keep the product secure, enforce our Terms and prevent abuse;
- improve the product — using our own server logs, aggregate feature counts and the feedback you send us, not your ledger data;
- send you our own marketing, which you can switch off (clause 44); and
- meet legal obligations and manage claims.
11. Sensitive information. We do not ask for sensitive information. Payroll data read from Xero could in principle permit inferences about matters such as leave; we use payroll data only to produce the product, and clauses 27 to 30 describe the extra protections it gets.
12. Tax file numbers. We do not collect tax file numbers. No Galaxy CFO field stores a TFN, and our Xero connection does not retrieve TFN records. If a document you upload happens to contain one, we do not extract it or use it for any purpose — and we suggest you redact it before uploading.
13. Benchmarks are public statistics, not your neighbours' books. Where Galaxy CFO compares your business to a benchmark — for example in the financial health score — the benchmark comes from published sources such as ATO small business benchmarks and ABS statistics, not from other customers' data.
The Xero connection
Exactly what the connection can see and do, how often it syncs, and what happens when you disconnect. Short version: read-only by default, you authorise it through Xero, and disconnecting cuts off access immediately.
14. You authorise it; we never see your password. Connecting Xero uses Xero's own sign-in and consent screen. We receive a secure token, which we store encrypted. We never see or hold your Xero password, and we cannot log in to Xero as you.
15. What we ask for. Our standard connection is read-only: organisation settings, invoices, bank transactions, payments, the profit and loss, balance sheet and bank summary reports, and payroll (pay runs, payslips, employees and payroll settings). We do not request write access as standard.
16. The one write exception. If you use Bills & Payments (currently in preview), we request the additional ability to create draft bills in your Xero and attach the source document to them. Drafts wait for your approval in Xero. We never approve, pay, or delete anything in your ledger.
17. How far back, and how often. On first connection we import the last two complete Australian financial years plus the current year to date. After that we sync once a day, early morning Sydney time, and whenever you press Sync.
18. Disconnecting. You can disconnect at any time from your entity's settings, or from within Xero. Disconnecting revokes our access on Xero's side, so all future access stops immediately. Information already imported stays in your entity so your forecasts keep working; if you want it gone too, delete the entity (clause 40) or ask us.
AI features
Where AI is used, what it sees, and the human in the loop. Payroll information about your employees is never sent to an AI model.
19. Where we use AI. Galaxy CFO uses AI in two ways:
- Document reading. When you upload a supplier bill, a loan contract or an ASIC company statement, an AI model reads it and proposes values — amounts, dates, terms, register entries — for you to review. Nothing is committed without a person accepting it.
- The assistant. The in-app assistant answers questions using an aggregate snapshot of the entity you're viewing — cash position, receivables and payables ageing, BAS position, headcount as a bare number. It is never given transaction lists or anything identifying an employee.
20. Who processes it. AI processing is performed by Anthropic, under an agreement that does not permit your data to be used to train AI models. Anthropic processes data in the United States; it appears in the service provider list at the end of this policy, and clause 34 covers overseas processing generally.
21. Employee information stays out. Payroll information about your employees — names, individual pay, anything at the person level — is never included in what we send to an AI model. The assistant sees a headcount, nothing more.
22. Automated processes. A few things in Galaxy CFO happen automatically, without a person at our end: your trial ends and the account locks when the trial period expires; your subscription can lock if payment repeatedly fails; and AI features pause when a monthly usage limit is reached. These use your account and billing information only. They are timers and meters, not profiling — no automated process at Galaxy CFO evaluates you as a person, and any of them can be reviewed by a human if you contact support. Decisions that matter — what the forecast means, what to do about it — remain yours.
Payroll and employee information
Payroll gets stricter treatment than anything else we hold: names live behind a PIN that only the account owner sets, and every reveal is logged.
23. What we import. From Xero payroll we import pay run summaries and per-employee pay components — gross pay, PAYG withholding, superannuation, pay cycle and state — because forecasting your largest expense requires them.
