Lodgeio
Legal

Privacy Policy

Lodgeio handles receipts, claims and the personal information that comes with them. This policy explains, in plain language, what we collect, why, where it lives and what you can ask us to do with it.

Last updated 19 August 2026

1. Who we are

Lodgeio Tech (ABN 56 642 772 736), trading as Lodgeio ("we", "us", "our"), provides expense management software for Australian businesses: a marketing website at lodgeio.com.au and a product at app.lodgeio.com.au where employees lodge expense claims and businesses approve and pay them.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we handle personal information in line with them regardless of our size.

If you use Lodgeio through your employer: your employer decides who has an account, what categories exist and how claims are approved. We process claim data on your employer's behalf to run the service. For questions about how your employer uses that data internally, start with them; for questions about how Lodgeio itself handles it, this policy applies and you can always contact us directly.

2. What we collect

  • Account information. Your name, work email address, role (for example Employee, Manager, Accounts, CFO), the company you belong to, and a securely hashed password. We never store passwords in readable form.
  • Expense information. Receipt and card statement images you upload, and the claim details drawn from them: merchant, date, amount, GST, category, description and payment method. Receipts can incidentally contain other details printed on them.
  • Mileage information. If your company uses mileage claims: trip origin, destination and distance.
  • Approval and audit history. Who lodged, approved, rejected, verified or exported a claim, and when. This trail is a core feature of the product.
  • Waitlist and contact details. Your email address if you join the waitlist or contact us.
  • Billing information. For company account owners: company name, billing contact and billing email. We do not currently collect card details on the website.
  • Technical information. Sign-in events, session tokens, server logs and similar records needed to keep the service running and secure.

3. How we collect it

  • Directly from you, when you join the waitlist, sign in, upload a receipt or lodge a claim.
  • From your employer, when a company administrator creates or updates your account.
  • From the documents you upload, when our software reads the fields on a receipt or statement.
  • Automatically, as routine technical logs when you use the website or the app.

We only collect what the service needs. We do not buy data about you, and we do not collect sensitive information (such as health or biometric data) by design; if a receipt happens to contain something of that nature, we treat it with the same protections as everything else and use it for nothing beyond storing your receipt.

4. How we use it

  • To provide the service: lodging, approving, verifying, paying and exporting expense claims.
  • To read receipts and statements so claim fields are filled in for you (see section 5).
  • To send the emails the service depends on: approval requests, claim status updates, reminders, account and security notices.
  • To keep the required records: audit trails and tax substantiation.
  • To invoice companies for their subscription.
  • To keep the service secure: detecting misuse, locking accounts after repeated failed sign-ins, investigating incidents.
  • To improve the product, using aggregated information (for example, how often claims are rejected and why) rather than anything that identifies you where we can avoid it.
  • To tell waitlist members when Lodgeio launches. One email; you can unsubscribe at any time.

We do not sell personal information, and we do not use it for third-party advertising.

5. AI processing

When you photograph a receipt or upload a statement, the image is read by an AI service so the claim form is filled in for you. The same applies to optional reporting features that summarise patterns in claim decisions for your company. Two things matter here:

  • The AI's output is a suggestion. A person (you, then your approvers) confirms every claim before it goes anywhere.
  • Our AI provider processes the data to provide the feature, not to train its models on your information.

6. Who we share it with

We share personal information only when the service needs it to function: with the specialised providers that operate parts of Lodgeio on our behalf, with your employer (whose administrators and approvers see the claims lodged in their company), and where the law requires it. We never share it for marketing or advertising, we do not sell it, and no provider may use it for its own purposes. The functions we outsource, and where each runs, are:

FunctionWhere it runs
Application hostingSydney, Australia
Database and file storage (receipts, statements)Sydney, Australia
Email delivery (notifications, waitlist)United States
AI reading of receipts and statementsUnited States

Each provider is bound by contractual and security obligations and receives only what its function needs. Beyond that, we disclose personal information only if the law requires it (for example, to the ATO or under a court order), or with your consent.

7. Overseas disclosure

Your data is stored in Australia. Receipts, statements, claims and account records live in Sydney, Australia.

Two functions involve processing overseas: email delivery and AI document reading, both in the United States. In each case the information is sent to perform that single task, is protected in transit, and is handled by the provider under its published security and privacy commitments. By using features that depend on these functions you consent to that limited overseas processing, as contemplated by APP 8.

8. Cookies

The app uses a session cookie so you stay signed in. It is essential, first-party and deleted when the session ends or you log out.

The marketing website does not use advertising trackers or analytics cookies. The website's fonts are currently loaded from a third-party font service, so your browser requests the font files from that service and it sees your IP address in the request, as happens on any site that uses hosted fonts.

9. How we protect it

  • All traffic is encrypted in transit (HTTPS), and data is encrypted at rest.
  • Each company's data is isolated at the database level; one company can never read another's records.
  • Access inside your company follows roles: an employee sees their own claims, approvers see what they approve, and every action is written to an audit trail.
  • Passwords are stored only as salted cryptographic hashes, and accounts lock after repeated failed sign-in attempts.

More detail is on our Security page.

10. How long we keep it

  • Expense records, receipts and audit trails are kept for seven years from the transaction, the period the Corporations Act 2001 requires companies to keep the financial records that explain their transactions (tax law asks for five; we keep the longer), and are then eligible for deletion. This retention continues even if an individual account is deleted, because the records belong to the employer's books.
  • Account details are kept while the account is active.
  • Waitlist emails are kept until launch communications finish or you unsubscribe, whichever comes first.
  • Technical logs are kept for short operational windows.

11. Access, correction and deletion

You can ask us, or your company administrator, to:

  • Access the personal information we hold about you. The product includes an export of your profile data for exactly this purpose.
  • Correct anything inaccurate or out of date.
  • Delete your personal identifiers. When a deletion request is actioned, your name and email are removed and replaced with anonymous placeholders and your account is deactivated. Expense records and audit entries are retained in de-identified form for the legally required period described in section 10.

We respond to these requests within a reasonable time and do not charge for making them. If we cannot do what you ask (for example, deleting records the law requires your employer to keep), we will tell you why in writing.

12. Data breaches

We follow the Notifiable Data Breaches scheme. If a breach occurs that is likely to result in serious harm, we will notify the affected people and the Office of the Australian Information Commissioner (OAIC) as the scheme requires, and tell you plainly what happened and what we are doing about it.

13. Complaints

If you think we have mishandled your personal information, email us at hello@lodgeio.com.au with "Privacy" in the subject line. We will acknowledge your complaint promptly, investigate, and reply with what we found and what we will do.

If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au or by calling 1300 363 992.

14. Changes to this policy

When our data practices change, this policy changes with them, and the date at the top moves. For significant changes we will tell account holders by email before the change takes effect.

15. Contact us

Privacy questions, access requests and complaints all go to hello@lodgeio.com.au. See the Contact page for more.