Privacy Policy
Sparrow Invoicing
Effective date: 01 June 2026
1. Introduction
Sparrow Invoicing(“Sparrow”, “we”, “us”, or “our”), respects your privacy and is committed to protecting personal information.
This Privacy Policy explains how we collect, hold, use, disclose, store, and otherwise handle personal information when you use our website, software platform, applications, support channels, integrations, and related services (together, the “Service”).
This Policy is intended to reflect our obligations under the New Zealand Privacy Act 2020 and, where applicable, the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles.
By accessing or using the Service, you acknowledge that your personal information will be handled in accordance with this Privacy Policy.
2. Who This Policy Applies To
This Policy applies to personal information we collect about:
- account holders, administrators, users, and authorised representatives of businesses using the Service
- sole traders and business owners
- customers, contacts, payers, recipients, and suppliers whose details are entered into the Service by our users
- individuals who contact us for support, sales, onboarding, or general enquiries
- visitors to our website and users of our applications
In this Policy, “personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
3. What Information We Collect
We may collect and hold the following categories of personal information.
- Account and identity information: full name, email address, phone number, login credentials, password hashes, account security settings, user role, permissions, and preferences.
- Business and profile information: business or trading name, NZBN, ABN, GST number, IRD number, business address, postal address, currency, tax settings, invoice preferences, and branding details.
- Financial and transaction information: invoices, quotes, credit notes, payments, refunds, transaction records, customer names, billing details, bank account details where provided, and subscription billing history.
- Integration and connected service data: information made available through third-party connections that you authorise, such as accounting, banking, or payment service data needed to provide the Service.
- Technical and usage information: IP address, browser type, device information, operating system, pages viewed, feature usage, timestamps, referring URLs, cookie identifiers, and diagnostic logs.
- Communications and support information: messages, emails, attachments, chat transcripts, support tickets, survey responses, onboarding information, feedback, and product enquiries.
- Sensitive information: we do not intentionally require sensitive information for ordinary use of the Service. Please do not provide sensitive information unless it is reasonably necessary and requested by us for a lawful purpose.
4. How We Collect Information
We collect personal information in several ways, including:
- directly from you when you create an account, subscribe, contact us, request support, or use the Service
- from information you or your authorised users upload, enter, generate, or store within the Service
- from third-party providers and integrations you choose to connect
- from payment processors and service providers involved in account administration and billing
- automatically through cookies, logs, analytics tools, and similar technologies when you use the Service
- from publicly available sources, where reasonably necessary for business verification, fraud prevention, or compliance purposes
Where practicable, we collect personal information directly from the relevant individual. However, much of the information in Sparrow Invoicing will be entered by our business customers on behalf of their staff, clients, and contacts.
5. Why We Collect, Use, and Hold Information
We may collect, hold, use, and disclose personal information for the following purposes.
- To provide the Service: create and manage user accounts; provide invoices, customer management, payment, reporting, and related features; generate, send, and manage invoices, reminders, statements, and related documents; and maintain account settings, user permissions, and subscription access.
- To operate and improve our platform: provide customer support; troubleshoot issues; monitor performance; maintain up-time; improve workflows and user experience; and develop new functionality using aggregated or de-identified insights.
- To secure accounts and prevent misuse: verify identity and account ownership; detect, investigate, and prevent fraud, abuse, unauthorised access, and security incidents; and enforce our Terms of Use.
- To communicate with you: send account-related notices, service messages, security alerts, verification emails, password reset messages, billing notices, support communications, onboarding content, and, where permitted, product updates and marketing communications.
- To comply with legal and regulatory obligations: comply with applicable tax, accounting, corporate, record-keeping, anti-fraud, and legal obligations; respond to lawful requests; and establish, exercise, or defend legal claims.
We do not sell personal information to third parties and do not use your invoice or customer content for third-party advertising.
6. Cookies and Similar Technologies
We use cookies and similar technologies to operate, secure, and improve the Service and our website.
These may include:
- strictly necessary cookies required for login, security, page navigation, forms, and core functionality;
- functional cookies that help remember user preferences such as region, language, or saved choices;
- analytics cookies that help us understand website visits, feature usage, page performance, and user behaviour; and
- marketing cookies used for advertising, remarketing, conversion tracking, and campaign performance, where enabled.
Only strictly necessary cookies should operate by default. Where required by law or where we choose to provide enhanced user control, non-essential cookies such as analytics and marketing cookies will not be enabled until you accept them or update your cookie preferences.
You can usually control cookies through your browser settings and, where available, through the Cookie Settings link on our website. If you disable certain cookies, some parts of the Service may not function properly.