24. Names are separated and PIN-locked. Employee names are stored separately from everything else and never appear in default screens, API responses or exports. By default, employees appear as "Employee #1", "Employee #2". Seeing actual names requires a PIN that the account owner sets, and each reveal, grant and revocation is written to an access log the owner can review.
25. Who can see payroll at all. Only the workspace owner, admins, and members expressly granted payroll access can use the payroll module.
Who we share it with
Our service providers, the people you invite, and the law — that's the list. We do not sell personal information and we do not share it for advertising.
26. Aggregated statistics. As clause 36 of our Terms of Use says, we may produce aggregated, de-identified statistics from platform usage — only once no business or individual can be identified from them. Nothing identifiable is ever shared this way.
27. Service providers. We share personal information with the providers listed at the end of this policy, each of which is bound to use it only to provide its service to us. We do not disclose personal information to any third party for their own marketing or advertising.
28. People you invite. When you invite someone to your workspace — a co-founder, an accountant, a fractional CFO — they see the information in that workspace according to the permissions you set.
29. Where the law requires. We may disclose personal information to regulators, courts or law enforcement where we are compelled to, or where necessary to establish or defend a legal claim. Where we are permitted to tell you, we will.
30. If our business changes hands. In connection with a sale, merger or restructure, information may be disclosed to the other party under confidentiality obligations. If your subscription transfers to another entity, we will tell you in writing, as clause 88 of our Terms promises.
31. Our own staff. Galaxy CFO has no "log in as customer" feature and no staff screen that shows your financial data. Access to production infrastructure is limited to a small number of authorised people and is used only to operate, secure and support the service — including when you ask us to look into a problem in your account.
Where your data lives, and security
Your data is stored in Australia. A few providers process limited data overseas, and we say which ones. Security claims here are ones the build actually makes good on.
32. Stored in Australia. Our database, file storage and application hosting run in Sydney, Australia.
33. Overseas processing. Some providers process limited personal information outside Australia in the course of serving us — AI processing and email delivery in the United States are the main ones. The service provider list at the end of this policy shows each provider, what it receives and where it operates. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
34. Security measures. Data is encrypted in transit and at rest, and Xero connection tokens are additionally encrypted at the application layer. Every user account requires multi-factor authentication — it is not optional. Employee payroll detail sits behind the owner's PIN with access logging (clause 24). Administrative changes on our side are recorded in an append-only audit log, and sensitive administrative actions are designed for two-person approval — where one person acts alone, the override itself is permanently recorded. Uploaded documents live in private storage accessible only through short-lived signed links.
35. What we won't claim. No system is completely secure, and we will not pretend otherwise. We also don't borrow our providers' certifications as our own: our hosting providers maintain their own compliance programs, and questions about our security practices can be sent to privacy@galaxycfo.com — we answer them plainly.
36. Data breaches. If a data breach occurs that is likely to result in serious harm, we will assess it promptly and, where required, notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where a breach affects your business information, we will notify you without undue delay and give you what you need to meet your own obligations to your contacts.
Retention and deletion
How long things are kept, what deleting an entity actually does, and the one legal carve-out: company register records the Corporations Act requires you to keep.
37. While your account is open, we keep your information so the product works and so you can come back after a lapse — if a subscription ends, your data is retained so you can return and export or delete it.
38. Billing records are kept for seven years, as tax and record-keeping law requires.
39. Your export. The account owner can export the entity's data at any time from the application, in a machine-readable format — no request or approval needed. Employee names are deliberately excluded from exports (clause 24). Because a full copy is sensitive, exports are limited to the owner, capped to a few per hour, and each one is recorded in our audit trail.
40. Deleting an entity. The account owner can delete an entity at any time by typing its name to confirm and acknowledging that the business remains responsible for its own records. Deletion removes the entity's data from our live systems immediately and revokes the Xero connection on Xero's side. We keep a secure archive for 30 days so that a mistaken deletion can be undone on request, then destroy it permanently. Archives are held in private storage in Australia, are never used for any other purpose, and are accessed only to restore an entity at the owner's request, to answer a lawful compulsory request, or to establish or defend a legal claim — and every access is recorded.
