01 / Privacy
Privacy Policy
Last updated 13 June 2026
1. Who's responsible for your data
ChipIn (chipinpay.app) is operated by [ENTITY NAME] Pty Ltd (ABN [ABN]), [REGISTERED ADDRESS], Australia ("ChipIn", "we", "us"). We're the APP entity responsible for your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You can reach our privacy officer at privacy@chipinpay.app.
1a. Sensitive information
We do not collect sensitive information as defined in the Privacy Act (such as health, biometric, racial or ethnic origin, religious, political or sexual-orientation information). Please don't include this kind of information in receipts, display names or notes you enter into ChipIn.
2. What we collect
- Account info: your email address (for sign-in via magic link or Google) and the display name you choose.
- Bill content: the receipt photo you upload, the extracted line items, totals, currency, and any edits you make.
- Guest sessions: if you join a ChipIn as a guest, we store your chosen display name and the items you claim. A short guest token lives on your device only.
- Payment data: when card payments are enabled, our payment processor handles card details directly — we only see the amount, status, and a reference ID.
- Technical data: basic logs (timestamps, error traces, anonymised request info) used to keep the service running.
3. How we use it
- To run the service — show your bills, sync diners in realtime, and compute shares.
- To process OCR on receipts you upload (handled by our AI provider; receipt text is sent for extraction and not used to train their models).
- To send essential account email (magic links, security notices, receipts and payout confirmations).
- To keep ChipIn secure and to investigate abuse.
We don't sell your data and we don't run advertising trackers.
Direct marketing (APP 7). We do not use your personal information for direct marketing. If we ever introduce optional product or marketing emails, they will be opt-in, will identify us as the sender, and will include a one-click unsubscribe link in line with the Spam Act 2003 (Cth). Transactional and account-security email is essential to the service and cannot be opted out of while your account is active.
4. Who we share it with
We use a small set of service providers acting on our instructions: hosting and database (Lovable Cloud / Supabase, EU region), OCR (our AI gateway provider), and — when enabled — Stripe or Paddle for card processing. Each is bound by data-processing terms.
5. How long we keep it
- Open ChipIns: while active, plus 12 months after settlement.
- Deleted ChipIns: removed within 30 days.
- Account deletion: erases your account and bills within 30 days; some backups roll off within 90 days.
- Payment records: retained as required by tax/financial regulations (typically 6–7 years).
6. Your rights
You have the right to access and correct the personal information we hold about you, to request its deletion, and to export it. Email privacy@chipinpay.app and we'll respond within 30 days. If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or with your local data-protection authority if you live outside Australia.
7. International transfers
Our primary servers are in the EU. Some sub-processors (e.g. payment providers) may process data in the US or UK under approved transfer mechanisms (Standard Contractual Clauses or equivalent).
8. Cookies and storage
ChipIn uses essential storage only — a sign-in session token, and a per-bill guest token kept in your browser's local storage. No third-party advertising or analytics cookies.
8a. Notifiable data breaches
We follow the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach that is likely to result in serious harm to individuals whose personal information we hold, we will notify those individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in line with our obligations under the scheme.
9. Children
ChipIn isn't intended for people under 15. We follow OAIC guidance that individuals aged 15 and over are generally presumed to have capacity to consent to the handling of their own personal information. If you're under 15, please don't create an account or join a ChipIn without a parent or guardian's involvement. If you believe we hold information about someone under 15 without appropriate consent, contact us and we'll delete it.
10. Changes to this policy
We'll post material changes in-app at least 14 days before they take effect. The "Last updated" date above always reflects the current version.