7. When We Share Information
We may disclose personal information only where reasonably necessary for the purposes described in this Policy, including:
- service providers and contractors, such as cloud hosting, email delivery, payment processors, customer support, monitoring, analytics, backup, and security service providers;
- professional advisers, auditors, insurers, and legal counsel;
- connected integrations where you authorise a connection, including accounting, payment, or other business software providers required to enable the requested functionality;
- parties involved in corporate transactions, such as a merger, acquisition, restructuring, financing, sale of assets, or similar transactions, subject to appropriate confidentiality protections;
- courts, tribunals, regulators, government agencies, law enforcement, tax authorities, and parties involved in dispute resolution or legal proceedings where required or permitted by law; and
- other parties where disclosure is made with your direction or consent.
8. Overseas Disclosure and Cross-Border Processing
Our primary hosting infrastructure is intended to operate in the Asia-Pacific region, including Australia (Sydney). Depending on the services you use, and the service providers engaged by us from time to time, personal information may also be processed, accessed, stored, or disclosed outside New Zealand or Australia.
This may include disclosures to approved service providers and sub-processors located in, or operating from, New Zealand, Australia, and other countries where our service providers operate.
Where we disclose personal information to overseas recipients, we will take reasonable steps to ensure that appropriate privacy, confidentiality, and security safeguards are in place, as required by applicable law.
9. Data Storage and Security
We take reasonable technical, organisational, and administrative measures to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
These measures may include encryption in transit, encryption at rest where appropriate, secure authentication controls, role-based access controls, logging and monitoring, backups and disaster recovery measures, staff access restrictions, and vendor due diligence and contractual safeguards.
However, no method of transmission over the internet or electronic storage is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security.
10. Data Breach Response
We maintain processes for identifying, assessing, and responding to privacy and security incidents.
If we become aware of a data breach affecting personal information, we will investigate and take appropriate steps to contain and remediate the issue. Where required by applicable law, we will notify affected individuals and the relevant regulator.
11. Retention of Information
We keep personal information only for as long as reasonably necessary for the purposes for which it was collected, and as required or permitted by law.
This means, for example, that account and profile information is generally retained while your account remains active; support and operational records may be retained for a reasonable period for service, audit, dispute resolution, and security purposes; and invoice, payment, tax, and business record data may be retained for the minimum period required under applicable tax, accounting, and legal obligations.
For customers operating in New Zealand, certain business and tax records may need to be retained for at least 7 years. For customers operating in Australia, many business records must generally be retained for at least 5 years, and in some cases longer. Where retention is required by law, we may retain information even after account closure.
After closure of your account, we may delete or de-identify information that is no longer required, subject to our legal, tax, accounting, fraud prevention, backup, and dispute resolution obligations.
12. Access and Correction
Subject to applicable law, you may request access to the personal information we hold about you and ask us to correct information that is inaccurate, incomplete, out of date, or misleading.
Before responding, we may require you to verify your identity and provide information to help us locate the relevant records.
In some circumstances, we may lawfully refuse a request, such as where the law permits or requires refusal, where the request would unreasonably impact the privacy of others, or where the information is subject to legal privilege or retention obligations.
If we do not make a requested correction, you may ask us to note your request with the relevant record where required by law.
13. Deletion, Account Closure, and Export
You may request closure of your Sparrow account at any time, subject to your contractual commitments and any legal retention requirements.
Where available, we may provide tools or reasonable assistance to help you export certain business records before closure. Some information may remain in backups or retained archives for a limited period, or may need to be kept to meet legal, regulatory, fraud prevention, accounting, tax, or dispute resolution requirements.
Deletion requests will be assessed in light of those obligations.
14. Direct Marketing and Preferences
We may send service-related announcements and administrative communications that are necessary to provide the Service.
Where permitted by law, we may also send you marketing or promotional communications about Sparrow Invoicing products, features, updates, or events. You can opt out of marketing communications at any time by using the unsubscribe link in the communication or by contacting us.
We will not use sensitive information for direct marketing without any consent required by applicable law.
15. Third-Party Websites and Services
The Service may contain links to third-party websites, apps, or services, or may integrate with third-party platforms. We are not responsible for the privacy practices of those third parties. You should review their privacy policies before providing personal information to them.
16. Children
The Service is designed for business and professional use and is not directed to children. We do not knowingly collect personal information directly from children through the Service for consumer use.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our business, technology, legal obligations, or privacy practices.
When we make material changes, we will take reasonable steps to notify users, such as by email, in-product notice, or by publishing an updated version on our website. The revised version will take effect from the updated effective date stated at the top of this Policy.
18. Complaints
If you have a privacy concern or complaint, please contact us first so we can try to resolve it.
If you are not satisfied with our response, you may be entitled to make a complaint to the relevant privacy regulator, including:
- the Office of the Privacy Commissioner (New Zealand)
- the Office of the Australian Information Commissioner (Australia)
19. Contact Us
Privacy Officer
Sparrow Invoicing
Email: admin@cozysparrow.com
For privacy requests, questions, corrections, or complaints, please contact us using the details above.