This policy explains what data the Kepd Trade Platform application collects, why we collect it, who we share it with, and the choices you have — including the data we access from your Intuit QuickBooks Online account.
Who we are
Kepd Trade Platform (the “App”) is operated by Eastmarket Investments Pty Ltd (ACN 636 076 974), registered at 10/100 Hay Street, Subiaco WA 6008, Australia. For data protection purposes we act as the controller of account data and as a processor of the business records you sync from QuickBooks.
Our data protection contact is info@kepd.com.au.
What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, company name, role, password hash | You, at sign-up |
| Billing data | Plan, billing address, invoice history, last four digits of card | You and our payment processor |
| QuickBooks data | See section 3 | Intuit API, with your authorisation |
| Business records | Jobs, quotes, invoices, clients, properties, timesheets, and expenses you enter or import | You |
| Usage data | Pages viewed, features used, sync timestamps, error events | Automatically |
| Technical data | IP address, browser and device type, time zone | Automatically |
| Support data | Messages, attachments, and correspondence you send us | You |
We do not intentionally collect special category data such as health, biometric, or political data. Please do not submit it through the App.
QuickBooks data
When you connect the App to QuickBooks Online, you authorise it through Intuit’s OAuth 2.0 flow. Intuit shows you the scopes being requested, and we never see or store your QuickBooks username or password — only the access and refresh tokens Intuit issues, which we store encrypted.
Depending on the scopes you approve, the App may read and write the following record types in the company file you select:
- Company profile and preferences
- Chart of accounts and journal entries
- Customers, suppliers, and their contact details
- Invoices, bills, estimates, purchase orders, and credit notes
- Payments, deposits, and bank transaction records
- Products, services, and inventory items
- Tax codes, tax rates, and currency settings
Some of these records contain personal data about your customers, suppliers, and staff. You remain the controller of that data. We process it only on your instructions, to provide the App.
How we use data
| Purpose | Data used |
|---|---|
| Operate the QuickBooks sync | QuickBooks data, trade data, account data |
| Authenticate you and secure accounts | Account data, technical data |
| Provide reporting and reconciliation in the App | QuickBooks data, trade data |
| Bill you and collect payment | Billing data, account data |
| Respond to support requests | Support data, usage data, account data |
| Diagnose errors and improve reliability | Usage data, technical data, error logs |
| Detect fraud and abuse, and meet legal obligations | Account data, technical data, billing data |
| Send service notices, and marketing where you have opted in | Account data |
Legal bases
As an Australian company we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the UK GDPR or EU GDPR also applies because you or your contacts are in the UK or EEA, we rely on the following legal bases:
- Contract — to provide the App you have signed up for and to bill you.
- Legitimate interests — to secure the service, prevent fraud, and improve reliability, balanced against your rights.
- Legal obligation — to meet accounting, tax, and regulatory duties.
- Consent — for optional analytics cookies and marketing email, which you can withdraw at any time.
Who we share with
We share data only with service providers who help us run the App, under written contracts that restrict them to our instructions:
| Provider | Role | Location |
|---|---|---|
| Supabase | Database and authentication hosting | Australia (ap-southeast-2) |
| Vercel Inc. | Application hosting and analytics | United States |
| Intuit Inc. | QuickBooks Online API | United States |
| Stripe, Inc. | Subscription billing | United States |
| Resend | Transactional email | United States |
| Twilio Inc. | SMS notifications | United States |
We may also disclose data where required by law or valid legal process, to enforce our terms, or in connection with a merger or acquisition — in which case we will notify you before your data becomes subject to a different privacy policy.
What we never do
We do not sell your data or your customers’ data. We do not share it with advertisers or data brokers. We do not use data obtained from QuickBooks for advertising, for building marketing profiles, or for any purpose other than providing the App to you and improving its reliability. We do not use identifiable QuickBooks data to train machine-learning models.
How long we keep it
| Data | Retained for |
|---|---|
| QuickBooks data and trade data | While your account is active; deleted within 30 days of account closure |
| OAuth tokens | Deleted immediately when you disconnect the App |
| Account data | Duration of the account, plus 90 days |
| Billing records | 7 years, to meet tax and accounting law |
| Security and audit logs | 12 months |
| Encrypted backups | Rolling 35 days, then overwritten |
Disconnecting and deletion
Disconnect the App
You can revoke the App’s access to QuickBooks at any time, either from Settings inside the App or from the Apps section of your QuickBooks Online account. Revoking access stops all further reading and writing of your QuickBooks data immediately.
Request deletion
To have your data erased, email info@kepd.com.au or use the delete option in your account settings. We will confirm within 30 days and remove your data from live systems, except records we must keep by law. Backup copies are purged on the rolling schedule in section 8.
Security
We protect data with measures appropriate to its sensitivity, including:
- Encryption in transit using TLS 1.2 or higher, and encryption at rest using AES-256
- OAuth tokens stored encrypted with keys held in a managed secrets service
- Role-based access control (Postgres row-level security) and least-privilege access for staff, with access reviewed quarterly
- Multi-factor authentication required for administrative systems
- Logging, monitoring, and alerting on access to production data
No system is perfectly secure. If a breach affects your data, we will notify you and any relevant regulator without undue delay and, where required, within 72 hours of becoming aware.
International transfers
We store data in Australia (ap-southeast-2). Some providers listed in section 6 process data in other countries, including the United States. Where data leaves the UK or EEA, we rely on Standard Contractual Clauses (and the UK IDTA where applicable) together with additional safeguards. You can request a copy of the relevant transfer mechanism from info@kepd.com.au.
Your rights
Under the Australian Privacy Principles you may request access to the personal information we hold about you and ask us to correct it. Depending on where you live, you may also have the right to delete your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. Residents of California and similar jurisdictions may also request disclosure of the categories of data collected and shared, and may opt out of any “sale” or “sharing” — though as stated in section 7, we do neither.
To exercise a right, email info@kepd.com.au. We will respond within 30 days and will not discriminate against you for making a request. We may need to verify your identity first.
If your personal data reached us because a Kepd customer synced it from their QuickBooks file, please contact that business directly; we will forward your request to them and support their response.
You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner’s Office; in the EU, your national data protection authority.
Cookies
We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These cannot be switched off. We do not use advertising or marketing cookies. You can clear or block cookies in your browser, though the App may not work correctly without the necessary ones.
Children
The App is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children. If we learn that we have, we will delete it promptly.
Changes to this policy
We may update this policy as the App evolves. The effective date at the top always reflects the current version. For material changes we will give notice by email or in-app at least 30 days before they take effect.
Contact us
Privacy questions and requests: info@kepd.com.au
Security reports: info@kepd.com.au
Post: Eastmarket Investments Pty Ltd, 10/100 Hay Street, Subiaco WA 6008, Australia