1. Who we are
Cash King ("we", "us") provides a cash-flow and invoice dashboard that connects to your accounting system and sends payment reminders by SMS. We act as a data controller for your account details and as a data processor for the accounting and contact data you import through connected services.
2. Data we process
- Account data: email address, display name, authentication identifiers.
- Financial data imported from Xero: invoice numbers, amounts, issue and due dates, status, and customer contact name, email and phone number.
- Communication data: SMS message content, recipient number, delivery status, segment count and estimated cost.
- Technical data: log and error information needed to operate the service.
3. Xero financial data — how it is secured
- We connect to Xero using OAuth 2.0. We never see, request or store your Xero username or password.
- Access and refresh tokens are held server-side only, in a database table that is unreadable by any browser client: row level security denies all access to anonymous and authenticated roles, and only privileged backend code may read it.
- Data is encrypted in transit (TLS 1.2+) and encrypted at rest by our infrastructure provider.
- We request the minimum scopes required to read and reconcile sales invoices, and we never write to your accounting ledger without an explicit action from you.
- Every imported invoice is stored against your user ID and protected by row level security, so no other customer or user can query it.
- You may disconnect Xero at any time; we revoke stored tokens and stop all further synchronisation.
4. Twilio SMS communications — how they are secured
- SMS reminders are sent exclusively from our backend. Twilio credentials are stored as encrypted server-side secrets and are never exposed to the browser.
- Requests to Twilio are authenticated over HTTPS. Message content is limited to the information needed to identify the invoice and amount due.
- Every message is logged against your account with status, timestamp and cost so you have a complete audit trail.
- Recipients can opt out at any time by replying STOP. We honour opt-outs immediately and suppress further messages to that number.
- You are responsible for having a lawful basis (contract or legitimate interest) to contact your customers, and for complying with local messaging rules such as the TCPA, the Australian Spam Act and equivalent regimes.
5. Legal bases and global compliance
We process personal data under the GDPR and UK GDPR on the bases of contract performance, legitimate interests in operating and securing the service, and consent where required. We support data subject rights under the GDPR, UK GDPR, the CCPA/CPRA, the Australian Privacy Act 1988 (including the Australian Privacy Principles), PIPEDA and the New Zealand Privacy Act 2020.
We do not sell or share personal information for cross-context behavioural advertising. International transfers rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.
6. Your rights
You may request access, correction, deletion, restriction, objection or portability of your personal data, and may withdraw consent at any time. We respond within the period required by applicable law (30 days in most jurisdictions, 45 days under the CPRA).
7. Retention
Invoice and SMS log records are retained while your account is active and for up to 12 months afterwards, unless a longer period is required for tax, accounting or legal purposes. OAuth tokens are deleted as soon as a connection is revoked.
8. Sub-processors
We rely on Xero (accounting data access), Twilio (SMS delivery) and our cloud database and hosting provider. Each is bound by a data processing agreement with appropriate security and confidentiality obligations.
9. Security incidents
We maintain access controls, least-privilege service credentials, encrypted secrets and audit logging. If a breach affects your personal data we will notify you and the relevant supervisory authority without undue delay and within 72 hours where required.
10. Contact
Privacy questions or rights requests: privacy@cashking.app.