Privacy Policy
Last updated 30 August 2026 · Version 2026-08-30
Corpmos (ABN 60 347 034 702) (Sydney, Australia) runs the Corpmos platform. This policy explains what personal information we collect, why we collect it, who we give it to and how you can get at it or have it corrected. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. What we collect
Account information. Your name, email address, password (stored only as a hash), and — if you turn on two-factor authentication — a phone number or authenticator secret. We record when you accepted these terms and which version you accepted.
Business information. Your business name, ABN, addresses, contact details, logo, opening hours, catalog, prices and tax settings. Most of this is published on your public page because that is what the page is for.
Information you enter about other people. Contact details of your customers and suppliers — names, emails, phone numbers, delivery addresses — and the quotes, orders, dispatch notes, invoices and payments you exchange with them. You choose what to enter here; we hold it for you (see clause 6).
Guest buyer details. If a business sends you a quote or order link without you having an account, we hold the email address it was sent to, anything you enter in response (delivery details, notes, your acceptance), and a record of when the link was opened.
Usage information. Page views on public profiles and catalogs (including where the visit came from, such as a shared link or QR code), log data such as IP address, browser type and timestamps, and records of emails we sent and whether they were delivered. We use this to run the service, keep it secure, and show a business simple statistics about its own page. We don't use third-party advertising trackers.
2. Why we collect it
To create and secure your account; to publish your business page and catalog; to produce and deliver your documents to the people you address them to; to send transactional email (verification, quotes, orders, invoices, reminders); to provide support; to detect and prevent fraud and abuse; to meet our legal and tax obligations; and to understand which parts of the product are used so we can improve them.
We don't sell personal information, and we don't use your business records to market to your customers.
3. Who sees it
The business you transact with. When you request a quote, place an order or respond to a document, the details you provide go to the other business — that is the point of the exchange. A business sees its own records; it does not see another business's.
Anyone with a guest link. A document link is a secret URL. Whoever holds it can open the document it points to, so send links only to the intended recipient.
Service providers we use to run Corpmos. Our cloud hosting and database provider, and our email delivery provider (so mail can be sent and delivery confirmed). They act on our instructions and only for these purposes.
Accounting software you connect. If you connect Xero, we send invoices, bills, contacts and payments to your Xero organisation when you tell us to. Once there, that data is governed by Xero's own privacy policy. Disconnecting stops any further syncing.
Where the law requires it. We may disclose information if compelled by law, or to protect someone's safety or our legal rights. If Corpmos is ever sold or merged, records may transfer to the new operator, and this policy will continue to apply to them.
4. Overseas disclosure
Corpmos runs on servers located in Sydney, Australia, and that is where your records are stored. Some of the services we rely on operate overseas — in particular our email delivery provider, which processes the address and content of the mail we send on your behalf, and the web font service a page loads from your browser, which sees your IP address. Those providers are typically located in the United States and the European Union. Where information goes overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, but overseas providers are also subject to the laws of their own countries.
5. Cookies and sessions
We use a small number of cookies: a session cookie that keeps you signed in, a security token that protects forms against cross-site request forgery, and — if you opened a document as a guest — a cookie that keeps that guest session open and remembers the device you verified, so you aren't asked to confirm your identity on every page. These are necessary for the service to work — blocking them will stop you signing in. We don't use advertising or cross-site tracking cookies. Page-view statistics are counted on our own servers, not by a third-party analytics network.
6. Whose information is it?
For your own account and business details, Corpmos decides how the information is handled, and this policy governs it.
For the customer and supplier details a business enters, that business decides what to collect and why — we hold and process it on their behalf. If you are a customer of a business that uses Corpmos and you want your details corrected or removed from their records, ask that business first; they can do it directly. If you can't reach them, contact us and we'll help.
7. How long we keep it
We keep account and business records for as long as the account is open. Business transaction records — invoices, payments and the documents behind them — are kept for at least seven years, in line with Australian tax and company record-keeping requirements.
When an account is closed we delete or de-identify personal information we no longer need, within a reasonable period, other than those records we're required to keep. Backups are retained on a rolling basis and age out; deleted data can persist in a backup for a short period before it does.
8. Security
Passwords are hashed, traffic is encrypted in transit, access to production data is limited to the people who need it, and each business's data is separated at the query level. Two-factor authentication is available, and required for accounts handling invoices and payments. No system is perfectly secure; if a data breach occurs that is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
9. Access, correction and deletion
You can view and correct most of your information directly in Corpmos — your profile, business details, catalog and documents. For anything else, email info@corpmos.com and ask us for a copy of the personal information we hold about you, to have it corrected, or to have your account and data deleted.
We'll respond within 30 days. We may need to verify who you are first, and there are limited situations where we can't action a request in full — for example records we must keep for tax, or information whose deletion would remove another business's legitimate record of a transaction. If we refuse, we will tell you why.
10. Complaints
If you think we've mishandled your personal information, email info@corpmos.com with the details. We'll acknowledge your complaint and aim to resolve it within 30 days.
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.
11. Changes and contact
We may update this policy. The current version and date are at the top of this page; if a change materially affects you, we'll tell you by email or in the app.
Pushpraj Joseph, trading as Corpmos (ABN 60 347 034 702), Sydney NSW, Australia — info@corpmos.com. This policy should be read with our Terms of Service.