40A. Keeping your own records. Australian law requires a business to keep certain records itself — financial records under the Corporations Act 2001 (Cth), and, for a company with a share register, details of former members. Those obligations rest with your business, not with us. Galaxy CFO is not a record-keeping service and should not be relied on as your statutory record. Download a copy of your data before you delete an entity (clause 39); after 30 days we will no longer hold one.
41. Closing your account. To close your account entirely, delete your entities and contact support@galaxycfo.com — we will deactivate the account and delete the personal information we no longer need. We keep what the law requires us to keep (such as billing records) and a minimal suppression record so we don't contact you again.
42. The Corporations Act carve-out. While your entity is live, company register records — the share register your company is required by law to keep — follow statutory retention rules inside the product, including retaining details of former shareholders for seven years; ordinary deletion features will not remove them before the law allows. Deleting the entity outright is the deliberate exception: it removes the register from our systems along with everything else, which is why the delete flow asks you to confirm that keeping those records is your company's own responsibility (clause 40A).
Cookies
Three cookies, all ours, all functional. No advertising trackers — and our emails don't track you either.
43. What we set. Galaxy CFO sets a sign-in session cookie, a cookie remembering which entity you're viewing, and — if you arrive through a promotional link — a cookie holding the discount code for 30 days. All are first-party and functional; none track you across other sites. We use no advertising cookies or third-party analytics cookies, so there is no consent banner to click. Our emails contain no tracking pixels — we don't know whether you opened them, and we're comfortable with that.
Your rights, and how to reach us
Access, correction, marketing choices, and how to complain — first to us, then to the OAIC if we haven't fixed it.
44. Marketing. We only send marketing where you've asked for it or where you're a customer and it's relevant. Every marketing message has an unsubscribe link, and we act on unsubscribes promptly. Service messages — outages, billing, security — aren't marketing and will continue while you have an account.
45. Access and correction. You can see and correct most of your account information directly in the application, and export your entity's data yourself (clause 39). For anything else, email privacy@galaxycfo.com. We will acknowledge your request within 5 business days and respond within 30 days. If we refuse access or correction, we will tell you why in writing and how to complain. If your request is about information in a workspace that belongs to a business — you as its employee, customer or supplier — see clause 3: start with that business, and we'll help them answer you.
46. Complaints. If you think we've mishandled your personal information, email privacy@galaxycfo.com and tell us what happened. We will acknowledge within 5 business days and respond within 30 days. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, GPO Box 5218 Sydney NSW 2001.
47. Changes to this policy. We may update this policy as the product and the law change. Where a change is material, we will tell you by email before it takes effect. The version and date at the top always reflect the current version, and prior versions are available on request.
48. Contact. Galaxy CFO · Jack and the Beanstalk Pty Ltd · Level 1, 53–55 Sydney Road, Manly NSW 2095, Australia · privacy@galaxycfo.com (privacy) · support@galaxycfo.com (everything else).
Service providers
Everyone who processes personal information on our behalf, what each receives, and where it operates.
- Supabase — database, sign-in and file storage. Holds account information, imported business information and uploaded documents. Data stored in Sydney, Australia.
- Vercel — application hosting. All data transits the application; served from Sydney, Australia. Vercel is a US company, and limited technical log data may be processed in the United States.
- Xero — the accounting platform you connect. Business information flows from (and, for draft bills, to) your Xero organisation under your authorisation; Xero's own handling is governed by the Xero privacy notice.
- Anthropic — AI processing for document reading and the assistant. Receives uploaded documents and aggregate financial snapshots — never employee-level payroll information. Processes in the United States. Not permitted to train AI models on your data.
- Postmark — email delivery, and our inbound support mailbox. Receives names, email addresses and message content. Processes in the United States.
- eWAY — card payments. Receives billing details and card information, which it tokenises; we never see full card numbers. An Australian payment provider.
- Australian Business Register — ABN verification. Receives the ABN you enter. An Australian government service.
We'll update this list before any material change, as clause 39 of our Terms promises.